Proven. CPD
Sign in Sign up
Features Who it's for Pricing Organisations FAQ About Contact
Sign in Sign up free
 Organisations

Data Processing Agreement

The agreement governing how Nexi Bot LTD processes personal data on behalf of organisations.

Last updated: 28 June 2026  •  UK GDPR compliant

This Data Processing Agreement ("DPA") applies to organisations (universities, NHS Trusts, training providers and other bodies) that have entered into a commercial agreement with Nexi Bot LTD for the use of the Proven. CPD platform. This DPA is incorporated into and forms part of the main organisation services agreement. It satisfies the requirements of Article 28 of the UK GDPR.

1. Definitions

  • "Controller": The Organisation that determines the purposes and means of processing personal data of its students and staff via the Platform.
  • "Processor": Nexi Bot LTD (trading as Proven. CPD), which processes personal data on behalf of the Controller.
  • "Data Subjects": Students, Practice Educators and other staff whose personal data is processed via the Platform.
  • "Personal Data": Any information relating to an identified or identifiable natural person processed via the Platform.
  • "UK GDPR": The UK General Data Protection Regulation as retained in UK law under the European Union (Withdrawal) Act 2018, as amended.
  • "DPA 2018": The Data Protection Act 2018.

2. Subject matter of processing

Subject matter: Provision of the Proven. CPD platform to facilitate student portfolio management, CPD logging, placement tracking, proficiency sign-off and related services.

Duration: For the term of the Organisation's service agreement with us, and for any retention periods specified in the relevant retention schedule thereafter.

Nature and purpose: Storage, retrieval, organisation, structuring, display, transmission and deletion of portfolio data as instructed by the Controller and as necessary to provide the contracted services.

Types of personal data processed:

  • Identity data: names, email addresses, professional roles, HCPC registration numbers
  • Professional portfolio data: CPD records, reflections, placement logs, skill forms, sign-off records
  • Usage data: login records, activity timestamps, IP addresses
  • Uploaded evidence documents and associated metadata

Categories of data subjects: Student paramedics, NQPs, qualified paramedics, Practice Educators and organisation administrators enrolled or created by the Organisation.

3. Obligations of the Processor (Nexi Bot LTD)

We shall, in our capacity as data processor:

  • Process personal data only on the documented instructions of the Controller and only for the purposes specified in this DPA and the service agreement, unless required to do so by applicable law;
  • Immediately notify the Controller if, in our opinion, an instruction infringes the UK GDPR or DPA 2018;
  • Ensure that all staff authorised to process personal data under this DPA are subject to appropriate confidentiality obligations;
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption of personal data in transit and at rest, access controls and regular security testing;
  • Not engage any sub-processor without the prior specific or general written authorisation of the Controller (see Schedule 1 for current authorised sub-processors);
  • Assist the Controller in fulfilling its obligations to respond to data subject requests within the required timescales;
  • Assist the Controller with its security, breach notification, data protection impact assessment and consultation obligations;
  • At the choice of the Controller, delete or return all personal data after the end of the provision of services, unless applicable law requires continued retention;
  • Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and permit and contribute to audits and inspections at reasonable notice (subject to reasonable confidentiality protections); and
  • Notify the Controller without undue delay (and in any event within 72 hours of becoming aware) of any personal data breach affecting the Controller's data.

4. Obligations of the Controller (Organisation)

The Organisation shall:

  • Have a lawful basis for providing student and staff personal data to us for processing;
  • Ensure that data subjects have been provided with appropriate privacy notices informing them that their data will be processed via the Platform;
  • Be responsible for the accuracy and lawfulness of the personal data provided to us;
  • Not instruct us to process personal data in a way that would violate applicable law; and
  • Ensure that any organisation administrators and Practice Educators with access to the Platform have completed appropriate data protection training.

5. Sub-processors

We may engage sub-processors to assist in the provision of the Platform. All sub-processors are bound by contractual terms that impose data protection obligations equivalent to those in this DPA. Current authorised sub-processors include (subject to update with notice):

  • UK-based cloud hosting provider (for data storage and platform infrastructure)
  • Email delivery service (for transactional emails)
  • Payment processor (for subscription billing — no portfolio data is shared)

We will inform the Controller of any intended changes to sub-processors and give the Controller the opportunity to object. If the Controller objects on reasonable data protection grounds, we will work with the Controller to find a suitable alternative.

6. International transfers

All personal data under this DPA is stored and processed in the United Kingdom. Where any sub-processor processes data outside the UK, we ensure that appropriate transfer mechanisms are in place, including UK International Data Transfer Agreements (IDTAs) or equivalent safeguards.

7. Security measures

We implement and maintain the following technical and organisational security measures:

  • Encryption of all personal data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls limiting staff access to personal data to what is strictly necessary
  • Multi-factor authentication for all administrative access to production systems
  • Regular automated vulnerability scanning and periodic penetration testing
  • Audit logging of access to personal data
  • Formal incident response procedures
  • Regular staff data protection training
  • Business continuity and disaster recovery plans with tested recovery procedures

8. Personal data breach notification

In the event of a personal data breach affecting the Controller's data, we will:

  • Notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach;
  • Provide all available information about the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach; and
  • Cooperate fully with the Controller's breach response activities.

9. Data subject rights

We will assist the Controller in responding to data subject rights requests within the required timeframes. Where a data subject contacts us directly with a rights request relating to data processed on behalf of an Organisation, we will promptly refer the request to the Controller.

10. Term and termination

This DPA remains in force for the duration of the service agreement between us and the Organisation. On termination of the service agreement, we will, at the Organisation's election, either securely delete or return all personal data within 30 days, save where applicable law requires continued retention.

11. Contact

To execute this DPA, raise questions or request an audit, contact us at [email protected]. Organisation accounts require a signed DPA before processing of student data commences.

Request a DPA for your organisation

Proven. CPD
Your practice, Proven.

The professional CPD, reflection and portfolio platform built exclusively for UK paramedics, student paramedics and healthcare organisations.

Proven. CPD is a trading name of Nexi Bot LTD

Company No: 16502958  |  ICO: ZB910034

Suite 627, 80A Ruskin Ave, Welling DA16 3QQ
(Correspondence only)

Platform

  • Features
  • Pricing
  • Organisations
  • How it works
  • FAQ
  • About

For You

  • Student Paramedics
  • Newly Qualified (NQP)
  • Qualified Paramedics
  • Practice Educators
  • Universities & NHS Trusts

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use
  • Data Processing Agreement
  • Cookie settings
  • Contact
HCPC Standards of CPD Aligned
UK GDPR Compliant
UK Data Residency
ICO Registered: ZB910034

© 2026 Proven. CPD — a trading name of Nexi Bot LTD. Company No. 16502958. All rights reserved.

Privacy Terms Cookies Acceptable Use
We use cookies

We use essential cookies to keep Proven working and optional analytics cookies to help us improve. We never sell your data. Cookie Policy

Cookie Preferences

Choose which cookies you allow. Essential cookies are always active as they are required for the platform to function. You can change your preferences at any time via the Cookie Policy page.

Essential Cookies

Required for the platform to function — authentication, security, session management and your cookie preferences. Cannot be disabled.

Analytics Cookies

Help us understand how Proven is used so we can improve features and fix problems faster. We use privacy-first analytics with no cross-site tracking.

Marketing Cookies

Allow us to show you relevant information about Proven on other websites. We do not sell your data to advertisers.