top of page

Data Processing Schedule

 

Last updated: 1 July 2026

 

1. About these terms

 

These Data Processing Terms form part of the Client Framework Terms between nuaxia Limited and the Client.

 

They apply only where nuaxia processes Client Personal Data:

  • as a processor on behalf of the Client or an End Client; or

  • as a subprocessor where the Client is itself acting as a processor.

 

These terms apply automatically to that processing unless the parties expressly agree different data-processing terms in writing.

 

2. When nuaxia acts as a controller

 

nuaxia ordinarily acts as an independent controller where it determines why personal data is collected or used and the essential means of that processing.

 

This may include processing connected with:

  • maintaining and developing nuaxia’s own healthcare professional, healthcare organisation and other professional databases;

  • verifying professional identity, qualifications, roles, workplaces and eligibility;

  • maintaining Participant profiles and relationship histories;

  • identifying and deciding whom to invite to surveys, educational activities and other engagements;

  • managing communications and relationships with Participants;

  • administering Participant accounts and honoraria;

  • preventing fraud, duplication, misuse and security incidents;

  • maintaining quality, compliance and business records;

  • managing nuaxia’s own website, alerts, applications and services; and

  • meeting nuaxia’s own legal, regulatory, pharmacovigilance and professional obligations.

 

Personal data processed by nuaxia as an independent controller is governed by nuaxia’s Privacy Notice and applicable Data Protection Laws, not by these Data Processing Terms.

 

The fact that nuaxia holds or processes information in connection with a Client project does not by itself determine whether nuaxia is a controller or processor. Each processing activity will be assessed according to the parties’ actual roles.

 

3. When nuaxia acts as a processor

 

nuaxia acts as a processor or subprocessor only where it processes personal data on behalf of, and under the documented instructions of, the Client or an End Client.

 

This may arise, for example, where:

  • the Client supplies a contact list for use solely in the Client’s project;

  • nuaxia hosts or processes identifiable data controlled by the Client;

  • the Client supplies identifiable data for analysis, validation or reporting;

  • nuaxia processes Client or End Client personnel information to provide a Client-specific service; or

  • an agency appoints nuaxia as a subprocessor on behalf of an End Client.

 

Where nuaxia acts as a processor for one activity and as an independent controller for another, these terms apply only to the processor activity.

 

4. Definitions

 

In these terms:

  • Client Personal Data means personal data processed by nuaxia as a processor or subprocessor under the Contract.

  • It does not include personal data for which nuaxia acts as an independent controller.

  • Data Protection Laws means all data-protection and privacy laws applicable to the relevant processing, including the UK GDPR, the Data Protection Act 2018 as amended, the EU GDPR where applicable and any legislation replacing or supplementing them.

  • Personal Data Breach means a breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Client Personal Data.

  • Subprocessor means another organisation appointed by nuaxia to process Client Personal Data.

  • The terms controller, processor, personal data, processing, Data Subject and special category data have the meanings given to them under applicable Data Protection Laws.

  • Other capitalised terms have the meanings given in the Client Framework Terms.

5. Default description of the processing

 

Unless the Proposal expressly states otherwise, the following description applies whenever nuaxia processes Client Personal Data as a processor or subprocessor.

 

5.1 Subject matter

The subject matter of the processing is the provision of the Services described in the Proposal where those Services involve Client Personal Data.

 

5.2 Duration

 

The processing will continue for:

  • the duration of the relevant Services;

  • any period reasonably required to complete the Services;

  • any agreed retention period; and

  • the time reasonably required to return, delete or securely remove the Client Personal Data from routine backup systems.

 

5.3 Nature of the processing

 

The processing may include:

  • receiving and collecting;

  • recording and organising;

  • storing and accessing;

  • reviewing and validating;

  • adapting and structuring;

  • analysing and reporting;

  • transmitting and making available to authorised recipients;

  • restricting and securing;

  • returning; and

  • deleting or anonymising Client Personal Data.

 

nuaxia will carry out only those processing operations reasonably required to provide the Services and comply with the Client’s documented instructions.

