Data Processing Addendum
Effective Date: May 11, 2026
Last Updated: May 11, 2026
Document Version: 1.0
This Data Processing Addendum is available in English only. The English language version is the legally binding version for all jurisdictions in which Dentare operates.
Legal Entity: FETOSOFT DOOEL ("Dentare")
Address: Goce Delchev 2/32, 1300 Kumanovo, North Macedonia
SaaS Product: Dentare — https://dentare.io
Privacy contact: [email protected]
1) Introduction and Acceptance
This Data Processing Addendum (the "DPA") forms part of, and is incorporated by reference into, the Dentare Terms of Service (the "Agreement") between Dentare and the customer that has entered into the Agreement (the "Customer"). It applies whenever Dentare processes Personal Data (as defined below) on behalf of the Customer in connection with the Customer's use of the Dentare Service, in particular to any Customer established in, or processing Personal Data of individuals located in, the European Union, the European Economic Area, the United Kingdom, or Switzerland, or where the Customer is otherwise subject to Applicable Data Protection Law.
The DPA is accepted electronically. By accepting the Agreement, by clicking "I agree" (or a similar control), or by continuing to use the Service after this DPA becomes effective, the Customer enters into this DPA on behalf of itself and, to the extent required under Applicable Data Protection Law, in the name and on behalf of its Authorized Affiliates. No separate signed copy is required for this DPA to be valid and enforceable.
If the Customer requires a counter-signed copy for its own audit or record-keeping purposes, the Customer may request one from [email protected]. Dentare will provide a counter-signed PDF that reflects the version of this DPA in force at the time of the request without modifying its substantive terms.
2) Definitions
Capitalized terms used but not defined herein have the meaning given in the Agreement. For purposes of this DPA:
- "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under the Agreement, including, as applicable: (i) Regulation (EU) 2016/679 (the "GDPR"); (ii) the UK Data Protection Act 2018 and the UK GDPR; (iii) the Swiss Federal Act on Data Protection ("FADP"); and (iv) any successor or implementing legislation.
- "Customer" means the dental clinic, practice, or other entity that has entered into the Agreement with Dentare.
- "Dentare" means FETOSOFT DOOEL, the legal entity that operates the Dentare platform at https://dentare.io.
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Dentare on behalf of the Customer under the Agreement. This includes patient identity, contact, appointment, communication, and (where the Customer elects to record it) health-related information that the Customer or its patients submit to the Service.
- "Processing" (and its grammatical variants) has the meaning given in Article 4(2) GDPR.
- "Data Subject" means an identified or identifiable natural person to whom Personal Data relates, including the Customer's patients, prospective patients, employees, contractors, and end users of the Service.
- "Sub-processor" means any third party engaged by Dentare to process Personal Data on the Customer's behalf in connection with the Service.
- "Standard Contractual Clauses" or "SCCs" means: (i) the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914 of 4 June 2021, in the module(s) appropriate to the relevant transfer; and (ii) where applicable, the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018.
- "Authorized Affiliate" means any entity that controls, is controlled by, or is under common control with the Customer, where "control" means ownership of more than 50% of the voting equity or equivalent governance rights, and that is permitted to use the Service under the Agreement.
3) Roles and Scope of Processing
For the purposes of this DPA and Applicable Data Protection Law, the parties agree that:
- The Customer acts as the data controller of Personal Data submitted to or processed through the Service;
- Dentare acts as the data processor processing Personal Data on the Customer's documented instructions;
- Where Dentare engages Sub-processors to perform specific processing activities on behalf of the Customer, those Sub-processors act as sub-processors of Dentare and, in turn, of the Customer.
The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Annex 1 to this DPA.
Each party is independently responsible for its own compliance with Applicable Data Protection Law in respect of its role. In particular, the Customer is solely responsible for the lawfulness of the collection of Personal Data, for establishing and maintaining a valid legal basis for processing, for providing required notices to Data Subjects, and for honoring the rights of Data Subjects.
4) Customer Instructions
Dentare will process Personal Data only on the Customer's documented instructions, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by Union or Member State law to which Dentare is subject. The Agreement, this DPA, and the Customer's use of the Service through its permitted configuration options constitute the Customer's complete and final instructions to Dentare regarding the processing of Personal Data.
Additional or alternative instructions must be agreed upon in writing between the parties and may, at Dentare's discretion, result in additional fees if they materially change the nature, scope, or cost of the processing.
