Clincue

Data Processing Agreement (DPA)

This DPA forms part of the Terms of Service between your clinic (Controller) and Clincue (Processor). It sets out how Clincue processes personal data on the clinic's behalf, in compliance with UK GDPR and EU GDPR Article 28.

Last updated: 14 July 2026

1. Definitions

Terms not defined here have the meanings in UK GDPR / EU GDPR (Regulation (EU) 2016/679 as it forms part of UK domestic law, and Regulation (EU) 2016/679 as it applies in the EU). "Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Sub-processor" follow those definitions.

2. Roles and scope

Where a clinic uses Clincue to interact with its patients, the clinic is the Controller and Clincue is the Processor. Clincue processes Personal Data solely on documented instructions from the Controller, which for this service consist of these Terms, the settings the clinic configures in the dashboard, and any additional written instructions the clinic sends to privacy@clincue.com.

3. Subject-matter and duration

  • Subject-matter: operating the AI receptionist platform, including branded chat, WhatsApp, and voice channels, and delivering booking, FAQ, and triage-adjacent administrative responses.
  • Duration: for the term of the subscription, plus 30 days of grace after termination for data export, subject to legal retention obligations.
  • Nature and purpose: automated conversational processing, storage, and analytics to help the clinic answer patient questions and manage bookings.

4. Categories of Data Subjects and Personal Data

  • Data Subjects: the clinic's patients, prospective patients, and any other individuals who initiate a conversation via a Patient Channel.
  • Personal Data: identifiers volunteered by the patient (name, contact number, email if provided), conversation transcripts, voice recordings and transcripts when voice is enabled, booking metadata, channel and session identifiers, and any additional content the patient chooses to share.
  • Special-category data: Clincue asks patients not to share health data. Where a patient volunteers it, we treat it under Article 9 UK GDPR / EU GDPR safeguards and route it only to clinic staff authorised by the Controller.

5. Sub-processors

The Controller authorises Clincue to engage the following Sub-processors, subject to the conditions in Section 6:

Sub-processorRoleLocation
Lovable Cloud (managed Supabase)Managed Postgres database, object storage, auth, edge functions.EU (Frankfurt) region
NVIDIA NIMLarge language model inference for AI receptionist responses.United States (SCCs)
Paddle.comMerchant of Record: payments, tax, invoicing, subscription lifecycle.United Kingdom + EU
Cloudflare WorkersEdge runtime hosting the Clincue application and API routes.Global edge (EU-preferred routing)
Twilio (BYO — clinic-configured)SMS and WhatsApp Business messaging via the clinic's own account.Configured by clinic
Mailgun (via Lovable Emails)Transactional and authentication emails.EU region

6. Adding or changing Sub-processors

Clincue will give the Controller at least 30 days' prior notice of any new or replacement Sub-processor via in-product notice or by email to the account owner. The Controller may object on reasonable data protection grounds within 14 days. If the parties cannot agree on a remedy, the Controller may terminate the affected part of the service without penalty.

7. Security measures

Clincue implements appropriate technical and organisational measures including, at minimum:

  • Encryption in transit (TLS 1.2+) for all Personal Data.
  • Encryption at rest for the primary database and object storage.
  • Row-level security in the database so each clinic can only access its own data.
  • MFA support for staff accounts; least-privilege access for Clincue engineers.
  • Automated backups with a 7-day point-in-time recovery window.
  • Structured audit logs and observability for security-relevant events.
  • Formal incident response procedures, quarterly review cycles, and dependency-vulnerability scanning.

8. International data transfers

Personal Data is primarily hosted in the EU. Where a Sub-processor operates outside the UK/EEA, Clincue relies on the UK IDTA and/or EU Standard Contractual Clauses (2021/914) with any required supplementary measures. Copies of the applicable transfer mechanisms are available on written request.

9. Data subject requests

Taking into account the nature of the processing, Clincue will assist the Controller with appropriate technical and organisational measures to respond to Data Subject requests exercising rights under UK GDPR / EU GDPR Chapter III (access, rectification, erasure, restriction, portability, objection). Where a Data Subject contacts Clincue directly, we will forward the request to the Controller without undue delay.

10. Personal Data breach notification

Clincue will notify the Controller without undue delay, and in any case within 48 hours of becoming aware, of any Personal Data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects concerned, the likely consequences, and the measures taken or proposed. Clincue will provide reasonable cooperation to enable the Controller to meet its own notification obligations under Articles 33 and 34 UK GDPR / EU GDPR.

11. Deletion and return of data

On termination of the subscription, Clincue will (at the Controller's option) return or delete all Personal Data within 30 days, except where retention is required by law. Backups age out on their normal rolling schedule (7 days point-in-time; 30 days snapshot) and are purged accordingly.

12. Audits

Clincue will make available to the Controller the information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits (including inspections) conducted by the Controller or a mutually agreed auditor, no more than once every 12 months except after a Personal Data breach. Audits will be conducted during regular business hours with reasonable notice, at the Controller's cost, and under confidentiality obligations. Where appropriate, up-to-date third-party attestations or reports satisfy this obligation.

13. Confidentiality of personnel

Clincue ensures that personnel authorised to process Personal Data have committed themselves to confidentiality and have received appropriate training on data protection.

14. Order of precedence

In the event of conflict, the order of precedence is: (i) applicable law, (ii) this DPA, (iii) the Terms of Service, (iv) any other documents referenced.

15. Contact

DPA queries — privacy@clincue.com, subject line "DPA".