Last updated: 20 July 2026

Version: 2.0

ClearEar Limited (“ClearEar”, “we”, “us”, “our”) is committed to protecting your privacy and handling your personal data — including your sensitive health information — lawfully, transparently, and securely. This Privacy Policy explains what personal data we collect, why we collect it, the legal basis on which we process it, who we share it with, how long we keep it, and the rights you have under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Irish Data Protection Act 2018.

Please read this policy carefully. By using our website, booking an appointment, or attending one of our clinics, you acknowledge that you have read and understood how we handle your personal data as described here.

 

1. Who we are (Data Controller)

ClearEar Limited is the data controller responsible for your personal data.

  • Company: ClearEar Limited
  • Company registration number (CRO): 757522
  • Registered office: Failte, Lucan Road, Lucan
  • Clinic locations: Dublin 1 — 21A Store Street, Dublin 1; Lucan — ClearEar Lucan, Lucan Road
  • General contact: info@clearear.ie
  • Data protection contact: info@clearear.ie

If you have any question about this policy or wish to exercise your data protection rights, please use the data protection contact above.

Note on a Data Protection Officer (DPO): Because ClearEar processes health data (a “special category” of data) on a significant scale as a core part of its activities, you should confirm with a data protection professional whether you are legally required to formally appoint a DPO under Article 37 GDPR. Whether or not one is mandatory, we recommend naming a single accountable data protection contact.

 

2. The categories of personal data we collect

We collect and process the following categories of personal data:

Identity and contact data — your name, date of birth, postal address, email address, and telephone number.

Appointment and booking data — the clinic and service you booked, appointment dates and times, and booking history, collected through our online booking system.

Special category health data — information about your ears, nose, throat, hearing and related health; your symptoms, medical history and relevant medications; clinical examination findings (including otoscopy and endoscopy images or video where taken); hearing test results; diagnoses; the treatment or procedure provided (for example microsuction wax removal or nasal endoscopy); clinical notes; and any referral information. Health data is treated with the highest level of protection under GDPR.

Payment data — the amount paid, the service paid for, and transaction records. Your full card details are processed directly by our payment provider (see Section 5); we do not store your full card number.

Communications data — records of your correspondence with us by email, phone, contact form, or booking messages, including any information you choose to share with us.

Technical and usage data — when you use our website, your IP address, browser type and version, device information, pages viewed, and how you interact with the site, collected via cookies and similar technologies (see Section 8).

Marketing preferences — your consent status and preferences for receiving communications from us.

We collect this data directly from you (when you book, attend, pay, or contact us), automatically through our website, and occasionally from third parties acting on your behalf (for example a referring clinician, or a family member booking on your behalf with your authorisation).

 

3. Why we process your data and our legal basis

Under GDPR we must have a lawful basis for every use of your personal data. Because health data is a special category, we rely on two layers of legal basis — one under Article 6 (for all personal data) and one under Article 9 (specifically for health data).

To provide you with clinical care and services — examining you, removing ear wax, performing hearing tests and nasal endoscopy, managing ear infections, and arranging referrals.

Legal basis: Article 6(1)(b) (performance of a contract with you) and, for your health data, Article 9(2)(h) (provision of health care and treatment by, or under the responsibility of, a health professional bound by professional secrecy). Where required, we also rely on your Article 9(2)(a) explicit consent.

To manage your booking and appointments — confirming, rescheduling, or reminding you about appointments.

Legal basis: Article 6(1)(b) (contract).

To take and record payment.

Legal basis: Article 6(1)(b) (contract) and Article 6(1)(c) (compliance with our legal obligations, including tax and accounting law).

To refer you for imaging or onward specialist care.

Legal basis: Article 6(1)(b) (contract) and Article 9(2)(h) (provision of health care); we will obtain your explicit consent before sharing your records with an external provider where consent is the appropriate basis.

To meet our legal, regulatory, and professional obligations — including clinical record-keeping, medico-legal requirements, responding to lawful requests, and professional standards set by our clinicians’ regulators.

