Data Processing Agreement
Sommaire
1. The Parties, and the Place of the Present Agreement in the Contract
1.1. The present Data Processing Agreement (the "DPA") is concluded between the dental clinic, dental practice, or other professional undertaking that subscribes to the Service (the "Controller", "Clinic", or "you") and DTCONCIERGE S.R.L., a limited liability company incorporated under the laws of Romania, with registered office at Aleea Călărașilor nr. 5, bl. G, ap. 54, Municipiul Sibiu, județul Sibiu, Romania, registered with the Trade Register under number J2026003869000, unique registration code 53369247, intra-Community VAT identification number RO54852877, operator of the DentalPolyglot service (the "Processor", "Provider", "we", or "us").
1.2. The DPA is concluded in satisfaction of Article 28(3) of Regulation (EU) 2016/679 (the "GDPR"), which requires the processing carried out by a processor on behalf of a controller to be governed by a contract binding the processor to the controller. Article 28(9) of the GDPR permits that contract to be concluded in electronic form, and the parties have chosen that form.
1.3. The DPA forms part of the Agreement described in Section 1.3 of the Terms of Service. Acceptance is recorded before any processing of Patient Data is enabled. On a paid Plan and on a paid upgrade of the Conversation Layer, acceptance is given clause by clause and is recorded on the Provider's servers before payment is authorised, and the subscription flow does not complete without it. On the free tier of the Conversation Layer, the DPA is presented and accepted as a distinct instrument rather than by reference within a general acceptance, and that acceptance is likewise recorded.
1.4. Where a conflict arises between the DPA and another document forming the Agreement, the DPA prevails in respect of the processing of Patient Data, as Section 1.4 of the Terms of Service provides. Where the Standard Contractual Clauses referred to in Section 11 are incorporated into a contract between the Provider and a third party, those Clauses prevail over any term of the DPA that would reduce the protection they afford.
1.5. Correspondence concerning the DPA is addressed to privacy@dentalpolyglot.com. Contractual correspondence is addressed to service@dentalpolyglot.com. Both addresses reach a member of staff.
2. Definitions
2.1. Terms defined in the Terms of Service carry the same meaning in the DPA unless the context requires otherwise. In particular, "Service", "Tenant Site", "Tenant Materials", "Plan", and "Authorised User" have the meanings given in Section 2 of the Terms of Service.
2.2. "Patient Data" means personal data relating to patients and prospective patients of the Clinic that is submitted to, generated within, or transmitted through the Service, including data concerning health and other special categories of personal data within the meaning of Article 9(1) of the GDPR.
2.3. "Applicable Data Protection Law" means the GDPR, Romanian Law no. 190/2018 on measures implementing Regulation (EU) 2016/679, Romanian Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, and, where the Clinic is established outside the European Economic Area, the data protection law to which the Clinic is subject in respect of the processing.
2.4. "Sub-processor" means a processor engaged by the Provider to carry out a specific processing activity on the Clinic's behalf, within the meaning of Article 28(2) and Article 28(4) of the GDPR.
2.5. "Standard Contractual Clauses" means the standard contractual clauses for the transfer of personal data to third countries set out in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, or any decision replacing them.
2.6. "Restricted Transfer" means a transfer of Patient Data to a country outside the European Economic Area that is not the subject of a decision of the European Commission under Article 45 of the GDPR applicable to that transfer.
2.7. "Personal Data Breach" bears the meaning given in Article 4(12) of the GDPR.
3. The Roles of the Parties
3.1. In respect of Patient Data, the Clinic is the controller within the meaning of Article 4(7) of the GDPR and the Provider is the processor within the meaning of Article 4(8). The Clinic determines the purposes of the processing and its essential means, including what is collected, from whom, for what clinical or commercial end, on what legal basis, and for how long it is kept.
3.2. The Provider determines certain non-essential means of a technical character, such as the architecture of the database, the choice of encryption algorithm, and the design of the interfaces, as the European Data Protection Board contemplates in Guidelines 07/2020 on the concepts of controller and processor in the GDPR. Determination of that kind does not confer the status of controller, and the Provider does not acquire that status in respect of Patient Data by reason of storing it, translating it, indexing it for retrieval, or submitting it to an artificial intelligence system on the Clinic's instruction.
3.3. In respect of the Clinic's own account data, the data of its Authorised Users, its billing data, prospect data, and the technical and security data generated when the Service is operated, the Provider acts as controller. Processing of that kind falls outside the DPA and is described in the Privacy Policy.
3.4. The parties are not joint controllers within the meaning of Article 26 of the GDPR in respect of Patient Data, and neither party may represent the relationship as one of joint control.
3.5. Where the Clinic is itself acting as a processor for a further controller, in particular where a clinic group or a management company subscribes on behalf of individual practices, the Clinic warrants that it holds the authority of that controller to conclude the DPA and to give the instructions it gives, and the Provider is entitled to rely on the warranty without further enquiry.
4. Subject Matter, Nature, Purpose, and Duration
4.1. The subject matter of the processing, its duration, its nature and purpose, the categories of data subjects, the types of personal data concerned, and the frequency of the processing are set out in Annex A, which forms part of the DPA and satisfies the description required by Article 28(3) of the GDPR.
4.2. The DPA takes effect on the date acceptance is recorded and continues for as long as the Provider processes Patient Data on the Clinic's behalf.
4.3. Termination of the Terms of Service does not terminate the DPA. Obligations relating to security, confidentiality, deletion, return, and assistance survive until the deletion or return described in Section 15 has been completed, and obligations that by their nature are intended to survive continue thereafter.
