Data processing agreement

Standard terms under Article 28 UK GDPR. They apply automatically when your organisation uses GrandRound.

Template wording — have it checked by your Information Governance or legal team before relying on it.

1. Roles

Each organisation (for example an NHS trust department, deanery or society) is the controller of the personal data it collects through its events. GrandRound is the processor and processes that data only on the organisation's documented instructions, which are the settings and actions it uses in GrandRound.

2. Subject matter and duration

Running academic and teaching events: registration, abstract submission and review, check-in, judging, feedback, CPD certificates and related emails. Processing lasts for as long as the organisation uses GrandRound, subject to the retention settings it chooses for each event.

3. Personal data and data subjects

  • Attendees, submitters, co-authors, reviewers, judges and organisation members.
  • Names, email addresses, grade, institution, professional registration numbers, consents, attendance, submissions, scores, feedback and certificates.
  • No special category data or patient-identifiable information should be entered. Forms warn users about this.

4. Processor obligations

  • Process data only on documented instructions, and tell the controller if an instruction appears to break data protection law.
  • Make sure everyone with access is bound by confidentiality.
  • Use appropriate technical and organisational security: encryption in transit, strict separation between organisations, role-based access and audit logging of administrator actions.
  • Help the controller respond to data subject requests, using the export and delete tools available for each event.
  • Notify the controller without undue delay, and within 48 hours, after becoming aware of a personal data breach.
  • At the end of the service, delete or return personal data as the controller chooses.
  • Make information available to demonstrate compliance, and allow reasonable audits.

5. Sub-processors

The controller authorises the following: cloud hosting and database infrastructure, and an email delivery provider (Resend) for event emails. We will give notice before adding or replacing sub-processors, so you can object.

6. International transfers

Where data is processed outside the UK, it is protected by appropriate safeguards such as the UK International Data Transfer Addendum.

7. Controller responsibilities

The controller publishes its own privacy notice (editable in organisation settings), makes sure it has a lawful basis for processing, sets retention periods and responds to data subjects.

Questions: privacy@grandround.co.uk