Neogenic Data Processing Agreement

Last updated 1 October 2026

Effective from the date your clinic accepts it in Neogenic.

1. Parties and roles

1.1 This agreement is between the clinic whose authorized person accepted it during onboarding, as recorded in Annex 1 (the Clinic), and Scality Ltd (Scality), which provides the Neogenic software. It forms part of the Neogenic Terms of Service.

1.2 For the processing in section 2 the Clinic is the controller and Scality is the processor. Scality's own processing of staff account, billing and support-contact data as controller is described in its privacy notice and is outside this agreement.

2. What is processed

2.1 Purpose: providing the Neogenic service to the Clinic: managing contacts, leads and enquiries, companies, opportunities, tasks, scheduling, forms, content and communications, and the Neo assistant acting within staff permissions, as the Clinic configures them. Nature of processing: collecting (including through the Clinic's forms and connected mailboxes), storing, organising, retrieving and displaying, sending email and calendar updates that the Clinic's staff make, AI-assisted drafting and summarising by Neo when staff ask for it, exporting and deleting.

2.2 Data subjects: the Clinic's leads, enquirers, clients and business contacts, and Clinic staff users.

2.3 Personal data: contact details (name, email, phone), source and campaign, marketing-consent and opt-out status and their records, including the record of a person's objection to marketing that is kept after their contact is erased (section 9.3), enquiry, pipeline and appointment status, calendar and appointment details, notes and tasks, form submissions (with the submitter's IP address and browser information recorded with them), email/message history, conversations with Neo and the instructions staff give it, files staff share with Neo, and staff user identifiers.

2.4 Excluded data (version 1): the Clinic shall not enter, and Scality is not instructed to process, special-category data under this version. That includes health information such as symptoms, conditions, diagnoses, treatments received, medical history, clinical notes, patient files and lab results. Service or treatment names from the Clinic's public menu used as marketing interest labels are allowed only if the Clinic has assessed they do not reveal health information about the person. If excluded data is entered by mistake, the Clinic removes it or asks Scality to, and the parties treat it as a potential incident under section 6.

2.5 Duration: from acceptance for as long as Scality processes Clinic data, including the end-of-service period in section 9. A later version accepted by the Clinic replaces this one.

3. Instructions

3.1 Scality processes the data only on the Clinic's documented instructions: this agreement, and the settings, automations and actions that authorized Clinic users configure in Neogenic within its scope. This includes instructions about transfers, unless EU or Member State law requires otherwise; Scality informs the Clinic of that requirement first where legally allowed.

3.2 Scality tells the Clinic immediately if it believes an instruction infringes data-protection law.

3.3 The Clinic is responsible for the lawful basis of its marketing, including consent or the existing-customer exemption for electronic marketing, its privacy notices to leads, and honouring objections and unsubscribes. Neogenic's unsubscribe and suppression functions support this but do not replace the Clinic's decisions.

3.4 Neo (AI assistant): the Clinic's staff may use Neo to act on Clinic records within their own permissions. Neo is an AI system; staff are told so in the product. Scality does not use Clinic data to train AI models and instructs its AI providers not to train on it or retain it beyond what the provider needs to deliver the service.

4. Confidentiality and security

4.1 Only people and service identities that need access for the service may access the data. They are bound by confidentiality.

4.2 Scality applies security measures appropriate to the risk (Article 32), including: encryption in transit, role-based staff permissions within each clinic, separation between clinics, multi-factor authentication for administrative access, and primary storage in an EU-hosted database. Annex 2 lists the measures in force.

4.3 Scality does not access Clinic data for support without the Clinic's request or a security need. Access through the Neogenic admin console is recorded.

5. Subprocessors

5.1 The Clinic gives general written authorization for the subprocessors on the published subprocessor list.

5.2 Scality gives the Clinic at least 14 days' written notice to the Clinic's privacy contact before adding or replacing a subprocessor, so the Clinic can object. If an objection cannot be resolved, the Clinic may stop the affected processing or end the service.

