Data Governance
Data Processing Addendum
A summary of the data-processing commitments that should be completed in a signed DPA, and where applicable a Business Associate Agreement, before a clinic submits regulated patient information.
Last updated: September 2, 2026
1. When this addendum applies
This addendum applies when MedSpaOS processes personal data or protected health information for a customer as part of the service. The customer is the controller, business, or covered entity as applicable, and MedSpaOS is the processor, service provider, or business associate only to the extent described in the signed agreement. For customers in Nigeria, the NDPA and applicable regulations are the primary data-protection framework; in other African countries, the applicable national data law governs where it provides stronger or different requirements. A signed DPA or BAA is required where applicable law requires one.
2. Processing instructions
We process customer data only to provide, secure, support, and improve the service as permitted by the customer agreement and documented instructions. We do not use patient data for advertising or sell it. Customers must ensure their instructions, data, and use of AI features are lawful and authorized.
3. Confidentiality and safeguards
Personnel and subprocessors with access to customer data are subject to confidentiality obligations. MedSpaOS maintains reasonable technical and organizational safeguards, including access controls, authentication, tenant isolation, monitoring, incident response, and secure development practices appropriate to the service.
4. Subprocessors and transfers
We may use infrastructure, authentication, email, monitoring, payment, and AI subprocessors to deliver selected features. The customer agreement should identify the current subprocessor list, notice process, international transfer mechanism, and objection rights. Customers should not enable an integration until they have reviewed its data flows and terms.
5. Nigerian and African compliance
The parties will cooperate in good faith to meet the NDPA, relevant NDPC guidance, and mandatory data-protection rules in the African jurisdictions where the customer operates. The customer is responsible for determining whether it is a data controller, processor, covered entity, or other regulated party, and for giving MedSpaOS lawful documented instructions. Country- specific transfer, retention, breach-notification, or healthcare terms may be added to the signed DPA.
6. Assistance and incidents
Taking into account the nature of processing, we provide reasonable assistance with data-subject requests, security assessments, breach investigations, and regulatory obligations. Customers must notify us promptly at security@medspaos.com if they suspect unauthorized access or disclosure.
7. Return and deletion
After service termination, customer data is made available for export and deleted or anonymized according to the customer agreement, documented retention periods, backups, and applicable law. Customers remain responsible for retaining records required by healthcare, tax, or other regulations.
8. Documentation status
This page is a public summary, not a complete DPA or BAA. Before production use with regulated data, confirm the contracting entity, governing law, security exhibit, subprocessors, cross-border terms, breach notice period, retention schedule, and signature process with counsel and MedSpaOS.
This page is provided for product and operational transparency. It is not legal advice. Have qualified counsel review the applicable agreement before relying on it in a live service.