LBعربيENFR

LBالعربيةEnglishFrançais

Policies

Privacy Policy

Last Updated: August 8, 2026

Ayadati is a clinic management platform operated by NEXALYTIXS LIMITED. This policy explains what personal data we handle, why, and what rights you have.

1. Who We Are

Ayadati is a trading name of:

NEXALYTIXS LIMITED Private Company Limited by Shares, registered in Ireland Company Registration Number: 775893 Registered Address: Apartment 101, Laurel Hall, Larkfield Heath, Dublin 18, Dublin, D18 XAP0, Ireland General enquiries: hello@ayadati.org Data protection enquiries: support@ayadati.org

2. Two Different Roles

It matters which role we are in, because it decides who you contact about your data.

We are the controller for:

  • Visitors to our public website and clinic landing pages
  • People who create or administer a clinic account with us
  • Billing, subscription and support records
  • The patient portal sign-in account itself: the email address used to sign in, the credentials protecting it, and the security records attached to it. We decide how authentication, password resets and account security work, so we control that narrow layer.

We are a processor for:

  • Patient records, appointments, prescriptions, clinical notes, messages and documents held inside a clinic's workspace
  • The link between a portal sign-in account and a patient record, which the clinic establishes and the patient confirms

For that second category the clinic is the controller. The clinic decides what is collected and why, and we only act on its instructions. If you are a patient and want to access, correct or delete your medical record, contact your clinic directly. We will help the clinic respond, but we cannot make those decisions for it.

Our processing on behalf of a clinic is governed by a separate Data Processing Agreement between us and that clinic, which sets out our instructions, confidentiality and security duties, use of subprocessors, and what happens to the data when the contract ends. Clinics can request a copy from support@ayadati.org.

3. Information We Collect

From website visitors: pages viewed, approximate location derived from IP address, browser and device type, and the clinic page you arrived through. Analytics data is only collected if you accept cookies. See our Cookie Settings page.

From clinic users: name, work email address, phone number, role, and the clinic you belong to. We also keep security records such as sign in times and IP addresses.

From people booking an appointment: name, contact details, the service requested and any note you add. The service you choose or the note you write can itself say something about your health, so we treat these fields as special category data. They are passed to the clinic you are booking with, and they are never placed into analytics, page titles, web addresses or application logs.

From patients using the patient portal: the account email you register, and the record the clinic has linked to you.

Billing information: subscription plan, invoices and payment status. Card details are handled by our payment provider and are never stored on our systems.

4. Why We Use It and Our Legal Basis

Where we act as controller, the legal basis is ours:

PurposeLegal basis
Providing the platform to the clinic that contracts with usPerformance of a contract
Managing accounts for the clinic's authorised usersLegitimate interests: giving the contracting clinic a usable, properly access-controlled service. Most clinic users are employees of the clinic rather than parties to our contract, so we do not rely on contract for them.
Authenticating users and keeping the service secureLegitimate interests: protecting patient records and preventing unauthorised access
Billing and collecting paymentPerformance of a contract, legal obligation
Website analyticsConsent
Marketing emailsConsent

Where we act as processor for a clinic, the legal basis is the clinic's, not ours. The clinic is responsible for identifying an applicable basis under Article 6 GDPR and, for health or other special category data, an applicable condition under Article 9 GDPR. This covers patient records, clinical notes, appointment confirmations and reminders, and messages sent to patients. We carry out that processing on the clinic's documented instructions. If you want to know the basis a particular clinic relies on, ask the clinic.

We do not sell personal data, and we do not use health information for advertising.

5. Health Data

Health information is a special category of personal data. It is held in the relevant clinic's workspace, is accessible to that clinic's authorised staff and to the patient it belongs to, and is never shared with another clinic unless the patient consents through the portal.

Where a clinic turns on an optional feature, the relevant content is also processed by the provider behind it. That applies to AI assistance, document text extraction, speech recognition, video consultations and messaging. Those providers are listed, with what each one handles and where, on our Service Providers and Subprocessors page, and each is bound by contractual, security and data residency terms. Our AI, document and speech providers are deployed inside the European Union, and content sent to them is not used to train their models.

Our website analytics is deliberately excluded from every page that shows health information. No health data is sent to Google or to any advertising service.

