SMILE EDITOR โ DATA PROCESSING AGREEMENT
Version 1.0 โ Global Master Draft
This Data Processing Agreement ("DPA") forms part of the agreement between the customer entity or professional ("Customer") and [LEGAL ENTITY NAME], doing business as Smile Editor ("Smile Editor") when Smile Editor processes Personal Data on Customer's behalf.
1. Definitions
"Applicable Data Protection Law" means privacy and data protection law applicable to the Processing, including, where applicable, GDPR, UK GDPR, LGPD, applicable US state privacy laws and Canadian privacy laws.
"Customer Personal Data" means Personal Data processed by Smile Editor on Customer's behalf.
"Patient Data" means Customer Personal Data relating to a patient or health/dental care.
"Subprocessor" means a third party engaged by Smile Editor to process Customer Personal Data on Customer's behalf.
"Security Incident" / "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, to the extent defined by applicable law.
2. Roles
Customer is Controller/Business or equivalent for Customer Personal Data unless the parties expressly agree otherwise.
Smile Editor is Processor/Operator/Service Provider or equivalent when processing Customer Personal Data on Customer's behalf.
Each party remains responsible for legal obligations that apply to its respective role.
3. Customer Instructions
Smile Editor will process Customer Personal Data only:
- on Customer's documented instructions;
- to provide and secure the Service;
- as required by applicable law.
The Agreement, Customer's use of configured features, support requests and documented administrator actions constitute instructions.
Smile Editor will inform Customer if, in its reasonable view, an instruction violates Applicable Data Protection Law, unless prohibited by law.
4. Customer Responsibilities
Customer will:
- have a valid lawful basis and authority for the processing;
- provide legally required patient notices;
- obtain consent or authorization where required;
- avoid uploading unnecessary identifiers;
- configure user access appropriately;
- use only features approved for the relevant data category;
- comply with professional recordkeeping obligations;
- respond to patient/data-subject requests as Controller.
5. Confidentiality
Smile Editor will ensure personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive access only as reasonably necessary.
6. Security
Smile Editor will implement technical and organizational measures appropriate to risk, described in the applicable Security/TOMs annex.
Security measures will address, as appropriate:
- confidentiality;
- integrity;
- availability;
- resilience;
- access control;
- authentication;
- tenant isolation;
- encryption;
- logging;
- backup and recovery;
- vulnerability management;
- incident response.
7. Subprocessors
Customer provides general authorization for Smile Editor to use subprocessors required to deliver the Service.
Smile Editor will:
- maintain a current Subprocessor List;
- impose data protection obligations materially consistent with this DPA;
- remain responsible for its subprocessors to the extent required by law;
- provide notice of material new subprocessors where required.
If Customer reasonably objects to a new subprocessor on data protection grounds, the parties will work in good faith on a commercially reasonable alternative. If no alternative is available, Customer may discontinue the affected feature or terminate the affected Service as provided by the Agreement.
8. Data Subject Requests
Taking into account the nature of Processing, Smile Editor will reasonably assist Customer with requests for access, correction, deletion, restriction, objection, portability and other applicable rights.
If Smile Editor receives a request directly concerning Customer Personal Data:
- Smile Editor will not respond substantively unless authorized or legally required;
- Smile Editor will notify or redirect the request to Customer without undue delay;
- Smile Editor will provide available information reasonably needed for Customer's response.
9. Assistance with Compliance
Smile Editor will reasonably assist Customer, taking into account the nature of Processing and information available to Smile Editor, with:
- security obligations;
- breach assessment and notification;
- DPIAs / data protection impact assessments;
- prior consultation with regulators where required;
- evidence reasonably necessary to demonstrate processor compliance.
10. Security Incidents
Smile Editor will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
Notice will include, as information becomes available:
- nature of the incident;
- categories of affected data;
- approximate affected data subjects/records where known;
- likely consequences;
- mitigation and remediation measures;
- contact for follow-up.
Smile Editor may provide information in phases and will not characterize an event as legally reportable on Customer's behalf unless expressly agreed.
11. Return and Deletion
Upon Customer's valid request or termination, Smile Editor will return or delete Customer Personal Data as provided by the Service and applicable retention policy, unless law requires retention.
Data remaining temporarily in backups will be protected, isolated from routine processing and deleted through the ordinary documented backup expiration process.
12. International Transfers
Where Customer Personal Data is transferred internationally, Smile Editor will use a lawful transfer mechanism required by Applicable Data Protection Law.
For EEA/UK transfers requiring contractual safeguards, the parties will enter or incorporate the then-current legally required SCC/UK mechanism applicable to the transfer roles. The operational annexes to this DPA will provide processing details, security measures and subprocessors.
For Brazil, Smile Editor will use transfer mechanisms permitted by applicable LGPD rules and regulatory guidance.
13. US Service Provider / Contractor Terms
Where applicable US state privacy law treats Smile Editor as a Service Provider or Contractor:
- Smile Editor processes Personal Information only for specified business purposes and the Agreement;
- Smile Editor will not sell Customer Personal Data;
- Smile Editor will not use Patient Data for cross-context behavioral advertising;
- Smile Editor will not retain, use or disclose Customer Personal Data outside the business relationship except as permitted by law;
- Smile Editor will impose appropriate restrictions on subcontractors;
- Customer may take reasonable steps to verify processing as required by law.
14. HIPAA
If Customer and Smile Editor execute a BAA and HIPAA applies, the BAA controls for PHI in case of conflict with this DPA.
No BAA is effective merely because this DPA is accepted.
15. Audits and Information
Upon reasonable written request, Smile Editor will make available information reasonably necessary to demonstrate compliance with its processor obligations, which may include:
- security documentation;
- third-party assessment summaries;
- certifications if obtained;
- questionnaire responses;
- audit reports where contractually available.
On-site audits will be limited to circumstances required by law or where alternative evidence is insufficient, subject to confidentiality, security and reasonable scope/cost controls.
16. Records of Processing
Smile Editor will maintain records required of processors under Applicable Data Protection Law.
17. Liability
Liability under this DPA is subject to the Agreement's limitations to the extent permitted by applicable law, except where the parties expressly agree otherwise or a limitation is prohibited by law.
18. Order of Precedence
For Customer Personal Data:
- mandatory law;
- BAA for HIPAA PHI, where applicable;
- applicable transfer clauses/SCCs;
- this DPA;
- Terms of Service.
Annex I โ Processing Details
Subject matter: provision of dental CAD, visualization, storage, collaboration and related software services.
Duration: for the term of the Service plus documented deletion/backup periods.
Nature of processing: collection, receipt, hosting, storage, organization, visualization, transformation, transmission, support, export, deletion and other operations required by Customer-configured features.
Purposes: providing and securing the Service under Customer's documented instructions.
Data subjects: patients, Customer personnel, contractors and other individuals whose information Customer submits.
Data categories: identifiers; professional information; dental/health information; images; 3D scans; STL/OBJ/PLY; DICOM when supported; case data; designs; technical metadata.
Sensitive data: health data, patient images, biometric-like facial data where applicable, and other special/sensitive categories Customer submits.
Annex II โ Technical and Organizational Measures
See `05_SECURITY_MEASURES_TOMS.md`. Only controls verified as implemented form part of production commitments.
Annex III โ Subprocessors
See the current Smile Editor Subprocessor List. Production publication requires actual vendor entity, purpose, data category, processing location and transfer mechanism.