When you use MassageHub to hold your clients' details, you are the data controller of that information and MassageHub is your data processor. A Data Processing Agreement is the contract that sets out that relationship under UK GDPR. You can accept yours and download a signed copy in a couple of taps.
Why you might want one
Most solo therapists don't strictly need a signed DPA on file, but it's a reasonable thing for a careful practitioner to keep, and an insurer, a landlord practice, or an occupational-health client may ask to see one. Having it ready shows you take your clients' data seriously.
How to accept it
Go to Settings, then Account, and find the Data Processing Agreement section. Your practice name and address are filled in for you from your profile, so check those look right first (if your address is missing, add it under Locations). Read the agreement, then tap Accept agreement. That records your acceptance with the date, and the section turns green to confirm.
Downloading your copy
Once accepted, tap Download signed PDF for a copy that shows it was accepted electronically by you, on the date you accepted, with MassageHub's side already completed. There's no need to print or physically sign anything. You can download it again any time.
What the agreement covers
It sets out that MassageHub only processes your client data to run the service, keeps it secure, and will delete or return it when you leave. It also lists, in plain terms, what is encrypted, where your data is stored (the EU), and the other services we rely on behind the scenes, such as Stripe for payments and Supabase for the database. If we ever change the agreement in a way that matters, you'll be asked to review and accept the updated version.
This article is general guidance, not legal advice. If you handle data for a high-volume or organisational client, it's worth having your own solicitor review the agreement too.