Data Processing Addendum (DPA)
Last Updated: June 2026
This Data Processing Addendum ("DPA") forms part of the Terms and Conditions between Lighthouse Advisory, operating Doctor Lead ("Doctor Lead"), and the Customer.
This DPA applies where Doctor Lead processes Personal Data on behalf of the Customer in connection with the Service.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable individual.
- "Controller" means the party that determines the purposes and means of processing Personal Data.
- "Processor" means the party that processes Personal Data on behalf of a Controller.
- "Applicable Data Protection Laws" means applicable privacy and data protection laws, including where relevant GDPR, UK GDPR, PDPA, CCPA, and similar legislation.
2. Roles of the Parties
- The Customer acts as the Controller of Personal Data submitted to the Service.
- Doctor Lead acts as a Processor of such Personal Data when processing information on behalf of the Customer.
- The Customer is responsible for ensuring that Personal Data has been collected, used, and disclosed lawfully.
3. Purpose of Processing
Doctor Lead processes Personal Data solely for the purpose of:
- providing the Service;
- operating platform functionality;
- generating lead intelligence;
- generating AI-assisted content and recommendations;
- providing support services;
- maintaining security and performance;
- complying with legal obligations.
Doctor Lead shall not process Personal Data for purposes unrelated to providing the Service.
4. Customer Instructions
The Customer instructs Doctor Lead to process Personal Data as necessary to provide the Service and as otherwise permitted under the Terms and Conditions.
Doctor Lead will not knowingly process Personal Data in a manner inconsistent with documented Customer instructions.
5. Confidentiality
Doctor Lead shall ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations.
6. Security Measures
Doctor Lead will implement reasonable technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access.
Such measures may include:
- access controls;
- authentication measures;
- encryption where appropriate;
- monitoring and security controls;
- restricted personnel access.
Doctor Lead does not guarantee absolute security.
7. Subprocessors
The Customer authorises Doctor Lead to engage third-party subprocessors to assist in providing the Service.
Such subprocessors may include:
- cloud hosting providers;
- AI service providers;
- analytics providers;
- payment processors;
- customer support providers;
- infrastructure providers.
Doctor Lead shall take reasonable steps to ensure subprocessors are subject to appropriate obligations regarding Personal Data.
8. International Transfers
Personal Data may be processed or stored in countries where Doctor Lead or its subprocessors operate.
Doctor Lead shall take reasonable measures to protect Personal Data during such transfers.
9. Data Subject Requests
Where legally required, Doctor Lead will provide reasonable assistance to the Customer in responding to requests relating to Personal Data, including requests for access, correction, deletion, or restriction of processing.
10. Data Breach Notification
If Doctor Lead becomes aware of a confirmed Personal Data breach affecting Customer Data, Doctor Lead will notify the Customer without undue delay and provide information reasonably available regarding the nature of the breach.
11. Deletion and Return of Data
Upon termination of the Service, Doctor Lead may delete Customer Data following a reasonable retention period unless retention is required by law or necessary for legitimate business, security, audit, dispute resolution, or compliance purposes.
The Customer is responsible for exporting any data it wishes to retain before termination.
12. Liability
The liability of the parties under this DPA shall be subject to the liability limitations set out in the Terms and Conditions.
13. Conflict
If there is any conflict between this DPA and the Terms and Conditions regarding Personal Data processing, this DPA shall prevail to the extent of that conflict.