BUSINESS ASSOCIATE AGREEMENT (BAA)
DATA PROTECTION, PRIVACY AND INFORMATION SECURITY
Governing the Processing of Protected Health Information Between AwaDoc and Its Healthcare Network Partners
RECITALS
- WHEREAS, AwaDoc Limited (“AwaDoc” or “Business Associate”) is a technology-enabled digital healthcare company operating an AI-powered clinical platform across 30 or more African countries, including Nigeria, and provides digital health services through its Noura AI clinical assistant, accessible natively via WhatsApp and the Mobile App;
- WHEREAS, the Partner identified on the cover page of this Agreement (“Covered Entity”) is a licensed and regulated healthcare provider that creates, receives, maintains, or transmits Protected Health Information in the course of providing healthcare services to patients;
- WHEREAS, AwaDoc, in the performance of services on behalf of, or in connection with, the Covered Entity, may create, receive, maintain, process, or transmit Protected Health Information that is subject to applicable data protection and health information privacy laws, including but not limited to the Nigeria Data Protection Act 2023 (NDPA), the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, and other applicable national and regional data protection legislation;
- WHEREAS, applicable laws and regulations require that the parties execute a Business Associate Agreement governing the terms under which Protected Health Information may be accessed, used, disclosed, and safeguarded;
- NOW, THEREFORE, in consideration of the mutual obligations set forth herein, and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the parties agree as follows:
1. DEFINITIONS
Unless otherwise defined herein, all capitalised terms shall have the meanings ascribed to them under applicable data protection law, including the NDPA 2023 and HIPAA. The following terms shall have the meanings set out below:
1.1 Protected Health Information (PHI): Any individually identifiable health information, in any form or medium, that is created, received, maintained, or transmitted by or on behalf of the Covered Entity, and that relates to: (a) the past, present, or future physical or mental health or condition of a data subject; (b) the provision of healthcare to a data subject; or (c) the past, present, or future payment for the provision of healthcare to a data subject. PHI includes Electronic Protected Health Information (ePHI) in all its forms.
1.2 Electronic Protected Health Information (ePHI): Protected Health Information that is created, received, maintained, or transmitted in electronic form, including information transmitted through mobile messaging platforms, AI-powered clinical systems, application programming interfaces, cloud storage systems, and any other electronic medium.
1.3 Business Associate: AwaDoc, a person or entity that, on behalf of a Covered Entity, creates, receives, maintains, or transmits PHI for a function or activity regulated under applicable health information privacy law, or provides services to a Covered Entity where the provision of such services involves the disclosure of PHI.
1.4 Covered Entity: The healthcare provider, facility, insurer, or other regulated health entity identified on the cover page of this Agreement, which creates, receives, maintains, or transmits PHI and is subject to applicable health information privacy obligations.
1.5 Permitted Purpose: The specific services, functions, or activities performed by AwaDoc on behalf of the Covered Entity as described in this Agreement and any associated service agreement, for which the use and disclosure of PHI is authorised.
1.6 Data Subject: The identified or identifiable natural person to whom PHI relates, being a patient or prospective patient of the Covered Entity or a user of the AwaDoc Platform.
1.7 Security Incident: Any attempted or successful unauthorized access, use, disclosure, modification, or destruction of PHI or ePHI, or any interference with system operations that may compromise the confidentiality, integrity, or availability of PHI.
1.8 Breach: An impermissible use or disclosure of PHI that compromises the security or privacy of the PHI and poses a significant risk of financial, reputational, or other harm to the Data Subject. A Breach does not include inadvertent disclosures between authorised workforce members where the information is not further disclosed beyond the authorised recipients.
1.9 Subcontractor: Any person or entity engaged by AwaDoc to carry out functions, activities, or services on behalf of AwaDoc that involve the creation, receipt, maintenance, processing, or transmission of PHI.
1.10 Applicable Law: The Nigeria Data Protection Act 2023 (NDPA) and its implementing regulations; the Nigeria Data Protection Regulation 2019 (NDPR); the Health Insurance Portability and Accountability Act 1996 (HIPAA) and the HIPAA Privacy Rule (45 CFR Part 164, Subpart E), Security Rule (45 CFR Part 164, Subpart C), and Breach Notification Rule (45 CFR Part 164, Subpart D); the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) where ratified; and any other applicable national, regional, or sectoral data protection, health information, or cybersecurity law applicable to the parties in the jurisdictions where Partner Services are delivered.
