CBT Flow

Data Processing Agreement

Version v1.0-temp · Effective 12 July 2026

Last updated 12 July 2026

Version: v1.0-temp · Last updated: 13 July 2026 · Effective: from the date this version is published at cbtflow.com/legal/dpa and accepted with the Platform Terms

This Data Processing Agreement (the DPA) forms part of the agreement under which Digita1 OÜ supplies CBT Flow to the customer identified in the applicable order or account record (the Platform Agreement). The Practice's acceptance of the Platform Terms includes acceptance of this DPA, and the accepted version is recorded and preserved with the acceptance evidence.

1. Parties and application

  1. Processor: Digita1 OÜ, Estonian registry code 17003669, VAT number EE102745881, registered office at Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia (CBT Flow, we, us).
  2. Controller: the sole practitioner, company, partnership or other practice entity identified as the customer in the Platform Agreement (the Practice, you).
  3. This DPA applies where CBT Flow processes Practice Personal Data on behalf of the Practice in providing the Platform.
  4. The Practice is normally controller of its clients' clinical records and related practice data. CBT Flow is processor of that data to the extent described in Annex 1.
  5. This DPA does not govern processing for which Digita1 OÜ determines the purposes and essential means as a controller, including defined account administration, subscription billing, platform security, fraud prevention, legal compliance, contract records and CBT Flow support administration. That processing is described in the CBT Flow Privacy Policy.
  6. Roles are determined purpose by purpose. Stripe and other recipients may act as independent or separate controllers for some purposes (for example Stripe's own identity verification, payment-network and fraud obligations); those purposes are described in the relevant privacy notice, and naming a recipient in an annex does not override the role determined by law and the actual processing.

2. Definitions and interpretation

Terms including controller, processor, data subject, personal data, personal data breach, processing, special category data and supervisory authority have the meanings given by the applicable Data Protection Law.

Data Protection Law means, in each case to the extent applicable to the processing concerned: the UK GDPR and the UK Data Protection Act 2018 (including relevant provisions of the Data (Use and Access) Act 2025); the EU General Data Protection Regulation 2016/679; the Estonian Personal Data Protection Act; and binding law implementing or replacing them.

Practice Personal Data means personal data processed by CBT Flow on the Practice's behalf under Annex 1. It excludes data for which Digita1 OÜ acts as controller.

If this DPA conflicts with the Platform Agreement on the protection of Practice Personal Data, this DPA prevails.

3. Instructions and compliance

  1. CBT Flow will process Practice Personal Data only:
    • on the Practice's documented instructions, including instructions expressed through configured use of the Platform, the Platform Agreement, this DPA and support requests;
    • to provide, secure, support and terminate the relevant Platform functions described in Annex 1; or
    • where law requires processing, in which case CBT Flow will inform the Practice before processing unless law prohibits that information.
  2. Annex 1 and the approved Platform configuration constitute the Practice's initial instructions. Instructions outside the agreed service scope may be subject to feasibility, an agreed fee and additional terms.
  3. CBT Flow will inform the Practice without undue delay if, in its opinion, an instruction infringes applicable Data Protection Law, and may pause the affected processing while the parties resolve the issue.
  4. CBT Flow will not sell Practice Personal Data, use it for advertising, or use it to train general-purpose AI models. Any future processing of clinical data by an AI provider requires a separate documented instruction, risk assessment, contractual safeguards and transparent disclosure. No autonomous treatment decision is authorised by this DPA.

4. Practice obligations

The Practice will:

  1. comply with Data Protection Law and ensure its instructions are lawful;
  2. determine and document the applicable Article 6 lawful basis and, where relevant, Article 9 condition for its processing, rather than relying on this DPA as consent;
  3. give clients and other data subjects accurate privacy information and handle their rights requests;
  4. collect only data appropriate for its clinical and practice purposes;
  5. maintain appropriate user permissions, device security and account controls;
  6. not invite anyone under 18 to the Client app while it is limited to adults; when CBT Flow enables support for clients aged 16–17, the additional eligibility, attestation and safeguarding obligations notified at that time will apply; and
  7. notify CBT Flow promptly of instructions relevant to restriction, correction, return, deletion, legal hold or a data subject request.

