Data Processing Agreement (DPA)

The data processing agreement between the clinic acting as controller and Farvex Labs LLC acting as processor, concluded pursuant to Article 12(2) KVKK and Article 28 GDPR. It forms an integral annex to the Terms of Service.

Last updated: 25 July 2026Version 1.0Effective: 25 July 2026

1. Parties and Scope

This Data Processing Agreement (the "DPA") is concluded between the clinic subscribing to the Service as controller (the "Controller") and Farvex Labs LLC as processor (the "Processor"). The DPA is an integral annex to the Terms of Service and takes effect upon subscription to the Service.

In the event of a conflict between the DPA and the Terms of Service on matters of data protection, the DPA prevails.

Signed copy

If you need a wet-signed or electronically signed copy for audit, tender or corporate compliance purposes, simply write to support@dentexa.co.

2. Subject Matter and Details of Processing

ItemDetails
Subject matterAI-assisted management of the Controller's WhatsApp communications with patients, appointment creation and record keeping
DurationThe subscription term plus the 30-day export window following its end
Nature of processingCollection, recording, storage, organisation, retrieval, transfer, erasure and destruction
PurposeProvision of the Service under the Terms of Service and execution of the Controller's instructions
Categories of dataIdentity (name, WhatsApp profile name), contact (phone number), message content, appointment data, transaction security data
Special categoriesInformation about dental health voluntarily shared by the patient in a message
Categories of data subjectsThe Controller's patients and prospective patients; the Controller's authorised users

3. Obligations of the Processor

The Processor undertakes to:

  1. 1Process personal data only on the Controller's documented instructions and for the purpose of providing the Service; it will not use the data for its own purposes or sell it.
  2. 2Inform the Controller in advance where a legal obligation requires it to depart from those instructions, unless prohibited from doing so.
  3. 3Ensure that all personnel with access to the data are bound by perpetual confidentiality obligations.
  4. 4Implement and maintain technical and organisational measures compliant with Article 12 KVKK and Article 32 GDPR.
  5. 5Assist the Controller, through appropriate technical and organisational measures, in responding to data subject requests.
  6. 6Provide reasonable assistance with data breach handling, data protection impact assessments and prior consultation with authorities.
  7. 7On termination of processing, return or delete the data at the Controller's choice.
  8. 8Make available the information necessary to demonstrate compliance with this DPA and allow for audits.

4. Obligations of the Controller

  1. 1Warrants that it has a lawful basis for the processing, has informed its patients and has obtained explicit consent where required.
  2. 2Informs its patients that their messages will be processed by AI-assisted infrastructure and that data may be transferred abroad.
  3. 3Ensures that the instructions it gives the Processor comply with applicable law.
  4. 4Ensures that content uploaded to the Knowledge Base contains no unnecessary personal data (data minimisation).
  5. 5Correctly configures user permissions on its account and removes access for departing staff without delay.
  6. 6Keeps its account credentials secure.

Unlawful instructions

Where the Processor considers an instruction to infringe applicable law, it will notify the Controller and may decline to carry out that instruction.

5. Sub-processors

The Controller gives general authorisation for the Processor to engage the sub-processors listed below in order to provide the Service. The Processor concludes written agreements with each sub-processor providing protection equivalent to this DPA and remains liable to the Controller for their acts.

Sub-processorProcessing activityLocation
Supabase Inc.Database, authentication and file storageUK (London)
Meta Platforms, Inc. (WhatsApp Business Platform)Message delivery over WhatsAppUSA / EU
OpenRouter, Inc. ve bağlı model sağlayıcılarıGeneration of AI (LLM) responsesUSA
Google LLC (Google Calendar API)Appointment calendar synchronizationEU / USA
Open Dental Software, Inc. (yalnızca bu PMS'i bağlayan klinikler için)Writing the approved appointment into the practice management softwareUSA
Dentally Ltd. (yalnızca bu PMS'i bağlayan klinikler için)Writing the approved appointment into the practice management softwareUnited Kingdom / EU
DodoPayments Ltd.Payment processing and subscription managementUnited Kingdom
Railway Inc.Application hosting and infrastructureUSA / EU

Where a sub-processor is added or replaced, the change is announced on this page and notified to Subscribers by email at least 30 days before it takes effect. The Controller may object on reasonable data protection grounds within 15 days of notification. If the parties cannot agree, the Controller may terminate its subscription without penalty and unused fees are refunded.

6. International Transfers

Some sub-processors are established outside Türkiye and the EU. In respect of such transfers:

  • The standard contracts or undertakings published by the Turkish Data Protection Board are applied under Article 9 KVKK; where unavailable, the explicit consent of the data subject is relied upon.
  • For EU-originating data the European Commission's Standard Contractual Clauses (SCCs) apply.
  • Where the law of the recipient country may undermine the level of protection, supplementary technical measures such as encryption and pseudonymisation are applied.
  • If a public authority requests data, the Controller is informed unless legally prohibited, and the lawfulness of the request is assessed.

7. Technical and Organisational Measures

Appropriate to the level of risk, the Processor implements at least the following:

  • TLS 1.2+ encryption in transit and encryption at rest,
  • Logical isolation between customers via tenant-based Row Level Security,
  • Role-based access control and least-privilege principle,
  • A redaction layer for direct identifiers before transmission to the model provider,
  • Webhook signature verification and replay attack protection,
  • Audit logs for access, change and deletion events,
  • Encrypted backups and regular restore testing,
  • Confidentiality undertakings and data protection training for personnel,
  • Change management, regular security patching and dependency updates.

8. Personal Data Breach Notification

  • The Processor notifies the Controller without undue delay and in any event within 24 hours of becoming aware of a personal data breach.
  • The notification describes the nature of the breach, the approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.
  • The Processor provides all support necessary for the Controller's notification to the supervisory authority within 72 hours and for communication to data subjects.
  • The Processor keeps records of breaches and shares them on request.

9. Audit Rights

The Controller may request an audit once per year to verify compliance with this DPA. Audits take place on at least 30 days' written notice, during business hours, without disrupting the Service and subject to a confidentiality undertaking. The Processor may satisfy such a request by providing up-to-date security documentation, a description of its technical measures or, where available, independent audit reports. The frequency limit does not apply following a data breach or where required by an authority. Reasonable extraordinary audit costs are borne by the Controller.

10. Return and Deletion of Data

  • On termination of the subscription the Controller may export its data from the dashboard for 30 days.
  • After that period personal data is deleted or anonymised, subject to statutory retention obligations.
  • Destruction of records in backup systems is completed within the backup rotation cycle and within 90 days at the latest.
  • A written statement of destruction is provided on request.

11. Liability and Term

  • Each party is liable for administrative fines and damages arising from breach of its own obligations.
  • The Processor's liability under this DPA is subject to the limitations of liability in the Terms of Service. Those limitations do not apply where the law does not permit them, nor to the rights data subjects hold against the controller.
  • The DPA remains in force for the subscription term and until personal data has been destroyed.
  • The DPA is governed by the same law and subject to the same jurisdiction as the Terms of Service.

12. Data Protection Contact Point

Processor
Farvex Labs LLC
Address
30 N Gould St #57914, Sheridan, WY 82801, Sheridan, Wyoming, United States
Privacy / DPA contact
support@dentexa.co
Data protection contact
support@dentexa.co
This document is provided for information only and does not constitute legal advice. Fields marked in brackets will be completed once the legal entity details are finalised.