Privacy Policy    Terms of Service    Home
Legal

Data Processing Agreement

Effective date: 1 June 2026  ·  Last updated: 16 June 2026  ·  GDPR Art. 28 compliant

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the dental practice ("Controller") and DentaPro Ltd ("Processor"). By accepting the Terms of Service at registration, the Controller enters into this DPA. No separate signature is required.

Data Controller
The Dental Practice
The clinic or practice that creates an account on Dental Assistant Pro. Identified by the practice name and email provided at registration.
Data Processor
DentaPro Ltd
Operator of Dental Assistant Pro at dentapro.org
Contact: privacy@dentapro.org

1. Definitions

Terms used in this DPA have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"). "Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Sub-processor" and "Supervisory Authority" have their GDPR meanings.

2. Subject Matter and Duration

The Processor provides practice management software (the "Service") to the Controller under the Terms of Service. This DPA governs all Processing of Personal Data carried out by the Processor on behalf of the Controller in connection with the Service.

This DPA remains in force for the duration of the Terms of Service and terminates automatically upon account deletion, subject to the data retention obligations in Section 9.

3. Nature and Purpose of Processing

The Processor processes Personal Data for the sole purpose of providing the Service, which includes:

4. Categories of Personal Data and Data Subjects

CategoryTypes of DataData Subjects
Patient health data
(Special category — Art. 9)
Name, date of birth, contact details, medical history, allergies, medications, diagnoses, treatment plans, prescriptions, X-rays, consent records, clinical notes Patients of the Controller's practice
Staff data Name, email address, role, login timestamps, audit logs Dentists, nurses, receptionists, and other staff added by the Controller
Communication data Portal messages, appointment requests, reminder messages Patients communicating via the patient portal

5. Obligations of the Controller

The Controller agrees to:

6. Obligations of the Processor

The Processor agrees to:

  1. Process only on instructions. Process Personal Data only on documented instructions from the Controller, except where required by law.
  2. Confidentiality. Ensure that all personnel authorised to process Personal Data are bound by confidentiality obligations.
  3. Security. Implement appropriate technical and organisational measures as described in Section 7.
  4. Sub-processors. Not engage sub-processors without prior written authorisation, and ensure sub-processors are bound by equivalent obligations (see Section 8).
  5. Data subject rights. Assist the Controller in fulfilling obligations to respond to data subject requests, to the extent technically feasible.
  6. Security assistance. Assist the Controller in ensuring compliance with GDPR Arts. 32–36 (security, breach notification, impact assessments).
  7. Deletion or return. At the Controller's choice, delete or return all Personal Data upon termination of the Service, and delete existing copies unless retention is required by law.
  8. Audit. Make available information necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice and confidentiality.

7. Security Measures

The Processor maintains the following technical and organisational security measures:

8. Sub-processors

The Controller hereby provides general authorisation to engage the following sub-processors. The Processor will notify the Controller of any intended change (addition or replacement) with at least 14 days' notice, giving the Controller the opportunity to object.

Sub-processorPurposeLocationDPA reference
Amazon Web Services (AWS)Cloud hosting, database (RDS), file storage (S3)EU West — IrelandAWS GDPR DPA
Stripe Inc.Payment processingEU / USA (SCCs)Stripe DPA
SendGrid / TwilioTransactional email deliveryEU / USA (SCCs)Twilio DPA

For transfers outside the EEA (Stripe, SendGrid), appropriate safeguards are in place via Standard Contractual Clauses (SCCs) as approved by the European Commission.

9. Data Retention and Deletion

Upon termination of the Service:

10. Data Breach Notification

In the event of a Personal Data breach, the Processor will:

The Controller is responsible for notifying affected data subjects as required by GDPR Art. 34.

11. Data Subject Rights

Where a data subject submits a request directly to the Processor, the Processor will forward the request to the Controller within 5 business days. The Controller is responsible for fulfilling data subject rights requests (access, rectification, erasure, portability, restriction, objection).

The Processor will provide reasonable technical assistance to help the Controller fulfil these requests, including data exports or deletion within the Service.

12. Liability

Each party is liable for any damages caused by processing in breach of this DPA or GDPR for which that party is at fault. The Processor's liability under this DPA is subject to the limitations set out in the Terms of Service.

13. Governing Law

This DPA is governed by the laws of Cyprus. Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the courts of Cyprus.

14. Contact and Amendments

For questions about this DPA, data subject rights requests, or to report a security concern: privacy@dentapro.org

The Processor may update this DPA from time to time to reflect changes in sub-processors, applicable law, or security measures. Controllers will be notified of material changes with at least 14 days' notice. Continued use of the Service after that date constitutes acceptance.