Dentare will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. In such cases, Dentare may suspend performance of the relevant instruction (without liability) until the Customer modifies or confirms the instruction in writing.
5) Confidentiality
Dentare will ensure that any person it authorizes to process Personal Data (including its employees, contractors, and Sub-processors) is bound by an obligation of confidentiality, whether by contract or statutory duty. Such persons will process Personal Data only as necessary to provide the Service and only in accordance with the Customer's instructions and this DPA.
6) Security Measures
Dentare implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk presented by the processing, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks of varying likelihood and severity for the rights and freedoms of Data Subjects.
These measures are described in Annex 2 (Technical and Organizational Measures) to this DPA. They include, at a minimum, encryption of Personal Data in transit and at rest, multi-tenant data isolation, role-based access controls, multi-factor authentication for staff with administrative access, audit logging, vulnerability scanning, automated backups, and a documented incident response procedure.
Dentare may update its security measures from time to time, provided that any such update does not materially reduce the overall level of protection of Personal Data.
7) Sub-processors
The Customer hereby grants Dentare a general authorization to engage Sub-processors to process Personal Data on the Customer's behalf, subject to the conditions in this Section 7.
7.1 Current Sub-processors
Dentare maintains an up-to-date list of its Sub-processors in the "Service Providers & Subprocessors" section of the Dentare Privacy Policy. That list is the single source of truth and is incorporated into this DPA by reference. By accepting this DPA, the Customer specifically authorizes Dentare to engage the Sub-processors listed there as of the Effective Date. Bilateral Data Protection Addenda have been executed with selected Sub-processors and are available to the Customer on request, including the executed DPA with The Constant Company, LLC (Vultr) dated 12 May 2026.
7.2 New Sub-processors
Dentare will provide reasonable advance notice (at least thirty (30) days, where practicable) of any intended addition or replacement of a Sub-processor by updating the list in the Privacy Policy. Customers that have provided contact information for sub-processor notifications will additionally be notified by email. The Customer acknowledges that, given the dynamic nature of cloud-based services, Sub-processors providing emergency security, fraud-prevention, or business-continuity functions may need to be engaged on shorter notice; in such cases, Dentare will provide notice as soon as reasonably practicable.
7.3 Right to Object
The Customer may object in writing to the engagement of a new Sub-processor on reasonable, documented data-protection grounds within thirty (30) days of the notice described in Section 7.2. If the Customer objects, the parties will work together in good faith to find a workable resolution. If no resolution can be reached, Dentare may, at its option, either (a) not engage the new Sub-processor with respect to the Customer's Personal Data, or (b) permit the Customer to terminate the affected portion of the Service for convenience on a pro-rata refund of any prepaid fees that cover the unused portion of the term. Continued use of the Service after the thirty (30)-day period constitutes acceptance of the new Sub-processor.
7.4 Sub-processor Obligations
Dentare will impose data-protection obligations on each Sub-processor that are no less protective than those set out in this DPA, by way of a written contract, including in particular obligations relating to security, confidentiality, data-subject rights assistance, breach notification, and international transfers. Dentare remains liable to the Customer for the acts and omissions of its Sub-processors to the same extent as for its own acts and omissions under this DPA.
8) Data Subject Rights Assistance
Taking into account the nature of the processing, Dentare will assist the Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests for the exercise of Data Subjects' rights under Applicable Data Protection Law (including the rights of access, rectification, erasure, restriction of processing, data portability, objection, and the right not to be subject to automated decision-making).
The Service provides the Customer with self-service functionality to respond to most Data Subject requests, including the ability to access, export, correct, and delete patient records. Where the Customer requires additional reasonable assistance that cannot be performed through the Service, Dentare will provide such assistance promptly and at no additional charge for assistance that is not unreasonable in scope.
If Dentare receives a Data Subject request directed at Customer Personal Data, it will, where lawful to do so, promptly notify the Customer and direct the Data Subject to the Customer. Dentare will not respond directly to such requests except on the Customer's documented instructions or as required by law.
9) Personal Data Breaches
Dentare will notify the Customer without undue delay, and in any event with the goal of doing so within forty-eight (48) hours after becoming aware of a Personal Data breach affecting the Customer's Personal Data. The notification will, to the extent the information is then available, include:
- a description of the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach and to mitigate its possible adverse effects;
- the name and contact details of a Dentare point of contact for further information.
Where it is not possible to provide all the information at the same time, Dentare may provide it in phases without further undue delay. Dentare's notification of a breach is not, of itself, an acknowledgement by Dentare of any fault or liability with respect to the breach.
