Data Processing Agreement
Last updated: July 5, 2026
1. Roles of the parties
For patient records and other personal data the Customer enters into the Service, the Customer is the controller (it decides why and how the data is processed) and the Provider is the processor (it processes that data only to provide the Service). The Customer is responsible for the lawfulness of the data it collects and for obtaining any patient consent or other legal basis required.
2. Subject matter, nature, and purpose
- Subject matter & duration: processing of Customer personal data for the duration of the Customer’s use of the Service, plus any retention period described in this DPA.
- Nature & purpose: hosting, storing, organising, transmitting, backing up, and displaying the data as necessary to provide dental practice-management features (appointments, records, charting, billing, patient portal, and offline sync).
- Types of data: identification and contact details, dates of birth, appointment data, dental and medical history, allergies and medical alerts, clinical and treatment records, billing and payment records, uploaded images/X-rays, and related notes.
- Categories of data subjects: the Customer’s patients and staff. This may include special categories of data (health data).
3. Provider (processor) obligations
The Provider will:
- Process Customer personal data only on the documented instructions of the Customer, which include the Customer’s use of the Service’s features and these documents, unless required to act otherwise by law;
- Ensure that persons authorised to process the data are bound by appropriate confidentiality obligations;
- Implement appropriate technical and organisational security measures (see Section 5);
- Engage sub-processors only in line with Section 4;
- Taking into account the nature of the processing, assist the Customer, so far as reasonably possible, in responding to requests from data subjects to exercise their rights;
- Assist the Customer in ensuring security of processing, notification of personal-data breaches, and any required data-protection impact assessments;
- At the Customer’s choice, delete or return the Customer personal data at the end of the Service, and delete existing copies except where storage is required by law (see Section 8);
- Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA.
4. Sub-processors
The Customer authorises the Provider to engage the following sub-processors to provide the Service. Each is bound by data-protection obligations consistent with this DPA:
- Supabase, database, authentication, and file/image storage hosting.
- Vercel, application hosting and content delivery.
- Resend, transactional email delivery.
If the Provider adds or replaces a sub-processor, it will update this list and make reasonable efforts to inform the Customer, who may object on reasonable data-protection grounds; if an objection cannot be resolved, the Customer may stop using the affected part of the Service or terminate as described in the Terms.
5. Security measures
Taking into account the state of the art and the risks of the processing, the Provider maintains measures designed to protect Customer personal data, including: access controls that scope each clinic’s data to that clinic (row-level security), role-based permissions, encryption of data in transit, hashed storage of passwords by the authentication provider, and use of reputable hosting infrastructure. No system is completely secure, and the Customer is responsible for the security of its own devices, accounts, and credentials.
6. Personal-data breaches
The Provider will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer’s data, and will provide reasonably available information to help the Customer meet any breach-notification obligations it may have.
7. International transfers
The Provider and its sub-processors may process data on infrastructure located outside Lebanon. The Provider will take reasonable steps to ensure such transfers are subject to appropriate safeguards consistent with applicable law.
8. Return and deletion of data
On termination or expiry of the Service, and on the Customer’s request made within a reasonable period, the Provider will make the Customer’s data available for export and will then delete it, except where retention is required by law. Residual copies may remain in routine backups for a limited time before being overwritten.
9. Customer (controller) responsibilities
- Ensuring it has a lawful basis and any required patient consent for the data it processes through the Service;
- Ensuring the accuracy and lawfulness of the data it enters;
- Configuring roles, permissions, and patient-portal sharing appropriately;
- Complying with its own obligations under applicable data-protection and health-record laws.
10. Liability and governing law
The liability provisions of the Terms of Service apply to this DPA. This DPA is governed by the laws of Lebanon, and the courts of Beirut, Lebanon have exclusive jurisdiction, except where applicable law requires otherwise.
11. Contact
Questions about this document? Contact us at dentabooklb@gmail.com.