Osprey Approach Data Processing Terms

Effective from 27 September 2026. Published 26 August 2026.

This policy forms part of the Osprey Approach Software Licensing & Services Agreement between Pracctice Limited and the Customer (Schedule G). Capitalised terms have the meanings given in that Agreement. In the event of any conflict, the Agreement prevails.


1. Definitions and Status

1.1 In this Schedule:

  • Controller, Processor, Data Subject, Personal Data, Processing, Special Category Data and Personal Data Breach have the meanings given to them by Data Protection Law;

  • Subprocessor means a third party appointed by or on behalf of Pracctice to Process Customer Personal Data.

1.2 The Customer is the Controller and Pracctice is the Processor of Customer Personal Data processed for the purpose of providing the Software and Services.

1.3 The Customer determines the purposes of the processing and the Customer Data placed within the Software. Pracctice does not determine the Customer’s lawful basis for processing Customer Personal Data.

2. Details of Processing

2.1 The subject matter of the processing is the Customer Personal Data processed through the Software and Services.

2.2 Processing will continue for the Term and for any reasonable period required afterwards to complete return, deletion, backup rotation, legal retention or other obligations under this Agreement.

2.3 The nature and purpose of the processing may include collection, receipt, storage, organisation, retrieval, consultation, use, transmission, migration, backup, support, alteration and deletion of Customer Personal Data as reasonably required to provide the Software and Services and act on the Customer’s documented instructions.

2.4 Customer Personal Data may include any categories of Personal Data the Customer elects to place in the Software, including identity and contact information, client and matter information, correspondence, financial information and, where the Customer chooses to process it, Special Category Data or data relating to criminal allegations, offences or convictions.

2.5 Data Subjects may include the Customer’s clients and prospective clients, employees, partners, officers, suppliers, professional advisers, counterparties, witnesses, beneficiaries and other persons whose Personal Data the Customer elects to process using the Software.

3. Customer Responsibilities and Warranties

3.1 The Customer is responsible for ensuring that:

  • its Processing of Customer Personal Data complies with Data Protection Law;

  • it has a lawful basis and, where required, an additional lawful condition for Processing all Customer Personal Data placed in the Software;

  • its collection, use, disclosure and retention of Customer Personal Data is lawful;

  • all privacy information and notices required by Data Protection Law are provided;

  • its instructions to Pracctice are lawful; and

  • it is entitled to provide Customer Personal Data to Pracctice for Processing under this Agreement.

3.2 The Customer is responsible for determining whether it is lawful and appropriate to place Special Category Data, criminal-offence data, legally privileged information or other sensitive information in the Software.

3.3 The Customer will not instruct Pracctice to Process Customer Personal Data in a manner that would cause Pracctice to breach Data Protection Law.

3.4 Pracctice is entitled to rely on the Customer’s instructions and is not required to independently determine the legality, accuracy, completeness or appropriateness of Customer Personal Data or the Customer’s Processing purposes.

4. Documented Instructions

4.1 Pracctice will Process Customer Personal Data only on documented instructions from the Customer, unless required to do otherwise by applicable law.

4.2 The Customer’s documented instructions comprise:

  • this Agreement and the Commercial Schedule;

  • the Customer’s authorised use and configuration of the Software;

  • agreed Implementation Services and Additional Services;

  • authorised support, migration, backup and administration requests; and

  • any other written instruction accepted by Pracctice.

4.3 Where applicable law requires Pracctice to Process Customer Personal Data other than on the Customer’s instructions, Pracctice will inform the Customer before doing so unless the law prohibits such notification.

4.4 If Pracctice reasonably considers that an instruction infringes Data Protection Law, it may suspend acting on that instruction while informing the Customer and seeking clarification or a lawful alternative.

5. Confidentiality

5.1 Pracctice will ensure that persons authorised to Process Customer Personal Data are subject to an appropriate duty of confidentiality.

