Terms of Service for Providers
Last updated: June 2026
Please read these Terms of Service for Providers carefully. By visiting, downloading, using or attempting to interact with any part of the Services, you confirm that you have read these terms, are entering into a legally binding contract with us, and agree to comply with these Terms. If you do not agree with these Terms you must not use the Services. For information about how we collect and use personal data, please see our Privacy Notice.
1. INTRODUCTION
1.1. Who are we?
We are MeTime Corporation Limited, with company number 669120 and registered address at 5 Fitzwilliam Square East, Dublin 2, Ireland ("we", "our" or "us").
1.2. Definitions
To make things easier, in these Terms, when we say:
1.2.1. "Customer" we mean an individual who has a customer account on the Services;
1.2.2. "Provider" we mean a clinic, company, or organisation, or an individual professional or consultant, that has a provider account on the Services;
1.2.3. "Services" we mean the MeTime app, the website located at www.metime.com, any content and materials on our app and website, and any other software, products, services, information, tools, and technology that we make available;
1.2.4. "Treatments" we mean advice, consultations, recommendations, products, services, procedures, and treatments that a provider offers or supplies.
When we use the terms 'personal data', 'controller', 'processor', 'special categories of personal data' and 'personal data breach', those terms have the meaning given to them in the EU General Data Protection Regulation (GDPR). HIPAA-specific definitions used in paragraphs 14.10 to 14.18 are set out in those paragraphs.
1.3. Service summary
The MeTime Services make it easier for customers seeking information on Treatments to learn more about the providers and Treatments offered. With the Services, a provider can:
1.3.1. create a provider account and upload and post information to their provider account, such as clinic information, specialties, experience, and photos;
1.3.2. receive information, for example through online messaging and video conferencing, from customers who choose to match with the provider. When a customer submits a multimedia request through the Services, the provider can review the customer's information and respond with treatment suggestions, offers and appointment proposals;
1.3.3. promote and suggest Treatments based on customer information, profiles, preferences and photos.
When a customer is ready he or she can use their own judgement to choose the best provider for them, and use the Services to book an appointment and pay for a Treatment.
1.4. Contacting us
If a provider wants to learn more about the Services or has any problems, it should first look at our online FAQs and support resources. If a provider still needs help, it can contact us at [email protected].
2. AGREEMENT
2.1. Intended users
These are the Terms on which we allow providers to download, sign-up for and use the Services (or any part of them). These Terms form a binding contract between the provider and us.
2.2. Current Terms
Each time a provider visits, downloads or accesses the Services, including any updates, it agrees to the current version of these Terms on its current visit.
2.3. Other terms
There are other terms that may apply to a provider when using the Services that are not part of these Terms but which contain provisions that the provider must comply with:
2.3.1. Privacy Notice available at https://metime.com/privacy-policy;
2.3.2. if a provider downloads our app from an app store the app store's rules and policies may also control the ways in which the provider can use our app.
2.4. Changes to these Terms
We have the right to change these Terms from time to time. We will notify a provider of a significant change by sending an email or in-app notification. By continuing to use the Services after a change comes into effect, the provider accepts the change.
3. RELATIONSHIP
3.1. Relationship with us
The Services offer a platform for a provider and a customer to identify with each other and transact directly with each other. Our role is limited to offering technology to facilitate the connection and exchange of information between a provider and a customer through the Services. We are not a party to the relationship or any dealings between a provider and a customer. We have no input and do not influence the interaction between providers and customers.
3.2. Supply of Treatments
The provider is solely responsible for determining what Treatments to offer, the time, place, manner, and means of providing those Treatments, and the terms on which it offers and supplies those Treatments.
3.3. Important information
We are a technology platform that connects customers with providers. We are not a healthcare provider and we do not deliver any medical or healthcare treatment ourselves. We do not supervise, direct or control how a provider supplies any Treatment, and we are not party to the contract between a provider and a customer for a Treatment.
The Services include automated features that surface information to help customers and providers find each other and to help providers manage their practice. These include the treatment suggestions presented to customers based on the multimedia journey information the customer has submitted (described at paragraph 1.3.3 and surfaced on metime.com as 'instant personalised suggestions'), the AI-supported matching that helps connect customers with relevant providers, the AI Smart Filter on the provider Matches list, and the algorithmic metrics rendered on the provider Business Dashboard. These features are decision-support only; they do not constitute medical advice, do not replace a provider's independent clinical judgement, and do not replace the customer's right to consult any provider of their choosing. All clinical decisions remain with the provider and the customer. Where the Services produce a decision that engages the rights in Article 22 GDPR or the equivalent rights under other applicable law, the customer can request human intervention as described in our Privacy Notice.
