How Clinexaa processes patient and clinic data on your behalf.
This Data Processing Agreement ("DPA") forms part of the agreement between a Clinic ("Controller") and Hermitz Ventures, operating as Clinexaa ("Processor"), and governs Clinexaa's processing of Patient Data and other personal data on the Controller's behalf. It is designed to reflect the requirements of the EU General Data Protection Regulation (GDPR) and comparable data protection frameworks, and applies automatically to all Clinics using the Platform to process personal data of patients or other data subjects.
This DPA is entered into between the Clinic identified in its Clinexaa Account ("Controller") and Hermitz Ventures, trading as Clinexaa ("Processor"). Terms such as "personal data," "processing," "data subject," "controller," "processor," and "personal data breach" have the meanings given to them under GDPR, and are interpreted consistently with equivalent terms under other applicable data protection law.
This DPA governs Processor's processing of personal data in the course of providing the Platform under the Clinexaa Terms and Conditions. It remains in effect for as long as Processor processes personal data on Controller's behalf, including any period following termination of the Subscription during which data is retained for export or legally required retention purposes.
Categories of data subjects: patients, patients' contacts/guardians, and Controller's staff using the Platform.
Categories of personal data: patient demographics and contact details; medical, consultation, and prescription records; appointment and queue data; billing and insurance records; and, where applicable, pet/owner records for veterinary use.
Nature and purpose: Processor processes this data solely to provide, secure, and support the Platform (storage, retrieval, display, transmission for booking/billing/reminder functions, and backup) in accordance with Controller's documented instructions, as set out in the Clinexaa Terms and configured by Controller within the Platform.
Controller warrants that it has, and will maintain, a valid legal basis for all personal data it processes through the Platform, including any necessary patient consents, and that its instructions to Processor comply with applicable data protection law. Controller is responsible for the accuracy of data it inputs and for configuring Authorized User roles and permissions appropriately.
Processor shall: (a) process personal data only on documented instructions from Controller, including as set out in this DPA and the Terms, unless required to act otherwise by law (in which case Processor will inform Controller, unless prohibited from doing so); (b) ensure persons authorized to process personal data are subject to confidentiality obligations; (c) implement appropriate technical and organizational security measures as described in Section 7; (d) engage Subprocessors only as permitted under Section 8; (e) assist Controller in responding to data subject rights requests as described in Section 9; (f) notify Controller of personal data breaches as described in Section 10; and (g) make available information necessary to demonstrate compliance with this DPA and allow for audits as described in Section 11.
Processor shall ensure that personnel authorized to process personal data have committed to confidentiality obligations or are under an appropriate statutory duty of confidentiality, and that access to Patient Data is restricted to personnel who require it to perform their role in supporting the Platform.
Processor implements technical and organizational measures appropriate to the risk, including: encrypted transmission of data (TLS) between Clinic users and the Platform; role-based access control within each Clinic's isolated tenant environment; administrative access restrictions and credential management for production systems; regular data backups; and a process for identifying and remediating security vulnerabilities. These measures are reviewed periodically and updated as the Platform and threat landscape evolve. Controller acknowledges that no system can guarantee absolute security, and that Controller remains responsible for the security of its own credentials, devices, and network access to the Platform.
Controller provides general authorization for Processor to engage Subprocessors necessary to deliver the Platform, including for payment processing (Stripe), messaging delivery (WhatsApp Business Platform / Meta), authentication and analytics (Google), and infrastructure/hosting. Processor will impose data protection obligations on each Subprocessor materially no less protective than those in this DPA, and will remain liable for Subprocessor performance. A current list of Subprocessors is maintained and available to Controller on request at hello@hermitz.com. Processor will provide reasonable advance notice of any new Subprocessor that will process Patient Data, allowing Controller an opportunity to object on reasonable data protection grounds.
Processor shall, taking into account the nature of the processing, provide reasonable assistance to Controller — through appropriate technical and organizational measures within the Platform (such as data export and deletion tools) and direct support where needed — to enable Controller to respond to requests from data subjects exercising their rights under applicable data protection law.
Processor shall notify Controller without undue delay, and in any case within 72 hours of becoming aware, of any confirmed personal data breach affecting Controller's data, providing available information regarding the nature of the breach, likely consequences, and measures taken or proposed to address it. Controller is responsible for assessing whether the breach triggers notification obligations to data protection authorities or affected individuals under applicable law.
Processor will make available to Controller information reasonably necessary to demonstrate compliance with this DPA. Where Controller has a reasonable, documented basis to request a more detailed audit (such as a regulatory requirement), the parties will agree on the scope, timing, and confidentiality terms of such audit in good faith, which may be satisfied through a written security questionnaire, summary audit report, or an on-site/remote review subject to reasonable notice and confidentiality safeguards.
Upon termination of the Subscription, Processor will make Controller's data available for export for the period described in the Refund & Cancellation Policy, after which Processor will delete or anonymize the data within a commercially reasonable timeframe, except to the extent retention is required by applicable law (such as financial recordkeeping).
Where processing involves the transfer of personal data across borders (including to Subprocessors located outside the Controller's jurisdiction), Processor will implement appropriate safeguards consistent with applicable data protection law, which may include standard contractual clauses, adequacy determinations, or equivalent mechanisms. Controllers operating under data residency requirements specific to their jurisdiction (for example, UAE health data localization rules) should contact hello@hermitz.com to discuss available configuration options.
Each party's liability arising out of or in connection with this DPA is subject to the limitation of liability provisions set out in the Clinexaa Terms and Conditions.
This DPA is governed by the laws of the United Arab Emirates, consistent with the governing law provision of the Clinexaa Terms and Conditions, except where mandatory data protection law applicable to Controller's jurisdiction requires otherwise.
Hermitz Ventures — Clinexaa
Email: hello@hermitz.com
WhatsApp / Phone: +971 54 438 1614
Location: Dubai, United Arab Emirates