 

5.4 Purpose

 

The purpose of the processing is to provide the Services described in the Proposal and to comply with lawful documented instructions concerning those Services.

5.5 Types of personal data

 

Client Personal Data may include:

  • names and contact details;

  • employment and professional information;

  • job titles, roles, qualifications and organisational affiliations;

  • professional identifiers;

  • survey, interview, research or consultation information;

  • account, portal and service-use information;

  • correspondence and project-administration information; and

  • other personal data supplied by or on behalf of the Client for the agreed Services.

 

nuaxia will not process special category data or criminal-offence data as a processor unless that processing is expressly agreed in the Proposal or other documented instructions.

 

5.6 Categories of Data Subject

 

The individuals concerned may include:

  • Client and End Client employees and representatives;

  • professional contacts identified or supplied by the Client;

  • customers, suppliers, advisers or contractors of the Client or End Client;

  • survey, research or interview respondents whose information is supplied or controlled by the Client; and

  • other individuals identified in Client Materials.

 

5.7 Variations

 

The Proposal or other agreed written project instructions may supplement or vary this default description where the Services involve different or additional processing.

 

If no variation is recorded, the default description in this clause applies.

 

6. Client responsibilities and rights

 

The Client is responsible for ensuring that:

  • it, or the relevant End Client, is entitled to act as controller of the Client Personal Data;

  • the processing has a lawful basis;

  • any required condition for processing special category or criminal-offence data is satisfied;

  • all required privacy information has been provided;

  • the Client Personal Data has been collected and disclosed lawfully;

  • its instructions comply with Data Protection Laws;

  • the Client Personal Data is adequate, relevant and limited to what is reasonably necessary;

  • the Client Personal Data is reasonably accurate and current; and

  • it is authorised to issue instructions on behalf of any End Client.

 

The Client has the right to:

  • issue lawful documented instructions concerning the processing;

  • receive reasonable information demonstrating nuaxia’s compliance with these terms;

  • require the return or deletion of Client Personal Data when the relevant Services end; and

  • exercise the audit rights set out below.

 

Where the Client is acting for an End Client, the Client confirms that:

  • it has authority to appoint nuaxia;

  • any necessary approval to appoint nuaxia as a subprocessor has been obtained;

  • it is authorised to issue instructions on the End Client’s behalf; and

  • it will communicate the End Client’s instructions accurately.

 

The Client must not instruct nuaxia to process personal data in a manner that would breach Data Protection Laws.

 

7. Processing instructions

 

nuaxia will process Client Personal Data only:

  • on the Client’s documented instructions;

  • as reasonably necessary to provide the Services;

  • as permitted by the Contract; or

  • where required by applicable law.

 

Documented instructions may be contained in:

  • the Client Framework Terms;

  • these Data Processing Terms;

  • the Proposal;

  • approved project materials;

  • an agreed change request; or

  • written communications from an authorised Client representative.

 

If nuaxia reasonably believes that an instruction infringes Data Protection Laws, nuaxia will notify the Client and may suspend the affected processing until the instruction is clarified, amended or withdrawn.

 

If applicable law requires nuaxia to process Client Personal Data other than on the Client’s instructions, nuaxia will inform the Client before doing so unless the law prohibits that notification.

 

8. Confidentiality and access

 

nuaxia will ensure that people authorised to process Client Personal Data:

  • are subject to appropriate confidentiality obligations;

  • receive access only where reasonably required for their role;

  • process the information only for the agreed Services and in accordance with authorised instructions; and

  • receive appropriate data-protection and security training.

 

nuaxia will remove or amend access when it is no longer required.

 

These confidentiality obligations continue after the relevant individual ceases working on the Services.

 

9. Security

 

nuaxia will maintain appropriate technical and organisational measures to protect Client Personal Data, taking account of:

  • the nature, scope, context and purposes of the processing;

  • the state of available technology;

  • implementation costs; and

  • the likelihood and severity of risks to individuals.

