Under the Saudi Personal Data Protection Law, the clinic is the controller, so the responsibility for what happens to patient data does not transfer to your vendor when you sign. It stays with you.
This is a buyer's checklist, not legal advice, because your counsel signs off on the contract. These are the 9 questions that surface a weak vendor on the first call, and they are worth asking of any tool that will hold a patient's name and phone number.
Are you a controller or a processor?
The correct answer is processor, and they should say it without hesitating. A vendor who describes themselves as a controller of your patients' data is telling you they intend to make their own decisions about it.
Will you sign a processing agreement before anything moves?
What you need is not a general terms of service, but a document that names what they handle, what they never handle, and what happens to the data when the engagement ends. If it does not exist before the first message is processed, it does not exist.
Where does the data physically sit?
Ask for the country, not the brand of the cloud, and then ask whether any part of the chain, including any model or subprocessor, sits somewhere else. Cross-border transfer is where most answers get vague.
Exactly which fields do you hold?
Make them list them, because the right answer for a booking service is short: a name, a phone number, the treatment asked about, the appointment, and a consent record. Anything longer than that needs a reason.
Do you touch clinical records?
For an enquiry and booking service the answer should be no, and the no should be in the contract. Booking an appointment does not require a medical history, so a vendor who wants access to your patient file system should explain why.
Does anything automated give medical advice?
This is the question to ask any vendor selling an AI assistant, because anything clinical or urgent should route to your own team. The escalation list should be one you wrote.
What happens in the first 72 hours of a breach?
Ask to see the procedure, written down and with named responsibilities, covering how they tell you and how the regulator gets told inside the legal window. A vendor who has not written this down has not thought about it.
Can I export everything and leave?
Your patient data is yours, so ask what the export contains, what format it is in, how long it takes, and what they delete afterwards. A vendor whose export is difficult has built a lock-in, not a service.
Do you use our data to train anything, or sell it?
Ask it directly and get the answer in writing, not on a policy page that can change next quarter.
One more, for whoever you already use
Run this list past the vendors you have already signed with, because most clinics discover the awkward answers are in the tools they have been using for years, not the one they are being pitched.