5. Processing on Documented Instructions
5.1. The Provider processes Patient Data only on the Clinic's documented instructions, in accordance with Article 28(3)(a) of the GDPR. The Clinic's documented instructions comprise the Agreement, the DPA and its annexes, the configuration the Clinic selects in the dashboard, including its language selections, its retention settings, and its activation or non-activation of optional channels, and any further instruction the parties record in writing.
5.2. Where Union or Member State law to which the Provider is subject requires processing beyond those instructions, the Provider informs the Clinic of the requirement before processing, unless the law concerned prohibits that information on important grounds of public interest.
5.3. An instruction that falls outside the ordinary functionality of the Service is accepted only where it is technically feasible, lawful, and compatible with the security of the Service and with the isolation of other clinics' data. The Provider may decline such an instruction, and may make its execution conditional on the reimbursement of the cost of performing it, having first notified the Clinic of that cost.
5.4. Where the Provider considers an instruction to infringe the GDPR or another provision of Union or Member State data protection law, it informs the Clinic immediately, in accordance with the final subparagraph of Article 28(3) of the GDPR. Pending resolution of the matter, the Provider may suspend execution of the instruction concerned, and suspension of that kind is not a breach of the Agreement.
5.5. The Clinic must not instruct the Provider to process a national identification number, which in Romania is the personal numerical code, on the basis of the legitimate interests of the controller under Article 6(1)(f) of the GDPR. Article 4 of Law no. 190/2018 attaches to processing carried out on that basis a cascade of additional safeguards, including the mandatory designation of a data protection officer, and an instruction of that kind therefore falls outside the scope of the Provider's authority to act.
5.6. The Provider ensures that persons acting under its authority who have access to Patient Data process it only on the Clinic's instructions, in satisfaction of Article 29 and Article 32(4) of the GDPR.
5.7. Patient Data is not used by the Provider for any purpose of its own, is not sold, and is not disclosed to an advertising network. The separate undertaking obtained from the artificial intelligence provider, excluding the content submitted to it from the training and improvement of models, is dealt with in Section 18.2.
6. The Clinic's Obligations and Warranties
6.1. The Clinic warrants that it holds, for every category of Patient Data it causes to be processed through the Service, a valid legal basis under Article 6 of the GDPR and, in respect of data concerning health and other special categories, a valid condition under Article 9(2) of the GDPR.
6.2. The condition in Article 9(2)(h) of the GDPR, concerning medical diagnosis and the provision of health care or treatment, applies only where the processing is carried out by or under the responsibility of a professional subject to the obligation of professional secrecy referred to in Article 9(3). The condition is satisfied by the Clinic and by its clinical personnel. It is never satisfied by the Provider, whose personnel are not health professionals and are not bound by professional secrecy within the meaning of that provision. The point is recorded expressly so that no Clinic selects its lawful basis on an assumption to the contrary, and Section 7.3 states the consequence for the Provider's own staff.
6.3. Providing patients with the information required by Articles 12, 13, and 14 of the GDPR is the Clinic's obligation as controller. The Provider maintains and keeps current the Patient Privacy Notice Template, and makes it available together with the sub-processor particulars and transfer mechanisms it contains, as a technical and organisational measure assisting the Clinic under Article 28(3)(e) and Article 28(3)(f) of the GDPR and under Section 12.4 of the Terms of Service. Adoption of the template, completion of the fields reserved to the Clinic, and the accuracy of the resulting notice remain the Clinic's responsibility.
6.4. The Clinic must not collect, or instruct the collection of, Patient Data that exceeds what is necessary for the purposes it has determined, in accordance with Article 5(1)(c) of the GDPR. Where a form, a message field, or an upload facility invites more than the purpose requires, the reduction is a matter for the Clinic, and the Provider will assist with the configuration on request.
6.5. Access rights within the Clinic's account are determined by the Clinic. Granting access only to persons who require it, withdrawing access promptly when it ceases to be required, and supervising the conduct of Authorised Users are obligations of the Clinic as controller.
6.6. Where the Clinic asks the Provider to add a component of the Clinic's own choosing to the Tenant Site, whether an analytics product, a chat widget supplied by a third party, an embedded player, or a comparable tool, the Clinic is the controller of the resulting processing and bears responsibility for any consent that component requires, as Section 8.2 of the Cookie Policy provides.
6.7. Where the Clinic is established outside the European Economic Area and offers services to, or monitors the behaviour of, patients located within it, the Clinic's own processing falls within the territorial scope of the GDPR under Article 3(2), and the Clinic should consider whether Article 27 obliges it to designate a representative in the Union. The Provider does not act as that representative, and nothing in the DPA appoints it to that function.
7. Confidentiality of Personnel
7.1. The Provider ensures that persons authorised to process Patient Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, in satisfaction of Article 28(3)(b) of the GDPR.
7.2. Access is granted on the principle of least privilege, is reviewed periodically, and is withdrawn when the function that justified it ends. Personnel with access receive instruction appropriate to their role, covering the handling of data concerning health, the recognition of a suspected breach, and the routing of a request received from a patient.
7.3. The obligation described in Section 7.1 is contractual. The Provider's personnel are not subject to the professional secrecy regime applicable to health professionals, and the Provider states the position candidly rather than allowing the Clinic to assume a protection that does not exist. The consequence for the Clinic's selection of a condition under Article 9(2) is set out in Section 6.2.
7.4. Confidentiality obligations continue after the individual concerned ceases to perform the function and after the DPA ends.
8. Security of the Processing
8.1. The Provider implements the technical and organisational measures set out in Annex C, which are appropriate to the risk within the meaning of Article 32(1) of the GDPR and which take account of the state of the art, the cost of implementation, and the nature, scope, context, and purposes of the processing.
