All policies

Records of Processing Activities (RoPA)

A record of the processing Consenta carries out, as required by UK GDPR Article 30.

Last updated: 1 July 2026

1. Controller / processor details

Operator: Manorath, LLC, doing business as Consenta (“Consenta”, “we”, “us”). Data-protection contact: [email protected].

2. Purposes of processing

  • Operating patient accounts, recording consent and paying revenue shares.
  • Enabling partner organisations to anonymise and publish datasets.
  • Enabling approved buyers to license anonymised datasets.
  • Securing the platform and maintaining an audit trail.

3. Categories of data subjects and data

  • Patients — account details, consent records, earnings; special-category health data is processed only in anonymised form on the platform.
  • Organisation and buyer users — account and contact details, organisation name.
  • Anonymised datasets — no data that can reasonably identify an individual.

4. Recipients, retention and safeguards

  • Recipients — approved buyers receive anonymised extracts only; no raw data is shared.
  • Retention — account and consent records are kept while an account is active and for any period required by law; anonymised datasets are retained under licence terms.
  • Security — encryption, access control, rate limiting, lockout and audit logging as described in our DPIA and DPA.