Data Processing
How Verityn Ltd processes personal data on behalf of institutional customers. These terms form part of the Data Processing Agreement under Article 28 UK GDPR.
Last updated: 1 October 2025
1
Scope and purpose
This page sets out the data processing terms that apply when Verityn Ltd processes personal data on behalf of an institutional Customer (a clinical organisation, hospital trust, or other healthcare provider). These terms form part of the agreement between the Customer and Verityn Ltd and supplement the Terms of Service.
For individual practitioner accounts on the Pilot plan, the Privacy Policy governs the processing of personal data. This document applies where a formal Data Processing Agreement is required, typically for NHS trusts and other institutional purchasers.
To receive a signed Data Processing Agreement as a separate document, contact hello@verityn.ai.
2
Roles of the parties
Where the Customer submits medical imaging Studies and associated metadata to the Verityn platform for second-read processing:
- The Customer is the data controller: it determines the purposes for which patient data is collected and the lawful basis for processing.
- Verityn Ltd is the data processor: it processes personal data only on the documented instructions of the Customer, as set out in this Agreement and the Instructions for Use.
- For the purposes of Article 28 UK GDPR, this document constitutes the written contract between controller and processor.
3
Subject matter, nature, and purpose of processing
- Subject matter: medical imaging data (DICOM studies) and associated clinical metadata submitted by the Customer for second-read processing.
- Nature of processing: automated computer vision analysis, generation of confidence-weighted flags and heatmaps, and return of outputs to the Customer. Outputs are clinical decision support, not diagnoses.
- Purpose: to provide the Verityn second-reader service as described in the Instructions for Use.
- Duration: for the subscription term and any applicable retention period set out in section 8 of this document.
- Types of personal data: imaging data that may constitute special category health data. The Customer is responsible for confirming that de-identification has been applied before upload.
- Categories of data subjects: patients whose imaging studies are submitted by the Customer.
4
Processor obligations
Verityn Ltd agrees, in its capacity as data processor, to:
- Process personal data only on documented instructions from the Customer, unless required by law to act otherwise, in which case we will notify the Customer before processing unless prohibited from doing so.
- Ensure that persons authorised to process personal data are bound by appropriate confidentiality obligations.
- Implement and maintain the technical and organisational security measures described in section 6 of this document.
- Assist the Customer in responding to requests from data subjects exercising their rights under the UK GDPR, to the extent that it is possible for us to do so given the nature of the processing.
- Assist the Customer in meeting its obligations under Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessments, and prior consultation with the ICO).
- Delete or return all personal data at the end of the provision of services, and delete existing copies unless applicable law requires retention.
- Make available to the Customer all information necessary to demonstrate compliance with these obligations, and permit and contribute to audits and inspections by the Customer or an auditor mandated by the Customer.
5
Customer (controller) obligations
- Establish a lawful basis for processing before submitting any Study containing personal data to the Platform.
- Apply de-identification to Studies before upload and confirm in writing that de-identification meets an appropriate standard (e.g. NHS DSPT or equivalent).
- Not submit Studies that you have reason to believe contain patient-identifying metadata.
- Ensure that Authorised Users are trained in the intended use and limitations of the Platform before accessing it.
- Notify Verityn Ltd promptly if you become aware of a security incident affecting your account or the studies submitted through it.
- Obtain any necessary Data Protection Impact Assessment approval from your Data Protection Officer before onboarding.
6
Security measures
We implement technical and organisational measures designed to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit using TLS 1.2 or higher, and at rest using AES-256.
- Access controls based on the principle of least privilege, with multi-factor authentication required for all staff with access to production systems.
- Audit logging of all access to personal data, retained for seven years.
- Annual penetration testing by an independent third party, with critical findings remediated within thirty days.
- A documented incident response plan tested at least annually.
- Physical security controls at all data centre facilities used by our infrastructure providers.
- Regular staff training on data protection, information security, and safe handling of clinical data.
Full details of our security controls are available on the Security page and in the Information Security Schedule, which is available to institutional customers on request.
7
Sub-processors
The Customer provides general written authorisation for Verityn Ltd to engage sub-processors. We will notify the Customer of any intended changes to sub-processors (additions or replacements) with not less than thirty days' written notice, giving the Customer the opportunity to object to the change before it takes effect.
We require all sub-processors to enter into data processing agreements that impose the same level of data protection obligations as set out in this document. We remain liable to the Customer for the acts and omissions of our sub-processors to the same extent as we would be liable if performing the services directly.
The current list of sub-processors is available on request from hello@verityn.ai. The main categories are: cloud infrastructure (hosting, storage, and compute), AI model inference (where processing is performed by a third-party model provider), and security monitoring.
8
Data residency and international transfers
By default, all personal data submitted to the Verityn Platform is stored and processed within the United Kingdom. Customers on the Hospital plan may request that data be processed within the European Economic Area or a specific jurisdiction, subject to availability and to additional terms.
Where personal data is transferred outside the UK, we rely on one of the following mechanisms: an adequacy decision by the UK Secretary of State, standard contractual clauses approved by the Information Commissioner's Office, or another appropriate safeguard under Article 46 UK GDPR. A transfer impact assessment is conducted for all new international transfer arrangements.
9
Retention and deletion
De-identified imaging data submitted for processing will be retained for no longer than ninety days from the date of upload, unless a shorter period is agreed with the Customer or deletion is requested earlier.
Audit logs, usage records, and flag outputs will be retained for seven years to support post-market surveillance obligations under the applicable medical device regulations.
On termination of the Agreement, we will delete or return all personal data within thirty days, and confirm deletion in writing on request. Copies held to comply with a legal obligation will be retained for the minimum period required by that obligation and will not be processed for any other purpose.
10
Security incident and breach notification
In the event of a personal data breach affecting data processed on behalf of the Customer,Verityn Ltd will notify the Customer without undue delay and, where feasible, within twenty-four hours of becoming aware of the breach.
Our notification will include, to the extent available at the time: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences of the breach, and the measures we have taken or propose to take to address the breach.
Breach notifications should be sent to security@verityn.ai. The Customer is responsible for notifying the ICO and, where required, data subjects in accordance with its obligations as data controller.
11
Audit rights
The Customer may, on not less than thirty days' written notice, audit Verityn Ltd's compliance with these data processing terms, at the Customer's cost and no more than once per calendar year, unless there is a reasonable belief of a material breach. We may require that any such audit is conducted by a mutually agreed independent third party, subject to appropriate confidentiality obligations, where we consider that direct access by the Customer would create an unacceptable security or confidentiality risk.
12
Governing law
These data processing terms are governed by the laws of England and Wales. Any dispute arising out of or in connection with these terms will be subject to the exclusive jurisdiction of the courts of England and Wales. Where mandatory local law provides stronger data protection rights to data subjects, those rights are not affected by this choice of governing law.