Data Processing Addendum
How CureYou.ai processes clinic and patient data as your data processor.
كيف تعمل منصة CureYou.ai بصفتها معالجًا للبيانات نيابةً عن العيادات.
Draft — not yet in force
This document is pending legal review by Omani-qualified counsel and is not yet legally binding. Do not rely on it as an executed agreement. Annexes 1–3 are indicative and must be completed before use.
This Data Processing Addendum ("DPA") forms part of the Clinic Subscription Agreement (the "Agreement") between Eye International Intg Serv LLC trading as CureYou ("Processor", "we") and the Customer ("Controller", "Clinic"). It governs our processing of Personal Data on the Controller's behalf. If there is a conflict on data protection, this DPA prevails over the Agreement.
1. Roles
1.1For Patient Data and other Customer Data processed through the Service, the Clinic is the Controller and CureYou is the Processor.
1.2The Clinic is responsible for the lawfulness of its instructions and for having a valid legal basis (including any patient consent) for the processing.
2. Scope and instructions
2.1We process Personal Data only (a) to provide and support the Service under the Agreement, (b) on the Controller's documented instructions, and (c) as required by law (in which case we will notify the Controller unless legally prohibited).
2.2We will inform the Controller if, in our opinion, an instruction infringes the Oman PDPL or other applicable law.
2.3We will not sell Personal Data, use it for our own purposes, or use Patient Data to train third-party AI models.
2.4No marketplace repurposing by default. Any use of Personal Data for the CureYou Marketplace is a separate, optional purpose governed by the Marketplace Data-Sharing Addendum. Absent the Controller's express opt-in there (and, for patient data, the patient's own consent), we will not share or repurpose Personal Data for the Marketplace. The Controller's possession of a record does not by itself authorise such repurposing.
3. Confidentiality
We ensure that personnel authorised to process Personal Data are bound by confidentiality and access it only on a need-to-know basis.
4. Security
4.1We implement appropriate technical and organisational measures to protect Personal Data, having regard to the state of the art and the risk — in particular for health data (a special category). These measures are described in Annex 2 and include encryption in transit, database-per-tenant isolation, role-based access control, hashed credentials, audit logging, and regular backups.
4.2The Controller is responsible for configuring user roles and permissions and for the security of its own devices and credentials.
5. Sub-processors
5.1The Controller authorises us to engage the sub-processors listed in Annex 3 to process Personal Data.
5.2We impose data-protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance.
5.3We will give the Controller 14 days' notice of any new or replacement sub-processor (by updating Annex 3 and notifying clinic administrators). The Controller may object on reasonable data-protection grounds; if we cannot resolve the objection, the Controller may terminate the affected Service.
6. Data residency and transfers
6.1We host Personal Data on infrastructure located in the Sultanate of Oman (data residency).
6.2We will not transfer Personal Data outside Oman except where (a) necessary to provide the Service via an Annex 3 sub-processor, and (b) the transfer complies with the Oman PDPL, including any required safeguards, approvals, or consents. We will inform the Controller of any such transfer.
7. Assistance to the Controller
7.1Taking into account the nature of the processing, we will provide reasonable assistance to the Controller in responding to data-subject (patient) requests to access, correct, delete, or object; carrying out data-protection impact assessments and consultations; and meeting its security and breach-notification obligations.
7.2Where a patient contacts us directly, we will, unless legally required to act, refer them to the relevant Clinic.
8. Personal-data breach
8.1We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's Personal Data, with the information reasonably available to us.
8.2We will take reasonable steps to contain and remediate the breach and assist the Controller in meeting its notification duties to the competent Omani authority and affected patients.
9. Return and deletion
On termination or expiry of the Agreement, or on the Controller's written request, we will (at the Controller's choice) return or delete the Personal Data, except to the extent retention is required by law. We will provide a reasonable export window before deletion.
10. Audit
We will make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits by the Controller (or an independent auditor) no more than once per year on reasonable notice, subject to confidentiality and not unreasonably disrupting our operations. We may satisfy this through up-to-date certifications or summary reports where available.
11. Liability
Liability under this DPA is subject to the limitations and exclusions in the Agreement.
Annex 1 — Details of processing
To be completed and confirmed before execution.
- Subject matter
- Provision of the CureYou clinic-management platform.
- Duration
- The term of the Agreement plus any return/deletion period.
- Nature & purpose
- Hosting, storage, organisation, retrieval, display, and back-up of Customer Data to operate the clinic's patient registration, appointments, billing, clinical (SOAP) notes, and document storage.
- Data subjects
- The Clinic's patients; the Clinic's staff (Authorised Users).
- Categories of Personal Data
- Identity and contact details; appointment and scheduling data; billing/payment references; account and authentication data.
- Special categories
- Health data — medical history, pain charts, clinical (SOAP) notes, assessments, discharge summaries, and uploaded clinical documents (e.g. X-ray, lab, referral).
Annex 2 — Technical and organisational security measures
Indicative list — to be completed to match the live environment before execution.
- Encryption in transit (TLS/HTTPS); encryption at rest.
- Database-per-tenant isolation; tenant resolution and access controls.
- Role-based access control (Super Admin / Admin / Therapist / Receptionist); least-privilege.
- Hashed credentials; session and token management (Sanctum).
- Audit logging of sensitive actions; lockable clinical notes.
- Regular, tested backups; defined retention and restoration.
- Network and server hardening; production secrets management.
- Incident-response process and breach notification.
- Personnel confidentiality and access governance.
Annex 3 — Authorised sub-processors
This list must be kept current. Locations marked "To be confirmed" will be updated before execution.
| Sub-processor | Purpose | Location | Personal data involved |
|---|---|---|---|
| Hosting provider | Platform hosting / database | Oman | All Customer Data |
| Transactional email (e.g. Mailgun) | Transactional email delivery | To be confirmed | Contact data |
| SMS / WhatsApp gateway | Appointment reminders (if enabled) | To be confirmed | Name, phone, appointment details |
| Document / file storage (e.g. R2) | Document and file storage | To be confirmed | Uploaded documents |
| Usage analytics | Usage analytics — account/usage data only, not patient data | To be confirmed | Usage, technical data |
For data protection enquiries, contact our DPO at dpo@cureyou.ai. Also see our Privacy Policy, Terms of Service, and Cookie Policy.