Legal · Data Processing Agreement
Data Processing Agreement
This DPA forms part of the Customer Terms between Circlemount Dental Technology Ltd (the "Processor") and the Customer (the "Controller"), and governs processing of personal data the Processor carries out on the Controller's behalf, in accordance with Article 28 of the UK GDPR.
Table of contents▾
1. Definitions
Capitalised terms have the meanings given in UK GDPR. "Personal Data", "Processing", "Data Subject", "Controller" and "Processor" carry their UK GDPR meanings. "Customer Personal Data" means Personal Data processed by us on the Controller's behalf under the Customer Terms.
2. Subject matter and duration
Subject matter: provision of the dentorb platform. Duration: the term of the Customer Terms plus any wind-down period agreed under section 11.
3. Nature and purpose of processing
- Hosting and operating the platform features the Customer enables.
- Patient communications across calls, SMS, email, web chat and WhatsApp.
- Workflow, scheduling, billing-support, and operations features.
- Producing analytics and reports for the Controller's own use.
- Providing technical support and security monitoring.
4. Categories of data and data subjects
- Patients of the Controller — name, contact details, demographics, appointment history, treatment notes, images, payment metadata, communications.
- Practice staff — name, role, login identifiers, access logs.
- Enquirers and prospective patients — name, contact details, source.
5. Processor obligations
- Process Customer Personal Data only on the Controller's documented instructions, including transfers to third countries.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement the security measures set out in section 7 (and Annex B).
- Engage sub-processors only under section 6.
- Assist the Controller with data-subject requests and DPIAs.
- Notify the Controller without undue delay (and within 72 hours) of any Personal Data breach.
- Make available all information necessary to demonstrate compliance and allow audits per section 9.
6. Sub-processors
The Controller authorises the Processor to engage the sub-processors listed at /legal/sub-processors. We will give at least 30 days' notice of changes via email and the published list. The Controller may object on reasonable data-protection grounds.
7. Security measures
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- UK / EU data residency for primary patient data.
- Role-based access control aligned to dental team roles; MFA enforced for staff and admin accounts.
- Tamper-evident audit logging of privileged actions.
- Network segmentation, vulnerability management, and continuous monitoring.
- Documented incident response and tested backup / restore procedures.
- Background checks and security training for personnel with access to production.
8. International transfers
Customer Personal Data is hosted in the UK with EU redundancy. Where any transfer outside the UK / EEA is necessary, we use UK adequacy regulations or the UK International Data Transfer Addendum to the EU SCCs, with supplementary measures as required.
9. Audits
On reasonable notice, no more than once per year (except after a breach), the Controller may audit the Processor's compliance with this DPA. We will provide our most recent third-party audit reports and security pack to satisfy this requirement where the Controller agrees.
10. Data-subject requests
We will assist the Controller in responding to data-subject requests using the in-product tooling and, where needed, manual support — without undue delay and at no additional charge for reasonable assistance.
11. Return or deletion of data
On termination of the Customer Terms, the Controller may export Customer Personal Data via the platform for 30 days. After that period, we delete or return the data per the Controller's instruction, except where retention is required by law.
12. Liability
Liability under this DPA is governed by the liability provisions in the Customer Terms.
13. Governing law
This DPA is governed by the laws of England and Wales.
Annex A — Processing details
Subject matter, duration, nature, purpose, data categories and data subjects are described in sections 2–4 above.
Annex B — Technical and organisational measures
The measures in section 7 form Annex B for the purposes of UK GDPR Article 32. The Security Overview document at /legal/security elaborates on each control.
Questions about this document?
Email marcus@dentorb.ai.
Circlemount Dental Technology Ltd · Company No. 17188772 · Registered in England & Wales
Incorporated 29 April 2026 · Registered office: The Squires, 5 Walsall Street, Wednesbury, West Midlands, England, WS10 9BZ
Related documents
© 2026 Circlemount Dental Technology Ltd · Company No. 17188772 · Registered in England & Wales
