Data Processor Appointment (Art. 28 GDPR)
This agreement (Data Processing Agreement) governs the processing of personal data that Dentra carries out on behalf of the client as part of the design service. The client (dental practice or laboratory) is the data controller; Hundredjack OÜ, operating under the Dentra brand, is the data processor. It is an integral part of the Terms of Service and is accepted in the platform before the first order is submitted.
Last updated: July 21, 2026
Subject matter, roles and data processed
Data controller: the client (dental practice or laboratory) who determines the purposes and means of processing the personal data of its patients.
Data processor: Hundredjack OÜ (“Dentra” brand), registry code 17310584, with registered office at Telliskivi tn 57, 10412 Tallinn (Estonia), which processes data on behalf of the controller solely for the design activity.
Terms not otherwise defined have the meaning given to them by Regulation (EU) 2016/679 (GDPR).
Subject matter: the processing of personal data necessary to perform the digital design service (CAD/CAM) commissioned by the controller.
Nature and purpose: receiving the files and information uploaded by the controller, processing and designing the device, revision, delivery of the designed files and possible forwarding to the indicated production partner.
Duration: processing lasts for the term of the contractual relationship and continues for as long as needed to comply with legal obligations, in accordance with the retention periods stated in the Privacy Policy.
Categories of data subjects: the controller's patients; the controller's staff and collaborators who use the platform.
Types of data: minimal identifying data possibly associated with the case (usually an anonymous code), scans and images, prescription and — where strictly necessary for the device conformity declaration — the patient's identifying data. Health data may be included (a special category under Art. 9 GDPR).
Obligations of the processor
The processor processes data only on the controller's documented instructions, including as regards any transfers, unless required to do so by Union or Member State law; in that case it informs the controller before processing, unless prohibited by law.
These terms, the Terms of Service and the operations given through the platform constitute the controller's documented instructions. The processor informs the controller if, in its opinion, an instruction infringes the GDPR or other data-protection rules.
The processor ensures that persons authorised to process the data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to the data is limited to what is necessary for each task.
The processor implements technical and organisational measures appropriate to the risk: access control and authentication, encryption of data in transit and, for the patient's identifying data, encryption at rest; logging of access; data residency in the European Union for the core infrastructure. The measures are described in the Privacy Policy and in the security documentation.
Taking into account the nature of the processing, the processor assists the controller by appropriate technical and organisational measures in responding to data-subject requests (Arts. 12-22) and in ensuring compliance with security, breach-notification and impact-assessment obligations (Arts. 32-36).
The processor notifies the controller without undue delay after becoming aware of a personal-data breach affecting the data processed on its behalf.
Sub-processors and transfers outside the European Union
The controller gives general authorisation for the processor to engage other processors (sub-processors) to provide the service. The up-to-date list is set out in the “Third-Party Services” section of the Privacy Policy.
The processor imposes on sub-processors data-protection obligations equivalent to those set out here and remains responsible for their performance. In the event of changes (adding or replacing a sub-processor), the controller may object on legitimate data-protection grounds.
Any processing by sub-processors outside the European Union takes place on the basis of adequate safeguards (an adequacy decision or standard contractual clauses), as indicated in the “Transfers outside the European Union” section of the Privacy Policy.
Return of data, audit and governing law
At the end of the service, at the controller's choice, the processor deletes or returns the personal data processed on its behalf and deletes existing copies, unless Union or Member State law requires storage.
The processor makes available to the controller the information necessary to demonstrate compliance with the obligations of Art. 28 and allows for and contributes to audits, including inspections, within the limits and in the manner agreed and without compromising the security and confidentiality of other clients.
This agreement is governed by Estonian law and is an integral part of the Terms of Service. For the physical production of devices carried out by Italian partner laboratories, the provisions of the Order Terms continue to apply.