Terms of Service
These Platform Terms are the complete standard online agreement for Clinilo Managed Launch. They provide an ordinary-data-only, DKK 0, month-to-month service and do not require a signed Order.
- Status
- Published
- Version
- managed-launch-terms-2026-08-17
- Effective date
- 2026-08-17
1. Provider, customer and contract documents
The provider is Clinilo FZE LLC, registration number 4431302, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates (Clinilo). Business, support, privacy, security and legal notices may be sent to casper@swprlabs.com. The customer is the clinic entity identified in the online acceptance record.
Clinilo’s appointed EU representative under applicable EU law is Mesoskinline ApS, company registration number 39967065, Denmark, with service address Juelsmindevej 57, 7120 Vejle Øst, Denmark, and email sales@mesoskinline.com.
The contract consists of these Terms, the accepted DPA and the versioned online schedule. The schedule is embedded here: DKK 0, no tax or payment due, month-to-month, 30 days’ termination notice and policy ordinary-data-only-2026-08-16. The online acceptance record identifies the exact versions, time, actor and clinic; the owner archive keeps them available and provides a downloadable text receipt on a durable medium. No signed Order, expected-Order record or sales document is required for registration, handover or use.
2. Eligibility and accounts
A person accepting for a clinic confirms that the clinic is a business, that the person is at least 18 and has authority to bind it. Each user must use an individual account, protect credentials, keep details current and notify Clinilo promptly of suspected compromise. Clinic owners control memberships; Clinilo may verify authority and refuses administrator impersonation as an acceptance method.
3. Service and limited right of use
Managed Launch supplies clinic administration, staff and service setup, availability, ordinary appointment scheduling, client contact, immediate booking confirmations and receipts, owner booking notifications, automatic email reminders 48 hours before and SMS reminders 24 hours before, cancellation and rescheduling links, invoices marked for offline handling, audit records and owner export. Clinilo grants Customer a non-exclusive, non-transferable right to use those hosted functions during the term for its internal business.
The active policy ordinary-data-only-2026-08-16 prohibits health data and every other special category of personal data. Clinical journals, treatment notes, clinical forms, intake answers, treatment photos, diagnoses and any field or service label that reveals health status must not be entered or uploaded. Health-data activation is disabled. Customer must use neutral service names and keep clinical records outside Clinilo. A later clinical or paid service requires a separately published contract and Customer’s fresh affirmative online acceptance.
4. Fees, taxes and payment
The entire Managed Launch subscription price is DKK 0 per month. No setup, platform, support, switching, card, cancellation or usage fee is due; Clinilo does not collect payment credentials for it. DKK 0 means there is no invoice or tax amount payable. A future paid offer cannot start automatically and requires a new versioned schedule, clear price and separate affirmative online acceptance. Silence, continued use, an old signed Order or an expected-Order record is not acceptance of payment.
5. Customer responsibilities
- Configure truthful clinic, seller, contact, service, price, practitioner, cancellation and privacy information before public booking.
- Use only ordinary personal data, instruct staff accordingly and remove or report prohibited content immediately.
- Provide lawful notices and instructions as controller, answer clients, and maintain any professional or statutory records outside Clinilo.
- Keep exports and secure links protected, review memberships and cooperate with security and rights requests.
6. Acceptable use
Customer must not use Clinilo unlawfully; upload malware; probe or bypass security or tenant isolation; scrape or overload the service; share accounts; impersonate another person; infringe rights; send unlawful marketing; reverse engineer except where mandatory law permits; or use Clinilo for emergency care, diagnosis, clinical decision-making or health records. Clinilo may block the affected operation where reasonably necessary and records privileged administrative action in the audit trail.
7. Customer Data and data protection
Customer retains its rights in Customer Data and is controller for personal data it places in Clinilo. Clinilo processes it as processor only to provide, secure, support, export and delete the service under the DPA and documented instructions. Clinilo is separately controller for its own account, contracting, security, support and legal-compliance records described in the Privacy Policy. Clinilo does not sell Customer Data or use identifiable Customer Data for advertising or model training.
