Legal
Draft — pending owner review
Privacy Notice
This notice explains how Prodia Systems Limited, the company behind Clinvela, handles personal data when you use our website, request a demo, or use the Clinvela platform.
Last updated: September 2026
Have a question? Ask our Privacy & Cookie Assistant
1. Who we are
Clinvela is a clinical coordination and workflow platform operated by Prodia Systems Limited, a private company limited by shares registered in Ireland under company number 822962.
Registered office: 27 Pembroke Street Upper, Dublin 2, D02 X361, Ireland
Email: contact@prodiasystems.com
Phone: +353 1 611 1534
For the purposes of the EU and UK General Data Protection Regulation (GDPR), Prodia Systems Limited is the data controller for personal data collected through this website and for account administration data. Where Clinvela is deployed within a healthcare organisation, that organisation typically acts as the data controller for patient and clinical data, and Prodia Systems Limited acts as a data processor under a data processing agreement.
2. What data we collect
We collect the minimum personal data needed to operate our website and services:
- Enquiry and demo requests — your name, work email, organisation, role and the content of your message.
- Account data — if your organisation adopts Clinvela, we process user names, work contact details and role assignments to provide access.
- Usage and technical data — log data, device and browser information, and aggregated usage statistics used to keep the service secure and reliable.
We do not use patient data processed within customer deployments for our own purposes, and we do not sell personal data to anyone.
If you use our Privacy & Cookie Assistant, your questions and its answers are saved and linked to a random identifier stored in your browser (not your name or email) so you can return to them. Please don't enter health or other sensitive information. You can delete conversations in the assistant, or ask us to at contact@prodiasystems.com.
3. How we use your data
We use personal data to:
- Respond to enquiries, demo requests and support questions.
- Provide, operate, secure and improve the Clinvela platform.
- Manage customer relationships, contracts and billing.
- Meet legal, regulatory and audit obligations.
Our lawful bases are performance of a contract, legitimate interest in operating and improving a secure clinical platform, and compliance with legal obligations. Where we rely on consent (for example, optional marketing communications), you can withdraw it at any time.
4. Clinical and patient data
Clinvela is designed for healthcare environments. Clinical data entered into the platform by a customer organisation remains under that organisation's control. We process it only on documented instructions, under a data processing agreement, with appropriate technical and organisational measures including encryption in transit and at rest, role-based access control and full audit logging.
For organisations in the United States, Clinvela deployments can be supported under a Business Associate Agreement in line with HIPAA and HITECH requirements. For a fuller picture of the regulations we design for — EU GDPR, UK GDPR, the EU AI Act, NIS2, EHDS, NHS and HSE requirements, and HIPAA — see our Security & Compliance page.
5. Sharing and international transfers
We share personal data only with carefully selected service providers (for example, hosting and email delivery) under written contracts, or where required by law. Where data is transferred outside the EEA or UK, we use appropriate safeguards such as adequacy decisions or standard contractual clauses.
6. Retention
We keep personal data only for as long as needed for the purposes described above. Enquiry data is retained for up to 24 months unless a customer relationship follows. Retention of clinical data within customer deployments is governed by the customer's own policies and the applicable data processing agreement.
7. Your rights
Under the GDPR you have the right to access, correct, delete or restrict processing of your personal data, the right to data portability, and the right to object to processing based on legitimate interests. To exercise any of these rights, use our data rights request form or contact us at contact@prodiasystems.com. We respond within one month. You also have the right to lodge a complaint with the Data Protection Commission (Ireland) or your local supervisory authority.
8. Security
We apply encryption in transit and at rest, role-based access controls, audit logging and privacy-by-design principles across the platform. For more detail, see our Security & Compliance page.
9. Changes to this notice
We may update this notice from time to time. Material changes will be highlighted on this page with a revised "last updated" date.
10. Contact
Questions about this notice or how we handle personal data:
Prodia Systems Limited, 27 Pembroke Street Upper, Dublin 2, D02 X361, Ireland
Email: contact@prodiasystems.com · Phone: +353 1 611 1534