8.2. Assessment of the risk takes into account that the processing concerns data concerning health, that a Personal Data Breach affecting such data carries a heightened risk to the rights and freedoms of the patients concerned, and that the Service holds the data of several clinics on shared infrastructure.
8.3. The measures in Annex C may be varied as the Service, the threat environment, and the state of the art develop. A variation may not reduce the overall level of security, and a variation that materially alters the measures described is notified to the Clinic under Section 21.2.
8.4. Security is a shared undertaking. Choosing what to collect, protecting authentication credentials, securing the devices from which the dashboard is reached, enabling second-factor authentication where offered, and withdrawing access from departing personnel are measures within the Clinic's control, and the Provider is not responsible for a compromise attributable to their absence.
8.5. The Provider tests, assesses, and evaluates the effectiveness of the measures periodically, in accordance with Article 32(1)(d) of the GDPR, and records the outcome.
9. Special Categories of Data, Identity Documents, and Minimisation
9.1. Data concerning health reaches the Service through several routes: the free text a patient writes in an enquiry form or a message, the diagnoses and per-tooth findings recorded in a treatment plan, the documents a patient uploads, including radiographs and referral letters, and the content of any translated thread. Each of those routes is treated as carrying special categories of personal data by default, and the security measures in Annex C apply to all of them without distinction.
9.2. Identity documents and insurance documents may contain a national identification number. Section 5.5 records the instruction the Clinic may not give in respect of such a number, and the Clinic should satisfy itself that its own basis for processing it is available under the law of its country of establishment.
9.3. The Provider recommends, without imposing, that identity documents and insurance documents be requested only once a treatment pathway has been established and a specific need has arisen, rather than at the enquiry stage, since a document collected before the need for it exists is difficult to justify under Article 5(1)(c) of the GDPR and enlarges the consequences of any breach.
9.4. Patient Data is not indexed, aggregated, or analysed by the Provider for any purpose of its own, is not used to construct profiles of patients, and is not disclosed to another clinic. Isolation between clinics is enforced at the database level as Annex C describes.
9.5. Free-text fields cannot be constrained by design without diminishing their usefulness to the patient. Where the Clinic becomes aware that patients are supplying more than the purpose requires, whether in a form or in a message, the Clinic should amend its prompts and its just-in-time notices accordingly, and the Provider will assist with the wording.
10. Sub-Processors
10.1. The Clinic grants a general authorisation, within the meaning of Article 28(2) of the GDPR, for the engagement of the sub-processors listed in Annex B. The general authorisation is one of the clauses subject to separate acceptance under Article 1203 of the Romanian Civil Code, as Section 4.3 and Section 14.2 of the Terms of Service provide.
10.2. The Provider gives the Clinic at least thirty days' notice before adding or replacing a sub-processor, stating the identity of the provider concerned, the function it will perform, the categories of Patient Data it will process, the location of the processing, and the transfer mechanism where the processing occurs outside the European Economic Area. Within that period the Clinic may object on reasonable grounds relating to data protection. Where the objection cannot be resolved, the Clinic may terminate the affected part of the Service without penalty, with reimbursement of any prepaid fee attributable to the unexpired period, in accordance with Section 14.3 of the Terms of Service and Section 12 of the Refund and Cancellation Policy.
10.3. Each sub-processor is engaged under a written contract imposing obligations no less protective than those imposed on the Provider by the DPA, in accordance with Article 28(4) of the GDPR. The Provider remains fully liable to the Clinic for the performance of each sub-processor's data protection obligations.
10.4. The Provider maintains, and supplies to the Clinic on request, the name, the address, and the contact details of every sub-processor engaged in the processing of Patient Data, together with the information the Clinic needs in order to satisfy itself that sufficient guarantees are offered throughout the chain. Supplying that information reflects the position taken by the European Data Protection Board in Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s), adopted on 7 October 2024, under which a controller must have readily available the identity of every processor and sub-processor in the chain, and must be able to verify the guarantees they offer, whatever the level of risk. The Clinic is not obliged to obtain the sub-processing contracts themselves, and assesses instead whether it needs them in order to demonstrate its own compliance.
10.5. Each provider listed in Annex B engages providers of its own, and the chain therefore extends beyond the parties named there. Every provider in Annex B publishes its own list, the Provider monitors those lists as part of the review described in Annex C, and the addresses at which they are published are supplied to the Clinic on request. A change further down the chain that materially alters the location of the processing or the transfer mechanism is treated as a change requiring notice under Section 10.2.
10.6. Where a sub-processor discontinues its service, changes its terms materially, or ceases to satisfy the Provider's requirements, and the urgency of the situation does not permit thirty days' notice, the Provider may substitute an equivalent provider on the shortest notice reasonably practicable, and then supplies a full explanation together with the particulars listed in Section 10.2.
10.7. Two providers used in the operation of the Service are not sub-processors of Patient Data, and Annex B records the reason in each case. The payment provider receives the Clinic's billing data alone, and no Patient Data reaches it. The screenshot service receives the address of the Clinic's own public website and returns an image of it, and no Patient Data and no personal data of the Clinic's personnel is transmitted to it.
11. Transfers Outside the European Economic Area
11.1. The application and the primary database are located in the European Union, in the Frankfurt region. Patient Data is stored there, and a transfer outside the European Economic Area occurs only where Annex B records it.
11.2. Where the Provider transfers Patient Data to a sub-processor established in a third country that is not the subject of an adequacy decision applicable to that transfer, the transfer is made on the basis of the Standard Contractual Clauses, applying the module governing transfers from a processor to a sub-processor. The Provider concludes those Clauses as data exporter in its own name, acting on the Clinic's instruction and with the authorisation the Clinic gives in Section 10.1, and a copy of the executed Clauses, with commercially sensitive terms redacted, is supplied on request to privacy@dentalpolyglot.com.
