Data processing addendum
The processing terms between a clinic, which controls patient data, and Dently, which processes it on the clinic's instructions.
Last updated September 2026
Roles
The clinic is the controller of patient data. Dently is the processor. We process patient data only to provide the service, only on the clinic’s documented instructions, and for no purpose of our own.
Scope of processing
Subject matter: operation of a dental practice management system. Duration: the term of the agreement plus the 90-day retention window. Categories of data subject: the clinic’s patients and staff. Categories of data: identity and contact details, clinical records, appointment history and payment records.
Sub-processors
We use a small number of sub-processors for hosting, messaging and payments. The current list is available on request and we will give notice before adding one, so a clinic that objects has time to do so.
Security
Encryption in transit and at rest, role-based access scoped per location, and an audit log of every read and write of a patient record that the practice owner can query without asking us. We hold no ISO 27001 or SOC 2 report at this time.
Breach notification
We will notify an affected clinic without undue delay and in any case within 72 hours of becoming aware of a personal data breach, with what we know at the time rather than waiting for a complete picture.
Deletion and return
On termination, clinic data is retained for 90 days and then deleted. Export is available throughout, and immediate deletion is available on request.
Contacting us
Questions about this document, or a request under it, go to hello@thedently.com. We aim to acknowledge within two working days.