Data Processing Agreement
This DPA governs Clinilo’s processing of ordinary personal data for the Customer under policy ordinary-data-only-2026-08-16. Health data and every other special category are outside the service.
- Status
- Published
- Version
- managed-launch-dpa-2026-08-17
- Effective date
- 2026-08-17
1. Parties, scope and precedence
Customer is the clinic controller identified by the accepted online agreement. Clinilo FZE LLC, registration 4431302, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, is processor. Contact and the appointed EU representative are identified in section 1 of the Platform Terms. This DPA forms part of that online agreement without a signed Order.
The GDPR terms controller, processor, personal data, processing, data subject, supervisory authority and personal-data breach have their statutory meanings. This DPA prevails for processor obligations; mandatory Standard Contractual Clauses prevail for a restricted transfer.
2. Documented instructions
Clinilo processes Customer Personal Data only to provide, secure, support, communicate, export and delete the ordinary-data service; comply with this DPA, the Platform Terms and Customer’s lawful in-product instructions; and comply with binding law. Clinilo immediately informs Customer if an instruction appears unlawful unless prohibited, and pauses the affected processing where practicable.
Policy ordinary-data-only-2026-08-16 is a binding instruction and technical limit: no health data, biometric data, genetic data, racial or ethnic origin, political opinions, religion, trade-union membership, sex-life or sexual-orientation data may be submitted. Clinical paths are disabled. Discovery of prohibited content triggers fail-closed handling and Customer notice rather than authorization to process it.
3. Customer's controller obligations
Customer determines lawful purposes and Article 6 bases, gives transparent notices, respects data-subject rights, limits users and fields, uses neutral service labels, keeps special-category and professional records outside Clinilo, and ensures instructions are lawful. Customer may not direct Clinilo to process prohibited data. Customer remains responsible for clinic services and the accuracy and lawfulness of Customer Data.
4. Confidentiality and authorized personnel
Clinilo limits Customer Personal Data to personnel and subprocessors who need it for assigned duties, are bound by confidentiality and receive privacy and security instructions. Privileged access is least-privilege, time-bounded where supported and auditable. Platform-administrator bootstrap is protected; impersonation cannot accept an agreement or generate an owner export.
5. Security of processing
Clinilo maintains measures appropriate to the ordinary-data scope: tenant scoping and authorization helpers; role and stale-membership rechecks; strong session, reset and handover credentials; TLS in transit; managed encryption at rest; private object storage; environment and secret separation; audit logging; dependency and deployment checks; vulnerability remediation; backups as described below; and incident response, continuity and restoration procedures proportionate to verified provider capabilities.
The Supabase Frankfurt primary database is backed up daily with the current Pro-plan window of the last seven days. Those database backups do not include object-storage files and no point-in-time recovery is represented. The private Cloudflare R2 bucket has EU jurisdiction, public development access disabled and restricted application-origin PUT CORS, but no independent backup, object versioning or object lock is represented. These limits form part of the risk assessment.
6. Subprocessors
Customer generally authorizes only the subprocessors listed in the versioned Subprocessor List and Annex C. Clinilo remains responsible for their processor duties and uses contracts imposing materially equivalent data-protection obligations. Clinilo gives the registered legal contact at least 30 days’ advance notice before a new or replacement subprocessor begins processing, except a documented urgent security or legal need, when it gives as much advance notice as possible.
Customer may object during the notice period on reasonable data-protection grounds. The parties seek a practical safeguard or alternative. If none is reasonably available, Customer may terminate the affected service before the change without a fee. A provider does not begin processing merely because code or an adapter exists.
7. International transfers and governmental requests
Customer’s EEA transfer to Clinilo in the UAE and any onward restricted transfer uses a valid Chapter V mechanism. Where no adequacy decision applies, the parties incorporate the European Commission 2021/914 Standard Contractual Clauses, Module 2 (controller to processor): Customer is exporter, Clinilo is importer, docking applies, optional clause 7 applies, general authorization and the notice period in section 6 apply, Denmark is the chosen Member State for clauses 17 and 18, and the Danish Data Protection Agency is the competent authority where the GDPR so provides. Annexes A to C complete the SCC annexes.
Clinilo assesses transfer law and provider safeguards, minimizes data, restricts access, uses encryption where applicable, challenges disproportionate demands where lawful, documents requests and notifies Customer where permitted. If Clinilo cannot comply with required safeguards, it stops the affected transfer and informs Customer. No special-category data is authorized for transfer.
8. Data-subject requests
Clinilo forwards a request relating to Customer Personal Data to Customer without undue delay and does not answer substantively unless instructed or legally required. Taking account of the processing, Clinilo provides reasonable technical and organizational assistance for access, correction, deletion, restriction, objection and portability. Customer can use product controls, the single-client export and the owner tenant export. Additional work beyond built-in functions is agreed in advance, but Clinilo does not charge for assistance mandatory under Article 28.
9. Personal-data breaches
Clinilo notifies Customer without undue delay after becoming aware of a confirmed breach affecting Customer Personal Data. As information becomes available, notice describes the nature, affected categories and approximate scale, likely consequences, containment and remediation, and a contact. Clinilo preserves relevant evidence, provides updates and reasonably assists Customer’s Articles 33 and 34 assessment. Customer makes controller notifications; Clinilo may notify where law independently requires.
10. DPIAs, consultation and compliance assistance
Clinilo provides information reasonably available about the service, security, subprocessors, transfers and incidents to help Customer meet Articles 32–36. Managed Launch is intentionally limited to ordinary scheduling data and disables health processing; Customer must not use this DPA as evidence that clinical processing is approved. If intended use presents a high risk or requires special-category processing, Customer must not start it in Clinilo.
