Data Processing Addendum
Effective 28 August 2026
This Addendum applies where Minnato processes personal data subject to the UK GDPR, the EU GDPR, or DIFC Data Protection Law No. 5 of 2020. You are the controller; we are the processor. It forms part of the Terms of Service.
1Subject matter and scope
| Item | Detail |
|---|---|
| Subject matter | Provision of the Minnato platform — patient intake forms, AI telephone reception, scheduling and delivery. |
| Duration | The term of the subscription, plus the thirty-day export window that follows. |
| Nature and purpose | Collection, storage, structuring, transmission, retrieval and erasure, solely to deliver the service. |
| Categories of data | Identity and contact details, appointment and scheduling data, information a patient volunteers on a form or a call, uploaded documents, and call recordings and transcripts where enabled. |
| Special categories | Data concerning health. Processed on the controller's instructions under Article 9(2)(h) or another basis the controller identifies. |
| Data subjects | Patients and prospective patients of the controller; the controller's own staff who use the console. |
2Our obligations
- Process personal data only on your documented instructions, including on international transfers, unless required otherwise by law — in which case we tell you first, unless the law forbids it.
- Ensure everyone authorised to process the data is bound by confidentiality.
- Implement the measures required by Article 32, described in section 4.
- Engage sub-processors only under section 3.
- Assist you, taking account of the nature of processing, in responding to data subject requests.
- Assist you with Articles 32 to 36 — security, breach notification and data protection impact assessments.
- Delete or return personal data at the end of the service, as you choose.
- Make available the information needed to demonstrate compliance, and allow and contribute to audits, once per year or after a personal data breach, on reasonable notice.
- Notify you without undue delay, and in any event within forty-eight hours, of becoming aware of a personal data breach.
3Sub-processors
You give general authorisation for the sub-processors listed in the sub-processor table. We will give at least thirty days' notice before adding or replacing one, and you may object on reasonable data-protection grounds. If we cannot resolve your objection, you may terminate the affected service and receive a pro-rata refund of prepaid fees. Each sub-processor is bound by written terms no less protective than these.
4Security measures
- Isolation enforced by the database. Every table holding patient data carries row-level security, forced at database level, so a query written incorrectly returns nothing rather than another customer's records.
- Encryption. Data is encrypted in transit with TLS and at rest under a key unique to each customer, wrapped by a managed key service and never stored in plaintext.
- Access derived from membership. Permission to read patient data is resolved from a verified membership on each request; it cannot be asserted by application code.
- Fail-closed defaults. Where a control is absent the system takes the most restrictive path — an unsigned agreement blocks collection, an unscanned file is not served, an unreachable scanner disables attachments.
- Audit logging. Actions affecting patient data are recorded in an append-only log available to the controller.
- Verified deletion. Purge removes the encrypted payload, attachments, call summaries and submission context together, and is verified by automated tests asserting the data is gone.
5International transfers
Personal data is processed in the United States. Our company is established in the DIFC, and the UAE holds no adequacy decision from the European Commission or the United Kingdom.
Transfers from the EEA rely on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), incorporated by reference; where we onward-transfer, Module Three applies. Transfers from the UK rely on the UK International Data Transfer Addendum (version B1.0) to those Clauses. In each case Clause 7 (docking) is included, Clause 9 uses Option 2 with thirty days' notice, Clause 11 omits the independent dispute-resolution option, Clause 17 selects the law of Ireland, and Clause 18(b) selects the courts of Ireland.
A transfer impact assessment is available on request. Its central point is that the per-customer encryption key means ciphertext obtained without that key discloses nothing.
6Representatives
Where Article 27 requires it, our appointed representatives in the European Union and the United Kingdom are named on our security page and may be contacted through privacy@minnato.ai.
7Order of precedence
Where this Addendum conflicts with the Terms of Service, this Addendum prevails for personal data governed by it. Where it conflicts with the Standard Contractual Clauses, the Clauses prevail. For PHI under HIPAA, the Business Associate Agreement prevails.
Start by finding out what your websites are leaking.
A free scan of any practice site tells you in ninety seconds which trackers are loading on pages that collect patient information. No account, no card.