Dental Nexus DIGITAL DENTISTRY INFRASTRUCTURE
How it works For professionals Trust & security Vision FAQ
Join Early Access →
Legal

Data Processing Agreement

Last updated: August 1, 2026 · Dental Nexus (“the Platform”, “we”, “us”, “our”)
1. Definitions 2. Roles of the Parties 3. Purpose of Processing 4. Categories of Data 5. Sub-processors 6. International Transfers 7. Security Measures 8. Client Responsibilities 9. Processor Responsibilities 10. Breach Notification 11. Retention & Deletion 12. Compliance Assistance 13. Audits 14. Governing Law 15. Term 16. Online Acceptance 17. HIPAA & BAA 18. Contact
⚠

For Clients (Controllers). This DPA governs how Dental Nexus processes Personal Data on your behalf. It works alongside our Terms of Service and Privacy Policy. Fields marked [TO BE DETERMINED] are placeholders pending completion.

1Definitions

“Personal Data” — Any information relating to an identified or identifiable individual, including patient data uploaded by the Client.

“Processing” — Any operation performed on Personal Data (storage, access, transmission, deletion, etc.).

“Controller” — The entity that determines the purpose and means of processing Personal Data (you).

“Processor” — The entity that processes Personal Data on behalf of the Controller (Dental Nexus).

“Sub-processor” — A third party engaged by Dental Nexus to assist with processing.

“Applicable Data Protection Laws” includes:

  • EU GDPR
  • UK GDPR
  • CCPA/CPRA
  • PIPEDA
  • HIPAA (where applicable)
  • APAC privacy frameworks
  • U.S. federal and state privacy law
  • Saudi Arabia's Personal Data Protection Law and Implementing Regulations
  • UAE Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, and Federal Law No. 2 of 2019 for health data processed in connection with UAE health services (including, where applicable, DIFC and ADGM data protection regimes)
  • Egypt's Personal Data Protection Law No. 151 of 2020
  • Qatar Law No. 13 of 2016 Concerning Personal Data Privacy Protection (and QFC Data Protection Regulations and Rules, where applicable)
  • Bahrain Law No. 30 of 2018 with Respect to Personal Data Protection
  • Oman's Personal Data Protection Law (Royal Decree No. 6 of 2022)
  • Jordan's Personal Data Protection Law No. 24 of 2023
  • Morocco Law No. 09-08 concerning the protection of individuals with regard to the processing of personal data
  • Algeria Law No. 18-07, as amended, concerning the protection of individuals in the processing of personal data
  • Tunisia Organic Law No. 2004-63 concerning personal-data protection
  • Any other laws applicable to the Controller's jurisdiction

“Sensitive Data” — Includes health data, patient identifiers, dental records, STL files, clinical photographs, prescriptions and treatment notes.

“Protected Health Information” or “PHI” — As defined under HIPAA: individually identifiable health information transmitted or maintained in any form.

2Roles of the Parties

You (the Client) act as the Data Controller for all Personal Data uploaded to Dental Nexus.

Dental Nexus acts as the Data Processor. For platform account administration and operational data (e.g., user accounts, billing and platform security logs), Dental Nexus may act as an independent Controller as described in our Privacy Policy.

Independent planners, labs, clinicians and manufacturers who access case data may act as Joint Controllers (if they determine processing purposes) or Independent Controllers (the most common case). You are responsible for ensuring all parties you work with have a legal basis to process patient data.

3Purpose of Processing

Dental Nexus will process Personal Data solely for the following purposes:

  • Providing access to the Dental Nexus platform
  • Case coordination and workflow management
  • Secure file sharing (STLs, images, PDFs, DICOMs, prescriptions)
  • Communication between Client and independent providers
  • Platform security, audit logging and monitoring
  • Backups and disaster recovery
  • Analytics using anonymized or aggregated data only
  • Improving platform performance and features

Dental Nexus will not process Personal Data for any purpose other than those instructed or permitted by the Client.

4Categories of Data Processed

4.1 Data Subjects

Patients, clinicians, treatment planners, lab staff, manufacturers and other platform users.

4.2 Data Types

Personal Data may include: patient-identifying information (if uploaded by the Client), STL/OBJ files, clinical images and photographs, treatment prescriptions and notes, case history, professional credentials, email addresses and account details, audit logs and activity data.

The Client is responsible for limiting uploads to the minimum necessary identifiers. Dental Nexus recommends using opaque patient references (such as a case number or initials) rather than full patient names wherever clinically appropriate.

5Sub-processors

Dental Nexus uses the following vetted Sub-processors to provide platform services. Where Sub-processors have access to Personal Data or PHI, appropriate data processing agreements are maintained with each.

Sub-processor Purpose Personal/PHI Data Access
Supabase, Inc. Cloud database (PostgreSQL), file storage, authentication Yes. Hosts all structured data and clinical files. AES-256 at rest, TLS in transit.
Stripe, Inc. Payment processing and specialist payouts Limited. Billing email and tokenized payment references only. No PHI. PCI-DSS Level 1 certified.
Resend, Inc. Transactional email delivery Limited. Emails may reference case identifiers and user names.
Vercel, Inc. Application hosting (Next.js) Server log level only. Request and response metadata.
Google LLC OAuth sign-in, address autocomplete during onboarding Identity only. No PHI.
AI Processing Providers (variable) AI-assisted case analysis where activated by the Client Yes. When an AI job is activated, signed file URLs and structured case metadata are transmitted to the provider's endpoint. This constitutes PHI egress. See §5.1.