5.2 Access to Customer Personal Data will be limited to persons who require access for the performance of their duties.

6. Security

6.1 Pracctice will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking account of the nature of the Processing, the risks presented, the state of the art and the costs of implementation.

6.2 Pracctice may modify individual technical or organisational measures from time to time provided that the overall level of protection for Customer Personal Data is not materially reduced.

6.3 The Customer remains responsible for security matters within its control, including User access, allocation of permissions, protection of credentials, endpoint security and the conduct of its Users.

7. Subprocessors

7.1 The Customer gives Pracctice general written authorisation to appoint Subprocessors for the purposes of providing the Software and Services.

7.2 Pracctice will ensure that each Subprocessor is subject to written data protection obligations providing a level of protection for Customer Personal Data substantially equivalent to the obligations imposed on Pracctice by this Schedule, to the extent applicable to the services performed by that Subprocessor.

7.3 Pracctice remains responsible to the Customer for the performance of a Subprocessor’s data protection obligations to the extent required by Data Protection Law.

7.4 Pracctice will make information about its material Subprocessors available to the Customer and will give reasonable prior notice of a material intended addition or replacement before the new Subprocessor begins Processing Customer Personal Data.

7.5 The Customer may object to a proposed Subprocessor only on reasonable and documented grounds relating to the protection of Customer Personal Data. The Parties will use reasonable efforts to resolve such an objection.

Where a reasonable objection cannot be resolved and use of the proposed Subprocessor is reasonably necessary to provide the affected Software or Services or to meet legal, security or operational requirements, Pracctice may terminate the affected Service on written notice or, where that Service cannot reasonably be separated from the remainder of the Agreement, terminate the Agreement on written notice.

8. International Transfers

8.1 Customer Personal Data will be stored within the UK as provided in Clause 3.6.6.

8.2 Where Processing involves a restricted transfer of Customer Personal Data outside the UK, Pracctice will ensure that the transfer is made in accordance with Data Protection Law, including by relying on applicable adequacy regulations or an appropriate transfer mechanism recognised under Data Protection Law.

9. Data Subject Requests

9.1 The Customer is responsible for responding to requests made by Data Subjects in exercise of their rights under Data Protection Law.

9.2 Taking account of the nature of the Processing, Pracctice will provide reasonable assistance to the Customer through appropriate technical and organisational measures where required for the Customer to respond to a Data Subject request.

9.3 Pracctice will not respond substantively to a Data Subject request relating to Customer Personal Data except on the Customer’s instructions or where required by law.

9.4 Assistance requiring material work outside the normal operation of the Software or Support Services may be charged at Pracctice’s prevailing professional services rates, except to the extent that the assistance is required as a direct result of Pracctice’s breach of Data Protection Law.

10. Personal Data Breaches

10.1 Pracctice will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

10.2 Pracctice will provide information reasonably available to it concerning the nature of the Personal Data Breach, the categories of affected data and Data Subjects, likely consequences and measures taken or proposed, and may provide that information in phases as it becomes available.

10.3 The Customer is responsible for determining whether notification to the ICO, another regulator or affected Data Subjects is required and for making any such notification, except where Data Protection Law expressly places that obligation on Pracctice.

10.4 Notification or cooperation under this Section does not constitute an admission by Pracctice of fault or liability.

11. Assistance with Compliance

11.1 Taking account of the nature of Processing and the information available to it, Pracctice will provide the assistance reasonably required of a Processor under Data Protection Law in relation to security, Personal Data Breaches, data protection impact assessments and prior consultation with supervisory authorities.

11.2 Assistance requiring material work outside the normal operation of the Software or Support Services may be charged at Pracctice’s prevailing professional services rates, except to the extent that the assistance is required as a direct result of Pracctice’s breach of Data Protection Law.

12. Audit and Compliance Information

12.1 Pracctice will make available information reasonably necessary to demonstrate compliance with the Processor obligations in this Schedule and Data Protection Law.

