MEMRY CORPORATION LIMITED
MEMO DATA PROCESSING AGREEMENT (DPA)
Version: 1.0
Effective Date: 20/07/2026
- Purpose
This Data Processing Agreement (“Agreement” or “DPA”) forms part of the contractual arrangements between Memry Corporation Limited (“Processor”, “Memry”, “we”, “our” or “us”) and the organisation using the Memo platform (“Controller”, “you” or “your”).
This Agreement governs the processing of Personal Data by Memry on behalf of the Controller in accordance with:
- UK General Data Protection Regulation (UK GDPR);
- Data Protection Act 2018;
- applicable UK privacy legislation;
- where applicable, other data protection legislation agreed between the parties.
This Agreement supplements, but does not replace, the parties’ principal service agreement.
- Definitions
Unless otherwise defined within this Agreement, capitalised terms have the meanings given in the UK GDPR.
For the purposes of this Agreement:
Controller means the organisation determining the purposes and means of processing Personal Data.
Processor means Memry Corporation Limited.
Personal Data
Has the meaning given in Article 4 UK GDPR.
Special Category Data
Has the meaning given in Article 9 UK GDPR.
Data Subject
Means an identified or identifiable natural person.
Sub-processor
Means any third party engaged by Memry to process Personal Data on behalf of the Controller.
- Scope
This Agreement applies whenever Memry processes Personal Data on behalf of an organisational customer through the Memo platform.
Typical Controllers include:
- NHS organisations;
- Integrated Care Boards;
- NHS Trusts;
- GP practices;
- local authorities;
- residential care providers;
- domiciliary care providers;
- charities;
- healthcare providers;
- regulated care organisations.
- Nature of the Processing
Processing may include:
- collection;
- recording;
- storage;
- organisation;
- retrieval;
- transmission;
- AI-assisted processing;
- updating;
- deletion;
- secure backup;
- destruction.
Processing is undertaken solely for providing the Memo platform and associated services.
- Categories of Personal Data
Depending upon the deployment, processing may include:
- identity information;
- contact details;
- account information;
- care coordination information;
- wellbeing information;
- appointment information;
- communication records;
- location information (where enabled);
- voice interaction data;
- audit records;
- system logs;
- emergency contact information;
- authorised Memry Vault content.
- Categories of Data Subjects
Processing may relate to:
- Primary Users;
- family members;
- informal carers;
- professional carers;
- NHS staff;
- healthcare professionals;
- care home staff;
- organisational administrators;
- emergency contacts;
- authorised representatives.
- Processor Obligations
Memry shall:
- process Personal Data only on documented instructions from the Controller unless otherwise required by law;
- ensure personnel authorised to process Personal Data are subject to appropriate confidentiality obligations;
- implement appropriate technical and organisational security measures;
- assist the Controller in complying with applicable data protection obligations;
- maintain appropriate records of processing where required;
- notify the Controller of legally binding requests for disclosure unless prohibited by law.
Memry will not determine the purposes for which the Controller processes Personal Data.
- Security Measures
Memry shall implement appropriate technical and organisational measures designed to protect Personal Data, including, where appropriate:
- encryption in transit;
- encryption at rest;
- multi-factor authentication for privileged access where appropriate;
- role-based access controls;
- secure software development practices;
- vulnerability management;
- security monitoring;
- audit logging;
- backup protection;
- disaster recovery arrangements;
- business continuity procedures.
Security measures may evolve as technology and recognised industry standards develop.
- Confidentiality
Memry shall ensure that all personnel authorised to process Personal Data:
- receive appropriate privacy and security training;
- are subject to contractual confidentiality obligations;
- access Personal Data only where necessary for authorised duties.
These obligations continue after employment or engagement ends.
- Sub-processors
The Controller grants general authorisation for Memry to engage Sub-processors to support delivery of the Service.
Memry shall:
- undertake appropriate due diligence before appointing a Sub-processor;
- impose data protection obligations substantially equivalent to those contained within this Agreement;
- remain responsible for the performance of its Sub-processors in relation to the processing carried out on behalf of the Controller.
An up-to-date list of Sub-processors will be made available upon reasonable request or through Memry’s website where appropriate.
Where Memry intends to appoint a new Sub-processor that materially affects processing, reasonable prior notice will be provided where practicable.
