Client Service and Data Processing Agreement
Proposed terms version 1.2 · England and Wales
This is a public reference copy. In the clauses below, “Agreement” means the completed private document for a particular client, not this web page. The descriptions in the schedules explain what must be confirmed; they are not fields to fill in here.
1. Parties, Agreement and Signing
The client-specific Agreement is between the Client identified in the completed private document and Ghulam Rasul Safi personally (the Supplier). GR Safi Care Solutions is the Supplier’s service name. It is not a separate incorporated company and is not a separate party to this Agreement.
| Item | What your private agreement will contain |
|---|---|
| Client legal identity | The client’s full legal name and business address, with a registration reference where applicable. |
| Manager or authorised contact | The named business contact responsible for the work and how to reach them. |
| Client signatory | The person’s name, role, business email and confirmation of authority to act for the client. |
| Supplier | Ghulam Rasul Safi personally. GR Safi Care Solutions is his service name, not a separate company. |
| Supplier correspondence details | The confirmed address is included in the private agreement, not in this public reading copy. The business email is info@grsafi.com. |
The complete Agreement consists of these 25 clauses and the four completed schedules in this fixed version. The Client signatory must confirm authority to act for the Client. A stated role or verified email address does not, by itself, establish that authority.
This Agreement becomes binding only when both the authorised Client signatory and Ghulam Rasul Safi have actually signed the same completed version through the agreed electronic-signing process. Its effective date is the later of the agreement start date in Schedule 1 and the date of the last required signature. No person or system signs automatically for the Supplier.
Completing a form, saving a draft, approving a review, receiving an invitation or acknowledgement, or signing as the Client alone does not confirm a booking or bind the Supplier. No work is required to start before both parties have signed and the agreed access, scope and timing arrangements are ready.
Electronic signing is used to show an intention to authenticate this exact document. Each party must have an opportunity to read, save and reproduce the complete version before signing. Both parties receive or can securely obtain the final signed document and audit record. If a party identifies an error or requests changed terms, the Supplier must issue a new version for review and fresh signatures; an existing signed version must not be silently edited.
2. Purpose and Standard of Service
The Supplier provides independent compliance, audit, quality-improvement and CQC-readiness support for care providers. Services may include gap audits, action plans, agreed correction support, focused re-audits and ongoing monitoring, but only to the extent stated in Schedule 1.
The Supplier will perform the Services with reasonable care and skill and within the agreed scope. The Supplier is not the Care Quality Commission, does not act for CQC, and does not guarantee any rating, inspection outcome or absence of regulatory findings.
3. Services and Scope
Schedule 1 confirms the selected Services, sample size, records, period, dates, delivery method, deliverables, fees and deadlines. A risk-based sample may be used. If a repeated or serious concern suggests a wider problem, a larger review may be recommended. Extra chargeable work requires the Client’s prior written approval.
The following areas may be selected in Schedule 1. The list does not include every service automatically.
- Care Records & Risk Audit
- Medicines Safety Audit
- Workforce Compliance Audit
- Safeguarding, Incidents & Complaints Audit
- Rota, Calls & Service Delivery Audit
- Service User Money & Financial Transactions Audit
- Quality & Service User Experience Audit
- Governance, GDPR & Regulatory Compliance Audit
- Full CQC Readiness & Improvement Review
- Action Planning / Correction Support
- Focused Re-Audit
- Monthly Compliance Monitoring
- Other work expressly agreed in writing
Service-user money and financial transactions work is a care-compliance and safeguarding review. It is not accountancy, tax, investment or FCA-regulated financial advice. On-site, remote or blended delivery is limited to the method expressly recorded in Schedule 1.
4. Improvement Process
Gap Audit: review agreed evidence to identify risks, gaps, conflicting information, overdue actions and good practice.
Action Plan: record important findings, priority or risk, required action, owner and target date.
Correction Support: support agreed improvements within the quoted limit. The Supplier will not invent information, falsely backdate records, alter medication instructions, or make clinical, safeguarding or authorised care decisions for the Client.
Re-Audit: where included, check updated evidence and record actions as Closed, Partly Closed, Open or Urgent/High Risk.
