Back to home

Data Processing Addendum

Last updated: May 27, 2026

DRAFT — pending legal review. This template was generated to give clinics a working DPA. Divan Group's legal counsel is reviewing it; the executed version will be available for download as a signed PDF on this page. Do not rely on this document for regulatory compliance without confirming with your own counsel.

This Data Processing Addendum ("DPA") forms part of the agreement between you ("Controller", "you") and ClinicPro, operated by Divan Digital Corp (o/a Divan Group) ("Processor", "we"), for the provision of the ClinicPro service (the "Service"). It applies when, in the course of providing the Service, we process Personal Data on your behalf in the European Economic Area, the United Kingdom, or Switzerland.

1. Definitions

"GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the UK General Data Protection Regulation. "Personal Data", "Processing", "Data Subject", "Controller", "Processor", and "Supervisory Authority" have the meanings given in the GDPR. "Subprocessor" means any third-party processor engaged by us to process Personal Data on your behalf.

2. Roles

For Personal Data processed via the Service, you are the Controller and we are the Processor. You determine the purposes and means of processing; we process only on your documented instructions.

3. Scope of processing

Subject matter: provision of the Service.
Duration: for the term of your subscription, plus any retention period set out in the Terms or required by law.
Nature and purpose: hosting, transmitting, displaying, and analyzing clinic operational data so that you can manage your practice.
Types of Personal Data: identification data, contact data, appointment data, payment metadata (not raw card numbers), clinical notes, photographs, signatures, and message content that you choose to store.
Categories of Data Subjects: your clinic staff and your clients (patients).

4. Our obligations

  • Process Personal Data only on your documented instructions.
  • Ensure that personnel authorized to process Personal Data are bound by confidentiality.
  • Implement appropriate technical and organizational measures, including those described in our Security page.
  • Assist you, taking into account the nature of the processing, in responding to Data Subject requests.
  • Assist you in ensuring compliance with Articles 32–36 GDPR (security, breach notification, DPIAs, prior consultation).
  • Notify you without undue delay (and within 72 hours where feasible) after becoming aware of a Personal Data Breach.
  • On termination, delete or return Personal Data unless retention is required by law.

5. Subprocessors

Sub-processor list version 2026-09-01. We will give clinic owners at least 30 days' notice of any addition to this list, published on this page with the version date above updated and sent by email to clinic owners. You provide a general authorization for us to engage the Subprocessors below and may object on reasonable grounds to a proposed addition. Our current Subprocessors are:

  • Supabase Inc. (USA) — database, authentication, and object storage hosting. All data is stored in the AWS ca-central-1 region (Montréal, Canada).
  • Vercel Inc. (USA) — application hosting, content delivery, and edge routing. Vercel serves the application; it does not store clinic or patient records, which remain in Supabase.
  • Paddle.com Market Limited (UK) — ClinicPro's own subscription billing and Merchant of Record for ClinicPro subscription fees.
  • Square, Inc. (USA) — processes your clinic's own in-clinic card payments, point-of-sale transactions, and membership subscription charges, when you connect your Square account via OAuth. Engaged only for clinics that connect Square.
  • Intuit Inc. (QuickBooks) (USA) — accounting data export, engaged only when you connect QuickBooks.
  • Anthropic, PBC (USA) — AI features (Claude). See Section 5A below for what is sent.
  • Resend Inc. (USA) — transactional and notification email delivery, sent from clinicpro.io. This is our only email delivery subprocessor; Lovable Labs Incorporated (Lovable Email) was removed on 2026-09-01 and no longer processes any ClinicPro data.
  • Twilio Inc. (USA) — SMS, WhatsApp Business messaging, and voice (when enabled).
  • Functional Software, Inc. (Sentry) (USA) — error monitoring (PII fields stripped client-side).

5A. AI processing detail

ClinicPro's AI features send data to Anthropic in two distinct ways:

  • Automated insights — only aggregated, de-identified clinic metrics are sent (e.g. booking volume, revenue trends).
  • Staff AI assistant — free-text prompts that staff type are sent to Anthropic as entered, and may contain client information if a staff member includes it in the prompt. Clinic-specific context (such as the service menu, staff names, and aggregate figures) is included automatically to make responses relevant. Our contractual arrangement with Anthropic is governed by Anthropic's commercial terms, which address use of submitted data. An owner or admin can disable the AI assistant for their clinic in Settings; when disabled, the assistant is blocked server-side and no prompts are sent.

6. International transfers and data residency

All Personal Data processed under this DPA is stored in Canada, in the AWS ca-central-1 region (Montréal). This includes the database, authentication records, and all file storage (consent PDFs, treatment photos, signatures), irrespective of the Controller's own location. Until 2026-09-01 this data was stored in the AWS us-west-2 region (Oregon, USA). We offer Canadian data residency; we do not currently offer EU, UK, or Australian data residency, and we will not represent otherwise.

Where Personal Data is transferred outside the EEA / UK to a country not deemed adequate by the European Commission or the UK ICO, the transfer is governed by the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, for UK data, the UK International Data Transfer Addendum, both of which are incorporated into this DPA by reference.

7. Audits

We will make available to you all information necessary to demonstrate compliance with this DPA, including third-party audit reports (SOC 2 Type II, when available). You may conduct an on-site audit no more than once per calendar year, on at least 30 days' written notice, at your own expense, subject to reasonable confidentiality requirements.

8. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in our Terms of Service.

9. Term and termination

This DPA takes effect on the date you accept the Terms of Service and remains in effect for the duration of the Service. It will terminate automatically on termination of the Service.

10. Governing law

This DPA is governed by the laws of the Province of Ontario, Canada, without regard to its conflict-of-laws principles. The parties submit to the exclusive jurisdiction of the courts of Toronto, Ontario.

11. Contact

Privacy and DPA questions: privacy@clinicpro.io.