1.11 Minimum Necessary: The principle that use, disclosure, and requests for PHI shall be limited to the minimum amount necessary to accomplish the Permitted Purpose, consistent with applicable law.
2. OBLIGATIONS AND ACTIVITIES OF AWADOC
AwaDoc shall not use or disclose PHI other than as permitted or required by this Agreement or as required by Applicable Law. AwaDoc is permitted to use and disclose PHI as follows:
- To perform the Permitted Purpose and provide the services described in the associated Partner Services Agreement between the parties.
- For the proper management and administration of AwaDoc’s operations, provided that disclosures for such purposes are required by Applicable Law, or AwaDoc obtains reasonable assurances from the recipient that the PHI will be held confidentially and used or further disclosed only as required by law or for the purpose for which it was disclosed.
- To carry out the legal responsibilities of AwaDoc, where required by Applicable Law.
- To provide data aggregation services relating to the healthcare operations of the Covered Entity, where authorised.
- To report violations of law to appropriate government authorities, consistent with applicable whistleblower protections, provided that any disclosure is limited to information directly pertaining to the violation.
AwaDoc shall not use or disclose PHI in a manner that would violate the requirements of Applicable Law if done by the Covered Entity, except as set out in this Section 2.1.
AwaDoc shall use, disclose, and request only the minimum amount of PHI necessary to accomplish the Permitted Purpose. AwaDoc shall implement policies and procedures to limit internal access to and use of PHI to those workforce members who need access to perform their functions, and only to the extent necessary for those functions.
AwaDoc shall implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI that it creates, receives, maintains, or transmits on behalf of the Covered Entity. Such safeguards shall, at a minimum, comply with the requirements of Applicable Law and shall include:
- Designating a Data Protection Officer or equivalent privacy and security lead responsible for overseeing compliance with this Agreement and Applicable Law.
- Implementing and regularly reviewing written privacy and information security policies and procedures applicable to all workforce members with access to PHI.
- Conducting mandatory data protection training for all workforce members who create, receive, maintain, or transmit PHI, with refresher training at least annually.
- Implementing a workforce sanctions policy addressing violations of privacy and security policies.
- Conducting regular risk assessments to identify, evaluate, and address risks to the confidentiality, integrity, and availability of ePHI.
- Implementing and testing a contingency plan, including data backup, disaster recovery, emergency mode operations, and testing and revision procedures.
- Maintaining internal audit controls to monitor access to and activity within systems containing PHI.
- Implementing facility access controls to limit physical access to electronic information systems and equipment containing PHI to authorised persons.
- Implementing workstation use policies specifying proper use of workstations that access ePHI.
- Implementing device and media controls for the receipt, removal, and disposal of hardware and electronic media containing PHI, including procedures for final disposal and re-use.
- Implementing access controls, including unique user identification, emergency access procedures, automatic logoff, and encryption and decryption of ePHI.
- Implementing audit controls, including hardware, software, and procedural mechanisms that record and examine activity in information systems containing or using ePHI.
- Implementing integrity controls to ensure ePHI is not improperly altered or destroyed, and to detect such alterations.
- Implementing transmission security measures including encryption of ePHI transmitted over electronic communications networks, including via WhatsApp Business API, REST APIs, and cloud services.
- Implementing multi-factor authentication for all systems containing PHI.
AwaDoc shall notify the Covered Entity without unreasonable delay and in no event later than seventy-two (72) hours after discovery of a Breach of unsecured PHI. The notification shall include, to the extent known at the time of notification:
- A description of the Breach, including the date of the Breach and the date of discovery;
- The types of PHI involved, including identifiers affected;
- The identity of individuals whose PHI was involved, to the extent known;
- Any steps Data Subjects should take to protect themselves from potential harm resulting from the Breach;
- A description of the steps AwaDoc is taking to investigate the Breach, mitigate harm, and prevent future Breaches;
- Contact information of the AwaDoc Data Protection Officer or designated privacy contact for further inquiries.
AwaDoc shall provide the Covered Entity with any additional information as it becomes available following the initial notification. The Covered Entity shall be responsible for notifying affected Data Subjects and, where required by Applicable Law, relevant supervisory authorities, unless the parties agree otherwise in writing.
AwaDoc shall report to the Covered Entity, within a reasonable timeframe not exceeding five (5) business days of discovery, any Security Incident of which it becomes aware that does not constitute a Breach, including unsuccessful attempts to access, use, or disclose PHI without authorisation.
