Data processing agreement
Data processing agreement (art. 28 GDPR) between Dently and the clinic that subscribes to the service.
Last updated: July 27, 2026
Version 1.0 — July 27, 2026. This agreement is part of theTerms and Conditions of the Dently service and is accepted electronically when the clinic account is created. The accepted version, with its date and time, is recorded on the platform.
This is a courtesy translation. The original agreement is executed in Spanish and is available at dently.es/encargo-tratamiento. In case of discrepancy, the Spanish version prevails.
Parties
The Processor: Carlos Frederick Díaz Sánchez, with Spanish tax ID (NIF) 02336521C, owner of the Dently service (the Processor). Full information in the Legal notice.
The Controller: the dental clinic (individual or legal entity) that creates an account on Dently and accepts this agreement, identified by the registration data and, where applicable, the fiscal data it enters on the platform (theController).
The provision of the Service requires the Processor to access and process personal data of the Controller's patients and users, always acting on behalf of and under the instructions of the Controller. In compliance with article 28 of Regulation (EU) 2016/679 (GDPR) and the Spanish Organic Law 3/2018 (LOPDGDD), the parties enter into this data processing agreement, executed in electronic form in accordance with article 28.9 GDPR.
1. Subject matter
The Processor shall process the personal data that the Controller enters into the Dently Service exclusively to provide the contracted Service, in accordance with the Controller's documented instructions.
2. Nature and purpose of the processing
The purpose of the processing is to enable the Controller to manage its clinical activity through the Service, and it includes the following operations on behalf of the Controller: schedule and appointment management, maintenance of the dental clinical record, preparation of quotes and invoices, sending communications to patients (appointment reminders, satisfaction surveys and patient recapture) when configured by the Controller, generation of internal metrics for the Controller, and the associated technical operations (collection, recording, storage, retrieval, organization, modification, backup and erasure).
3. Data processed
- Patient identification and contact data: name, surname, phone, email, date of birth and, where applicable, national ID and address if collected by the Controller.
- Health data: dental clinical history, completed and planned treatments, quotes, and images and documents the clinic uploads to the Service.
- Service user data: name and email of the Controller's practitioners and administrative staff who access the dashboard, and records of their activity in the system.
Health data are special categories of personal data under art. 9 GDPR and are subject to the reinforced protection measures of Annex I.
4. Categories of data subjects
- The Controller's patients.
- The Controller's healthcare practitioners and administrative staff using the Service.
- Where applicable, people who contact the Controller or request an appointment and whose data the Controller enters into the Service.
5. Duration
This agreement lasts as long as the Service relationship. Once the Service ends, the Processor shall proceed in accordance with clause 15 (Return and deletion of data).
6. Controller's instructions
The Processor shall process personal data only on the Controller's documented instructions and under these terms. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR, the LOPDGDD or other data protection provisions.
7. Prohibition of processing for own purposes
The Processor undertakes not to use the Controller's personal data for its own purposes, in particular for commercial analysis, profiling, advertising or training artificial intelligence models, or for any other purpose not covered by the Service. This prohibition is non-waivable and survives termination of the agreement.
8. Confidentiality
The Processor shall ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation survives termination of this agreement.
9. Security measures
The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with art. 32 GDPR, including at least those set out in Annex I. Since special categories of data (health) are processed, the Processor shall pay particular attention to encryption, access control and traceability.
10. Sub-processors
The Processor may engage sub-processors for the partial provision of the Service. Current sub-processors are listed in Annex II. The Processor shall notify the Controller of any intended addition or replacement of sub-processors at least 15 calendar days in advance, giving the Controller the opportunity to object on reasonable grounds. The Processor shall ensure by contract that sub-processors assume data protection obligations equivalent to those of this agreement.
11. Assistance with data subject rights
Taking into account the nature of the processing, the Processor shall assist the Controller, through appropriate technical and organizational measures, in handling requests to exercise rights (access, rectification, erasure, portability, objection and restriction) within a maximum of 5 business days from when the Controller forwards the request. If a data subject addresses a request directly to the Processor, it shall forward it to the Controller without delay. Contact channel:privacy@dently.es.
12. Security assistance and breach notification
The Processor shall notify the Controller, without undue delay and in any case within24 hours of becoming aware of it, of any personal data breach, providing the information necessary for the Controller to notify the supervisory authority within the 72-hour period of art. 33 GDPR and to communicate to data subjects under art. 34 where applicable.
13. Data protection impact assessments (DPIA)
The Processor shall assist the Controller with data protection impact assessments (art. 35 GDPR) and prior consultations with the supervisory authority (art. 36), when required by the Controller, providing the information available to it about the Service.
14. International transfers
The Processor shall not transfer personal data outside the European Economic Area (EEA) except through the sub-processors listed in Annex II and always with appropriate safeguards under Chapter V GDPR (standard contractual clauses approved by the European Commission and/or valid adequacy mechanisms). The main hosting of the Service and the database is on infrastructure located in the European Union. Any sub-processor outside the EEA is listed in Annex II with its transfer safeguard.
