Data Processing Agreement

Last updated: 5 August 2026

When a clinic uses Clovaar to hold patient records, the clinic is the controller of those records and we are its processor. UK GDPR Article 28 requires that relationship to be governed by a written contract. This is that contract. It forms part of our Terms of Service and applies automatically to every clinic, so there is nothing separate to sign.

1.Parties and status

This agreement is between the clinic that holds a Clovaar subscription, referred to here as you or the Clinic, and Clovaar Ltd, registered in England and Wales under company number 17372298, referred to as we or us.

You are the controller of the personal data you record using Clovaar. We are your processor in respect of it. We are a separate and independent controller of the data described in our Privacy Policy as being about clinic staff and account holders, and this agreement does not apply to that.

Data Protection Law in this agreement means the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any legislation that amends or replaces them. Terms such as controller, processor, data subject, personal data, special category data, processing and personal data breach have the meanings given to them in that law.

Why this matters to you, not only to us

Article 28 places the obligation to have this contract on you, the controller. A clinic that passes patient records to a software supplier without a written processing agreement is in breach whether or not the supplier is. Publishing this and applying it automatically is how we make sure you are not.

2.Subject matter, duration, nature and purpose

Subject matterProviding the Clovaar platform to you: scheduling, patient records, clinical documentation, digital consent, stock control, communications with your patients, payments and reporting.
DurationFor as long as you hold a subscription, and then for the deletion period set out in section 10.
Nature of the processingCollection, recording, organisation, structuring, storage, retrieval, encryption, transmission to recipients you designate, backup, and erasure. All by automated means.
PurposeSolely to provide the platform to you and to perform our contract with you. We do not process your patient data for our own purposes, and we do not sell it, mine it, or use it to train models.

3.Categories of data subject and personal data

Data subjects: your patients, including prospective patients who enquire or book but do not attend; the people your patients name as emergency or next-of-kin contacts, where you record them; and the person completing a form on a patient's behalf where that patient lacks capacity or is a minor.

Personal data: name, date of birth, sex or gender where recorded, address, email address, telephone numbers, patient reference, appointment history, communication history and preferences, marketing consent status, payment and account balance records, and any free text you enter.

Special category data under Article 9, being data concerning health: medical history, allergies and their severity, current medications, treatment records including product, dose, batch and site, clinical consultation notes, signed consent forms and the answers given on them, clinical photographs, and details of any adverse event or complication.

Your Article 9 condition, not ours

Special category data can only be processed if a condition in Article 9 is met. As controller, identifying and documenting that condition is yours to do. For a clinic it will usually be Article 9(2)(h), the provision of health care by a professional under a duty of confidentiality, together with a Data Protection Act 2018 Schedule 1 condition. We rely on your instruction that a lawful condition exists.

4.Our obligations

We will:

  1. Process only on your documented instructions. Your instructions are this agreement, our Terms of Service, and your use of the platform's features. If we are required by law to process your data otherwise, we will tell you before we do unless the law forbids us from telling you.
  2. Tell you if we think an instruction is unlawful. If in our opinion something you ask us to do would breach Data Protection Law, we will say so rather than quietly comply.
  3. Keep it confidential. Everyone we authorise to access your data is bound by a written duty of confidence that survives the end of their engagement with us.
  4. Apply the security measures in section 7, and keep them under review as risks and technology change.
  5. Use sub-processors only on the terms in section 6.
  6. Help you respond to your patients. Section 8 sets out how.
  7. Help you meet your own obligations on security, breach notification, data protection impact assessments and prior consultation with the Information Commissioner, taking account of what we know and what you do not.
  8. Delete or return your data at the end of the contract, as set out in section 10.
  9. Give you the information you need to demonstrate compliance, and allow the audits described in section 9.
  10. Keep records of the processing we carry out on your behalf, as Article 30(2) requires.

5.Your obligations

As controller, you are responsible for:

  • Having a lawful basis, and an Article 9 condition, for everything you record and everything you ask us to send.
  • Giving your patients a privacy notice that explains what you do with their data, including that you use a software provider to hold it.
  • The accuracy and relevance of what you enter, and deciding how long to keep it.
  • Obtaining any consent the law requires before you use the platform to send marketing, and honouring an opt-out once it is given. The platform records opt-outs and will not send to a patient who has opted out, but the decision to run a campaign is yours.
  • Managing who in your clinic has an account, what role they hold, and removing access promptly when someone leaves.
  • Deciding your own retention period and applying it. We will not delete a patient record on our own initiative.

6.Sub-processors

You give us general authorisation to engage the sub-processors listed below. Each is engaged under a written contract imposing obligations equivalent to those in this agreement, and we remain fully liable to you for their performance.

Sub-processorData it may handleLocation
DigitalOceanAll platform data, including patient records, documents and imagesUnited Kingdom (London region)
AnthropicIdentifying details are removed inside the platform before anything is sent. For a consultation transcript the patient's name, date of birth, email address, telephone number, postcode and address are replaced with placeholders before it leaves our systems, and are re-inserted into the finished draft locally, so the AI provider never receives them. If that removal cannot be completed the request is abandoned and nothing is sent. Dashboard summaries send only already-calculated totals, never patient details. The remaining features read business information such as supplier documents, not patient records.United States
StripeBilling contact details and payment card data. Card numbers are handled by Stripe and never reach our systems.United States and European Union
ResendRecipient email address, and the content of the message being sentEuropean Union
The SMS WorksRecipient mobile number, and the content of the message being sentUnited Kingdom
NylasMessages in the connected mailbox, and the credentials authorising access to itEuropean Union
GoogleAccount email address and the access token authorising the connectionUnited States and European Union
FirecrawlThe public web address supplied by the clinic, and the public page content retrieved from itUnited States
CloudflareWebsite visitor connection data, including IP addressGlobal content delivery network

Notice of change. We will give you at least 30 days' notice by email before adding or replacing a sub-processor that handles patient data. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative. If we cannot, you may terminate your subscription without penalty and receive a refund of any fees paid for the period after termination.

