What this agreement is — at a glance
This table is a plain summary only. The detailed sections below govern.
| Subject | Who decides | Our role |
|---|---|---|
| Your patients' medical records | your clinic, as Controller | we process them on your behalf and under your instructions (sections 5, 6) |
| Lawful basis, notices, and consents | your clinic | we do not check them or rule on them (section 5) |
| Registering a patient on the Platform, and which of your staff may open a record | your clinic | we supply the tool; we decide nothing and check nothing (sections 5.2–5.4) |
| Your patients' requests about their records | your clinic | assistance only (section 9) |
| Security measures and subprocessors | us | we apply them and choose them (sections 7, 8) |
| Telling patients or an authority about a security incident | your clinic | we notify you and cooperate (section 10) |
| Account identity, platform security, audit logs | us, as Controller | us (section 5.1) |
| Liability, remedies, fees, and termination | the Terms & Conditions | they apply unchanged (sections 14, 15) |
This agreement is between us and the clinic alone, and creates no rights for any patient or third party (section 1.4).
1. The parties, and where this agreement sits
1.1 The parties. This agreement is between Clareeva, a company registered in Palestine ("we", the Operator) and the clinic that uses the Platform ("you", the "Clinic"), acting through its Owner. It is made in the context of the clinic's use of the Platform and forms part of the agreement between us. Clareeva is an online service and does not operate a public office; notices to us are given by email.
1.2 What this agreement does. It governs our processing of personal data on the clinic's behalf and as its Processor, and allocates the responsibilities between us on that subject.
1.3 What it does not do. It does not replace or amend the Terms & Conditions or the Privacy Policy. It does not widen the scope of what we provide, and it creates no commitment as to availability, performance, or response time. The Terms & Conditions remain governing for liability, remedies, fees, and termination (sections 14, 15).
1.4 No third-party rights. This agreement is between us and the clinic alone. It creates no right, claim, or remedy for any patient, staff member, or third party. What individuals are told about their data is set out in the Privacy Policy.
2. Definitions
- Controller — the party that decides why and how personal data is used.
- Processor — a party that handles personal data on behalf of, and under the instructions of, a Controller.
- Personal data and health data — as defined in the Privacy Policy (its section 2).
- Clinic data — the personal data we process on the Platform on the clinic's behalf.
- Subprocessor — a service provider we engage to carry out part of the processing on our behalf.
- Security incident — a breach of security leading to the destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to the clinic's personal data.
- Documented instructions — this agreement and the Terms & Conditions, the clinic's settings on and use of the Platform, and any other instruction we accept in writing.
3. Subject matter, nature, purpose, and duration of the processing
3.1 Subject matter. The processing of personal data needed to provide the clinic with the Platform as described in the Terms & Conditions (its section 5).
3.2 Nature and purpose. Collecting, storing, organising, retrieving, displaying, transmitting, backing up, correcting, and deleting data, as far as is necessary to run the features the clinic uses: appointments, intake, clinical documentation, billing records, staff administration, notifications, and the optional AI features. The purpose is to provide, secure, and support the Service, and nothing else.
3.3 Duration. Processing continues for as long as the clinic uses the Platform, and thereafter for the period set out in section 13.
3.4 The limits of what we do. We take no clinical or administrative decision on the clinic's behalf — including no decision about which patients are registered on the Platform and which of the clinic's staff may open a record (section 5.4). We do not review, validate, or correct its clinical content, we do not use clinic data for our own purposes, we do not sell it, and we do not train our models on it (Privacy Policy, section 10).
4. Categories of data subjects and of personal data
4.1 Data subjects. The clinic's patients — including those its staff register who may never use the Platform themselves — guardians and dependents, and the clinic's staff and Owner.
4.2 Categories of data. Identity and contact details; profile details; the health data the clinic's staff create or enter about a patient; appointment and intake data; the clinic's records of its own billing of its patients; staff notes; and activity logs of actions inside records. These categories are described in detail in the Privacy Policy (section 4) and are not repeated here.
4.3 Health data is a sensitive category. Clinic data includes health information, which is among the most sensitive categories of personal data. That is reflected in our obligations (sections 6, 7) and in your responsibilities (section 5).
