Data Processing Agreement | Medara

Effective 12 July 2026

Data Processing Agreement

This agreement sets out how Medara Limited processes personal data on behalf of practitioners and practices using the platform.

01

Parties

Controller: the Medara-registered practitioner or practice. Processor: Medara Limited. Sub-processors (hosting, email, SMS) are listed in the subprocessor schedule available on request.

02

Instructions

The Processor processes personal data only on documented instructions from the Controller, including storage of clinical records, imaging, billing metadata, and audit logs necessary to provide the Service.

03

Security measures

Technical measures include encryption at rest for clinical media and receipts, TLS in transit, signed time-limited media URLs, API-layer role-based access control, MFA, session controls, and audit logging of access to patient records. See Security & DR for detail.

04

Data protection authority

Medara Limited complies with applicable data protection legislation in the jurisdictions where it operates. Controllers remain responsible for their own registration obligations with relevant local data protection authorities.

05

Breach notification

The Processor notifies the Controller without undue delay on becoming aware of a personal data breach affecting Controller data, with sufficient detail to meet applicable notification duties.