Nothing in this DPA transfers the Practice's clinical, professional, confidentiality or safeguarding responsibilities to CBT Flow.

5. Confidentiality and personnel

  1. CBT Flow ensures that people authorised to process Practice Personal Data are bound by confidentiality obligations and receive access only where needed for their role.
  2. CBT Flow maintains access-management procedures appropriate to the risk, including authorisation, review and removal of privileged access.
  3. CBT Flow gives relevant personnel privacy and security guidance appropriate to their role.

6. Security

  1. Taking account of the state of the art, implementation costs, the nature and risks of the processing, and the sensitivity of mental-health data, CBT Flow will implement and maintain appropriate technical and organisational measures under Article 32.
  2. The measures operating at the effective date are described in Annex 2.
  3. CBT Flow may update measures where this does not materially reduce the overall protection of Practice Personal Data.
  4. CBT Flow does not promise that authorised privileged personnel can never access Practice Personal Data. Access is instead limited, controlled and auditable.

7. Sub-processors

  1. The Practice gives general written authorisation for CBT Flow to engage the sub-processors recorded in the register at cbtflow.com/legal/subprocessors. The Practice authorises the sub-processors listed in the register version incorporated when it accepts this DPA.
  2. Before a new or replacement sub-processor begins processing Practice Personal Data, CBT Flow will give at least 30 days' notice by email to the account administrator and/or a prominent in-product notice, containing sufficient information for the Practice to assess the change. A change to the register page alone is not notice.
  3. The Practice may object during that notice period on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If no reasonable resolution is available, the Practice may discontinue the affected feature or terminate the affected service and use the return/export process in clause 12, without prejudicing accrued rights.
  4. CBT Flow will impose written data-protection obligations on each sub-processor that provide materially equivalent protection for the relevant processing, as required by law.
  5. CBT Flow remains responsible to the Practice for its sub-processors' performance to the extent required by Data Protection Law.

8. International transfers

  1. CBT Flow will not make a restricted transfer of Practice Personal Data unless the transfer is permitted by Data Protection Law.
  2. The Platform's primary database and storage are hosted in the European Economic Area (Ireland region). Transfers of UK personal data to the EEA are covered by the applicable UK adequacy regulations, and EEA-to-UK transfers by the EU adequacy decision, while those arrangements remain in force.
  3. Where a sub-processor or support arrangement involves processing in a country without an adequacy arrangement, CBT Flow uses the applicable transfer tool — the EU Standard Contractual Clauses with the correct module and, for UK transfers, the UK International Data Transfer Addendum or International Data Transfer Agreement — together with a transfer risk assessment and supplementary measures where required. The register at cbtflow.com/legal/subprocessors records the location and transfer route per sub-processor.
  4. Each onward transfer, remote-access path and recipient is assessed separately; EEA hosting does not by itself answer onward-transfer questions, and CBT Flow maintains its transfer records accordingly.

9. Data subject requests

  1. Taking account of the nature of processing, CBT Flow will provide appropriate technical and organisational assistance for the Practice to respond to requests exercising data-subject rights, through the Platform's available self-service tools and assisted support via privacy@cbtflow.com.
  2. If CBT Flow receives a request relating primarily to Practice-controlled data, CBT Flow will notify the Practice without undue delay and will not respond substantively except on the Practice's instruction or where law requires it.
  3. CBT Flow may authenticate the requester, explain its role, preserve the request, and respond directly concerning personal data for which Digita1 OÜ is controller.

