Legal
Data processing agreement
Last updated: 10 June 2026
Every clinic using Clinear is covered by a GDPR Article 28 data processing agreement. Hearing health records are special-category data under GDPR Article 9, and the DPA is written to that standard — not adapted from a generic business-software template.
What the DPA covers
- Roles: your practice is the data controller; Clinear Limited is the data processor, acting only on your documented instructions
- Data location: patient data is hosted in the EU (Dublin) and is not transferred outside the EU/EEA for storage or processing of clinical records
- Sub-processors: named, with role and location; you are notified of changes and have the right to object
- Security measures: encryption in transit and at rest, role-based access, and tested backups
- Breach procedure: notification without undue delay so your practice can meet its own 72-hour obligations
- Retention and exit: full structured exports at no charge, and deletion from live systems and backups on a defined schedule when you leave
Request a copy
The current DPA and sub-processor list are available before you commit to anything — most practices request them during the evaluation stage. Email hello@clinear.net with the subject line “DPA request” and we will send both within one working day.
Questions about our security posture more broadly are answered on the Security & trust page.