The Customer is responsible for notifying supervisory authorities and affected Data Subjects where required under Applicable Data Protection Law. Dentare will provide reasonable assistance to the Customer in meeting those obligations.
10) Data Protection Impact Assessments and Prior Consultation
Taking into account the nature of the processing and the information available to Dentare, Dentare will provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with supervisory authorities that the Customer is required to carry out under Articles 35 and 36 GDPR (or the equivalent provisions of other Applicable Data Protection Law). Such assistance may include providing relevant documentation about Dentare's security measures, sub-processing arrangements, and data flows.
11) International Data Transfers
Dentare's primary infrastructure for production data (including application servers, databases, and object storage for patient-uploaded files) is located within the European Union. The primary hosting region is Amsterdam, Netherlands (The Constant Company, LLC, operating as Vultr). Edge services (DNS, CDN, DDoS protection) are provided by Cloudflare, Inc. via its EU edge network.
Where Personal Data is transferred from the EEA, the United Kingdom, or Switzerland to a country that has not been recognized by the European Commission, the UK government, or the Swiss Federal Data Protection and Information Commissioner as providing an adequate level of protection for Personal Data, Dentare will rely on one or more of the following transfer mechanisms:
- the EU Standard Contractual Clauses in their Module 3: Processor to Processor form for transfers from Dentare (as processor) to a Sub-processor;
- the EU Standard Contractual Clauses in their Module 2: Controller to Processor form where the Customer is established outside the EEA and instructs Dentare to process EEA-origin Personal Data on its behalf, and no other adequacy mechanism applies;
- the UK International Data Transfer Addendum to the EU SCCs for transfers subject to UK GDPR;
- the Swiss FADP-equivalent addendum or amendment to the EU SCCs where required for transfers subject to the FADP;
- any other lawful transfer mechanism recognized under Applicable Data Protection Law from time to time.
The Customer authorizes Dentare to enter into the SCCs and any related transfer mechanisms with Sub-processors on the Customer's behalf. The applicable SCCs are incorporated into this DPA by reference and apply to the relevant transfers as if executed by the Customer and Dentare directly. On request, Dentare will provide the Customer with copies of the executed SCCs with its Sub-processors, with any commercially sensitive information redacted.
Dentare has executed a bilateral Data Processing Addendum with each Sub-processor for which one is procedurally available. As of the date of this DPA, executed DPAs are on file for: The Constant Company, LLC (operating as Vultr; executed 12 May 2026, EU SCCs Module 2 and Module 3, UK IDTA, Swiss DPA modifications). Additional executed DPAs are being collected progressively; the current state is reflected in Dentare's internal sub-processor registry and is viewable on request via [email protected].
12) Audits and Inspections
Dentare will make available to the Customer all information reasonably necessary to demonstrate compliance with its obligations under this DPA and Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer, subject to the following:
- Frequency. The Customer may request an audit no more than once in any twelve (12)-month period, except where required by a supervisory authority or following a confirmed Personal Data breach affecting the Customer's Personal Data.
- Notice. The Customer will provide at least thirty (30) days' written notice in advance of any audit and will schedule the audit during Dentare's regular business hours.
- Scope. The audit will be limited to information, systems, and facilities relevant to the processing of the Customer's Personal Data and will not include access to data, systems, or premises of other Dentare customers.
- Confidentiality. The Customer and its auditor will be bound by appropriate confidentiality obligations. Dentare may require the auditor to sign a non-disclosure agreement before any audit begins.
- Cost. Audits will be carried out at the Customer's expense. Dentare may charge a reasonable fee for assistance that goes materially beyond standard cooperation.
- Third-party reports. The Customer agrees that Dentare may satisfy its obligation under this Section by providing copies of third-party audit reports (such as ISO 27001 certification reports, penetration-test summaries, or equivalent attestations) instead of permitting an on-site inspection, provided that such reports adequately address the scope of the proposed audit.
Nothing in this Section limits the audit rights of supervisory authorities under Applicable Data Protection Law.
13) Return and Deletion of Personal Data
Upon termination or expiration of the Agreement, Dentare will, at the Customer's choice, return or delete all Personal Data processed on the Customer's behalf within thirty (30) days, unless retention is required by Union or Member State law applicable to Dentare. The Customer's choice (return or delete) must be communicated to Dentare in writing during the thirty (30)-day period; absent a choice, Dentare will delete the Personal Data.