Where we describe providers on our public pages as 'Verified Providers' or by similar terms, that statement refers to the limited account-verification checks we carry out during provider onboarding (including reviewing the information the provider supplies about its identity, business, and credentials). Account-verification by us is not an endorsement, certification, or warranty of the provider's clinical competence, ongoing fitness to practise, treatment quality, or treatment outcomes. The information shown on each provider's profile is supplied by the provider themselves; we do not warrant that it is accurate or current. Customers should make their own inquiries before booking any Treatment, including verifying the provider's qualifications, registration, and standing directly with the relevant regulator or professional body.
3.4. Provider’s responsibilities
A provider is solely responsible for: (a) evaluating and determining if a customer is fit and suitable for the Treatments the provider offers; (b) performing the Treatments to the professional standards required by applicable law and the provider's regulatory or professional body; (c) compliance with all applicable laws including HIPAA where applicable to the provider; (d) the accuracy of all content the provider uploads or makes available; and (e) all communications with customers.
3.5. Provider commitments
By using the Services, the provider confirms that it:
3.5.1. is 18 years old or older and has the legal capacity and authority to enter into and agree to these Terms;
3.5.2. is using the Services for business purposes only and not for domestic or private use;
3.5.3. has the necessary skills, experience, and certifications to supply the Treatments it offers through the Services;
3.5.4. has in place all licensing, insurance, consents, registration, and other requirements with respect to its business, or the business for which it is acting;
3.5.5. will comply with all applicable laws when using the Services and offering Treatments, and it will not use the Services for any illegal or unauthorised purpose;
3.5.6. is solely responsible for paying all tax and similar amounts due in respect of any payments received from customers for a Treatment.
3.6. Background checks
We have the right to ask the provider, at any time, to provide proof of its compliance with paragraph 3.5. The provider must immediately supply the information we request.
3.7. Arranging access
It is the provider's responsibility to select, obtain, and pay for internet access (including excess charges if a provider exceeds any data allowance) and the device or equipment necessary to access and use the Services.
3.8. Updates to the Services
From time to time, we may automatically update any part of the Services to improve or modify performance, functionality, reflect changes in laws or regulations, deal with security issues, or for other reasons.
3.9. Avoiding fees
We invest heavily in our Services to make it easy for customers and providers to connect and transact efficiently and safely. The provider must not avoid the fees and charges we apply by encouraging a customer to transact, communicate, or pay outside the Services.
4. PROVIDER ACCOUNTS
4.1. Creating a provider account
To access and use certain elements of the Services, a provider must register and create a provider account by providing its details. The provider must supply accurate, complete, and up-to-date information at the time of registration and keep it up to date. We have the right to decline to supply a provider account or to offer the Services to anyone.
4.2. Safeguarding details
The provider is responsible for maintaining the security of its user ID and password used to access its account. The provider must keep these confidential, must not share them with anyone, and must not allow anyone else to use them. The provider is responsible for all activities under its provider account.
4.3. Interactive features
The Services may provide access to interactive features, for example, live message and video chat functionality that allows customers to interact with providers and us. The provider must use the interactive features in a manner consistent with these Terms and applicable laws.
4.4. Third-party links
The Services may display links to independent websites or content that are not connected to us. These are not under our control, and we are not responsible for their content, function, or availability.
5. CONFIDENTIALITY
5.1. The provider agrees:
5.1.1. to keep secret and safeguard all confidential information that it receives or is otherwise exposed to in the course of exercising its rights or performing its obligations under these Terms;
5.1.2. to use that confidential information only for the purpose of fulfilling its obligations or exercising its rights under these Terms;
5.1.3. to use the same care to protect that confidential information as it would use to protect its own similar information, but in no event less than commercially reasonable safeguards;
5.1.4. not to disclose any of that confidential information to any third party unless it has prior written consent or the disclosure is required by a court or by applicable law.
When we use the term "confidential information," we mean any information of ours or of a customer that is marked confidential or should reasonably be understood to be confidential.
5.2. We have the right to use and reproduce the provider's name, expertise, business name, and photograph from the provider's profile data for our advertising and marketing.
6. SUBSCRIPTION PLAN & FEES
6.1. Subscription plans
We offer different subscription plans. Each subscription plan includes a range of features and benefits, as described here. A provider may choose the subscription plan that best suits its needs and change it at any time.
