Data Processing Agreement
Version: 7 August 2026
Who this applies to
This Data Processing Agreement (DPA) is the standard template Minikai offers to customers established in the United Kingdom, where the UK GDPR applies to the customer's processing.
Customers established in Australia or New Zealand do not need this document. Their data protection terms are in the Privacy and Health Information clause of the Terms of Service, which is governed by the laws of Victoria, Australia and applies the Privacy Act 1988 (Cth) and the Australian Privacy Principles, the Privacy Act 2020 (NZ) and the Information Privacy Principles, and the Health Information Privacy Code 2020 (NZ), as applicable to the customer.
1. Purpose and status
This DPA supplements and forms part of the customer agreement (the Agreement) between the Customer and Minikai Pty Ltd and records the terms on which Minikai processes Customer Personal Data on the Customer's behalf, as required by Article 28 of the UK GDPR.
It is completed per engagement: the parties' details and the processing particulars in Annex 1 are populated from the Order Form, and the transfer mechanisms in Annex 3 are selected where they apply. Once signed by both parties it is binding. Capitalised terms not defined here have the meaning given in the Agreement. If there is a conflict on a data protection matter, this DPA prevails over the rest of the Agreement.
2. Definitions and roles
Customer Personal Data means the Personal Information within Customer Data that Minikai processes on the Customer's behalf under the Agreement.
For Customer Personal Data, the Customer is the controller and Minikai is the processor. The Customer warrants that it has a lawful basis for the processing it instructs and, for any special category data such as health and care records, an Article 9 condition.
This DPA governs only Minikai's processing of Customer Personal Data as a processor. It does not govern Account Data or Company Data, which are separate categories defined in the Agreement and are not Customer Personal Data: Account Data (the Identity Data of Authorised Users and the Credential Data used to connect to the Customer's systems) is processed by the platform's control layer, and Company Data is de-identified operational and usage data. Those categories are governed by the Agreement and the published Privacy Policy; Credential Data in particular is used only to operate and secure the relevant connection and for no other purpose.
"Data Protection Law", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given in the applicable data protection law.
3. Scope and instructions
Minikai processes Customer Personal Data only on the Customer's documented instructions, including on transfers, unless required to do otherwise by law, in which case Minikai informs the Customer first unless the law prohibits it. The Agreement, this DPA, and the Customer's configured use of the platform are the Customer's complete documented instructions; further instructions must be agreed in writing. Minikai informs the Customer if, in its opinion, an instruction infringes Data Protection Law.
The subject matter, duration, nature and purpose of the processing, the types of Customer Personal Data, and the categories of data subjects are set out in Annex 1.
4. Restrictions on processing
Minikai does not:
- process Customer Personal Data for any purpose other than performing the Services and the Permitted Purpose;
- use Customer Personal Data to train AI models;
- sell Customer Personal Data or disclose it except as permitted by the Agreement or required by law; or
- carry out solely automated decision-making that produces legal or similarly significant effects on data subjects. Platform outputs are recommendations or drafts for a human to review and act on.
5. Processor obligations
Minikai meets the obligations of a processor under Article 28(3):
a. Instructions. Minikai processes Customer Personal Data only on the Customer's documented instructions, as set out in section 3.
b. Confidentiality. Minikai ensures that personnel authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and are trained on their data protection responsibilities.
c. Security. Minikai implements the technical and organisational measures required by Article 32, described in Annex 2.
d. Sub-processors. Minikai engages sub-processors only on the conditions in section 6.
e. Data subject rights. Taking into account the nature of the processing, Minikai assists the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise data subject rights. The platform supports this through structured export, correction, re-sync, and deletion of a person's record.
f. Controller assistance. Minikai assists the Customer in ensuring compliance with its obligations under Articles 32 to 36, taking into account the nature of processing and the information available to Minikai, including security of processing, personal data breach notification, communication to data subjects, data protection impact assessments, and prior consultation.
g. Return or deletion. On termination or expiry of the Agreement, Minikai returns or deletes Customer Personal Data as set out in section 9.
h. Audits and information. Minikai makes available to the Customer the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, as set out in section 10.
6. Sub-processors
The Customer gives Minikai general written authorisation to engage sub-processors to process Customer Personal Data. Minikai maintains the current list of sub-processors, and the countries in which they operate, at trust.minikai.com/subprocessors.
Minikai imposes on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
Minikai gives the Customer prior notice of the addition or replacement of a sub-processor and an opportunity to object. If the Customer reasonably objects on data protection grounds and the parties cannot resolve the objection, the Customer may terminate the affected Services as provided in the Agreement.
