Aura — Terms & Conditions | Aura | The Private Clinic | Booking Link in Bio

Aura — Terms & Conditions

Version 1.0 · Effective date: 22 July 2026 Operator: The Private Clinic — العيادة الشخصية الطبية, registered in the Hashemite Kingdom of Jordan, Company No. 75818, National Establishment ID 200204705 (“Aura“, “we“, “us“). Contact: care@theprivateclinic.me

These Terms & Conditions (the “Terms“) are a single, global agreement that governs all use of the Aura platform on link.theprivateclinic.me and its connection to care.theprivateclinic.me (the “Platform“). They incorporate and replace the separate signature of a Data Processing Addendum and the distribution of a standalone patient privacy notice: everything in this document takes effect automatically through use of the Platform — no signature, form, or written acceptance is required from any Provider or client. Creating an account, entering data, or making a booking constitutes full acceptance. If you do not accept these Terms, do not use the Platform.


Part I — General

1 · The three roles

  • Providers — professionals who create an account, publish a booking page and manage clients.
  • Clients / patients — people who book sessions with a Provider.
  • Visitors — anyone viewing a public page.

For Provider account data and platform operations, Aura is the data controller. For every client and patient record a Provider creates or collects through the Platform — bookings, charts, session notes, medications, communications — the Provider is the data controller and Aura acts exclusively as a data processor on the Provider’s instructions. This allocation applies automatically and continuously; it is not subject to negotiation, signature or opt-out.

2 · The service

Aura provides booking, scheduling, group classes, packages, client records, payments facilitation, analytics, messaging automations and related tools. Aura is a technology platform only: it is not a healthcare provider, does not employ Providers, does not supervise treatment, does not verify the clinical content Providers create, and is not a party to the professional relationship between a Provider and a client.

3 · Accounts

Account holders must be 18 years of age or older. You are responsible for the confidentiality of your credentials and for all activity under your account. Accounts lock automatically after repeated failed sign-ins; contact care@theprivateclinic.me to restore access. Aura may suspend or terminate accounts that violate these Terms, abuse the Platform, or create legal risk.


Part II — Provider responsibility (the core allocation)

4 · Your license, your law, your practice

The Provider is solely and entirely responsible for:

(a) holding, maintaining and complying with every license, registration, qualification and permission required to offer their services in their place of practice; (b) the nature, quality, legality and outcomes of their practice, including diagnoses, treatment, advice, prescriptions and clinical decisions; (c) compliance with the laws of their country and place of practice — including health law, professional-secrecy law, medical-records and retention law, consumer law, tax law and data-protection law — as those laws apply to their license and specialty; (d) determining and honoring a lawful basis (and, where required, valid consent) for every item of client or patient data they process through the Platform; (e) informing their patients about how their data is handled where local law requires it — Part IV of these Terms provides that information publicly on the Provider’s behalf, and the Provider is responsible for confirming this satisfies, or supplementing it to satisfy, their local obligations; (f) the accuracy of everything they publish on their public page, and ensuring no client or patient information ever appears on it; (g) the security and lawfulness of every endpoint they direct data to — webhook receivers, connected calendars, automation tools and advertising pixels; (h) obtaining guardian consent where they lawfully treat minors.

Indemnity. The Provider indemnifies and holds harmless Aura, its owners, and personnel against any claim, penalty, loss or expense arising from the Provider’s breach of this Section 4, from their professional practice, or from data they unlawfully process or publish.

5 · Data processing terms (processor commitments)

For all client and patient data, Aura commits — automatically and without signature — to the following processor terms:

5.1 Instructions. Aura processes such data only to operate the features the Provider uses, to transmit data to third parties the Provider has enabled (Part III §9), and to comply with law. No analytics on clinical content, no advertising use, no sale, no model training — ever.

5.2 Confidentiality. Personnel access data on a strict need-to-know basis and are bound by confidentiality. Clinical content is not read except where strictly necessary to execute a support request initiated by the Provider, or as required by law.

