Data Processing Agreement

Effective: February 2026

Introduction & Parties

This Data Processing Agreement ("DPA") forms part of the Terms of Service between:

  • Data Controller: The Customer (the clinic, business, or individual using the Borradh platform)
  • Data Processor: Borradh Technologies Limited, 72 Mount Prospect Avenue, Clontarf, Dublin 3, D03 XV79, Ireland

Contact: privacy@borradh.io

This DPA sets out the terms under which the Processor processes Personal Data on behalf of the Controller in connection with the Services, and reflects the parties' agreement with regard to the processing of Personal Data in accordance with the requirements of Data Protection Laws.

Sub-processors

The Controller provides general written authorisation for the Processor to engage the following sub-processors:

Sub-processorPurposeLocationData Processed
Amazon Web Services (AWS)Cloud infrastructure, database hosting, file storage, secrets management, SMS delivery (SNS)Ireland (eu-west-1) / USAll platform data
Meta PlatformsAd campaigns, lead forms, page management, WhatsApp messaging, chatbot conversationsUSALead data, ad creatives, targeting data, messages, conversation content
StripePayment processing, subscription billing, depositsUSACustomer name, email, payment details
Google (Calendar, Gmail, Maps, Drive, My Business)Calendar integration, email sending, geocoding, template storage, business reviewsUSAEmails, calendar events, addresses, reviews, files
Microsoft (Outlook)Email integrationUSAEmail addresses, email content
TelnyxAI voice calls, phone number provisioningUSAPhone numbers, call transcripts, recordings, AI summaries
ElevenLabsText-to-speech for voice callsUSAVoice synthesis data
OpenAILLM for voice AI agents, website analysis, chatbot intelligenceUSALead context, conversation content, website content
ResendTransactional email deliveryUSAEmail addresses, email content
Loops.soEmail marketing automationUSAEmail addresses, contact properties
CalendlyAppointment schedulingUSAEvent details, availability, invitee information
Timely / PhorestBooking system integrationVariousAppointment details, availability
PostHogProduct analyticsUSAUsage events, anonymised user identifiers
SentryError monitoringUSAError logs, user IDs (no personal data beyond ID)
BetterStack (Logtail)Log aggregation and monitoringUSAServer logs, request metadata

The Processor shall provide the Controller with at least 14 days' prior notice of any intended changes to sub-processors. The Controller may object within 7 days of receiving notice.

Security & Data Transfers

Personal Data is stored in AWS eu-west-1 (Ireland) where possible. Transfers to US-based sub-processors are covered by EU Standard Contractual Clauses (Module 2: Controller to Processor) and the UK International Data Transfer Addendum.

We implement encryption in transit (TLS/HTTPS) and at rest (AWS RDS storage encryption, AWS Secrets Manager), role-based access control, Row-Level Security (RLS) at the PostgreSQL database level, OAuth-token AES encryption, network isolation in private subnets, and structured logging with error tracking.

The Processor shall notify the Controller without undue delay (and no later than 48 hours) upon becoming aware of a Personal Data Breach.

Data Retention & Deletion

Personal Data is processed for the duration of the service agreement. On termination, the Controller may request the return or deletion of all Personal Data.

  • Deletion of active data completed within 30 days of request
  • Backup data purged within 90 days
  • Limited data may be retained where required by law (e.g., billing records for tax compliance)

Contact

For questions about this DPA, please contact:

  • Borradh Technologies Limited
  • 72 Mount Prospect Avenue, Clontarf, Dublin 3, D03 XV79, Ireland
  • Email: privacy@borradh.io

See also our Privacy Policy and Data Deletion Policy.