Security & trust
Patient data, treated like patient data.
Hearing health records are special-category data under GDPR Article 9. That is the standard Clinear is engineered to — not the standard of a generic business app.
Clinear never uses patient data for commercial purposes and never contacts a clinic's patients. Clinical data is hosted in the EU (Dublin).
In practice
What protecting patient data actually involves
EU data residency
Patient data is hosted in the EU (Dublin, Ireland). It is not transferred outside the EU/EEA for storage or processing of clinical records.
Encryption everywhere
Data is encrypted in transit (TLS 1.2+) and at rest. Backups are encrypted with the same standard as live data.
Role-based access
Clinicians, reception, and management see what their role requires. Access is authenticated per user — no shared logins — and revocable the moment someone leaves.
Backups and recovery
Automated, encrypted backups with point-in-time recovery. Restore procedures are tested — a backup that has never been restored is a hope, not a plan.
A real DPA
Every clinic on Clinear is covered by a GDPR Article 28 data processing agreement naming roles, sub-processors, retention, and breach procedure. Available before you sign anything.
Breach procedure
A documented incident process: contain, assess, notify. Where a breach is notifiable, affected clinics are informed without undue delay so they can meet their own 72-hour obligations.
Roles & responsibilities
Controller and processor, named plainly
Your practice is the data controller: you decide why and how patient data is used. Clinear Limited is the data processor: we process patient data only on your documented instructions, under a GDPR Article 28 agreement.
Sub-processors are listed in the DPA with their role and location, and the list is kept current — you are notified of changes with the right to object. A copy of the current DPA and sub-processor list is available on request before you sign anything.
The marketing site itself follows the same philosophy: cookieless-first analytics, consent before any non-essential cookies, and forms that collect only what you type into them.
Security questions
What practices ask about data
Next step
Ask us the hard questions.
Bring your data protection officer, your IT person, or your scepticism. We would rather answer before you sign than after.
