Data Processing Terms
Last updated
These Data Processing Terms form part of the Terms of Service and apply when DentoSim processes personal data on behalf of an organisation (the "Customer"), such as patient information in treatment plans.
1. Roles
The Customer is the controller of personal data it uploads to the Service. DentoSim is the processor and processes that data only on the Customer's documented instructions, which are given through the Customer's use and configuration of the Service and these Terms.
2. Scope of processing
- Subject matter: hosting, converting and displaying treatment plans and related case information.
- Data subjects: patients, doctors, clinic staff and lab staff.
- Types of data: patient references or names, dental 3D models and treatment plans, case notes and messages, and contact details of professional users.
- Duration: for the term of the Customer's use of the Service, plus the deletion period described below.
3. Confidentiality
We ensure that people authorised to process Customer personal data are bound by confidentiality and access it only as needed to provide and support the Service.
4. Security measures
- separation of each organisation's data;
- encryption of data in transit, and hashed passwords;
- role-based access, optional two-factor authentication and audit logging;
- virus scanning of uploaded files;
- private patient links with optional PIN, expiry and revocation;
- removal of patient information from error reports.
5. Sub-processors
The Customer authorises us to use sub-processors for hosting, storage, email delivery, error monitoring and push notifications. We remain responsible for our sub-processors and will inform the Customer of material changes, giving it the opportunity to object.
6. Assistance
We will help the Customer, taking into account the nature of the processing, to respond to data subject requests and to meet its security, breach notification and impact assessment obligations.
7. Personal data breaches
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, with the information reasonably available to help the Customer meet its obligations.
8. Deletion and return
The Customer can delete cases and set retention periods in the Service. When the Customer's account ends, we will delete Customer personal data within a reasonable period, unless the law requires us to keep it. The Customer may request an export before deletion.
9. Audits
We will make available information reasonably necessary to demonstrate compliance with these terms, and will respond to reasonable written questions from the Customer about our security practices.
10. Contact
Contact us on WhatsApp at +92 314 1523562.