Data Processing Agreement (model)
Agreement on the processing of personal data on behalf of a controller pursuant to Art. 28 GDPR between the using laboratory ("Controller") and [FIRMA EINTRAGEN], [STRASSE + HAUSNUMMER EINTRAGEN], [PLZ EINTRAGEN] [ORT EINTRAGEN] ("Processor"). This DPA becomes part of the contract once the Controller agrees to it during registration or in the account settings.
1. Subject and duration
The Processor operates the Pontiq platform and processes personal data on behalf of the Controller for the duration of the platform usage contract.
2. Nature, purpose and scope
Collection, storage, display, transmission and deletion of the data the Controller processes via the platform, in particular for case and order management, production planning, document generation and optional AI features.
3. Categories of data subjects and data
- Data subjects: patients of the submitting dental practices; employees of the Controller; contact persons of the practices.
- Data categories: identification data (e.g. patient name/pseudonym, case numbers), order and case data (work type, material, shade, notes), 3D scan files and attachments, user data of employees (name, email, role), communication data. Health data within the meaning of Art. 9 GDPR may be included.
4. Instructions
The Processor processes data exclusively on documented instructions of the Controller; use of the platform features constitutes an instruction. If the Processor considers an instruction unlawful, it informs the Controller without undue delay.
5. Confidentiality
Only persons committed to confidentiality or subject to an appropriate statutory duty of secrecy are deployed.
6. Technical and organizational measures (Art. 32 GDPR)
TLS transport encryption for all connections; encrypted storage of access tokens and password hashing; role-based access control and tenant isolation at data level; logging of security-relevant events; regular backups and restore tests; hosting exclusively in EU data centers. Measures are maintained in line with the state of the art.
7. Sub-processors
The Controller generally approves sub-processors for hosting (EU), email delivery and AI processing (Mistral AI SAS, France — processing within the EU). The Processor announces intended changes with reasonable notice; the Controller may object for important data protection reasons. Art. 28 (4) GDPR agreements exist with all sub-processors.
8. Assistance
The Processor reasonably assists the Controller with data subject rights (Art. 12–23 GDPR), security of processing, breach notifications (Art. 33, 34 GDPR) and data protection impact assessments (Art. 35, 36 GDPR).
9. Breach notification
The Processor notifies the Controller of personal data breaches without undue delay, at the latest within 48 hours of becoming aware, including the information required by Art. 33 (3) GDPR where available.
10. Deletion and return
After the usage contract ends, the Processor deletes or returns all personal data unless statutory retention duties apply. The Controller may request a data export beforehand (provided within 30 days).
11. Evidence and audits
The Processor provides all information necessary to demonstrate compliance. The Controller may conduct audits after prior notice during normal business hours or have them conducted by suitable third parties; existing attestations and reports are used with priority.
12. Final provisions
German law applies. Otherwise the provisions of the main contract (Terms of Service) apply. Should individual provisions be invalid, the remainder stays in force.