Data Processing Agreement

Last updated August 8, 2026

This Data Processing Agreement (DPA) sets out how ClinyPal processes personal and health data on behalf of the clinics ("Controllers") using the platform, consistent with applicable data protection law.

Roles

The clinic is the data controller for the patient and business information it enters into ClinyPal. ClinyPal acts as the data processor, handling that data only as instructed by the clinic and only for the purpose of providing the service.

Scope of processing

Processing covers the categories of data a clinic enters through normal use (patient records, appointments, billing, and communications) for the duration of the subscription.

Security measures

Data is encrypted in transit and at rest, access is controlled through role-based permissions, and every access or change to patient data is logged in an audit trail. See our Security page for detail.

Sub-processors

We use a limited set of infrastructure and communications sub-processors (hosting, email/SMS delivery, payment processing) required to operate the service, each bound by their own data protection obligations.

Data subject requests

If ClinyPal receives a request directly from a patient regarding their data, we'll forward it to the relevant clinic, since the clinic controls that record.

Breach notification

In the event of a data breach affecting a clinic's data, we will notify the affected clinic without undue delay, consistent with our obligations under applicable law.

Questions about this policy?

Reach out and we'll get back to you directly.

Solutions Features Security Pricing App Integrations

Popular features

Scheduling Telehealth Clinical AI DICOM viewer Billing
Start free trial Sign in