5. Roles, and the clinic's warranties
5.1 Your clinic is the Controller; we are the Processor. You are the Controller of your patients' medical records, and we process them on your behalf and under your documented instructions. For account identity, platform security, audit logs, the public site, and the subscription relationship, we are the Controller (Terms & Conditions, section 10.2; Privacy Policy, section 3).
5.2 Your warranties. By signing this agreement, or by your clinic using the Platform, you represent and warrant that:
- you have a lawful basis to collect, process, and keep your patients' and staff's data, and that this basis covers our processing of it on your behalf;
- the decision to register a patient on the Platform is yours, taken by you and never by us, including for a patient who is not present and may never use the Platform themselves (Terms & Conditions, sections 3.3 and 17.2);
- you have given your patients the notice and obtained any consent the law requires before their account or record is created and before your staff open it — including patients your staff register who may never use the Platform themselves, and before a doctor uses the optional AI features in a way that involves a patient's information;
- every access by your staff to a patient's record is made on your authority, for the care of that patient, and with whatever consent or authority the law requires;
- your instructions to us are lawful, and our processing in accordance with them does not breach any applicable law;
- what you and your staff enter on the Platform is accurate and necessary for the purpose it was collected for;
- supervising your staff and controlling their access to patient records is your responsibility (Terms & Conditions, section 17.3).
5.3 We check none of this. We do not review your lawful basis, your notices, your patients' consents, or the lawfulness of your instructions, and we take no responsibility for any of them. In particular, we do not verify that a patient consented to being registered on the Platform or to any access to their record, and we take no part in either decision. Your responsibility for your use of the Platform remains as set out in the Terms & Conditions (section 17.8).
5.4 Our expectation, stated plainly. We expect every clinic to ask every patient for the consent the law requires before it registers them and before its staff open their record, and the Platform is made available to you on that basis. Where the Platform offers you a way to record that you asked, it is a convenience for you and not a check by us: whether you use it, and whether the consent behind it was genuinely given, is yours. Using it — or not using it — transfers none of your responsibility to us. A patient registered, or a record opened, without the consent the law requires is your act, for which you answer under the Terms & Conditions (sections 17.2 and 17.8).
6. Our obligations as Processor
6.1 Processing on instructions. We process clinic data in accordance with your documented instructions (section 2), as far as is necessary to provide, secure, and support the Service, and where applicable law requires otherwise.
6.2 Where an instruction appears unlawful. If an instruction appears to us to breach applicable law, or to put patients, their data, or the Platform at risk, we may tell you, decline to carry it out, or suspend carrying it out — and no liability attaches to us for doing so. This clause does not create any duty on us to examine your instructions (section 5.3).
6.3 Confidentiality. Our personnel who have access to clinic data are bound by a duty of confidence, and access is granted only as far as their work requires. Our platform administrators are walled off from clinical data (Terms & Conditions, section 6.2).
6.4 Security measures. We apply appropriate technical and organisational measures as described in section 7.
6.5 Subprocessors. We engage subprocessors in accordance with section 8.
6.6 Assistance. We assist you within the limits of sections 9 and 10, as far as is reasonably available to us given the nature of the processing, the information we hold, and the tools the Platform provides.
6.7 What we do not undertake. We do not undertake to perform any Controller duty on your behalf — such as an impact assessment, consulting a competent authority, responding to data subjects, or appointing a data protection officer for you. Nothing in this agreement is to be read as transferring your duties as Controller to us.
7. Technical and organisational measures
7.1 The measures. We apply a range of measures appropriate to the nature of the data, including: encryption of the connection in transit; encryption of clinical free text at rest; storing passwords in a protected form that cannot be read back as plain text; optional two-factor authentication for staff; access limited by role and by the relationship to the patient; separation of each clinic's data from every other clinic's; limits on repeated login attempts; uploaded files stored privately and served only through access-checked views; audit logging of sensitive actions; and regular backups. These measures are also described in the Privacy Policy (section 12).
7.2 Measures evolve. Security is a moving practice. We may change, replace, or update these measures, provided the change does not materially reduce the level of protection.
7.3 What sits on your side. Controlling your staff's accounts, permissions, and devices, revoking the access of anyone who leaves your clinic, protecting credentials, and confining access to records to what the care of that patient requires are measures we cannot apply for you. They are your responsibility (Terms & Conditions, sections 4.3 and 17.3).
