Sehtak Data Processing Agreement (DPA)
Version: 2.1 Effective date: 2026-06-08 Document URL: https://sehtak.ae/legal/dpa
This Data Processing Agreement ("DPA") forms part of the Sehtak Terms of Service ("Terms", at sehtak.ae/legal/terms) and is binding on every Facility User of the Sehtak platform. By clicking "I agree to the Sehtak Terms of Service and Data Processing Agreement" at signup, you accept this DPA on behalf of the Facility you represent. Click-through acceptance satisfies the "in writing" requirement under UAE PDPL Article 26 by virtue of UAE Federal Decree-Law 46 of 2021 on Electronic Transactions and Trust Services.
This DPA applies to all Personal Data, including Protected Health Information ("PHI"), that Sehtak Processes on behalf of the Facility through the Services.
1. Definitions
Capitalised terms not defined here have the meanings given in the Terms.
- "Applicable Data Protection Laws" means UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the "PDPL"), UAE Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in Healthcare (the "ICT Health Law"), and any implementing regulations, executive directives, decisions of the UAE Data Office, and sector-specific rules of DHA, DOH, MOHAP, and SHA as applicable to the Facility.
- "Customer Data" means any Personal Data Sehtak Processes on the Facility's behalf under the Terms.
- "Personal Data" has the meaning given in PDPL Article 1.
- "Protected Health Information" or "PHI" means Personal Data concerning health within PDPL Article 1, and "health data" within the ICT Health Law.
- "Data Subject" means the individual to whom Personal Data relates (a patient or a member of the Facility's staff).
- "Process", "Processing" have the PDPL meanings.
- "Sub-processor" means any third party engaged by Sehtak to Process Customer Data under this DPA. The current list is published at https://sehtak.ae/legal/sub-processors.
- "Security Incident" means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data.
2. Roles and Scope
2.1 Roles
The Facility is the Controller of Customer Data. Sehtak is the Processor acting on the Facility's documented instructions.
Where Sehtak determines the purposes and means of processing for its own operational purposes (billing data, fraud prevention, sub-processor management, security operations, service-improvement analytics on de-identified data), Sehtak is the Controller for that limited scope. §11 (Sehtak as Controller) and the Sehtak Privacy Policy apply to that scope.
2.2 Scope
This DPA covers all Processing Sehtak performs in delivering the Services to the Facility. It supersedes any prior data-processing arrangement between the parties.
2.3 Subject matter, duration, nature, purpose
Set out in Annex A.
2.4 Categories of Data Subjects and Personal Data
Set out in Annex A.
2.5 The Facility's documented instructions
The Facility's "documented instructions" to Sehtak comprise: (a) this DPA; (b) the Terms; (c) any Order Form signed by both parties; (d) the configuration choices the Facility makes in the Facility dashboard (HIE opt-in elections, AI Scribe enablement, sub-processor objections, telehealth licence uploads, payment-processor selection); (e) any further written instruction the Facility issues at legal@sehtak.ae. Sehtak will not Process Customer Data for any purpose other than as set out in these instructions, except as required by UAE law.
3. Facility Obligations
3.1 The Facility warrants that:
- (a) it has a lawful basis under PDPL Article 4 for each category of Customer Data it loads into the Services;
- (b) it has obtained, recorded, and retains the necessary patient consents for the clinical Processing Sehtak performs on its behalf (Sehtak provides the in-product consent UX; the Facility is responsible for using it);
- (c) any consent the Facility has obtained for cross-emirate or cross-border transfer of Personal Data under PDPL Article 22 is sufficient for the routes described in §7;
- (d) the Facility's instructions to Sehtak comply with Applicable Data Protection Laws.
3.2 The Facility is responsible for verifying that its UAE health-authority licences (DHA / DOH / MOHAP / SHA) are valid and in good standing before activating any regulated feature in the Services (telehealth, eClaims, HIE submission, controlled-drug ledger, e-pharmacy storefront). The Services gate these features behind admin-verified licence uploads, but the Services do not validate the underlying authenticity of the licence; the Facility warrants the licence is genuine.
