Terms for a SaaS product handling health data

Customer terms for a software product that processes health information, for clinics, providers, employers or individuals, drafted for a fixed fee of £995 in five working days.

Share

Terms for a SaaS product handling health data

Terms for a SaaS product that processes health data, drafted for the rules that attach to it, covering special category data and the conditions for processing, the duty of confidence, whether the product is a medical device, what the product is and is not for, security and breach, retention and research use, and liability within consumer and business rules. £995, delivered in five working days.

Buy now, £995

Health data is the category of personal data the law protects most, and a product that processes it has to be built and contracted with that in mind: a condition for processing special category data as well as a lawful basis, the duty of confidence that patient information carries, the question of whether the software is a medical device, security that matches the risk, and terms that say clearly what the product is not, because a health app that implies diagnosis has made a promise. I draft those terms for a fixed fee of £995, delivered in five working days.

Who this is for

Digital health, healthtech and wellbeing businesses in England and Wales whose SaaS product stores or processes health information, whether sold to clinics and providers as a processor, to employers for occupational health or wellbeing, or directly to individuals.

What matters in terms for a product handling health data

Special category data and the conditions for processing

Health data is special category data under Article 9 of the UK GDPR, which prohibits processing it unless a condition applies, with the conditions for health and social care purposes, research and substantial public interest set out in Schedule 1 to the Data Protection Act 2018 and requiring an appropriate policy document. The terms should identify who is controller and on what condition the processing relies: a clinic using the product as a processor relies on its own condition, while a product sold to individuals relies on explicit consent, and the terms and the privacy notice should say which and capture what is needed.

The duty of confidence and who may see what

Patient information carries a common law duty of confidence independent of data protection law, owed by the clinician and extending to those who receive it, and the terms should commit the supplier to confidentiality, restrict access to staff who need it, and prohibit any use of identifiable information beyond providing the service. Where the product is sold to employers for occupational health or wellbeing, the terms should say that the employer does not receive individuals' health information without their consent, because the product's credibility with employees depends on it.

Whether the product is a medical device

Software that is intended to diagnose, prevent, monitor, treat or alleviate disease, or to influence a clinical decision, can be a medical device under the Medical Devices Regulations 2002, requiring conformity assessment and registration before it is placed on the market; software that stores records, schedules appointments or provides general wellbeing information is not. The terms should describe the product's intended purpose in words that reflect the regulatory decision the business has made, because the intended purpose is what the regulator reads, and a marketing claim of diagnosis is an intended purpose.

What the product is for and what it is not

The terms should say that the product does not provide medical advice, diagnosis or treatment unless it is regulated to do so, that it is not a substitute for a clinician, that users should seek medical help in an emergency, and what a professional user remains responsible for in their own clinical judgement. Against consumers those statements must be accurate under Part 4 of the Digital Markets, Competition and Consumers Act 2024 and the liability clause must sit within the Consumer Rights Act 2015; against clinics the terms are business terms tested under the Unfair Contract Terms Act 1977.

Security, breach notification and where data is held

Security must be appropriate to the risk under Article 32 of the UK GDPR, and for health data that means encryption, access controls, audit logs and the certifications health customers ask for; the terms should state the measures, commit to notify a controller customer of a breach without undue delay so that it can meet Article 33, describe where data is hosted and any transfers under Article 46, and list subprocessors. A data protection impact assessment under Article 35 is required for large-scale processing of health data, and the terms should commit the supplier to providing the inputs a customer needs for its own.

Retention, research use and the end of the contract

The terms should state retention periods that respect the records management obligations health customers have, provide for export in a usable format and deletion or return at the end, and address any use of de-identified data for research or product improvement expressly: with the controller's agreement, with anonymisation that meets the standard, and with the research condition in Schedule 1 to the Data Protection Act 2018 where the data remains identifiable. Silence on research use is read as no permission, and consumers will read it as the reverse.

What it costs

SaaS terms of service, £995. Your standard customer-facing terms. Five working days.

Buying online forms the engagement on payment. The scope is what the saas and technology contracts page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A bespoke contract drafted for how your product is sold, delivered and supported
  • Service levels you can meet, with remedies that are proportionate rather than aspirational
  • A liability position that is defensible and will survive enterprise procurement
  • IP and data provisions that fit together rather than contradicting each other
  • A commercial note on where you will get pushback and what is worth conceding
  • One round of amendments

What is not included

  • Negotiating individual enterprise deals, which I quote separately
  • Advice on the law of jurisdictions outside England and Wales
  • Technical security certification or audit
  • Regulatory advice for regulated sectors such as financial services or health

Questions I am often asked

Logging and displaying what the user entered is generally not; interpreting the data to suggest a condition or a course of action can be. The terms describe the intended purpose as the business has decided it, and that decision should be taken with the regulatory criteria in view.

Can a clinic customer rely on our terms for its own data protection compliance?

The terms give the clinic the processor terms and the security commitments it needs. The clinic's own condition for processing, its policy document and its impact assessment remain its responsibility, and the terms say so.

Can we use anonymised health data to train our models?

Only with the controller's agreement, anonymisation that meets the standard, and terms that say so. Health data that remains identifiable needs the research condition and the safeguards that come with it.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.