Data Processing Agreement

Version 2026-09-10

How Similia processes patient information on behalf of practitioners, clinics and schools, including responsibilities, security, retention and service providers.

Read or share this agreement here. Acceptance is recorded in Similia once for the account and named practitioner or organisation, before entering patient information.

Open patient-data settings

This Data Processing Agreement governs how Similia processes patient information on behalf of the practitioner or organisation identified in the acceptance record. It includes the processing description, security and retention obligations, and service-provider arrangements in Schedules A–C. It forms part of the service agreement when accepted electronically by an authorised representative of the Customer.

1. Parties and acceptance

This Data Processing Agreement (DPA) is between SIMILIA LTD, registered address 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ (Similia), and the practitioner, clinic or other organisation identified in the electronic acceptance record (Customer).

The individual accepting confirms their authority to bind the Customer. Where a practitioner operates personally rather than through a separate entity, the Customer is that practitioner. The acceptance record identifies the Customer, representative, authenticated account, accepted DPA version and schedules, and acceptance date. Similia provides a copy of that record and the agreed documents.

When the Customer accepts Similia's offer of this DPA through the patient-data activation flow, both parties are bound. This DPA becomes part of the service agreement and covers the processing described below. It is not accepted again for each patient or case. Acceptance covers the named Customer’s use through the account identified in the record. It does not automatically cover other account holders. A different Customer requires its own agreement.

2. Scope and roles

“Customer Patient Data” means personal information submitted by or for the Customer about patients and people mentioned in their records, together with identifiable information derived from it. This includes health notes, symptoms, histories, contact details, photographs, recordings, transcripts and analysis results. Information linked to a patient through a code or other reasonably available information remains covered.

The Customer determines the purposes of this processing and acts as controller. Similia processes Customer Patient Data on the Customer's behalf as processor. The description of processing is in Schedule A.

Where the Customer itself acts as processor for another controller, this DPA applies to Similia as its subprocessor. The Customer must have authority from that controller to appoint Similia and provide the instructions and authorisations in this DPA; references to controller obligations apply to the Customer to the extent of its responsibilities and authorised instructions.

Similia's separate processing of account, billing and business-administration information for its own purposes is described in its Privacy Policy. That role does not authorise Similia to use Customer Patient Data for independent purposes. This DPA does not apply to reference browsing or entirely fictional or effectively anonymised study material, although ordinary account privacy obligations continue.

“Applicable Data Protection Law” means the personal-data laws applicable to the relevant party and processing, including UK GDPR, the UK Data Protection Act 2018 and EU GDPR where applicable. Using this common DPA internationally does not, by itself, make every Customer subject to EU or UK GDPR.

3. Instructions and permitted use

Similia will process Customer Patient Data only on documented Customer instructions, including instructions about transfers. The service agreement, this DPA, selected features and authorised actions within the service constitute those instructions. Additional instructions may be agreed in writing.

Similia will inform the Customer immediately if, in its opinion, an instruction infringes applicable UK, EU or Member State data-protection law, and pause the affected instruction while it is resolved.

If processing beyond those instructions is required by applicable UK, EU or Member State law, Similia will notify the Customer before processing, unless that law prohibits notice on important public-interest grounds. Other government demands will be assessed under the applicable law and transfer safeguards; they do not create a general exception to this DPA.

Customer Patient Data will not be sold, used for advertising or used to train or fine-tune AI models. Similia will not authorise its subprocessors to use it for those purposes. AI processing is limited to the authorised feature and the providers, purposes and retention arrangements disclosed in Schedule C. This clause does not promise zero retention by every provider.

4. Customer responsibilities

The Customer is responsible for lawful collection, use and disclosure of Customer Patient Data, appropriate patient notices, data minimisation and authorised access and sharing. Where applicable, it must identify an Article 6 lawful basis and an Article 9 condition for health information and meet relevant confidentiality and national-law requirements.

The Customer must obtain consent where consent is required. Accepting this DPA or enabling an AI feature is not consent from the patient. Students must act within the authority of the responsible practice or institution when using its patient information; a student account alone provides no such authority.

These responsibilities do not remove Similia's own legal or contractual obligations.

5. Confidentiality and security

Similia will limit access to personnel who need it for the agreed processing and who are bound by contractual or statutory confidentiality duties.

Similia will maintain technical and organisational measures appropriate to the risks, including the sensitivity of health information, as specified in Schedule B. These address access control, encryption, resilience and recovery, incident handling and regular evaluation of safeguards. Material changes will not reduce the agreed level of protection.

6. Subprocessors

The Customer gives general written authorisation for the subprocessors described in Schedule C, subject to its disclosure requirements, to perform the specified processing. Similia will give at least 30 days' advance written notice of a proposed addition or replacement, with information sufficient to assess its effect.