 

The measures may include, where appropriate:

  • confidentiality requirements and staff training;

  • individual accounts and role-based access controls;

  • password controls and multi-factor authentication;

  • secure transmission and storage;

  • encryption where appropriate;

  • system, network and endpoint protection;

  • security updates and vulnerability management;

  • backup and recovery arrangements;

  • incident-detection and response procedures;

  • logical separation of projects and data;

  • secure deletion and disposal; and

  • appropriate controls over Subprocessors.

 

nuaxia may update its security measures where the change does not materially reduce the overall level of protection.

 

The Client will:

  • keep its accounts and credentials secure;

  • restrict access to authorised personnel;

  • notify nuaxia promptly of suspected unauthorised access;

  • use agreed secure methods to transmit Client Personal Data; and

  • comply with reasonable security instructions relating to the Services.

 

10. Subprocessors

 

The Client gives nuaxia general written authorisation to appoint Subprocessors where reasonably required to provide the Services.

 

nuaxia will:

  • make information about material Subprocessors processing Client Personal Data available to the Client on request or through a maintained online list;

  • give reasonable prior notice of a material new or replacement Subprocessor;

  • enter into written terms requiring the Subprocessor to provide data-protection safeguards materially equivalent to the relevant requirements of these terms; and

  • remain responsible for the Subprocessor’s performance of those obligations to the extent required by Data Protection Laws.

 

The Client may object to a proposed Subprocessor on reasonable grounds specifically relating to the protection of Client Personal Data.

 

The Client must raise an objection promptly after receiving notice and explain its grounds.

 

The parties will work in good faith to address a valid objection. If no reasonable solution is available, either party may terminate the affected part of the Services.

 

nuaxia may make an urgent Subprocessor change where reasonably necessary to address a security incident, supplier failure, legal requirement or other material operational risk. nuaxia will notify the Client as soon as reasonably practicable.

 

11. International transfers

 

nuaxia will not make a restricted international transfer of Client Personal Data unless a lawful transfer mechanism or exception applies.

 

Where required, nuaxia will use appropriate safeguards, which may include:

  • applicable adequacy regulations or decisions;

  • approved standard contractual clauses;

  • an approved UK international-transfer agreement or addendum;

  • binding corporate rules; or

  • another lawful transfer mechanism.

 

nuaxia will require relevant Subprocessors to comply with applicable international-transfer requirements.

 

Unless the Proposal expressly states otherwise, the Services do not guarantee that all Client Personal Data will remain in a particular country.

 

12. Data Subject requests

 

If nuaxia receives a request from a Data Subject relating to Client Personal Data, nuaxia will:

  • notify the Client without undue delay;

  • provide available relevant details; and

  • not respond substantively unless instructed by the Client or required by law.

 

The Client remains responsible for:

  • verifying the requester’s identity;

  • determining whether the request is valid;

  • deciding how to respond; and

  • meeting the applicable legal deadline.

 

Taking account of the nature of the processing, nuaxia will provide reasonable assistance to enable the Client or End Client to respond to the request.

 

13. Compliance assistance

 

Taking account of the nature of the processing and the information available to it, nuaxia will provide reasonable assistance with the Client’s obligations relating to:

  • security of processing;

  • Data Subject rights;

  • Personal Data Breaches;

  • data-protection impact assessments;

  • consultations with a data-protection authority; and

  • demonstrating compliance with Data Protection Laws.

 

The Client must provide reasonable notice and sufficient information when requesting assistance.

 

nuaxia may charge reasonable additional Fees where a request:

  • is unusually extensive;

  • falls outside the ordinary scope of the Services;

  • requires material technical development or retrieval work; or

  • results from incomplete, inaccurate or changed Client instructions.

 

nuaxia will notify the Client of material additional charges before incurring them where reasonably practicable.

 

14. Personal Data Breaches

nuaxia will notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data.

 

To the extent available, nuaxia will provide information about:

  • the nature of the breach;

  • the categories of Client Personal Data affected;

  • the categories and approximate number of affected individuals and records;

  • the likely consequences;

  • measures taken or proposed to contain, investigate and address the breach; and

  • an appropriate contact for further information.