11.3. Where a sub-processor maintains a current certification under the EU-US Data Privacy Framework, the transfer may be made in reliance on Commission Implementing Decision (EU) 2023/1795 of 10 July 2023. Certifications are verified against the official list published at https://www.dataprivacyframework.gov before reliance is placed on them, and are reverified at each review of the DPA. The General Court dismissed the action for annulment brought against that decision on 3 September 2025 in Case T-553/23, Latombe v Commission, and an appeal against that judgment, registered as Case C-703/25 P, is pending before the Court of Justice at the date of the present version. Because the outcome of the appeal cannot be anticipated, the Standard Contractual Clauses are concluded in addition wherever a certification is relied upon, so that a mechanism remains in place should the certification lapse or the decision cease to apply.
11.4. Artificial intelligence processing for translation, for extraction of treatment-plan text, and for the conversational assistant is engaged from Anthropic Ireland, Limited, which is the entity contracting with customers established in the European Economic Area, and is carried out on infrastructure operated in the United States by Anthropic, PBC. Neither entity maintains a certification under the EU-US Data Privacy Framework, and no adequacy decision is relied upon in respect of those transfers, which rest on the Standard Contractual Clauses alone. At the date of the present version, no processing region within the European Union is offered for the interface the Service uses, and the Provider reassesses the position at each review.
11.5. For every Restricted Transfer, the Provider has assessed the law and practice of the destination country as they bear on the effectiveness of the mechanism relied upon, and applies supplementary measures where the assessment calls for them. Measures applied include encryption in transit, minimisation of the data actually transmitted, removal of personal data from diagnostic records before transmission, contractual commitments concerning requests for access by public authorities, and the contractual exclusion of the use of transmitted content for the training or improvement of models.
11.6. Responsibility for the assessment does not rest with the Provider alone. As controller, the Clinic must be in a position to demonstrate to its own supervisory authority that the transfers carried out on its behalf are lawful, and the Provider therefore supplies the documentation on which that demonstration rests, including the transfer map, the assessment described in Section 11.5, and the particulars listed in Section 10.4.
11.7. Onward transfer by a sub-processor to a further recipient in a third country is permitted only where a valid mechanism under Chapter V of the GDPR covers it, and the obligation to secure such a mechanism is imposed on the sub-processor by the contract described in Section 10.3.
11.8. Independently of the GDPR, Article 32 of Regulation (EU) 2023/2854 obliges the Provider to take adequate technical, organisational, and legal measures to prevent international and third-country governmental access to, or transfer of, non-personal data held in the Union where such access or transfer would conflict with Union law or with the national law of a Member State. The measures described in Section 11.5 serve that obligation as well.
12. Assistance With Requests From Patients
12.1. Taking account of the nature of the processing, the Provider assists the Clinic by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Clinic's obligation to respond to requests for the exercise of the rights conferred by Chapter III of the GDPR, in accordance with Article 28(3)(e).
12.2. Assistance is delivered principally through the functions built into the Service, which allow the Clinic to retrieve an enquiry and its associated thread, to export the content and the documents attached to it in a structured, commonly used, and machine-readable format, to correct a record, and to delete a record together with its attachments. Where a request cannot be satisfied through those functions, the Provider acts on the Clinic's written instruction.
12.3. Where a patient addresses a request directly to the Provider, the Provider does not answer it on the merits. The request is forwarded to the Clinic without undue delay and in any event within five business days, the patient is informed that the request has been forwarded and is given the Clinic's contact details, and the Provider retains a record of the forwarding.
12.4. The Provider responds to a request for assistance from the Clinic without undue delay and, where the Clinic states the deadline applicable to it under Article 12(3) of the GDPR, in time to allow that deadline to be met.
12.5. No charge is made for assistance of the kind described in Sections 12.2 to 12.4. Where a request requires engineering work materially exceeding that ordinary assistance, Section 5.3 applies.
13. Assistance With Security, Impact Assessments, and Prior Consultation
13.1. The Provider assists the Clinic in ensuring compliance with the obligations in Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to it, in accordance with Article 28(3)(f).
13.2. Processing of data concerning health on a large scale is listed in Article 35(3)(b) of the GDPR among the cases requiring a data protection impact assessment, and appears likewise in the list adopted by the Romanian supervisory authority in Decision no. 174/2018, published in Monitorul Oficial no. 919 of 31 October 2018. Whether the threshold is met is a question for the Clinic on the facts of its own practice, and the Provider does not answer it. Where the Clinic carries out an assessment, the Provider supplies the description of the processing operations, the security measures in Annex C, the sub-processor particulars, and the transfer documentation, and answers reasonable questions on the technical architecture.
13.3. Where the Clinic is required to consult its supervisory authority under Article 36 of the GDPR, the Provider supplies the information the authority requests of it through the Clinic, and cooperates with the consultation.
13.4. The Provider does not carry out the impact assessment on the Clinic's behalf, does not sign it, and does not certify the Clinic's compliance. Assessment and sign-off are functions of the controller and, where one is designated, of its data protection officer.
14. Personal Data Breaches
14.1. The Provider notifies the Clinic of a Personal Data Breach affecting Patient Data without undue delay after becoming aware of it, and in any event within forty-eight hours, in accordance with Article 33(2) of the GDPR. Notification is sent to the address recorded in the Clinic's account and, where the circumstances warrant it, is followed by a telephone call.
