This Data Processing Agreement ("DPA") forms part of the Terms of Use between Clara ("Processor", "we", "us") and you ("Controller", "you") and governs the processing of personal data in connection with your use of Clara's services. This DPA is designed to meet the requirements of Article 28 of the General Data Protection Regulation (GDPR).
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person, including patient data, session recordings, transcripts, and clinical notes processed through Clara.
- Processing: Any operation performed on Personal Data, including collection, recording, storage, retrieval, use, transmission, erasure, or destruction.
- Controller: You, the licensed healthcare professional who determines the purposes and means of processing Personal Data using Clara.
- Processor: Clara, which processes Personal Data on behalf of the Controller.
- Sub-processor: Any third party engaged by Clara to process Personal Data on behalf of the Controller.
- Data Subject: The individual whose Personal Data is processed, primarily your patients.
- Data Breach: A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
2. Scope and Roles
You act as the Controller of patient data and are responsible for ensuring lawful processing, obtaining patient consent, and fulfilling data subject rights. Clara acts as the Processor and will only process Personal Data according to your documented instructions and as necessary to provide the Services. Clara does not determine the purposes of processing patient data and does not use it for any purpose other than delivering the Services.
3. Subject Matter of Processing
This DPA governs Clara's processing of Personal Data in connection with providing therapy session recording, transcription, and clinical documentation services. This DPA also covers digital consent collection, validation, PDF generation, private evidence storage, status tracking, and retrieval on the Controller's instructions.
4. Types of Personal Data
Clara processes the following categories of Personal Data on your behalf:
- Patient identifying information (names, contact details) as entered by you
- Session audio recordings
- Automated transcripts of therapy sessions
- AI-generated clinical notes and summaries
- Session metadata (dates, times, duration)
- Clinical information discussed during sessions
- Professional account identifiers needed to authenticate requests, apply access controls, and route processing instructions
- Patient and guardian identity and contact data, consent selections, notes, typed signatures, signature dates, status and timestamps, and generated consent documents
5. Categories of Data Subjects
- Your patients whose therapy sessions are recorded
- Patients and guardians or other signatories completing consent forms
- You, as the healthcare professional using Clara
6. Obligations of the Processor (Clara)
Clara commits to the following obligations:
- Process Personal Data only on your documented instructions, unless required by EU or Member State law
- Ensure that persons authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures as described in Section 10
- Engage Sub-processors only with your prior authorization and under written contracts imposing equivalent data protection obligations
- Assist you in responding to data subject requests to exercise their rights under GDPR
- Assist you in ensuring compliance with GDPR obligations regarding security, breach notification, and data protection impact assessments
- Delete or return all Personal Data upon termination of Services, at your choice, unless EU or Member State law requires storage
- Make available all information necessary to demonstrate compliance and allow for audits
- Immediately inform you if we believe an instruction infringes GDPR or other data protection laws
7. Obligations of the Controller (You)
As the Controller, you are responsible for:
- Ensuring you have a valid legal basis for processing patient data, including obtaining informed consent for recording sessions
- Providing patients with appropriate privacy notices explaining how their data will be processed
- Ensuring the accuracy and relevance of Personal Data provided to Clara
- Responding to data subject requests and informing Clara of any relevant requests
- Conducting data protection impact assessments where required
- Complying with all applicable data protection laws in your use of Clara
- Providing Clara with lawful processing instructions
- Maintaining records of processing activities as required by GDPR Article 30
8. Sub-processors
You authorize Clara to engage the following Sub-processors to assist in providing patient-data processing Services. Each Sub-processor is bound by contractual obligations consistent with this DPA. Clara's subscription billing provider is described in the Privacy Policy and Terms and is not used to process patient Personal Data under this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud infrastructure, database hosting, audio storage, transcription, and AI processing (Azure OpenAI) | European Union |
| Google Calendar API | Optional calendar sync when enabled by the Controller | European Union / applicable Google processing locations under contractual safeguards |
| PostHog | Limited product analytics, recorder diagnostics, and masked troubleshooting replay | European Union / applicable processing locations under contractual safeguards |
| Resend | Transactional email delivery for consent, invoices, account messages, and clinician notifications | United States / applicable processing locations under contractual safeguards |
Clara will notify you of any intended changes to Sub-processors, giving you the opportunity to object. If you have reasonable grounds to object, you may terminate the affected Services.
9. International Data Transfers
Clara's primary application infrastructure and service data are hosted within the European Union. If an optional integration or Sub-processor processes limited Personal Data outside the EU/EEA, Clara will ensure appropriate contractual and legal safeguards are in place, such as Standard Contractual Clauses approved by the European Commission where applicable.
10. Security Measures
Clara implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256)
- Access controls and authentication mechanisms to prevent unauthorized access
- Regular security assessments and vulnerability testing
- Secure development practices and code review processes
- Employee confidentiality agreements and data protection training
- Incident response procedures and business continuity plans
- Automatic deletion of session audio 14 days after processing
- Logical separation of customer data
- Regular backups with encryption
- Logging and monitoring of system access
11. Data Subject Rights
Clara will assist you in fulfilling your obligations to respond to data subject requests under GDPR, including rights of access, rectification, erasure, restriction, portability, and objection. If Clara receives a request directly from a data subject, we will promptly notify you and await your instructions unless legally required to respond directly. You can manage patient data, including deletion requests, through Clara's interface.
12. Personal Data Breach Notification
In the event of a Personal Data Breach, Clara will notify you without undue delay after becoming aware of the breach. The notification will include:
- A description of the nature of the breach, including categories and approximate number of data subjects and records affected
- Contact details for obtaining more information
- A description of likely consequences of the breach
- A description of measures taken or proposed to address the breach and mitigate its effects
13. Audit Rights
Clara will make available to you all information reasonably necessary to demonstrate compliance with this DPA and GDPR Article 28. Upon reasonable notice, Clara will allow for and contribute to audits, including inspections, conducted by you or an independent auditor you mandate. Audits shall be conducted during normal business hours, with reasonable advance notice, and shall not unreasonably interfere with Clara's operations. You shall bear the costs of any audit unless the audit reveals material non-compliance by Clara.
14. Data Return and Deletion
Upon termination of the Services or upon your request, Clara will, at your choice, delete or return all Personal Data and delete existing copies, unless EU or Member State law requires continued storage. When the clinician instructs Clara to retain consent evidence to preserve proof of lawful basis, Clara retains that evidence for the period stated in the Privacy Policy before deleting or returning it. Session audio is automatically deleted 14 days after processing. Data return is handled upon request to Clara. Clara does not currently provide a general self-serve export function for Personal Data. After account deletion, Clara will remove all other Personal Data within 30 days, except where retention is legally required.
15. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set forth in the Terms of Use. Clara shall be liable for damages caused by processing that does not comply with GDPR obligations specifically directed to processors, or where Clara has acted outside or contrary to your lawful instructions.
16. Term and Termination
This DPA becomes effective when you start using Clara's Services and remains in effect until all Personal Data is deleted or returned. The obligations in this DPA survive termination to the extent necessary to fulfill their purpose. Either party may terminate this DPA in accordance with the termination provisions in the Terms of Use.
Contact Information
For questions about this DPA or to exercise your rights as a Controller, please contact our Data Protection Officer at privacy@heyclara.app.