eLogbookAI

Terms of Service

Effective date: 12 Aug 2026Version: 1.0.0Apeiron Digital Labs Ltd (trading as eLogbookAI)

1. Parties, status and contract

1.1 These Terms of Service ("Terms") are a contract between Apeiron Digital Labs Ltd, a company registered in England and Wales with company number 16382596 ("Company", "we", "us" or "our"), and the individual doctor who creates and uses an eLogbookAI account ("Subscriber", "you" or "your"). eLogbookAI and the related websites, software and processing functions are the "Service".

1.2 The Service is available only to an individual who is at least 18 years old, is a GMC-registered doctor with a licence to practise, uses the Service in the United Kingdom, and uses it wholly and exclusively for an authorised professional surgical-logbook purpose.

1.3 You contract in your individual professional capacity. An employer, NHS Trust, hospital or other organisation does not become a party merely because it employs you, supplies a source record, reimburses you, or permits you to use the Service.

1.4 The parties intend this to be a professional-use contract rather than a consumer contract. Nothing in these Terms excludes a right or remedy that applicable law does not permit the parties to exclude, and any provision affected by such a right applies only to the fullest lawful extent.

1.5 By creating an account, accepting the versioned legal-document set, or using the Service, you agree to these Terms. You must not accept or use the Service if you do not satisfy clause 1.2 or cannot comply with these Terms.

2. Definitions

2.1 "Account Data" means personal data that we process as controller to create, administer, secure and support your account and the Service.

2.2 "CPI" means Confidential Patient Information. It includes patient information in an authorised theatre-list image and associated extracted fields, and may include special-category health data.

2.3 "Controller Personal Data" means personal data that we process on your behalf as Processor under Schedule 1. It principally consists of transient CPI used for your professional-logbook workflow.

2.4 "Output" means information extracted, classified, calculated or arranged by the Service for your review. Output is not an authoritative clinical or professional record.

2.5 "Privacy Policy" means the versioned eLogbookAI Privacy Policy presented with these Terms. "Register" means the versioned eLogbookAI Sub-Processor Register presented with these Terms.

2.6 "Schedule" means Schedule 1, the Article 28 Data Processing Schedule forming part of these Terms. "Applicable Data Protection Law" means the UK GDPR, the Data Protection Act 2018 and other data-protection law applying to the relevant processing, in each case as amended.

2.7 "Private Beta" means the current invitation-only pre-release phase of the Service, during which the Company individually approves participants and continues to test, evaluate and develop the Service with a limited cohort of real users.

3. Professional eligibility and authority

3.1 You must maintain your GMC registration and licence to practise and keep your account information accurate and current. We may verify your status and suspend access if we cannot verify it or reasonably believe you no longer satisfy clause 1.2.

3.2 You must have lawful access to every source record you use and all authority required by the organisation responsible for it. This includes any applicable local information-governance, confidentiality, Caldicott, employer or contractual approval.

3.3 The NHS Trust, hospital or other organisation that issued a theatre list remains responsible for that source record. These Terms, your account, and our processing declaration do not grant access to a source record or replace any local approval.

3.4 You must stop uploading immediately if your authority is withdrawn, your recorded declaration ceases to be true, or you can no longer give a lawful processing instruction.

4. Contract documents, instructions and precedence

4.1 The contract includes these Terms and Schedule 1. The Privacy Policy explains our controller processing and describes current processing and deletion controls. The Register identifies service providers and transfer arrangements. The versioned CPI authorisation declaration records your Controller authority, and the per-upload confirmation provides a documented instruction for that upload.

4.2 Your acceptance record identifies the five document versions presented to you and a digest derived from that version tuple. The digest identifies the accepted versions; it is not a cryptographic hash of the documents' text.

4.3 If documents conflict, Schedule 1 prevails for our processing of Controller Personal Data. Subject to that, these Terms prevail. The Privacy Policy, Register and declaration support and explain the contract but do not override the Terms or Schedule unless the relevant provision expressly says otherwise.

