Terms of Use

Version 2026-09-01, in effect from 2026-09-01. Issued by Samplify FZCO.

The interface is translated into six languages; these terms are published in two. Where the English and the Russian text differ, the English version is the one that applies.

These are the terms presented in the product, referred to by the summary at mednais.com/terms. They apply to your use of MedNAIS. If your organisation has signed a separate written agreement with us, that agreement prevails wherever the two differ.


1. Who these terms are between

MedNAIS is operated by Samplify FZCO, a company registered in Dubai, United Arab Emirates, at DDP, Building A2, office 101. In this document “we” and “us” mean Samplify FZCO; “MedNAIS” is the name of the product. “You” means both the individual using the product and the organisation on whose behalf they use it.

You accept these terms when you first sign in, and again whenever we publish a version that changes what they say. The version you accepted, the date and time you accepted it, and the language version you were shown are recorded against your account, and you can ask us for that record at any time.

If you are signing in on behalf of a hospital, laboratory or clinic, you confirm that you are authorised to accept these terms for that organisation.

2. What the service is

MedNAIS is a tool for writing, publishing, running and measuring standard operating procedures. It lets you draft a procedure — with the help of a language model, from documents you supply — have a qualified person review and publish it, run it step by step at the point of work, and see afterwards what was recorded.

It also maintains an index of regulatory documents and standards. That index is bibliographic: designation, title, publisher, edition and where the document can be obtained. We do not supply, license or resell standards. Designations and titles are used to identify the documents they name; we claim no affiliation with, and no endorsement by, any standards body. Availability and price information is indicative and the publisher's own page governs.

What MedNAIS is not. It is not a medical device and must not be used as one: it does not diagnose, treat, monitor or make any decision about an individual patient. It is not a quality management system of record, not a certification service, and not a substitute for compliance review. Section 6 says more about this, and it is the most important section in this document.

3. Accounts and organisations

You sign in with a Google account, or with a one-time code we send to your e-mail address. Both reach the same account when the address is the same. You may additionally set a password, in which case we hold it in the customary irreversible form and never in plain text; if you set none, we hold no password for you at all. We cannot recover access to a Google account or a mailbox you have lost. Keep your credentials to yourself: anything done from your account is treated as done by you, and a one-time code is a credential for as long as it lasts.

Work in MedNAIS belongs to an organisation, not to a person. Everyone in an organisation can see that organisation's procedures, documents and execution records according to their role. Owners and administrators decide who is in the organisation, and they can remove a member's access, transfer work and delete the organisation and everything in it.

Some actions are restricted to owners and administrators specifically because they are statements the organisation makes rather than statements one employee makes — confirming that the organisation holds a licence for a third party's standard is the main one.

4. Your documents and the rights you confirm

You keep every right you have in what you upload and in the procedures you write. We do not acquire ownership of them. We use them to run the service for you and for nothing else: your files are held in your organisation's own tenant, are not shown to any other customer, are not added to the shared index, and are not used to train or fine-tune any model, ours or anyone else's.

What you confirm when you upload a file. That your organisation holds rights sufficient to let us store it, process it and generate documents from it for that organisation's internal use; that the file was not obtained in breach of a licence or by circumventing an access control; and that you have actually checked whether the licence permits storage across the organisation, because many standards are sold as single-user or single-site licences that do not.

The product asks you to say, in your own words, on what basis your organisation holds each third party's document, and records that with your name and the date. Nobody checks it at the time. It is what your organisation can show later if it is asked.

We delete uploaded files and the text extracted from them on request, and when your organisation stops using the service. Section 11 says how that works.

5. Processing of uploaded documents by third parties

To generate a procedure from a document you upload, Samplify FZCO transmits the text of that document to third-party providers of language and embedding models, acting as our sub-processors. Today these are Anthropic PBC (generation of steps and citations) and OpenAI OpCo, LLC (computation of embeddings for search). We will give you notice before adding or replacing a sub-processor that receives document text. The complete list of our sub-processors is in section 7.

What is transmitted is the extracted text of the document, or the passages of it selected as relevant to your request, together with the topic you entered. The files themselves are not transmitted; images and formatting are not transmitted. Both providers are engaged under terms that prohibit the use of content submitted through their programming interfaces to train their models.

This concerns you if you upload a standard you have licensed. Standards are frequently sold under single-user or single-site licences that prohibit disclosure of the document to anyone outside the licensed entity. Transmission to a sub-processor may fall within such a prohibition. Before uploading a licensed document, check its terms. If they do not permit it, do not upload it: our index will still tell you that the document exists, what it is called and where to obtain it, and you can write your procedure referring to it without giving us its text.

You confirm, each time you upload a document, that you have the rights necessary to permit this transmission. We rely on that confirmation and do not independently verify the licence terms of documents you upload.

6. Clinical responsibility

A generated procedure is a draft. MedNAIS writes procedure steps using a language model. What comes out is a starting point for a person to work from. It is not medical advice, not a clinical protocol, not validated against any standard, guideline or regulation, and not fit to be followed as written.

Language models produce fluent text that can be wrong, and being fluent is what makes it dangerous. A generated draft can state an incorrect quantity, temperature or interval; omit a control, a check or a safety step that the source document requires; attribute a requirement to a standard that does not contain it; or cite a document that does not say what the citation claims. We reduce this where we can and we cannot eliminate it.