AwaDoc shall notify the Covered Entity promptly, to the extent permitted by law, before complying with any judicial order, regulatory demand, or other legal process requiring disclosure of PHI, so that the Covered Entity may seek a protective order or take other appropriate action.
AwaDoc shall ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of AwaDoc agrees, in a written agreement that is at least as protective as this Agreement, to the same restrictions, conditions, and requirements applicable to AwaDoc under this Agreement and Applicable Law. AwaDoc shall maintain a register of all Subcontractors that have access to PHI and shall make such register available to the Covered Entity upon request. AwaDoc shall remain responsible for the acts and omissions of its Subcontractors to the same extent as if performed by AwaDoc directly.
AwaDoc shall cooperate with the Covered Entity and, where directed by the Covered Entity, directly with Data Subjects, to facilitate the exercise of data subject rights under Applicable Law, including:
- The right of access: providing Data Subjects or the Covered Entity with copies of PHI held by AwaDoc within the timeframes required by Applicable Law.
- The right to rectification: correcting inaccurate or incomplete PHI upon instruction from the Covered Entity or, where directed, from the Data Subject.
- The right to erasure: deleting or de-identifying PHI upon instruction from the Covered Entity, subject to AwaDoc’s legal retention obligations and the rights of third parties.
- The right to restriction: restricting the processing of PHI upon instruction from the Covered Entity where permitted by Applicable Law.
- The right to data portability: providing PHI in a structured, commonly used, and machine-readable format upon instruction from the Covered Entity.
- The right to object: ceasing or restricting processing of PHI upon instruction from the Covered Entity where the Data Subject has exercised a right to object.
AwaDoc shall respond to requests from the Covered Entity relating to Data Subject rights within ten (10) business days of receipt, and shall not respond directly to Data Subjects regarding their PHI without prior written authorisation from the Covered Entity, except where directly required by Applicable Law.
AwaDoc shall make its internal policies, procedures, practices, and records relating to the use and disclosure of PHI, and its safeguard measures, available to the Covered Entity and to any relevant regulatory authority upon request, for the purpose of assessing compliance with this Agreement and Applicable Law. AwaDoc shall cooperate fully with any audit, investigation, or review conducted by the Covered Entity or a regulatory authority.
AwaDoc shall not directly or indirectly receive remuneration in exchange for PHI, unless the Covered Entity has provided prior written authorisation consistent with Applicable Law and the relevant Data Subjects have given informed consent where required. AwaDoc shall not use PHI for marketing, targeted advertising, or any purpose that benefits AwaDoc commercially beyond the delivery of the Permitted Purpose.
AwaDoc may use de-identified data derived from PHI, provided that the de-identification is performed in accordance with a recognised de-identification standard (such as the HIPAA Expert Determination or the Safe Harbor method), and the resulting information does not permit identification of the individual data subject either directly or in combination with other information reasonably available to AwaDoc. De-identified data so produced shall not be considered PHI for the purposes of this Agreement.
AwaDoc expressly agrees not to:
- Use or disclose PHI in any manner inconsistent with this Agreement, Applicable Law, or the written instructions of the Covered Entity;
- Use PHI for any secondary, commercial, or research purpose not authorised by this Agreement;
- Attempt to re-identify de-identified information;
- Contact Data Subjects directly for purposes unrelated to the delivery of healthcare services without the prior written consent of the Covered Entity;
- Transfer PHI to any jurisdiction outside Nigeria or the Partner’s primary jurisdiction without: (a) the prior written consent of the Covered Entity; (b) appropriate data transfer mechanisms as required by Applicable Law (such as Standard Contractual Clauses or equivalent instruments); and (c) where required, the informed consent of the relevant Data Subjects.
3. OBLIGATIONS OF THE COVERED ENTITY
- 3.1 Lawful Disclosures to AwaDoc: The Covered Entity shall not request that AwaDoc use or disclose PHI in any manner that would violate Applicable Law if such use or disclosure were made by the Covered Entity. The Covered Entity shall ensure that it has a lawful basis for any disclosure of PHI to AwaDoc and that all required patient consents have been obtained prior to sharing PHI with AwaDoc.
- 3.2 Notice of Privacy Practices: The Covered Entity shall provide AwaDoc with any changes to its Notice of Privacy Practices or equivalent patient information document that may affect AwaDoc’s use or disclosure of PHI, promptly upon the Covered Entity becoming aware of such changes.