Several of the sub-processors above are optional and are only engaged if you turn on the feature that uses them. If you never enable SMS, connect a mailbox, or use the AI features, no patient data reaches those suppliers.

7.Security measures

The technical and organisational measures we apply under Article 32 are:

Encryption. All traffic is encrypted in transit with TLS. Storage is encrypted at rest. In addition, clinical free text and directly identifying fields are encrypted at the application layer with keys held separately from the database, so that a copy of the database alone does not disclose them.

Tenant isolation. Every clinic's data is separated at the database layer using row-level security keyed to the clinic, not only by conditions in application code. A query that omitted a filter still cannot return another clinic's records.

Access control. Access within a clinic is governed by role. Two-factor authentication is required for password sign-in, and privileged actions such as record erasure are restricted to the clinic owner.

Accountability. Security-relevant and record-level actions are written to an audit log. Signed consent records and record-lock events are held in a form that cannot be altered or deleted after the event, so the history of a record can be reconstructed.

Availability and resilience. The platform runs on managed infrastructure in the United Kingdom with daily backups retained for 30 days, and restoration is tested.

Our own staff. Access to production data by our personnel is limited to those who need it to operate or support the service, is authenticated individually, and is logged. We do not access patient records for support purposes without a request from you, except where necessary to investigate a fault or a security incident.

We keep these measures under review and may change them, provided the level of protection is not reduced.

8.Helping you with patient requests and breaches

Requests from patients. The platform lets you deal with most requests yourself: you can export a patient's full record, correct it, restrict it, lock it, or erase it, without needing us. If a patient contacts us directly, we will not act on the request. We will tell them to contact you and let you know it happened, without undue delay.

A note on erasure. The right to erasure is not absolute, and a health record is one of the clearest cases where it may be refused, because keeping it can be necessary for the establishment or defence of legal claims and for the purposes of health care. The platform therefore supports locking a record out of everyday use while retaining what is needed, as well as full erasure. Which one is appropriate is your decision as controller, and the platform records the reasoning either way.

Personal data breaches. If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 24 hours of becoming aware of it. Our notification will describe what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will keep you updated as we learn more, and we will help you notify the Information Commissioner and affected patients where you have to. Report a suspected breach to us at [email protected].

The obligation to notify the Information Commissioner within 72 hours falls on you as controller. Our 24-hour commitment exists so that you have time to meet it.

9.Audit and information

We will make available to you the information reasonably necessary to demonstrate our compliance with this agreement. In most cases documentation, a completed security questionnaire or a third-party report will answer what you need, and we will provide those first.

Where that is genuinely not sufficient, you may audit us, or appoint an independent auditor who is not a competitor of ours and who is bound by confidentiality. Audits are on at least 30 days' written notice, during business hours, no more than once a year unless a breach or a regulator's direction makes another necessary, and conducted so as not to disrupt the service or the confidentiality of other clinics' data. Each party bears its own costs.

10.International transfers

Your patient records are stored in the United Kingdom. We will not transfer them outside the United Kingdom except through a sub-processor listed in section 6, and only where a lawful transfer mechanism is in place: an adequacy decision, the UK International Data Transfer Agreement, or the International Data Transfer Addendum to the European Commission's standard contractual clauses, supported by a transfer risk assessment.

The transfer most likely to matter to you is to our AI supplier in the United States. It happens only if you enable the AI features, and direct identifiers are removed from consultation transcripts before they are sent. If you would prefer that no data leaves the United Kingdom, leave the AI features switched off and none will.

Dictated audio is not part of that transfer. Recorded consultation audio is transcribed by software we run ourselves in the United Kingdom, in the same London region as the rest of the platform. There is no transcription sub-processor and the recording does not leave the country. Only the resulting transcript, with identifiers already removed, is sent to the AI supplier to be structured into a draft note.

11.What happens to your data when you leave

  1. You can export your data at any time while your subscription is active, and we recommend doing so before you close the account.
  2. For 30 days after your subscription ends, your data is retained and you can still request an export. This is deliberate: an account closed by mistake, or in a dispute, should be recoverable.
  3. After that 30 days, and in any event within 90 days of the subscription ending, we will delete your patient data from our live systems.
  4. Backups are overwritten on their own cycle and data is fully removed from them within 6 months of deletion from live systems. Until then it stays encrypted and is not accessible for any other purpose.
  5. We will confirm deletion in writing if you ask.
  6. If you instruct us in writing to delete earlier, we will, and you accept that it cannot then be recovered.

We may retain data for longer only where the law requires it, and only for as long as it requires. If that happens we will tell you what we are keeping and why.

12.Liability, precedence and general

Each party is liable for its own compliance with Data Protection Law. Nothing in this agreement relieves either of us of an obligation the law places on us directly, and nothing in it limits a data subject's rights or the Information Commissioner's powers.

The limitations and exclusions of liability in our Terms of Service apply to this agreement and to any claim arising from it, except where the law does not permit them to.

If anything in this agreement conflicts with our Terms of Service, this agreement prevails in respect of the processing of patient personal data.

We may update this agreement to reflect a change in the law, in our sub-processors, or in our security measures. We will give account holders at least 30 days' notice by email of any change that materially reduces your rights or our obligations, and your right to object to a new sub-processor under section 6 is unaffected.

This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction over it.

Questions about this agreement, or a request for a signed copy on your own paper, go to [email protected].