Back to Payments

    GDPR and the Data Processing Agreement

    Accept the DPA before taking patient payments or enabling the Developer API.

    Clinic Membership acts as a data processor for patient data when you take payments and use certain features. UK GDPR requires a Data Processing Agreement (DPA) between your clinic and Clinic Membership (Apavai Ltd).

    Patient payments DPA (Stripe Connect)

    1. Connect Stripe under Settings → Payments.
    2. When prompted, open the Data Processing Agreement section.
    3. Read the DPA at /dpa (opens in a new tab).
    4. Tick I have read and accept the Data Processing Agreement.
    5. Patient checkout and card readers unlock once accepted.
    Data Processing Agreement checkbox in Payments settings
    Settings → Payments — accept the DPA before taking patient payments.

    Developer API DPA

    1. Go to Settings → API (Founders+).
    2. Read API access & data processing.
    3. Accept the API DPA with Accept & continue before enabling API access.

    Note

    Settings → Data covers audit trail and export tools — separate from DPA acceptance.

    What happens next

    Still stuck?

    Send us a message and we'll get you sorted. If you're logged in, you can also use the ? Help button in your admin dashboard.

    Contact support