- 3.3 Permissions and Restrictions: The Covered Entity shall notify AwaDoc in writing of any restriction on the use or disclosure of PHI that the Covered Entity has agreed to or is required to implement under Applicable Law, to the extent such restriction may affect AwaDoc’s permitted uses and disclosures. The Covered Entity shall notify AwaDoc of any revocation of a Data Subject’s authorisation for disclosure of PHI, to the extent such revocation may affect AwaDoc’s permitted activities.
- 3.4 Accuracy of Information: The Covered Entity shall take reasonable steps to ensure that PHI disclosed to AwaDoc is accurate, complete, and current, and shall promptly notify AwaDoc of any corrections or updates to PHI that may affect AwaDoc’s delivery of services.
- 3.5 Patient Consent: Where required by applicable law or the nature of the services being provided, the Covered Entity shall obtain and document the informed consent of Data Subjects prior to sharing their PHI with AwaDoc. The Covered Entity shall maintain records of all such consents and shall make them available to AwaDoc upon request.
- 3.6 Cooperation with AwaDoc: The Covered Entity shall cooperate reasonably with AwaDoc in the implementation of the safeguards, policies, and procedures required under this Agreement. The Covered Entity shall promptly notify AwaDoc of any changes in the nature or volume of PHI shared with AwaDoc that may require updates to AwaDoc’s risk assessment or security measures.
4. PERMITTED USE OF PHI FOR AWADOC MANAGEMENT AND ADMINISTRATION
AwaDoc is permitted to use PHI for the proper management and administration of its own operations and to fulfil legal responsibilities, provided that:
- Such use is necessary for the conduct of AwaDoc’s business operations and does not constitute a use for commercial gain, marketing, or secondary purposes not authorised by this Agreement;
- AwaDoc implements appropriate safeguards to protect the confidentiality of such PHI during any such use;
- AwaDoc uses the minimum necessary PHI for the management or administrative purpose;
- Any disclosure of PHI for management purposes is required by applicable law, or AwaDoc obtains written assurances from the recipient of the PHI that it will be kept confidential and used only for the stated purpose.
5. TERM AND TERMINATION
- 5.1 Term: This Agreement shall become effective on the date of execution and shall remain in force for so long as AwaDoc performs services on behalf of the Covered Entity that involve the creation, receipt, maintenance, or transmission of PHI, unless earlier terminated in accordance with this Section 5.
- 5.2 Termination for Cause: Either party may terminate this Agreement immediately upon written notice if the other party materially breaches any provision of this Agreement and fails to cure such breach within thirty (30) calendar days of receiving written notice specifying the breach in reasonable detail. In cases where cure is not possible, either party may terminate this Agreement immediately upon written notice. Where the Covered Entity becomes aware of a pattern of activity or practice by AwaDoc that constitutes a material breach of AwaDoc’s obligations under this Agreement and cure is not feasible, the Covered Entity may terminate this Agreement and all related service agreements immediately.
- 5.3 Termination Without Cause: Either party may terminate this Agreement without cause by providing sixty (60) days’ prior written notice to the other party.
- 5.4 Effect of Termination – Return or Destruction of PHI: Upon termination of this Agreement for any reason, AwaDoc shall, at the direction of the Covered Entity: (a) Return to the Covered Entity all PHI in AwaDoc’s possession, including all copies held by Subcontractors, within thirty (30) calendar days of the effective date of termination; or (b) Destroy all PHI in AwaDoc’s possession, including all copies held by Subcontractors, in a manner that renders the PHI unreadable, indecipherable, and irretrievable, and provide the Covered Entity with written certification of such destruction within thirty (30) calendar days. If AwaDoc determines that returning or destroying PHI is not feasible, AwaDoc shall notify the Covered Entity in writing, specifying the reasons. AwaDoc shall continue to apply the protections of this Agreement to the retained PHI.
- 5.5 Survival: The obligations of AwaDoc with respect to the use, disclosure, and protection of PHI shall survive the termination or expiration of this Agreement for as long as AwaDoc retains any PHI. Sections 2, 5.4, 6, 7, 8, 9, and 10 shall survive termination.
6. INFORMATION SECURITY STANDARDS
- 6.1 Risk Assessment and Management: AwaDoc shall conduct a comprehensive risk assessment of potential threats and vulnerabilities to the confidentiality, integrity, and availability of all ePHI it creates, receives, maintains, or transmits on behalf of the Covered Entity. AwaDoc shall implement security measures sufficient to reduce identified risks to a reasonable and appropriate level, document the assessment and the measures taken, and review and update the risk assessment at least annually.
