Parties and formation
The client organisation is the controller and DBX ONE is the processor for the agreed processing. The DPA forms when an authorised representative accepts it through the upload, implementation or continuation route.
Data Processing Agreement
This DPA covers the agreed INSIGHTS, STOCKROOM and supplier-document processing where DBX ONE acts as processor on the client's documented instructions.
Last updated: 23 August 2026
The client organisation is the controller and DBX ONE is the processor for the agreed processing. The DPA forms when an authorised representative accepts it through the upload, implementation or continuation route.
Receiving, storing, extracting, normalising, checking and presenting supplier invoices, credit notes and supporting business documents; where STOCKROOM is agreed, processing configured stock lists, room or cupboard names, pack sizes, replenishment levels, delivery confirmations, stock-round records and supplier discrepancies; and generating agreed management, exception, reporting or draft-import outputs.
For a free trial, processing lasts during preparation, delivery and the stated decision-retention period unless deletion is requested earlier. For a paid service, processing continues for the contract and agreed retention or return period.
Business contact details may appear for practice staff, supplier staff, couriers or advisers. Supplier documents, internal accounting structures, stock lists, room labels, supplier mappings and replenishment records may be confidential business information. Patient records, clinical data, payroll employee files, personal tax records, pension records and credentials are prohibited unless separately agreed under a different documented scope.
DBX ONE processes data only for the agreed service, documented support, security, deletion or legal requirements. If an instruction appears unlawful or outside scope, DBX ONE may suspend that step and seek clarification.
Access is limited to authorised persons and providers used for the service. Appropriate technical and organisational measures include private storage, protected delivery, access controls, validation, audit trail, purpose limitation and incident handling proportionate to the risk.
The controller gives general written authorisation for contracted providers used for hosting, storage, business email and payments as listed in the Confidentiality page. DBX ONE will apply appropriate contractual/data-protection obligations where applicable and notify material changes as required.
OpenAI's consumer ChatGPT service is disclosed separately because the current workflow may send original supplier files to an individual consumer account under OpenAI consumer terms rather than under an OpenAI business data-processing agreement.
Where AI assistance is used in the current supplier-document workflow, DBX ONE uses an individual ChatGPT consumer account rather than ChatGPT Business, Enterprise or the OpenAI API. Original supplier files may be uploaded directly to that account and may contain business contact details, supplier details, postal addresses, signatures, invoice/account references, bank details and other personal or confidential commercial information printed on the documents. Patient records, clinical documents, prescription data and unrelated special-category information must not be submitted.
DBX ONE keeps “Improve the model for everyone” switched off before client material is uploaded. OpenAI states that new consumer conversations are not used to train its models when this setting is off. This setting controls model-improvement use; ordinary chats remain in account history until deleted.
A separate conversation is used for each client, public shared links are not created, client material is not reused for another client, and DBX ONE does not provide thumbs-up/down feedback on conversations containing client material. For a free run, the client conversation follows the same decision-retention lifecycle as the DBX ONE submission. For an active paid service, relevant client conversations may be retained while needed for corrections or later periods. When deletion is required, DBX ONE deletes the conversation and any corresponding client file retained separately in ChatGPT Library where applicable. OpenAI then applies its published deletion process, including its stated legal/security exceptions.
The controller expressly instructs and authorises this disclosed consumer-service workflow when its authorised representative accepts the Terms and this DPA during submission. DBX ONE will not represent a future OpenAI API, Business or Enterprise workflow as active until the applicable production configuration, contractual terms and disclosures have been updated before live processing.
Taking account of the nature of processing, DBX ONE will reasonably assist the controller with data-subject requests, security information, breach response, DPIA information and regulator enquiries as required by law and the contract.
DBX ONE will notify the controller without undue delay after becoming aware of a personal-data breach affecting the service and provide available information needed for the controller's assessment and reporting duties.
At the end of processing, DBX ONE will delete or return personal data as agreed, except where law requires retention. Provider deletion may follow documented technical cycles. ChatGPT conversations and any separately retained Library files used for client processing follow the client lifecycle described in section 7.
DBX ONE will make available information reasonably necessary to demonstrate compliance with processor obligations and permit proportionate audits subject to confidentiality, security and reasonable notice.
The client confirms lawful authority, data minimisation, appropriate instructions, staff access controls and competent review of accounting or operational outputs. The client decides whether a DPIA, ROPA update or internal information-governance approval is required.
The Terms, Paid Service Schedule, Privacy Notice and this DPA should be read together. Data-protection obligations prevail where required by law. England and Wales law applies unless mandatory law requires otherwise.