Data Processing Agreement

Last updated: August 30, 2026

This applies to every customer automatically. It forms part of the Terms of Service and takes effect the moment You start using the Services, whether or not You have also signed a Business Associate Agreement. You do not need to sign or request it separately.

It exists because the protections in it are required by data protection law wherever You are, while a Business Associate Agreement is a United States instrument that only a HIPAA covered entity would sign. A clinic in Dublin, Toronto or Lagos is not a covered entity - so the terms below could not be allowed to depend on one.

Parties and scope

This Data Processing Agreement ("DPA") is between Bettar Platforms, Inc., a Delaware corporation trading as ClinikEHR, of 8 The Green, Suite B, Dover, DE 19901, United States (the "Processor", "We" or "Us"), and the customer that has agreed to the Terms of Service (the "Controller" or "You").

It applies to Personal Data We Process on Your behalf where the EU General Data Protection Regulation, the UK GDPR, or the Nigeria Data Protection Act 2023 (together, the "Data Protection Laws") apply. For Your patients' information You are the Controller and We are the Processor. For Your own account, billing and authentication data We are a controller in our own right, and our Privacy Policy governs that.

Where a HIPAA Business Associate Agreement is also in place, both apply. The BAA governs Protected Health Information under United States law; this DPA governs Personal Data under the Data Protection Laws. Where they conflict as to Personal Data covered by the Data Protection Laws, this DPA prevails.

VI. EUROPEAN, UNITED KINGDOM, AND NIGERIAN DATA PROTECTION

This this DPA applies to the extent that Processor Processes Personal Data on behalf of Controller that is subject to the General Data Protection Regulation (EU) 2016/679 ("EU GDPR"), the UK GDPR and the Data Protection Act 2018 (together, "UK Data Protection Law"), or the Nigeria Data Protection Act 2023 ("NDPA") (collectively, the "Data Protection Laws"). It supplements, and does not replace, the obligations set out elsewhere in this DPA. Where a term of this DPA and a term elsewhere in this DPA or in the Agreement differ in their application to Personal Data governed by this Section, this DPA shall prevail as to that Personal Data.

The terms "Personal Data", "Process" (and "Processing"), "Controller", "Processor", "Sub-processor", "Data Subject", "Supervisory Authority", and "Personal Data Breach" have the meanings given to them in the Data Protection Laws. Where Personal Data is also PHI, both this DPA and the remainder of this DPA apply to it, and the requirement affording the greater protection shall govern.

