Loading…
Loading…
Effective: 2026-01-01
NOTE: This page is a structural placeholder. The final DPA must be reviewed by qualified Saudi legal counsel and signed alongside your service agreement.
This Data Processing Addendum (DPA) describes how we process patient and clinic data on your behalf in compliance with PDPL.
Clinic = Data Controller. BIT Information Technology = Data Processor. We process data only on documented instructions from the Controller.
All personnel with access to clinic data are bound by confidentiality obligations.
See our Security overview. Includes TLS 1.3, encryption at rest, RBAC, audit logging, and backups.
We maintain an updated list of sub-processors available on request. Material changes are communicated in advance.
We assist the Controller in responding to data subject requests received via the platform.
We notify the Controller of a personal data breach without undue delay, and within 72 hours of awareness.
On termination, we provide a data export and securely delete remaining copies within 90 days, unless retention is required by Saudi law.