14.2. The notification describes the nature of the breach, including where possible the categories and approximate number of data subjects and of records concerned, the likely consequences, the measures taken or proposed to address the breach and to mitigate its effects, and the point of contact from which further information may be obtained. Where the information is not available in full at the time of the first notification, it is supplied in phases without undue further delay, and the Provider states in each notification what remains outstanding.
14.3. The Provider does not notify the supervisory authority, and does not communicate with the affected patients, on the Clinic's behalf, unless the Clinic instructs it in writing to do so. Deciding whether the notification required by Article 33(1) and the communication required by Article 34 of the GDPR are due is a function of the controller.
14.4. The Provider cooperates with the Clinic in investigating, containing, and remediating a breach, supplies the technical particulars the Clinic requires for its own notification, and preserves the evidence relevant to the incident.
14.5. A breach occurring at a sub-processor is treated as a breach affecting the Provider for the purposes of Section 14, and the notification period runs from the moment the Provider becomes aware of it.
14.6. Every breach is recorded, whether or not it becomes notifiable, together with the facts, the effects, and the remedial action taken, and the record is made available to the Clinic on request.
15. Deletion and Return at the End of the Services
15.1. At the end of the provision of services relating to processing, the Provider deletes or returns Patient Data at the Clinic's choice, in accordance with Article 28(3)(g) of the GDPR. The ninety-day read-only window described in Section 22.2 of the Terms of Service is the period during which the Clinic exercises that choice and retrieves its data.
15.2. Absent an instruction within the ninety-day window, the Provider deletes the Patient Data at the end of it. Deletion extends to the copies held in the live systems, including uploaded documents held in file storage and the indexes referring to them.
15.3. Two backup mechanisms operate, and their consequences for deleted data differ. The primary database maintains a continuous recovery window of approximately six hours. An encrypted nightly snapshot is taken in addition, held outside the platform on which the Service runs under AES-256-GCM encryption, and retained for thirty days from the date it is taken, after which it is destroyed. Deleted Patient Data accordingly ceases to be recoverable from the continuous window once six hours have elapsed, and ceases to be recoverable from the snapshots once the last snapshot containing it has been destroyed, which occurs within thirty days of the deletion.
15.4. A snapshot is used only to recover from a failure, a corruption, or a comparable incident affecting the live systems. It is not consulted in order to retrieve a record that has been deleted, and is not used to reinstate data whose erasure the Clinic or a patient has caused. Where a restoration nevertheless reinstates a record deleted before the incident, the deletion is applied again to the restored system as soon as the restoration is complete, and the event is entered in the Provider's records.
15.5. Deletion does not extend to data the Provider is required to retain by Union or Member State law. Data retained on that ground is isolated, is protected by the measures in Annex C, is processed for no purpose other than the one that requires its retention, and is deleted when the requirement ends.
15.6. The Provider confirms the completion of deletion in writing on request.
15.7. Export is free of charge, and no charge is levied for retrieving Patient Data, for using the export tooling, or for assistance during the transitional period, in accordance with Article 29 and Article 30 of Regulation (EU) 2023/2854 and with Section 17 of the Terms of Service. Exportable material comprises message threads, treatment-plan documents, uploaded files, appointment records, and the content of the Tenant Site.
16. Audits, and Information to Demonstrate Compliance
16.1. The Provider makes available to the Clinic the information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allows for and contributes to audits, including inspections, conducted by the Clinic or by an auditor mandated by it, in accordance with Article 28(3)(h).
16.2. In the ordinary case the obligation is discharged by documentation, comprising the security measures in Annex C, the description of the processing in Annex A, the sub-processor particulars in Annex B and in Section 10.4, the transfer documentation described in Section 11.6, the record maintained under Article 30(2) of the GDPR insofar as it concerns the Clinic, and any third-party assessment or certification the Provider holds. Documentation is supplied within thirty days of a written request and free of charge.
16.3. Where the documentary route does not answer a specific and reasoned concern, the Clinic may conduct an audit on site or remotely, on not less than thirty days' written notice, no more than once in any period of twelve consecutive months, and at a time agreed between the parties. The scope is limited to the processing carried out on the Clinic's behalf. An auditor mandated by the Clinic must not be a competitor of the Provider and must accept confidentiality obligations at least as protective as those in Section 23 of the Terms of Service. Access is not granted to the data of other clinics, to material subject to the confidentiality of a third party, or to information whose disclosure would compromise the security of the Service.
16.4. The limits in Section 16.3 do not apply where an audit is required by a competent supervisory authority, where it follows a Personal Data Breach affecting the Clinic's Patient Data, or where a mandatory provision of Applicable Data Protection Law requires otherwise. In each of those cases the audit proceeds on the terms the authority or the provision requires.
16.5. The Provider bears its own cost of the documentary route described in Section 16.2. The Clinic bears the cost of an audit it initiates under Section 16.3, including the reasonable cost of the Provider's participation, unless the audit reveals a material failure by the Provider to comply with the DPA, in which case the Provider bears that cost.
17. Records of Processing Activities
17.1. The Provider maintains a record of the categories of processing carried out on behalf of its controllers, in accordance with Article 30(2) of the GDPR.
17.2. Because the Provider processes special categories of personal data on behalf of controllers, the derogation in Article 30(5) of the GDPR for undertakings employing fewer than 250 persons is not available to it, and the record is maintained irrespective of the Provider's size.
17.3. The record is made available to a supervisory authority on request, in accordance with Article 30(4), and the extract concerning the Clinic is supplied to the Clinic on request.
17.4. Maintaining the record required of a controller by Article 30(1) in respect of Patient Data is the Clinic's obligation, and the Provider supplies the particulars needed for the entries that concern the Service.
