Bareilly, Bareilly AI-Powered Healthcare 24/7 Emergency
WEBSITE EXCLUSIVE 50% OFF on Consultation Book online & save! Limited time offer.

Data Processing Agreement (DPA)

For B2B Customers (Clinics/Hospitals using SmileAiXl)

Business Contract | HIPAA Compliant
Agreement Parties
Data Processor: SmileAiXl
Data Controller: The Client (Clinic/Hospital)

1. Scope and Responsibility

SmileAiXl acts as a Data Processor. We process patient data solely on behalf of the Client (Data Controller) to provide Hospital Management and Diagnostic services.

Data Ownership

The Client retains full ownership of all patient records. SmileAiXl processes this data only as instructed by the Client.

2. The "Local-First" Processing Guarantee

We differentiate ourselves from standard cloud providers through our architecture:

AI Processing

We guarantee that Protected Health Information (PHI) used for AI diagnostics (X-ray analysis, Clinical Intelligence) is processed locally on the Client's instance or via secure, private tunnels.

No Third-Party Training

We strictly do not use the Client's patient data to train our foundational AI models for other customers without explicit, anonymized consent.

3. Security Obligations

SmileAiXl agrees to implement appropriate technical measures, including:

Encryption

AES-256 encryption for data at rest and TLS 1.3 for data in transit.

Access Control

Enforcing Passkey-based (FIDO2) authentication to prevent unauthorized access.

Audit Logs

Maintaining immutable logs of who accessed which patient record and when.

4. Sub-processors

We use the following infrastructure providers (Sub-processors) to deliver the service:

Service Type Provider Purpose Data Protection
Hosting AWS Mumbai Region / DigitalOcean Bangalore Encrypted Storage AES-256 Encryption
Communication WhatsApp Business API (Meta), SMS Gateway Patient Notifications End-to-End Encryption
IoT MQTT Broker Smart Chair Data Secure Channel (TLS)

5. Data Breach Notification

Incident Response

In the unlikely event of a data breach, SmileAiXl will notify the Client within 24 hours of becoming aware of the incident.

We will provide a detailed report including:

  • Nature and scope of the breach
  • Data categories affected
  • Immediate mitigation steps taken
  • Recommendations for Client action

6. Data Subject Rights

SmileAiXl will assist the Client in fulfilling data subject requests, including:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to data portability
  • Right to object

7. Contract Termination

Upon termination of this agreement, SmileAiXl will:

  • Return or securely delete all Client data within 30 days
  • Provide data export in standard formats
  • Certify complete data destruction

8. Contact Information

For DPA-related questions or data protection concerns:

  • Email: [email protected]
  • Phone: +91 9368997410
  • Address: Ghous E Azam Hospital, Bareilly, UP 243001