11. Return, portability and deletion
During the term and exit period an authenticated, non-impersonated owner can obtain the documented archive at /portability without extra charge. It supplies the ordinary-data mode allowed by policy and fails closed if prohibited clinical content is discovered. Tenant return and deletion are documented, operator-led case processes; there is no self-service tenant-deletion button. On Customer’s instruction or termination, Clinilo returns or deletes Customer Personal Data, then deletes remaining ordinary copies after the applicable retrieval period, unless Union or Member-State law requires limited retention. Legally retained copies are isolated and deleted when the duty ends.
Deletion follows live systems and then provider backup expiry. Supabase daily database backups currently retain the last seven days and exclude object-storage files. R2 has no represented version or independent backup to restore after live-object deletion. Clinilo provides a deletion or return confirmation only after the scoped live-system, object, provider and backup evidence required by the offboarding process is recorded; it does not promise destruction of records a provider must retain by law.
12. Information and audit rights
Clinilo makes available current policies, subprocessor records, security descriptions, acceptance archive and other information necessary to demonstrate Article 28 compliance. Customer may audit once per year and after a material incident on reasonable notice, first using documents and remote review. A necessary on-site audit occurs during business hours, avoids other customers’ data and security harm, and is conducted by an independent confidential auditor. Each party bears its own ordinary costs; Clinilo bears reasonable audit costs caused by its material breach.
13. Liability, duration and termination
This DPA starts with the online agreement and continues while Clinilo processes Customer Personal Data. Liability follows the Platform Terms without limiting data-subject rights or regulatory powers. Either party may terminate affected processing where the other materially breaches this DPA and fails to cure within 30 days, or immediately where compliance is impossible. Sections that must protect retained data survive until deletion.
Annex A — Processing details
| Item | Managed Launch instruction |
|---|---|
| Subject matter and purpose | Host and secure ordinary clinic administration, availability, appointment scheduling, client contact, immediate confirmations and receipts, owner notifications, automatic 48-hour email and 24-hour SMS reminders, audit, export and deletion under ordinary-data-only-2026-08-16. |
| Duration and frequency | Continuous during the month-to-month term, exit and deletion period; operations occur when users, clients, jobs and security processes use the service. |
| Data subjects | Clinic owners, staff and business contacts; clients and prospective clients making ordinary appointments; authorized support contacts. |
| Personal-data categories | Names, business contact details, account and role identifiers, neutral service and appointment details, availability, ordinary messages, invoices without online payment, consent/preferences, audit and security metadata, and export records. |
| Special categories | None authorized. Health, clinical, biometric, genetic and all other Article 9 data are prohibited and technically disabled. |
| Operations | Collect, validate, organize, host, retrieve, display, transmit, log, back up within verified limits, export, restrict and delete. |
Annex B — Technical and organizational measures
- Tenant-scoped queries, role-based authorization, stale-membership checks and least-privilege administrative controls.
- TLS, managed encryption at rest, private storage, secret separation, protected deployment environments and verified database targets.
- Individual accounts, secure sessions, atomic password reset, fresh-credential handover, impersonation restrictions and audit events.
- Data minimization, fixed provider payloads, no request bodies in error telemetry and technical blocking of special-category paths.
- Reset, migrate, seed, focused security tests, CI checks, exact-release deployment, health checks and incident response.
- Daily seven-day database-backup window and explicit exclusion of object assets from that backup; no unverified recovery promise.
Annex C — Authorized subprocessors and transfers
| Provider and entity | Purpose and minimized ordinary data | Primary location and transfer safeguard |
|---|---|---|
| Vercel Inc. | Hosts Sites and Dashboard requests, technical headers, credentials and ordinary submitted content. Source configuration pins functions to fra1. Vercel’s DPA prohibits special-category Customer Data. A source-pinned authenticated cron in fra1 claims and processes due database jobs every minute. | Frankfurt compute; US provider/support and onward locations under Vercel DPA and SCCs where required. |
| Supabase Pte. Ltd. | Managed PostgreSQL for ordinary application data, authentication and audit. Daily Pro backups retain the last seven days and exclude object-storage files; no PITR is represented. It also stores the durable job_outbox queue, scheduled reminder instants, leases, attempt counters and fixed delivery outcomes. | Frankfurt eu-central-1 primary data; Singapore entity and provider locations under Supabase DPA and SCCs where required. |
| Cloudflare, Inc. (R2) | Private tenant assets. EU jurisdiction, public development URL disabled, no custom domain, and application-origin PUT CORS. No independent backup, object versioning or lock is represented. | EU R2 jurisdiction; US provider/support under Cloudflare DPA and SCCs where required. |
| Plus Five Five, Inc. (Resend) | Email recipient, sender, subject, ordinary message body, booking link and non-clinical attachments; no health data. | United States; Resend DPA and SCCs where required. |
| ONLINECITY.IO ApS (GatewayAPI.eu) | SMS recipient number, clinic sender label, ordinary appointment time and secure manage or unsubscribe link; no health data. | Denmark / EEA. |
| Functional Software, Inc. (Sentry) | Bounded error code/name, area, tenant identifier, environment and release; no request bodies, direct contact text or health data. | United States; Sentry DPA and SCCs where required. |
Stripe, PostHog, Anthropic, Mailpit, MinIO and console adapters are not authorized production subprocessors under this DPA. They require a new assessment, contract update, notice and technical activation before receiving Customer Personal Data.