Data Processing Agreement

Effective date: 22 July 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Customer”, the data controller) and Aku Online Limited trading as DoulaOne (“DoulaOne”, “we”, the data processor). It governs our processing of personal data on your behalf under the EU General Data Protection Regulation (GDPR) and the UK GDPR (together, “Data Protection Law”). By using DoulaOne to process personal data about your clients, you agree to this DPA.

1. Roles of the parties

For personal data you enter about your clients and their families (“Customer Personal Data”), you are the controller and DoulaOne is the processor. Where you act as a processor for someone else, DoulaOne acts as a sub-processor. DoulaOne is an independent controller for your own account data, as described in our Privacy Policy.

2. Scope and instructions (Art. 28(3)(a))

We process Customer Personal Data only on your documented instructions, including as set out in this DPA and the Terms, unless required to do otherwise by law (in which case we will inform you where legally permitted). Your use of the platform's features constitutes your instructions for processing.

You warrant and undertake that: (a) you have identified, and will maintain, an appropriate lawful basis under Data Protection Law for the processing of Customer Personal Data (and, for special category data such as health and pregnancy information, a valid condition under Art. 9); (b) where you act on behalf of another controller, you have confirmed that an appropriate lawful basis exists before instructing us to process the data; and (c) your instructions to us will not cause either party to breach Data Protection Law. You are also responsible for providing appropriate privacy notices to your clients and for obtaining any consents required for your processing.

3. Subject matter and details of processing (Art. 28(3))

  • Subject matter: provision of the DoulaOne practice-management platform.
  • Duration: for the term of your account, plus any limited retention described in Section 9.
  • Nature and purpose: storage, organisation, display, transmission, and deletion of Customer Personal Data to operate the Service.
  • Types of data: contact details, due dates, appointments, care and clinical notes, birth preferences, contracts and e-signatures (including signer IP address and browser/user-agent captured for signature audit), intake responses, invoices and payment records (including references from our payment processor where online payment is enabled), messages, and uploaded documents, and any other information uploaded, submitted, or otherwise provided by you or your clients through the platform.
  • Categories of data subjects: your clients, their partners, family members, and emergency contacts.
  • Special categories: health-related and other sensitive data you choose to store.

4. Confidentiality (Art. 28(3)(b))

We ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and access data only as needed to provide and support the Service.

5. Security measures (Art. 28(3)(c), Art. 32)

We implement appropriate technical and organisational measures, including:

  • Row-level security isolating each workspace's data
  • Private, access-controlled file storage with signed URLs
  • Encryption in transit (HTTPS/TLS)
  • Server-side authentication and access controls
  • Restricted access to production systems and secrets

6. Sub-processors (Art. 28(2), (4))

You grant general authorisation for us to engage the sub-processors below to provide the Service. Each is bound by data-protection terms no less protective than this DPA.

  • Supabase — database, authentication, and file storage (EU, Paris region)
  • Vercel — application and website hosting
  • Brevo — transactional and (where recipients opt in) marketing email delivery
  • Stripe — payment processing, where you enable online client payments (only if you connect it)
  • Mapbox — map display on public directory pages
  • NHS Website Content API — health content for the resources library (UK workspaces)
  • Google — optional Sign-in and Calendar / Meet integration (only if you connect it)
  • Zoom — optional meeting links for appointments (only if you connect it)
  • Calendly — optional booking import (only if you connect it)
  • OpenAI — optional AI assists (only if you enable them)

We will give notice of any intended addition or replacement of a sub-processor by updating this page and, where you have subscribed to notices, by email. You may object on reasonable data-protection grounds by contacting contact@doulaone.com; if we cannot accommodate your objection, you may stop using the affected feature or terminate.

7. Assistance to the controller (Art. 28(3)(e), (f))

Taking into account the nature of the processing, we will assist you with:

  • Responding to data subject requests (access, rectification, erasure, portability, restriction, and objection), including through in-app export and deletion tools and by support where needed
  • Meeting your obligations on security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities

8. Personal data breaches (Art. 33)

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably available to help you meet your own notification obligations. Notice of a breach is not an acknowledgement of fault or liability.

9. Return and deletion (Art. 28(3)(g))

You can export and delete Customer Personal Data through the platform at any time. On termination of your account, we will delete or return Customer Personal Data within a reasonable period, except where retention is required by law. Backups are deleted on our routine backup-expiry cycle.

We may create and retain aggregated or anonymised data that no longer identifies any individual (for example, statistical or performance insights), and may continue to use such data after termination to operate and improve the Service. This data is not Customer Personal Data.

10. Audits (Art. 28(3)(h))

We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior request and subject to confidentiality, respond to your audit enquiries. Where available, third-party certifications or reports from our sub-processors may be used to satisfy audit requests.

11. International transfers (Chapter V)

Customer Personal Data is primarily stored in the European Union (Supabase, Paris). Where a sub-processor processes data outside the UK or EEA in a country that is not covered by a UK or EU adequacy decision (for example, in the United States), we rely on appropriate safeguards such as the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, or an adequacy mechanism such as the UK Extension to the EU-US Data Privacy Framework where the recipient is certified. We carry out a transfer risk assessment before relying on the Standard Contractual Clauses or Addendum.

You can request a copy of the safeguards we rely on for a particular transfer by contacting contact@doulaone.com.

12. Changes to this DPA

We may update this DPA from time to time to reflect changes in the Service, our sub-processors, or legal requirements. We will post the revised version on this page and update the effective date, and for material changes will provide notice through the Service or by email where appropriate.

13. Liability and precedence

This DPA is subject to the limitations and exclusions of liability set out in the Terms. If there is a conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA prevails.

14. Contact

For data-protection enquiries, sub-processor objections, or to request a signed copy of this DPA:

contact@doulaone.com

See also our Privacy Policy and Terms of Service.