10. Personal data breaches

  1. CBT Flow will notify the Practice without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Practice Personal Data.
  2. Notice will be sent to the account administrator and/or designated privacy contact and, as information becomes available, will describe:
    • the nature of the breach, affected data and approximate people/records;
    • likely consequences;
    • containment, remediation and risk-reduction measures;
    • a contact for follow-up; and
    • other information reasonably needed for the Practice's assessment and notifications.
  3. CBT Flow may provide information in phases and will reasonably cooperate with investigation, evidence preservation and legally required notifications.
  4. CBT Flow will not notify affected clients or a supervisory authority on the Practice's behalf without instruction, unless law requires it. Where Digita1 OÜ is independently controller for affected data, it retains its own notification duties. This clause does not change the Practice's own statutory notification deadlines as controller.

11. DPIAs, consultation and regulatory cooperation

Taking account of the nature of processing and information available to it, CBT Flow will reasonably assist the Practice with security obligations, data protection impact assessments, prior consultation and supervisory-authority enquiries. This includes proportionate information concerning the Platform, sub-processors and the measures in Annex 2. The Practice remains responsible for its DPIA and decisions about clinical use.

12. Return, export and deletion

  1. The Practice instructs CBT Flow, on cancellation, termination or expiry without conversion, to:
    • lock the normal workspace while preserving available billing, support and export access;
    • make Practice Personal Data available for return/export for 30 days; and
    • after that window, delete Practice Personal Data from active systems, unless a documented extension or legal hold applies.
  2. The Practice may give a different documented instruction choosing return or deletion of Practice Personal Data before the applicable deadline. If it does not, the Practice instructs CBT Flow to apply the default export-and-deletion sequence in this clause.
  3. CBT Flow will notify the Practice at the start of the window and 14, 7 and 1 day before scheduled deletion.
  4. The Practice may request one documented extension of up to 30 days, free of charge, before the initial deadline.
  5. The export covers the Practice's workspace records in usable formats and may combine self-service and assisted steps; contact support@cbtflow.com for assistance. CBT Flow does not promise a one-click export or a particular file format.
  6. After deletion, CBT Flow records an auditable deletion event and provides confirmation on request or through the account workflow.
  7. Residual backup copies are isolated from ordinary use and expire through the documented backup lifecycle, unless restoration is required for continuity; restored data remains subject to the deletion instruction.
  8. This clause does not require deletion of records that Digita1 OÜ holds as controller for tax, billing, contract acceptance, security, fraud prevention or legal claims. Those records are subject to a separate retention schedule and must not include clinical content unless retention is legally necessary.
  9. Nothing prevents preservation required by law or a documented legal hold. CBT Flow will inform the Practice where permitted.

13. Information and audits

  1. CBT Flow will make available information reasonably necessary to demonstrate compliance with this DPA, normally beginning with current policies, control summaries, questionnaires and independent reports that are available.
  2. If that information is insufficient, the Practice may conduct or commission a proportionate audit, including inspection where legally required, subject to reasonable advance notice, confidentiality, security, non-disruption and protection of other customers' data.
  3. Ordinary audits are limited to one in any 12-month period, and each party bears its own costs. This limit does not apply to an audit reasonably required by a personal data breach, a supervisory authority, or credible evidence of material non-compliance, and nothing in this clause restricts a competent supervisory authority.

14. Liability, term and general terms

  1. This DPA begins with the Platform Agreement and continues while CBT Flow processes Practice Personal Data.
  2. Contractual liability is governed by the Platform Agreement (including its separate limit for data-protection and security claims), but no contractual term limits statutory rights of a data subject or powers of a supervisory authority.
  3. Governing law and courts follow the Platform Agreement: English law and the courts of England and Wales, subject to any mandatory data-protection rules that apply regardless of the chosen law.
  4. Notices under this DPA may be sent to privacy@cbtflow.com and to the Practice's designated account/privacy contact.