Ongoing Monitoring: where agreed, monitor trends, repeated concerns, overdue actions and new risks at the agreed frequency. Each stage is included only within its express allowance in Schedule 1.
5. Client Responsibilities
- Provide accurate, complete and current information and secure access to agreed records.
- Ensure a lawful basis and, where relevant, a valid UK GDPR Article 9 condition and any required Data Protection Act 2018 Schedule 1 condition for special-category data shared for the Services.
- Where criminal-offence or DBS information is provided, ensure the disclosure and processing are lawful and limited to what is necessary.
- Keep responsibility for care delivery, staffing, clinical and medication decisions, safeguarding decisions, notifications, referrals and all duties owed to service users.
- Make authorised staff available for clarification and confirm facts before records are changed.
- Take prompt action where an urgent safety concern is raised and complete Client-owned actions within agreed timescales.
- Tell the Supplier promptly if supplied information is inaccurate, incomplete or no longer current.
6. Supplier Responsibilities
- Work only within the agreed scope and base findings on evidence made available.
- Use reasonable care and skill and clearly identify material concerns.
- Keep Client confidential information secure and use it only for the agreed purposes.
- Raise a serious or immediate safety concern with an authorised Client contact without waiting for the final report.
- Recommend specialist clinical, legal, HR or data-protection advice where the issue is outside the agreed competence or authority of the Supplier.
- Keep reasonable records of agreed actions, deliverables and Client instructions.
7. Fees, Invoices and Late Payment
The agreed fixed or monthly fee, VAT treatment, deposit and invoice payment period are stated in Schedule 1. No VAT registration status or tax treatment is assumed from the service name. A deposit is payable only where Schedule 1 states one.
The Client must pay for work properly completed up to a cancellation date and any approved non-refundable costs. For qualifying business-to-business late payments, the Supplier may claim statutory interest and fixed recovery compensation under the Late Payment of Commercial Debts (Interest) Act 1998, where applicable.
8. Changes, Delays and Cancellation
Either party may request a change to scope, timing or deliverables. A material change must be agreed in writing, including any fee or deadline change. A change to this signed Agreement must not be made by editing its existing electronic record.
For ongoing monthly Services, either party may terminate on the written notice recorded in Schedule 1. Either party may terminate immediately for a material breach that cannot be remedied, unlawful instructions, serious confidentiality or data-security concerns, or persistent non-payment after reasonable notice.
Neither party is responsible for delay caused by events outside its reasonable control, but the affected party must notify the other and take reasonable steps to reduce the delay.
9. Confidentiality
Each party must keep the other party’s confidential information confidential and use it only for this Agreement. Disclosure is permitted only to people who need it for the Services and are bound by confidentiality, or where disclosure is required by law or a competent authority. This clause continues after the Agreement ends.
10. Intellectual Property and Reports
The Client may use final reports, action plans and deliverables created specifically for its organisation for its internal business and regulatory purposes. The Supplier retains ownership of pre-existing templates, methods, checklists, frameworks and general know-how. The Client receives a non-exclusive licence to use embedded background materials as needed to use the deliverables.
Client information or identifiable case material will not be used in public marketing, case studies or testimonials without written permission. Anonymised learning may only be used where individuals and the Client cannot reasonably be identified.
11. No Guarantee and Limits of Audit
An audit is based on the agreed sample, records supplied and information available at the time. It cannot guarantee that every issue in the organisation will be found. CQC may review different evidence and may reach its own conclusions.
The Client remains responsible for legal, clinical, operational and regulatory decisions and for deciding whether actions recommended by the Supplier are appropriate in the Client’s circumstances.
12. Liability
Nothing in this Agreement excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any liability that cannot lawfully be excluded or limited.
Subject to the paragraph above, neither party is liable to the other for indirect or consequential loss, loss of profit, loss of business or loss of anticipated savings, except where such exclusion is not permitted by law.
Subject to the paragraphs above, the Supplier’s total aggregate liability arising from this Statement of Work is limited to the specific cap or fee-based formula recorded in Schedule 1. The cap does not reduce separate statutory rights of data subjects or powers of a regulator.