No generated procedure may be used in patient care until a person qualified in the relevant discipline has read it in full and approved it. The product will not publish a version by itself; a named person has to publish it. That requirement is not an administrative formality, and approving a draft without reading it defeats the only safeguard there is.

Responsibility for the clinical correctness, the safety and the regulatory compliance of every procedure you publish, run or rely on rests with your organisation and with the professionals who approve it. We do not practise medicine, do not supervise your procedures, do not review what you publish, and are not a party to any clinical decision taken in your organisation.

Citation of a standard in a draft is not certification against that standard. Execution records, timings and KPI figures describe what was entered into the product; they are a record of use, not an audit, and not evidence of compliance on their own.

7. Personal data and sub-processors

For the personal data your organisation puts into MedNAIS — the accounts of your staff, and whatever appears in the procedures and execution records they create — your organisation decides what is collected and why, and we process it on your instructions in order to provide the service. We do not sell it, and we do not use it for advertising.

MedNAIS is not designed to hold patient data and should not be used to hold it. Procedures describe how work is done; they do not need a patient's name, and an execution record is a record of a procedure being run, not of a patient being treated.

These are everyone who processes customer data on our behalf. The first two are the ones that receive the text of documents you upload; the other two are the infrastructure the product runs on.

Sub-processorAnthropic PBCWhat it receivesThe extracted text of uploaded documents, or the passages selected as relevant, and the topic you enteredWhereUnited States
Sub-processorOpenAI OpCo, LLCWhat it receivesThe same text, for computation of search embeddingsWhereUnited States
Sub-processorSupabase, Inc.What it receivesAll customer data at rest: accounts, procedures, uploaded files, extracted text, execution recordsWhereManaged PostgreSQL in the European Union (Stockholm, eu-north-1)
Sub-processorVercel Inc.What it receivesRequest handling and application logs. Document text passes through the application; it is not stored thereWhereUnited States and Vercel's global edge network

We will give you notice before adding or replacing any of them. If your organisation requires a separate data processing agreement, or needs the transfers above documented for its own compliance file, write to us at the address in section 13 and we will deal with it individually.

The privacy policy at mednais.com/privacy describes the personal data we hold about visitors and users generally. Where it and this section differ about the product, this section is the more specific and more current of the two.

8. Acceptable use

Do not:

  • upload a document you do not have the rights to upload, or obtain one by circumventing an access control or a paywall;
  • use MedNAIS to reproduce or redistribute a standard you licensed, to anyone outside the licensed entity;
  • try to reach another organisation's data, probe the service for vulnerabilities without asking us first, or work around a limit or a permission;
  • present a generated draft as a reviewed, approved or certified document when it is not;
  • use the service in a way that breaks the law where you are, or your own institution's rules.

If you find a security problem, tell us at the address in section 13 before telling anyone else. We will not pursue anyone who reports one in good faith and gives us a reasonable chance to fix it.

9. Availability, and changes

We do not promise the service will be available at any particular time or to any particular standard, and we have not agreed a service level with you unless a separate written agreement says otherwise. We will not deliberately take it away without warning.

The product changes. Features are added, altered and occasionally removed. We will tell you before removing something you rely on, where we can see that you rely on it.

We may change these terms. When a change alters what they say, we publish a new version and ask you to accept it the next time you sign in; you will see what changed and you can read the new text before accepting. Corrections that do not change the meaning — a broken link, a typographical error — are made without asking again. If you do not accept a new version, you can stop using the service and ask us for your data under section 11.

10. Limitation of liability

MedNAIS is provided as it is. We do not warrant that a generated procedure is accurate, complete, safe or compliant, and section 6 explains why you must not rely on one as though we did.

We are not liable for loss of profit, loss of business, loss of reputation, or for indirect or consequential loss of any kind. We are not liable for a clinical outcome, a regulatory finding, or a licensing dispute arising from a procedure your organisation published, approved or ran, or from a document your organisation uploaded.

Our total liability to you for everything arising out of your use of the service is limited to the amount your organisation paid us for the service in the twelve months before the claim arose.

Nothing here limits liability that cannot lawfully be limited — including liability for death or personal injury caused by our negligence, and for fraud.

11. Ending it, and getting your data back

You can stop using MedNAIS whenever you like. An owner can delete an organisation from its settings, which removes that organisation's procedures, documents, uploaded files and execution records.

We may suspend or close an account that is being used in breach of section 8, or where we are required to. Except where the breach is serious or we have no choice, we will tell you first and give you a chance to put it right.

Ask us and we will export your organisation's procedures and records in a machine-readable form, and delete what we hold. Backups are cycled out rather than edited, so a copy can persist in backup for a short period after deletion.

12. Governing law

These terms are governed by the laws of the United Arab Emirates as applied in the Emirate of Dubai, and disputes arising out of them are for the courts of Dubai. If your organisation has a separate written agreement with us, its governing law and dispute resolution provisions apply instead of this section.

Nothing in this section takes away a protection that the law of the country you are in gives you and does not allow to be contracted out of.

13. Contact

Samplify FZCO, DDP, Building A2, office 101, Dubai, United Arab Emirates. Write to mednais@samplify.org — for questions about these terms, to request a data processing agreement, to ask for an export or a deletion, or to report a security problem.

Terms of Use · MedNais