18. Processing by Artificial Intelligence Systems
18.1. Artificial intelligence is used within the Service to translate the content of the Tenant Site and the messages exchanged between the Clinic and a patient, to extract text from treatment-plan documents, and to operate a conversational assistant on the Tenant Site. The models are supplied by the provider identified in Annex B, engaged as a sub-processor.
18.2. Content submitted to that provider is excluded by contract from use in training or improving models. The exclusion is a term of the processing, and a change to it would be a change of a material character requiring notice under Section 21.2.
18.3. No function of the Service takes a decision producing legal effects concerning a patient, or similarly significantly affecting a patient, based solely on automated processing within the meaning of Article 22 of the GDPR. Translation, extraction, and conversational assistance do not evaluate a patient, do not score a patient, and do not determine an outcome concerning a patient.
18.4. The conversational assistant discloses that it is an artificial intelligence system, clearly and in a manner distinguishable from the surrounding content, at the latest at the time of the first interaction, in satisfaction of Article 50(1) and Article 50(5) of Regulation (EU) 2024/1689. Those obligations have applied since 2 August 2026 and were not postponed by Regulation (EU) 2026/1744, which entered into force on 27 July 2026 and which deferred the application of the requirements attaching to high-risk systems. Messages rendered by automatic translation are labelled where they are displayed.
18.5. The Clinic must not disable, obscure, relabel, or otherwise defeat the disclosure described in Section 18.4, must not represent the assistant as a human interlocutor or as a clinician, and must not configure it with material that would cause it to triage, to diagnose, to recommend or to exclude treatment, or to give advice of a clinical nature.
18.6. Output produced by an artificial intelligence system may contain errors, omissions, and mistranslations. Review of any output on which a clinical, contractual, or regulatory decision is to rest is the Clinic's responsibility, and Section 7.4 and Section 13.6 of the Terms of Service apply to it.
19. The WhatsApp Channel
19.1. An optional relay of patient messages over the WhatsApp Business Platform has been built but is not activated. Until a Clinic activates it, no message is relayed through that channel, no Patient Data is disclosed to the provider of it, and the provider is not a sub-processor of that Clinic's Patient Data.
19.2. Activation is a decision for the individual Clinic and takes effect for that Clinic alone. On activation, WhatsApp Ireland Limited becomes a sub-processor in respect of the telephone number, the message content, and the media transmitted through the channel, under the WhatsApp Business Data Processing Terms and the WhatsApp Business Data Transfer Addendum published by that provider.
19.3. The terms published by that provider at the date of the present version designate it as processor in respect of the messages a business sends and receives. Because a messaging network of that kind may process related data outside the scope of those terms, and because the terms may be revised, the Provider verifies the position afresh before enabling the channel for a Clinic and supplies the Clinic with the then current particulars. The Clinic assesses, as controller, whether the resulting processing is compatible with the basis on which it holds the patient's data.
19.4. Before activating the channel, the Clinic must obtain the patient's informed agreement to be contacted through it, must render the WhatsApp block of the Patient Privacy Notice Template, and must reflect the channel in the just-in-time notice presented at the point where the patient elects to use it.
19.5. Annex B records the channel as contingent. Activation for a Clinic does not require the notice described in Section 10.2, because the addition is made at that Clinic's own request and affects that Clinic alone, and the particulars are instead supplied at the moment of activation.
20. Liability
20.1. Liability under the DPA is subject to the limitations in Section 20 of the Terms of Service, save to the extent that Applicable Data Protection Law does not permit those limitations to apply.
20.2. Article 82(2) of the GDPR renders a processor liable for the damage caused by processing only where it has not complied with obligations of the Regulation specifically directed to processors, or where it has acted outside or contrary to lawful instructions of the controller. Nothing in the DPA extends that liability, and nothing in it excludes liability the Regulation imposes.
20.3. Where one party has paid compensation in full for damage to which both contributed, it may claim back from the other the part corresponding to that other's responsibility, in accordance with Article 82(5) of the GDPR.
20.4. The Clinic indemnifies the Provider against any loss, claim, penalty, or expense arising from an instruction that infringes Applicable Data Protection Law, from the absence of a valid legal basis for Patient Data submitted to the Service, or from a failure to give patients the information required by Articles 12 to 14 of the GDPR, save to the extent the Provider caused or contributed to the loss.
20.5. Nothing in Section 20 limits or excludes any right of a data subject under Article 79 or Article 82 of the GDPR, or the power of a supervisory authority.
21. Term, Amendment, and Publication
21.1. The DPA remains in force for the period stated in Section 4.2.
21.2. The Provider may amend the DPA in order to reflect a change in Applicable Data Protection Law, a decision or guidance of a competent authority, a change in the Service, or a change in the sub-processors engaged. A material amendment is notified to the Clinic at its registered email address at least thirty days before it takes effect, and the notice identifies what is changing. Amendments to Annex B follow the notice and objection route in Section 10.2 rather than the route in Section 21.2.
21.3. Where the European Commission adopts a decision replacing the Standard Contractual Clauses, the replacement clauses apply to transfers made after the date on which they become applicable, and the Provider concludes them with the sub-processors concerned within the transition period the decision allows.
21.4. Where a provision of the DPA is held invalid, unlawful, or unenforceable, it is severed to the minimum extent necessary and the remainder continues in force. The parties will agree a replacement provision achieving the original purpose so far as the law allows.
21.5. The version in force, with the date of its last revision, is published on this page. Superseded versions are retained and supplied on request to privacy@dentalpolyglot.com, so that the Clinic may establish which version applied at a given time.
22. Governing Law, and Supervisory Authority
22.1. The DPA is governed by the law of Romania, and the courts of Sibiu have jurisdiction over disputes arising out of or in connection with it, in accordance with Section 27 of the Terms of Service and subject to any mandatory rule that confers jurisdiction elsewhere.