Any limitation applies only to the extent it is fair and legally enforceable in the circumstances. The Supplier contracts personally; the service name does not create a separate company or a corporate liability shield. The insurance disclosure in clause 13 does not itself exclude or limit liability.
13. Insurance Position
The Supplier does not currently have professional indemnity insurance or cyber/data-liability insurance in place. No policy, insurer or policy limit is represented in this Agreement. The Client should consider this disclosed position before signing.
This disclosure does not waive a duty imposed by law, reduce the Client’s statutory rights or the rights of a data subject, or replace the liability provisions in clause 12. Any later insurance arrangement must be stated accurately in writing; it must not be assumed from this service name or website.
14. Data Protection Roles
For personal data that the Client controls and the Supplier processes solely on the Client’s documented instructions to provide the Services, the Client is the Controller and the Supplier is the Processor.
For the Supplier’s own business administration data, including business contacts, contract/signature evidence, invoicing, accounting and legal records, the Supplier acts as an independent Controller. The processor terms below do not apply to that separate controller processing. The relevant privacy information describes its purposes, lawful basis, recipients and retention.
15. Processor Instructions and Lawfulness
The Supplier will process Client Personal Data only on the Client’s documented instructions, including instructions about international transfers, unless UK law requires otherwise. If legally permitted, the Supplier will tell the Client before processing required by law.
The Client is responsible for determining and documenting the lawful basis for the processing and any special-category or criminal-offence data condition. The Supplier will tell the Client if, in the Supplier’s reasonable view, an instruction may breach applicable data-protection law.
16. Security and Confidentiality of Personal Data
The Supplier will ensure that anyone authorised to process Client Personal Data is bound by confidentiality and will implement appropriate technical and organisational measures proportionate to the risk, including Schedule 3.
Sensitive care or staff records must not be uploaded through an ordinary public website form or an agreement-signing process. Secure access or transfer arrangements must be agreed for this Client and are identified in Schedule 1.
17. Sub-Processors and AI / Third-Party Tools
The Supplier will not appoint a sub-processor without the Client’s prior specific or general written authorisation. Approved sub-processors for Client-controlled personal data are listed in Schedule 4. Where general authorisation is used, the Client will be notified of intended material changes and given a reasonable opportunity to object.
Each sub-processor must be bound by written data-protection terms offering equivalent protection. The Supplier remains responsible to the Client for the sub-processor’s compliance with its processor obligations.
Identifiable Client Personal Data, including health, medication, care, safeguarding or staff data, will not be entered into a generative-AI service or other third-party platform unless that service is approved in Schedule 4 or separately authorised in writing and the required processor, security and transfer safeguards are in place.
18. International Transfers
The Supplier will not initiate a restricted transfer of Client Personal Data outside the UK except on documented instructions or with the Client’s written authorisation and only where it complies with UK data-protection law. This includes an applicable UK adequacy regulation, an appropriate safeguard such as the UK IDTA/Addendum where required, and any required transfer risk assessment. Schedule 4 identifies the agreed location and transfer arrangements for approved sub-processors.
19. Data Subject Rights and Assistance
Taking account of the nature of processing, the Supplier will use appropriate measures to help the Client respond to individuals exercising their data-protection rights. If the Supplier receives a request relating to Client Personal Data, it will be forwarded to the Client without undue delay and will not be answered substantively unless authorised or legally required.
20. Security, Breach, DPIA and Regulator Assistance
Taking account of the nature of processing and available information, the Supplier will reasonably assist the Client with security obligations, personal data breach assessment and notification, data protection impact assessments and prior consultation with the ICO where required.
The Supplier will notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data and will provide available information reasonably needed for the Client’s response.
21. Return, Deletion and Retention
At the end of the relevant Services, the Supplier will follow the Client’s return or secure-deletion choice in Schedule 2 and delete existing copies, unless UK law requires retention. Where immediate deletion from protected backups is not reasonably possible, the data will be put beyond ordinary use and deleted in the normal secure deletion cycle.
Schedule 2 states the agreed retention of identifiable working data or reports. This does not authorise indefinite retention. Separate business contract and signing records under clause 14 follow the Supplier’s justified controller retention schedule and any lawful preservation requirement, not an automatic retention period for Client care records.
