Neogenic Data Processing Agreement

Earlier version (24 September 2026)See the current version

Effective from the date your clinic accepts it in Neogenic.

1. Parties and roles

1.1 This agreement is between the clinic whose authorized person accepted it during onboarding, as recorded in Annex 1 (the Clinic), and Scality Ltd (Scality), which provides the Neogenic software. It forms part of the Neogenic Terms of Service.

1.2 For the processing in section 2 the Clinic is the controller and Scality is the processor. Scality's own processing of staff account, billing and support-contact data as controller is described in its privacy notice and is outside this agreement.

2. What is processed

2.1 Purpose: providing the Neogenic service to the Clinic: managing contacts, leads and enquiries, companies, opportunities, tasks, scheduling, forms, content and communications, and the Neo assistant acting within staff permissions, as the Clinic configures them.

2.2 Data subjects: the Clinic's leads, enquirers, clients and business contacts, and Clinic staff users.

2.3 Personal data: contact details (name, email, phone), source and campaign, marketing-consent and opt-out status and their records, enquiry, pipeline and appointment status, notes and tasks, form submissions, email/message history, and staff user identifiers.

2.4 Excluded data (version 1): the Clinic shall not enter, and Scality is not instructed to process, special-category data under this version. That includes health information such as symptoms, conditions, diagnoses, treatments received, medical history, clinical notes, patient files and lab results. Service or treatment names from the Clinic's public menu used as marketing interest labels are allowed only if the Clinic has assessed they do not reveal health information about the person. If excluded data is entered by mistake, the Clinic removes it or asks Scality to, and the parties treat it as a potential incident under section 6.

2.5 Duration: from acceptance for as long as Scality processes Clinic data, including the end-of-service period in section 9. A later version accepted by the Clinic replaces this one.

3. Instructions

3.1 Scality processes the data only on the Clinic's documented instructions: this agreement, and the settings, automations and actions that authorized Clinic users configure in Neogenic within its scope. This includes instructions about transfers, unless EU or Member State law requires otherwise; Scality informs the Clinic of that requirement first where legally allowed.

3.2 Scality tells the Clinic immediately if it believes an instruction infringes data-protection law.

3.3 The Clinic is responsible for the lawful basis of its marketing, including consent or the existing-customer exemption for electronic marketing, its privacy notices to leads, and honouring objections and unsubscribes. Neogenic's unsubscribe and suppression functions support this but do not replace the Clinic's decisions.

3.4 Neo (AI assistant): the Clinic's staff may use Neo to act on Clinic records within their own permissions. Neo is an AI system; staff are told so in the product. Scality does not use Clinic data to train AI models and instructs its AI providers not to train on it or retain it beyond what the provider needs to deliver the service.

4. Confidentiality and security

4.1 Only people and service identities that need access for the service may access the data. They are bound by confidentiality.

4.2 Scality applies security measures appropriate to the risk (Article 32), including: encryption in transit, role-based staff permissions within each clinic, separation between clinics, multi-factor authentication for administrative access, and primary storage in an EU-hosted database. Annex 2 lists the measures in force.

4.3 Scality does not access Clinic data for support without the Clinic's request or a security need. Any such access is recorded.

5. Subprocessors

5.1 The Clinic gives general written authorization for the subprocessors on the published subprocessor list.

5.2 Scality gives the Clinic at least 14 days' written notice to the Clinic's privacy contact before adding or replacing a subprocessor, so the Clinic can object. If an objection cannot be resolved, the Clinic may stop the affected processing or end the service.

5.3 Scality binds each subprocessor to data-protection obligations equivalent to this agreement and remains liable to the Clinic for them.

6. Assistance, requests and incidents

6.1 Scality helps the Clinic answer data-subject requests (access, correction, deletion, objection, unsubscribe) with the product's functions or, where needed, manually. Scality forwards any request it receives directly to the Clinic.

6.2 Scality notifies the Clinic without undue delay, and in any case within 48 hours, after becoming aware of a personal-data breach affecting the Clinic's data. It gives the information then available and updates it as more becomes known.

6.3 Scality provides information reasonably needed for the Clinic's security, breach, and impact-assessment duties (Articles 32–36).

7. Transfers

7.1 Primary storage is in the EU (see the subprocessor list). Where a subprocessor processes data outside the EEA, Scality relies on an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified) or the Commission's standard contractual clauses, as shown for each subprocessor on the subprocessor list.

8. Audit and records

8.1 Scality makes available the information needed to demonstrate compliance with this agreement and allows and contributes to reasonable audits by the Clinic or its mandated auditor, with reasonable notice and confidentiality.

9. End of processing

9.1 When the service ends, the Clinic chooses return or deletion. Scality provides an export of the Clinic's data in a usable format on request within 30 days, then deletes live copies. Backup copies expire on the backup schedule in Annex 2 and are not restored into use.

9.2 If the Clinic accepts a later version, the data continues under that version.

10. General

10.1 This agreement prevails over the service terms on data protection. It is governed by the laws of the Republic of Cyprus.

Accepted electronically by the Clinic's authorized person during onboarding (Annex 1 acceptance record).

Annex 1 — Parties and acceptance

Scality Ltd, company HE459172, Attikis 3, City Residences 1, 6045 Larnaca, Cyprus; VAT CY60062286C. Privacy contact: privacy@neogenic.ai. Security incidents: security@neogenic.ai.

The Clinic is identified by the details its authorized person enters during onboarding: legal entity name, registration number, registered address, privacy contact and security-incident contact. Neogenic records the accepting person, the time of acceptance and this version.

Annex 2 — Security measures

  • All traffic to and from Neogenic is encrypted in transit (TLS).
  • Clinic data is stored in an EU-hosted database that is encrypted at rest.
  • Every user signs in with their own account. Access within a clinic follows the roles and permissions the clinic sets, and each clinic's data is separated from every other clinic's in the database.
  • Access to production systems is limited to authorized Scality personnel and protected by multi-factor authentication.
  • The database is backed up daily. Backups are kept for a limited period and then expire.
  • Security incidents are handled under a documented procedure, including notice to the Clinic under section 6.2.

Other earlier versions: Version 2 (30 September 2026)

Product preview

Neogenic product preview

Clinic enquiries board grouped by stage, with cards showing each opportunity's contact, status and entered value and a total per stage
Where each enquiry stands, and which ones need follow-up. Open full-size image