7. International transfers
Minikai processes and stores Customer Data in the Customer's Data Region. Where Minikai makes a restricted transfer of Customer Personal Data, including remote access from outside the Data Region (whether to Customer Data held on Minikai's systems or, for integration development, to the Customer's own source systems), it relies on an appropriate safeguard under Article 46:
- for United Kingdom personal data, the UK International Data Transfer Agreement.
Where United Kingdom personal data is transferred, the UK International Data Transfer Agreement (IDTA) is incorporated into this DPA by reference and executed together with it as a separate document in the same signing. The IDTA's Mandatory Clauses prevail over this DPA and the Agreement to the extent of any inconsistency on transfer matters. The categories of transferred data in the IDTA mirror Annex 1, and a change to the processing scope requires the IDTA tables to be re-agreed. The applicable mechanism for the engagement is recorded in Annex 3, and the transfer is supported by Minikai's Transfer Risk Assessment, which is completed before the safeguard is relied on and is available to the Customer on request.
8. Personal data breaches
Minikai notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay and in any event within 24 hours of becoming aware of it, and provides the information the Customer reasonably needs to meet its own obligations under Articles 33 and 34.
9. Return and deletion
On termination or expiry of the Agreement, Minikai returns or deletes Customer Personal Data in accordance with the Return and Destruction clause of the Agreement: within 30 days of the Customer's written request, Minikai returns Customer Data in a standard, machine-readable format or permanently deletes it from its active systems, except to the extent retention is required by law, for business records, or for continuity of care with consent.
10. Audits and information
Minikai makes available the information necessary to demonstrate compliance with Article 28, including its current certifications and, subject to confidentiality, summary audit reports. Minikai holds ISO/IEC 27001:2022 and ISO/IEC 42001:2023 certification.
These certifications and the information and summary reports Minikai makes available are accepted as satisfying this obligation in the first instance, and the Customer relies on them before requesting an audit.
Where, having considered that information, the Customer reasonably requires further assurance, Minikai allows for and contributes to an audit. The audit is conducted as a remote documentary review, with an on-site inspection only where the documentary review does not reasonably resolve the Customer's concern or a supervisory authority requires one; on reasonable prior notice; no more than once in any 12-month period except where required by a supervisory authority or following a personal data breach; by the Customer or an independent auditor it mandates who is not a competitor of Minikai and is bound by confidentiality; and so as to minimise disruption and protect the confidentiality and security of other customers' data. The Customer bears its own costs and Minikai's reasonable costs of any audit beyond the provision of the information and reports described above.
11. Liability and general
The liability of each party under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales in respect of it; this governing law and jurisdiction prevail over any contrary provision in the Agreement for matters arising under this DPA. All other terms of the Agreement remain in full force.
Annex 1: Details of processing
To be completed from the Order Form for each engagement.
| Field | Detail |
|---|---|
| Controller | [Customer legal name and address] |
| Processor | Minikai Pty Ltd (ABN 32 674 548 577), Australia |
| Subject matter | Provision of the Minikai platform under the Agreement. |
| Duration | The term of the Agreement, plus the return or deletion period. |
| Nature and purpose | Hosting, processing, and AI-assisted support of care and support records for the customer's stated use case, to deliver the Services for the Permitted Purpose. This includes Minikai's staff, on the Customer's documented instructions, accessing the Customer's source systems to build, configure, and maintain the integration, and remotely accessing the platform for support, quality assurance, and monitoring. |
| Types of personal data | About the people who draw on care and support: identifiers and contact details; care, support, and funding details; and health and care records (special category data). About the people delivering their care: identifiers and contact details, and workforce records such as role, qualifications and certifications, training, rostering and scheduling, and time and billing, where the Customer's configured use of the platform includes them. |
| Categories of data subjects | People who draw on care and support, and the people delivering their care. |
| Data Region | As selected by the Customer in the Order Form. |
Annex 2: Technical and organisational measures
Minikai applies measures appropriate to the risk under Article 32, and includes:
- encryption of Customer Data at rest and in transit using current industry-standard algorithms and protocols;
- role-based access control on least privilege, with multi-factor authentication for all staff accounts;
- tenant isolation between customers;
- private network endpoints for database and storage services;
- audit logging of access and processing, with security monitoring and alerting;
- pseudonymisation where appropriate;
- documented access request, onboarding, and offboarding procedures, and staff confidentiality obligations and training; and
- business continuity and disaster recovery arrangements.
Annex 3: Sub-processors and transfer mechanism
The current sub-processors and the countries in which they operate are listed at trust.minikai.com/subprocessors.
Transfer mechanism for this engagement (select where a restricted transfer applies):
- UK International Data Transfer Agreement (United Kingdom personal data)
- Not applicable: no restricted transfer for this engagement