Dentare may retain Personal Data in encrypted backups for the duration of its standard backup retention cycle, after which the data is overwritten. During that residual retention period, the data remains subject to the confidentiality and security obligations in this DPA and will not be actively processed for any other purpose.
Certain categories of data (such as billing records, fiscal records, and accounting documentation) are retained for the periods specified in the Dentare Privacy Policy and as required by applicable tax, accounting, and other regulatory law. Such retention is on Dentare's own behalf as a controller of that data for legal-obligation purposes and is not, for the avoidance of doubt, processing on the Customer's behalf under this DPA.
14) Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations of liability set out in the Agreement, and any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together.
Nothing in this DPA limits or excludes either party's liability to a Data Subject under Article 82 GDPR or the equivalent provisions of other Applicable Data Protection Law.
15) Governing Law and Jurisdiction
This DPA is governed by the laws of the Republic of North Macedonia, except where Applicable Data Protection Law mandates a different governing law (in particular, the SCCs are governed by the law of an EU Member State as specified in the SCCs themselves, and the UK Addendum is governed by the laws of England and Wales).
Subject to mandatory provisions of Applicable Data Protection Law, any dispute arising out of or in connection with this DPA will be resolved by the competent courts of Skopje, North Macedonia, except where the Agreement specifies an alternative forum, in which case that forum applies to the extent not inconsistent with Applicable Data Protection Law.
16) Term, Order of Precedence, and Updates
This DPA takes effect on the date the Customer accepts it and remains in force for as long as Dentare processes Personal Data on the Customer's behalf under the Agreement. Sections relating to confidentiality, liability, governing law, and any provision that by its nature is intended to survive termination will continue in force after termination.
In the event of a conflict between this DPA and the Agreement, this DPA prevails with respect to matters concerning the processing of Personal Data. In the event of a conflict between this DPA and any executed SCCs, the SCCs prevail to the extent of the conflict for the relevant transfer.
Dentare may update this DPA from time to time. Material changes will be communicated to the Customer in advance, either by email to the address associated with the Customer's account or by a prominent notice within the Service. If the Customer continues to use the Service after the effective date of a material change, the Customer is deemed to have accepted the updated DPA. Non-material changes (such as clarifications, corrections of typographical errors, or the addition of optional safeguards) take effect on the date specified at the top of this document.
Annex 1 — Description of the Processing
This Annex describes the processing of Personal Data carried out by Dentare on the Customer's behalf under the Agreement.
Subject matter
The provision of the Dentare practice-management Service to the Customer, including hosting, transmission, display, and processing of Personal Data submitted by or on behalf of the Customer.
Duration
The duration of the Agreement plus any post-termination period required to return or delete the Personal Data in accordance with Section 13.
Nature and purpose of processing
To enable the Customer to operate its dental practice using the Service, including (without limitation): patient registration and record-keeping; appointment scheduling, booking, and reminders; patient and staff communications by SMS, email, and WhatsApp; treatment planning, visit documentation, X-ray request management, and laboratory order management; payment and invoicing; fiscalization where applicable; partner / referral program administration; security, fraud-prevention, and abuse-prevention activities; service operation, support, monitoring, troubleshooting, and improvement.
Categories of Data Subjects
- The Customer's patients (current, former, and prospective);
- The Customer's staff, including owners, dentists, hygienists, technicians, assistants, and receptionists, who use the Service;
- The Customer's contractors, partners, and other authorized users of the Service;
- Emergency contacts and guardians designated by the Customer's patients;
- Other natural persons whose data the Customer chooses to record in the Service.
Categories of Personal Data
- Identity and contact data: name, date of birth, gender, national identifier (where applicable and lawfully collected), email address, phone number, postal address.
- Account credentials and security data: hashed passwords, hashed PINs, OAuth tokens, sign-in event logs, device hashes, IP addresses, user-agent strings, geolocation derived locally from IP.
- Appointment and scheduling data: dates, times, services requested, doctor, room, status, notes.
- Communication content and metadata: SMS, email, and WhatsApp message records, including recipient, content, delivery status, and timestamps.
- Health-related data (only where the Customer elects to record it and is lawfully permitted to do so): blood type, allergies, medical history, dental chart notes, treatment plans, before/after images, X-ray images, laboratory orders.
- Financial data: billing details, payment status, invoices, fiscal receipts, partner-program payout information (where applicable).
- Consent and audit records: notification-channel opt-in history, terms-acceptance records, security audit logs.
