1. Parties and Scope
This Data Processing Agreement (the "DPA") is concluded between the clinic subscribing to the Service as controller (the "Controller") and Farvex Labs LLC as processor (the "Processor"). The DPA is an integral annex to the Terms of Service and takes effect upon subscription to the Service.
In the event of a conflict between the DPA and the Terms of Service on matters of data protection, the DPA prevails.
Signed copy
If you need a wet-signed or electronically signed copy for audit, tender or corporate compliance purposes, simply write to support@dentexa.co.
2. Subject Matter and Details of Processing
| Item | Details |
|---|---|
| Subject matter | AI-assisted management of the Controller's WhatsApp communications with patients, appointment creation and record keeping |
| Duration | The subscription term plus the 30-day export window following its end |
| Nature of processing | Collection, recording, storage, organisation, retrieval, transfer, erasure and destruction |
| Purpose | Provision of the Service under the Terms of Service and execution of the Controller's instructions |
| Categories of data | Identity (name, WhatsApp profile name), contact (phone number), message content, appointment data, transaction security data |
| Special categories | Information about dental health voluntarily shared by the patient in a message |
| Categories of data subjects | The Controller's patients and prospective patients; the Controller's authorised users |
3. Obligations of the Processor
The Processor undertakes to:
- 1Process personal data only on the Controller's documented instructions and for the purpose of providing the Service; it will not use the data for its own purposes or sell it.
- 2Inform the Controller in advance where a legal obligation requires it to depart from those instructions, unless prohibited from doing so.
- 3Ensure that all personnel with access to the data are bound by perpetual confidentiality obligations.
- 4Implement and maintain technical and organisational measures compliant with Article 12 KVKK and Article 32 GDPR.
- 5Assist the Controller, through appropriate technical and organisational measures, in responding to data subject requests.
- 6Provide reasonable assistance with data breach handling, data protection impact assessments and prior consultation with authorities.
- 7On termination of processing, return or delete the data at the Controller's choice.
- 8Make available the information necessary to demonstrate compliance with this DPA and allow for audits.
4. Obligations of the Controller
- 1Warrants that it has a lawful basis for the processing, has informed its patients and has obtained explicit consent where required.
- 2Informs its patients that their messages will be processed by AI-assisted infrastructure and that data may be transferred abroad.
- 3Ensures that the instructions it gives the Processor comply with applicable law.
- 4Ensures that content uploaded to the Knowledge Base contains no unnecessary personal data (data minimisation).
- 5Correctly configures user permissions on its account and removes access for departing staff without delay.
- 6Keeps its account credentials secure.
Unlawful instructions
Where the Processor considers an instruction to infringe applicable law, it will notify the Controller and may decline to carry out that instruction.
5. Sub-processors
The Controller gives general authorisation for the Processor to engage the sub-processors listed below in order to provide the Service. The Processor concludes written agreements with each sub-processor providing protection equivalent to this DPA and remains liable to the Controller for their acts.
| Sub-processor | Processing activity | Location |
|---|---|---|
| Supabase Inc. | Database, authentication and file storage | UK (London) |
| Meta Platforms, Inc. (WhatsApp Business Platform) | Message delivery over WhatsApp | USA / EU |
| OpenRouter, Inc. ve bağlı model sağlayıcıları | Generation of AI (LLM) responses | USA |
| Google LLC (Google Calendar API) | Appointment calendar synchronization | EU / USA |
| Open Dental Software, Inc. (yalnızca bu PMS'i bağlayan klinikler için) | Writing the approved appointment into the practice management software | USA |
| Dentally Ltd. (yalnızca bu PMS'i bağlayan klinikler için) | Writing the approved appointment into the practice management software | United Kingdom / EU |
| DodoPayments Ltd. | Payment processing and subscription management | United Kingdom |
| Railway Inc. | Application hosting and infrastructure | USA / EU |
Where a sub-processor is added or replaced, the change is announced on this page and notified to Subscribers by email at least 30 days before it takes effect. The Controller may object on reasonable data protection grounds within 15 days of notification. If the parties cannot agree, the Controller may terminate its subscription without penalty and unused fees are refunded.
6. International Transfers
Some sub-processors are established outside Türkiye and the EU. In respect of such transfers:
- The standard contracts or undertakings published by the Turkish Data Protection Board are applied under Article 9 KVKK; where unavailable, the explicit consent of the data subject is relied upon.
- For EU-originating data the European Commission's Standard Contractual Clauses (SCCs) apply.
- Where the law of the recipient country may undermine the level of protection, supplementary technical measures such as encryption and pseudonymisation are applied.
- If a public authority requests data, the Controller is informed unless legally prohibited, and the lawfulness of the request is assessed.
7. Technical and Organisational Measures
Appropriate to the level of risk, the Processor implements at least the following:
- TLS 1.2+ encryption in transit and encryption at rest,
- Logical isolation between customers via tenant-based Row Level Security,
- Role-based access control and least-privilege principle,
- A redaction layer for direct identifiers before transmission to the model provider,
- Webhook signature verification and replay attack protection,
- Audit logs for access, change and deletion events,
- Encrypted backups and regular restore testing,
- Confidentiality undertakings and data protection training for personnel,
- Change management, regular security patching and dependency updates.
8. Personal Data Breach Notification
- The Processor notifies the Controller without undue delay and in any event within 24 hours of becoming aware of a personal data breach.
- The notification describes the nature of the breach, the approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.
- The Processor provides all support necessary for the Controller's notification to the supervisory authority within 72 hours and for communication to data subjects.
- The Processor keeps records of breaches and shares them on request.
9. Audit Rights
The Controller may request an audit once per year to verify compliance with this DPA. Audits take place on at least 30 days' written notice, during business hours, without disrupting the Service and subject to a confidentiality undertaking. The Processor may satisfy such a request by providing up-to-date security documentation, a description of its technical measures or, where available, independent audit reports. The frequency limit does not apply following a data breach or where required by an authority. Reasonable extraordinary audit costs are borne by the Controller.
10. Return and Deletion of Data
- On termination of the subscription the Controller may export its data from the dashboard for 30 days.
- After that period personal data is deleted or anonymised, subject to statutory retention obligations.
- Destruction of records in backup systems is completed within the backup rotation cycle and within 90 days at the latest.
- A written statement of destruction is provided on request.
11. Liability and Term
- Each party is liable for administrative fines and damages arising from breach of its own obligations.
- The Processor's liability under this DPA is subject to the limitations of liability in the Terms of Service. Those limitations do not apply where the law does not permit them, nor to the rights data subjects hold against the controller.
- The DPA remains in force for the subscription term and until personal data has been destroyed.
- The DPA is governed by the same law and subject to the same jurisdiction as the Terms of Service.
12. Data Protection Contact Point
- Processor
- Farvex Labs LLC
- Address
- 30 N Gould St #57914, Sheridan, WY 82801, Sheridan, Wyoming, United States
- Privacy / DPA contact
- support@dentexa.co
- Data protection contact
- support@dentexa.co