Skip to content
All legal information

Data processing agreement

The commitments of Clinoly, as processor, to the clinic, as controller of its patients’ data.

Version 1.0In force since 10 September 2026Accepted by the clinic

This translation is provided for information. Where it differs from the French version, the French version prevails.

This document is being finalised: some of the publisher’s legal details have still to be filled in.

1.Parties and purpose

This agreement is made between the Client, as controller, and Clinoly, as processor, within the meaning of Law No. 09-08. It forms part of the subscription contract and applies to the personal data the Publisher processes on the Client’s behalf in providing the Service.

It is accepted by the clinic owner on subscribing; that acceptance is recorded with the version, the date and the IP address. It ends with the contract, subject to the return-and-deletion clause.

2.Description of the processing

ItemDescription
NatureHosting, storage, organisation, consultation, transmission (reminders and messages) and backup of the data the Client records
PurposeEnabling the Client to run its care practice: records, appointments, consultations, prescriptions, billing, patient communication
Data subjectsThe Client’s patients, people they name (emergency contacts), the Client’s staff
DataIdentity, contact details, administrative and insurance data, appointments, billing; health data: history, consultations, vital signs, diagnoses, prescriptions, results, documents
DurationThe term of the contract, extended by the ninety (90) day return period
Hosting location[to be completed]

3.The Client’s instructions

The Publisher processes data only on the Client’s documented instructions, which consist of the contract, this agreement and the Client’s configuration of the Service. The Publisher does not use the data for its own purposes: it does not sell it, exploit it for advertising or use it to train artificial intelligence models.

The Publisher informs the Client immediately if it considers that an instruction infringes the law.

4.Confidentiality

People authorised to process the data are bound by a duty of confidentiality. The Publisher’s staff do not access medical records, save under an explicit support-access authorisation that is time-limited, justified and logged.

5.Security

In accordance with Articles 23 and 24 of Law No. 09-08, the Publisher implements technical and organisational measures appropriate to the sensitivity of health data. They are described on the Security page and include, in particular, separation between establishments, role-based access control, encrypted communications, unalterable access logging and backups.

6.Sub-processing

The Client authorises the Publisher to use the sub-processors on the list of Subprocessors. The Publisher binds them by contract to protection obligations at least equivalent to those of this agreement and remains liable for their failures.

The Publisher informs the Client of any addition or replacement at least thirty (30) days in advance. The Client may object on legitimate grounds; failing agreement, it may terminate the contract free of charge and receive a pro-rata refund of the unused period.

7.Transfers outside Morocco

Any transfer of data to a third country complies with Articles 43 and 44 of Law No. 09-08. It is for the Client to complete the CNDP formalities that fall to it for its own processing; the Publisher provides it with the information required.

A Client established in France must have health data hosted by a certified health-data host (HDS), in accordance with Article L.1111-8 of the French Public Health Code. It tells the Publisher before subscribing, so that compliant hosting can be put in place.

8.Assistance to the Client

The Publisher helps the Client meet its obligations, in particular through the following functions of the Service:

  • right of access: a complete export of a patient’s record, to answer their request;
  • rights of rectification and erasure: editing of data, and irreversible erasure of a patient’s identity while keeping the clinical record the law requires;
  • consents: recording of patients’ consents, channel by channel and with their history;
  • traceability: an unalterable log of access and changes, which the Client can consult;
  • portability: a complete export of the clinic’s data.

The Publisher forwards to the Client without delay any request it receives directly from a data subject, and does not answer it without the Client’s instruction.

9.Personal data breaches

The Publisher notifies the Client of any personal data breach as soon as possible and no later than forty-eight (48) hours after becoming aware of it. The notification describes the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences and the measures taken or proposed. The Publisher adds to that information as it obtains more.

10.Documentation and audit

The Publisher makes available to the Client the information needed to demonstrate compliance with this agreement. Once a year, on thirty (30) days’ notice, the Client may have an audit carried out at its own cost by an independent auditor bound by confidentiality, under conditions that compromise neither the security of the Service nor other clients’ data.

11.Return and deletion

When the contract ends, the data remains available to the Client for reading and export for ninety (90) days. At its request, the Publisher provides a copy in a structured format. Once that period has passed, the Publisher deletes the data, including from backups at the end of their rotation cycle, and confirms this to the Client on request.

12.The Client’s obligations

  • to have a legal basis for each processing operation and to inform patients;
  • to complete the CNDP prior formalities that fall to it;
  • to obtain the consents required, in particular for communications and the artificial intelligence assistant;
  • to authorise only people bound by secrecy or confidentiality, and to manage their access rights;
  • to set and respect its retention periods.

13.Clients subject to the EU regulation

Where the Client is subject to Regulation (EU) 2016/679, this agreement serves as the contract required by its Article 28, and the terms of that Article are deemed incorporated.

14.Precedence

On data protection, this agreement prevails over any other contractual term. The parties’ liability is governed by the Terms of sale.

Data processing agreement · Clinoly