Records of Processing Activities (RoPA)
A record of the processing Consenta carries out, as required by UK GDPR Article 30.
Last updated: 1 July 2026
1. Controller / processor details
Operator: Manorath, LLC, doing business as Consenta (“Consenta”, “we”, “us”). Data-protection contact: [email protected].
2. Purposes of processing
- Operating patient accounts, recording consent and paying revenue shares.
- Enabling partner organisations to anonymise and publish datasets.
- Enabling approved buyers to license anonymised datasets.
- Securing the platform and maintaining an audit trail.
3. Categories of data subjects and data
- Patients — account details, consent records, earnings; special-category health data is processed only in anonymised form on the platform.
- Organisation and buyer users — account and contact details, organisation name.
- Anonymised datasets — no data that can reasonably identify an individual.
4. Recipients, retention and safeguards
- Recipients — approved buyers receive anonymised extracts only; no raw data is shared.
- Retention — account and consent records are kept while an account is active and for any period required by law; anonymised datasets are retained under licence terms.
- Security — encryption, access control, rate limiting, lockout and audit logging as described in our DPIA and DPA.