15. Return and deletion of data
Upon termination of the Service, the Processor shall make all processed personal data available to the Controller in a standard export format (CSV/JSON) for a period of30 calendar days from the cancellation date. After that period, the Processor shall securely delete the data, unless the Controller expressly requests a longer period with justified need (for example, ongoing legal proceedings or compliance with the legal obligation to retain clinical records). The Processor shall certify the deletion in writing upon the Controller's request.
The Processor shall not unilaterally delete data while the Service is active, except upon the Controller's express instruction.
16. Audits
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations of this agreement, and shall allow for and contribute to reasonable audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, with at least 10 business days' notice, without disproportionately interfering with the operation of the Service and preserving the confidentiality of other customers' data.
17. Acceptance, governing law and jurisdiction
This agreement is accepted by electronic means during the account sign-up process, together with the Terms and Conditions of the Service, and is in writing in electronic form for the purposes of article 28.9 GDPR. The Processor keeps a record of the accepted version, the date and time of acceptance and the account that performed it, and shall provide it to the Controller upon request.
This agreement is governed by Spanish law (GDPR and LOPDGDD). To the extent that an express choice of forum is legally permissible between the parties, they submit to the Courts of the Processor's domicile, expressly waiving any other jurisdiction. Where such choice is not permissible, the competent court shall be the one determined by the applicable law.
Annex I — Processor's security measures (art. 32 GDPR)
The following measures reflect the actual, implemented state of the Service. Those marked(partial) transparently describe what is implemented and what is pending.
1. Encryption in transit. TLS-encrypted communications between clients and servers on all API and dashboard routes, and in the transfer of backups to the storage provider.
2. Multi-clinic isolation. Role-based access control (RBAC) with per-clinic segmentation in queries, so one clinic cannot access another clinic's data.
3. Two-step verification — available to all users. The Service allows each user to enable two-step verification for dashboard access. When a user has it enabled, after validating email and password the system issues a 6-digit one-time code (OTP) sent to their email address, valid for 10 minutes, single-use and stored only as a hash; the session token is issued only after the code is verified. Activation is up to each individual user, so the Controller may require its use across its own staff as part of its own security measures. Independently of this, all user passwords are stored with bcrypt hashing.
4. Backups. Automatic database backups twice a day (every 12 hours), compressed and transferred via TLS to an independent storage provider (Cloudflare R2, see Annex II) with provider-managed encryption at rest. Each run generates a success or error notification. A documented and tested restore procedure exists. De facto recovery point objective (RPO) of approximately 12 hours.
5. Encryption at rest (partial). Backups are stored in Cloudflare R2, which applies provider-managed AES-256 encryption at rest by default. The production database resides on a server volume in the EU (Hetzner); there is currently no additional application-level, column-level or Processor-managed disk encryption on that volume. Access control to the database is the main safeguard for data at rest in the live database.
6. Access control and confidentiality. Access restricted by credentials, with two-step verification where the user has enabled it (measure 3), segmentation by role and clinic (measure 2), and confidentiality commitments of authorized personnel (clause 8).
7. Audit logs (partial). The system keeps append-only audit trails of clinical schedule operations (creation, rescheduling, status change, cancellation, restoration and deletion of appointments, with user identification and timestamp) and of the activation and deactivation of account features. These records are kept indefinitely. There is currently no centralized, persistent log of authentication events (logins, failed attempts, password resets) or of read access to patient records.
8. Backup retention and restore testing (partial). A documented restore procedure exists, verified through a test with production data. Pending: formalizing a retention and rotation policy in storage consistent with the legal retention period for clinical records, and establishing a schedule of periodic restore tests measuring recovery time (RTO).
9. Breach response plan (dated commitment). The Processor is contractually bound (clause 12) to notify the Controller of any security breach within a maximum of 24 hours. The Processor shall document in writing an internal breach response procedure (detection, containment, impact assessment, notification and record-keeping under art. 33.5 GDPR) before September 30, 2026. As of this version, that procedure is not yet formalized in writing.
Annex II — Sub-processors
| Sub-processor | Location | Purpose regarding the processed data | Transfer safeguard |
|---|---|---|---|
| Hetzner Online GmbH | EU (Germany / Finland) | Hosting of the application and the database (includes patient data); internal cache on the same infrastructure | Within the EEA — GDPR directly applicable, no international transfer |
| Cloudflare, Inc. | USA (R2 service) | Storage of encrypted backups | Standard Contractual Clauses (SCC) incorporated in its Data Processing Addendum + certified adherence to the EU-US Data Privacy Framework |
| Resend, Inc. | USA | Sending transactional emails and patient communications configured by the clinic (reminders, surveys, recapture). Accesses the patient's name and email | Standard Contractual Clauses (SCC) incorporated in its Data Processing Agreement + certified adherence to the EU-US Data Privacy Framework |
Not sub-processors of patient data:
- Stripe Payments Europe, Ltd. exclusively processes the Controller's billing data (the clinic as the Processor's customer) to collect the subscription. It does not access patient data, so it falls outside this agreement. The payment relationship is governed by the Processor's Privacy Policy and Stripe's DPA.
Version history
- Version 1.0 — July 27, 2026: first published version.