Legal

Terms of Service

The agreement governing use of the PrimumAI practice management solution — including the GDPR Article 28 data processing addendum and the annexes it refers to.

Effective date 11 September 2025

Company
PrimumAi Limited
“PrimumAI”, “we”, “us”
CRO (Ireland)
77714
Registered office
Blackrock, Co. Dublin
A94 A4T8
Support & DPO
harsh@primumai.eu
Support, privacy, and notices

Definitions

Clinic
The healthcare provider (and its authorised staff) that uses the PMS.
PMS
PrimumAI’s Practice Management Solution — web apps, APIs, integrations, and AI tools.
Controller / Processor
As defined by GDPR. For patient data in the PMS, Clinic = Controller; PrimumAI = Processor.
Data Subject
A natural person whose personal data are processed.
AI Features
Drafting tools (e.g. note suggestions, coding prompts, triage summaries) that a clinician reviews and approves.
Sub-processor
A third party engaged by PrimumAI to process personal data for the Clinic.

Accounts & Access

  • You must be 18+ and authorised to bind the Clinic.
  • Keep credentials secret; enable MFA.
  • You are responsible for actions under your accounts, and must maintain accurate account information.

Services & Support

We provide the PMS and reasonable support. We may update features for security, performance, and usability.

Availability
We aim for high uptime, with planned maintenance windows notified in advance where practicable.
Support hours
09:00–17:30 (Europe/Dublin) on business days, unless your Order Form states otherwise.

Acceptable Use

  • Do not use the PMS unlawfully, to infringe IP, to attempt unauthorised access, or to introduce malware.
  • No reverse-engineering, scraping, automated scanning, or security testing without written approval.
  • You must comply with the professional and healthcare obligations applicable to your practice.

Clinical Responsibility & AI Features

  • The PMS supports — but does not replace — clinical judgment.
  • Human-in-the-loop. AI outputs are drafts for clinicians to review, edit, and approve.
  • No automated decisions with legal or similarly significant effects are made by PrimumAI.
  • Clinics remain responsible for consent, notices to patients, and record-keeping in the PMS.
Safety & usage constraints — no emergency use
The PMS (including AI features) is not for emergency communications or time-critical clinical decisions. Use standard emergency channels.
Beta / Preview features
Features marked Beta or Preview may change, have limits, or be withdrawn. They are optional, excluded from uptime commitments, and should not be used for critical workflows or patient-identifiable data unless agreed in writing with controls.

Fees & Taxes

  • Fees (if any) are set out in the Order Form or Plan. Taxes and regulatory fees are extra unless stated.
  • Late payments may lead to suspension after notice.

Your Content & IP

Ownership
The Clinic owns its content and patient records.
Licence to PrimumAI
You grant us a limited licence to process your data to provide, secure, and support the PMS, to comply with law, and as set out in the DPA.

We do not sell patient data or use it for advertising.

Privacy & Data Protection

  • When acting as Processor for patient data, the DPA in Annex A applies, and controls in case of conflict.
  • When acting as Controller for PrimumAI’s own business data, our Privacy & Cookies Policy applies.

Security Safeguards

  • We maintain industry-standard safeguards described in Annex B (TOMs): encryption in transit and at rest, RBAC and MFA, logging and monitoring, vulnerability management, backups and DR, secure SDLC, and vendor due diligence.
  • We configure EU regions by default and, for AI services, settings that do not train on Clinic data.

Sub-processors

  • We use vetted sub-processors under written data protection terms.
  • We maintain an up-to-date list (Annex C) and will give prior notice of material changes.
  • You may object on reasonable grounds; if not resolved, you may terminate the affected service.

Compliance Assistance & Audit

  • We keep records of processing and will provide information reasonably necessary to demonstrate compliance (e.g. security summaries, certificates) under NDA.
  • On reasonable written notice, you may perform audits as permitted by Annex A, subject to confidentiality, safety, and proportionality.

Confidentiality

  • Each party must protect the other’s confidential information and use it only for the agreed purpose.
  • Patient data is always confidential.

Warranties

  • We warrant that we will provide the PMS with reasonable skill and care.
  • Except as expressly stated, the PMS is provided “as is”.

Liability & Indemnity

Cap
Each party’s aggregate liability under these Terms is capped at the fees paid or payable in the prior 12 months, excluding: death or personal injury; fraud; wilful misconduct; IP infringement; and any specific caps set in Annex A for data protection.
Exclusions
Neither party is liable for indirect, incidental, or consequential damages, where permitted by law.
Indemnities
(a) PrimumAI will defend you against third-party IP infringement claims about the PMS (excluding your content or use). (b) You will defend us against claims arising from your unlawful use, or instructions that breach law.

Term, Suspension & Termination

  • Term is per the Order Form or Plan. Either party may terminate for uncured material breach after 30 days’ notice.
  • We may suspend for non-payment, security risks, or legal requirements, after notice where practicable.

Exit, Return & Deletion

  • On termination or expiry, we will return or delete patient data per Annex A and your written instructions.
  • Requests for deletion can be sent to harsh@primumai.eu. Export access is provided for a limited period, and backups are purged on a rolling basis.

Deletion & exit SOP

  1. Request
  2. Verify
  3. Export
  4. Primary deletion
  5. Backups purge
  6. Certificate
  7. Cascade
Request
Email harsh@primumai.eu from a Clinic admin address, with the subject “Deletion/Exit – [Clinic]”.
Verify
We verify authority and scope (tenancy, features, backups, sub-processors).
Export (optional)
We provide a structured export (JSON, CSV, or PDF per module) for 14–30 days.
Primary deletion
We delete active copies within 5–10 business days of confirmation.
Backups
Encrypted backups purge within 30–45 days, on a rolling basis.
Certificate
We issue a Deletion Certificate on request to harsh@primumai.eu.
Cascade
We cascade deletion to the relevant sub-processors and keep proof of completion.

