Back to Smart Clinic Reception AI

Paid-Client Legal Pack

Pack version: 12 July 2026. Owner: Aryan Rao, Proprietor. Status: counsel-review draft; legal reviewer not appointed. Complete every bracketed field, obtain appropriate legal review for the client jurisdiction, and sign the applicable documents before production data import.

Provider record

Legal nameAryan Rao
Trading nameSmart Clinic Reception
StructureSole Proprietorship; not incorporated
AddressMahendragarh, Haryana – 123029, India
GST statusNot registered for GST
Business emailconnect@smartclinicreception.online
Legal/privacy/security/supportsupport@smartclinicreception.online
Authorized signerAryan Rao, Proprietor

Document 1 — Pilot Order Form

This Order Form is entered between Aryan Rao, sole proprietor trading as Smart Clinic Reception (“Provider”), and the clinic identified below (“Customer”). It incorporates the signed MSA, DPA, applicable schedules, and the online Terms version stated below.

Customer legal name[CLINIC LEGAL NAME]
Registered address[CLINIC ADDRESS]
Signer[NAME, TITLE, EMAIL]
Clinic/location[ONE APPROVED LOCATION]
Plan and fee[PLAN] / [FEE AND CURRENCY], paid for one 30-day access period
Terms version2026-07-12
Start / target launch[DATES]
Included lead sources[EXACT SOURCES; DO NOT LIST UNBUILT FEATURES]
Included integrations[PROVIDERS, ACCOUNTS, DEPENDENCIES]
Excluded servicesClinical advice, diagnosis, treatment decisions, autonomous pricing/insurance promises, unrestricted PHI, and any feature not expressly listed above
Production data classNo unrestricted PHI unless a signed clinic-specific activation addendum says otherwise
Support channelsupport@smartclinicreception.online

Acceptance criteria: configured sources pass test events; staff users and approval rules are confirmed; consent/opt-out wording is approved; security and data scope are recorded; launch approval is written. Changes require a written change request identifying scope, fee, timeline, testing, and approvers.

Document 2 — Master Services Agreement

1. Formation and documents

The agreement consists of signed Order Forms, this MSA, applicable DPA/BAA and schedules, and the identified online Terms. A signed document prevails over online terms for a direct conflict; an Order Form prevails for commercial scope.

2. Services and changes

Provider will supply the services and implementation assistance in each Order Form with reasonable skill and care. Customer dependencies, credentials, approvals, content, and third-party accounts must be delivered on time. A change is effective only when authorized representatives approve its scope, price, security impact, and schedule in writing.

3. Customer responsibilities

Customer controls its patient/prospect relationship and is responsible for lawful data collection, notices, consent, approved claims, staff review, suppression lists, account security, clinical escalation, and its users. Customer will not instruct Provider to send unlawful or deceptive communications or process data outside the approved scope.

4. Fees, taxes, renewal, and refunds

Fees are paid as stated in the Order Form. Public checkout is a one-time purchase of 30 days and never auto-renews. Each distinct verified payment adds one 30-day period. Fees exclude applicable taxes unless stated. Provider is not registered for GST as of this pack version. Refunds consider work delivered and committed third-party cost; a confirmed full refund revokes the matching access grant.

5. Confidentiality

Each receiving party will protect confidential information with at least reasonable care, use it only for the agreement, and disclose it only to personnel and contractors who need it and are bound by confidentiality. Exclusions apply to information independently developed, lawfully received, public without breach, or required by law after permitted notice.

6. Intellectual property and data

Customer owns its data, brand, content, and materials. Provider owns the platform, code, workflows, models, templates, documentation, improvements, and pre-existing materials. Customer grants Provider a limited, revocable right to process Customer data only to deliver, secure, support, and comply with the agreement.

7. Privacy, security, and AI

The DPA governs personal data. The Security Schedule describes current controls, not a certification. AI output is a staff-review draft and must not make autonomous clinical, pricing, or insurance decisions. No unrestricted production PHI is permitted unless a clinic-specific written activation is signed after legal, vendor, and security review.

8. Warranties

Each party has authority to sign. Provider warrants reasonable care in performing the service. Except for express commitments, the service is provided as available to the extent permitted by law. Provider does not guarantee uninterrupted third-party systems, revenue, clinical outcomes, patient acceptance, or a number of bookings.

9. Liability and indemnity — counsel review required

Neither party is liable for indirect, incidental, special, punitive, or consequential loss to the extent permitted by law. The parties must negotiate and insert an appropriate aggregate liability cap, statutory carve-outs, data/security allocation, third-party intellectual-property protection, customer-content and unlawful-instruction indemnities, defense control, and insurance requirements before signature: [COUNSEL-APPROVED LIABILITY AND INDEMNITY CLAUSE].