6.2. Subscription fees
We will charge the subscription fee for the subscription plan to the provider's payment method on the billing date indicated on the provider's account.
6.3. Provider's right to change its subscription plan
A provider can change to another subscription plan at any time, including by downgrading to a basic free plan if one is available.
6.4. Our right to modify subscription features
We have the right to change subscription fees, modify the features and benefits included in each subscription plan, and introduce new subscription plans. We will notify the provider in advance.
6.5. Taxes
Where applicable, we may also collect all required taxes (such as value-added tax) on subscription fees.
7. PRICING, BOOKINGS & PAYMENTS
7.1. Pricing
The provider is responsible for setting the price it offers and charges a customer for a Treatment. The provider must offer pricing and terms through the Services that are at least as favorable as those it offers through any other channel.
7.2. Booking a Treatment & Payment
A customer can book a Treatment from a provider through the Services. The provider can request payment from the customer through the Services. We process payments through a third-party payment processor (Stripe). The provider is responsible for any chargebacks, refunds, or other amounts deducted from a payment.
7.3. Contract of sale
We are not involved in the actual transaction between the provider and the customer, and we do not represent either party in any negotiations. The contract for the supply of a Treatment is between the provider and the customer.
7.4. Canceling a booking
If, for any reason, a provider is unable to supply the Treatment, the provider must tell the customer before canceling use of the Services. If the customer requests a refund for a Treatment the provider has not supplied, we will consider the request and ask the customer to contact the provider directly. If the provider or the customer cancels a Treatment or a Treatment does not take place, we are not required to refund our administration fees or the payment processing charges.
7.5. Provider and customer complaints
If a customer has any queries or complaints about the booking, payment, or the provision of a treatment, we will advise the customer to contact the provider directly. The provider must respond to and seek to resolve any such complaints in good faith.
7.6. Non-payment
If a provider does not pay any fees or charges it owes, we may, in our sole discretion, suspend or terminate the provider's account and take any other action we consider appropriate.
7.7. Changing fees
We may change the fees and charges or introduce new fees and charges from time to time, and we will notify the provider in advance.
8. OUR INTELLECTUAL PROPERTY RIGHTS
8.1. IP rights
All intellectual property rights in the Services throughout the world belong to us, or our licensors, and the rights in the Services are licensed (not sold) to the provider. The provider has no intellectual property rights in, or to, the Services other than the right to use them in accordance with these Terms.
8.2. Limited rights
The elements of the Services, including the general design and imagery, are protected by copyright, database rights, trademarks, patents, and other intellectual property rights.
8.3. Unauthorised use
We have the right to investigate any suspected or actual improper, illegal, or unauthorised use of the Services (or any part of them) and to take any action we consider appropriate, including reporting any suspected illegal activity to the relevant authorities.
9. PROVIDER INTELLECTUAL PROPERTY RIGHTS
9.1. Provider content
To enable us to provide the Services, the provider agrees to give us certain permissions in respect of the content that it provides to us through the Services ("provider content"). The provider grants us a non-exclusive, worldwide, royalty-free licence to use, reproduce, modify, adapt, publish, translate, distribute, perform and display the provider content in connection with the Services and our business.
9.2. Provider profile
To help providers, we will create a sample provider profile for them using the provider content. We do not publish a provider profile on the Services unless and until the provider approves it.
9.3. Right to share
The provider warrants that it owns or has a right to share any provider content and that the provider content will not violate the rights (including the intellectual property rights) of any third party.
9.4. Removal and edits
The provider agrees that, in our sole discretion, we are entitled to: (a) remove any provider content if, in our opinion, it does not comply with these Terms or applicable law; and (b) edit any provider content to make it more useful or accessible to customers.
10. TERMINATION
10.1. Term
These Terms remain in effect until we or a provider terminates them.
10.2. Provider rights
A provider can close its provider account and terminate these Terms at any time by following the instructions in the provider account section of the Services.
10.3. Our rights
We have the right to limit, suspend, modify, or withdraw all or any part of the Services, delete the provider content, or suspend or terminate a provider account at any time, with or without notice and with or without cause.
10.4. App store terms
The app store where the provider has an account may stop marketing or stop allowing the installation of our app at any time. This is outside our control, and we are not responsible for any termination of the provider's right to use the app as a result.
10.5. Effects of termination
Upon termination of a provider account, the provider must immediately cease all activities authorized by these Terms, including the provider's use of the Services.