  1. Roles of the Parties. With respect to Personal Data that Processor Processes on behalf of Controller in providing the Services, Controller is the Controller and Processor is the Processor. Controller is responsible for the lawfulness of the Personal Data that it and its authorized users submit to the Services, and for having a lawful basis for the Processing it instructs. Processor acts as a Controller in its own right only in respect of the account, subscription, billing, security, and fraud-prevention records it holds about Controller and its authorized users as customers of the platform; that Processing is not carried out on Controller's behalf, is not PHI, and is described in the ClinikEHR Privacy Policy rather than in this DPA.
  2. Documented Instructions. Processor shall Process Personal Data only on Controller's documented instructions, including with regard to any transfer of Personal Data to a third country, unless Processing is Required by Law; where Processor Processes Personal Data because it is Required by Law, Processor shall inform Controller of that legal requirement before Processing, unless the law prohibits it from doing so on important grounds of public interest. This BAA, the Agreement, and Controller's configuration and use of the Services together constitute Controller's complete documented instructions. Processor shall inform Controller without undue delay if, in Processor's opinion, an instruction infringes the Data Protection Laws. The permissions set out in Sections II.B, II.C, II.E, and II.F, and any disclosure contemplated by Section III.L, do not extend to Personal Data governed by this DPA except where the Processing concerned is itself a documented instruction of Controller or is Required by Law. In particular, and notwithstanding any other provision of this DPA, Processor shall not Process such Personal Data for its own purposes; shall not use it to train, develop, or improve any artificial intelligence or machine learning model except as instructed by Controller; and shall not treat information de-identified in accordance with 45 C.F.R. § 164.514 as falling outside this DPA unless that information is anonymous within the meaning of the Data Protection Laws.
  3. Confidentiality of Personnel. Processor shall ensure that each person it authorizes to Process Personal Data is subject to an enforceable duty of confidentiality, whether contractual or statutory, that survives the end of that person's engagement; that access to Personal Data is limited to those persons who require it in order to provide the Services or to comply with the Data Protection Laws; and that those persons are trained on their obligations with respect to Personal Data.
  4. Security of Processing. Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risk to the rights and freedoms of Data Subjects. Those measures shall address, as appropriate: the pseudonymization and encryption of Personal Data; the ongoing confidentiality, integrity, availability, and resilience of Processing systems and services; the ability to restore the availability of and access to Personal Data in a timely manner following a physical or technical incident; and a process for regularly testing, assessing, and evaluating the effectiveness of the measures. These measures include the safeguards Processor is required to implement under the Security Rule. Processor shall make a current description of these measures available to Controller on request and shall not materially diminish them during the term of this DPA.
  5. Sub-processors. Controller gives Processor general written authorization to engage Sub-processors to Process Personal Data in providing the Services, subject to this paragraph (E).
    1. Processor shall maintain a current list of the Sub-processors that Process Personal Data on Controller's behalf, identifying each Sub-processor, the Processing it carries out, and the country in which that Processing takes place. Processor shall make that list available to Controller on request to [email protected].
    2. Processor shall give Controller at least thirty (30) days' notice before adding or replacing a Sub-processor. Because the list is provided on request rather than published, Processor gives that notice by email to the account owner's registered address, and Controller may ask at any time to have additional recipients added for this purpose. Controller may object to the change on reasonable grounds relating to data protection by giving written notice within that period. The parties shall work in good faith to resolve the objection; if they cannot, Controller may terminate the affected Services without penalty by written notice given before the change takes effect.
    3. Processor shall impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those set out in this DPA and in Section III.E, and shall remain fully liable to Controller for the performance of each Sub-processor's obligations.
  6. Assistance with Data Subject Rights. Taking into account the nature of the Processing, Processor shall assist Controller by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Controller's obligation to respond to requests by Data Subjects to exercise their rights, including the rights of access, rectification, erasure, restriction of Processing, data portability, objection, and the right not to be subject to a decision based solely on automated Processing. The Services provide functionality by which Controller may itself access, correct, export, and delete Personal Data; where Controller cannot give effect to a request through the Services, Processor shall provide reasonable assistance. If Processor receives a request directly from a Data Subject in respect of Personal Data Processed on Controller's behalf, Processor shall not respond to it other than to acknowledge receipt and direct the Data Subject to Controller in accordance with Section III.I, and shall notify Controller of the request without undue delay.
  7. Assistance with Breach Notification, Impact Assessments, and Consultation.
    1. Processor shall notify Controller of a Personal Data Breach affecting Personal Data Processed on Controller's behalf without undue delay after becoming aware of it, and in any event no later than twenty-four (24) hours after becoming aware of it. The parties acknowledge that Controller may be required to notify a Supervisory Authority, including the Nigeria Data Protection Commission where the NDPA applies, within seventy-two (72) hours of becoming aware of a Personal Data Breach, and that the notification period stated in Section III.D.1 would not permit Controller to do so. Accordingly, the period stated in Section III.D.1 does not apply to a Personal Data Breach governed by this DPA, and the period stated in this paragraph applies instead.
    2. The notification shall contain the information described in Section III.D.2, together with the categories and approximate number of Data Subjects and records concerned and the likely consequences of the Personal Data Breach, in each case to the extent known to Processor. Processor shall supplement its notification as further information becomes available, and shall not delay an initial notification in order to complete its investigation.
    3. Taking into account the nature of the Processing and the information available to it, Processor shall provide reasonable assistance to Controller in ensuring compliance with Controller's obligations relating to the security of Processing, the notification of a Personal Data Breach to a Supervisory Authority, the communication of a Personal Data Breach to Data Subjects, the carrying out of data protection impact assessments, and prior consultation with a Supervisory Authority.
    4. Processor shall not notify a Supervisory Authority or any Data Subject of a Personal Data Breach affecting Personal Data Processed on Controller's behalf, and shall not identify Controller publicly in connection with such a Personal Data Breach, unless Controller instructs it to do so or Processor is Required by Law to do so.
  8. Records, Information, and Audits. Processor shall maintain records of the Processing it carries out on behalf of Controller as required by the Data Protection Laws, and shall make available to Controller all information reasonably necessary to demonstrate compliance with this Section Processor shall allow for and contribute to audits, including inspections, conducted by Controller or by an auditor mandated by Controller. Such an audit shall be conducted no more than once in any twelve (12) month period, except following a Personal Data Breach or where a Supervisory Authority requires it; on at least thirty (30) days' written notice; during normal business hours; subject to reasonable confidentiality obligations; and in a manner that does not disrupt the Services or compromise the security or confidentiality of any other customer's data. Processor may satisfy a request under this paragraph by providing current third-party audit reports, certifications, or completed security questionnaires where these are available and reasonably address the request. This paragraph is in addition to, and does not limit, the access afforded to the Secretary under the BAA, where one is in place.
  9. International Transfers. Processor is established in the United States and has no establishment in the European Economic Area or the United Kingdom. Processor's provision of the Services therefore involves the transfer of Personal Data from the European Economic Area and the United Kingdom to a third country. Where such a transfer is not covered by an adequacy decision, the parties agree as follows:
    1. The standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 (the "EU SCCs") are incorporated into and form part of this DPA, with Module Two (transfer controller to processor) applying, Controller as data exporter, and Processor as data importer.
    2. For transfers subject to UK Data Protection Law, the EU SCCs apply as varied by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, which is likewise incorporated into and forms part of this DPA.
    3. For the purposes of the EU SCCs: Annex I and Annex II are completed by the Annex to this DPA; the general written authorization and notice period in Section E apply for the purposes of Clause 9 (Option 2); and the competent Supervisory Authority for the purposes of Clause 13 is that of the Member State in which Controller is established, determined in accordance with that Clause. For the purposes of Clause 17 of the EU SCCs, those Clauses are governed by the law of Ireland. For the purposes of Clause 18(b), disputes arising from the EU SCCs shall be resolved before the courts of Ireland. Where the UK Addendum applies, it is governed by the laws of England and Wales and subject to the courts of England and Wales, as that Addendum requires.
    4. Where a term of the EU SCCs conflicts with a term of this DPA or the Agreement, the EU SCCs shall prevail in respect of the transfer to which they apply.
  10. Deletion and Return of Personal Data. At the choice of Controller, on expiry or termination of the Agreement Processor shall delete or return all Personal Data Processed on Controller's behalf and shall delete existing copies, except to the extent that applicable law requires Processor to retain it. Where Processor retains Personal Data because law requires it to, including audit records that record access to PHI and records of a fraud or security assessment that Processor may need in order to establish or defend a legal claim, Processor shall retain only what that requirement demands; shall continue to apply the protections of this DPA to the retained Personal Data; shall Process it only for the purpose for which it is retained, and not for marketing, analytics, product development, or any other purpose; and shall delete it once that requirement no longer applies. Processor shall confirm to Controller on request what has been deleted or returned and what has been retained under this paragraph. This paragraph qualifies Section V.C, and shall survive termination of this DPA.
  11. Automated Decision-Making. Where the Services present output produced by automated Processing, including output produced by an artificial intelligence feature, that output is presented for review by Controller's authorized users and is not a decision of Processor. Processor does not take any decision in respect of a Data Subject that produces a legal effect concerning that Data Subject, or similarly significantly affects that Data Subject, on the basis of automated Processing alone.
  12. Nigeria. Where the NDPA applies to Personal Data Processed on Controller's behalf, Controller is the data controller and Processor is the data processor, and the commitments in this DPA apply to that Personal Data. Processor shall transfer such Personal Data out of Nigeria only where the NDPA permits the transfer, including on the basis of a contract that binds the recipient to protections equivalent to those in this Section Nothing in this DPA limits Controller's own obligations to the Nigeria Data Protection Commission.

