Data Processing Agreement
Effective 22 September 2026
This Data Processing Agreement ("DPA") is between SmileSort Ltd (company number 17457160, registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ — "SmileSort", "Processor") and the dental practice using SmileSort ("the Practice", "Controller"). It governs how SmileSort processes your patients' personal data on your behalf, as required by Article 28 UK GDPR.
This DPA is incorporated into and forms part of our Terms of Service — accepting the Terms at signup accepts this DPA too, for any patient data you process through SmileSort. If your practice needs a separately countersigned copy for your own records, email privacy@smilesort.com and we'll send one.
1. Roles of the parties
In respect of Patient Data, the Practice is the Controller and SmileSort is the Processor. The Practice determines the purposes and means of processing its patients' clinical data; SmileSort processes it only to provide the Service, on the Practice's instructions.
The Practice's own lawful basis for processing Patient Data is its responsibility to establish and is outside the scope of this DPA — as a matter of general UK practice for dental care, this is ordinarily Article 6(1)(b) or 6(1)(e) combined with Article 9(2)(h) (health or social care), available to a registered dentist as a health professional under DPA 2018, Schedule 1, Part 1, paragraph 2. SmileSort does not need, and does not claim, an independent Article 6/9 basis for Patient Data — it processes that data solely on the Practice's documented instructions.
Separately, and outside the scope of this DPA: where SmileSort processes the Practice's own account and billing data, SmileSort is the Controller of that data under its own Privacy Policy.
2. Processing on instructions
SmileSort shall process Patient Data only:
- to provide the Service in accordance with the Terms of Service (the Practice's standing instruction); or
- on further documented instructions from the Practice, given through the Service or in writing; or
- where required by UK law, notifying the Practice first unless the law prohibits it.
SmileSort will notify the Practice if, in its opinion, an instruction infringes Applicable Data Protection Law.
3. Confidentiality
Anyone SmileSort authorises to process Patient Data, including its own personnel, is bound by a duty of confidentiality and only processes Patient Data as necessary for their authorised role. SmileSort's application and internal admin tooling have no read access to patient, photo, folder or clinical-note data, enforced at the database level. Direct administrative access to the production database is limited to SmileSort's co-founders and used only for maintenance and incident response — see Annex 2.
4. Security of processing
SmileSort implements appropriate technical and organisational measures to secure Patient Data, appropriate to the risk — see Annex 2 — and reviews and improves them over time.
5. Sub-processing
The Practice gives SmileSort general written authorisation to engage the sub-processors listed in Annex 3 to process Patient Data.
SmileSort will give at least 30 days' notice (by email to the account holder) before engaging a new sub-processor, so the Practice can object on reasonable data-protection grounds. SmileSort remains fully liable for a sub-processor's performance, and imposes terms no less protective of Patient Data than this DPA on every one of them.
6. International transfers
SmileSort's primary data store is hosted in the UK. Where Patient Data is transferred to a sub-processor established outside the UK — see Annex 3 — the transfer relies on that sub-processor's own Data Processing Addendum, each independently confirmed to incorporate the EU Standard Contractual Clauses and the UK's International Data Transfer Addendum, automatically forming part of their standard terms. SmileSort will not transfer Patient Data elsewhere without an appropriate safeguard in place.
7. Data subject rights
The Practice is responsible for responding to its patients' rights requests. SmileSort will not respond directly to a request it receives about Patient Data (beyond acknowledging it and redirecting the individual to the Practice), will notify the Practice without undue delay if it receives one, and provides reasonable technical assistance — including a self-service data export the Practice can use directly, without waiting on SmileSort.
8. Personal data breach
SmileSort will notify the Practice without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Patient Data — giving the Practice time to meet its own 72-hour notification duty to the ICO — describing what's known of the breach's nature, scope, likely consequences and the steps taken, with further assistance and updates as the investigation continues.
9. DPIA & consultation assistance
SmileSort will provide reasonable assistance with any data protection impact assessment or ICO prior consultation the Practice reasonably considers necessary for its use of the Service, including making the information in this DPA available for that purpose.
10. Audit and inspection
SmileSort will make available the information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits by the Practice or its mandated auditor — in the first instance through a written compliance summary or security questionnaire, given the Service is a shared multi-tenant platform. Any on-site or system-level audit is limited to once in any 12-month period (unless triggered by a suspected breach), with at least 14 days' notice, reasonable scope, and mutual confidentiality.