10.6. Surviving provisions
Paragraphs 5, 6, 7, 8, 9, 11, 13, and 14 (including, where applicable to the provider, paragraphs 14.10 to 14.18 — the HIPAA Business Associate terms) survive the termination or expiration of these Terms. Any amounts owed by a party to the other party before termination remain owing after termination.
11. LIABILITY
11.1. Warranties
To the extent permitted by applicable law, we provide the Services on an 'as-is' and 'as available' basis. We make no representations, warranties, or guarantees of any kind, express or implied, regarding the Services.
11.2. Service limitations
The Services have not been developed to meet a customer's or a provider's specific requirements. We are not a provider of medical services, and we do not warrant that the Services will be free of viruses, bugs, or other defects.
11.3. Force majeure
We are not liable or responsible if our provision of the Services or any other responsibility we have under these Terms is hindered, delayed, or prevented by events outside our reasonable control.
11.4. Our liability
To the extent applicable law permits, we and our affiliates, and our and their respective directors, officers, employees, affiliates, agents, contractors, suppliers, and licensors ("our team") have no liability to the provider for any loss of profit, loss of opportunity, loss of goodwill, loss of data, loss of anticipated savings, or any indirect, consequential, incidental, special, punitive, or exemplary loss or damage, however caused.
11.5. Exclusions
Nothing in these Terms excludes or limits either party's liability where doing so would be unlawful, including for death or personal injury caused by negligence, fraud, or fraudulent misrepresentation. The HIPAA Business Associate terms in paragraphs 14.10 to 14.18 contain their own allocation of risk with respect to PHI and prevail over this paragraph 11 in the event of any conflict on a HIPAA matter (see paragraph 13.9.1).
11.6. Scope
The limitations and exclusions in these Terms apply to every loss, damage, claim, and liability arising under or in connection with these Terms, whether in contract, tort (including negligence), breach of statutory duty, restitution, or any other legal theory.
11.7. Claims
The provider agrees to indemnify, defend, and hold harmless us, our affiliates, and our and their respective directors, officers, employees, consultants, and agents from and against any claim, demand, action, suit, proceeding, loss, damage, cost, or expense (including reasonable attorneys' fees) arising out of or in connection with the provider's use of the Services or a breach of these Terms.
11.8. Disputes
If a complaint or dispute arises between a provider and a customer, the provider agrees to release us (and our affiliates, and our and their respective directors, officers, employees, consultants, and agents) from all liability arising from that complaint or dispute.
12. ACCEPTABLE USE
12.1. Use of the Services
The provider must not use the Services:
12.1.1. in any manner inconsistent with these Terms;
12.1.2. in a way that violates or attempts to violate any applicable law, regulation, rule, or code;
12.1.3. in a way that causes or is likely to cause the Services, or access to any part of them, to be interrupted, damaged, or impaired in any way;
12.1.4. for any unlawful, fraudulent, improper, or malicious purpose or effect;
12.1.5. to submit false or misleading information;
12.1.6. to engage in any deceptive or misleading practices;
12.1.7. in any way that infringes the legal rights (including the privacy or intellectual property rights) of any other person;
12.1.8. to deceive any person, to impersonate any person, to mislead as to the origin of the provider's information, or to misrepresent the provider's identity or affiliation;
12.1.9. to send, knowingly receive, upload, download, use or re-use any material which does not comply with these Terms;
12.1.10. to transmit or procure the sending of content or material that is defamatory, racist, sexist, false, misleading, discriminatory, hateful, obscene, offensive, or otherwise unlawful;
12.1.11. to harass, abuse, insult, harm, defame, slander, disparage, intimidate, or discriminate based on gender, sexual orientation, religion, ethnicity, race, age, national origin, or disability;
12.1.12. to transmit, or procure the sending of, any unsolicited or unauthorised advertising or promotional material or any other form or similar solicitation (spam);
12.2. Restrictions
The provider must not:
12.2.1. access or attempt to access the accounts of another user;
12.2.2. use the Services in any way that could damage, compromise, overburden, disable, or impair the Services, anyone's server, systems, or networks, or that could interfere with any other party's use of the Services;
12.2.3. use the Services in order to build a product or service that competes with the Services;
12.2.4. circumvent or manipulate the security features of the Services or attempt to gain unauthorised access to the Services, any part or feature of the Services, or any other systems or networks connected to the Services;
12.2.5. use the Services to obtain or attempt to obtain any materials or information through any means not intentionally made available to the provider;
12.2.6. rent, lease, sell, sub-license, loan, provide, delegate, or otherwise make available the provider's access to the Services (or any part of it, including any of the software in or accessible through it) in any form, in whole or in part to any person;
12.2.7. reproduce, republish, reverse-engineer, disassemble, decompile, translate, duplicate, copy, create derivative works from the whole or any part of the Services;
12.2.8. translate, merge, adapt, vary, alter, or modify the whole or any part of the Services, or allow the Services or any part of it to be combined with, or become incorporated in, any other programs;
12.2.9. hack into or insert harmful or malicious code, such as viruses, or harmful data, into the Services, or any other network or system.
