Legal
Data Processing Agreement
The terms under which we process patient data on your practice's behalf, written to track GDPR Article 28. If you are the person who has to sign off on a supplier before a clinic can use it, this page is for you.
What this document is
The processing agreement that sits underneath the privacy policy: what we process on your instructions, the obligations that come with it, which sub-processors are involved, and what happens to your data when you leave.
Last updated: 25 July 2026
Parties and roles
This agreement forms part of the Terms of Service between your practice ("Customer", the controller) and Hypermetron, the company that operates HyperCRM (the processor) — Hypermetron is also the party that contracts with and invoices your practice, and is a controller in its own right for that billing relationship. It governs our processing of personal data on your behalf and is written to satisfy Article 28 of the GDPR. For our full legal entity details, or a countersigned copy for your compliance file, write to hello@hypercrm.app.
What we process, and why
- Subject matter: providing the HyperCRM practice management service.
- Duration: for as long as your account is open, plus the deletion window below.
- Nature and purpose: scheduling, clinical record-keeping, forms, file storage and invoicing, as configured by you.
- Types of personal data: patient demographics, clinical notes, form responses, uploaded documents, imaging and 3D scans, appointments and invoices — including health data, which is special-category data under Article 9.
- Categories of data subject: your patients and your staff.
Our obligations
We will:
- process personal data only on your documented instructions, including as to transfers, unless the law requires otherwise — and where it does, tell you first unless we are legally forbidden from doing so;
- ensure that everyone we authorise to process the data is under a duty of confidentiality;
- implement appropriate technical and organisational security measures — set out concretely on the security page: passkey authentication, role-based access, an audit log of every change, private file storage served only through short-lived signed links, and encryption in transit and at rest;
- engage sub-processors only on the terms below;
- help you respond to data-subject requests — access, correction, deletion, portability and objection;
- help you meet your own obligations on security, breach notification and data protection impact assessments (Articles 32 to 36);
- delete or return the personal data at the end of the service, as described below;
- make available the information you need to demonstrate compliance, and submit to audits as described below.
Sub-processors
You give general authorisation for us to engage the sub-processors published at sub-processors, which names each one, what it processes, and whether it is essential or only active when a practice enables it.
We will give you at least 30 days' notice before adding or replacing a sub-processor, during which you may object on reasonable data-protection grounds. We impose data-protection obligations on each sub-processor equivalent to those in this agreement, and we remain responsible to you for their performance.
Personal data breaches
We will notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations under Articles 33 and 34. We will not wait until we have a complete picture before telling you that something has happened.
International transfers
Some of our sub-processors are based outside the EEA, principally in the United States. Those providers offer the standard safeguards for such transfers — Standard Contractual Clauses and, where applicable, participation in the EU–US Data Privacy Framework. Ask us and we will provide the transfer documentation we hold for each provider so you can map it in your own records.
Audit
We will make available, on your reasonable request, the documentation needed to demonstrate our compliance with this agreement. We do not hold a SOC 2 report or an ISO 27001 certificate, and we will not imply otherwise.
Return and deletion
You can export everything at any time, free and immediately: every list to CSV, every file downloadable. After your account closes we delete your personal data within 30 days, except where the law requires us to keep it. That window exists so an accidental closure is recoverable — it is not a retention period you should rely on to meet a clinical record-keeping obligation, which stays with your practice. A subscription that lapses or is cancelled does not close the account and deletes nothing: the data is kept, read-only, until you close it.
Changes and governing law
We will update this agreement as the product and our processors change, and the date at the top will always reflect the current version. It is governed by the same law as the Terms of Service.
Reviewing us as a supplier?
Ask for whatever your compliance file needs. We would rather answer awkward questions early.
Contact us