ANNEX A. DETAILS OF PROCESSING

This Annex describes the Processing carried out under this DPA. It completes Annex I and Annex II of the EU SCCs where those clauses apply under Section I.

  1. The parties. The data exporter is Controller, the ClinikEHR customer identified by the account under which the Services are used, acting as Controller. Its contact details are the account details it provides on account creation. The data importer is Bettar Platforms, Inc., 8 The Green Suite B, Dover, DE 19901, United States, acting as Processor, and may be contacted at [email protected].
  2. Subject matter. Processor's provision of the Services to Controller under the Agreement.
  3. Duration. From the Effective Date until expiry or termination of the Agreement, together with any period for which Personal Data is retained under Section J.
  4. Nature and purpose. The hosting, storage, transmission, backup, and support of the Services, and the Processing operations that Controller and its authorized users initiate through the Services in the course of delivering care and administering their practice. The purpose is to provide the Services; Processor does not determine the purposes for which Controller records Personal Data in the Services.
  5. Frequency. Continuous, for the duration described above.
  6. Categories of Data Subjects. The patients and clients of Controller and, where Controller records them, their dependants, guardians, and emergency contacts; the owners, staff, and other authorized users of Controller; and the contacts and correspondents of Controller, including referring providers and payer contacts.
  7. Categories of Personal Data. Identification and contact details; account and authentication details for authorized users; appointment, scheduling, and attendance data; clinical records, including notes, observations, prescriptions, laboratory and radiology orders and results, imaging, and documents; billing, payment, and insurance data; communications between Controller and Data Subjects, and telehealth session data where Controller enables that feature; and technical log and audit data recording access to the foregoing.
  8. Special categories of Personal Data. Data concerning health, which is inherent in the Services, and any other special category of Personal Data that Controller chooses to record. Such data is Processed only for the purpose of Controller delivering and administering care, and is subject to the restrictions in Sections VI.B, VI.C, and VI.D, including the limitation of access to authorized persons bound by a duty of confidentiality.
  9. Sub-processors. As described in Section E. A current list, identifying each Sub-processor, the Processing it carries out, and the country in which that Processing takes place, is available on request to [email protected].
  10. Technical and organizational measures. The measures described in Section D. A current description of those measures is available on request to [email protected].
  11. Competent Supervisory Authority. Determined in accordance with Clause 13 of the EU SCCs, as stated in Section I.

Questions About This Agreement?

If you have any questions about our Processor Agreement or HIPAA compliance practices, please contact our compliance team at [email protected]