Legal
Data Processing Agreement
Effective date: 1 June 2026 · Last updated: 16 June 2026 · GDPR Art. 28 compliant
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the dental practice ("Controller") and DentaPro Ltd ("Processor"). By accepting the Terms of Service at registration, the Controller enters into this DPA. No separate signature is required.
Data Controller
The Dental Practice
The clinic or practice that creates an account on Dental Assistant Pro. Identified by the practice name and email provided at registration.
Data Processor
DentaPro Ltd
1. Definitions
Terms used in this DPA have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"). "Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Sub-processor" and "Supervisory Authority" have their GDPR meanings.
2. Subject Matter and Duration
The Processor provides practice management software (the "Service") to the Controller under the Terms of Service. This DPA governs all Processing of Personal Data carried out by the Processor on behalf of the Controller in connection with the Service.
This DPA remains in force for the duration of the Terms of Service and terminates automatically upon account deletion, subject to the data retention obligations in Section 9.
3. Nature and Purpose of Processing
The Processor processes Personal Data for the sole purpose of providing the Service, which includes:
- Storing and retrieving patient records, appointments, invoices, prescriptions, and clinical notes
- Enabling the patient portal for patients to view their own records
- Sending appointment reminders and notifications configured by the Controller
- Generating reports and analytics for the Controller's practice
- Providing technical support and maintaining service security
4. Categories of Personal Data and Data Subjects
| Category | Types of Data | Data Subjects |
Patient health data (Special category — Art. 9) |
Name, date of birth, contact details, medical history, allergies, medications, diagnoses, treatment plans, prescriptions, X-rays, consent records, clinical notes |
Patients of the Controller's practice |
| Staff data |
Name, email address, role, login timestamps, audit logs |
Dentists, nurses, receptionists, and other staff added by the Controller |
| Communication data |
Portal messages, appointment requests, reminder messages |
Patients communicating via the patient portal |
5. Obligations of the Controller
The Controller agrees to:
- Ensure it has a valid legal basis for processing each category of personal data before entering it into the Service
- Obtain all necessary consents from patients and staff before their data is processed
- Ensure its instructions to the Processor comply with applicable law
- Notify affected individuals of any data breach in accordance with GDPR Art. 34
- Maintain records of processing activities as required by GDPR Art. 30
- Not instruct the Processor to process data in a way that would violate GDPR or other applicable law
6. Obligations of the Processor
The Processor agrees to:
- Process only on instructions. Process Personal Data only on documented instructions from the Controller, except where required by law.
- Confidentiality. Ensure that all personnel authorised to process Personal Data are bound by confidentiality obligations.
- Security. Implement appropriate technical and organisational measures as described in Section 7.
- Sub-processors. Not engage sub-processors without prior written authorisation, and ensure sub-processors are bound by equivalent obligations (see Section 8).
- Data subject rights. Assist the Controller in fulfilling obligations to respond to data subject requests, to the extent technically feasible.
- Security assistance. Assist the Controller in ensuring compliance with GDPR Arts. 32–36 (security, breach notification, impact assessments).
- Deletion or return. At the Controller's choice, delete or return all Personal Data upon termination of the Service, and delete existing copies unless retention is required by law.
- Audit. Make available information necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice and confidentiality.
7. Security Measures
The Processor maintains the following technical and organisational security measures:
- Encryption at rest: AES-256 encryption for all stored data
- Encryption in transit: TLS 1.2 or higher for all data transmissions
- Access control: Role-based access control; staff can only access data within their assigned practice
- Tenant isolation: Row-level security (RLS) in the database ensures each practice's data is strictly isolated
- Authentication: Secure hashed passwords; two-factor authentication available
- Backups: Automated daily backups with 30-day retention, stored encrypted
- Infrastructure: Hosted on AWS EU West (Ireland); SOC 2 Type II certified infrastructure
- Access logging: Audit logs for all administrative and data access events
- Vulnerability management: Regular dependency updates and security patching
8. Sub-processors
The Controller hereby provides general authorisation to engage the following sub-processors. The Processor will notify the Controller of any intended change (addition or replacement) with at least 14 days' notice, giving the Controller the opportunity to object.
| Sub-processor | Purpose | Location | DPA reference |
| Amazon Web Services (AWS) | Cloud hosting, database (RDS), file storage (S3) | EU West — Ireland | AWS GDPR DPA |
| Stripe Inc. | Payment processing | EU / USA (SCCs) | Stripe DPA |
| SendGrid / Twilio | Transactional email delivery | EU / USA (SCCs) | Twilio DPA |
For transfers outside the EEA (Stripe, SendGrid), appropriate safeguards are in place via Standard Contractual Clauses (SCCs) as approved by the European Commission.
9. Data Retention and Deletion
Upon termination of the Service:
- The Processor will retain Personal Data for 90 days to allow the Controller to request export
- After 90 days, all Personal Data will be securely and permanently deleted from production systems
- Backup copies may persist for up to 30 additional days before automatic deletion
- The Controller may request immediate deletion by contacting privacy@dentapro.org
- Certain data may be retained longer if required by applicable law (e.g. financial records)
10. Data Breach Notification
In the event of a Personal Data breach, the Processor will:
- Notify the Controller without undue delay and where feasible within 48 hours of becoming aware of the breach
- Provide available information including: the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed
- Cooperate with the Controller in notifying the relevant Supervisory Authority within the GDPR 72-hour window
The Controller is responsible for notifying affected data subjects as required by GDPR Art. 34.
11. Data Subject Rights
Where a data subject submits a request directly to the Processor, the Processor will forward the request to the Controller within 5 business days. The Controller is responsible for fulfilling data subject rights requests (access, rectification, erasure, portability, restriction, objection).
The Processor will provide reasonable technical assistance to help the Controller fulfil these requests, including data exports or deletion within the Service.
12. Liability
Each party is liable for any damages caused by processing in breach of this DPA or GDPR for which that party is at fault. The Processor's liability under this DPA is subject to the limitations set out in the Terms of Service.
13. Governing Law
This DPA is governed by the laws of Cyprus. Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the courts of Cyprus.
14. Contact and Amendments
For questions about this DPA, data subject rights requests, or to report a security concern: privacy@dentapro.org
The Processor may update this DPA from time to time to reflect changes in sub-processors, applicable law, or security measures. Controllers will be notified of material changes with at least 14 days' notice. Continued use of the Service after that date constitutes acceptance.