- 6.2 Encryption Standards: AwaDoc shall encrypt all ePHI at rest and in transit using industry-standard encryption algorithms. Encryption at rest shall use AES-256 or equivalent. Encryption in transit shall use TLS 1.2 or higher for all API communications. All ePHI transmitted via the WhatsApp Business API shall use end-to-end encryption as provided by Meta, with additional application-layer encryption applied to structured clinical data.
- 6.3 Access Controls: AwaDoc shall implement role-based access controls ensuring that access to PHI is granted on a need-to-know basis. All user accounts with access to systems containing PHI shall be subject to multi-factor authentication. Privileged access accounts shall be subject to additional monitoring. Accounts of departing workforce members shall be disabled within twenty-four (24) hours of termination.
- 6.4 Audit Logging: AwaDoc shall maintain comprehensive audit logs of all access to, and use and disclosure of, ePHI. Logs shall record at minimum the user identity, action performed, timestamp, and data accessed or affected. Logs shall be retained for a minimum of six (6) years and shall be protected from alteration or deletion.
- 6.5 Incident Response: AwaDoc shall maintain and regularly test a documented incident response plan that addresses detection, containment, eradication, recovery, and post-incident review for security incidents involving PHI. AwaDoc shall conduct tabletop exercises or simulated incident responses at least annually.
- 6.6 Vulnerability Management: AwaDoc shall implement and maintain a vulnerability management programme that includes regular scanning of systems containing ePHI, timely remediation of identified vulnerabilities, and application of security patches. Critical vulnerabilities shall be remediated within seventy-two (72) hours of identification.
- 6.7 Third-Party Cloud and AI Services: AwaDoc utilises third-party cloud computing and AI model services in the delivery of the Permitted Purpose. AwaDoc shall ensure that all such third-party services: (a) Are governed by written agreements that impose data protection obligations at least as stringent as those in this Agreement; (b) Process ePHI only within jurisdictions that provide an adequate level of data protection under Applicable Law, or where appropriate data transfer mechanisms are in place; (c) Are assessed for security and compliance on an annual basis; (d) Do not use ePHI to train AI models without the prior written consent of the Covered Entity and the informed consent of the relevant Data Subjects.
7. DATA GOVERNANCE AND RETENTION
- 7.1 Data Inventory: AwaDoc shall maintain a current inventory of all PHI it holds on behalf of the Covered Entity, including the type of data, its source, location, retention period, and the legal basis for processing.
- 7.2 Retention Periods: AwaDoc shall retain PHI only for as long as necessary to fulfil the Permitted Purpose or as required by Applicable Law. PHI shall not be retained beyond the following maximum periods unless a longer retention period is required by law: (a) Clinical consultation records: thirty (30) days from the date of the last interaction; (b) Prescription and medication records: thirty (30) days; (c) Laboratory and diagnostic records: thirty (30) days; (d) Financial and billing records: thirty (30) days; (e) Audit logs and security records: one (1) year; (f) Consent records: the duration of the Agreement plus thirty (30) days; (g) All other PHI: thirty (30) days from collection, unless otherwise agreed.
- 7.3 Secure Disposal: Upon expiry of applicable retention periods, AwaDoc shall securely dispose of PHI in a manner that renders it permanently unreadable and unrecoverable, in accordance with recognised secure disposal standards.
- 7.4 Cross-Border Data Transfers: AwaDoc shall not transfer PHI to any country outside the jurisdiction of origin without: (a) ensuring that the receiving country provides an adequate level of data protection under Applicable Law; (b) implementing appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms; and (c) obtaining the prior written consent of the Covered Entity.
8. REGULATORY COMPLIANCE
- 8.1 Nigeria Data Protection Act 2023 (NDPA): AwaDoc shall fully comply with the requirements of the NDPA 2023 in its processing of PHI, including obligations relating to: lawful basis for processing; data subject rights; data minimisation; storage limitation; and mandatory breach notification to the Nigeria Data Protection Commission (NDPC) within seventy-two (72) hours of awareness of a reportable breach.
- 8.2 HIPAA Compliance: To the extent that PHI is subject to HIPAA, AwaDoc shall comply with the applicable requirements of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, as applicable to a Business Associate. AwaDoc acknowledges that it is directly liable under HIPAA for impermissible uses and disclosures of PHI and for failures to safeguard ePHI in accordance with the Security Rule.
- 8.3 Other Applicable Laws: AwaDoc shall comply with all other applicable data protection, health information privacy, and cybersecurity laws in each jurisdiction in which it operates. AwaDoc shall promptly notify the Covered Entity of any changes in Applicable Law that materially affect AwaDoc’s obligations under this Agreement.
