DentaSuite/Data Processing Agreement

DentaSuite Data Processing Agreement (DPA)

DRAFT — for legal review before publication. Presented as

click-wrap at signup for practices subject to GDPR/UK GDPR and

incorporated into the Terms. Structure follows GDPR Article 28(3).

English text authoritative.

Parties. The dental practice accepting these terms ("Controller")

and [FILL-IN entity] ("Processor", "DentaSuite").

1. Subject matter, duration, nature and purpose

Processor processes Practice Content — including patient photographs,

scans, notes and related documents ("Patient Data") — solely to

provide the DentaSuite applications the Controller subscribes to, for

the duration of the subscription.

2. Categories of data and data subjects

Data subjects: the Controller's patients and staff. Data categories:

clinical photographs and imaging, transcribed notes, patient

identifiers the Controller chooses to enter (e.g. name, date of

birth), account and usage data of practice staff. Patient Data may

include special-category health data.

3. Controller instructions

Processor processes Patient Data only on documented instructions from

the Controller — namely the functions of the applications as operated

by the Controller's users — and will inform the Controller if an

instruction appears to infringe data-protection law.

4. Confidentiality

Persons authorised to process Patient Data are bound by

confidentiality obligations and access it only as necessary for

service operation and support.

5. Security (Art. 32)

Processor implements the measures described at dentasuite.com/security

including: TLS encryption in transit; encryption at rest; logical

per-practice segregation; least-privilege and audited administrative

access; transient processing with 24-hour deletion for unsaved

uploads; tested backup and incident-response procedures.

6. Sub-processors

Controller grants general authorisation for the sub-processors listed

at dentasuite.com/security. Processor gives 30 days' notice of

changes; Controller may object on reasonable data-protection grounds,

in which case the parties will seek a solution and Controller may

terminate the affected service if none exists. Processor remains

liable for sub-processors' performance.

7. International transfers

Processing occurs in the European Union. Where Patient Data is

transferred to a third country without an adequacy decision, the

parties rely on the European Commission's Standard Contractual

Clauses (Module 2, controller-to-processor), which are incorporated

by reference [FILL-IN: annex with completed SCCs before first

non-EU/UK transfer].

8. Assistance

Taking into account the nature of processing, Processor assists the

Controller with data-subject requests (access, deletion, portability

— largely self-service via in-app export/delete), with security,

breach notification, and data-protection impact assessments, at no

charge for reasonable requests.

9. Personal data breach

Processor notifies the Controller without undue delay after becoming

aware of a personal data breach affecting Patient Data, with the

information reasonably required for the Controller's own notification

duties (see Processor's internal breach-response runbook).

10. Deletion and return

On termination, Controller may export Practice Content for 30 days;

Processor then deletes it (backups within 90 days), unless law

requires retention. Transiently processed uploads are deleted within

24 hours in normal operation.

11. Audit

Processor makes available information necessary to demonstrate

compliance (this DPA, the security page, certifications as obtained)

and allows audits by the Controller or its mandated auditor, no more

than annually, on 30 days' notice, at Controller's cost, in a manner

that does not compromise other practices' data.

12. Model improvement (opt-in only)

Patient Data is used to improve Processor's models only while the

Controller's improvement-programme setting is enabled. Enabling it is

a documented instruction under §3; disabling it stops future use.

Improvement processing uses the same security measures and remains

within the scope of this DPA.

Privacy PolicyTerms of ServiceData Processing AgreementSecurity & Subprocessors