Version 2026.2 · in effect from September 9, 2026
Draft document: the company details are not filled in yet. Do not treat it as in force.
This agreement supplements the Terms and Conditions and is entered into between:
The controller — the dental laboratory using Dent Lab Pro, identified by its laboratory account (the "Laboratory");
The processor — [DENUMIRE SOCIETATE], [IDNO], with its registered office at [ADRESĂ SEDIU] ("We", "us").
It applies to the processing of personal data that the Laboratory enters into or receives through the Platform, including health data.
1.1. The Laboratory is the controller. It decides what data is entered, for what purpose, and how long it is kept.
1.2. We are the processor. We process the data solely on the Laboratory's documented instructions. The baseline instruction is normal use of the Platform under the Terms.
1.3. The doctor who sends a case is the controller for their patient's data. The relationship between doctor and Laboratory is outside this agreement; the Laboratory is responsible for the legal basis of the data it receives.
1.4. If we ever determine the purposes of processing ourselves, we become a controller for that processing and will inform you in advance.
2.1. We process the data for as long as the Laboratory has an active account, plus the retention period in Annex D.
2.2. The subject matter, nature, purpose, categories of data and categories of data subjects are described in Annex A.
3.1. We process data only on your instructions, including as regards international transfers. We will inform you immediately if an instruction, in our opinion, infringes applicable law.
If the law applicable to us requires us to process the data otherwise than you instruct, we inform you of that requirement before processing — unless the law prohibits informing you on important grounds of public interest.
3.2. We ensure that persons authorised to process the data are bound by a duty of confidentiality.
3.3. We implement the technical and organisational measures in Annex C.
3.4. We do not engage a new subprocessor without giving you prior notice, as set out in Annex B.
3.5. We assist you, within our means, with:
3.6. On termination we delete or return the data, as set out in Annex D.
3.7. We make available the information needed to demonstrate compliance with these obligations and allow audits, under clause 7.
4.1. You warrant that you have a legal basis for every category of data you enter, including health data, which requires an additional condition under Article 9(2) GDPR.
4.2. You warrant that you have informed data subjects as required by Articles 13 and 14 GDPR. This expressly includes:
We provide a template patient notice. The template is a help, not a transfer of responsibility: the obligation to deliver it remains yours.
4.3. Enter only the data necessary to carry out the work. The Platform is not a medical record.
4.4. You are responsible for managing the accounts in your laboratory: who has access, in what role, and when it is revoked.
5.1. We notify you without undue delay after becoming aware of a security breach affecting your data.
5.2. The notification includes, so far as known to us: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken.
5.3. Notifying the supervisory authority and, where applicable, the data subjects, is your responsibility as controller. We provide the information you need.
6.1. Our subprocessors and the location of processing are listed in Annex B.
6.2. Transfers outside the European Economic Area rely on the European Commission's standard contractual clauses or another valid mechanism.
7.1. On written request, we make available documentation on the measures in Annex C.
7.2. You may request an audit at most once a year, on 30 days' notice, during business hours, without disrupting operations and without access to other customers' data. You bear the cost, unless the audit finds a breach on our part.
8.1. Each party is liable for its own infringements of data protection law.
8.2. The liability cap in the Terms (clause 10.3) does not apply to liability for breach of data protection obligations, including those in this agreement. The other limitations in the Terms continue to apply, to the extent permitted by law.
9.1. This agreement is effective for as long as we process data on your behalf and ends when the data is deleted or returned under Annex D.
9.2. Clauses that by their nature survive termination — confidentiality, liability, audit — remain in force.
Nature and purpose: hosting and processing the data needed to manage dental technical work: receiving orders, planning stages, assigning work to technicians and partners, tracking production, storing files, financial records and notifications.