3.3 The Facility must respond to a Data Subject who exercises a right under PDPL Articles 9–17 (access, correction, deletion, restriction, portability, objection, automated-decision-making). Sehtak supports the Facility under §4.4 but the Controller remains responsible for the response.
3.4 The Facility must implement reasonable security measures on its own end (workstation security, staff training, password hygiene, MFA enrolment, off-boarding procedures when staff leave) commensurate with the sensitivity of PHI.
4. Sehtak Obligations as Processor
Sehtak will:
4.1 Process Customer Data only on the Facility's documented instructions (§2.5), including with regard to transfers to other emirates or third countries, unless required to do otherwise by UAE law (in which case Sehtak will inform the Facility of that legal requirement before Processing, unless prohibited by that law).
4.2 Confidentiality of personnel. Ensure that any personnel authorised to Process Customer Data is bound by a written confidentiality undertaking that survives the personnel's engagement.
4.3 Security measures. Implement and maintain the technical and organisational measures set out in Annex B, and not materially reduce the overall security posture below the level in Annex B without thirty (30) days' notice to the Facility.
4.4 Assist with Data Subject rights. Taking into account the nature of the Processing, assist the Facility in fulfilling its obligation to respond to requests from Data Subjects under PDPL Articles 9–17. The Services include built-in endpoints for each (request portal, in-app export, in-app NABIDH opt-out, marketing-consent revocation).
4.5 Assist with compliance. Assist the Facility in ensuring compliance with security, breach-notification, DPIA, and Data Office consultation obligations under PDPL.
4.6 Return or delete on termination. On termination of the Terms, return or delete all Customer Data within thirty (30) days of the data-export window expiring (Terms §15.6), except where retention is required by UAE law (clinical records minimum 25 years per ICT Health Law, audit logs 10 years, billing 7 years).
4.7 Audit support. Make available to the Facility the information necessary to demonstrate compliance with this DPA, and contribute to audits as set out in §9.
4.8 No reliance on Customer Data for own purposes (except as documented). Sehtak will not Process Customer Data for Sehtak's own marketing, sale to third parties, profiling against the Facility, or training of public AI models. The only Sehtak-as-Controller Processing permitted is the limited scope in §11.
4.9 DPO available. Sehtak's Data Protection Officer is reachable at dpo@sehtak.ae for any inquiry under this DPA.
5. Security Measures (summary)
Full controls listed in Annex B. Headlines:
- TLS 1.3 in transit; AES-256-GCM at rest for sensitive fields.
- RS256 JWT authentication; argon2id password hashing (above OWASP 2025 floor).
- Deny-by-default RBAC with per-tenant ownership checks on every PHI route; append-only audit log on every PHI read or mutation, retained 10 years.
- MFA enforced on all staff accounts.
- PHI resident in the UAE — compute (du Cloud), storage and database (Moro Hub), AI inference (UAE-hosted self-hosted vLLM + Whisper). No PHI to any non-UAE inference endpoint.
- AI Scribe transcripts de-identified before LLM Processing; raw audio and transcript purged after 30 days.
- 25-year retention on clinical records; immutable append-only audit log.
- Vulnerability management: blocking CI security gate (
pnpm audit --audit-level=high), Renovate auto-PRs, gitleaks scanning, annual external penetration testing.
6. Sub-processors
6.1 Authorisation
The Facility authorises Sehtak to engage the Sub-processors listed at https://sehtak.ae/legal/sub-processors.
6.2 Flow-down obligations
Each Sub-processor is engaged under a written agreement that imposes data-protection obligations no less protective than this DPA.
6.3 Notice of change
Sehtak will give the Facility at least thirty (30) days' prior written notice of the addition or replacement of any Sub-processor that Processes PHI. Notice is delivered in-app to the Facility admin and by email to the registered admin contact.
6.4 Objection
The Facility may object to a new Sub-processor on reasonable data-protection grounds within fourteen (14) days of notice. If the parties cannot resolve the objection within a further fourteen (14) days, the Facility's sole remedy is to terminate the Terms; no other remedy applies. Termination on this ground does not entitle the Facility to a refund of prepaid fees, but Sehtak will not enforce any remaining commitment term.
