Paid-Client Legal Pack
Pack version: 12 July 2026. Owner: Aryan Rao, Proprietor. Status: counsel-review draft; legal reviewer not appointed. Complete every bracketed field, obtain appropriate legal review for the client jurisdiction, and sign the applicable documents before production data import.
Production PHI is disabled by default
Checkout, payment, or a general service agreement does not authorize unrestricted production PHI. Live patient-message processing may be enabled per clinic only after the applicable clinic agreement, security and subprocessor review, and country-specific data-processing requirements are completed and recorded.
Provider record
| Legal name | Aryan Rao |
|---|---|
| Trading name | Smart Clinic Reception |
| Structure | Sole Proprietorship; not incorporated |
| Address | Mahendragarh, Haryana – 123029, India |
| GST status | Not registered for GST |
| Business email | connect@smartclinicreception.online |
| Legal/privacy/security/support | support@smartclinicreception.online |
| Authorized signer | Aryan Rao, Proprietor |
Document 1 — Pilot Order Form
This Order Form is entered between Aryan Rao, sole proprietor trading as Smart Clinic Reception (“Provider”), and the clinic identified below (“Customer”). It incorporates the signed MSA, DPA, applicable schedules, and the online Terms version stated below.
| Customer legal name | [CLINIC LEGAL NAME] |
|---|---|
| Registered address | [CLINIC ADDRESS] |
| Signer | [NAME, TITLE, EMAIL] |
| Clinic/location | [ONE APPROVED LOCATION] |
| Plan and fee | [PLAN] / [FEE AND CURRENCY], paid for one 30-day access period |
| Terms version | 2026-07-12 |
| Start / target launch | [DATES] |
| Included lead sources | [EXACT SOURCES; DO NOT LIST UNBUILT FEATURES] |
| Included integrations | [PROVIDERS, ACCOUNTS, DEPENDENCIES] |
| Excluded services | Clinical advice, diagnosis, treatment decisions, autonomous pricing/insurance promises, unrestricted PHI, and any feature not expressly listed above |
| Production data class | No unrestricted PHI unless a signed clinic-specific activation addendum says otherwise |
| Support channel | support@smartclinicreception.online |
Acceptance criteria: configured sources pass test events; staff users and approval rules are confirmed; consent/opt-out wording is approved; security and data scope are recorded; launch approval is written. Changes require a written change request identifying scope, fee, timeline, testing, and approvers.
Document 2 — Master Services Agreement
1. Formation and documents
The agreement consists of signed Order Forms, this MSA, applicable DPA/BAA and schedules, and the identified online Terms. A signed document prevails over online terms for a direct conflict; an Order Form prevails for commercial scope.
2. Services and changes
Provider will supply the services and implementation assistance in each Order Form with reasonable skill and care. Customer dependencies, credentials, approvals, content, and third-party accounts must be delivered on time. A change is effective only when authorized representatives approve its scope, price, security impact, and schedule in writing.
3. Customer responsibilities
Customer controls its patient/prospect relationship and is responsible for lawful data collection, notices, consent, approved claims, staff review, suppression lists, account security, clinical escalation, and its users. Customer will not instruct Provider to send unlawful or deceptive communications or process data outside the approved scope.
4. Fees, taxes, renewal, and refunds
Fees are paid as stated in the Order Form. Public checkout is a one-time purchase of 30 days and never auto-renews. Each distinct verified payment adds one 30-day period. Fees exclude applicable taxes unless stated. Provider is not registered for GST as of this pack version. Refunds consider work delivered and committed third-party cost; a confirmed full refund revokes the matching access grant.
5. Confidentiality
Each receiving party will protect confidential information with at least reasonable care, use it only for the agreement, and disclose it only to personnel and contractors who need it and are bound by confidentiality. Exclusions apply to information independently developed, lawfully received, public without breach, or required by law after permitted notice.
6. Intellectual property and data
Customer owns its data, brand, content, and materials. Provider owns the platform, code, workflows, models, templates, documentation, improvements, and pre-existing materials. Customer grants Provider a limited, revocable right to process Customer data only to deliver, secure, support, and comply with the agreement.
7. Privacy, security, and AI
The DPA governs personal data. The Security Schedule describes current controls, not a certification. AI output is a staff-review draft and must not make autonomous clinical, pricing, or insurance decisions. No unrestricted production PHI is permitted unless a clinic-specific written activation is signed after legal, vendor, and security review.
8. Warranties
Each party has authority to sign. Provider warrants reasonable care in performing the service. Except for express commitments, the service is provided as available to the extent permitted by law. Provider does not guarantee uninterrupted third-party systems, revenue, clinical outcomes, patient acceptance, or a number of bookings.
9. Liability and indemnity — counsel review required
Neither party is liable for indirect, incidental, special, punitive, or consequential loss to the extent permitted by law. The parties must negotiate and insert an appropriate aggregate liability cap, statutory carve-outs, data/security allocation, third-party intellectual-property protection, customer-content and unlawful-instruction indemnities, defense control, and insurance requirements before signature: [COUNSEL-APPROVED LIABILITY AND INDEMNITY CLAUSE].
10. Term, suspension, and termination
The MSA continues while an Order Form is active. Either party may terminate for uncured material breach after written notice and a reasonable cure period stated in the Order Form, or immediately where cure is impossible, law requires, or security/patient safety is at risk. Provider may suspend for non-payment, unlawful use, credential compromise, or provider restrictions.