10. Term, suspension, and termination

The MSA continues while an Order Form is active. Either party may terminate for uncured material breach after written notice and a reasonable cure period stated in the Order Form, or immediately where cure is impossible, law requires, or security/patient safety is at risk. Provider may suspend for non-payment, unlawful use, credential compromise, or provider restrictions.

11. Exit, force majeure, notices, and law

Exit follows the Support and Offboarding Schedule. Neither party is liable for delay beyond reasonable control, excluding accrued payments. Notices go to the stated contract contacts. Unless the Order Form states a counsel-approved alternative, Indian law governs and courts of competent jurisdiction in Mahendragarh District, Haryana, India have jurisdiction, following good-faith written escalation first.

Document 3 — Data Processing Addendum

Customer is controller/business and Provider is processor/service provider for Customer Data. Provider processes only documented instructions necessary to provide intake, follow-up, booking, reporting, security, support, and deletion/export services.

Processing schedule

Processor duties

Provider will maintain confidentiality and appropriate technical/organizational measures; restrict access; assist with data-subject requests, impact assessments, breach obligations, and regulator inquiries as reasonably required; keep processing records; notify Customer of unlawful instructions; and delete or return data at end of service unless law requires retention.

Subprocessors and transfers

Customer authorizes listed subprocessors subject to written data-protection obligations. Provider will publish/materially notify changes through the Subprocessors page and contract channel. Customer may object on reasonable data-protection grounds. International transfer mechanisms and hosting location must be confirmed for the clinic jurisdiction before launch.

Security incidents and audit

Provider will notify Customer without undue delay after confirming a personal-data breach affecting Customer Data, provide available facts and remediation updates, and preserve evidence. Provider will supply reasonable compliance information; audits must protect other customers, security, confidentiality, and service continuity.

Document 4 — Conditional Business Associate Agreement

Inactive unless separately completed and signed. This schedule does not authorize PHI today. Before activation, confirm that Customer is a HIPAA covered entity/business associate, Provider's role is a business associate, every relevant subprocessor supports required obligations, and the workflow/security review is approved.

If activated, the BAA must define HIPAA terms; permitted and required uses/disclosures; minimum-necessary restrictions; safeguards and Security Rule duties for ePHI; reporting of impermissible use/disclosure, breaches, and security incidents; subcontractor flow-down; access, amendment, and accounting support; HHS access; return/destruction; cure and termination rights; survival; and the exact notification timeline and contacts.

Covered Entity[CLINIC LEGAL NAME]
Business AssociateAryan Rao trading as Smart Clinic Reception
Permitted PHI/workflow[MINIMUM NECESSARY DATA AND PURPOSE]
Approved PHI subprocessors[VERIFIED LIST AND BAAs]
Incident notice[COUNSEL-APPROVED DEADLINE AND CONTACTS]
Activation approval[LEGAL + SECURITY + BOTH SIGNERS]

Schedule A — Security Controls

These are current design controls, not a claim of certification or a substitute for a clinic-specific risk assessment. Security exceptions and required remediation must be recorded before launch.

Schedule B — Acceptable Use and Messaging Consent

Customer will provide lawful recipient lists and consent evidence, identify marketing versus service messages, honor STOP/unsubscribe promptly, avoid purchased/scraped lists, respect quiet hours and country/provider rules, and keep staff escalation available. Prohibited uses include spam, harassment, discrimination, impersonation, misleading medical/financial claims, malware, credential abuse, unlawful surveillance, or bypassing safety and access controls.

Schedule C — Support, Service, and Offboarding

Support channelsupport@smartclinicreception.online
Coverage[BUSINESS HOURS AND TIME ZONE]
Critical response target[TARGET; NOT A GUARANTEED RESOLUTION]
Standard response target[TARGET]
Maintenance[NOTICE PROCESS]
Export window[DAYS AFTER TERMINATION]
Deletion schedule[ACTIVE + BACKUP TIMELINE AND LEGAL HOLDS]

Offboarding includes disabling integrations and credentials, exporting agreed data, confirming open patient/staff handoffs, revoking users, recording retained legal/audit data, scheduling deletion, and providing written completion evidence.

Signature record

Provider: Aryan Rao, Proprietor — Signature: ____________________ Date: __________

Customer legal name: ____________________ Authorized signer/title: ____________________ Signature: ____________________ Date: __________

Applicable documents: ☐ Order Form ☐ MSA ☐ DPA ☐ Conditional BAA ☐ Security Schedule ☐ Acceptable Use ☐ Support/Offboarding

Before signature: replace every bracketed field, attach the exact scope and pricing, complete legal review for the client jurisdiction, verify vendor/data-location requirements, and store the executed document reference against the clinic account.