4.4 A patient has not consented merely because you accept the legal-document set or confirm an upload. Those acts record your authority and instructions as Controller; they are not patient consent or the lawful basis for processing.

5. Service scope and human review

5.1 The Service assists a doctor to prepare a professional surgical-logbook entry. It receives an authorised theatre-list image, uses automated tools to extract and classify relevant information, presents Output for review, and may transmit a reviewed entry to elogbook.org when you instruct it to do so.

5.2 Automated extraction and classification can be incomplete, inaccurate, inconsistent or fabricated. You must compare every Output with the authoritative source, correct or reject errors, and approve the final entry before instructing submission.

5.3 You remain professionally responsible for the accuracy, completeness, necessity and lawful use of every entry you approve. You must maintain any authoritative clinical or professional record in the appropriate system.

5.4 The Service is a processing conduit, not a patient-record or logbook archive. It is designed not to add source images or complete extraction results to your account or a long-term application datastore. Transient copies are nevertheless processed and deleted using the controls described in the Privacy Policy and Schedule 1; deletion is not instantaneous or guaranteed at an exact time.

6. CPI and your Controller responsibilities

6.1 For the professional-logbook processing of Controller Personal Data, you are the Controller and we are the Processor. Schedule 1 applies to that processing. Legal status is determined by the facts and Applicable Data Protection Law, not merely by the labels in these Terms.

6.2 You determine the purpose and permitted scope of each upload. You must upload only the minimum information reasonably necessary for your own authorised professional logbook and must not upload a source merely because it is convenient to do so.

6.3 Before processing, you must determine, document and maintain an applicable Article 6 lawful basis, Article 9 condition and any required Data Protection Act 2018 Schedule 1 condition. You are also responsible for required transparency, rights handling and local governance.

6.4 You instruct us to process Controller Personal Data only as set out in the accepted document set, your versioned authorisation, each per-upload confirmation, and any later written instruction that we accept under Schedule 1.

6.5 You must not include CPI in support messages, feedback, analytics forms, general email or any input field not expressly provided for authorised CPI processing.

6.6 We are controller for Account Data and our own service-administration processing, as described in the Privacy Policy.

6.7 We act as controller for operational audit records used for accountability, security, legal compliance and incident investigation. These records are associated with the Subscriber but are designed to exclude patient names, patient identifiers, source images and clinical content. Their contents and retention are described in the Privacy Policy.

7. Clinical and other excluded uses

7.1 The Service is an administrative professional-logbook tool. It is not a medical device, clinical record, diagnostic or treatment system, clinical decision-support tool, emergency service, or substitute for professional judgement or the source record.

7.2 You must not use the Service for diagnosis, treatment, prescribing, triage, patient monitoring, clinical decisions, emergencies, patient communications, research, model training, bulk health-record processing or any purpose unrelated to your authorised professional logbook.

7.3 You must not rely on an Output to provide care or alter a patient record. If an Output appears clinically significant or inconsistent with the source, use the appropriate clinical system and escalation route independently of the Service.

8. Acceptable use

8.1 You must use the Service lawfully, professionally and only for its intended purpose. In particular, you must not:

  • 8.1.1 upload information you are not authorised to access or process, another professional's material, or information that is excessive for your logbook purpose;
  • 8.1.2 use another person's account, allow another person to use yours, misstate your identity or GMC registration, or conceal who is issuing an instruction;
  • 8.1.3 probe, bypass or interfere with authentication, rate limits, deletion controls, access restrictions, security monitoring or the processing-agreement gate;
  • 8.1.4 introduce malicious code, automate abusive requests, overload the Service, scrape it, reverse engineer it except where law expressly permits, or use it to develop a competing extraction service;
  • 8.1.5 use Output or the Service in a way that infringes confidentiality, privacy, intellectual-property or other rights; or
  • 8.1.6 use the Service where doing so would breach a restriction imposed by your employer, the source-record controller, elogbook.org or applicable law.

8.2 You must promptly tell us at legal@elogbook.ai if you become aware of unauthorised access, an unlawful upload, a processing error that may create a risk to an individual, or another material breach of these Terms.