- 8.4 Regulatory Cooperation: AwaDoc shall cooperate fully with any audit, inquiry, or investigation by any relevant supervisory or regulatory authority, including the Nigeria Data Protection Commission, any state-level health regulatory body, or any equivalent authority in any other jurisdiction.
- 8.5 Data Protection Impact Assessments: Where required by Applicable Law, or where a proposed processing activity involving PHI is likely to result in a high risk to the rights and freedoms of Data Subjects, AwaDoc shall conduct and document a Data Protection Impact Assessment (DPIA) prior to commencing the relevant processing activity.
9. LIABILITY AND INDEMNIFICATION
- 9.1 AwaDoc Indemnification: AwaDoc shall indemnify, defend, and hold harmless the Covered Entity and its officers, directors, employees, and agents from any claims, losses, damages, liabilities, penalties, and expenses arising from: (a) Any breach by AwaDoc of its obligations under this Agreement; (b) Any impermissible use or disclosure of PHI by AwaDoc or its Subcontractors; (c) Any Security Incident or Breach arising from AwaDoc’s failure to maintain adequate safeguards.
- 9.2 Covered Entity Indemnification: The Covered Entity shall indemnify, defend, and hold harmless AwaDoc and its officers, directors, employees, and agents from any claims, losses, damages, liabilities, penalties, and expenses arising from: (a) Any breach by the Covered Entity of its obligations under this Agreement; (b) Any instruction given by the Covered Entity to AwaDoc that would cause AwaDoc to violate Applicable Law; (c) Any failure by the Covered Entity to obtain required patient consents prior to disclosing PHI to AwaDoc.
- 9.3 Limitation of Liability: To the maximum extent permitted by Applicable Law, neither party shall be liable to the other for any indirect, special, incidental, or consequential damages arising from a breach of this Agreement, except in cases of gross negligence, wilful misconduct, or breach of confidentiality obligations.
- 9.4 Insurance: Each Party shall maintain appropriate insurance coverage, including cyber liability and data breach insurance, in amounts sufficient to cover its obligations under this Agreement and any liabilities that may arise.
10. GENERAL PROVISIONS
- 10.1 Amendment: This Agreement may be amended only by a written instrument signed by authorised representatives of both parties. AwaDoc shall amend this Agreement as necessary to comply with changes in Applicable Law and shall notify the Covered Entity in writing at least thirty (30) days before any such amendment takes effect.
- 10.2 Interpretation: This Agreement shall be interpreted to give effect to the intent of the parties to comply with Applicable Law. In the event of any conflict between the provisions of this Agreement and the requirements of Applicable Law, the more protective provision shall prevail.
- 10.3 Entire Agreement: This Agreement, together with any associated Partner Services Agreement and Annexes, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior agreements.
- 10.4 Severability: If any provision of this Agreement is found to be invalid, illegal, or unenforceable, the remaining provisions shall continue in full force and effect.
- 10.5 Waiver: No waiver by either party of any breach of this Agreement shall constitute a waiver of any prior or subsequent breach.
- 10.6 Governing Law: This Agreement shall be governed by and construed in accordance with the laws of the Federal Republic of Nigeria, including the NDPA 2023. To the extent that any PHI is subject to HIPAA, the relevant provisions of United States federal law shall apply concurrently.
- 10.7 Notices: All notices under this Agreement shall be in writing and delivered by email (with read receipt or delivery confirmation) or by courier to the contact details set out in Schedule 1.
- 10.8 Assignment: Neither party may assign its rights or obligations under this Agreement without the prior written consent of the other party. Notwithstanding the foregoing, AwaDoc may assign this Agreement to a successor entity in connection with a merger or acquisition.
- 10.9 No Third-Party Beneficiaries: This Agreement is entered into solely for the benefit of the parties and their permitted successors. Nothing in this Agreement shall create any rights in any third party, except as required by Applicable Law.
- 10.10 Counterparts: This Agreement may be executed in one or more counterparts, each of which shall be deemed an original. Electronic signatures shall be deemed valid and binding.
11. EXECUTION
All partners have executed this Agreement; each Party confirms that it has read, understood, and agrees to be bound by all terms set out herein, that the obligations contained herein are legally binding and that the signatory is duly authorised to execute this Agreement on behalf of the respective Party.
Need a copy of this agreement for your records?
Download BAA (.docx)