Skip to content
Legal

Data processing addendum

The processing terms between a clinic, which controls patient data, and Dently, which processes it on the clinic's instructions.

Last updated September 2026

Roles

The clinic is the controller of patient data. Dently is the processor. We process patient data only to provide the service, only on the clinic’s documented instructions, and for no purpose of our own.

Scope of processing

Subject matter: operation of a dental practice management system. Duration: the term of the agreement plus the 90-day retention window. Categories of data subject: the clinic’s patients and staff. Categories of data: identity and contact details, clinical records, appointment history and payment records.

Sub-processors

We use a small number of sub-processors for hosting, messaging and payments. The current list is available on request and we will give notice before adding one, so a clinic that objects has time to do so.

Security

Encryption in transit and at rest, role-based access scoped per location, and an audit log of every read and write of a patient record that the practice owner can query without asking us. We hold no ISO 27001 or SOC 2 report at this time.

Breach notification

We will notify an affected clinic without undue delay and in any case within 72 hours of becoming aware of a personal data breach, with what we know at the time rather than waiting for a complete picture.

Deletion and return

On termination, clinic data is retained for 90 days and then deleted. Export is available throughout, and immediate deletion is available on request.

Contacting us

Questions about this document, or a request under it, go to hello@thedently.com. We aim to acknowledge within two working days.