This Data Processing Addendum ("DPA") forms part of the agreement between CliniTech and the clinic or other organization using the CliniTech Service ("Customer") and applies where CliniTech processes Personal Data on behalf of the Customer in connection with the Service.
This DPA supplements the CliniTech Terms of Service and applies to the processing of Personal Data submitted to CliniTech by or on behalf of the Customer.
By creating or using a clinic account and using CliniTech to process Personal Data, the Customer agrees to this DPA as part of its agreement with CliniTech.
1. Definitions
For purposes of this DPA:
"Applicable Data Protection Law" means privacy, personal-data-protection, healthcare-confidentiality, and related laws applicable to the processing of Personal Data under this DPA.
"Customer" means the clinic, healthcare organization, or other organization using CliniTech and determining the purposes for which Customer Personal Data is processed through the Service.
"Customer Personal Data" means Personal Data processed by CliniTech on behalf of the Customer through the Service.
"Data Subject" means an identified or identifiable natural person whose Personal Data is processed.
"Personal Data" means information relating to an identified or identifiable natural person and includes patient and healthcare information where protected by Applicable Data Protection Law.
"Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, retrieval, consultation, use, transmission, restriction, deletion, or destruction.
"Processor" means a person or organization processing Personal Data on behalf of another party. Where applicable Armenian law uses the concept of an authorized person, references to Processor in this DPA are intended to include CliniTech acting in that corresponding capacity.
"Subprocessor" means a third party engaged by CliniTech to process Customer Personal Data on behalf of CliniTech in connection with providing the Service.
"Service" means the CliniTech website, web application, mobile applications, APIs, and related clinic-management services.
2. Roles of the Parties
For Customer Personal Data entered into CliniTech for the Customer's clinic operations:
- the Customer determines the purposes and lawful basis for processing that information;
- the Customer acts as the controller or corresponding responsible processing party under Applicable Data Protection Law; and
- CliniTech acts as processor or authorized person on behalf of the Customer.
CliniTech may separately process account, billing, security, support, and business information for its own legitimate operational purposes as described in the CliniTech Privacy Policy. Such processing is outside CliniTech's processor role under this DPA to the extent CliniTech determines the purposes and means of that processing itself.
3. Customer Instructions
The Customer instructs CliniTech to process Customer Personal Data as necessary to:
- provide and maintain the Service;
- store and retrieve patient and clinical records;
- provide visits, scheduling, treatment plans, procedures, referrals, follow-ups, dental charting, and related functionality;
- store and serve authorized files and documents;
- authenticate users and enforce roles and permissions;
- provide authorized notifications and integrations;
- maintain security and audit functionality;
- provide technical support;
- perform other processing reasonably necessary to provide functionality selected and configured by the Customer.
The Terms of Service, this DPA, the Customer's use and configuration of the Service, and documented instructions accepted by CliniTech constitute the Customer's instructions for processing.
CliniTech will not intentionally process Customer Personal Data for purposes unrelated to providing the Service except where required or permitted by applicable law.
If CliniTech is legally required to process Customer Personal Data contrary to or beyond the Customer's instructions, CliniTech will inform the Customer where legally permitted.
4. Customer Responsibilities
The Customer is responsible for:
- complying with Applicable Data Protection Law;
- having an appropriate legal basis for processing Customer Personal Data;
- obtaining required patient notices, authorizations, or consents where applicable;
- ensuring that instructions given to CliniTech are lawful;
- determining what patient and clinical information should be entered into the Service;
- ensuring the accuracy and appropriateness of Customer Personal Data;
- determining which personnel may access the Service;
- assigning appropriate roles and permissions;
- protecting user credentials;
- determining legally applicable medical-record retention periods;
- responding to requests from patients and other Data Subjects concerning Customer-controlled records;
- ensuring optional integrations selected by the Customer are appropriate for its legal and professional obligations.
The Customer must not instruct CliniTech to process Personal Data in a manner that would violate applicable law.
5. Categories of Data Subjects
Customer Personal Data may relate to:
- patients;
- prospective patients where entered by the Customer;
- doctors;
- dentists;
- nurses;
- receptionists;
- assistants;
- clinic administrators;
- other clinic personnel;
- referral contacts;
- emergency or other patient contacts;
- other individuals whose information is lawfully entered into the Service by the Customer.