Data Processing Agreement
Last updated 3 August 2026
This page is for hospitals, not individual pet parents or staff members. When a hospital uses MediClear, MediClear processes that hospital's client and patient records on its behalf. This Data Processing Agreement (DPA) is the contract that governs that processing — it sits underneath the Terms of Service, the same way it would as a signed addendum in a traditional SaaS contract.
1. Roles
For the personal data a hospital's staff enter into MediClear about their clients (pet parents) and patients (animals) — names, contact details, clinical records, billing, insurance, and uploaded files — the hospital is the Controller (GDPR/UK GDPR) or Data Fiduciary (India's DPDP Act), and MediClear is the Processor. This DPA governs that relationship. It does not cover a pet parent's own account data (their login, their self-entered contact preferences) — for that, MediClear is the controller/fiduciary directly, as described in the Privacy Policy.
2. Subject matter, duration, nature and purpose
Subject matter: hosting and processing a hospital's client and patient records so its staff can run appointments, discharge summaries, billing, and insurance tracking, and so pet parents can view their own pet's records through the pet parent portal. Duration: for as long as the hospital has an active MediClear account, plus the retention period described in Section 9 (Return or deletion of data) after it ends. Nature and purpose: the processing activities and purposes are exactly those listed in the Privacy Policy's “How we use this information” and “How AI is used” sections — this DPA incorporates them by reference rather than repeating them.
3. Categories of data subjects and personal data
Data subjects: the hospital's clients (pet parents) and staff. (Patients — the animals — are not personal data subjects themselves, but records about them are frequently identifying of their owner.) Categories of personal data: the account, clinical, billing, insurance, and uploaded-file categories listed in the Privacy Policy's “Information we collect” section. No special category data (as GDPR Article 9 defines it) is deliberately collected; MediClear asks hospitals not to enter a client's own health, biometric, or similarly sensitive information into a free-text field where it isn't necessary for the pet's care.
4. MediClear's obligations as processor
MediClear agrees to:
- Process personal data only on the hospital's documented instructions — namely, to provide the MediClear service as configured and used by the hospital's own staff — and tell the hospital if an instruction appears to violate applicable data protection law.
- Ensure anyone processing the data (MediClear's own personnel) is bound by confidentiality.
- Implement the technical and organizational security measures described in the Privacy Policy's “How we protect your information” section: encrypted transport, per-hospital tenant isolation enforced in application code, magic-byte file validation, short-lived signed URLs for file access, hashed passwords, rate limiting, and PHI-free audit logging.
- Not engage a new sub-processor without the authorization and notice process in Section 5.
- Assist the hospital, to the extent reasonably possible, in responding to a data subject/data principal rights request (see the Privacy Policy's “Your rights, by region” section) and in meeting its own breach-notification and impact-assessment obligations.
- Delete or return personal data at the end of the relationship, per Section 9.
- Make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits per Section 10.
5. Sub-processors and change notice
MediClear uses three sub-processors today, each named and described in the Privacy Policy's “Who we share information with” section: Supabase(database and file storage), Anthropic (AI processing), and Vercel (hosting). The hospital authorizes MediClear's use of these three by entering into this DPA.
Before adding a new sub-processor, or replacing one of the three above, MediClear commits to giving the hospital's registered administrator at least 15 days' notice by email, and updating the current sub-processor list wherever it is published. The hospital may object on reasonable data-protection grounds within that window; if the concern can't be resolved, the hospital may terminate the affected part of the service without penalty.
Honestly stated gap: that 15-day email notice is a contractual commitment MediClear is making in this document, not yet an automated pipeline — there is no code today that emails hospital administrators when the sub-processor list changes. Until that's built, MediClear will notify hospitals by hand and update this page's sub-processor list on the same day the change takes effect.
6. International data transfers
Where processing crosses a border in a way that requires a transfer mechanism — for example, out of the EU/UK to a country without an adequacy decision — MediClear relies on Standard Contractual Clauses (or the UK's International Data Transfer Addendum) with the relevant sub-processor, as described in the Privacy Policy. MediClear does not transfer personal data out of India to any country restricted under the DPDP Act.
7. Personal data breach notification
If MediClear becomes aware of a personal data breach affecting a hospital's data, it will notify that hospital's registered administrator without undue delay, and in any case within 72 hours of becoming aware, with whatever detail is known at that time — consistent with the timeline the UK and EU GDPR expect of a processor notifying its controller, and “as soon as possible,” per the DPDP Act, where India applies. The notice will describe, to the extent known: the nature of the breach, the categories and approximate number of records affected, likely consequences, and the steps MediClear is taking or proposes to take. MediClear will update the hospital as more information becomes available rather than waiting for a complete picture.
8. Assistance with rights requests
If a pet parent or staff member contacts MediClear directly with a rights request that concerns a specific hospital's records (see the Privacy Policy's “Your rights, by region” section), MediClear will forward it to that hospital's administrator promptly, since the hospital — as controller/ fiduciary — is generally the right party to decide how to respond. MediClear will provide the hospital with the technical means to fulfil a valid request (for example, retrieving or deleting a specific record) where the product doesn't already offer it as self-service.
9. Return or deletion of data at the end of the relationship
When a hospital's MediClear account ends, the hospital may request an export of its client and patient records, deletion, or both. MediClear will act on that request within a reasonable period, not to exceed 30 days, except where continued retention of a specific record is required by law (for example, invoice retention under applicable tax law) — in which case that record is retained only for the legally required period and is not otherwise used.
10. Audit rights
On reasonable notice, and no more than once per year absent a specific incident, a hospital may request information reasonably necessary to verify MediClear's compliance with this DPA — for example, a summary of the security measures in place, or evidence of the sub-processor agreements referenced in Section 5. MediClear may satisfy this through documentation rather than an on-site audit, where doing so reasonably demonstrates compliance.
11. Relationship to the Terms of Service
This DPA is incorporated into, and forms part of, the Terms of Service for any hospital account. Where this DPA and the Terms of Service conflict on a matter of data processing specifically, this DPA governs; on all other matters, the Terms of Service govern.
12. Contact
Questions about this DPA, or to request a countersigned copy for your hospital's own records: privacy@mediclear.example.
Questions about this document? See the contact details in the section above, or read the Terms of Service and Privacy Policy together — they are meant to be read as a pair.