22. Audit and Compliance Information
The Supplier will provide information reasonably necessary to demonstrate compliance with these processor obligations and will allow for and contribute to reasonable audits or inspections by the Client or its appointed auditor. Audits should normally be on reasonable notice, during normal business hours and arranged to protect other clients’ confidential information, except where urgent regulatory or breach circumstances require otherwise.
23. Data Protection Records and Cooperation
Each party will maintain the records and notices required of it by applicable data-protection law. The parties will cooperate in good faith if the ICO or another competent authority makes a lawful enquiry relating to processing under this Agreement.
24. Complaints, Disputes and Governing Law
A complaint about the Services should be made in writing so the parties can first try to resolve it in good faith. This Agreement and its Statement of Work are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, subject to any mandatory law that applies.
25. Entire Agreement and Order of Documents
This completed Agreement and its four schedules form the agreement for the Services stated in this version. The written quotation is incorporated through the completed Schedule 1, not through a changeable website price or an editable external link. If these documents conflict, Schedule 1 takes priority for the expressly agreed commercial scope and price, followed by these clauses and the data-processing schedules; other written project instructions follow them.
No priority provision removes a mandatory obligation under applicable law. An amendment requires both parties’ express written agreement and must be retained as a new, identifiable record. A later signing invitation, automated completion message or unilateral change to a web page is not itself an amendment or acceptance.
Schedule 1. Statement of Work and Commercial Terms
Your private agreement will record the confirmed quote details below. An item that does not apply must say so clearly.
| Item | What your private agreement will contain |
|---|---|
| Quote reference and version | A unique reference and version identifying the work and terms being signed. |
| Client service or project | The specific service, organisation and project covered. |
| Service locations | The locations included in the review. |
| Delivery method | On-site, remote or blended delivery, as confirmed for this work. |
| Services selected | The named audit or support services included in the quote. |
| Service-user records in the sample | An agreed whole number, including 0 where this sample is not used. |
| Staff files in the sample | An agreed whole number, including 0 where this sample is not used. |
| Period or data range reviewed | The dates and records covered by the review. |
| Deliverables | The reports, action plans, meetings or other outputs included. |
| Correction-support limit | The agreed hours, records or other limit, or an explicit statement that this support is not included. |
| Re-audit allowance | The included follow-up checks and limits, or an explicit statement that a re-audit is not included. |
| Monitoring frequency | The agreed frequency and scope, or an explicit statement that monitoring is not included. |
| Agreement start date | The agreed date, subject to both parties signing as described in clause 1. |
| Work start date | The agreed start for the work, subject to clause 1 and the necessary access arrangements. |
| Target report date | The specific report date agreed for the work. |
| Agreed fee | The confirmed amount and whether it is a fixed fee or a monthly fee. |
| VAT treatment | The treatment confirmed for this quote. No VAT status is assumed from the service name. |
| Deposit | The agreed amount or percentage, or an explicit statement that no deposit is payable. |
| Invoice payment terms | The agreed number of calendar days for payment. |
| Monthly-service termination notice | The agreed notice period if ongoing monthly services are included. |
| Liability cap | An expressly agreed amount, or the recorded formula of 150% of the total fees paid or payable for the Statement of Work, subject to clause 12. It must not be left blank. |
| Professional indemnity insurance | Not currently in place. No policy or policy limit is represented. |
| Cyber/data-liability insurance | Not currently in place. No policy or policy limit is represented. |
| Secure record-sharing method | The specific approved method and access arrangements for the agreed records. |
| Exclusions | The work, records, advice or support not included in the quote. |
Who signs the private agreement
The Client’s named authorised signatory signs for the Client. Ghulam Rasul Safi signs personally as the Supplier. Their actual signatures and dates must be recorded through the separately agreed signing process; printed names are not pre-applied signatures.
Under these proposed terms, the Client signs first and Mr Safi then decides whether to countersign. Both parties must be able to keep the complete signed version and its signing record. No signature or acceptance takes place on this public page.