The Customer may object during that period on reasonable data-protection grounds. The parties will seek an alternative or suitable safeguards. The proposed subprocessor will not receive that Customer's data while its timely objection is unresolved. If no solution is possible, either party may end the affected feature or service; the Customer may retrieve its data and receive a proportionate refund of unused prepaid fees for the discontinued service.

Similia will impose equivalent relevant data-protection obligations on each subprocessor through a binding contract and remains responsible to the Customer for its subprocessor's performance. AI routing does not provide blanket authorisation for undisclosed downstream providers.

7. International processing

Similia will disclose the relevant processing and access countries and applicable transfer arrangements under Schedule C before the affected processing begins. Before a transfer requiring safeguards takes place, the responsible party will put the required mechanism and any necessary assessment and supplementary measures in place. Similia remains responsible for transfers it initiates to its subprocessors.

Where applicable, safeguards may include a valid adequacy decision, completed EU transfer standard contractual clauses, or an applicable UK international-transfer instrument. These must cover the actual transfer and parties; this DPA alone does not supply missing transfer clauses. Remote access from another country must also be considered.

8. Assistance and incidents

Taking account of the nature of processing, Similia will provide appropriate assistance so the Customer can respond to requests for access, correction, erasure, restriction, portability and other applicable individual rights. Similia will forward patient requests concerning Customer Patient Data to the Customer without undue delay and will not decide or fulfil them independently except on instruction or where legally required.

Taking account of the information available to it, Similia will assist with security obligations, breach assessment and notification, data-protection impact assessments and required prior consultation with regulators.

Similia will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Patient Data. Initial notice will not wait for a complete investigation. Available information will cover the nature of the incident, affected data and people, likely consequences, response measures and a contact point; further information will follow as it becomes available. The Customer remains responsible for its own notification decisions and deadlines, without affecting Similia's direct duties.

Notices to the Customer will use the privacy contact in the acceptance record or a replacement notified in writing. Data-protection requests, incident reports and notices to Similia should be sent to info@similia.io. Similia will monitor this contact and route requests to the responsible personnel.

9. Return, deletion and duration

The DPA continues while Similia processes Customer Patient Data for the Customer, including any protected residual copies after service termination.

At the end of the relevant processing services, the Customer may choose return followed by deletion, or deletion, of Customer Patient Data. Similia will delete existing copies unless applicable UK, EU or Member State law requires storage. Export, deletion and residual-copy handling follow Schedule B.

Residual copies remain protected, unavailable for ordinary service use and are deleted at the next applicable scheduled deletion cycle. If a backup is restored for recovery, completed deletion instructions will be reapplied before the restored data returns to ordinary use. Similia will provide confirmation of completion on request.

Information about patients will not be retained under a general service-improvement, shared-content or de-identification exception. Any different processing purpose needs its own valid legal and contractual basis.

10. Accountability, audits and changes

Similia will provide information necessary to demonstrate compliance with its processor obligations and allow and contribute to Customer audits, including inspections by an authorised independent auditor. Relevant reports and remote evidence may be used first where sufficient; they do not remove the right to an inspection when necessary. Reasonable arrangements must protect other customers' data and service security without obstructing effective oversight or regulators.

If this DPA conflicts with the general terms about Customer Patient Data, this DPA prevails. Applicable mandatory transfer clauses prevail over inconsistent provisions. Nothing limits statutory responsibilities or individuals' rights.

Changes to this DPA require direct notice and a valid agreement mechanism before taking effect. Merely replacing the published page is insufficient. Subprocessor changes follow clause 6. This DPA is governed by the law of England and Wales, and its courts have jurisdiction, subject to mandatory data-protection law, individuals’ statutory rights and transfer-clause requirements. The accepted language version and its schedules are preserved in the acceptance record.

Schedule A — description of processing

ItemScope
Subject matterPatient-related records and workflows the Customer chooses to use in Similia.
PurposeProvide the Customer's authorised record storage, retrieval, organisation, sharing, export and selected analysis/transcription features.
OperationsCollection from the Customer, storage, retrieval, structuring, authorised disclosure, inference/analysis, transcription, export and deletion, as instructed.
PeoplePatients, including minors where lawfully submitted, and relatives, carers or others mentioned in their records.
DataNames or identifiers, contact and demographic details, complaints, histories, consultation notes, selected rubrics, assessments, images, voice recordings, transcripts and outputs, as submitted or generated.
Sensitive informationHealth information and any other special-category information lawfully included in the records. Images and voice are not automatically biometric identification data; no biometric-identification purpose is authorised here.
Frequency and durationAs the Customer uses selected features; retention and termination arrangements are specified in Schedule B.
Shared recordsOnly recipients and uses authorised by the Customer. A school or independent recipient's own controller obligations require separate assessment.

