Back to Payments

    GDPR and the Data Processing Agreement

    Accept the DPA before taking patient payments or enabling the Developer API.

    Clinic Membership acts as a data processor for patient data when you take payments and use certain features. UK GDPR requires a Data Processing Agreement (DPA) between your clinic and Clinic Membership (Apavai Ltd).

    Patient payments DPA (Stripe Connect)

    1. Connect Stripe under Settings → Payments.
    2. When prompted, open the Data Processing Agreement section.
    3. Read the DPA at /dpa (opens in a new tab).
    4. Tick I have read and accept the Data Processing Agreement.
    5. Patient checkout and card readers unlock once accepted.
    Data Processing Agreement checkbox in Payments settings
    Settings → Payments, accept the DPA before taking patient payments.

    Developer API DPA

    1. Go to Settings → API (Founders+).
    2. Read API access & data processing.
    3. Accept the API DPA with Accept & continue before enabling API access.

    Note

    Settings → Data covers audit trail and export tools, separate from DPA acceptance.

    What happens next

    Still stuck?

    Send us a message and we'll get you sorted. If you're logged in, you can also use the ? Help button in your admin dashboard.

    Contact support

    Get started

    One platform for clinic operations and membership growth

    Try it free. No card required. Your first 10 patients are free forever. Upgrade when you add patient 11.

    Cancel anytime · GDPR compliant · UK based

    Clinic Membership dashboard with calendar, patients, memberships and reports for UK aesthetics clinics