Legal basis: Article 6(1)(c) (legal obligation) and Article 9(2)(h), and where relevant Article 9(2)(f) (establishment, exercise or defence of legal claims).

To operate, secure, and improve our website and services, and to protect against fraud and misuse.

Legal basis: Article 6(1)(f) (our legitimate interests in running a safe, effective service), balanced against your rights.

To send you marketing communications (for example service updates, reminders, or offers), where you have opted in.

Legal basis: Article 6(1)(a) (consent), in line with the Irish ePrivacy Regulations (S.I. 336 of 2011). You can withdraw consent at any time (see Section 7).

To use cookies and analytics that are not strictly necessary for the website to function.

Legal basis: Article 6(1)(a) (consent), collected via our cookie banner (see Section 8).

We will not use your data for a new, incompatible purpose without first informing you and, where required, obtaining your consent.

 

4. Automated decision-making and profiling

We do not make decisions about your care, eligibility, or treatment using solely automated means, and we do not carry out profiling that produces legal or similarly significant effects on you. All clinical decisions are made by qualified clinicians.

 

5. Who we share your data with

We do not sell, rent, or trade your personal data. We share it only where necessary to provide our services, meet a legal obligation, or with your consent. The main categories of recipients are:

Our clinicians and staff — the ENT clinicians, physician associates, and administrative staff involved in your care and the running of the clinic, on a strict need-to-know basis.

Onward healthcare providers — where you are referred for imaging or specialist care, we share the relevant clinical information with that provider, with your knowledge and consent.

Our service providers (data processors), who process data on our behalf under written contracts that require them to protect it and use it only on our instructions, including:

  • our website host and online booking system provider (WordPress hosting and the Amelia booking plugin), which processes your booking and contact details;
  • our payment provider, Stripe, which processes card payments securely (Stripe is PCI-DSS compliant and handles your full card details directly);
  • our banking provider, Bank of Ireland, in connection with payments;
  • our clinical records system provider, Socrates Health, which securely hosts patient records;
  • our email and communications providers;
  • our marketing and advertising partners — Advivo (Google and Meta advertising) and 5Films Media (content and social media) — who may process limited data such as website analytics and advertising identifiers; and
  • our professional advisers (accountants, auditors, insurers, and legal advisers) where reasonably required.

Regulators, authorities, and courts — where we are legally required to disclose data, or where disclosure is necessary to establish, exercise, or defend legal claims, or to protect the vital interests of you or another person.

We keep an up-to-date record of the processors we use and carry out due diligence on their security and GDPR compliance. A current list is available on request.

 

6. International transfers of your data

Some of our service providers (for example Stripe, Google, and Meta) may process data outside the European Economic Area (EEA), including in the United States. Where your data is transferred outside the EEA, we ensure an appropriate safeguard is in place as required by GDPR, such as:

  • the recipient being certified under the EU–US Data Privacy Framework; or
  • Standard Contractual Clauses approved by the European Commission; together with
  • additional technical and organisational measures where needed.

Your clinical health records are held within the EEA and are not routinely transferred outside it. You can ask us for more information about the safeguards applied to any transfer.

 

7. How long we keep your data (retention)

We keep your personal data only for as long as necessary for the purposes described in this policy, and to meet our legal, clinical, and professional obligations. Our retention periods reflect the guidance of the Medical Council of Ireland and applicable Irish law:

  • Adult clinical records: retained for a minimum of eight (8) years after your last treatment (or after death).
  • Records of children and young people: retained until the patient’s 25th birthday (or 26th if they were 17 at the conclusion of treatment), or eight years after death, whichever is later.
  • Financial and payment records: retained for six (6) years as required by Irish tax and company law.
  • Booking and appointment data (non-clinical): retained for the duration of your relationship with us and for a reasonable period afterwards, then deleted or anonymised.
  • Marketing consent and preference records: retained until you withdraw consent, and for a short period afterwards to evidence that withdrawal.
  • Website and analytics data: retained in line with the retention settings disclosed in our Cookie Policy.

When data is no longer required, we securely delete, destroy, or irreversibly anonymise it.

