Data Processing Agreement (DPA)

Last updated: May 1, 2026

This agreement governs the processing of patient data (patients' personal data) by 3yadtk as data processor on behalf of the subscribing clinic (data controller), under whichever data protection law applies in the clinic's own country, across all fourteen we serve — the table of supervisory authorities below names the authority and the statute for each.

1. Parties & Roles

The subscribing clinic is the Data Controller. The Data Processor is Limitless Royalty LLC, a limited liability company formed in the State of Florida, United States, which operates the 3yadtk platform. The Processor acts only on the clinic's documented instructions regarding patient data.

2. Purpose of Processing

3yadtk processes patient data for the sole purpose of delivering clinic management services to the subscribing clinic.

3. Security Measures

Security measures include: AES-256 encryption at rest, TLS 1.3 in transit, MFA for administrative access, and restricted, logged access.

4. Storage Location and Cross-Border Transfer

By default, patient data is stored on our hosting provider's infrastructure in Europe — including data belonging to clinics in Saudi Arabia and the UAE — so using the platform on the standard subscription involves transferring data outside those countries. Because the Processor is established in the United States and its personnel access the hosted data from there, the controller has two destinations to account for rather than one: the European hosting region, and the United States. In-region hosting is available as a paid add-on on request, once agreed in writing and provisioned for the clinic. As data controller, the clinic is responsible for assessing the lawfulness of those transfers and obtaining any regulatory consent required; we will provide the information needed for that assessment on request.

5. Data Breach Notification

Upon discovering a data breach affecting patient data, we will notify the subscribing clinic within 72 hours of discovery.

6. Sub-processors

We use trusted sub-processors: Railway (hosting, databases and file storage), Resend (transactional email and appointment reminders), Stripe (payment processing, with no access to patient data), Sentry (error tracking, no patient data), and Google (the in-app assistant, where it is enabled). We use no SMS or WhatsApp provider today, because neither channel is enabled. We notify clinics 30 days before any change to sub-processors.

7. Data Deletion

Upon account termination, patient data is securely deleted within 90 days, unless the medical-record retention rules of the clinic's own country require longer — these differ by country and reach twenty-five years in some. The retention period that binds you is set by your country's law, not by our choice.

8. Standard Contractual Clauses (SCC)

For transfers of personal data outside the European Economic Area or otherwise subject to GDPR Art. 46 — including access from the United States, where the Processor is established — Limitless Royalty LLC adopts the EU Commission Standard Contractual Clauses (Module 2: Controller→Processor) as the primary international transfer mechanism.

Annex A — Description of Processing: Clinic operational data and electronic medical records for clinic management service delivery.

Annex B — Technical & Organisational Measures: AES-256 at rest with per-field encryption of patient data, TLS 1.3 in transit, MFA, least-privilege access, and an audit trail the database will not permit to be deleted.

Annex C — Sub-processors: Railway (hosting, databases and storage), Resend (email and appointment reminders), Stripe (payments), Sentry (error monitoring), Google (the in-app assistant, where enabled). This is the same list published in the privacy policy.

9. Regional Supervisory Authorities

If a complaint cannot be resolved internally, clinics and patients have the right to lodge a complaint with the relevant supervisory authority:

CountryAuthorityLaw
🇸🇦 Saudi ArabiaNDMO / SAMAPDPL 2021
🇦🇪 UAETDRAFederal DL 45/2021
🇪🇬 EgyptMCITLaw 151/2020
🇶🇦 QatarNPCLaw 13/2016
🇧🇭 BahrainPDPB (MOIC)Law 30/2018
🇯🇴 JordanNICLaw 24/2023
🇴🇲 OmanNCSIRD 6/2022
🇲🇦 MoroccoCNDPLaw 09-08
🇹🇳 TunisiaINPDPLaw 2004-63
🇱🇧 LebanonMTI (pending DPA)Law 81/2018

Request a Custom DPA

For clinics requiring a formally signed DPA or custom terms, contact: legal@3yadtk.com