5.3 Security. Encrypted transport (HTTPS); hashed credentials; role-based access enforced at the API layer — front-desk assistants can never access clinical charts, notes, medications, revenue or content, by both interface and API enforcement; brute-force sign-in lockout; nonce-verified authenticated requests; least-privilege administration; diagnostic logging.

5.4 Sub-processor. Hostinger (hosting and email infrastructure). Aura will update its published policies before adding any sub-processor that touches personal data. Vendors the Provider enables (Google, Microsoft, Zoom, automation endpoints, payment processors, pixel vendors) are recipients at the Provider’s direction, not Aura sub-processors.

5.5 Breach. Aura will notify affected Providers without undue delay — and in any event within 72 hours of becoming aware — of a breach affecting their clients’ data, so the Provider can meet their own notification duties. Providers must promptly report suspected compromise of their account or endpoints to care@theprivateclinic.me.

5.6 Assistance. Aura executes retrievals, corrections, exports and deletions of clinical records as the Provider instructs, so the Provider can answer their patients’ requests.

5.7 Retention & deletion. Patient records are never deleted automatically. Disposition follows the Provider’s request, consistent with the retention law of their place of practice. If, 90 days after account termination and written prompt, the Provider gives no instruction, Aura may delete residual data unless law requires storage. Deleted data ages out of rolling 90-day backups.

5.8 Audit. On reasonable written request (at most annually, absent a breach), Aura provides documentation demonstrating compliance with this Section 5.


Part III — Platform data practices

6 · What Aura collects

From Providers: identity and profile, professional credentials, practice configuration (services, classes, seats, schedules, prices, currencies), plan and billing history, payout bank details (bank name, branch, beneficiary, account, IBAN, SWIFT, address, country — used solely to execute payouts), integration tokens (OAuth tokens, never passwords), team roles.

From clients: account data (name, email, hashed credentials), bookings (service, class seat, time, timezone, status, amount, currency, package credits), and — under the Provider’s control per Part II — health records.

Technical, from everyone: functional cookies (aura_pref_lang, aura_lang_applied, aura_lang_auto, aura_client_tz, WordPress session cookies), interface state in local storage (tour progress, dismissed banners — no tracking identifiers), page-view and click counts on public pages aggregated for the Provider’s own analytics, and security logs retained 90 days.

Aura does not collect government ID numbers, biometrics or precise geolocation. Payment card details never touch Aura’s systems.

7 · Payments

Client payments and plan purchases are processed by HyperPay, PayTabs, Paymob and Zbooni under their own terms and privacy policies; Aura receives only order outcome, amount, currency and status. Provider payouts are computed from completed sessions minus the platform commission applicable to the Provider’s plan (or an individually agreed rate); each payout receipt itemizes amount earned, commission and payout amount.

8 · Public pages

Everything a Provider publishes at /@handle is publicly accessible, indexable and shareable. Link previews in messaging apps display a QR code encoding the page address (a third-party QR service receives only the URL). Aura cannot recall copies cached by search engines or third parties after unpublishing.

9 · Integrations

Every integration is off by default and activates only at the Provider’s direction. Enabling one instructs Aura to transmit the described data to that vendor, whose own terms then govern it: calendar sync (booking events with the client identifier the Provider configures — full name or anonymous label), listing sync to care.theprivateclinic.me (public data only, never clinical), booking webhooks to Provider-controlled URLs, Zoom links in confirmations, and marketing pixels that run on the public page only — never on the dashboard or any page containing clinical data.

10 · Communications

Transactional messages (confirmations, reminders, payment and payout receipts, security and plan notices) are inherent to the service and cannot be opted out of while an account exists. Non-essential Provider announcements carry an unsubscribe link honored platform-wide. Aura never messages a Provider’s clients for Aura’s own marketing. Providers using WhatsApp or other channels via automations are responsible for obtaining any opt-ins those channels require.


