Last updated August 8, 2026
This Data Processing Agreement (DPA) sets out how ClinyPal processes personal and health data on behalf of the clinics ("Controllers") using the platform, consistent with applicable data protection law.
The clinic is the data controller for the patient and business information it enters into ClinyPal. ClinyPal acts as the data processor, handling that data only as instructed by the clinic and only for the purpose of providing the service.
Processing covers the categories of data a clinic enters through normal use (patient records, appointments, billing, and communications) for the duration of the subscription.
Data is encrypted in transit and at rest, access is controlled through role-based permissions, and every access or change to patient data is logged in an audit trail. See our Security page for detail.
We use a limited set of infrastructure and communications sub-processors (hosting, email/SMS delivery, payment processing) required to operate the service, each bound by their own data protection obligations.
If ClinyPal receives a request directly from a patient regarding their data, we'll forward it to the relevant clinic, since the clinic controls that record.
In the event of a data breach affecting a clinic's data, we will notify the affected clinic without undue delay, consistent with our obligations under applicable law.