Annex 1 — Processing details

ItemDescription
Subject matterProvision of CBT Flow's therapist workspace and invited Client app functions for the Practice.
DurationThe subscription/free entitlement and the 30-day return/export window (plus any documented extension), followed by deletion from active systems and expiry of backups through the documented backup lifecycle, subject to legal holds.
Nature and purposeCollection, recording, organisation, hosting, storage, retrieval, display, transmission, communication, restriction, export, support, security, backup and deletion to provide Treatment Plans, sessions, homework, outcome measures, protocols, appointments, messages, progress features, invoices/payment administration and related practice functions.
FrequencyContinuous or as initiated by authorised Practice users and invited clients during use of the Platform.
Data subjectsPractice clients (currently aged 18 or over; support for 16–17-year-olds is planned and will be introduced with updated terms); therapists and other authorised Practice users where their data forms part of the client record; emergency contacts, referrers, GPs and other people whose details the Practice lawfully records.
Personal dataNames, contact and account details; date of birth/age eligibility; identifiers; appointments; communications; therapy invoices and payment status; device/notification identifiers; files; audit metadata; and other data entered by the Practice or client.
Special category/high-risk dataMental and physical health information, therapy history, symptoms, diagnoses where recorded, Treatment Plans, session notes, homework, outcome measures (for example PHQ-9/GAD-7), safeguarding-relevant information, messages and attachments. Data may also incidentally reveal other special categories (for example sex life, sexual orientation, ethnicity or religion) where the Practice or client records it.
Processing instructionsPlatform Agreement, this DPA, configured use of the Platform, support requests and documented instructions accepted by CBT Flow.
Controller rights/obligationsAs set out in clauses 3, 4 and 9–13.
Return/deletionClause 12.

Digita1 OÜ controller records

The following are not Practice Personal Data merely because they relate to a Practice or transaction: CBT Flow account administration, SaaS billing/tax records, contract acceptance, platform-wide security/fraud records, legal claims, direct support administration and payment-facilitation records used for CBT Flow's own compliance. That processing is described in the CBT Flow Privacy Policy, and clinical content is minimised in those records.

Annex 2 — Technical and organisational measures

Control areaMeasures
GovernanceA named internal Privacy Lead (Paulius Alionis), security ownership, and supplier review through the sub-processor register and change-notice process.
Identity and accessUnique user accounts; role-based access with least privilege; privileged and support access limited to defined roles, controlled and auditable; access removed when no longer needed.
Workspace separationApplication and database authorisation controls that separate each Practice's workspace from other customers' data.
EncryptionTLS encryption in transit; provider-managed encryption at rest for the primary database and storage.
Logging and monitoringSecurity-relevant access and change events are logged proportionately to risk and available for incident investigation.
Backups and resilienceRegular backups, isolated from ordinary use, with expiry through the documented backup lifecycle; hosting on established EEA cloud infrastructure (see clause 8).
Secure developmentSeparated development and production environments; change review; dependency and secret management.
Incident managementA defined incident process covering detection, triage, containment, investigation and the customer notification commitment in clause 10.
Data minimisationNo clinical or sensitive content in public analytics or advertising; notification content designed to limit exposure of sensitive detail; support access limited to what the case needs.
Deletion and portabilityThe 30-day return/export window, scheduled deletion from active systems, backup expiry and deletion confirmation described in clause 12.

Annex 3 — Sub-processors and transfers

The current authorised sub-processor register, including each provider's legal entity, service, data, location and transfer route, is published at cbtflow.com/legal/subprocessors and is incorporated into this DPA. Changes follow the notice and objection process in clause 7.

Annex 4 — Contacts and DPA administration

ItemDetail
ProcessorDigita1 OÜ, registry code 17003669
AddressSepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Privacy contactprivacy@cbtflow.com
Security contactsecurity@cbtflow.com
DPONo statutory DPO is required or appointed.
Internal Privacy LeadPaulius Alionis (via privacy@cbtflow.com)
UK Article 27 representativeAppointment in progress; details will be published in the CBT Flow Privacy Policy once confirmed.
Practice controller contactAs specified in the account/order and privacy settings.
Sub-processor change noticeAt least 30 days, by email to the account administrator and/or prominent in-product notice.