Part IV — Patient information (public notice, no distribution required)

This Part is addressed to clients and patients and constitutes the standing privacy information for data processed when booking or receiving care through the Platform. It applies automatically; no Provider needs to distribute, adapt or obtain signature of any separate notice for Platform processing (though local law may require a Provider to give additional information — Part II §4(e)).

Who is responsible. Your booking account is operated by Aura. Your health information — the notes, history and medications your practitioner records — is controlled by your treating practitioner, who uses Aura as a secure storage and management tool. Aura makes no use of your health information of its own: no advertising, no sale, no analysis of clinical content.

What is processed. Your name, contact details and timezone; your bookings and their payment status; and the clinical records your practitioner keeps. Payments are handled by licensed processors (HyperPay, PayTabs, Paymob, Zbooni); your card details never reach Aura or your practitioner through the Platform.

Who can see what. Your clinical notes are visible only to your treating practitioner (and, in team practices, the practice owner who administers that practice). Front-desk staff see appointment times and contact details only — never clinical notes. Nothing clinical is shown to other clients, to visitors, or on any public page. If your practitioner has enabled calendar sync, your appointment may appear in their personal calendar under your full name or an anonymous label, per their configuration; appointment details (never clinical notes) may flow to scheduling automations they control.

Reviews. If you rate a session, your rating and any comment you choose to write may appear publicly on your practitioner’s page with your name masked to its first letter only (e.g., “a****”). Do not include personal or health details in a review comment.

How long. Clinical records are retained per the medical-records law applicable to your practitioner’s license and place of practice, and are disposed of on your practitioner’s lawful instruction — never by automatic deletion.

Your rights. Subject to applicable law you may request access, correction, a copy, or deletion of your data. Requests about clinical records go to your treating practitioner, who controls them; Aura assists as processor. Requests about your booking account go to care@theprivateclinic.me. Answers within 30 days; identity may be verified; retention laws may lawfully override deletion. You may complain to the data-protection authority in your country.

Minors. Booking and consent for anyone under 18 must be provided by a parent or legal guardian.


Part V — Legal

11 · Acceptable use

No unlawful content or activity; no data entry concerning persons without a genuine professional relationship; no scraping, probing, or circumvention of access controls; no misrepresentation of identity, credentials or affiliation; no use of the Platform to send spam or unlawful communications.

12 · Availability and changes

The Platform is provided “as is” and “as available.” Aura may modify features, apply maintenance windows, and update these Terms; material changes are announced to account holders at least 14 days before taking effect. Continued use after the effective date constitutes acceptance.

13 · Liability

To the maximum extent permitted by law: Aura is not liable for the acts, omissions, or professional conduct of any Provider, for the content of clinical records, for outcomes of care, for third-party services (payment processors, calendar vendors, automation endpoints, pixel vendors), or for indirect, consequential or lost-profit damages. Aura’s aggregate liability to any Provider is limited to the platform fees that Provider paid in the twelve months preceding the claim; toward clients, to the amount of the booking concerned. Nothing limits liability that cannot lawfully be limited.

14 · Term and termination

Providers may close their account at any time; Part II §5.7 governs record disposition. Aura may terminate for breach with notice, or immediately where the breach creates legal or safety risk. Sections 4, 5, 13 and 15 survive termination.

15 · Governing law and disputes

These Terms are governed by the laws of the Hashemite Kingdom of Jordan, including the Personal Data Protection Law No. 24 of 2023 — without prejudice to the mandatory laws of the Provider’s place of practice, which remain the Provider’s own responsibility under Part II. Disputes are subject to the competent courts of Jordan, after a good-faith attempt at amicable resolution via care@theprivateclinic.me.

16 · Entire agreement

These Terms, together with the Privacy Policy, form the entire agreement for use of the Platform and supersede any separate data-processing addendum or notice previously published. If any provision is held invalid, the remainder stands.


The Private Clinic — العيادة الشخصية الطبية · Company No. 75818 · Jordan · care@theprivateclinic.me