6.5 Sehtak's responsibility
Sehtak remains liable to the Facility for the acts and omissions of its Sub-processors in their performance of this DPA as if they were Sehtak's own acts and omissions, subject to the limitations of liability in the Terms.
7. Cross-Border and Cross-Emirate Transfers
7.1 Rule — PHI stays in the UAE
Customer Data containing PHI is hosted on UAE-resident infrastructure. PHI does not leave the UAE except as expressly permitted in this §7.
7.2 Permitted transfers (non-PHI metadata only)
- (a) WhatsApp message routing — Twilio (primary BSP) or Unifonic (UAE-resident BSP). Where Twilio routes WhatsApp messages through Meta US infrastructure for delivery, Sehtak enforces in code that no clinical content (diagnoses, lab values, prescription details) is included in the WhatsApp message body. Only appointment time, doctor name, and links to the Sehtak app are routed. The Facility's acceptance of this DPA constitutes consent to this routing under PDPL Article 22. (Sehtak is migrating clinical-context routing fully to Unifonic; see the sub-processors list for the current status.)
- (b) Transactional email — Resend (US/EU) processes operational email (reminders, password resets, signup verification, billing receipts). Email bodies do not include PHI; clinical content is delivered only via the in-app patient view.
- (c) Error tracking — Sentry (US) with aggressive PII scrubbing and PHI denylist.
- (d) Identity verification (eKYC) — Entrust IDV (formerly Onfido), operated by Onfido Ltd (UK, an Entrust company) under UK GDPR adequacy, processes the document scan (Emirates ID for UAE residents, passport for non-residents) and the liveness selfie. UAE residents who choose UAE Pass SOP3 instead never reach Entrust IDV; only users who elect document+selfie verification do.
- (e) Payment processing — Stripe and Tap Payments. Sehtak shares only payment-tokenised data, customer name, email, phone, and amount; no PHI.
7.3 Hard prohibitions
Sehtak will not transmit PHI to any non-UAE-resident inference endpoint, including without limitation Anthropic API, OpenAI API, Azure OpenAI, Amazon Bedrock, Google AI, or any other foreign cloud LLM endpoint. All AI Scribe and AI translation Processing runs on UAE-hosted self-hosted vLLM + Whisper. This prohibition is enforced architecturally (network ACLs prevent egress) and is audited. Breach of this §7.3 is carved out of the liability cap in Terms §13.3(d).
7.4 Migration on regulatory change
If a future regulatory change makes any route in §7.2 non-compliant, Sehtak will promptly notify the Facility and migrate to a UAE-resident alternative within a reasonable transition period.
7.5 Transfer-impact assessment
Sehtak maintains a written transfer-impact assessment for each route in §7.2, documenting: the categories of data transferred; the legal basis under PDPL Articles 22–24; the safeguards in place at the receiving end; and the residual risk to Data Subjects. The Facility may request the current assessment from dpo@sehtak.ae and Sehtak will provide it within fourteen (14) business days, subject to a confidentiality undertaking.
7.6 Patient-level cross-border consent
Where a Data Subject (patient) exercises a right under PDPL Article 22 to refuse a specific cross-border transfer (for example, refusing to have appointment-reminder metadata routed via Meta US infrastructure), the Facility will configure the Services to route that Data Subject's communications via the UAE-resident alternative (Unifonic) where available, and to fall back to in-product notification where not. Sehtak provides the routing toggle; the Facility is responsible for honouring the patient's election.
8. Security Incidents
8.1 Sehtak will notify the Facility without undue delay (target: 24 hours from confirmed detection) of any Security Incident affecting Customer Data.
8.2 The notice will describe, to the extent then known:
- (a) the nature of the incident (categories and approximate number of Data Subjects and records affected);
- (b) the likely consequences;
- (c) the measures taken or proposed to mitigate possible adverse effects;
- (d) the contact point at Sehtak (DPO).
8.3 Sehtak will assist the Facility in meeting any onward notification obligation to the UAE Data Office under PDPL Article 9 (target: 72 hours from the Facility's knowledge) and to affected Data Subjects where required.
