DentaSuite Data Processing Agreement (DPA)
DRAFT — for legal review before publication. Presented as
click-wrap at signup for practices subject to GDPR/UK GDPR and
incorporated into the Terms. Structure follows GDPR Article 28(3).
English text authoritative.
Parties. The dental practice accepting these terms ("Controller")
and [FILL-IN entity] ("Processor", "DentaSuite").
1. Subject matter, duration, nature and purpose
Processor processes Practice Content — including patient photographs,
scans, notes and related documents ("Patient Data") — solely to
provide the DentaSuite applications the Controller subscribes to, for
the duration of the subscription.
2. Categories of data and data subjects
Data subjects: the Controller's patients and staff. Data categories:
clinical photographs and imaging, transcribed notes, patient
identifiers the Controller chooses to enter (e.g. name, date of
birth), account and usage data of practice staff. Patient Data may
include special-category health data.
3. Controller instructions
Processor processes Patient Data only on documented instructions from
the Controller — namely the functions of the applications as operated
by the Controller's users — and will inform the Controller if an
instruction appears to infringe data-protection law.
4. Confidentiality
Persons authorised to process Patient Data are bound by
confidentiality obligations and access it only as necessary for
service operation and support.
5. Security (Art. 32)
Processor implements the measures described at dentasuite.com/security
including: TLS encryption in transit; encryption at rest; logical
per-practice segregation; least-privilege and audited administrative
access; transient processing with 24-hour deletion for unsaved
uploads; tested backup and incident-response procedures.
6. Sub-processors
Controller grants general authorisation for the sub-processors listed
at dentasuite.com/security. Processor gives 30 days' notice of
changes; Controller may object on reasonable data-protection grounds,
in which case the parties will seek a solution and Controller may
terminate the affected service if none exists. Processor remains
liable for sub-processors' performance.
7. International transfers
Processing occurs in the European Union. Where Patient Data is
transferred to a third country without an adequacy decision, the
parties rely on the European Commission's Standard Contractual
Clauses (Module 2, controller-to-processor), which are incorporated
by reference [FILL-IN: annex with completed SCCs before first
non-EU/UK transfer].
8. Assistance
Taking into account the nature of processing, Processor assists the
Controller with data-subject requests (access, deletion, portability
— largely self-service via in-app export/delete), with security,
breach notification, and data-protection impact assessments, at no
charge for reasonable requests.
9. Personal data breach
Processor notifies the Controller without undue delay after becoming
aware of a personal data breach affecting Patient Data, with the
information reasonably required for the Controller's own notification
duties (see Processor's internal breach-response runbook).
10. Deletion and return
On termination, Controller may export Practice Content for 30 days;
Processor then deletes it (backups within 90 days), unless law
requires retention. Transiently processed uploads are deleted within
24 hours in normal operation.
11. Audit
Processor makes available information necessary to demonstrate
compliance (this DPA, the security page, certifications as obtained)
and allows audits by the Controller or its mandated auditor, no more
than annually, on 30 days' notice, at Controller's cost, in a manner
that does not compromise other practices' data.
12. Model improvement (opt-in only)
Patient Data is used to improve Processor's models only while the
Controller's improvement-programme setting is enabled. Enabling it is
a documented instruction under §3; disabling it stops future use.
Improvement processing uses the same security measures and remains
within the scope of this DPA.