Terms of Service
Last updated: 29 May 2026
These Terms govern clinic and staff use of the Clinith OS platform. Patient-facing terms are provided by each clinic.
1. Agreement
These Terms of Service ("Terms") are a binding agreement between Clinith OS ("Clinith OS", "we", "us", "our") and the organization or individual that registers for or uses our software and related services (the "Services") ("Customer", "you").
By creating an account, executing an order, or using the Services, you accept these Terms on behalf of yourself and, if applicable, the clinic or organization you represent. If you do not agree, do not use the Services.
If you use the Services on behalf of a clinic or company, you represent that you have authority to bind that entity.
2. Definitions
- "Customer Data" means data you or your users submit to the Services, including patient, staff, and operational records.
- "Personal Data" has the meaning given under applicable data protection law, including India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
- "Protected Health Information" or "PHI" has the meaning under applicable US health privacy law, including HIPAA, where relevant.
- "Documentation" means our published product documentation, security materials, and acceptable use guidelines.
3. Roles and responsibilities
Clinith OS provides software tools for clinic operations. We do not provide medical care, clinical advice, diagnosis, or treatment. All clinical decisions and patient care remain solely with licensed providers and the Customer.
For patient and staff Personal Data processed through the Services, the Customer is typically the data controller / Data Fiduciary (or equivalent under applicable law). We act as a data processor / service provider processing Customer Data on the Customer's documented instructions, except for limited platform account and billing data for which we may act as an independent controller.
Customers are solely responsible for: (a) the accuracy, quality, and legality of Customer Data; (b) providing required privacy notices and obtaining valid consents or other lawful bases; (c) configuring roles, retention, and access appropriately; (d) compliance with healthcare, billing, insurance, and professional regulations in their jurisdiction; and (e) responses to data subject or patient requests relating to care they provide.
Where required by law, separate written agreements apply: a Data Processing Agreement for India DPDP-style processing, and a Business Associate Agreement for US HIPAA-covered processing. Those agreements supplement these Terms and control on conflict for data protection obligations.
4. Accounts, credentials, and access
- You must provide accurate registration information and keep it current.
- You are responsible for all activity under your accounts and for maintaining the confidentiality of credentials, API keys, and integration secrets.
- You must implement least-privilege access, promptly revoke access for departing staff, and enable multi-factor authentication where available.
- You must notify us promptly at security@clinithos.com if you suspect unauthorized access, credential compromise, or a security incident affecting the Services.
5. Acceptable use
You must not, and must not permit others to:
- Use the Services for unlawful, fraudulent, or harmful purposes.
- Upload malware, attempt unauthorized access, probe or scan systems, or bypass tenant isolation or access controls.
- Reverse engineer, decompile, or copy the Services except where permitted by mandatory law.
- Scrape, harvest, or resell data from the Services without our written consent.
- Use the Services to send spam or unsolicited communications without lawful basis and required consents.
- Process special-category or sensitive data beyond what the product is designed for without appropriate safeguards and agreements.
- Misrepresent affiliation with us or use the Services in a manner that could harm patients, our reputation, or third parties.
6. Subscriptions, fees, and payment
Paid plans, trials, and module entitlements are described at order or checkout. Fees are billed in advance unless otherwise stated. Taxes are your responsibility unless we are required to collect them.
Payments may be processed by third-party payment providers (e.g., Razorpay). Their terms apply to payment processing. Failed or chargeback payments may result in suspension after reasonable notice.
Except where required by applicable consumer law, fees are non-refundable once a billing period has started. We may change pricing on renewal with reasonable advance notice.
7. Privacy and data protection
Our Privacy Policy at /legal/privacy describes how we handle platform account data and our role regarding Customer Data. Customer Data remains your property. We process it only to provide, secure, and support the Services, as instructed by you through product configuration and these Terms, and as required by law.
You must not submit Personal Data to the Services without a lawful basis and appropriate notices. You grant us a limited license to host, process, transmit, display, and back up Customer Data solely to operate the Services.
We implement technical and organizational measures described in our security and compliance materials. No system is perfectly secure; you share responsibility for account hygiene, configuration, and incident reporting.
