GDPR Compliance
Clinero processes patient and practice data exclusively as a data processor acting on your instruction, in full compliance with DSGVO requirements. Before any work begins, a formal data processing agreement — Auftragsverarbeitungsvertrag (AVV) — is signed between Clinero and your practice. This agreement defines the scope of processing, the categories of data involved, and the technical and organisational measures Clinero has in place to protect that data. You remain the data controller at all times.Clinero operates fully under German and EU data protection law (DSGVO/GDPR). A signed AVV is a prerequisite for any engagement and is provided to every partner practice before the service begins.
Data Storage
Patient records, billing data, and all associated practice information are stored exclusively within Germany:- All data is stored on German high-security servers — no exceptions
- No data is transferred outside Germany or the European Union
- Infrastructure is hosted in certified German data centres, covered by contractual data processing agreements that meet DSGVO requirements
- Data at rest is encrypted using industry-standard protocols
Access Controls
Access to your practice data is tightly controlled at every level:- All remote connections use end-to-end encryption via TeamViewer or VPN — no unencrypted access paths exist
- Strict need-to-know access policies apply — only the billing expert assigned to your practice can access your data
- Access is limited to agreed sessions or pre-scheduled time windows; no unannounced or background access occurs
- All Clinero employees and contractors sign comprehensive confidentiality agreements before handling any practice data
- Regular internal access audits and quality control reviews are conducted to verify compliance