In short
Your clinic decides what happens to your patients’ data. We hold and process it only to run the service, only on your instructions, and we tell you what we do with it.
This agreement forms part of the Terms and applies automatically to every clinic — there is nothing to sign, and you do not have to ask for it.
1.Roles
- Data Fiduciary
- The clinic. You determine why and how patient personal data is processed.
- Data Processor
- SQABY Technologies. We process it on your documented instructions and for no purpose of our own.
- Data Principal
- The patient, or any individual whose personal data is processed.
Your instructions are, in practice, your configuration of the product and your use of it. If you ever want to instruct us to do something the product does not do by itself, put it in writing to [email protected].
We will tell you if we believe an instruction breaks the law, and we may decline it. We will not silently comply with something that would put your patients at risk.
2.Scope, nature and duration
- Subject matter
- Providing the Sqavio Doctor clinic management service to your clinic.
- Categories of data
- Patient identity and contact details, appointment and visit records, clinical notes, vitals, diagnoses, prescriptions, investigations, invoices and payment records; and clinic staff account data.
- Categories of data principals
- Your patients, your doctors and your staff.
- Nature of processing
- Storing, organising, displaying, transmitting, backing up, and deleting — as the product does.
- Duration
- For as long as your subscription lasts, plus the deletion window in the Terms.
3.What we commit to
- Process patient data only to provide the service, and never for our own marketing, profiling, model training or resale.
- Keep it separated: each clinic has its own database rather than a shared table.
- Limit access to the few staff who need it for support or operations, under confidentiality obligations, with access recorded.
- Apply the security measures described below and keep them current.
- Assist you in answering a data principal, in notifying a breach, and in meeting your own obligations under the DPDP Act.
- Delete or return the data at the end, as set out below.
4.Security measures
- Encryption in transit (HTTPS) and at rest, including backups.
- A separate database per clinic; no shared patient table.
- Role-based access enforced on the server, not merely hidden in the interface.
- Passwords stored as slow one-way hashes; sessions that can be revoked.
- An audit trail of significant actions, with the account that performed them.
- Scheduled backups with tested restores.
- Data hosted in Germany.
We may change specific measures as technology moves, but not in a way that materially weakens protection. The current position is described on the security page.
5.Sub-processors
You give us general authorisation to engage the sub-processors listed on the sub-processors page, each of which is bound to protections no weaker than these.
Before adding or replacing one, we update that page and give at least 30 days’ notice to account owners. If you reasonably object on data protection grounds within that period, tell us; if we cannot resolve it, you may terminate the affected service and receive a pro-rata refund of the unused period.
We remain responsible to you for what a sub-processor does with your data.
6.Helping you answer a patient
Most requests you can answer yourself: viewing, correcting, exporting and deleting patient records are things the product lets you do without us.
If a patient contacts us directly, we will not answer for you. We will tell them to contact the clinic, and tell you that they tried. Where you need help to answer, ask and we will provide it in reasonable time and at no charge for ordinary requests.
7.If there is a personal data breach
We will tell you without undue delay once we are aware of a breach affecting your data — as a target, within 24 hours of confirmation — with what we know: what happened, which data and roughly how many people are affected, what we are doing, and what we suggest you do.
We will keep you updated as we learn more, so you can meet your own duty to notify the Data Protection Board and affected individuals, including the detailed report expected within 72 hours. We will cooperate with that notification and will not obstruct it.
8.Audit
On reasonable written notice, and no more than once a year unless a breach or a regulator requires otherwise, we will provide the information you reasonably need to verify our compliance with this agreement. Where an on-site or third-party audit is genuinely necessary, we will agree a scope that protects other clinics’ data and our security posture, at your cost.
9.Return and deletion
You can export your data at any time while the subscription is live. After it ends, we keep the data for 30 days so you can export or reactivate, then delete it from live systems; backup copies age out within a further 60 days.
We keep only what law requires us to keep — invoices and accounting records — and nothing more. On request we will confirm deletion in writing.
10.Relationship to the Terms
This agreement forms part of the Terms of Service, and the liability, governing law and dispute provisions there apply to it. Where this agreement and the Terms conflict on the handling of personal data, this agreement governs.
Questions about this document? Write to [email protected]. If you are not satisfied with the answer, the grievance route is open to you.