8. Confidentiality
Each party protects the other’s non-public business, security and technical information with at least reasonable care and uses it only for this contract. The duty excludes information lawfully public, already known without restriction, independently developed or lawfully received from another source. A compelled disclosure is limited to what is required, with prior notice where legally permitted. These duties survive for five years and for trade secrets while protected by law; personal data remains governed by the DPA.
9. Security, availability and third parties
Clinilo uses tenant scoping, role checks, protected platform-administrator bootstrap and impersonation controls, encryption in transit, managed database encryption at rest, private object storage, audit events, secret separation, tested migration and deployment gates, and incident procedures. Customer remains responsible for endpoint security, user access and secure handling of exports and links.
The service depends on the providers listed in the Subprocessor List. Maintenance, internet failure, provider incident or emergency remediation may interrupt it. There is no uptime SLA or service credit under DKK 0. The primary Frankfurt database has daily provider backups with a current seven-day retention window; database backups exclude object-storage files. The EU-jurisdiction R2 bucket has no represented independent backup, object versioning or object lock. Clinilo therefore does not promise point-in-time recovery or recovery of every file.
10. Intellectual property
Clinilo and its licensors retain the service, software, documentation, designs, trademarks and improvements. Customer retains Customer Data, clinic branding and its materials. Customer grants Clinilo the limited rights needed to host and process them during the term. Non-confidential feedback may be used without identifying Customer or exposing Customer Data.
11. Term, renewal, suspension and termination
The contract begins when an authorized owner accepts online and renews month-to-month in rolling 30-day periods. Either party may terminate for convenience on 30 days’ written notice. A material breach may be terminated if not cured within 30 days after notice, or immediately where cure is impossible, processing would be unlawful or insolvency law permits. Clinilo may narrowly suspend affected access for a credible security threat, unlawful use or material breach, gives notice where practicable, preserves mandatory export rights and restores access when the cause ends. There is no payment-related suspension.
12. EU Data Act switching process
Customer may instruct Clinilo to switch to another provider, move exportable data and digital assets to its own infrastructure, or erase them without switching. The maximum notice period to initiate switching is two months. The normal transition completes without undue delay and within 30 calendar days after that notice period. If technically unfeasible, Clinilo explains why within 14 working days and states an alternative period no longer than seven months; Customer may extend once. Contract termination follows successful switching or the agreed erasure date.
Clinilo assists the Customer and its authorized destination provider, maintains reasonable continuity and security, supplies available interface and limitation information, confirms completion, and charges DKK 0 for mandatory switching. Customer has at least 30 calendar days after transition to retrieve exportable data before ordinary deletion, subject to narrow legal retention.
13. Portability register and owner export
The stable public register at /portability describes clinilo-tenant-export-v1, formats, schemas, checksums, included data, exclusions and provider boundaries. A currently authenticated, non-impersonated clinic owner can request the same export interface without extra charge. The streaming ZIP includes NDJSON, schema and index files, tenant-prefixed assets allowed by policy, SHA-256 checksums and a final manifest.
Under ordinary-data-only-2026-08-16 the archive exposes 49 registered ordinary-data datasets and 7 supplemental datasets. Six clinical dataset paths remain documented but unavailable. Export fails closed instead of silently omitting discovered clinical rows, known legacy clinical fields or clinical storage categories. Credentials, live sessions, verification secrets, rate-limit buckets and the global provider-integrity ledger are excluded. The retained tenant_expected_signed_orders dataset is compatibility evidence only and is not a contracting route.
14. Infrastructure jurisdiction and foreign-government access
Application functions are source-configured for Frankfurt (fra1). The primary Supabase project is in Frankfurt (eu-central-1). Cloudflare R2 uses EU jurisdiction. Resend and Sentry are US providers with minimized ordinary-data payloads; GatewayAPI.eu is an EEA SMS provider. Provider contracting, remote support and onward processing may involve the countries and safeguards in the DPA and Subprocessor List. Vercel’s current DPA prohibits special-category Customer Data, independently reinforcing this schedule’s technical health-data block.