8. Intellectual property
We and our licensors retain all rights in the Services, software, branding, and Documentation. We grant you a limited, non-exclusive, non-transferable, revocable license to use the Services during an active subscription for your internal clinic operations.
Feedback you provide may be used by us without restriction or compensation, provided we do not identify you publicly without consent.
9. Third-party services and subprocessors
The Services may integrate with third-party providers (hosting, database, email, SMS, WhatsApp, payments, analytics). Your use of those features may be subject to their terms. We use subprocessors to deliver the Services and will maintain an up-to-date subprocessor list available on request at security@clinithos.com.
We are not responsible for third-party services outside our reasonable control, but we require subprocessors that process Customer Data to contractual confidentiality and security obligations appropriate to their role.
10. Service availability and support
We strive for reliable operation but do not guarantee uninterrupted or error-free service. Maintenance, upgrades, and force majeure events may cause downtime. Support channels and response targets, if any, are as stated in your order or support plan.
You are responsible for maintaining your own backups of critical records where required by law or professional standards, in addition to our infrastructure backups.
11. Disclaimer of warranties
THE SERVICES AND DOCUMENTATION ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND ACCURACY. WE DO NOT WARRANT THAT THE SERVICES WILL MEET YOUR REGULATORY OBLIGATIONS WITHOUT YOUR OWN COMPLIANCE PROGRAM.
12. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, COVER, OR PUNITIVE DAMAGES, OR LOST PROFITS, REVENUE, DATA, OR GOODWILL, EVEN IF ADVISED OF THE POSSIBILITY.
EXCEPT FOR (A) YOUR PAYMENT OBLIGATIONS, (B) YOUR INDEMNIFICATION OBLIGATIONS, (C) YOUR BREACH OF SECTION 5 (ACCEPTABLE USE), OR (D) LIABILITY THAT CANNOT BE LIMITED BY APPLICABLE LAW, EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS WILL NOT EXCEED THE FEES PAID OR PAYABLE BY YOU TO US FOR THE SERVICES IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY.
Nothing in these Terms limits liability for fraud, wilful misconduct, or death or personal injury caused by negligence where limitation is prohibited by law.
13. Indemnification
You will defend, indemnify, and hold harmless us and our affiliates, officers, and employees from third-party claims, fines, and reasonable costs arising from: (a) Customer Data or your clinical/business practices; (b) your violation of these Terms or applicable law; (c) lack of required notices, consents, or agreements with patients or staff; or (d) disputes between you and your patients, payers, or employees, except to the extent caused by our material breach of these Terms or our gross negligence.
14. Term, suspension, and termination
- These Terms continue while you use the Services or until terminated.
- Either party may terminate for material breach if not cured within thirty (30) days of written notice, or immediately for legal prohibition, fraud, or serious security risk.
- We may suspend access immediately if required by law, for non-payment, or to protect the Services, other customers, or data.
- Upon termination, your right to use the Services ends. We will delete or return Customer Data per our Privacy Policy, your DPA/BAA, and applicable retention settings, subject to legal retention requirements.
15. Export and sanctions
You may not use the Services in violation of applicable export control or sanctions laws. You represent that you and your users are not prohibited persons under such laws.
16. Governing law and disputes
These Terms are governed by the laws of India, without regard to conflict-of-law rules. Courts in Bangalore, Karnataka, India will have exclusive jurisdiction, subject to mandatory consumer protections where applicable.
Before filing a claim, the parties will attempt good-faith resolution by contacting legal@clinithos.com. Nothing prevents either party from seeking urgent injunctive relief for security, IP, or confidentiality breaches.
17. Changes to these Terms
We may update these Terms for legal, security, or product reasons. Material changes will be notified via the Services, email, or our website with reasonable advance notice where practicable. Continued use after the effective date constitutes acceptance. If you object, you may terminate before the effective date.
18. General
- These Terms, the Privacy Policy, and any executed order, DPA, or BAA form the entire agreement regarding the Services.
- If any provision is unenforceable, the remainder stays in effect.
- You may not assign these Terms without our consent; we may assign in connection with a merger, acquisition, or asset sale with notice.
- No waiver is effective unless in writing.
19. Contact
Legal / Terms: legal@clinithos.com
Support: support@clinithos.com
Security incidents: security@clinithos.com
Related: Privacy Policy · Compliance overview