9. Accounts and security

9.1 Your account is personal and non-transferable. You must use supported authentication, keep your devices and linked accounts secure, and promptly report suspected compromise.

9.2 You are responsible for instructions issued through your authenticated account unless the unauthorised use resulted from our breach of these Terms or a duty we cannot lawfully exclude and you took reasonable steps to protect and report the account.

9.3 We may require re-verification, re-authentication or reacceptance of a materially changed legal-document set before allowing further CPI processing.

10. Service providers and elogbook.org

10.1 We use service providers to host, secure, operate and administer the Service. Where a provider processes Controller Personal Data on our behalf, it is engaged as a sub-processor under Schedule 1 and is identified in the Register.

10.2 elogbook.org is a separate third-party service and a user-selected destination. It is not operated by us, is not our sub-processor under this contract, and is not affiliated with or endorsed by us. We currently have no contract with its operator.

10.3 When you connect an elogbook.org account and approve an entry, you instruct us to transmit that entry to elogbook.org using your account access. You are responsible for your right to use that destination, its terms, the accuracy of the submission and the resulting record. Its own processing and availability are outside our control.

10.4 We may suspend or remove the integration promptly if its operator objects, a security or compliance concern arises, access is withdrawn, or continued operation may be unlawful. We do not guarantee that the integration will remain available.

11. Private Beta access, fees and plans

11.1 Private Beta access

The current Service is an invitation-only Private Beta made available without an availability or support service level. We individually approve participants and may limit participants, uploads, features or access while we test and develop it. Free access does not create a right to continued free use or to any future feature.

11.2 Paid offers

We may introduce a paid plan or a one-time lifetime-access offer. Before you buy, the order page will state the price, taxes, included tier or features, payment timing, whether any charge recurs, and any offer-specific restrictions. No charge will recur unless that is clearly disclosed and you expressly agree before purchase.

11.3 Meaning of lifetime access

A "lifetime-access" purchase means access to the purchased Service tier for as long as the Company continues to operate that tier or a reasonably equivalent eLogbookAI service. It does not mean the Subscriber's lifetime, guarantee that the Service or Company will exist indefinitely, include every future product or paid add-on, or prevent changes reasonably needed for security, law, provider availability or sustainable operation. This definition must be shown prominently with the offer.

11.4 Payment

You authorise our payment provider to collect the disclosed charges and must provide accurate billing information. Prices are inclusive or exclusive of VAT as stated at checkout. The payment provider may process information under its own terms and privacy notice.

11.5 Cancellation and refunds

You may cancel a recurring plan before its next renewal using the method stated at checkout or, while no self-service route is available, by emailing legal@elogbook.ai. Cancellation stops future renewal and normally takes effect at the end of the paid period. A lifetime-access purchase has no recurring renewal to cancel. Fees already paid are non-refundable except where the offer expressly says otherwise, we fail to provide purchased access, or applicable law requires a refund.

11.6 Ending paid access does not by itself delete your account. During the Private Beta, request account closure or erasure by emailing privacy@elogbook.ai. We will handle personal data as described in the Privacy Policy and Schedule 1.

12. Licence, intellectual property and Output

12.1 Subject to these Terms, we grant you a personal, limited, revocable, non-exclusive, non-transferable right to access and use the Service for your authorised professional-logbook purpose during your permitted access period.

12.2 We and our licensors retain all rights in the Service, software, workflows, branding, documentation and improvements. These Terms do not transfer ownership of our technology or of any third-party service.

12.3 You retain any rights you have in material you lawfully provide. You grant us only the limited rights needed to process it on your instructions, provide and secure the Service, comply with law, and enforce these Terms. You do not grant us a right to use CPI for advertising or to train or fine-tune an AI model.

12.4 As between you and us, you may use reviewed Output for your authorised professional logbook. We do not claim ownership of patient facts, the source record, or a final professional entry merely because the Service assisted in preparing it. Third-party rights and destination terms continue to apply.

