> ## Documentation Index
> Fetch the complete documentation index at: https://docs.clinero.de/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Security and GDPR Compliance for Dental Practices

> Clinero processes all patient and practice data in compliance with GDPR on German high-security servers, with full encryption and strict access controls.

Data security is foundational to everything Clinero does. All patient and billing data is handled in strict compliance with the EU General Data Protection Regulation (GDPR), known in Germany as the Datenschutz-Grundverordnung (DSGVO), as well as all applicable German federal and state data protection laws. Clinero does not treat security as an afterthought — it is built into every layer of the service, from the connection method your team uses to the server infrastructure where data is stored.

## GDPR Compliance

Clinero processes patient and practice data exclusively as a data processor acting on your instruction, in full compliance with DSGVO requirements. Before any work begins, a formal data processing agreement — Auftragsverarbeitungsvertrag (AVV) — is signed between Clinero and your practice. This agreement defines the scope of processing, the categories of data involved, and the technical and organisational measures Clinero has in place to protect that data. You remain the data controller at all times.

<Note>
  Clinero operates fully under German and EU data protection law (DSGVO/GDPR). A signed AVV is a prerequisite for any engagement and is provided to every partner practice before the service begins.
</Note>

## Data Storage

Patient records, billing data, and all associated practice information are stored exclusively within Germany:

* All data is stored on German high-security servers — no exceptions
* No data is transferred outside Germany or the European Union
* Infrastructure is hosted in certified German data centres, covered by contractual data processing agreements that meet DSGVO requirements
* Data at rest is encrypted using industry-standard protocols

## Access Controls

Access to your practice data is tightly controlled at every level:

* All remote connections use end-to-end encryption via TeamViewer or VPN — no unencrypted access paths exist
* Strict need-to-know access policies apply — only the billing expert assigned to your practice can access your data
* Access is limited to agreed sessions or pre-scheduled time windows; no unannounced or background access occurs
* All Clinero employees and contractors sign comprehensive confidentiality agreements before handling any practice data
* Regular internal access audits and quality control reviews are conducted to verify compliance

## Patient Data Handling

Patient records are accessed only to the extent strictly necessary to carry out the billing tasks you have commissioned. Clinero does not retain copies of patient data beyond what is required for active service delivery, does not share patient information with any third parties outside the agreed processing relationship, and does not use patient data for any purpose other than the billing and optimisation services your practice has engaged.

## Your Rights

As the data controller, your practice retains full ownership of and authority over all patient and billing data. Under DSGVO, you have the right to request information about exactly what data is being processed on your behalf, to request corrections to any inaccurate data, to request deletion of data that is no longer required, and to withdraw your consent to processing at any time. Clinero will respond promptly to any data subject access requests or correction requests you forward from patients.

<Tip>
  Request a copy of Clinero's data processing agreement (DPA/AVV) during your initial consultation. Review it with your practice's data protection officer or legal adviser before signing up — Clinero encourages this as part of responsible onboarding.
</Tip>
