1. Parties and roles
This Data Processing Agreement ("DPA") is between you — the dental practice or individual dentist using DentConsentUK (the "Controller") — and DentConsentUK Ltd, a company registered in England and Wales (company number 17267707), registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ (the "Processor", "we", "us").
You decide why and how your patients' personal data is processed; we process it only on your behalf, to provide the DentConsentUK service. This DPA satisfies Article 28 of the UK GDPR and is incorporated into our Terms of Service.
Our ICO Data Protection register reference is ZC214362.
2. Definitions
Terms such as Controller, Processor, Personal Data, Special Category Data, Data Subject, Processing, Personal Data Breach and Sub-processor have the meanings given in the UK GDPR and the Data Protection Act 2018 (together, the "Data Protection Legislation").
Patient dental and medical data processed through the platform is Special Category Data (health data) under Article 9 UK GDPR, to which a higher standard of protection applies throughout this DPA.
3. Scope and your instructions
We process Personal Data only for the purposes of providing the Services and only on your documented instructions — of which this DPA, our Terms of Service, and your use of the platform's features form part — unless we are required to process it by law (in which case we will tell you first, unless the law prohibits this).
We will tell you without undue delay if, in our opinion, an instruction infringes the Data Protection Legislation.
4. Our obligations as Processor
In relation to Personal Data processed under this DPA, we will:
• Security — implement appropriate technical and organisational measures (see Section 8), appropriate to the risk of processing Special Category health data.
• Confidentiality — ensure that anyone authorised to process the data is under a binding duty of confidentiality and has received appropriate training.
• Data Subject rights — assist you, so far as possible, to respond to requests from patients exercising their rights (access, rectification, erasure, restriction, portability, objection). The platform includes a one-click per-patient export (PDF and JSON) to support this. If a patient contacts us directly, we will forward the request to you and will not respond to it ourselves unless you instruct us to.
• Assistance — provide reasonable assistance with Data Protection Impact Assessments, prior consultation with the Information Commissioner, and your security and breach-notification obligations.
• Breach notification — notify you without undue delay, and in any event within 24 hours of becoming aware of a Personal Data Breach affecting your data, with enough information for you to meet your own reporting obligations.
• Records and audit — maintain records of our processing under Article 30(2) UK GDPR, make available the information needed to demonstrate compliance with this DPA, and allow for audits (on reasonable notice, no more than once per year, or after a breach). We may satisfy an audit request with an up-to-date independent security assessment.
• Deletion or return — on termination, and at your choice, delete or return your Personal Data (and copies), except where retention is required by law (see Section 7).
5. Sub-processors
You give general written authorisation for us to use the sub-processors below. We will give you at least 30 days' notice of any intended addition or replacement, so you can object, and we impose data-protection terms on each sub-processor that are no less protective than this DPA. We remain fully liable to you for our sub-processors.
• Supabase — database, authentication and encrypted file storage for consent and medical-history records. Data is stored at rest in the United Kingdom (AWS London).
• Vercel — application hosting and server-side processing for the web platform. Processing takes place in the United Kingdom (London region).
• Stripe — payment processing for your subscription. Stripe processes your own billing and contact details only — no patient clinical data.
• Twilio and Resend — SMS and email delivery of patient links and consent records.
Each sub-processor operates under its own data-processing terms and appropriate safeguards for any processing outside the UK.
6. International transfers
Your patients' consent and medical-history records are stored at rest in the United Kingdom, and server-side processing takes place in the United Kingdom.
Where a sub-processor (for example, an email or SMS provider, or a US-parent company) processes limited Personal Data outside the UK, we ensure an appropriate transfer mechanism is in place under the Data Protection Legislation — such as UK adequacy regulations or the ICO International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.
7. Data retention and deletion
Dental records must be retained for a minimum of 11 years for adults, or until the patient's 25th birthday for children (whichever is longer). Accordingly, you may direct us to retain records for the applicable retention period rather than delete them on termination.
Where you direct deletion, we will provide written confirmation of secure deletion.
8. Technical and organisational measures
We maintain at least the following measures:
• Encryption of Personal Data in transit (TLS) and at rest.
• Tenant isolation — database row-level security ensures each practice can access only its own patients' data; cross-practice access is prevented at the database layer.
• An immutable, versioned audit trail — consent and medical-history records cannot be edited or deleted after confirmation; every consent event (viewed, understood, signed, withdrawn) is timestamped and attributed.
• Role-based access controls, with privileged credentials restricted to server-side operations.
• Least-privilege access, backups with timely recoverability, and periodic review of these measures.
9. Liability
Subject to the exclusions below, each party's total aggregate liability arising out of or in connection with this DPA — whether in contract, tort (including negligence), breach of statutory duty or otherwise — shall not exceed the total fees paid or payable by you under your subscription in the 12 months immediately preceding the event giving rise to the claim.
Each party will indemnify the other against losses, fines and reasonable costs arising from the indemnifying party's breach of the Data Protection Legislation or this DPA, subject to that cap.
Nothing in this DPA limits liability that cannot lawfully be limited — including death or personal injury caused by negligence, and fraud.
10. Term and governing law
This DPA takes effect when you accept it and continues for as long as we process Personal Data on your behalf. Termination of your subscription terminates this DPA, subject to Section 7.
This DPA is governed by the law of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.
11. Acceptance
You accept this DPA when you tick the acceptance box during registration. We record the version you accepted, the date and time, and the IP address of acceptance, so that acceptance is provable. Your acceptance is the DPA required under Article 28 UK GDPR between you (Controller) and DentConsentUK Ltd (Processor).