12.5 If you voluntarily provide feedback that contains no CPI or confidential information, you permit us to use it without restriction or payment to improve the Service. This does not permit us to identify you publicly without permission.

13. Availability, support and Service changes

13.1 The Private Beta is under active development. It may contain defects and may be unavailable, slow or changed without a service-level commitment. We do not promise uninterrupted operation, a particular recovery time, compatibility with every device, or continued availability of a provider or integration.

13.2 We may change, limit or discontinue features where reasonably necessary to develop the Service, address risk, comply with law, respond to a provider change or keep the Service viable. We will not use this clause to remove the essential benefit of a paid offer arbitrarily.

13.3 We may temporarily freeze CPI uploads or other functions without notice where reasonably necessary for safety, security, deletion assurance, legal review or incident response. The Service is designed to fail closed when the required legal-document set is unapproved or inconsistent.

13.4 Any support is provided on a reasonable-efforts basis through the contact route we publish. No response or resolution time applies unless we agree one in a separate written order.

14. Suspension and termination

14.1 You may stop using the Service at any time and may request account closure as described in clause 11.6. Your payment consequences are governed by clause 11.

14.2 We may suspend an account, reject an upload or terminate access immediately where we reasonably believe this is necessary to protect patients or other people, prevent unlawful or unauthorised processing, contain a security incident, obey law or a regulator, protect the Service, or address a material breach.

14.3 For another remediable material breach, we may give you a reasonable opportunity to remedy it before termination. We may discontinue free Private Beta access on reasonable notice where practicable.

14.4 On termination, your licence ends and you must stop using the Service. Because the Service is not a logbook archive, you must ensure that approved entries are held in the appropriate destination. Controller Personal Data and other personal data are handled under Schedule 1 and the Privacy Policy.

14.5 Clauses intended by their nature to continue after termination do so, including provisions on intellectual property, accrued payment obligations, liability, indemnity, data protection, confidentiality, dispute resolution and general interpretation.

15. Warranties and disclaimers

15.1 We will provide the Service with reasonable care and skill, subject to its Private Beta status, intended administrative purpose and limitations stated in these Terms.

15.2 We do not warrant that Output is accurate, complete or suitable without review; that the Service will meet a clinical, regulatory, employer, portfolio or training requirement; or that elogbook.org will accept, preserve or treat a submission in a particular way.

15.3 Except for express terms and terms implied by law that cannot be excluded, the Service and Output are provided as available. No statement outside these Terms creates a warranty unless we expressly agree it in writing.

16. Liability

16.1 Nothing in these Terms excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, deliberate unlawful conduct, or any other liability that cannot lawfully be excluded or limited. Nothing limits either party's direct statutory responsibilities under Applicable Data Protection Law.

16.2 Subject to clause 16.1, we are not liable for an indirect or consequential loss, or for loss of profit, revenue, business, anticipated saving, goodwill, opportunity or data, arising from the Service. This does not exclude the reasonable direct cost of restoring data where loss was caused by our breach and restoration is possible.

16.3 Subject to clause 16.1, we are not liable for a loss caused by your failure to review Output, an unlawful or excessive upload, loss of your local authority, your professional or clinical decision, an inaccurate source record, your account or device compromise, or the act, omission or unavailability of elogbook.org or another third party outside our reasonable control, except to the extent our own breach materially caused the loss.

16.4 Subject to clause 16.1, our total aggregate liability arising out of or relating to the Service and these Terms in any 12-month period is limited to the greater of £100 and the fees you paid for the affected Service during that period. For a one-time lifetime-access purchase, the relevant fees include the price paid for that purchase even if it was paid more than 12 months before the event giving rise to the claim.

16.5 Each party must take reasonable steps to avoid and reduce losses. The limitations in this clause apply to contract, tort including negligence, misrepresentation, restitution and any other cause of action, to the fullest extent permitted by law.

17. Subscriber indemnity

17.1 You will indemnify us against a third-party claim and the reasonable, properly incurred loss resulting from your knowing or negligent upload of information you were not authorised to process, your material breach of clauses 3, 6, 7 or 8, or your deliberate misuse of the Service.