8.4 Sehtak will record all Security Incidents in an internal log retained for at least five (5) years.
8.5 The Facility will reciprocally notify Sehtak of any Security Incident on the Facility's end that may affect Customer Data Processed by Sehtak (compromised staff credentials, lost devices with cached Customer Data, ransomware on the Facility's local network).
9. Audits
9.1 Sehtak will make available to the Facility, on at most one occasion per calendar year and on reasonable prior notice, the most recent third-party audit reports or attestations Sehtak holds (ISO 27001 readiness assessment, ADHICS attestation where applicable, penetration-test summary), subject to a confidentiality undertaking.
9.2 If, in the Facility's reasonable view, the third-party reports are insufficient to demonstrate compliance with this DPA, the Facility may request an on-site audit. The audit will be conducted at the Facility's cost during business hours, with at least thirty (30) days' notice, and will not unreasonably interfere with Sehtak's operations or compromise the confidentiality or security of other customers' data.
9.3 Sehtak may require that any on-site audit be performed by a mutually-agreed independent auditor under non-disclosure terms.
9.4 The Facility may not audit a Sub-processor directly. Sehtak will obtain audit information from the Sub-processor where reasonably required to demonstrate compliance.
10. Liability
This DPA is governed by the limitation-of-liability and indemnification provisions in the Terms §13 and §14. The carve-outs in Terms §13.3 apply, including §13.3(d) for breach of the §7.3 hard prohibitions. Nothing in this DPA limits liability that cannot be limited under UAE law.
11. Sehtak as Controller
For the limited Processing Sehtak performs as Controller (Facility admin contact data, billing data, fraud-prevention signals, sub-processor management, de-identified service-improvement analytics, security-operations telemetry), Sehtak applies the Sehtak Privacy Policy at https://sehtak.ae/legal/privacy and the technical and organisational measures in Annex B. Sehtak does not Process PHI in its Controller capacity.
12. Sehtak Data Protection Officer
Sehtak Data Protection Officer Sehtak FZ-LLC · Meydan Free Zone · Dubai · UAE Email: dpo@sehtak.ae Appointed under PDPL Article 23. Appointment letter on file at the registered office and available to the UAE Data Office on request.
All notices under this DPA are sent to dpo@sehtak.ae.
13. Order of Precedence
If there is any conflict between:
- (a) this DPA and the Terms — this DPA prevails for data-protection matters within its scope;
- (b) this DPA and the published Sub-Processors list — the Sub-Processors list prevails as the up-to-date statement of Sehtak's Sub-processor relationships;
- (c) this DPA and an Order Form — the Order Form prevails for the specific subject matter it covers, provided the Order Form does not reduce the data-protection level below this DPA;
- (d) this DPA and any other Sehtak document — this DPA prevails on data-protection matters.
ANNEX A — Subject Matter, Duration, Nature, Purpose; Categories of Data Subjects and Personal Data
Subject matter
Sehtak's provision of the Sehtak platform (clinic workspace, pharmacy workspace, doctor app, patient app, AI Scribe, patient communications, microsite, reception, claims, telehealth, identity verification) to the Facility.
Duration
The term of the Terms, plus:
- 25 years post-termination for clinical records (ICT Health Law)
- 10 years post-termination for audit logs (security and compliance)
- 7 years post-termination for billing and tax records (UAE financial-record retention)
- 5 years post-termination for security-incident logs (§8.4)
after which Personal Data is securely destroyed or anonymised.
Nature and purpose
Operational: providing clinical-records management, patient communications, billing and claims, telehealth, AI-assisted clinical documentation, identity verification, and marketing within explicit patient consent.
Categories of Data Subjects
1. The Facility's patients (current and former, and family members linked under the family-link feature). 2. The Facility's staff (doctors, nurses, receptionists, managers, owners, sales agents). 3. Third parties referenced in clinical records (next-of-kin, emergency contacts, prescribing or referring doctors at other facilities, insurance member contacts).