Categories of data subjects:
| Category | How the data reaches us |
|---|---|
| Patients | Entered by the doctor or the laboratory |
| Doctors and clinics | Own account, or recorded by the laboratory |
| Technicians | Invitation from the laboratory |
| Laboratory owners and staff | Own account |
| External partners (subcontractors) | Recorded by the laboratory |
Ordinary categories of data: first and last name, email address, phone number, clinic or laboratory name, address, role, preferred language, account identifiers, billing details, amounts and financial records, activity records, IP address, browser type, device token.
Special categories of data (Article 9 GDPR) — health data:
| What | Where it appears |
|---|---|
| Patient name | Free-text field on the case |
| Treated teeth and shades | Product order |
| Chairside appointment dates | Try-in stages |
| Clinical notes and rework reasons | Comments on cases and tasks |
| Intraoral and extraoral photographs | Uploaded files |
| Radiographs and medical documents (PDF) | Uploaded files |
| 3D intraoral scans (STL, OBJ) | Uploaded files |
Frequency: continuous, for the duration of the contract.
The current list is published at https://dentlabpro.com/en/legal/subprocessors and forms an integral part of this agreement.
Change procedure. We give you at least 30 days' notice before engaging a new subprocessor or replacing an existing one. During that period you may object in writing, with reasons. If the objection cannot be resolved, you may terminate without penalty, effective from the date the subprocessor would begin processing.
We impose on each subprocessor data protection obligations at least equivalent to those in this agreement, and we remain fully liable to you for its performance.
Access control. Authentication is delegated to an identity provider; we store no passwords. Access is limited by role and by laboratory membership, checked on every request. Sessions can be revoked individually or for a whole laboratory.
Tenant isolation. Every record carries the laboratory identifier and queries are filtered by it. Looking up a code that does not belong to your laboratory returns the same response as a non-existent code, so the existence of another customer's data cannot be inferred.
Encryption. Traffic is encrypted in transit. Files are served through temporary, time-limited addresses rather than permanent public links. At rest, content is encrypted by the object storage provider and by the database provider, with keys managed by them. We also state what we do not do: we apply no field-level encryption layer of our own in the database, so protection at rest is that of the providers in Annex B, not an additional layer from us.
Pseudonymisation. We do not pseudonymise patient data in day-to-day operation: the patient's name is the very means by which the laboratory identifies the case at the bench. We apply it where it has real effect — on account closure, through irreversible anonymisation, and when redacting a particular patient's data at your request as controller.
Logging. Sensitive administrative actions require a written reason and are written to a log that cannot be altered or deleted. The log records the actor, the time, the target, the before and after state, the IP address and the browser.
Our staff's access. Limited to technical support, incident investigation, or a legal obligation. Each access to a customer account requires a recorded reason, is time-limited, and is written to the log.
Backups and continuity. The database is hosted with a provider that performs regular backups and point-in-time restore.
Testing and evaluation. We reassess the measures here at every significant architectural change and at least once a year, and retention periods are held in a single place in the code so they cannot silently diverge from the documents. What we do not have yet: a formal programme of penetration testing by an independent third party. When we do, we will state it here.
Deletion. Files deleted in the interface are permanently removed, including from object storage, after 30 days.
Measures may evolve. We do not reduce them below the level described here without informing you.
The choice is yours. On termination you decide, as controller: we either return the data in a structured, commonly used, machine-readable format, or delete it. Tell us your choice at [EMAIL PROTECȚIA DATELOR].
Extraction period. Whichever you choose, the Laboratory's data remains available for 90 days after termination so that you can export it yourself from the app. We tell you the date from which deletion begins.
Deletion. If you do not tell us your choice within those 90 days, we delete — after the period expires we permanently delete the laboratory's data, including files in object storage.
What is kept, and why. We do not delete records the law requires us to keep: accounting documents under tax legislation, and audit logs — 24 months — as evidence of who did what. The full periods are in the Privacy Policy; when they expire, the records are deleted.
These periods are shorter than your own legal obligations to retain medical documentation. Extracting your data before the 90-day period expires is your responsibility.