22.2. Where the Standard Contractual Clauses are incorporated into a contract concluded by the Provider with a sub-processor, the law and the forum designated in those Clauses govern the Clauses themselves, and Section 22.1 does not displace that designation.
22.3. The Provider's lead supervisory authority is the National Supervisory Authority for Personal Data Processing of Romania, at B-dul General Gheorghe Magheru nr. 28-30, Sector 1, 010336 Bucharest, Romania, reachable at anspdcp@dataprotection.ro and at https://www.dataprotection.ro. The Clinic's own supervisory authority is determined by its establishment, and the Provider cooperates with it under Article 31 of the GDPR.
22.4. The Provider has not designated a data protection officer. The reasoning supporting that position, the triggers on which it is reconsidered, and the standing privacy contact are set out in Section 16 of the Privacy Policy. The address privacy@dentalpolyglot.com is the privacy contact and is not a data protection officer within the meaning of Article 37 of the GDPR.
Annex A: Description of the Processing
Annex A is drawn up in satisfaction of the description required by Article 28(3) of the GDPR and reproduces, for the purposes of the Standard Contractual Clauses referred to in Section 11, the particulars that Annex I to those Clauses requires.
- Subject matter: Provision of the DentalPolyglot service to the Clinic, comprising the hosted multilingual Tenant Site, the inbound enquiry workflow attached to it, and, where the Clinic uses it, the Conversation Layer plugin installed on the Clinic's own website.
- Nature of the processing: Collection, recording, organisation, structuring, storage, adaptation, translation, retrieval, consultation, use, disclosure by transmission, restriction, erasure, and destruction.
- Purpose of the processing: Receiving and storing patient enquiries; translating enquiries, replies, and site content; operating a two-way translated message thread; generating, storing, and displaying multilingual treatment-plan documents; extracting text from treatment-plan documents; storing documents uploaded by a patient; operating the page on which a visit is arranged from a treatment plan; delivering transactional electronic mail, including confirmations and appointment reminders; operating a conversational assistant on the Tenant Site; and securing the Service against abuse.
- Categories of data subjects: Patients and prospective patients of the Clinic, including persons who submit an enquiry without becoming patients, and, where a patient supplies them, persons connected with the patient such as a parent, a guardian, or an accompanying person.
- Categories of personal data: Identification and contact particulars, including name, email address, telephone number, and country of residence; the content of enquiries, chat messages, and message threads, in the original language and in translation; appointment particulars; correspondence metadata; technical identifiers, including internet protocol address and request metadata, processed for security and rate limiting; and the language and currency preferences a visitor selects.
- Special categories of personal data: Data concerning health, comprising diagnoses and per-tooth findings recorded in treatment plans, clinical descriptions supplied by the patient in free text, and medical documents uploaded by the patient such as radiographs and referral letters; and, where the Clinic requests them, identity or insurance documents, which may contain a national identification number.
- Nature of the special-category processing: Storage, translation, extraction of text, display to the Clinic and to the patient, and transmission between them. The data is not analysed, scored, or profiled, and is not used for any purpose of the Provider.
- Frequency of the processing: Continuous, for the duration of the Agreement.
- Duration of the processing: The term of the Agreement, followed by the ninety-day read-only window described in Section 15.1 and the backup cycle described in Section 15.3.
- Retention applied within the Service: An enquiry that does not result in a treatment plan is deleted twenty-four months after the last activity on it. A request for erasure is executed within thirty days of receipt. Where the Clinic instructs a different period in order to meet its own medical-record obligations, the Clinic's instruction governs, and the Clinic remains responsible for the lawfulness of the period it sets.
- Transfers: As recorded in Annex B.
- Competent supervisory authority: For the purposes of Annex I.C to the Standard Contractual Clauses, the supervisory authority of the Member State in which the Clinic is established, or, where the Clinic is not established in the Union, the supervisory authority of the Member State in which the patients concerned are located, in accordance with Clause 13 of those Clauses.
Annex B: Authorised Sub-Processors
The following providers are authorised sub-processors of Patient Data. The general authorisation in Section 10.1 extends to each of them, and a change is notified in accordance with Section 10.2. The particulars stated are those in force at the date of the present version, verified against each provider's own published terms at that date.
Neon, LLC, a company of Databricks, Inc.
- Function: Primary database.
- Location of processing: European Union, Frankfurt region.
- Transfer mechanism: Data at rest in the Union. Residual access from the United States is covered by the provider's certification under the EU-US Data Privacy Framework, with the Standard Contractual Clauses concluded in addition.
- Patient Data processed: All Patient Data held in structured form, including enquiries, message threads, treatment-plan records, and appointment records.
Vercel Inc.
- Function: Application hosting, content delivery, file storage, and bot protection.
- Location of processing: Compute and storage in the European Union, Frankfurt region, with access from the United States possible for support and operational purposes.
- Transfer mechanism: Certification under the EU-US Data Privacy Framework, with the Standard Contractual Clauses concluded in addition under the provider's data processing agreement.
- Patient Data processed: Page traffic to the Tenant Site, and the documents a patient uploads.
Anthropic Ireland, Limited, the entity contracting for the European Economic Area, with the processing carried out by Anthropic, PBC
- Function: Artificial intelligence processing: translation of content and messages, extraction of treatment-plan text, and the conversational assistant.
- Location of processing: United States.
- Transfer mechanism: Standard Contractual Clauses alone. Neither the contracting entity nor the entity carrying out the processing maintains a certification under the EU-US Data Privacy Framework, and no adequacy decision is relied upon.
