Data Processing Addendum
Version 1.0. Last updated: 7 October 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Outlook Aesthetics Ltd, trading as Dentistry Dashboard (company number 12259567, registered office Flat 60, 340A Clapham Road, London SW9 9FA) (“we”, “us”, the “Processor”), and the customer that uses the Services (the “Customer”, the “Controller”). It applies whenever we process personal data on the Customer’s behalf.
The Customer accepts this DPA by accepting the Terms of Service. NHS organisations and dental groups can also sign it as a standalone agreement, or ask us to sign their own data processing terms, by emailing info@dentistrydashboard.com. A signed agreement takes precedence over this page.
1. Definitions
- Data Protection Law means the UK GDPR, the Data Protection Act 2018 and, where they apply, the EU GDPR and other laws on the processing of personal data.
- Customer Personal Data means personal data we process on the Customer’s behalf in providing the Services, as described in Annex 1.
- Personal Data Breach, Data Subject, processing and special category data have the meanings given in Data Protection Law.
- Subprocessor means a third party we engage to process Customer Personal Data.
- Services means Dentistry Dashboard as described in the Terms of Service, including AI Notes.
2. Roles
The Customer is the controller of Customer Personal Data, including patient information, and we are its processor. We are the controller of our own customers’ account, billing and security data, as described in our Privacy Policy.
3. Our obligations
3.1 Instructions
We process Customer Personal Data only on the Customer’s documented instructions. The Terms of Service, this DPA and the Customer’s use and settings of the Services are those instructions. They include processing needed to provide, support and secure the Services, to investigate problems the Customer reports to us, and to meet our legal obligations, including post-market surveillance for AI Notes as a medical device. We tell the Customer if we believe an instruction breaks Data Protection Law. We do not sell Customer Personal Data, use it for advertising or use it to train AI models.
3.2 Confidentiality
Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality.
3.3 Security
We apply the technical and organisational measures in Annex 2, which are appropriate to the risk, and keep them under review.
3.4 Subprocessors
The Customer gives general authorisation for us to use the Subprocessors in Annex 3. We tell the Customer at least 14 days before we add or replace a Subprocessor, by email to the account owner and by updating Annex 3, so the Customer can object on reasonable data protection grounds. If we cannot meet an objection, the Customer may close its account. Each Subprocessor is bound by data protection terms that give the same level of protection as this DPA, and we remain responsible for its work.
3.5 Individuals’ rights
We help the Customer respond to requests from Data Subjects, such as access, correction and deletion, and reply to the Customer’s request for help within 5 working days. If a Data Subject contacts us directly about Customer Personal Data, we pass the request to the Customer and do not respond to it ourselves unless the Customer asks us to.
3.6 Assistance
We help the Customer meet its obligations on security, Personal Data Breaches, data protection impact assessments and consultation with the Information Commissioner’s Office, taking into account the nature of the processing and the information available to us. Our AI Notes DPIA is available on request.
3.7 Personal Data Breaches
We notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, with a first notice within 24 hours. We give the information the Customer needs to assess the breach and meet any duty to report it, and update the Customer as we learn more.
3.8 Deletion and return
The Customer can export and delete its data at any time. When the Customer closes its account, or asks us to, we delete Customer Personal Data from our live systems within 30 days, unless the law requires us to keep it, and can return it first if the Customer asks. Copies in our automated backups expire within 7 days after that.
3.9 Information and audits
We make available the information needed to show we meet this DPA, including our policies, certificates, DPIA and penetration test summary. The Customer, or an auditor it appoints under a duty of confidentiality, may audit our compliance once a year on 30 days’ written notice, at its own cost and without disrupting the Services or putting other customers’ data at risk.
4. International transfers
Customer Personal Data is stored in the United Kingdom. AI Notes content is processed in the UK and the EEA, which UK law treats as adequate. Where a Subprocessor processes Customer Personal Data outside the UK and EEA, we put in place the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another safeguard Data Protection Law allows, as set out in Annex 3.
5. The Customer’s obligations
The Customer makes sure it has a lawful basis for the processing, gives patients and staff the information Data Protection Law requires (including telling patients before an appointment conversation is recorded with AI Notes), and only gives us lawful instructions.
6. General
- This DPA lasts for as long as we process Customer Personal Data.
- Liability under this DPA is subject to the limits in the Terms of Service.
- If this DPA and the Terms of Service conflict on data protection, this DPA applies. A standalone data processing agreement signed with the Customer applies over both.
- We may update this DPA to reflect changes in law or in the Services, and will say so on this page.
- This DPA is governed by the law of England and Wales.
Annex 1: Details of the processing
- Subject matter and duration: providing the Services, for as long as the Customer uses them and until deletion under section 3.8.
- Nature and purpose: hosting, storing, organising and displaying the Customer’s information; transcribing audio and drafting clinical documentation in AI Notes for the clinician to review; sending notifications and emails the Customer’s users choose to send; and support.
- Data Subjects: the Customer’s staff and users; patients and prospective patients; other people named in the Customer’s content, such as referrers, lab contacts and people present at an appointment.
- Personal data: names, contact details and identifiers; account details; content created in the Services, such as notes, transcripts, letters, care plans, referrals, enquiries, messages, rotas and boards; and audio of dictation or appointment conversations, which is sent for transcription and discarded (audio is never stored).
- Special category data: health data, and any other special category data in the Customer’s content.
- Frequency: continuous, while the Services are used.
Annex 2: Security measures
- Hosting on Amazon Web Services in London, with the database in private networks and not publicly accessible.
- Encryption in transit (TLS 1.2 or higher) and at rest for the database, backups and file storage.
- Individual accounts with hashed passwords and complexity rules, multi-factor authentication available on every account, and rate limiting on sign-in.
- Role-based permissions in the Services; AI Notes are private to the clinician unless the practice turns on shared notes.
- Access to Customer Personal Data by our staff only where needed for support, issue investigation and safety.
- Infrastructure audit logging and threat detection, application and security logging, and alerting.
- Daily automated backups kept for 7 days, multi-zone hosting and a tested business continuity plan.
- Cyber Essentials certification, NHS Data Security and Protection Toolkit Standards Met, and independent penetration testing.
- Change control, vulnerability management and regular patching.
- Confidentiality obligations and annual data protection and security training for our staff.
- An incident response plan, tested by exercise.
Annex 3: Subprocessors
| Subprocessor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Amazon Web Services | Hosting, database, file storage and backups | United Kingdom (London) | Not needed |
| Microsoft (Azure AI Speech) | Speech-to-text for AI Notes | United Kingdom (UK South) and the Netherlands (West Europe) | UK adequacy regulations for the EEA |
| Google Cloud (Vertex AI) | Drafting notes and other AI Notes features | European Union | UK adequacy regulations for the EEA |
| Pusher | Real-time in-app notifications | European Union | UK adequacy regulations for the EEA |
Integrations the Customer chooses to connect, such as Facebook, Instagram or WhatsApp (Meta) for the Social Inbox, Zapier or Google Workspace, are provided under the Customer’s own agreement with that provider.