Schedule B — security and retention

Similia will implement and maintain the following measures for Customer Patient Data. These obligations apply to Similia’s own systems and, through appropriate contractual and technical controls, to the services it appoints.

AreaRequired measures
Access controlAuthenticate access to patient records; restrict records to the Customer and authorised recipients; check permissions on server operations and direct database access. Limit privileged access to authorised personnel who need it, require strong authentication, and revoke access when no longer needed.
ConfidentialityBind personnel to confidentiality and instruct them in handling health information, access requests and incidents.
EncryptionProtect data in transit with encrypted connections and use the storage providers’ encryption at rest. Restrict access to service credentials and encryption keys. This is not an end-to-end encryption service.
Monitoring and minimisationUse security and error monitoring to detect failures and investigate incidents. Exclude patient narratives, images and audio from advertising and product analytics; minimise and restrict any personal data required for diagnostic or support records.
ResilienceMaintain recovery arrangements for stored records, restrict access to recovery copies, and regularly assess restoration procedures. Reapply completed deletion instructions before restored data returns to ordinary use.
Security maintenanceAssess the effectiveness of safeguards regularly and after material changes; investigate vulnerabilities, apply risk-appropriate updates and maintain incident-response procedures.
Supplier controlsAssess the safeguards of services receiving patient data, put binding processor terms in place and restrict their processing to authorised purposes. Do not route patient data to a service whose terms or settings permit training on that data.

Active records and return. Records remain available while the Customer uses the service, until the Customer instructs deletion or the relevant processing ends. The Customer can export account data in the available machine-readable format and retrieve retained attachments. Similia will assist with a return request that the export tools cannot fulfil. On termination, Similia will provide a reasonable opportunity to receive the data before deleting it, unless the Customer has instructed immediate deletion or the law prevents return.

Deletion. An authenticated record or account deletion instructs Similia to remove the affected data from active service use. Similia will complete deletion from active systems without undue delay and propagate the instruction to relevant subprocessors. Deleted Google Cloud Storage objects may remain in restricted soft-delete storage for up to seven days. This period concerns those objects and does not describe every system’s retention.

Residual copies. Backups, disaster-recovery copies and provider security records that cannot be selectively erased immediately must be put beyond ordinary use, remain protected and be erased as soon as possible at the next applicable deletion cycle. Similia will document each applicable retention period, make those particulars available to the Customer, and ensure that any delay is necessary and proportionate. Similia will confirm deletion on request. Any legally required storage will be limited to the data and period required by law, with the reason disclosed unless legally prohibited.

Audio, images and AI. Only the content needed for the selected feature may be forwarded. Prerecorded proving audio is temporary and is removed from active storage after transcription; its deleted storage object follows the soft-delete treatment above. Saved transcripts, images and analysis outputs follow the Customer’s record instructions. Provider-side security or operational retention must be limited, disclosed and covered by the subprocessor obligations; this DPA does not authorise training or unrelated reuse and does not promise universal zero retention.

Schedule C — service providers and processing

The Customer gives general written authorisation for Similia to appoint services within the scope below under clause 6. This does not authorise an undisclosed processing chain. Before a service receives Customer Patient Data, Similia will give the Customer its contracting legal identity and contact, purpose, processing and access countries, applicable retention arrangements, and any required transfer safeguards. Similia will maintain this information for the processing chain, including onward providers, and make it readily available. Changes follow clause 6.

ServicePermitted processing
Google Firebase and Google CloudAuthentication associated with record access, database and file storage, infrastructure security, recovery and necessary support.
VercelApplication hosting, request execution and necessary service diagnostics.
OpenAI and Google AI servicesProcessing the input needed for an AI feature selected by the Customer and returning its output.
OpenRouterRouting selected AI requests to a separately disclosed model provider. Only providers covered by the required processor terms, permitted purpose and transfer safeguards may receive patient data; automatic fallback does not remove these requirements.
DeepgramTranscribing live or uploaded audio when the Customer selects the relevant feature.
Upstash and SentryThe limited caching, service-state, security or diagnostic processing necessary to operate the service, to the extent that it contains Customer Patient Data. Patient content must be minimised under Schedule B.

Use of an optional feature is an instruction for the processing necessary to provide that feature. It is not authority for additional purposes. Similia will not send Customer Patient Data to an optional AI or transcription service merely because the Customer has accepted this DPA.

Hosting, model processing and authorised support access may involve international transfers. A provider’s brand or a database location does not establish where every processing operation occurs. Similia must disclose and lawfully cover the actual locations and onward processing before the transfer, as required by clause 7.

Similia’s data-protection contact is info@similia.io. The Customer’s legal identity, address, country, authorised representative and privacy contact are recorded at acceptance. Patient details must not be included in that record.