12.2 The Customer will ordinarily rely on compliance documentation, certifications, policies, reports or other information made available by Pracctice before requesting an on-site or bespoke audit.

12.3 Where an audit or inspection is reasonably required under Data Protection Law, the Customer may conduct it itself or through an independent professional auditor that is not a competitor of Pracctice, subject to:

  • reasonable prior written notice;

  • no more than one audit in any 12-month period unless required by a supervisory authority, reasonably necessary following a material Personal Data Breach, or Data Protection Law requires otherwise;

  • performance during normal Working Hours and in a manner that does not materially disrupt Pracctice’s business;

  • compliance with Pracctice’s reasonable security and confidentiality requirements; and

  • no access to information relating to another customer or to information Pracctice is prohibited from disclosing.

12.4 The Customer will bear its own audit costs and Pracctice’s reasonable costs of supporting a bespoke audit, unless the audit identifies a material breach by Pracctice of its obligations under this Schedule.

13. Return and Deletion

13.1 At the end of the Processing of Customer Personal Data under this Agreement, and subject to any separate written agreement under which Pracctice continues lawfully to Process the same data, the Customer may elect to have Customer Personal Data returned or deleted, except to the extent applicable law requires retention.

13.2 Unless the Customer instructs Pracctice to delete the Customer Data before the End of Agreement Backup is prepared, the Customer will be treated as having elected return. The End of Agreement Backup provided under Schedule C is the standard mechanism under this Agreement for return of Customer Data.

13.3 Unless Customer Data is being lawfully retained under a separate Continued Availability Agreement or applicable law requires otherwise, Pracctice may permanently delete the Customer’s database, documents, files and other Customer Data from its active production systems 30 calendar days after the Termination Date.

13.4 The Customer is responsible for collecting the End of Agreement Backup within the collection period stated in Schedule C. Failure to collect the backup does not extend the retention period in Section 13.3.

13.5 Once Customer Data has been deleted from Pracctice’s active production systems, Pracctice has no obligation under this Agreement to restore, reconstruct or otherwise make that Customer Data available.

13.6 Customer Personal Data contained in Pracctice’s internal backup, disaster-recovery or residual systems may remain until overwritten or deleted through Pracctice’s normal retention cycle. Such data will remain protected and will not be restored to active use except where reasonably required for disaster recovery, legal compliance or another lawful internal purpose.

13.7 Internal backup, disaster-recovery or residual copies remaining after deletion from active production systems do not constitute a customer-accessible archive and do not give the Customer any right to require restoration, extraction or supply of another copy.

14. Customer Indemnity

14.1 The Customer will indemnify Pracctice against losses, liabilities, claims, damages and reasonable professional costs arising from:

  • the Customer’s breach of Data Protection Law in relation to Customer Personal Data;

  • an unlawful instruction given by the Customer;

  • the Customer’s failure to establish or maintain an appropriate lawful basis or condition for Processing;

  • Customer Personal Data which the Customer was not lawfully entitled to collect, disclose or Process; or

  • a breach by the Customer of this Schedule,

except to the extent that the relevant loss was caused by Pracctice’s own breach of Data Protection Law or this Schedule.

14.2 The indemnity in Section 14.1 includes reasonable costs of responding to regulatory investigations and, to the extent lawfully indemnifiable, regulatory penalties arising from the matters listed in Section 14.1.

14.3 The relationship between this indemnity and the limitations and exclusions of liability in Clause 9 will be governed by Clause 9.

15. Order of Precedence

15.1 This Schedule forms part of the Agreement.

15.2 If there is an inconsistency between this Schedule and another provision of the Agreement concerning Processing of Customer Personal Data, this Schedule will prevail to the extent required to comply with Data Protection Law.

15.3 Except as provided in Section 15.2, the order of precedence stated in Clause 1 applies.