Categories of Personal Data and PHI
| Category | Examples | Sensitivity |
|---|---|---|
| Identifiers | Name, Emirates ID, passport number, UAE Pass UUID, MRN, phone, email, address | Personal Data; EID encrypted at rest |
| Demographics | DOB, gender, nationality, marital status, language preference | Personal Data |
| Clinical | Diagnoses (ICD-10-CM), prescriptions, lab results, radiology, vitals, allergies, immunisations, encounter notes, AI-generated SOAP drafts, fitness-certificate results | PHI (special category) |
| Insurance | Payer, policy and member number, network, co-pay, eligibility responses, claim adjudication | PHI |
| Communications | WhatsApp / SMS / email content between Facility and patient | Personal Data; clinical content excluded by design |
| Telehealth | Video-session metadata; recordings only where patient explicitly consents | PHI |
| Identity verification | UAE Pass user-info payload; Entrust IDV (formerly Onfido) document + liveness — Emirates ID for residents, passport for non-residents | Personal Data (incl. biometric for liveness) |
| Audit logs | Who-did-what-when across PHI access and mutations | Operational; references Personal Data |
| Billing | Payment-method token, billing address, VAT TRN | Personal Data |
| AI Scribe | Audio and raw transcript (purged after 30 days); de-identified transcript sent to LLM; approved SOAP note retained as clinical | PHI + Personal Data |
| Marketing consent | Opt-in records, withdrawal records | Personal Data |
ANNEX B — Technical and Organisational Measures
| Domain | Control |
|---|---|
| Transport | TLS 1.3 minimum; HSTS preload; modern cipher suite only; mTLS on inter-service traffic where applicable. |
| Encryption at rest | AES-256-GCM for users.emiratesId, mfa_settings.totpSecret, mfa_settings.backupCodes (hashed), facility_integrations.credentials. Database-level encryption at rest at the provider tier. Object storage encrypted with customer-managed key. |
| Authentication | RS256 JWT (15-min access, 30-day refresh with rotation). argon2id password hashing (64 MB / 3 iterations / 4 lanes — above OWASP 2025 floor). MFA enforced on all staff accounts; recommended for patient accounts. |
| Authorisation | RBAC (packages/auth/src/rbac.ts) + per-tenant facility / organisation ownership checks on every PHI route. Deny-by-default. Wildcard-aware permission checks. |
| Audit | Append-only audit_logs table — INSERT-only at the database role level. 10-year retention. PHI reads and mutations both logged. Bulk-PHI-read anomaly alerting. |
| Network | API behind Cloudflare with Turnstile bot protection; private endpoints for Postgres and Redis; GPU inference VMs not reachable from the public internet. |
| Endpoint hardening | CSP, X-Frame-Options DENY, Referrer-Policy strict-origin-when-cross-origin, console removal in production builds. |
| Rate limiting | Per-IP + per-user + per-API-key tiered limits (apps/api/src/middleware/rateLimit.ts). |
| Anti-enumeration | Generic 403 messaging on RBAC and tenancy denials. Login timing oracle closed (dummy argon2 verify). OTP path-scoped. |
| AI Scribe | De-identification (packages/ai/src/deidentify.ts) runs server-side before any LLM call. Self-hosted Qwen 72B + Whisper on UAE-resident GPU; no cloud LLM endpoints. Audio and raw transcript purged after 30 days. |
| Patient identity | UAE Pass SOP3 required for clinical data access. Emirates ID column AES-encrypted; HMAC-SHA256 index for equality search. |
| Telehealth | Self-hosted LiveKit on UAE-resident infrastructure. Per-facility Sheryan telehealth add-on licence required to enable. |
| Vulnerability management | pnpm audit --audit-level=high blocking in CI; Renovate auto-PRs; gitleaks scanning; quarterly internal review; annual external penetration test. |
| Backup | Database snapshots daily, retained 30 days. Point-in-time recovery enabled at the provider tier. Disaster recovery to the secondary UAE region. |
| Personnel | All Sehtak personnel sign confidentiality, IP assignment, and data-protection terms before access. Access on a least-privilege basis. |
| Incident response | Detect → notify (24h target) → assist Customer notification (72h target). Logged in incident_reports. |
| Sub-processor management | Each Sub-processor under written agreement with no-less-protective terms. Quarterly review. Public list with change notice. |
Last reviewed: 2026-06-08. Sehtak FZ-LLC, Meydan Free Zone, Dubai, UAE.