 

Where all information is not immediately available, nuaxia may provide it in stages as the investigation progresses.

 

nuaxia will:

  • take reasonable steps to contain and investigate the breach;

  • take reasonable steps to mitigate possible adverse effects;

  • preserve relevant information; and

  • provide reasonable cooperation with the Client’s assessment and notification obligations.

 

The Client or relevant End Client is responsible for determining whether notification must be made to:

  • a data-protection authority;

  • affected Data Subjects;

  • another regulator;

  • a project sponsor; or

  • another third party.

 

nuaxia will not make a notification identifying the Client or End Client unless:

  • instructed by the Client;

  • agreed between the parties; or

  • required by law.

 

A breach notification does not constitute an admission of liability.

 

15. Compliance information and audits

 

On reasonable request, nuaxia will provide information reasonably necessary to demonstrate compliance with these terms.

 

This may include:

  • relevant security information;

  • completed security questionnaires;

  • policy summaries;

  • Subprocessor information;

  • available independent assurance reports; and

  • reasonable written responses to compliance questions.

 

Where that information is reasonably insufficient, the Client may audit nuaxia’s compliance with these terms.

 

Unless an audit is required following a material breach or by a competent regulator:

  • the Client must provide reasonable prior written notice;

  • no more than one audit may be conducted in any 12-month period;

  • the audit must take place during normal business hours;

  • it must be limited to processing covered by these terms;

  • it must minimise disruption to nuaxia’s operations; and

  • it must be conducted by an appropriately qualified person subject to confidentiality obligations.

 

An auditor must not be a direct competitor of nuaxia without nuaxia’s prior written agreement.

 

An audit must not expose:

  • another customer’s personal data or confidential information;

  • nuaxia source code;

  • legally privileged material;

  • security credentials; or

  • detailed information that would create a material security vulnerability.

 

The Client will bear its own audit costs and nuaxia’s reasonable costs of supporting an unusually extensive audit. nuaxia will bear its own reasonable costs where the audit identifies a material breach of these terms by nuaxia.

 

Nothing in this clause restricts the powers of a competent data-protection authority.

 

16. Return and deletion

 

When the relevant Services end, nuaxia will, at the Client’s written choice:

  • return the Client Personal Data;

  • delete it; or

  • return part and delete the remainder,

unless applicable law requires continued retention.

 

The Client must provide its return or deletion instructions within 30 days after completion or termination of the relevant Services.

 

If the Client does not provide instructions within that period, nuaxia may delete the Client Personal Data in accordance with its ordinary retention and deletion procedures.

 

Client Personal Data contained in secure backups may remain until deleted or overwritten through the ordinary backup cycle, provided that it:

  • remains appropriately protected;

  • is not used for another purpose; and

  • is restored only where reasonably necessary for disaster recovery, security or legal purposes.

 

This clause does not require nuaxia to delete:

  • personal data for which nuaxia acts as an independent controller;

  • information required to be retained by law;

  • irreversibly anonymised information;

  • statistical information that no longer identifies an individual, Client or End Client; or

  • information that the Contract separately permits nuaxia to retain.

 

17. Relationship with the Client Framework Terms

 

Liability arising under these Data Processing Terms is governed by the liability provisions in the Client Framework Terms.

 

Nothing in these terms limits liability where it cannot lawfully be limited.

 

If there is a conflict concerning Client Personal Data, the following order of priority applies:

  1. a mandatory international-transfer agreement or instrument;

  2. any data-processing terms expressly signed by both parties for the relevant Services;

  3. these Data Processing Terms;

  4. the applicable Proposal; and

  5. the Client Framework Terms.

 

18. Duration

 

These Data Processing Terms apply for as long as nuaxia processes Client Personal Data as a processor or subprocessor under the Contract.

 

The provisions concerning confidentiality, security, return and deletion, audits and liability continue for as long as nuaxia retains the relevant Client Personal Data.

bottom of page