7.4 No system is perfectly secure. We cannot and do not guarantee that data can never be accessed, altered, or lost. The measures above are an obligation of reasonable care, not a guarantee of a result (Privacy Policy, section 12).
8. Subprocessors
8.1 General authorisation. The clinic gives us a general authorisation to engage subprocessors to run the Platform, in the following categories: hosting and infrastructure; file storage; message and email delivery; fault monitoring; and the processing needed for the optional AI features.
8.2 How they are chosen, and their limits. We choose subprocessors with reasonable care, and they handle data only as far as is necessary to perform their service, and on our instructions, under the terms on which we engage them (Privacy Policy, section 10).
8.3 Changes. We may add or replace a subprocessor, or change the categories above. We will notify clinics of any material change to the categories of subprocessors by reasonable means, and a clinic's continued use of the Platform after notice is acceptance of that change.
8.4 What this agreement does not include. It does not include a list of subprocessors by name, and it gives no right to object to or veto their selection. Choosing them is an operational decision of ours, and it changes as the Platform changes.
8.5 Our responsibility for them. We are responsible for choosing them with reasonable care. We do not guarantee their performance (Terms & Conditions, section 11.4), and section 14 applies to everything concerning them.
9. Data subject requests
9.1 The decision is yours. Requests patients make about their medical records — access, correction, deletion, objection, or restriction — are decided by the Controller, that is you, and you are the one who responds to them (Privacy Policy, section 13).
9.2 Our role is assistance only. We assist you as far as is reasonably available to us given the nature of the processing and the tools the Platform provides. We do not answer a patient about their medical record in your place, we do not delete or amend a clinical record at a patient's request, and we do not exercise judgement in your stead.
9.3 Requests that reach us. If a request about a medical record held at your clinic reaches us, we direct the person to you or refer the request to you, without deciding it.
9.4 What we handle ourselves. Requests about data for which we are the Controller — account identity, login, platform security, and the like — we handle directly (section 5.1).
9.5 The cost of assistance. Ordinary assistance is included in the Service. For repeated, excessive, or disproportionately burdensome requests, we may agree the cost with you before carrying them out, or decline to carry them out.
10. Security incidents
10.1 Notification. If we become aware of a security incident affecting your clinic's personal data, we will notify the clinic without undue delay.
10.2 What the notification contains. We provide what is reasonably available to us at the time: a description of the incident, the categories affected as far as we know them, and the measures we have taken. Information may be completed in stages as the investigation progresses, and incomplete detail will not delay notifying you.
10.3 Cooperation. We cooperate with you reasonably in assessing and containing the incident, and in providing what you need to meet your own duties as Controller.
10.4 Reporting is your obligation. As Controller, you decide whether an incident requires telling your patients or any competent authority, and when and how, and you carry that out. We do not notify your patients or any authority on your behalf; we do so for what we are the Controller of, or where the law directly requires it of us (Privacy Policy, section 16).
10.5 A notification is not an admission. Neither notifying you of an incident nor cooperating on it is an admission of fault or of liability on our part.
11. Information and demonstrating compliance
11.1 What you get. On a reasonable written request, we provide the information reasonably necessary to demonstrate that we are meeting our obligations under this agreement. It is provided in writing, and no more often or more broadly than is reasonably necessary.
11.2 What this agreement does not include. It grants no right of on-site audit, no visit or inspection of our premises or those of our providers, no access to our systems, code, or internal logs, and no audit by a third party or external auditor.
11.3 What we may withhold. We may decline to provide any information whose disclosure would compromise the security of the Platform, the confidentiality of another clinic or user, a duty of confidence owed by us, or our own commercial information.
11.4 Confidentiality. What we provide under this section is confidential: it may be used only to demonstrate compliance, and may not be disclosed to a third party except where the law requires it.
12. Processing outside Palestine
12.1 Some processing happens outside Palestine. Some subprocessors operate outside Palestine, which means clinic data may be processed or stored outside it (Privacy Policy, section 10).
12.2 Safeguards. Where that happens, we choose providers with reasonable care and apply appropriate safeguards to protect the data.