Special categories of Personal Data
To the extent the Customer records health-related data (Article 9(1) GDPR), the Customer is responsible for ensuring that an appropriate exemption under Article 9(2) GDPR applies (most commonly Article 9(2)(h) — provision of health care). Dentare applies country-based data minimization on public, unauthenticated surfaces such as the QR patient self-registration form (see the Privacy Policy for details).
Annex 2 — Technical and Organizational Measures
Dentare implements and maintains the following technical and organizational measures to protect Personal Data processed on the Customer's behalf. These measures are reviewed periodically and may be updated provided that the overall level of protection of Personal Data is not materially reduced.
A. Encryption and transport security
- TLS 1.2 or higher enforced for all connections to the Service, with HSTS for production endpoints.
- AES-256 encryption at rest for production databases and object storage of patient-uploaded files.
- OAuth tokens, partner-program bank details, and other particularly sensitive fields are encrypted at the application layer in addition to disk-level encryption.
- HMAC-SHA256 signature verification on all inbound webhooks from third-party providers (e.g., Meta WhatsApp Business Cloud API) to prevent forged status updates.
B. Access control and authentication
- Multi-tenant data isolation enforced at the application layer using row-level tenant scoping (
acts_as_tenant) on all tenant-scoped models, with cross-tenant queries blocked by default. - Role-based access controls within the Service (owner, doctor, receptionist, technician, etc.), enforced by an authorization layer.
- Multi-factor authentication (MFA) available for all Customer end users and mandatory for Dentare staff with administrative access to production systems or databases.
- Principle of least privilege: production database and infrastructure access is limited to named staff who require it for their role.
- Progressive lockout on repeated failed sign-in or PIN attempts; automated lockout on patterns indicative of brute-force or credential-stuffing attacks.
- Automated risk scoring on every sign-in (device trust, IP geolocation, impossible-travel detection, behavioral signals), performed on-server with no third-party scoring services.
C. Logging, monitoring, and incident response
- Audit logging of authentication events, kiosk lock/unlock events, consent changes, administrative actions, and other security-relevant operations.
- Error monitoring with automatic redaction of known sensitive fields before reports leave Dentare's infrastructure.
- Documented incident response procedure with defined escalation paths and notification targets.
- Personal data breach notification to affected Customers without undue delay and with the goal of doing so within forty-eight (48) hours of becoming aware of the breach (see Section 9).
D. Backups and resilience
- Automated daily database backups with point-in-time recovery for the production database.
- Backups encrypted at rest and stored within the EU region.
- Documented restore procedures, tested on a periodic basis.
E. Application security and vulnerability management
- Static application security testing on every change to the Service (Brakeman) and dependency-vulnerability scanning (
bundle audit) integrated into the development pipeline. - Secure software development lifecycle, including code review for all changes affecting production.
- Penetration testing roadmap: external penetration testing planned on a periodic basis once the Service has reached the relevant maturity threshold, with remediation tracked to closure.
- Filter parameter logging configured to exclude passwords, PINs, OAuth tokens, payment data, and other sensitive fields from application logs.
F. Organizational and personnel measures
- Confidentiality obligations imposed on all employees and contractors who may access Personal Data.
- Security awareness training for staff with access to production systems.
- Vendor security review prior to engaging Sub-processors that process Personal Data.
- Information Security Management System (ISMS) aligned with ISO/IEC 27001; formal certification is part of Dentare's ongoing compliance roadmap.
G. Physical security
- All production data is hosted in third-party data centers operated by Sub-processors with their own physical security controls (access control, surveillance, environmental controls, fire suppression). The primary production region is Amsterdam (The Constant Company, LLC, operating as Vultr), within the European Union.
Annex 3 — List of Sub-processors
The current list of Sub-processors engaged by Dentare to process Personal Data on behalf of the Customer is maintained in the "Service Providers & Subprocessors" section of the Dentare Privacy Policy. That list is incorporated into this DPA by reference and is the single source of truth.
For each Sub-processor, the Privacy Policy identifies the entity, the processing activity performed, and (where available) a link to that Sub-processor's data processing agreement or equivalent Article 28 GDPR terms.
Changes to the list of Sub-processors are governed by Section 7 of this DPA.
Contact
For any questions, audit requests, sub-processor objections, or other matters relating to this DPA, please contact:
[email protected]
FETOSOFT DOOEL, Goce Delchev 2/32, 1300 Kumanovo, North Macedonia