13. GENERAL
13.1. Relationship
Nothing in these Terms creates a partnership, agency, joint venture, or employment relationship between a provider and us. A provider has no authority to bind us or to act on our behalf.
13.2. Contact
If we have to contact a provider, we will do so by email, SMS, or online message using the contact details the provider has supplied to us.
13.3. Entire agreement
These Terms (and any other terms, policies, and operating rules we provide when a provider engages with a feature of the Services) are the entire agreement between the provider and us in respect of their subject matter and supersede any prior agreements, proposals, or representations.
13.4. Transfer
A provider may only transfer its rights or obligations to someone else under these Terms if we agree to this in writing. We may transfer our rights and obligations under these Terms to another organisation without the provider's consent. We will tell the provider in writing if this happens.
13.5. Third parties
These Terms are personal to the provider, and there are no third-party beneficiaries to these Terms.
13.6. Waiver
If we fail to insist that the provider perform any of its obligations under these Terms, or if we do not enforce our rights against the provider, or if we delay in doing so, that will not mean that we have waived our rights against the provider or that the provider does not have to comply with those obligations.
13.7. Severability
Each paragraph in these Terms operates separately. If a court decides that any of them are unlawful, the remaining paragraphs remain in full force and effect.
13.8. Meaning of certain terms
When we use the words "writing" or "written" in these Terms, this includes emails. In these Terms, the singular includes the plural and vice versa.
13.9. Governing law & jurisdiction
The existence, formation, interpretation, operation, and termination of these Terms and any claim, matters, or disputes arising out of or in connection with these Terms (whether contractual or non-contractual) are governed by the laws of Ireland. The courts of Ireland have exclusive jurisdiction to hear and determine any such claim, matter, or dispute between a provider and us. However, this does not prevent us from instituting proceedings in any other competent court to seek injunctive or interim relief.
13.9.1. HIPAA conflict-of-laws. Where the provider is a HIPAA Covered Entity (paragraph 14.10 below applies), the HIPAA Business Associate terms at paragraphs 14.10 to 14.18 are governed by U.S. federal law (HIPAA and the HITECH Act and their implementing regulations at 45 CFR Parts 160 and 164) and by the law of the state in which the Covered Entity has its principal place of business, to the extent that state law is not pre-empted by HIPAA. To the extent of any conflict between paragraphs 14.10 to 14.18 and any other provision of these Terms in relation to a HIPAA matter, paragraphs 14.10 to 14.18 prevail. Nothing in this paragraph 13.9.1 affects the exclusive Irish jurisdiction in paragraph 13.9 for any non-HIPAA dispute.
14. DATA PROTECTION AND HIPAA BUSINESS ASSOCIATE TERMS
14.1. Roles
The provider is the controller (or acts on the controller's behalf) of the customer's personal data that a customer sends to the provider using the Services whenever that personal data resides in the provider's account on the Services. In these cases, we act as the provider's processor, and paragraphs 14.1 to 14.9 set out the obligations on us and the provider. The HIPAA Business Associate terms at paragraphs 14.10 to 14.18 apply in addition where the provider is a U.S. HIPAA Covered Entity and the personal data the provider processes through the Services constitutes Protected Health Information.
14.2. Provider's obligations as controller
The provider must ensure that it documents the instructions it provides to us as its processor. If you act on behalf of the controller, you warrant that you are authorized to provide the controller's instructions to us. As the controller of the customer's personal data stored in the provider's account, the provider is responsible for compliance with data protection law, including supplying privacy notices to customers when acting as the controller; using appropriate security measures to safeguard the personal data; obtaining necessary authorization for the collection, processing, and transfer of customer personal data; and complying with data subject requests from customers (for example, access, correction, and erasure requests).
