What we do for clinics
- EU-hosted database and storage by default.
- Row-level isolation so a clinic can only ever see its own data.
- Signed Data Processing Agreement available for every paying clinic.
- Sub-processor list maintained transparently in our Privacy Policy.
- Tooling for data subject access, rectification, and erasure requests.
- Breach notification within 72 hours where feasible.
What we expect from clinics
- Inform patients that an AI receptionist may answer first.
- Ask patients not to share clinical or sensitive data via chat.
- Keep the knowledge base accurate and free of patient identifiers.
- Use the dashboard's role and access controls.
Sub-processors
We use a short, vetted list of sub-processors — see the Privacy Policy for details. Any change is announced before it takes effect.
Get the DPA
The full Data Processing Agreement applies automatically to every paid account. Contact legal@clincue.com for a countersigned copy.