- Assistance to the Controller
Taking into account the nature of the processing and the information available, Memry shall provide reasonable assistance to enable the Controller to comply with obligations relating to:
- Data Subject rights;
- security of processing;
- personal data breach notification;
- Data Protection Impact Assessments;
- prior consultation with the Information Commissioner’s Office where required.
Additional assistance beyond standard operational support may be subject to reasonable charges where permitted under the principal agreement.
- Data Subject Rights
Where Memry receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Controller, Memry shall:
- promptly notify the Controller unless prohibited by law;
- not respond directly except on documented instructions or where legally required.
The Controller remains responsible for responding to Data Subject requests.
- Personal Data Breaches
Where Memry becomes aware of a Personal Data Breach affecting Personal Data processed on behalf of the Controller, Memry shall:
- notify the Controller without undue delay after becoming aware of the breach;
- provide available information necessary to assist the Controller in assessing the breach;
- take reasonable steps to investigate and mitigate the incident;
- cooperate with the Controller in responding to the breach.
Notification does not constitute an admission of liability.
- International Transfers
Where Personal Data is transferred outside the United Kingdom, Memry shall ensure that appropriate safeguards are in place, including where appropriate:
- UK International Data Transfer Agreements (IDTAs);
- UK Addendum to the European Commission Standard Contractual Clauses;
- adequacy regulations;
- other lawful transfer mechanisms recognised under UK law.
Memry will not transfer Personal Data internationally in a manner prohibited by applicable legislation.
- Audit Rights
The Controller may request reasonable information demonstrating Memry’s compliance with this Agreement.
Where appropriate, Memry may satisfy audit requirements by providing:
- recognised independent audit reports;
- security certifications;
- compliance statements;
- penetration testing summaries where appropriate;
- responses to reasonable security questionnaires.
Where an on-site audit is reasonably necessary:
- reasonable notice shall be provided;
- audits must not unreasonably interfere with Memry’s operations;
- auditors shall comply with confidentiality obligations;
- audits shall occur no more frequently than once in any twelve-month period unless required by law or following a material security incident.
Each party shall ordinarily bear its own audit costs unless otherwise agreed.
- Deletion or Return of Personal Data
Upon termination of the Services, and subject to applicable law, Memry shall:
- return Personal Data to the Controller where requested and technically practicable; or
- securely delete Personal Data following expiry of any agreed recovery period.
Memry may retain information where required:
- by law;
- for legitimate regulatory purposes;
- for the establishment, exercise or defence of legal claims;
- within secure encrypted backup systems until routine deletion occurs.
Deletion shall be carried out in accordance with the Data Retention & Deletion Policy.
- Records of Processing
Where required by law, Memry shall maintain records of processing activities undertaken as Processor.
- Compliance and Cooperation
Each party agrees to cooperate in good faith to ensure ongoing compliance with applicable data protection legislation.
The Controller remains responsible for:
- determining the lawful basis for processing;
- providing appropriate privacy information to Data Subjects;
- obtaining any required consents;
- ensuring that instructions to Memry comply with applicable law.
- Liability
Liability arising under this Agreement shall be governed by the limitation of liability provisions contained within the principal agreement between the parties unless otherwise required by law.
Nothing within this Agreement excludes liability that cannot lawfully be excluded.
- Term and Termination
This Agreement shall remain in force for as long as Memry processes Personal Data on behalf of the Controller.
Termination of the principal agreement shall automatically terminate this DPA except where continuing obligations remain under applicable law.
- Governing Law
This Agreement shall be governed by the laws of England and Wales.
The courts of England and Wales shall have exclusive jurisdiction except where mandatory legislation provides otherwise.
- Contact
Questions regarding this Agreement should be directed to:
Memry Corporation Limited
Privacy & Information Governance Team
Email: Team@Memry.io
Website: www.Memry.io
Registered Office: The Towers Building, 6 Brincliffe Crescent, Sheffield, S119AW UK

Compassionate digital companionship for dementia care, supporting families with dignity and NHS-approved resources.
- Made with care in the UK
Quick Links
- How It Works
- Features
- Pricing
- NHS Integration
- Family Resources
Support
- Help Centre
- Carer Guides
- Privacy Policy
- Terms of Service
- GDPR Compliance
Contact Us
- 07429 744007
- support@memry.io
© 2024 The Memry Project. All rights reserved. NHS Digital Health Partner.
- GDPR Compliant
- NHS Approved
- ISO 27001