14.3. Our obligations as a processor
Regarding the customer personal data that we process on behalf of the provider, we will:
14.3.1. implement appropriate technical and organisational measures in a manner that ensures our processing meets the requirements of the applicable data protection laws and ensures the protection of the rights of the data subject;
14.3.2. only process customer personal data based on the instructions the provider supplies to us through the Services, unless applicable law requires us to do otherwise (we will let the provider know that legal requirement before processing, unless that law prohibits us from doing so on important grounds of public interest);
14.3.3. make sure we inform the people who we allow to process the customer's personal data of the confidential nature of the customer's personal data and ensure that those people have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
14.3.4. take steps to make sure that the people acting under our authority who have access to customer personal data only process the customer personal data in accordance with our instructions, unless applicable law requires otherwise;
14.3.5. on the provider's reasonable request, provide the provider with written responses regarding our compliance with the obligations in this paragraph 14, if that information is not otherwise available to the provider;
14.3.6. considering the nature of the processing, help the provider, at the provider's cost, by taking appropriate technical and organisational measures, insofar as this is possible, for the fulfillment of the provider's obligation to respond to requests for exercising the data subject's rights set out in Chapter III of the GDPR;
14.3.7. on the provider's request, make available to the provider all information necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the provider or another third-party auditor the provider mandates, at a mutually agreed time, place, and manner. The provider must notify us no fewer than four weeks in advance of its intention to conduct an audit, and the provider and any third-party auditor must sign a non-disclosure agreement we request and comply with our security and other rules. The provider may exercise this audit right no more than once every 12 months, unless applicable data protection law requires more frequent audits;
14.3.8. take all measures required under Article 32 of the GDPR;
14.3.9. to the extent legally permitted, promptly notify the provider of any data subject requests we receive and reasonably cooperate with the provider to fulfill its obligations under data protection laws in relation to those requests;
14.3.10. help the provider, at the provider's cost, ensure compliance with the provider's obligations as a controller under Articles 32 to 36 of the GDPR, taking into account the nature of the Services and the information available to us;
14.3.11. notify the provider without undue delay after becoming aware of a personal data breach, and we will reasonably respond to the provider's requests for further information to assist the provider in fulfilling its obligations under data protection laws (including the controller's notification obligations under Articles 33 and 34 of the GDPR as applicable);
14.3.12. at the provider's choice, delete or return to the provider all customer personal data within 30 days: (a) when the provider deletes its provider account, or these Terms are terminated for any reason; or (b) at any other time if the provider submits a written request to [email protected].
14.4. Instructions
We will promptly notify the provider if, in our opinion, its instructions infringe applicable data protection law or if we are unable to comply with them.
14.5. Subprocessors
By entering into these Terms, the provider gives us a general authorisation to engage subprocessors to assist in providing the Services. We maintain an up-to-date list of the subprocessors we engage, which is available on request and which we update as subprocessors are added or replaced. We will impose on each subprocessor, by written contract, data protection obligations that are, in all material respects, equivalent to those set out in this paragraph 14. Where a subprocessor fails to fulfil its data protection obligations, we remain fully liable to the provider for the performance of that subprocessor's obligations, subject to these Terms, including the limitations and exclusions of our liability.
14.6. International transfers
Some of the subprocessors that support our business and help us operate and deliver the Services are located in countries outside the European Economic Area (EEA) and the United Kingdom (UK), including the USA. The provider instructs us to transfer customer personal data to any country where we or our subprocessors maintain facilities or provide services to us, including the USA. Where the recipient is in a country that is not deemed by the European Commission (for EEA transfers) or the UK Secretary of State (for UK transfers) to provide an adequate level of protection for personal data, we provide for these transfers using: (a) the European Commission's Standard Contractual Clauses (Module 2 or Module 3, as applicable) for EEA-origin transfers; (b) the UK International Data Transfer Addendum to the EU SCCs or the UK International Data Transfer Agreement for UK-origin transfers; (c) the EU-US Data Privacy Framework and the UK Extension to the DPF where the recipient is DPF-certified; or (d) any other transfer mechanism that applicable law permits and that we determine appropriate. The provider authorises us and our subprocessors to enter into and implement these transfer mechanisms on the provider's behalf and to replace them if applicable law changes the permitted basis for transfers.
14.7. Nature of the internet
The transmission of information over the internet can never be completely private or secure, and the provider accepts the risk that others may be able to read or intercept any information, text, video, or image it submits or sends using the Services, even if a particular transmission is identified as secure or encrypted. The provider understands that it is solely responsible for all electronic communications and content sent from its devices and network.
