Data Processing Agreement
Last updated 2026-08-16
This Data Processing Agreement supplements the Terms of Service and governs the processing of personal data under the Law of Georgia on Personal Data Protection. The clinic is the data controller: it decides why and how its patients’ data is processed. Unicorn Care is the processor, acting only on the clinic’s documented instructions. Accepting it at registration binds both parties to the terms below.
Not a medical device, and never an emergency service
Unicorn Care is a post-operative assistance tool. It does not diagnose, does not treat, does not triage and does not monitor anyone. It is not a diagnostic device, not a clinical decision support system, and not a medical device of any class.
Nothing the platform sends — a reminder, an adherence figure — is medical advice or a substitute for consultation with a clinician. Under the Law of Georgia on Health Care every clinical judgement remains the clinic’s.
The platform is not monitored in real time and must never be relied on in an emergency. A patient experiencing a medical emergency must call 112, or the local emergency number where they are, or go to the nearest emergency department. Messages sent through this platform are not seen by a clinician on receipt and may not be read at all.
Roles and definitions
Terms used but not defined here have the meaning given to them in the Law of Georgia on Personal Data Protection.
“Personal data” means any information relating to an identified or identifiable natural person. “Data of special category” includes data concerning health, which is what this platform exists to carry and which the Law subjects to stricter conditions. “Controller” means the clinic. “Processor” means Unicorn Care. “Data subject” means the patient. “Personal Data Protection Service” means the supervisory authority established under that Law.
The clinic is the controller of its patients’ data throughout. Unicorn Care never determines the purposes of processing, never processes patient data for its own ends, and never sells or discloses it for advertising.
Scope of processing and the clinic’s instructions
Unicorn Care processes patient personal data solely to provide the service: storing the care plan the clinic authors, generating the reminders it prescribes, delivering those reminders to the patient, and showing the clinic what was completed.
Processing happens only on the clinic’s documented instructions, of which this Agreement and the clinic’s use of the platform are the record. If Unicorn Care is required by law to process data otherwise, it will inform the clinic before doing so unless that law forbids the notice.
Data concerning health is processed on the basis of the data subject’s explicit consent, which the clinic obtains and warrants it holds. Consents captured through the platform are recorded with their timestamp, the version of the wording shown, the source of the acceptance, and the moment of any withdrawal.
Personnel authorised to access personal data are bound by confidentiality obligations that survive the end of their engagement.
Security of processing
Unicorn Care applies organisational and technical measures appropriate to the risk, as the Law of Georgia on Personal Data Protection requires of a processor handling data of special category.
In practice that means: personal data encrypted at rest with AES-256 at the database and object-storage providers; all traffic to the platform, including patient portal links, carried over TLS 1.3 with HTTP Strict Transport Security enforced; access scoped so a clinic can only ever read its own records; patient portal access by single-use, expiring links rather than shared credentials; and passwords stored as hashes, never in a recoverable form.
Third-party services receive the minimum data required to perform their function. An email provider receives the recipient address and the message; a push service receives an opaque endpoint and an encrypted payload. Notification content carries no diagnosis, no procedure name and no free-text clinical instruction, because a lock-screen preview is readable by anyone holding the phone.
Access to production data is limited to the personnel who need it to operate the service, and is subject to the confidentiality obligations above.
Sub-processors and transfer of data abroad
Unicorn Care engages sub-processors for hosting, database storage, object storage, email delivery, push notification delivery and payment processing. Each is bound in writing to obligations no less strict than those in this Agreement, as the Law requires of any onward engagement.
The Privacy Policy names the current sub-processors. A clinic that needs the list as of a given date may request it. Unicorn Care will give the clinic notice of an intended change of sub-processor, and the clinic may object.
Some sub-processors process data outside Georgia. Under the Law of Georgia on Personal Data Protection such a transfer is permitted where the receiving country provides appropriate safeguards, or where one of the other grounds in that Law applies. Unicorn Care selects processing regions accordingly and contracts for appropriate safeguards with each recipient. A clinic that requires its data to remain within a particular jurisdiction should raise it at privacy@unicorn.care before entering patient data.
