PontiqPontiq
Features Integrations Pricing Desktop Agent Help Center Contact
Start for free

Data Processing Agreement (model)

Agreement on the processing of personal data on behalf of a controller pursuant to Art. 28 GDPR between the using laboratory ("Controller") and [FIRMA EINTRAGEN], [STRASSE + HAUSNUMMER EINTRAGEN], [PLZ EINTRAGEN] [ORT EINTRAGEN] ("Processor"). This DPA becomes part of the contract once the Controller agrees to it during registration or in the account settings.

1. Subject and duration

The Processor operates the Pontiq platform and processes personal data on behalf of the Controller for the duration of the platform usage contract.

2. Nature, purpose and scope

Collection, storage, display, transmission and deletion of the data the Controller processes via the platform, in particular for case and order management, production planning, document generation and optional AI features.

3. Categories of data subjects and data

  • Data subjects: patients of the submitting dental practices; employees of the Controller; contact persons of the practices.
  • Data categories: identification data (e.g. patient name/pseudonym, case numbers), order and case data (work type, material, shade, notes), 3D scan files and attachments, user data of employees (name, email, role), communication data. Health data within the meaning of Art. 9 GDPR may be included.

4. Instructions

The Processor processes data exclusively on documented instructions of the Controller; use of the platform features constitutes an instruction. If the Processor considers an instruction unlawful, it informs the Controller without undue delay.

5. Confidentiality

Only persons committed to confidentiality or subject to an appropriate statutory duty of secrecy are deployed.

6. Technical and organizational measures (Art. 32 GDPR)

TLS transport encryption for all connections; encrypted storage of access tokens and password hashing; role-based access control and tenant isolation at data level; logging of security-relevant events; regular backups and restore tests; hosting exclusively in EU data centers. Measures are maintained in line with the state of the art.

7. Sub-processors

The Controller generally approves sub-processors for hosting (EU), email delivery and AI processing (Mistral AI SAS, France — processing within the EU). The Processor announces intended changes with reasonable notice; the Controller may object for important data protection reasons. Art. 28 (4) GDPR agreements exist with all sub-processors.

8. Assistance

The Processor reasonably assists the Controller with data subject rights (Art. 12–23 GDPR), security of processing, breach notifications (Art. 33, 34 GDPR) and data protection impact assessments (Art. 35, 36 GDPR).

9. Breach notification

The Processor notifies the Controller of personal data breaches without undue delay, at the latest within 48 hours of becoming aware, including the information required by Art. 33 (3) GDPR where available.

10. Deletion and return

After the usage contract ends, the Processor deletes or returns all personal data unless statutory retention duties apply. The Controller may request a data export beforehand (provided within 30 days).

11. Evidence and audits

The Processor provides all information necessary to demonstrate compliance. The Controller may conduct audits after prior notice during normal business hours or have them conducted by suitable third parties; existing attestations and reports are used with priority.

12. Final provisions

German law applies. Otherwise the provisions of the main contract (Terms of Service) apply. Should individual provisions be invalid, the remainder stays in force.

PontiqPontiq

All scanners. One inbox. One workflow.

Product

  • Features
  • Integrations
  • Pricing
  • Desktop Agent

Resources

  • Help Center
  • Desktop Agent
  • Contact
  • Demo
  • Log in

Legal

  • Imprint
  • Terms
  • Privacy
  • Withdrawal
  • DPA

© 2026 Pontiq. All rights reserved.