Changes to Terms

  • We may update these Terms for legal or operational reasons.
  • We will provide at least 30 days’ notice for material changes. Continued use means acceptance.

Governing Law & Disputes

  • Irish law governs.
  • Disputes are subject to the exclusive jurisdiction of the Irish courts, after good-faith escalation and optional mediation.

Notices

Notices are valid when emailed to harsh@primumai.eu and to the admin email associated with your account.

Order of Precedence

If documents conflict, the earlier in this chain prevails:

  1. Annex A (DPA)
  2. Order Form
  3. These Terms
  4. Policies / FAQs

Annex A — Data Processing Addendum (GDPR Art. 28)

A1. Parties & roles
Controller: the Clinic named in the Order Form. Processor: PrimumAi Limited.
A2. Processing scope
Purpose: deliver and secure the PMS; provide support; implement AI drafting tools; comply with law. Nature: hosting, storing, structuring, transmitting, pseudonymising, and transforming data. Duration: the term of the subscription, plus the backup purge window.
A3. Data & subjects
Subjects: patients; Clinic staff and contractors. Data types: patient demographics, contact details, clinical notes, codes, treatment and history, scheduling, communications, billing metadata, and user access logs. Special categories: health data for patients (no genetic or biometric data unless input by the Clinic).
A4. Instructions & lawful basis
We act only on the Clinic’s documented instructions. The Clinic determines the lawful bases (e.g. Art 6(1)(e) or (f) and Art 9(2)(h)).

A5. Processor obligations

Confidentiality
Bind personnel; train them; least-privilege access.
Security
Implement the TOMs in Annex B, and improve them over time.
Sub-processors
Written contracts, equivalent protections, change notices, and a right to object.
Assistance
Support with DSARs, DPIAs, security obligations, and prior consultations (Art 36).
Breach
Notify the Clinic without undue delay; share Art 33(3) details; assist with notifications.
Audits
Provide information; allow audits or third-party reports under NDA and reasonable limits.
Return / delete
On end of services, return or delete per the Clinic’s choice; purge backups within 30–45 days; issue a deletion certificate on request.
Records
Maintain Art 30(2) processor records.
A6. International transfers
Default processing is in the EEA. Transfers outside the EEA apply a valid mechanism (e.g. EU SCCs 2021/914) with TIAs and supplementary measures.
A7. Liability & precedence
The DPA prevails over conflicting Terms when it comes to personal data processing. Unless otherwise agreed, the liability cap in §14 applies; the parties may agree a specific data-protection cap in the Order Form.

Annex B — Technical & Organisational Measures (TOMs)

Governance
Named DPO; security officer; policies; training; confidentiality agreements; background checks.
Access control
RBAC; MFA; SSO support; quarterly access reviews; immediate de-provisioning.
Encryption
TLS 1.2+ for data in transit; AES-256 for data at rest; keys via cloud KMS; secrets in a secrets manager.
Data management
Tenant isolation; environment segregation; data minimisation; pseudonymisation and anonymisation for analytics.
Secure SDLC
Peer review; dependency scanning; SAST/DAST; IaC; change control; vulnerability SLAs.
Monitoring & logging
Centralised logs; admin and audit trails; SIEM alerts; time sync; integrity controls.
Backups & resilience
Encrypted backups; tested restores; RTO/RPO targets; multi-AZ; DDoS protection; capacity planning.
Incident response
24/7 on-call; runbooks; evidence preservation; post-incident reviews; communications templates.
Third-party risk
Due diligence; DPAs and SCCs; annual re-assessment; sub-processor change logs.
AI safeguards
Human-in-the-loop; clinician review; UI labels; prompt and output logging; the ability to disable AI per Clinic; no training on Clinic data without written approval.

Annex C — Current Sub-processors

Infrastructure & platform
Amazon Web Services (AWS), EU regions — hosting, storage, backups, and notifications and emails (SES/SNS). Microsoft Azure, EU regions — compute, databases, and optional platform services.
AI inference (optional)
Azure OpenAI Service, EU deployment — model inference for AI drafting. Configured not to use data for training.
Communications
Twilio, EU or appropriate regions — phone numbers, SMS and voice delivery, appointment reminders. Recordings are disabled by default unless the Clinic enables them and lawfully notices or obtains consent.
Payments
[Payment Provider], EU/EEA — payment processing for patient payments. PrimumAI does not store card numbers.

Annex D — Audio, Voice & Telephony (Twilio)

Scope
Optional call, SMS, and voice features via Twilio; appointment reminders; call recording off by default.
Consent & notices
Clinics must provide clear notice before audio capture, and collect consent where required.
Default retention
Real-time transcription is ephemeral unless the Clinic enables retention; PrimumAI deletes per Clinic instructions.
Storage location
Twilio EU endpoints are used where available; if non-EEA routing is used, SCCs and supplementary measures apply.
Risk & accuracy
Audio capture may fail and AI drafts may be incomplete; clinicians must verify before use.
Prohibited content
No card numbers, credentials, or unlawful content via telephony.

Questions about these Terms?

Contact harsh@primumai.eu — the same address handles support, privacy, deletion requests, and formal notices. How we handle personal data is set out in our Privacy & Cookies Policy.