DATA PROCESSING AGREEMENT (DPA)
Between: Your Care Home (Data Controller)
And: MAAP Limited (Data Processor)
1. DEFINITIONS
Controller: Your care home (you decide what data to process and why)
Processor: MAAP Limited (we process data on your instructions)
Personal Data: Staff names, emails, login activity, resident names, photos, likes, dislikes
Processing: Storing, using, managing, and securing data via the apps
2. SCOPE OF PROCESSING
MAAP Limited processes data for:
- Staff account management and authentication
- Meal planning service delivery
- Activity planning service delivery
- Resident activity personalization and preferences
- Service security and fraud prevention
3. YOUR INSTRUCTIONS
You (the Controller) instruct MAAP to:
- Store staff and resident data securely
- Process data only for stated purposes
- Delete staff data within 30 days of account termination or access revocation
- Delete resident data within 30 days of resident leaving your care home
- Retain resident data 90 days after death, then auto-delete
- Never share resident data with other care homes
- Comply with UK GDPR and data protection law
MAAP processes data ONLY on your documented instructions.
4. SECURITY MEASURES
MAAP will:
- Encrypt all data in transit (HTTPS)
- Encrypt all data at rest (AES-256)
- Hash all passwords securely (bcrypt)
- Maintain strict access controls and role-based permissions
- Conduct regular security audits and penetration testing
- Maintain automated daily backups
- Store data in secure EU data center (France)
- Notify you of breaches within 72 hours
5. SUB-PROCESSORS
MAAP uses:
- Supabase (database provider, France, EU) – DPA at https://supabase.com/legal
- Netlify (hosting, US-based) – for static assets only
You authorize these sub-processors.
If we add new sub-processors, we will notify you 30 days in advance.
You may object to new sub-processors.
6. DATA SUBJECT RIGHTS
You must:
- Inform staff about data processing
- Handle data subject rights requests (access, deletion, etc.)
- Forward requests to MAAP if needed
- Obtain proper consent for resident data
MAAP will:
- Respond to data subject rights requests within 30 days
- Assist with Subject Access Requests (SARs)
- Provide data in portable format on request
7. DATA RETENTION & DELETION
7.1 Staff Data
Retention: 30 days after account termination or access revocation
Automatic deletion: On Day 30
Legal basis: GDPR Article 5(1)(e) - Storage Limitation Principle
Exception: If active legal claim, retain for 3 years from claim end
Why 30 days? Once access revoked, purpose is served. GDPR requires deletion of unnecessary data.
7.2 Resident Data - Living Resident (In Your Care)
Retention: While resident is in your care home
You can delete resident profiles anytime
Data includes: Name, photo, likes, dislikes, activity preferences
Data does NOT include: Medical information, health data, care plans
7.3 Resident Data - When Resident Moves to Another Care Home
Retention: Maximum 30 days after resident leaves your care home
Auto-deletion: On Day 30 of resident no longer being in your care
Legal basis: GDPR Article 5 (Storage Limitation Principle)
No exceptions: We automatically delete resident data after 30 days. Your care home must notify us when resident leaves.
7.4 Resident Data - When Resident Passes Away
Retention: 90 days from date of resident death
Auto-deletion: Permanent on Day 97
Backup removal: Days 98-120 (removed from backup archives)
Legal basis: Vital Interests (UK Data Protection Act 2018 Schedule 1)
Timeline:
- Day 0: Care home notifies us of resident death
- Days 1-90: Profile accessible for staff handover and family inquiries
- Day 90: Deletion notification sent to care home
- Day 97: All resident data permanently deleted
- Days 98-120: Removed from backups
Extension: If CQC investigation or legal hold is ongoing, you can request extension beyond 90 days. Contact dpo@happyday.care
7.5 Backups
Retention: 90 days (disaster recovery)
After 90 days: No recovery possible
8. DATA TRANSFER & LOCATION
All data is stored in France (Supabase, EU)
No transfers outside the European Economic Area
All processing complies with UK GDPR
9. AUDIT & INSPECTION RIGHTS
You may request:
- Documentation of security measures
- Audit reports (subject to confidentiality)
- Evidence of compliance
- Inspection of processing activities
MAAP will respond within 30 days.
10. LIABILITY
MAAP is liable for:
- Data breaches caused by our negligence
- Unauthorized disclosure of your data
- Failure to delete data on request
MAAP is NOT liable for:
- Breaches caused by your instructions or actions
- Data you incorrectly entered into the app
- Third-party breaches beyond our control
- Indirect or consequential damages
11. YOUR RESPONSIBILITIES
You confirm:
- You have obtained consent for storing resident data (photos, preferences)
- You have authority to bind your care home
- Data entered is accurate and lawfully obtained
- You will handle staff credentials securely
- You will not export resident data
- You will notify us within 24 hours of resident death
- You will notify us within 7 days of resident moving to another care home
- You will not share resident data externally
12. DATA BREACH RESPONSE
In case of breach:
- MAAP will notify you within 72 hours
- We will provide details of affected data
- We will advise on protective steps
- We will report to ICO as required
13. TERM & TERMINATION
This DPA is effective when you sign up.
Upon termination:
- Staff data deleted within 30 days
- Living resident data deleted within 30 days
- Deceased resident data retained per 90-day post-death schedule
- Backups deleted per retention schedule
14. GOVERNING LAW
This DPA is governed by English law and UK GDPR.
15. CONTACT
MAAP Limited
Email: dpo@happyday.care
Website: happyday.care
Response time: 5 working days
16. ACCEPTANCE
By signing up for the apps, your care home agrees to this DPA.
You confirm you are authorized to bind your care home.
APPENDIX A: PROCESSING DETAILS
Item | Detail |
Subject Matter | Staff account management; Meal planning; Activity planning; Resident activity personalization |
Duration | Staff: 30 days after termination. Living resident: While active. Deceased resident: 90 days post-death |
Nature | Storage, display, organization, deletion |
Purpose | Delivery of meal and activity planning services for care homes |
Data Types | Staff: email, name, login logs. Residents: names, photos, likes, dislikes, activity preferences |
Data Categories | Care home employees; Residents in care |
Recipients | MAAP Limited staff only; Never shared with other care homes |
Data Location | Supabase (France, EU) |
Deletion Rights | Staff: 30 days after access revoked. Living residents: Anytime. After move: 30 days. After death: 90 days |
© MAAP Limited. All rights reserved.
Last updated: 18 May 2026