6. Who We Share It With

We use a small number of service providers who process data on our behalf:

  • Microsoft Azure (Ireland and the EU): hosting, databases, file storage and email delivery
  • Azure Communication Services: video consultations, in-app chat, SMS and WhatsApp messaging
  • Azure OpenAI: optional AI assistance inside a clinic workspace, such as drafting and summarising text
  • Azure AI Document Intelligence: reading uploaded documents so their contents can be filed against a record
  • Azure AI Speech: converting dictated audio into text where a clinic uses dictation
  • Google Analytics: website analytics on public pages only, and only with your consent
  • Whish: payment processing

Most of these act as our processors under a written agreement and handle data only on our instructions. Some do not: payment providers and telecommunications or messaging carriers determine parts of their own processing and act as independent controllers for it, under their own terms and privacy notices. Where a clinic connects its own analytics or messaging account, that clinic is the controller for that connection.

Our current subprocessor list, including what each one processes and where, is published at /policies/subprocessors. We also disclose data where the law requires it.

7. Where Your Data Is Held

Core platform data is hosted in the European Union. Some communications and service provider processing happens elsewhere, as set out on our Service Providers and Subprocessors page. Where personal data is transferred outside the EU or EEA, that transfer relies on either an adequacy decision by the European Commission or the Commission's Standard Contractual Clauses, together with any additional technical measures needed for the specific transfer. You can ask us which safeguard applies to a particular transfer, and request a copy of the relevant terms, by emailing support@ayadati.org.

8. How Long We Keep It

  • Clinic and patient records: for as long as the clinic's account is active, and afterwards for any period the clinic is legally required to retain them
  • Website analytics: user-level and event-level data is configured for 14 months; aggregated statistical reports may be retained for longer
  • Billing and tax records: for the period required by Irish law, generally six years
  • Security logs: 12 months

When a clinic closes its account we delete or return its data on request, subject to any retention the law requires of us.

9. Security

Data is encrypted in transit and at rest. Access is controlled by role, separated by clinic, and logged. Staff accounts require a password and are approved by a clinic administrator before they can reach any record.

No system is perfectly secure. If a personal data breach is likely to result in a risk to individuals, we will notify the Data Protection Commission where required, normally within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to you, we will also tell you without undue delay. Where we act as processor for a clinic, we notify that clinic without undue delay so it can meet its own obligations.

10. Your Rights

Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict how we use it, provide it in a portable format, or object to processing based on legitimate interests. You may also withdraw consent at any time.

To exercise these rights, email support@ayadati.org. We will respond within one month.

If you are a patient, where you send your request depends on what it concerns. Requests about your medical record, including access, correction and deletion, go to your clinic, because the clinic controls it. Requests about your portal sign-in account, such as the email address, your credentials or closing the account, come to us at support@ayadati.org.

If you are unhappy with our response you may complain to the Irish Data Protection Commission at www.dataprotection.ie.

11. Whether You Have to Provide Data

A clinic must give us account and billing details to take out a subscription, because we cannot provide or invoice the service without them. A patient must give an email address and set a password to create a portal sign-in, because that is what the account is. Marketing consent is entirely optional and refusing it changes nothing else.

We do not make decisions about you based solely on automated processing that produce legal effects or similarly significant effects. Any suggestion, reminder or calculation the platform produces, including AI generated text, is informational, and a person at your clinic decides what to do with it.

12. Clinic Pages That Link Their Own Notices

A clinic can replace the privacy and terms links in the footer of its own public clinic page with its own documents. Where a clinic has done that, the linked document is the clinic's and the clinic is responsible for it. This policy continues to govern the processing we carry out and control, whichever document the footer points to. The Cookie Settings link on those pages always points here and always describes the analytics actually running on the page.

13. Children

The platform is not intended for children to use directly. A clinic may hold records for a child patient, which are managed by the clinic and accessed by a parent or guardian through the portal.

14. Changes

We will update this page when our practices change and revise the date above. If a change is significant we will tell account holders directly.

15. Contact

Questions about this policy, or about data we hold on you, should go to support@ayadati.org, or by post to the registered address in section 1. Billing questions go to billing@ayadati.org.