- Patient Data processed: Message text and treatment-plan text submitted for translation or extraction, and the content of an exchange with the conversational assistant. Content is excluded by contract from use in training or improving models.
Plus Five Five, Inc., trading as Resend
- Function: Delivery of transactional email, and handling of bounces and complaints.
- Location of processing: United States.
- Transfer mechanism: The provider's data processing agreement incorporates the Standard Contractual Clauses and records adherence to the EU-US Data Privacy Framework. Because the certification is not restated in that provider's privacy policy, the Provider verifies it against the official list at each review, and the Standard Contractual Clauses apply in any event.
- Patient Data processed: Recipient name and email address, and the subject and body of the message sent.
Upstash, Inc.
- Function: Rate limiting and short-lived caching.
- Location of processing: United States.
- Transfer mechanism: Certification under the EU-US Data Privacy Framework, with the Standard Contractual Clauses as a fallback.
- Patient Data processed: Technical identifiers only, comprising request counters keyed to an internet protocol address. No message content and no document reaches this provider.
Functional Software, Inc., trading as Sentry
- Function: Application error monitoring.
- Location of processing: European Union, Frankfurt region, for the data of the Provider's organisation.
- Transfer mechanism: Certification under the EU-US Data Privacy Framework, with the Standard Contractual Clauses as a fallback, covering residual access by the United States entity.
- Patient Data processed: Error reports from which personal data is removed before transmission. Session replay is disabled, and no default collection of personal data is enabled.
Contingent sub-processor, not engaged at the date of the present version
WhatsApp Ireland Limited, in respect of the WhatsApp Business Platform, becomes a sub-processor only for a Clinic that activates the channel described in Section 19, and processes for that Clinic the telephone number, the message content, and the media transmitted through it. The channel is built but is not activated, and no Patient Data has been disclosed to that provider. The transfer position and the current terms are verified and supplied to the Clinic at the moment of activation.
Providers that are not sub-processors of Patient Data
Stripe operates subscription billing for clinics. It receives the Clinic's billing data, and no Patient Data reaches it. The processing of billing data is carried out by the Provider as controller and is described in the Privacy Policy, so Stripe is not a sub-processor under the DPA.
ScreenshotOne renders an image of the Clinic's own public website during onboarding. It receives the public address of that website and returns an image. No Patient Data and no personal data of the Clinic's personnel is transmitted to it, so it is not a sub-processor under the DPA.
Annex C: Technical and Organisational Measures
Annex C describes the measures implemented under Article 32 of the GDPR and serves, for the purposes of the Standard Contractual Clauses referred to in Section 11, as the description that Annex II to those Clauses requires. The measures are stated at a level of detail sufficient to allow the Clinic to assess them, and short of the level that would itself create a security exposure.
Pseudonymisation and encryption. Data in transit is protected by transport-layer security on every interface, and certificates are provisioned and renewed automatically. Authentication credentials are stored as Argon2id hashes rather than in any recoverable form. Nightly database snapshots held outside the platform are encrypted with AES-256-GCM. Personal data is removed from diagnostic records before they are transmitted to the error-monitoring provider, and session replay is disabled there.
Confidentiality of processing systems and services. Each clinic's data is isolated at the database level by row-level security, so that a query executed in the context of one tenant cannot return the records of another. Access is governed by role-based controls and by the principle of least privilege. Administrative access is restricted to the smallest workable group and is conditioned on second-factor authentication. Rate limiting is applied to sensitive endpoints in order to blunt credential-stuffing and enumeration attempts. Personnel with access are bound by the confidentiality obligations described in Section 7.
Integrity of processing systems and services. Audit records are generated for authentication events, for administrative actions, and for access to Patient Data through administrative interfaces. Changes to the application pass through version control and review before deployment. Bot protection is applied at the edge of the hosting platform. The Provider does not permit direct database access from outside the application layer save through controlled administrative paths.
Availability and resilience, and restoration of access. Two independent recovery paths protect availability. The first operates inside the database and permits restoration to any moment within the window described in Section 15.3. The second is an encrypted copy held outside the platform on which the Service runs, so that an incident reaching the platform does not carry away the only copy of the data. Restoration procedures are documented and rehearsed, integrity of a restored dataset is verified before it is returned to service, and Section 15.4 governs the treatment of records deleted before the incident.
Testing, assessment, and evaluation. The measures described are reviewed at least annually, on any material change to the Service, and following any Personal Data Breach. The review covers the sub-processors engaged, the transfer mechanisms relied upon, the access rights in force, and the effectiveness of the logging and alerting in place. Outcomes are recorded, and remedial actions are tracked to completion.
Measures for the engagement of sub-processors. Before a provider is engaged, the Provider assesses its published security documentation, its data processing terms, the location of its processing, its transfer mechanism, and any third-party assessment it holds. Engagement proceeds under a written contract imposing obligations no less protective than those in the DPA, as Section 10.3 requires, and the particulars are entered in Annex B.
Measures for breach detection and handling. A documented procedure governs detection, assessment, containment, notification, and recording. Every event is recorded whether or not it proves notifiable. The forty-eight hour notification undertaking in Section 14.1 is shorter than the period Article 33(2) of the GDPR fixes by reference to undue delay, and is stated as a firm outer limit so that the Clinic retains a workable margin within its own seventy-two hour period under Article 33(1).
Contact
DTCONCIERGE S.R.L., Aleea Călărașilor nr. 5, bl. G, ap. 54, Municipiul Sibiu, județul Sibiu, Romania. Data protection correspondence: privacy@dentalpolyglot.com. Contractual correspondence: service@dentalpolyglot.com. Website: https://dentalpolyglot.com.