12.3 The clinic's instruction. The clinic's use of the Platform is its instruction and authorisation for this processing and for the transfers outside Palestine it requires. If the clinic is subject to a legal restriction preventing this, it must tell us before using the Platform.
13. Retention, and return and deletion on termination
13.1 While this agreement is in force. We keep clinic data for as long as it is needed to provide the Service, as described in the Privacy Policy (section 11).
13.2 On termination. After the clinic's use of the Platform ends, and on the clinic's written request within a reasonable period, we make a copy of its data available in a reasonable format agreed between us (Terms & Conditions, section 19.3).
13.3 After that. We then delete clinic data, or keep it for as long as is necessary for legitimate purposes or required by law, as set out in the Terms & Conditions (section 19.4).
13.4 What remains in every case. Deletion does not extend to: what mandatory medical-record retention duties require to be kept; audit and security logs, which are kept unaltered for integrity; anything the law or a competent authority requires us to keep; and backups, which are replaced on their ordinary cycle rather than by selective deletion from them.
13.5 Your duties do not end. You remain the Controller of your patients' records after termination, and remain subject to whatever retention, confidentiality, and access duties apply to them, whether those records stay on the Platform or not (Terms & Conditions, section 19.5).
14. Liability — the Terms & Conditions govern
14.1 The liability limits apply in full. Section 12 of the Terms & Conditions — including what we are not responsible for (12.2), no legal action (12.3), and the liability limit (12.4) — applies to this agreement and to every claim arising out of or connected with it or with our processing of clinic data, in full and unmodified.
14.2 This agreement creates no new remedy. Nothing in this agreement is to be read as creating a cause of action, claim, remedy, or additional liability against us, or as widening, limiting, or carving out any part of section 12 of the Terms & Conditions.
14.3 Your responsibility for your own compliance. Your responsibility to us for your breach of this agreement or of the Terms & Conditions, for your instructions to us as Processor, and for your clinic's care of its patients remains as set out in the Terms & Conditions (section 17, and in particular 17.8).
14.4 The single channel. If you have a comment or a complaint about our processing of your
clinic's data, write to support@clareeva.com. We will look at it and reply, and this is the
agreed channel for resolving any matter concerning this agreement (Terms & Conditions,
sections 12.3 and 13.2).
15. Order of precedence between the documents
15.1 Each document has its place. The three documents apply together:
| Document | What it governs |
|---|---|
| Data Processing Agreement (this document) | the detail of data processing between us and the clinic, and how responsibility for it is allocated between us |
| Terms & Conditions | liability, remedies, fees, subscription, suspension, and termination |
| Privacy Policy | what individuals are told about their data, and how it is handled on the Platform |
15.2 On conflict. Where this agreement conflicts with the Terms & Conditions on liability, remedies, fees, or termination, the Terms & Conditions apply. Where it conflicts with the Privacy Policy on what individuals are told, the Privacy Policy applies. On everything else concerning the detail of processing between us and the clinic, this agreement applies.
15.3 No implied amendment. Nothing in this agreement amends the Terms & Conditions or the Privacy Policy.
16. Term, changes, acceptance, contact, and language
16.1 Term. This agreement runs for as long as the clinic uses the Platform and ends when that ends — with sections 11, 13, 14, and 15 continuing to apply afterwards as far as necessary.
16.2 Changes. This agreement carries a version number and a last-updated date at the top. We may update it as the Platform and the law evolve; when we do, we change both, and for material changes we take reasonable steps to bring the update to the clinic's attention. The clinic's continued use of the Platform after that means it accepts the updated version.
16.3 Acceptance and effect. This agreement takes effect when the Owner activates the subscription or the clinic continues to use the Platform, whichever is earlier.
16.4 Contact. Any notice or request under this agreement is sent to us at
support@clareeva.com, and to the clinic at the contact details it has recorded with us or by a
notice inside the Platform.
16.5 Severability. If any part of this agreement is found unenforceable, the rest continues to apply.
16.6 Governing law. This agreement is governed by the laws applicable in Palestine (Terms & Conditions, section 13.1).
16.7 Language. Arabic is the primary version of this agreement. This English text is provided for convenience, and if the two differ in meaning, the Arabic version prevails.