11. Exit, force majeure, notices, and law
Exit follows the Support and Offboarding Schedule. Neither party is liable for delay beyond reasonable control, excluding accrued payments. Notices go to the stated contract contacts. Unless the Order Form states a counsel-approved alternative, Indian law governs and courts of competent jurisdiction in Mahendragarh District, Haryana, India have jurisdiction, following good-faith written escalation first.
Document 3 — Data Processing Addendum
Customer is controller/business and Provider is processor/service provider for Customer Data. Provider processes only documented instructions necessary to provide intake, follow-up, booking, reporting, security, support, and deletion/export services.
Processing schedule
- Subjects: Customer users, clinic prospects/leads, appointment contacts, and support contacts.
- Data: identifiers, contact details, consent evidence, inquiry context, messages, booking details, account data, and security logs. Clinical records/diagnoses are excluded unless separately approved.
- Duration: the service term plus documented export, deletion, backup, dispute, and legal-retention periods.
- Purpose: contracted workflow delivery only; no sale of personal data and no independent advertising use.
Processor duties
Provider will maintain confidentiality and appropriate technical/organizational measures; restrict access; assist with data-subject requests, impact assessments, breach obligations, and regulator inquiries as reasonably required; keep processing records; notify Customer of unlawful instructions; and delete or return data at end of service unless law requires retention.
Subprocessors and transfers
Customer authorizes listed subprocessors subject to written data-protection obligations. Provider will publish/materially notify changes through the Subprocessors page and contract channel. Customer may object on reasonable data-protection grounds. International transfer mechanisms and hosting location must be confirmed for the clinic jurisdiction before launch.
Security incidents and audit
Provider will notify Customer without undue delay after confirming a personal-data breach affecting Customer Data, provide available facts and remediation updates, and preserve evidence. Provider will supply reasonable compliance information; audits must protect other customers, security, confidentiality, and service continuity.
Document 4 — Conditional Business Associate Agreement
Inactive unless separately completed and signed. This schedule does not authorize PHI today. Before activation, confirm that Customer is a HIPAA covered entity/business associate, Provider's role is a business associate, every relevant subprocessor supports required obligations, and the workflow/security review is approved.
If activated, the BAA must define HIPAA terms; permitted and required uses/disclosures; minimum-necessary restrictions; safeguards and Security Rule duties for ePHI; reporting of impermissible use/disclosure, breaches, and security incidents; subcontractor flow-down; access, amendment, and accounting support; HHS access; return/destruction; cure and termination rights; survival; and the exact notification timeline and contacts.
| Covered Entity | [CLINIC LEGAL NAME] |
|---|---|
| Business Associate | Aryan Rao trading as Smart Clinic Reception |
| Permitted PHI/workflow | [MINIMUM NECESSARY DATA AND PURPOSE] |
| Approved PHI subprocessors | [VERIFIED LIST AND BAAs] |
| Incident notice | [COUNSEL-APPROVED DEADLINE AND CONTACTS] |
| Activation approval | [LEGAL + SECURITY + BOTH SIGNERS] |
Schedule A — Security Controls
- Cloudflare Pages Functions and D1 production boundary; TLS in transit.
- Hashed passwords/session tokens, secure cookies, clinic-scoped authorization, and operator-only administration.
- Encrypted sensitive integration tokens, signed webhooks, idempotency controls, audit events, and masked operational views.
- Staff approval for outbound drafts; no clinical-advice mode; consent, opt-out, quiet-hours, and risk-handoff controls.
- Retention/erasure tooling, lead export, incident logging, dependency/provider review, and documented access/offboarding steps.
These are current design controls, not a claim of certification or a substitute for a clinic-specific risk assessment. Security exceptions and required remediation must be recorded before launch.
Schedule B — Acceptable Use and Messaging Consent
Customer will provide lawful recipient lists and consent evidence, identify marketing versus service messages, honor STOP/unsubscribe promptly, avoid purchased/scraped lists, respect quiet hours and country/provider rules, and keep staff escalation available. Prohibited uses include spam, harassment, discrimination, impersonation, misleading medical/financial claims, malware, credential abuse, unlawful surveillance, or bypassing safety and access controls.
Schedule C — Support, Service, and Offboarding
| Support channel | support@smartclinicreception.online |
|---|---|
| Coverage | [BUSINESS HOURS AND TIME ZONE] |
| Critical response target | [TARGET; NOT A GUARANTEED RESOLUTION] |
| Standard response target | [TARGET] |
| Maintenance | [NOTICE PROCESS] |
| Export window | [DAYS AFTER TERMINATION] |
| Deletion schedule | [ACTIVE + BACKUP TIMELINE AND LEGAL HOLDS] |
Offboarding includes disabling integrations and credentials, exporting agreed data, confirming open patient/staff handoffs, revoking users, recording retained legal/audit data, scheduling deletion, and providing written completion evidence.
Signature record
Provider: Aryan Rao, Proprietor — Signature: ____________________ Date: __________
Customer legal name: ____________________ Authorized signer/title: ____________________ Signature: ____________________ Date: __________
Applicable documents: ☐ Order Form ☐ MSA ☐ DPA ☐ Conditional BAA ☐ Security Schedule ☐ Acceptable Use ☐ Support/Offboarding
Before signature: replace every bracketed field, attach the exact scope and pricing, complete legal review for the client jurisdiction, verify vendor/data-location requirements, and store the executed document reference against the clinic account.