14.8. Account deletion
If the provider would like more information about how to delete its account, please follow the instructions in the provider account section of the Services or contact us at [email protected].
14.9. HIPAA Business Associate Terms
The following paragraphs 14.10 to 14.18 (the 'BA Terms') apply only where the provider is a Covered Entity (as defined below) and the personal data the provider processes through the Services constitutes Protected Health Information (as defined below). Where the BA Terms apply, they form a Business Associate Agreement between the provider (as Covered Entity) and MeTime Corporation Limited (as Business Associate) consistent with the requirements of 45 CFR §§ 164.502(e) and 164.504(e). The BA Terms apply in addition to, and do not replace, paragraphs 14.1 to 14.9 above.
14.10. Applicability, parties, and HIPAA definitions
These BA Terms apply when the provider self-identifies during onboarding (or at any later point) as a Covered Entity under HIPAA, or when the provider processes PHI through the Services. In these BA Terms, the provider is referred to as the 'Covered Entity,' and MeTime Corporation Limited is referred to as the 'Business Associate.' These BA Terms apply automatically upon acceptance of these Terms and require no separate signature; they are the sole and authoritative source of the parties' HIPAA Business Associate obligations. If a Covered Entity's compliance practice requires a separate signed instrument for its files, Business Associate will, upon request to [email protected], provide a standalone signing pack consisting of paragraphs 14.10 to 14.18, together with a cover page identifying the Covered Entity and Business Associate and signature blocks. The signing pack is derived from these Terms and is not a separate agreement; in the event of any conflict, the inline paragraphs 14.10 to 14.18 prevail. Capitalized terms used in these BA Terms but not defined elsewhere in these Terms have the meanings given to them in HIPAA (45 CFR §§ 160.103, 164.103 and 164.501). For convenience:
(a) 'HIPAA' means the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, together with the HITECH Act and the implementing regulations at 45 CFR Parts 160 and 164, as amended.
(b) 'Protected Health Information' or 'PHI' has the meaning given to that term in 45 CFR §§ 160.103 and 164.501, limited to information created or received by Business Associate from or on behalf of Covered Entity in connection with the Services.
(c) 'Electronic PHI' means any PHI maintained in or transmitted by electronic media as defined in 45 CFR § 160.103.
(d) 'Breach' and 'Unsecured PHI' have the meanings given to those terms in 45 CFR § 164.402 and the Breach Notification Rule (45 CFR Part 164, Subpart D).
(e) 'Security Incident' means the attempted or successful unauthorised access, use, disclosure, modification or destruction of information or interference with system operations in an information system that contains PHI.
(f) 'Designated Record Set', 'Individual', 'Privacy Rule', 'Security Rule', 'Data Aggregation', 'De-Identify' and other capitalised terms used in these BA Terms have the meanings given to them in 45 CFR §§ 160.103, 164.501 and 164.514, as applicable.
14.11. Permitted uses and disclosures of PHI
Business Associate will not use or disclose PHI except as permitted or required by these BA Terms, as permitted by the Privacy Rule, or as required by law. Subject to that limitation, Business Associate may use or disclose PHI: (a) as reasonably necessary to perform the Services for Covered Entity under these Terms, including the activities described in paragraph 14.1; (b) for the proper management and administration of Business Associate or to carry out its legal responsibilities, provided that any onward disclosure for those purposes is either required by law or made under written assurances from the recipient that the PHI will be held confidentially and that the recipient will notify Business Associate of any breach of confidentiality; (c) to provide Data Aggregation services relating to Covered Entity's health-care operations, where Covered Entity requests those services in writing; (d) to report violations of law to appropriate Federal and State authorities, consistent with 45 CFR § 164.502(j)(1); and (e) at Covered Entity's request, to De-Identify PHI in accordance with 45 CFR §§ 164.514(a) and (b). Upon request, Business Associate will make available to Covered Entity any of Covered Entity's PHI that Business Associate or any of its agents or subcontractors have in their possession.
14.12. Safeguards against misuse of PHI
Business Associate will use appropriate administrative, physical, and technical safeguards and comply with the Security Rule regarding Electronic PHI to prevent the use or disclosure of PHI other than as provided by these BA Terms (45 CFR §§ 164.308, 164.310, and 164.312).