17.2 The indemnity does not apply to the extent the claim or loss was caused by our breach, negligence or processing outside your lawful instructions. We must notify you promptly, allow you reasonable participation in the defence, take reasonable steps to mitigate loss, and not settle a claim imposing an admission or non-monetary obligation on you without your consent, not to be unreasonably withheld.

17.3 This clause does not transfer either party's statutory data-protection responsibility or prevent a data subject or regulator from exercising a statutory right.

18. Changes to these Terms and notices

18.1 We may update the legal-document set as the Private Beta develops, law or guidance changes, legal advice is received, or features and providers change. We will version each changed document in accordance with our legal-document governance.

18.2 For a legally material change, we will ordinarily give at least 14 days' advance notice by email. We may use a shorter period where a change is required urgently for law, security, patient protection or to address a third-party restriction. A material change will take effect only after the stated date and any reacceptance required by the Service.

18.3 Contractual notices to us must be sent to legal@elogbook.ai. Privacy requests should be sent to privacy@elogbook.ai. We may send notices to the email address associated with your account, and you must keep it current. Email is treated as received on the next working day unless the sender receives a delivery-failure notice.

18.4 This email-notice clause does not alter a mandatory legal rule about service of proceedings or statutory documents. Formal service on the Company may be made at its registered office where applicable law requires or permits it.

19. General terms

19.1 We may assign or transfer this contract as part of a reorganisation, financing, sale of the business or transfer of the Service, provided this does not materially reduce your rights. You may not assign it without our written consent because access and professional verification are personal to you.

19.2 A delay or failure to enforce a right is not a waiver. A waiver is effective only for the specific matter stated in writing.

19.3 If a provision is unlawful or unenforceable, it is to be read down to the minimum extent necessary or removed, and the remaining provisions continue to apply.

19.4 These Terms and the documents incorporated under clause 4 are the entire agreement about the Service. Neither party relies on a statement not included in them, but this does not exclude liability for fraud or fraudulent misrepresentation.

19.5 Nothing creates a partnership, employment, agency, fiduciary or clinical-supervision relationship between the parties. You cannot bind the Company, and the Company does not supervise your professional practice.

19.6 A person who is not a party has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce these Terms. This does not affect a data subject's, regulator's or other person's rights under applicable law.

20. Governing law and jurisdiction

20.1 These Terms and any non-contractual dispute arising from them are governed by the law of England and Wales.

20.2 The courts of England and Wales have exclusive jurisdiction, subject to any mandatory right under applicable law that cannot validly be excluded for a particular Subscriber or dispute.

Schedule 1 — Article 28 Data Processing Schedule

Schedule version: 1.0.0. This Schedule forms part of the Terms and applies when the Company processes Controller Personal Data on the Subscriber's behalf for the professional-logbook workflow.

Schedule 1 — 1. Roles, scope and precedence

1.1 The Subscriber is the Controller and the Company is the Processor for the processing described in this Schedule. Each party shall comply with its own obligations under Applicable Data Protection Law.

1.2 This Schedule applies only to Controller Personal Data. It does not make the Company a processor for Account Data, operational audit records, billing data, or the Company's own security, legal-compliance and service-administration processing described in the Privacy Policy.

1.3 The parties acknowledge that legal roles follow the facts. If Applicable Data Protection Law determines a different role for particular processing, the parties shall cooperate to document and comply with that role, and neither party may rely on this Schedule to avoid a statutory duty.

1.4 This Schedule prevails over the general Terms for the processing of Controller Personal Data. The accepted Privacy Policy, Register, authorisation declaration and per-upload confirmation provide further documented instructions where consistent with this Schedule.

1.5 elogbook.org is a separate destination selected by the Controller and is not a sub-processor appointed by the Processor under this Schedule. The Controller's instruction to submit permits the Processor to transmit the reviewed entry to that destination. This Schedule does not determine elogbook.org's own legal role.