To confirm: These are the recommended minimums under current Irish guidance. You should confirm your final retention schedule — and any longer periods your medical indemnity insurer or professional regulator requires — with your data protection contact or solicitor before publishing.

 

8. Cookies and similar technologies

Our website uses cookies and similar technologies. Strictly necessary cookies (needed for the site and booking system to function) are always active. Analytics and advertising cookies — including those used by Google and Meta via our advertising partners — are only set with your consent, which we collect through the cookie banner shown when you first visit the site. You can change or withdraw your cookie preferences at any time.

Full details of the specific cookies we use, their purpose, and their duration are set out in our separate Cookie Policy, which forms part of this Privacy Policy.

 

9. How we protect your data (security)

We take the security of your data seriously and use appropriate technical and organisational measures to protect it, including access controls that limit patient records to authorised staff on a need-to-know basis, secure and access-controlled clinical and booking systems, encryption of data in transit, secure payment processing through a PCI-DSS-compliant provider, staff confidentiality obligations and data protection training, and secure storage and disposal of both paper and electronic records.

No method of electronic storage or transmission over the internet is completely secure, and we cannot guarantee absolute security. However, we maintain procedures to deal with any suspected personal data breach and, where we are legally required to do so, we will notify the Data Protection Commission and any affected individuals without undue delay in accordance with Articles 33 and 34 GDPR.

 

10. Children’s data

We provide clinical services to children as well as adults. Where the patient is a child, an appointment is normally booked by, and consent provided by, a parent or legal guardian, who is responsible for the information they provide on the child’s behalf. We handle children’s health data with particular care and retain it in line with the periods set out in Section 7. Our website and marketing are directed at adults and are not intended to collect data from children online.

 

11. Your data protection rights

Under GDPR you have the following rights in relation to your personal data:

  • The right to be informed — to know how we use your data, as set out in this policy.
  • The right of access — to obtain a copy of the personal data we hold about you (a “subject access request”).
  • The right to rectification — to have inaccurate data corrected. For clinical records, we can correct factual errors; where you disagree with a clinical opinion recorded at the time, we will note your disagreement alongside the original entry rather than altering the clinical record.
  • The right to erasure — to have your data deleted in certain circumstances. This right is limited for health records that we are legally or professionally obliged to retain (see Section 7).
  • The right to restrict processing — to limit how we use your data in certain circumstances.
  • The right to data portability — to receive certain data in a structured, commonly used, machine-readable format.
  • The right to object — including to direct marketing at any time, and to processing based on our legitimate interests.
  • The right to withdraw consent — where we rely on your consent, you can withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Rights relating to automated decision-making — though, as noted, we do not carry out such decision-making.

To exercise any of these rights, contact us using the details in Section 1. We will respond within one month as required by GDPR (this may be extended by up to two further months for complex requests, in which case we will tell you). We do not charge a fee for a valid request unless it is manifestly unfounded, excessive, or repetitive. We may need to verify your identity before releasing information, particularly for health records.

 

12. Your right to complain

If you have a concern about how we handle your personal data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the Irish supervisory authority:

Data Protection Commission (DPC)

21 Fitzwilliam Square South, Dublin 2, D02 RD28

Website: www.dataprotection.ie

Telephone: +353 (0)1 765 0100 / 1800 437 737

 

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, or the law. When we make material changes, we will update the “Last updated” date at the top and, where appropriate, notify you directly. We encourage you to review this policy periodically. Continued use of our services after a change indicates your awareness of the updated policy.

 

14. Contact us

For any question about this Privacy Policy or your personal data, please contact:

ClearEar Limited

Data protection contact: info@clearear.ie

General enquiries: info@clearear.ie

01 234 7385

 

This Privacy Policy should be read together with our Cookie Policy and any patient consent forms or terms of service. It is provided as a comprehensive draft and should be reviewed by a qualified data protection professional or solicitor before publication.

Temporary Notice

Our Paediatrics and ENT specialist is unavailable until September 14, 2026. Both Basic and Comprehensive appointments are available as normal. We apologise for any inconvenience and appreciate your understanding.