5.3 Scality binds each subprocessor to data-protection obligations equivalent to this agreement and remains liable to the Clinic for them.

6. Assistance, requests and incidents

6.1 Scality helps the Clinic answer data-subject requests (access, correction, deletion, objection, unsubscribe) with the product's functions or, where needed, manually. Scality forwards any request it receives directly to the Clinic. Help with switching to another provider is set out in section 10 of the Terms of Service.

6.2 Scality notifies the Clinic without undue delay, and in any case within 48 hours, after becoming aware of a personal-data breach affecting the Clinic's data. It gives the information then available and updates it as more becomes known.

6.3 Scality provides information reasonably needed for the Clinic's security, breach, and impact-assessment duties (Articles 32–36).

7. Transfers

7.1 Primary storage is in the EU (see the subprocessor list). Where a subprocessor processes data outside the EEA, Scality relies on an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified) or the Commission's standard contractual clauses, as shown for each subprocessor on the subprocessor list.

8. Audit and records

8.1 Scality makes available the information needed to demonstrate compliance with this agreement and allows and contributes to reasonable audits by the Clinic or its mandated auditor, with reasonable notice and confidentiality.

9. End of processing

9.1 When the service ends, the Clinic chooses return or deletion. Scality provides an export of the Clinic's data in a usable format on request within 30 days, then deletes live copies. This does not apply to a copy that EU or Member State law requires Scality to keep; Scality then keeps only that copy, protects it and uses it for nothing else. Backup copies expire on the backup schedule in Annex 2 and are not restored into use.

9.2 If the Clinic accepts a later version, the data continues under that version.

9.3 Marketing objections after erasure. When a contact who has objected to marketing or unsubscribed is erased during the service, Scality keeps, on the Clinic's instruction, only the email address and the date of the objection, so that the Clinic does not market to that person again by mistake (GDPR Articles 17(3) and 21). This record is used for nothing else and is deleted with the rest of the Clinic's data under section 9.1.

9.4 After deleting the Clinic's data under section 9.1, Scality confirms the erasure in writing to the Clinic's privacy contact.

10. General

10.1 This agreement prevails over the service terms on data protection. It is governed by the laws of the Republic of Cyprus.

Accepted electronically by the Clinic's authorized person during onboarding (Annex 1 acceptance record).

Annex 1 — Parties and acceptance

Scality Ltd, company HE459172, Attikis 3, City Residences 1, 6045 Larnaca, Cyprus; VAT CY60062286C. Privacy contact: privacy@neogenic.ai. Security incidents: security@neogenic.ai.

The Clinic is identified by the details its authorized person enters during onboarding: legal entity name, registration number, registered address, privacy contact and security-incident contact. Neogenic records the accepting person, the time of acceptance and this version.

Annex 2 — Security measures

  • Traffic between users and Neogenic, and between Neogenic and its providers over public networks, is encrypted in transit (TLS).
  • Clinic data is stored in an EU-hosted database that is encrypted at rest.
  • Every user signs in with their own account. Access within a clinic follows the roles and permissions the clinic sets, and each clinic's data is separated from every other clinic's in the database.
  • Access to production systems is limited to authorized Scality personnel and protected by multi-factor authentication.
  • The database is backed up daily. Backups are kept for 7 days and then expire.
  • Requests from Neo, the AI assistant, go only to the AI providers on the subprocessor list, which keep no copy of the data and do not train on it.
  • Application logs record identifiers, counts and timings, not the content of Clinic records or conversations.
  • Security incidents are handled under a documented procedure, including notice to the Clinic under section 6.2.

Previous versions: Version 3 (30 September 2026), Version 2 (30 September 2026), Version 1 (24 September 2026)

Product preview

Neogenic product preview

Clinic enquiries board grouped by stage, with cards showing each opportunity's contact, status and entered value and a total per stage
Where each enquiry stands, and which ones need follow-up. Open full-size image