14.13. Reporting of disclosures, Security Incidents and Breaches; mitigation
Business Associate will report to Covered Entity in writing any use or disclosure of PHI not permitted by these BA Terms of which it becomes aware. Business Associate will promptly report to Covered Entity any Security Incident affecting Electronic PHI of which it becomes aware, on the understanding that the Parties agree that this paragraph constitutes notice by Business Associate of the ongoing existence and occurrence of attempted but unsuccessful Security Incidents (such as pings on Business Associate's firewall, port scans, attempts to log on with an invalid password or user name, denial-of-service attacks that do not result in a server being taken offline, malware that did not result in unauthorized access, and any combination of the above) for which no additional notice to Covered Entity shall be required. Business Associate will notify Covered Entity in writing promptly upon the discovery of any Breach of Unsecured PHI in accordance with the Breach Notification Rule (45 CFR §§ 164.410 and 164.414). Business Associate will take reasonable measures to mitigate, to the extent practicable, any harmful effects known to Business Associate of any use or disclosure of PHI by Business Associate in violation of these BA Terms or applicable law.
14.14. Sub-business-associate agreements
Business Associate will ensure that any of its agents or subcontractors that have access to PHI, or to which Business Associate provides PHI, agree in writing to be bound by restrictions and conditions on the use and disclosure of PHI that are at least as restrictive as those that apply to Business Associate under these BA Terms (45 CFR § 164.504(e)(2)(ii) and § 164.308(b)(1)). Business Associate maintains a written list of its current sub-business-associates that touch PHI in connection with the Services, which is available to Covered Entity upon request. Where a subprocessor listed in paragraph 14.5 will not enter into back-to-back HIPAA terms, Business Associate will either: (a) not use that subprocessor in the PHI processing flow for Covered Entity; or (b) propose a contractual or technical alternative that achieves the same outcome.
14.15. Access, amendment, and accounting of disclosures (HIPAA Individual rights)
Upon request, Business Associate agrees to furnish Covered Entity with copies of the PHI maintained by Business Associate in a Designated Record Set, in the time and manner designated by Covered Entity, so Covered Entity can respond to Individual access requests under 45 CFR § 164.524. If any Individual or personal representative requests access to the Individual's PHI directly from Business Associate, Business Associate will, within 10 business days, forward that request to Covered Entity for response. Upon request and instruction from Covered Entity, Business Associate will amend PHI or a record about an Individual in a Designated Record Set that is maintained by, or otherwise within the possession of, Business Associate, in accordance with 45 CFR § 164.526. Business Associate will document any disclosures of PHI it makes, as required by 45 CFR § 164.528, and, within 10 business days after a written request by Covered Entity, make available to Covered Entity the information necessary for Covered Entity to respond to an accounting-of-disclosures request from an Individual.
14.16. Covered Entity's responsibilities
With regard to the use and/or disclosure of PHI by Business Associate, Covered Entity agrees to: (a) notify Business Associate of any limitation(s) in its notice of privacy practices in accordance with 45 CFR § 164.520, to the extent that such limitation may affect Business Associate's use or disclosure of PHI; (b) notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI; (c) notify Business Associate of any restriction to the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 CFR § 164.522, to the extent that such restriction may affect Business Associate's use or disclosure of PHI; and (d) except for Data Aggregation or management and administrative activities of Business Associate, not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity directly.
14.17. Data ownership, term, termination, return of PHI, and HITECH compliance
Business Associate's data stewardship does not confer data ownership rights on Business Associate with respect to PHI. These BA Terms become effective at the same time as the rest of these Terms and remain in effect for as long as Business Associate holds PHI on behalf of Covered Entity. Each Party may terminate these BA Terms (and the rest of these Terms with respect to HIPAA-relevant Services) if the other Party breaches a material term of these BA Terms and fails to cure the breach within thirty (30) days of written notice. On termination of these Terms or these BA Terms for any reason, all PHI held by Business Associate on behalf of Covered Entity will, at Covered Entity's option, be returned to Covered Entity or destroyed by Business Associate within thirty (30) days (consistent with paragraph 14.3.12). If return or destruction is not feasible, Business Associate will extend the protections of these BA Terms to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible. References in these BA Terms to a section in HIPAA mean that section as in effect or as amended at the time. The Parties acknowledge the HITECH Act and agree to comply with the provisions of the HITECH Act applicable to Business Associate, including the Breach Notification Rule. To the extent the HITECH Act, the Privacy Rule, or the Security Rule is amended, the Parties will work in good faith to amend these BA Terms to remain compliant.