Schedule 1 — 2. Processing particulars

2.1 Subject matter

Transient processing of an authorised theatre-list image and extracted information to prepare, present for review and, when instructed, submit the Controller's professional surgical-logbook entry.

2.2 Duration

For the term of the contract and, for each upload, from receipt until processing, review delivery or instructed submission and deletion under the documented controls. Any Controller Personal Data remaining when the Service ends is handled under clause 11 of this Schedule.

2.3 Nature and operations

  • 2.3.1 transmission through the Subscriber's browser, service edge and London-hosted application components;
  • 2.3.2 restricted transient storage of the source image and processing result;
  • 2.3.3 automated extraction, transformation and classification, including conversion of date of birth to age and exclusion of patient names from the intended Output;
  • 2.3.4 presentation of Output for mandatory human review and correction;
  • 2.3.5 transmission to elogbook.org only when the Controller instructs it; and
  • 2.3.6 job coordination, access control, security, incident response and deletion associated with that processing.

2.4 Purpose

The Controller's authorised professional-logbook workflow only. The Processor shall not use Controller Personal Data for advertising, unrelated analytics, research, model training or another independent purpose.

2.5 Personal-data types

Information visible in an authorised theatre-list image may include patient name, NHS number, medical-record or other patient identifier, date of birth and derived age, procedure, operation date, hospital, consultant, CEPOD classification, laterality, ASA grade, supervision level, and other information incidentally visible in the image. It includes special-category health data. Intended Output excludes the patient's name and date of birth but may include the other logbook fields stated in the Privacy Policy.

2.6 Data subjects

Patients appearing on an authorised theatre list and healthcare workers or other staff whose names, roles or activities appear in that source.

Schedule 1 — 3. Controller rights and obligations

3.1 The Controller shall determine and document the lawful purpose and data scope, Article 6 basis, Article 9 condition, any Data Protection Act 2018 condition, transparency arrangements, retention instruction, and authority from the controller of the source record.

3.2 The Controller shall minimise each upload, issue only lawful and documented instructions, review Output before use, withdraw or correct an instruction that is no longer lawful, and respond to data subjects and regulators as required by law.

3.3 The Controller may issue, amend or withdraw instructions in a durable written form accepted by the Processor; request reasonable assistance and compliance information; object to a proposed sub-processor under clause 7 of this Schedule; exercise the audit rights in clause 10 of this Schedule; and choose deletion or return under clause 11 of this Schedule where return is technically possible.

3.4 The Controller shall not instruct processing beyond the subject matter, purpose or excluded-use restrictions in these Terms without first agreeing a written amendment with the Processor.

Schedule 1 — 4. Documented instructions

4.1 The Processor shall process Controller Personal Data only on the Controller's documented instructions, including for a transfer outside the United Kingdom, unless UK law requires the Processor to do otherwise.

4.2 The accepted versioned legal-document set, Controller authorisation declaration, per-upload confirmation, selections made in the Service, and later written instructions accepted by the Processor together constitute documented instructions.

4.3 If UK law requires processing beyond the Controller's instruction, the Processor shall inform the Controller of that legal requirement before processing unless the law prohibits the information on important grounds of public interest.

4.4 The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law. It may suspend the affected processing while the parties clarify, amend or withdraw the instruction.

Schedule 1 — 5. Confidentiality and authorised persons

5.1 The Processor shall ensure that each person authorised to process Controller Personal Data has committed to confidentiality or is under an appropriate statutory duty of confidentiality.

5.2 The Processor shall restrict access to persons who need it for an authorised duty, provide appropriate data-protection and security instruction, and remove access when it is no longer required.

5.3 The Processor shall not disclose Controller Personal Data to another person except on the Controller's instruction, under clause 7 of this Schedule, or where law requires it.

Schedule 1 — 6. Security measures

6.1 Taking account of the state of the art, implementation cost, processing context and risks to individuals, the Processor shall maintain appropriate technical and organisational measures meeting Article 32 UK GDPR.