Incidents and breach notification
Unicorn Care will report to the clinic any processing of personal data not permitted by this Agreement of which it becomes aware, and any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Notification will be made without undue delay after discovery, to the contact address the clinic holds on its account, so that the clinic can meet its own notification deadline to the Personal Data Protection Service. It will include, to the extent known, what happened, which data subjects and which categories of data were involved, what has been done, and what Unicorn Care recommends the clinic do next.
Unsuccessful security events that result in no unauthorised access — blocked scans, failed logins, rejected connection attempts — are reported on request rather than individually, which this paragraph serves as notice of.
Notification to the Personal Data Protection Service, and to affected data subjects where the Law requires it, is the clinic’s obligation as controller. Unicorn Care will provide the information the clinic needs to make it.
Assisting with data subject rights
The Law of Georgia on Personal Data Protection and the Law of Georgia on the Rights of the Patient give the patient rights of access, correction, and — within the limits below — erasure, together with the right to withdraw consent at any time. Answering them is the clinic’s obligation; Unicorn Care builds the means.
The patient portal lets a patient download everything held about them in a structured, machine-readable form, without waiting on anyone. Correction and erasure requests are filed through the portal and routed to the clinic, which answers them and records the answer.
A patient may withdraw consent to automated messages, or to the portal itself, at any time — through the portal or by telling clinic staff, who can record it on their behalf. Withdrawal takes effect immediately and stops further automated dispatch. It does not alter the clinical record or the care the clinic provides.
Retention, erasure and what must be kept
Personal data is retained only as long as the purpose requires, except where another law requires it to be kept longer — which, for a clinical record, it does.
The Law of Georgia on Health Care and the record-keeping rules made under it require clinical records to be retained for a fixed period. The platform’s configured default is 15 years, and a clinic operating under a longer sectoral rule should tell Unicorn Care so it can be raised. No automated routine deletes a care plan, a reminder history, a recovery log or a symptom report inside that period.
An erasure request is therefore answered in two parts. Identifying and contact data — name, telephone number, email address, free-text notes — is erased. The clinical record is retained for the statutory period and severed from those identifiers. Data a clinician needs to read the record safely, including recorded allergies, is kept. Where a request cannot be met in full the clinic must give the patient the reason in writing, and the platform records it.
On termination, and at the clinic’s choice, Unicorn Care will return or delete the personal data it holds for that clinic, except what it is required by law to retain. Anything retained stays subject to this Agreement for as long as it is held.
The clinic’s obligations
The clinic warrants that it has a lawful basis for every patient record it enters, including the data subject’s explicit consent to the processing of data concerning health, and that it has informed the patient as the Law of Georgia on the Rights of the Patient requires.
The clinic is responsible for the accuracy of what it enters, for keeping account credentials confidential, for removing staff access when someone leaves, and for the clinical content of every care plan it authors.
The clinic must not enter data the platform does not ask for. It is built for post-operative reminders and the record around them; it is not a general medical record system, and data minimisation is a duty the controller owes, not one the processor can discharge on its behalf.
Audit and supervision
Unicorn Care will make available to the clinic the information reasonably necessary to demonstrate compliance with this Agreement, and will cooperate with an inspection carried out by the Personal Data Protection Service or by an auditor the clinic mandates.
Where an inspection would expose another clinic’s data, it will be arranged so that it does not — an audit right over a shared platform cannot become a route into a third party’s patient records.
Term, interpretation and a signed copy
This Agreement takes effect when the clinic accepts it at registration and continues for as long as Unicorn Care processes personal data on the clinic’s behalf. The version accepted is recorded against the clinic’s account with the date and the originating address.
Any ambiguity is resolved in favour of an interpretation that complies with the Law of Georgia on Personal Data Protection, and a reference to a provision of that Law means the provision as amended from time to time. Where this Agreement and the Terms of Service conflict on the processing of personal data, this Agreement prevails.
A clinic that needs a countersigned copy on paper may request one at privacy@unicorn.care.