Schedule 2. Article 28 Processing Details
These details must match the actual records and work. They do not give permission to share care or staff records before the lawful basis, instructions and secure access are confirmed.
| Processing detail | What your private agreement will contain |
|---|---|
| Subject matter | The specific services, records and samples stated in Schedule 1. |
| Duration | The service period and a specific retention period, followed by the agreed return or deletion method, subject to law. |
| Nature of processing | The agreed secure access, viewing, checking, comparison, limited extraction of findings, reporting, action tracking, re-checking and return or deletion. |
| Purpose | Providing the contracted services on the Client controller’s documented instructions. |
| Data subjects | The categories of people whose information is necessary for the agreed work. |
| Personal data types | The specific information needed from the agreed records. A broad list is not permission to collect unnecessary data. |
| Special-category data | The types of sensitive information, such as health information, that are necessary and lawfully included, or an explicit statement that none is included. |
| Criminal-offence data | Any necessary and lawfully included criminal-offence or DBS information, or an explicit statement that none is included. |
| Controller rights and obligations | The Client determines purposes and means, provides lawful instructions, identifies the applicable lawful basis and additional conditions, provides transparency and handles data-subject and regulator decisions. |
| Processor obligations | Clauses 14 to 23 and the applicable UK data-protection law. |
| Working-data retention | A specific justified period for identifiable working data or reports, not indefinite storage. |
| End-of-service method | The Client’s choice of return and deletion of remaining copies, or secure deletion, subject to any legal retention requirement. |
| Secure sharing | The method recorded in Schedule 1. Care records must not be attached to the agreement or an ordinary public enquiry. |
Schedule 3. Minimum Technical and Organisational Security Measures
- Access limited to authorised persons with a genuine need to know.
- Strong passwords and multi-factor authentication where available.
- Encryption in transit and appropriate protection, including encryption where required by the assessed risk, for sensitive stored files.
- Only the records and fields needed for the agreed audit are accessed or copied.
- No sensitive records through ordinary public website forms or the agreement-signing flow.
- Use of the approved secure portal, Client system, encrypted transfer method or other secure method identified in Schedule 1.
- Local downloads avoided where possible; any necessary local copies kept on secured devices and deleted when no longer required.
- Devices protected by current operating-system security updates, screen lock and anti-malware controls appropriate to the platform.
- Paper records, if used, kept secure and returned or confidentially destroyed.
- Reasonable backup and recovery arrangements for business records that must be retained.
- Personal-data breaches recorded and escalated promptly.
- No identifiable Client data entered into unapproved AI tools or third-party services.
- Periodic review of access, software, sub-processors and data-retention practices.
Schedule 4. Approved Sub-Processors for Client Personal Data
Your private agreement will name each approved sub-processor that can handle Client-controlled personal data for the Services, its purpose, the data involved, and its processing location and transfer arrangements. If none is approved, the completed list must explicitly say “None”.
Client authorisation must be recorded. Signing a completed private version can authorise the specifically listed appointments; later appointments or changes must follow clause 17. This public page does not approve any supplier.
This schedule covers Client-controlled personal data processed for the Services. The Supplier’s separate business contact and signature records are covered by clause 14 and the relevant privacy information. That distinction is not permission to send care records through a signing service.
Before these terms are used
- Confirm the Client’s legal identity, the signatory’s authority, the work, fees, dates, support limits and all four schedules in the private agreement.
- Review the proposed version 1.2 formation and liability terms with a UK solicitor for the work concerned. The Supplier contracts personally, and neither professional indemnity nor cyber/data-liability insurance is currently in place. Publication is not legal approval.
- Check the current controller and processor requirements, including lawful instructions, confidentiality, security, approved sub-processors, assistance, return or deletion, and audit rights.
- Record the applicable lawful basis and any additional conditions for special-category or criminal-offence data. Include only the information needed for the agreed work.
- Check any restricted international transfer and the provider, privacy and evidence arrangements for the chosen signing method before it is used.
- Give both parties the complete private document to review, correct and keep. Changes to a version entering signing require a new review and fresh signatures.
The requirement for both parties to sign in clause 1 is a proposed term of this agreement, not a statement that every business contract must be made that way. For background, read the Law Commission’s guidance on electronic signatures and the ICO’s guidance on controller and processor contracts. This reference copy is not a substitute for legal advice.