6.2 The current measures include, as appropriate to the relevant component:

  • 6.2.1 authenticated, version-gated and per-upload authorised access before CPI is accepted;
  • 6.2.2 encryption in transit and provider-supported encryption at rest, including customer-managed encryption for transient object storage;
  • 6.2.3 access controls, service identities, restricted service-to-service paths and separation of application privileges;
  • 6.2.4 data minimisation, intended exclusion of patient names and dates of birth from Output, and prevention by design of source images and complete results entering the long-term account datastore;
  • 6.2.5 immediate best-effort deletion after terminal processing, periodic state-aware deletion sweeps and an asynchronous storage-lifecycle backstop, as described in the Privacy Policy;
  • 6.2.6 application-layer insert-only CPI processing-event records designed to exclude patient content, with access restricted to internal administration;
  • 6.2.7 security logging, monitoring, incident handling, dependency and configuration review; and
  • 6.2.8 resilience and backup measures for persistent account and operational data, without treating transient CPI as a recoverable archive.

6.3 The Processor may replace a measure with one that provides an equivalent or higher level of protection, taking account of the risks. It shall not materially reduce the overall protection of Controller Personal Data during the contract.

6.4 No security or deletion control is infallible. The Processor does not represent that its audit records are cryptographically immutable, that all processing occurs only in the United Kingdom, or that deletion, recovery or availability will occur at an exact guaranteed time.

Schedule 1 — 7. Sub-processors and transfers

7.1 The Controller gives general written authorisation for the Processor to use the sub-processors identified in the accepted Register for the purposes and data categories stated there.

7.2 Before a sub-processor processes Controller Personal Data, the Processor shall carry out appropriate due diligence and enter a written contract imposing data-protection obligations that provide an equivalent level of protection to the obligations required by Article 28(3), so far as applicable to the delegated processing.

7.3 The Processor shall give the Controller at least 14 days' advance notice by email of an intended addition or replacement that will process Controller Personal Data. Where an urgent security, legal, availability or provider event makes advance notice impracticable, it shall notify the Controller as soon as reasonably practicable and explain the reason for the urgency where lawful.

7.4 The Controller may object during the notice period on reasonable data-protection grounds, explaining those grounds in writing. The parties shall work in good faith to address the objection. If no reasonable alternative is available, the Processor may suspend the affected processing and either party may terminate the affected Service. Any refund is governed by clause 11 of the Terms and applicable law.

7.5 The Processor remains liable to the Controller for its sub-processor's performance of the data-protection obligations imposed on it, subject to Applicable Data Protection Law and the lawful contractual limits in clause 16 of the Terms.

7.6 The Processor shall ensure that a restricted transfer of Controller Personal Data uses a lawful transfer mechanism and any supplementary measures required by Applicable Data Protection Law. Current locations and mechanisms are identified in the Register.

Schedule 1 — 8. Data-subject rights

8.1 Taking account of the nature of the processing, the Processor shall assist the Controller through appropriate technical and organisational measures, so far as possible, to fulfil its obligations to respond to requests under Chapter III UK GDPR.

8.2 If the Processor receives a request relating to Controller Personal Data, it shall notify the Controller without undue delay and shall not respond substantively except on the Controller's documented instruction or where law requires it.

8.3 Assistance may include locating, restricting, correcting, exporting or deleting data that remains technically available. The Processor is not required to recreate transient Controller Personal Data that has already been securely deleted in accordance with the instructions.

Schedule 1 — 9. Articles 32 to 36 assistance and breaches

9.1 Taking account of the nature of processing and information available to it, the Processor shall reasonably assist the Controller with security under Article 32, personal-data-breach assessment and notifications under Articles 33 and 34, data-protection impact assessments under Article 35, and prior consultation under Article 36.

9.2 The Processor shall notify the Controller without undue delay and, in any event, aim to give initial notice within 24 hours after becoming aware of a personal data breach affecting Controller Personal Data. The Processor may provide information in phases and shall not delay initial notice because an investigation is incomplete.