11. Deletion or return of data
On termination, SmileSort will make Patient Data available for export and delete it per the Service's standard data lifecycle:
- Data deleted during an active subscription is held in Trash for 28 days, then permanently purged.
- Following cancellation, the account is read-only and exportable for 30 days, after which all Patient Data is permanently and irreversibly deleted, automatically.
- A share recipient's email address and the Practice's note on a share are cleared automatically 12 months after the share link stops working. The record of the share itself is kept until the account is deleted.
SmileSort will delete Patient Data sooner on the Practice's written request, except where UK law requires it to retain it.
12. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions in Section 13 (Limitation of Liability) of our Terms of Service.
13. Term, termination & survival
This DPA takes effect from the Practice's acceptance of the Terms of Service and continues for as long as SmileSort processes Patient Data on the Practice's behalf. Clauses 3 (Confidentiality), 11 (Deletion or return of data) and 12 (Liability) survive termination to the extent needed to give them effect.
14. General provisions
Variation. This DPA may only be varied by written agreement, except that SmileSort may update Annex 3 in accordance with Clause 5.
Notices. Notices under this DPA go to the account holder's registered email (for the Practice) and to privacy@smilesort.com (for SmileSort).
Governing law. This DPA is governed by the laws of England and Wales.
Annex 1 — Details of processing
| Subject matter | Provision of the SmileSort clinical-photography management platform to the Practice. |
| Duration | For the term of the Agreement, plus the Trash and post-cancellation retention windows in Clause 11. |
| Nature & purpose | Secure storage, AI-assisted classification and sorting, organisation into patient/visit folders, and controlled time-limited sharing at the Practice's direction. |
| Frequency | Continuous, for the duration of the Practice's active use of the Service. |
| Data subjects | The Practice's patients whose clinical photographs are uploaded. |
| Personal data | Patient name, date of birth, the Practice's own patient reference, clinical photographs (including extraoral/facial views), and any notes or labels attached. |
| Special category data | Yes. Clinical photographs and notes constitute health data under Article 9(1); extraoral photographs are also identifiable facial images. |
| Recipients | The sub-processors in Annex 3, and any third party the Practice itself chooses to share a folder with via the Service's expiring links. |
Annex 2 — Technical & organisational measures
- Tenant isolation. Row-level security scopes every table holding patient or clinical data to the requesting practice, on every read and write.
- Authentication. Session tokens are verified against the identity provider on every request, not merely decoded from a cookie.
- Storage. Photograph files sit in a private object store, gated by the same per-practice scoping as the database.
- Sharing. External share links use a 192-bit random token, are scoped to only the folders they were created for, expire after 7 days, and can be revoked at any time.
- Encryption. TLS in transit; at-rest encryption at the infrastructure level.
- Staff access control. SmileSort's application and internal admin tooling cannot read patient, photograph, folder or clinical-note data — enforced at the database level, not just hidden in the interface. Direct administrative access to the production database, which sits outside those controls, is limited to SmileSort's co-founders and used only for maintenance and incident response.
- Automated data lifecycle. A 28-day recoverable Trash before permanent erasure; a lapsed subscription is fully purged 30 days after cancellation, automatically.
- No unnecessary third-party exposure. No third-party analytics or error-tracking tool has access to Patient Data.
- Backup coverage — disclosed, not assumed. The database is backed up daily. Photograph files are not currently covered by a separate file-level backup; SmileSort has assessed and accepted this at current scale, and the Practice should factor it into its own risk assessment.
Annex 3 — Approved sub-processors
| Sub-processor | Entity & location | Purpose | Patient data? |
|---|---|---|---|
| Anthropic | Anthropic PBC — United States | AI classification and sorting of clinical photographs | Yes — image data |
| Supabase | Supabase Pte. Ltd — Singapore (data hosted in the UK) | Database, authentication, file storage | Yes — primary store |
| Cloudflare | Cloudflare, Inc. — United States | Application hosting, execution and CDN | Indirect — execution environment only |
| Stripe | Stripe — see Stripe's own DPA | Subscription billing (account only) | No |
| Resend | Resend — see Resend's own DPA | Transactional email | No |
Every sub-processor established outside the UK has its own DPA incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, independently confirmed rather than assumed. Stripe and Resend are listed for completeness — they never receive Patient Data, verified against every call site that uses them.