This Data Processing Agreement ("DPA") forms part of the Terms of Service between Smileline Ltd (the "Processor") and the practice accepting it (the "Controller" or "Practice"). It is entered into when the Practice owner accepts it in the app, and it governs all processing of Practice Data that contains personal data. It is written to satisfy Article 28 of the UK GDPR.
1. Roles and scope
The Practice is the controller of the personal data it stores in the Service — its patients, leads and contacts. Smileline is the processor and processes that data only to provide the Service, on the documented instructions given through the Practice's use of the platform. Smileline is a separate, independent controller of its own account, billing and security data, as described in the Privacy Policy.
2. Details of the processing
| Subject matter | Hosting and operating a dental CRM: lead capture, patient records, journeys, messaging, scheduling, reporting and integrations. |
|---|---|
| Duration | The term of the Practice's subscription, plus the deletion window in section 9. |
| Nature and purpose | Storage, retrieval, display, transmission (messages the Practice sends), analysis (reports) and the automated workflows the Practice configures. |
| Data subjects | The Practice's patients, prospective patients (leads/enquiries), their contacts, and Practice staff. |
| Categories of personal data | Contact details, demographic details, enquiry and communication history, appointment and treatment-interest information, payment status, marketing consents, and identifiers from connected systems. |
| Special category data | Data concerning health — dental history, treatment plans and clinical context the Practice records or syncs from its practice management system. The Practice is responsible for its Article 9 condition for processing this data (typically the provision of health care, Art. 9(2)(h)). |
3. The Processor's obligations
Smileline shall:
- process Practice Data only on the Practice's documented instructions (the platform's features and settings), unless required by law to do otherwise — in which case it will inform the Practice unless the law prevents it;
- ensure everyone authorised to access Practice Data is bound by confidentiality;
- implement the technical and organisational measures in section 6;
- respect the sub-processing conditions in section 5;
- assist the Practice, taking into account the nature of the processing, in responding to data-subject rights requests and in meeting its obligations on security, breach notification and impact assessments;
- delete or return Practice Data as set out in section 9;
- make available the information reasonably necessary to demonstrate compliance with this DPA, and allow audits as set out in section 10.
4. The Practice's obligations
The Practice warrants that it has a lawful basis (and, for health data, an Article 9 condition) for the personal data it stores in the Service; that its patient-facing privacy information covers the use of a CRM processor; and that the instructions it gives through the platform comply with UK data protection law. The Practice controls — and is responsible for — who on its team can access what, through the platform's roles.
5. Sub-processors
The Practice gives general authorisation to the sub-processors below. Smileline will give at least 30 days' notice before adding or replacing a sub-processor (by updating this page and notifying account owners), during which the Practice may object on reasonable data-protection grounds; if the objection cannot be resolved, the Practice may terminate and export its data.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Application hosting, networking, storage | UK/EU edge; global network |
| Managed PostgreSQL provider | Primary database hosting | EU |
| Stripe Payments Europe, Ltd. | Subscription billing | EU/US |
| Resend, Inc. | Transactional email delivery | EU/US |
| OpenAI, LLC | AI assistant features — only where the Practice enables the AI add-on | US |
Messaging and integration providers the Practice connects itself (WhatsApp/SMS providers, its practice management system, advertising platforms) act under the Practice's own agreements with them and are not Smileline sub-processors.
6. Security measures
- Encryption in transit (TLS 1.2+) and at rest;
- per-practice data isolation enforced at the application layer on every query;
- role-based access control within the Practice, and audit logging of actions taken in the platform;
- additional envelope encryption for stored channel credentials and secrets;
- restricted, credentialed access to production systems for Smileline staff, limited to what operating the Service requires;
- backups and tested restore procedures.
7. International transfers
Practice Data is hosted in the UK/EU where the provider allows it. Where a sub-processor processes personal data outside the UK, the transfer is protected by UK adequacy regulations or standard contractual clauses with the UK International Data Transfer Addendum.
8. Personal data breaches
Smileline will notify the Practice without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Practice Data, and will provide the information the Practice needs for its own notification obligations, cooperating in the investigation and remediation.
9. Return and deletion
The Practice can export its data from the platform at any time. Following termination of the subscription, Smileline will delete Practice Data from production systems within 90 days, and from backups as they expire on their rotation schedule, unless retention is required by law.
10. Audits
Smileline will make available documentation demonstrating compliance with this DPA. Where that is insufficient, the Practice (or its appointed auditor, not a Smileline competitor) may audit once in any 12-month period, on 30 days' notice, during business hours, without disrupting the Service, and subject to confidentiality.
11. Liability and precedence
The liability provisions of the Terms of Service apply to this DPA. If this DPA conflicts with the Terms on data-protection matters, this DPA prevails. This DPA is governed by the laws of England and Wales.
12. Record of acceptance
The Practice owner accepts this DPA in the app during onboarding (and again when a new version is published). Smileline records who accepted, the version, the time, IP address and browser; the Practice can view its acceptance record at any time in Settings → Agreements.