Skip to content

Security & trust

Patient data, treated like patient data.

Hearing health records are special-category data under GDPR Article 9. That is the standard Clinear is engineered to — not the standard of a generic business app.

Clinear never uses patient data for commercial purposes and never contacts a clinic's patients. Clinical data is hosted in the EU (Dublin).

In practice

What protecting patient data actually involves

01

EU data residency

Patient data is hosted in the EU (Dublin, Ireland). It is not transferred outside the EU/EEA for storage or processing of clinical records.

02

Encryption everywhere

Data is encrypted in transit (TLS 1.2+) and at rest. Backups are encrypted with the same standard as live data.

03

Role-based access

Clinicians, reception, and management see what their role requires. Access is authenticated per user — no shared logins — and revocable the moment someone leaves.

04

Backups and recovery

Automated, encrypted backups with point-in-time recovery. Restore procedures are tested — a backup that has never been restored is a hope, not a plan.

05

A real DPA

Every clinic on Clinear is covered by a GDPR Article 28 data processing agreement naming roles, sub-processors, retention, and breach procedure. Available before you sign anything.

06

Breach procedure

A documented incident process: contain, assess, notify. Where a breach is notifiable, affected clinics are informed without undue delay so they can meet their own 72-hour obligations.

Roles & responsibilities

Controller and processor, named plainly

Your practice is the data controller: you decide why and how patient data is used. Clinear Limited is the data processor: we process patient data only on your documented instructions, under a GDPR Article 28 agreement.

Sub-processors are listed in the DPA with their role and location, and the list is kept current — you are notified of changes with the right to object. A copy of the current DPA and sub-processor list is available on request before you sign anything.

The marketing site itself follows the same philosophy: cookieless-first analytics, consent before any non-essential cookies, and forms that collect only what you type into them.

Security questions

What practices ask about data

Next step

Ask us the hard questions.

Bring your data protection officer, your IT person, or your scepticism. We would rather answer before you sign than after.