> ## Documentation Index
> Fetch the complete documentation index at: https://docs.clinikehr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Protection Addendum for Organizations

> What an organization agrees to before it receives patient information through the ClinikEHR API. Version 2026-10-03.

<p>
  {"Version 2026-10-03"}
</p>

<p>
  {"Effective: the date it is published on the API site."}
</p>

<p>
  {"This addendum is between Bettar Platforms, Inc. (\"we\") and the organization that accepts it (\"you\"). It applies when you receive patient information through the ClinikEHR API. It adds to the API Terms of Use. It is accepted only by an organization that will receive patient information; an organization that will not does not accept it."}
</p>

## 1. WHO IS WHO

<p>
  {"1.1 The clinic decides what its patients' information is used for. We handle it on the clinic's instructions."}
</p>

<p>
  {"1.2 When a clinic grants you a permission that includes patient information, the clinic is disclosing it to you. We carry out that disclosure on the clinic's instruction."}
</p>

<p>
  {"1.3 You receive it as an independent controller, for the purpose the clinic agreed to and no other. You decide how you protect and use it within that purpose, and you are responsible for doing so lawfully."}
</p>

<p>
  {"1.4 We are not your processor, and you are not the clinic's processor, for what you receive."}
</p>

## 1A. APPROVAL

<p>
  {"1A.1 You may receive patient information only after we approve your organization for it, and only the kinds of information we approved (for example demographics, appointments, notes)."}
</p>

<p>
  {"1A.2 We may refuse an application, limit the kinds approved, or suspend or withdraw approval at any time — including if information you gave us is inaccurate, after an incident, or if you breach this addendum. Access stops on the next request."}
</p>

<p>
  {"1A.3 Approval is not a clinic's permission: a clinic still decides whether to grant you any permission, and on what basis."}
</p>

## 2. THE BASIS FOR EACH DISCLOSURE

<p>
  {"2.1 Before a clinic grants you a permission that includes patient information, the clinic records the basis on which it may share it with you. The bases the clinic can record are:"}
</p>

<p className="ml-6">
  {"(a) treatment, payment or health-care operations: the sharing is for the person's care, for payment for it, or for the clinic's or your health-care operations, as the law allows;"}
</p>

<p className="ml-6">
  {"(b) a business associate agreement is in place between the clinic and you;"}
</p>

<p className="ml-6">
  {"(c) patient authorization: the patient has authorized the sharing;"}
</p>

<p className="ml-6">
  {"(d) de-identified, not patient information: the information has been de-identified and does not identify a person."}
</p>

<p>
  {"2.2 You confirm that the basis the clinic recorded is true for every person whose information you request."}
</p>

<p>
  {"2.3 You will request information only about people within the group the clinic agreed to."}
</p>

## 3. MINIMUM NECESSARY

<p>
  {"3.1 You will ask for the least information that serves your purpose. The API returns a defined set of fields for each permission; fields a clinic restricts are not returned."}
</p>

## 4. WHAT YOU MUST DO WITH IT

<p>
  {"4.1 Keep it secure, with safeguards appropriate to health information: encryption in transit and at rest, access limited to people who need it, a record of who accessed it."}
</p>

<p>
  {"4.2 Use it only for the purpose the clinic agreed to."}
</p>

<p>
  {"4.3 Keep it only as long as that purpose and the law require."}
</p>

<p>
  {"4.4 Do not pass it on except to someone bound by terms at least as protective, and tell the clinic who, on request."}
</p>

<p>
  {"4.5 Help the clinic answer a patient who asks what was shared, or asks for a correction or erasure."}
</p>

## 5. A RECORD OF WHAT WAS SHARED

<p>
  {"5.1 We record every disclosure of patient information made to you: which patient, which kind of record, when, under which connection and basis."}
</p>

<p>
  {"5.2 The clinic can see that record. The patient can see, in the clinic's patient portal, which organizations received their information, when, and what kind — never the information itself."}
</p>

<p>
  {"5.3 We keep these records for seven years."}
</p>

## 6. INCIDENTS

<p>
  {"6.1 If you become aware of unauthorised access to patient information you received, you will tell us at support@clinikehr.com, marked \"Security incident\", and tell the clinic, without undue delay and in any case within 72 hours, with what you know."}
</p>

<p>
  {"6.2 If we become aware of unauthorised access to patient information through the API, we will tell the clinic, and you where it concerns you, within 72 hours."}
</p>

## 7. WHEN A CONNECTION ENDS

<p>
  {"7.1 When a clinic withdraws a permission, the API stops returning that information on the next request."}
</p>

<p>
  {"7.2 You will stop using what you hold for that clinic's patients, and return or destroy it, unless the law requires you to keep it. Where the law requires you to keep some of it, you will keep only what it requires, for as long as it requires, protect it as this addendum requires, and use it for no other purpose."}
</p>

## 8. TRANSFERS BETWEEN COUNTRIES

<p>
  {"8.1 Each party is responsible for making sure that any transfer of patient information it makes across a border is lawful where the information comes from and where it goes."}
</p>

<p>
  {"8.2 You will not transfer patient information you received to a country in which you cannot protect it as this addendum requires. Where the law requires a safeguard for a transfer, you will put it in place before the transfer and give it to the clinic or us on request."}
</p>

<p>
  {"8.3 The clinic's own agreements govern where the clinic sends its patients' information. Nothing here changes them."}
</p>

## IF YOU ARE ESTABLISHED IN NIGERIA

<p>
  {"8.4 This clause applies if you are established in Nigeria, or process the information of people in Nigeria. You are a data controller for what you receive and you will comply with the Nigeria Data Protection Act, including its rules on the lawful basis for processing, on sensitive personal data, on the rights of the person, on security, on breach notification, and on transfers out of Nigeria."}
</p>

<p>
  {"8.5 Where the Act requires you to register with, or notify, the Nigeria Data Protection Commission, you will do so, and you will tell us if the Commission asks you about information received through the API. Bettar Platforms, Inc. is registered with the Nigeria Data Protection Commission."}
</p>

<p>
  {"8.6 Where the Act and this addendum both apply, you will follow whichever protects the person more."}
</p>

## 9. AUDIT

<p>
  {"9.1 Each party may ask the other, on reasonable notice, to show that it is meeting this addendum. It may do so once a year, and again after an incident that involves patient information."}
</p>

<p>
  {"9.2 We meet a request from you by written answers and reports about our controls. We do not give access to our sites or systems."}
</p>

<p>
  {"9.3 You meet a request from us, or from a clinic that asks through us, in the same way, by written answers and reports, and by showing your records of who has accessed the information."}
</p>

<p>
  {"9.4 Each party bears its own costs of an audit."}
</p>

## 10. LIABILITY

<p>
  {"10.1 Our liability to you under this addendum is limited in the same way as under the API Terms of Use: to the fees you paid us in the 12 months before the claim arose."}
</p>

<p>
  {"10.2 Your responsibility to a clinic and to patients for what you do with the information you receive is not limited by these terms."}
</p>

<p>
  {"10.3 Nothing here limits liability that cannot be limited by law."}
</p>

## 11. PROVIDERS

<p>
  {"We use providers of hosting, email and similar services to run ClinikEHR. They are described by category, not by name. We give their names on request, in confidence."}
</p>

<p>
  {"ClinikEHR is a product of Bettar Platforms, Inc."}
</p>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.