9.3 So far as known, notice shall describe the nature of the breach, affected data and data subjects, likely consequences, containment and mitigation, and a contact point. The Processor shall provide material updates and reasonable cooperation. Notice is not an admission of fault or liability.

9.4 The Controller remains responsible for deciding whether and how to notify the Information Commissioner, a data subject or another person. The Processor shall not notify them about the Controller's breach without instruction unless law requires it.

Schedule 1 — 10. Compliance information, audits and inspections

10.1 The Processor shall make available information reasonably necessary to demonstrate compliance with Article 28 and this Schedule, and shall allow for and contribute to audits and inspections by the Controller or an independent auditor mandated by it.

10.2 For a routine audit, the Controller shall ordinarily give at least 20 working days' notice, conduct no more than one audit in any 12-month period, use existing reports and documentary evidence first, and use remote review where it can provide reasonable assurance. An on-site audit shall occur during normal business hours and minimise disruption.

10.3 The routine limits in clause 10.2 of this Schedule do not apply where a regulator requires an audit, a personal data breach has occurred, or the Controller has reasonable evidence of material non-compliance. They shall never operate to prevent an audit required by Applicable Data Protection Law.

10.4 The Controller shall ensure its auditor is independent, competent, not a competitor of the Processor, and bound by confidentiality. An audit must not expose another customer's information, compromise security, or require access beyond what is reasonably necessary.

10.5 The Controller bears its audit costs and the Processor's reasonable additional costs of a routine audit. The Processor bears its own reasonable costs where the audit establishes its material breach of this Schedule. Each party bears its costs of responding to a regulator unless law determines otherwise.

Schedule 1 — 11. Return and deletion

11.1 At the end of the provision of processing services, the Processor shall, at the Controller's choice, return Controller Personal Data that remains technically available and then delete it, or delete it without return, and shall delete existing copies unless UK law requires storage.

11.2 The Service does not maintain a long-term copy of a theatre-list image, extraction result or completed professional logbook. Once transient Controller Personal Data has been deleted, it cannot be returned or recreated by the Processor. The Controller is responsible for preserving an approved entry in the appropriate destination before deletion.

11.3 During ordinary processing, immediate deletion is attempted after successful processing or the final failed attempt and after a result is delivered. State-aware sweeps and a storage-lifecycle rule provide additional deletion controls. The detailed current timings and qualifications are stated in the accepted Privacy Policy and form part of the Controller's deletion instruction.

11.4 If UK law requires the Processor to retain Controller Personal Data, it shall inform the Controller unless prohibited, isolate and protect the retained data, process it only for the legally required purpose, and delete it when the requirement ends.

11.5 A sub-processor may complete secure deletion on its documented deletion cycle where immediate physical deletion from backup or resilient storage is not technically possible, provided the data is put beyond ordinary use, remains protected and is deleted as soon as reasonably practicable under the applicable provider terms.

11.6 Operational audit records are Company-controller records under clause 6.7 of the Terms, not the Controller's retained logbook or a copy of Controller Personal Data intended for return. Their retention and erasure are governed by the Privacy Policy, Applicable Data Protection Law and any applicable individual right.

Schedule 1 — 12. Records, direct duties and termination

12.1 The Processor shall maintain the records of processing required of it by Applicable Data Protection Law and shall cooperate reasonably with the Information Commissioner in performing the Commissioner's tasks.

12.2 Nothing in this Schedule relieves either party of a direct statutory responsibility or liability. If the Processor determines the purposes and means of processing contrary to the Controller's instructions, Article 28(10) applies to that processing.

12.3 The Controller shall promptly tell the Processor when processing must cease. Termination or expiry of the Terms ends the Processor's authority to process Controller Personal Data except as necessary to carry out clause 11 of this Schedule or comply with law.

12.4 Clauses in this Schedule concerning confidentiality, compliance evidence, liability and deletion continue for as long as the Processor or a sub-processor retains Controller Personal Data.

Apeiron Digital Labs Ltd (trading as eLogbookAI) · Version 1.0.0 · Effective 12 Aug 2026