For data held in the Union, Clinilo uses contractual safeguards, least privilege, encryption where applicable, minimization, legality review, reasonable challenge and notice where permitted to resist conflicting third-country governmental access. Personal-data requests remain governed by the DPA and applicable GDPR transfer rules.
15. Exit, deletion and survival
During notice and transition Customer may use the owner export and retrieve its data. Tenant return and deletion are documented, operator-led case processes; there is no self-service tenant-deletion button. On termination Clinilo returns or deletes Customer Personal Data as instructed under the DPA and erases exportable data after the mandatory retrieval period, except narrow copies retained by law. Clinilo confirms completion only after the scoped live-system, object, provider and backup evidence required by the offboarding process is recorded. Legally retained data is isolated from ordinary use and deleted when the duty ends. Accrued rights, confidentiality, intellectual property, liability, audit and required privacy duties survive as necessary.
16. Warranties and disclaimers
Each party has authority to contract. Clinilo will use reasonable skill and care and materially provide the described ordinary-data service. After notice Clinilo uses reasonable efforts to cure a material nonconformity within 30 days; Customer may terminate the affected service if it is not cured. No refund is due under DKK 0. Except for express commitments and non-excludable law, Clinilo does not guarantee uninterrupted availability, recovery of every file, or a clinical, commercial, regulatory or legal outcome.
17. Liability
Neither party is liable for indirect or consequential loss or lost profit, revenue, goodwill or anticipated savings, except where law prohibits exclusion. Subject to the carve-outs, aggregate liability in a rolling 12-month period is the greater of fees paid or payable and DKK 100,000; for confidentiality, personal-data obligations and Clinilo’s covered intellectual-property indemnity it is the greater of twice those fees and DKK 200,000.
No exclusion or cap applies to fraud, wilful misconduct, death or personal injury caused by negligence, liability that mandatory law prohibits limiting, or deliberate misuse of the other party’s intellectual property. Mandatory privacy and EU Data Act remedies remain available.
18. Third-party claims
Customer defends and indemnifies Clinilo against third-party claims to the extent caused by Customer Data, Customer services, unlawful instructions or Customer’s material breach, except to the extent caused by Clinilo. Clinilo defends and indemnifies Customer against an EEA third-party claim that authorized, unmodified use of the service infringes intellectual property, excluding Customer Data, instructions, unauthorized changes and combinations not supplied by Clinilo. The protected party gives prompt notice and reasonable cooperation; no settlement may admit fault or impose non-monetary duties without consent.
19. Changes to the contract
Clinilo gives at least 30 days’ direct notice before a material adverse change unless an urgent legal or security reason requires a narrower earlier change, in which case it gives as much notice as practicable. Customer may object and terminate before the change takes effect. Subprocessor changes follow the DPA. Accepted versions remain available in the owner archive.
No change can make DKK 0 paid, authorize a charge, shorten the 30-day termination right, permit health or special-category data, or introduce a signed-Order requirement. Each requires a separately versioned offer and fresh affirmative online acceptance.
20. Governing law and disputes
The contract is governed by the federal laws of the United Arab Emirates as applied in the Emirate of Sharjah, without conflict-of-laws rules. The parties first seek good-faith resolution for 30 days; subject to mandatory rights and venue, Sharjah courts have exclusive jurisdiction. This does not remove mandatory Danish or EU privacy, employment, consumer, data-access or Data Act rights. The EU Standard Contractual Clauses retain their own governing law, authority and forum provisions.
21. General
Operational notices may be sent through the account. Notices to Clinilo may be sent to casper@swprlabs.com or, where physical delivery is required, the address in section 1. Email is accepted continuously and handled on business days. The English and Danish versions are intended to have the same meaning; the English version controls only to the extent a genuine inconsistency remains, subject to mandatory law.
Neither party may assign without consent, not unreasonably withheld, except with its business or to an affiliate able to perform. The parties are independent contractors. Neither is liable for delay beyond reasonable control except duties that remain practicable. Failure to enforce is not waiver; invalid terms are minimally adjusted. These Terms, DPA and online schedule are the entire agreement and are accepted online without a signed Order.