Security & data
Is Clincue GDPR compliant?
Clincue is designed for GDPR-aligned clinic operations with contractual and technical safeguards.
Clincue is built around GDPR-aligned processing, encryption in transit and at rest, clinic-scoped access, and a Data Processing Agreement.
Access separation
Clinic data is protected by database policies that resolve the signed-in user through the real clinic membership chain. Client-supplied clinic identifiers are not accepted as proof of access.
Processing terms
The DPA explains roles, sub-processors, security measures and deletion commitments. Clinics remain responsible for their patient-facing notices and lawful basis.
Operational controls
Use named staff accounts, review access regularly, avoid putting unnecessary health information into configuration fields and follow your organisation's incident procedures.