Skip to content

Appointment as Data Processor (art. 28 GDPR)

This agreement (Data Processing Agreement) governs the processing of personal data that Dentra carries out on behalf of the client within the scope of the design service. The client (dental practice or laboratory) is the Data Controller; Hundredjack OÜ, operating under the Dentra brand, is the Data Processor. It forms an integral part of the Terms of Service and is accepted on the platform before the first order is submitted.

This is an automatic translation. The binding version of this document is the Italian one.

1. Subject Matter, Roles, and Data Processed

Data Controller: the client (dental practice or laboratory) who determines the purposes and means of processing their patients' data.

Data Processor: Hundredjack OÜ (brand «Dentra»), registrikood 17310584, with registered office at Telliskivi tn 57, 10412 Tallinn (Estonia), which processes data on behalf of the Controller solely for the design activity.

Terms not otherwise defined herein shall have the meaning ascribed to them by Regulation (EU) 2016/679 (GDPR).

Subject matter: the processing of personal data necessary for the execution of the digital design service (CAD/CAM) commissioned by the Controller.

Nature and purpose: reception of files and information uploaded by the Controller, processing and design of the artifact, revision, delivery of the designed files, and eventual forwarding to the indicated production partner.

Duration: the processing lasts for the duration of the contractual relationship and continues for the time necessary to comply with legal obligations, according to the retention periods indicated in the Privacy Policy.

Categories of data subjects: the Controller's patients; the Controller's staff and collaborators who use the platform.

Types of data: minimal identification data potentially associated with the case (usually an anonymous code), scans and images, prescription and — when strictly necessary for the device's declaration of conformity — patient identification data. Health-related data (special category pursuant to art. 9 GDPR) may be included.

2. Processor's Obligations

The Processor shall process personal data only on documented instructions from the Controller, including those regarding any transfers, unless required to do so by Union or Member State law to which the Processor is subject; in which case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

These terms, the Terms of Service, and the operations instructed through the platform constitute the Controller's documented instructions. The Processor shall inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.

The Processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to data is limited to what is necessary for each task.

The Processor shall implement technical and organisational measures appropriate to the risk: access control and authentication, encryption of data in transit and, for patient identification data, encryption at rest; consultation tracking; data residency in the European Union for the main infrastructure. The measures are described in the Privacy Policy and security documentation.

Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the data subject's rights (Articles 12-22) and to ensure compliance with the obligations regarding security, notification of breaches, and data protection impact assessment (Articles 32-36).

The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach concerning data processed on its behalf. In particular, pursuant to Articles 33-34 of the GDPR, the Processor must support the Controller in any personal data breach notification activities to the competent Data Protection Authority and to the data subjects. In this regard, by way of example and not exhaustive, the Processor must notify the Controller without delay, and in any case no later than 48 hours from the discovery of: i. any relevant event concerning data processing (e.g., unauthorised access or attempts thereof, irregularities or events that have increased the risk to the rights of data subjects); ii. any security breach of its IT systems; iii. any attempt to penetrate such systems that could reasonably compromise the security of personal data; iv. any act or event, regardless of the identity of the actor, that may constitute a breach of the Controller's instructions, the Contract, this designation act, or data protection legislation;

3. Sub-processors and Transfers outside the European Union

The Controller generally authorises the Processor to engage other processors (sub-processors) for the provision of the service. The updated list is provided in the «Third-Party Services» section of the Privacy Policy.

The Processor shall impose on sub-processors data protection obligations equivalent to those set out herein and remains responsible for their actions. In the event of changes (addition or replacement of a sub-processor), the Controller may object for legitimate reasons related to data protection.

Any processing by sub-processors outside the European Union shall take place on the basis of appropriate safeguards (adequacy decision or standard contractual clauses), as indicated in the «Transfers outside the European Union» section of the Privacy Policy.

4. Data Cessation, Audit, and Applicable Law

Upon termination of the service, at the Controller's choice, the Processor shall delete or return the personal data processed on its behalf and delete existing copies, unless Union or Member State law requires storage.

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in art. 28 and allow for and contribute to audits, including inspections, within the agreed limits and modalities and without compromising the security and confidentiality of other clients.

This agreement is governed by Regulation 679/2016 (alias GDPR) and local laws on the matter and forms an integral part of the Terms of Service. For the physical production of devices carried out by Italian partner laboratories, the provisions of the Order Conditions remain valid.

Terms of Service