Data Processing Agreement
The Data Processing Agreement between each clinic (the controller) and Nano AI (the processor) for the patient data recorded in Synora.
1. Parties and how this agreement applies
This Data Processing Agreement ("DPA") is between the clinic that holds a Synora account (the "Clinic", the controller) and Nano System for Artificial Intelligence (نانو سيستم للذكاء الاصطناعي), a Limited Liability Company (LLC) registered in the Arab Republic of Egypt at the Cairo Investment Commercial Registry Office under commercial register no. 213792, tax registration no. 755-247-124, with its registered office at 53 Capital Mall, behind the Court, 2nd floor, Fifth Settlement, New Cairo, Cairo, Egypt ("Nano AI", the processor). It forms part of the Terms of Service and applies automatically from the moment the Clinic accepts them. A clinic that needs a signed copy can ask for one at hello@nano-ai.net.
It is made under Articles 4 to 6 of Egypt's Personal Data Protection Law (Law 151 of 2020) and its executive regulations. If this DPA and the Terms conflict on the protection of personal data, this DPA prevails.
2. Subject matter, duration, nature and purpose
- Subject matter: hosting and processing the personal data the Clinic records in Synora.
- Duration: for as long as the Clinic's account exists, and afterwards until the data is deleted under section 11.
- Nature: storage, organisation, retrieval, display, transmission (messages the Clinic sends), backup, export and deletion.
- Purpose: solely to provide the Synora service to the Clinic, as described in the Terms.
3. Data subjects and categories of data
- Data subjects: the Clinic's patients (including minors) and their guardians, the Clinic's staff, and other people the Clinic records (such as referring doctors or lab contacts).
- Categories: identity and contact details; demographic data; medical and dental history, allergies and medicines, diagnoses, charts, treatment plans, clinical notes, prescriptions, images and documents (sensitive personal data); appointments; financial and insurance data; messages and consent records; technical data about staff users.
4. The Clinic's instructions and duties
The Terms, this DPA and the Clinic's use of Synora's features are the Clinic's complete documented instructions. Other instructions must be in writing and consistent with the service.
The Clinic warrants that it has a lawful basis for all the data it records, including patients' explicit consent for sensitive data (Terms section 6), that it holds any licence it needs from the Personal Data Protection Center, and that its instructions comply with the law.
5. Our duties as processor
We will:
- process the data only on the Clinic's documented instructions, unless the law requires otherwise — in which case we tell the Clinic first unless the law forbids it; and tell the Clinic if we believe an instruction breaks the law;
- not use the data for any purpose of our own, not sell it, and not use it for advertising, profiling or training artificial-intelligence models;
- make sure everyone authorised to access the data is bound by confidentiality, and give access only to staff who need it to provide or support the service;
- apply appropriate technical and organisational security measures, including those described in section 8 of the Privacy Policy, and keep them under review;
- keep a record of the processing we carry out for the Clinic;
- obtain and maintain any licence or permit the law requires of us as a processor of sensitive data;
- help the Clinic, as far as the service allows, to answer data-subject requests, to carry out impact assessments and to deal with the Personal Data Protection Center.
6. Data-subject requests
If a patient contacts us directly, we pass the request to the Clinic without undue delay and do not answer it ourselves unless the Clinic asks us to. The Clinic can export a patient's record itself from the patient's file. On the Clinic's written instruction, and in time for it to answer within 30 days, we export a patient's record, or remove a patient's identifying details while keeping the clinical and financial records the law requires.
7. Sub-processors
The Clinic gives general authorisation for the sub-processors listed in section 6 of the Privacy Policy. We impose on each of them data-protection obligations no weaker than this DPA, and remain responsible to the Clinic for their performance. We give at least 14 days' notice of any new or replacement sub-processor for patient data, by email to the Clinic's owner; if the Clinic objects on reasonable data-protection grounds and we cannot resolve the objection, the Clinic may close its account and receive a refund of the unused part of any prepaid period.
8. Location and transfers
We will not store or transfer the Clinic's data outside Egypt except as Articles 14 to 16 of Law 151 of 2020 allow, with the licence or permit the Personal Data Protection Center requires and appropriate written safeguards. We tell the Clinic the storage location (Privacy Policy section 7) and give notice before changing it.
9. Personal data breaches
We notify the Clinic of any personal data breach affecting its data without undue delay and within 24 hours at most of becoming aware of it. The notice describes, as far as known: the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences, and the measures taken or proposed. We add information as it becomes available, take reasonable steps to contain the breach, and cooperate so that the Clinic can notify the Personal Data Protection Center within 72 hours and inform patients where needed.
10. Audits
We make available to the Clinic the information needed to show compliance with this DPA. Once a year, or after a breach affecting its data, the Clinic may audit our compliance itself or through an independent auditor bound by confidentiality, on at least 30 days' written notice, during business hours, at the Clinic's cost, and without access to other clinics' data or to our security secrets. We also cooperate with any inspection by the Personal Data Protection Center.
11. End of the service: return and deletion
At any time, including before closing its account, the Clinic's owner can download a full export itself from Settings → Data export (CSV and JSON with stored files; each link valid for 7 days). When the Clinic's account is closed, we keep its data available for 60 days, during which we also provide on request a full export in the same formats, within 14 days of the request. After that we delete the data within a further 30 days, and it leaves our backups as they roll over (up to 30 days), unless the law requires us to keep part of it. On request, we confirm the deletion in writing.
12. Liability and term
Each party's liability under this DPA is subject to the limitation of liability in the Terms, to the extent the law allows. This DPA lasts as long as we process personal data for the Clinic. It is governed by Egyptian law, and the Economic Courts in Cairo have exclusive jurisdiction, as in the Terms.
Operator
| Operator | Nano System for Artificial Intelligence — Limited Liability Company (LLC) (Nano AI) |
|---|---|
| Commercial Register No. | 213792 — Cairo Investment Commercial Registry Office |
| Tax Registration No. | 755-247-124 — Nasr City 1 Tax Office |
| Registered office | 53 Capital Mall, behind the Court, 2nd floor, Fifth Settlement, New Cairo, Cairo, Egypt |
| hello@nano-ai.net |