Listing Review & Compliance Checklist

Every listing is reviewed by Xolize before publication. Dentolize clinics handle patient medical and financial data under Saudi PDPL and comparable regimes — the bar is deliberately high.

What you submit

Compliance checklist (all required)

  1. DPA countersigned. You act as a data processor for the installing clinic; the platform DPA governs use, sub-processing, and breach notification.
  2. Data minimization. You request only the scopes your features need; unused scopes are grounds for rejection.
  3. Retention statement. Document what you store, where (region), and for how long.
  4. Deletion handling. Demonstrated handling of patient.deleted and installation.uninstalled (purge within 30 days).
  5. Secret handling attestation. API tokens and signing secrets live in a secret manager; never in client-side code, logs, or repositories.
  6. Transport security. Webhook endpoint on TLS with a valid certificate; no logging of raw request bodies at your edge.
  7. Arabic + English. Listing copy and settings labels in both languages; RTL-safe where you render anything yourself.
  8. Support channel. A monitored support email with a stated response SLA.

Ongoing obligations