Skip to content

Legal

Data processing agreement

Last updated: 10 June 2026

Every clinic using Clinear is covered by a GDPR Article 28 data processing agreement. Hearing health records are special-category data under GDPR Article 9, and the DPA is written to that standard — not adapted from a generic business-software template.

What the DPA covers

  • Roles: your practice is the data controller; Clinear Limited is the data processor, acting only on your documented instructions
  • Data location: patient data is hosted in the EU (Dublin) and is not transferred outside the EU/EEA for storage or processing of clinical records
  • Sub-processors: named, with role and location; you are notified of changes and have the right to object
  • Security measures: encryption in transit and at rest, role-based access, and tested backups
  • Breach procedure: notification without undue delay so your practice can meet its own 72-hour obligations
  • Retention and exit: full structured exports at no charge, and deletion from live systems and backups on a defined schedule when you leave

Request a copy

The current DPA and sub-processor list are available before you commit to anything — most practices request them during the evaluation stage. Email hello@clinear.net with the subject line “DPA request” and we will send both within one working day.

Questions about our security posture more broadly are answered on the Security & trust page.