5.1 AI Sub-processors and PHI

Where a Client activates AI-assisted case processing, case files and clinical metadata are transmitted to the relevant AI provider. This is a PHI egress path. Dental Nexus maintains data processing agreements with AI providers that cover PHI processing obligations. Clients subject to HIPAA should confirm that the AI provider is covered under their Business Associate Agreement with Dental Nexus (see §17).

Dental Nexus will maintain an up-to-date list of active Sub-processors and will notify Clients of material additions or changes with reasonable notice.

Dental Nexus will not use identifiable patient data for AI model training.

6International Data Transfers

Because Dental Nexus serves global users, data may be transferred outside your home country. Transfer mechanisms include:

  • EU/UK transfers — Governed by Standard Contractual Clauses (SCCs) in accordance with GDPR Article 46 and UK equivalent provisions.
  • Canada — Transfers comply with PIPEDA and applicable provincial privacy law.
  • United States — Transfers comply with CCPA/CPRA and applicable U.S. federal privacy law.
  • Middle East and North Africa — Transfers involving Saudi Arabia comply with the Regulation on Personal Data Transfer Outside the Kingdom, relying on a permitted purpose, appropriate safeguards and a documented risk assessment. Transfers involving the UAE follow Federal Decree-Law No. 45 of 2021, and health information relating to UAE health services is not stored, processed, generated or transferred outside the UAE unless a specific legal exception, decision or authorization permits it — which may require an approved in-country hosting environment. Transfers involving Egypt, Qatar, Bahrain, Oman, Jordan, Morocco, Algeria and Tunisia rely on the applicable local transfer mechanism (which may include explicit consent, adequacy of the receiving jurisdiction, contractual safeguards, or prior regulatory authorization), consistent with each country's law as described in our Privacy Policy.
  • AI Sub-processors — Where AI processing providers operate outside the EEA or UK, Dental Nexus will ensure appropriate transfer mechanisms (SCCs or equivalent adequacy decision) are in place before activating such providers for EU or UK Clients. The same principle applies before activating AI providers for Clients whose data is subject to MENA data-residency or transfer restrictions.

Supabase supports regional hosting options. Dental Nexus will use commercially reasonable efforts to support regional data residency upon written request, including for Clients subject to UAE health-data localization or other MENA data-residency requirements.

7Security Measures

Dental Nexus implements appropriate technical and organizational security measures, which are continuously reviewed and improved. Current measures include:

  • Encryption of data in transit (TLS) and at rest (AES-256 via Supabase)
  • Postgres Row-Level Security (RLS) enforcing organization-scoped data access as the primary security boundary
  • Server-side authentication checks on all data mutations
  • HTTP-only session cookies for authentication tokens
  • Multi-factor authentication for internal administrative systems
  • Audit logging of all material platform events (case submission, payment capture, disputes, admin actions)
  • Secure development and deployment practices
  • Regular vulnerability assessment and remediation
  • Firewall and network safeguards

Infrastructure certification: Supabase, our primary infrastructure provider, maintains SOC 2 Type II and ISO 27001 alignment. Dental Nexus follows secure development practices aligned with these standards. Dental Nexus does not currently hold its own SOC 2 certification; documentation of our security posture is available upon request.

Known remediation in progress: Dental Nexus has identified and is actively remediating a number of Row-Level Security policy gaps across internal tables. These are documented in our internal security register and do not affect the primary data access boundary for Client data.

A detailed summary of security measures is available upon reasonable request.

8Client Responsibilities (Controller)

The Client agrees to:

  • Obtain all required patient consent before uploading data to Dental Nexus
  • Ensure all uploads comply with applicable medical and privacy laws in the Client's jurisdiction
  • Limit Personal Data uploads to what is clinically necessary
  • Maintain accuracy of data submitted to the platform
  • Ensure authorized users comply with this DPA
  • Submit data deletion and export requests in writing to Dental Nexus

Dental Nexus is not responsible for Personal Data uploaded unlawfully by the Client or its users.

9Processor Responsibilities (Dental Nexus)

Dental Nexus will:

  • Process Personal Data only on documented Client instructions or as permitted by this DPA
  • Maintain confidentiality and implement appropriate security measures
  • Ensure Sub-processors are bound by obligations at least equivalent to this DPA
  • Notify the Controller without undue delay of any legally binding governmental or law enforcement request for Client data
  • Provide reasonable assistance to the Controller in meeting regulatory obligations

Dental Nexus will not:

  • Sell Personal Data to any third party
  • Share data for advertising or marketing purposes
  • Use identifiable patient data for AI model training
  • Access case files except for purposes of support, diagnostics, platform security, or as required by law

10Data Breach Notification

If Dental Nexus becomes aware of a confirmed Personal Data Breach affecting Client data, we will:

  • Notify the Client without undue delay and, where required by GDPR Article 33, within 72 hours of becoming aware
  • Provide available details of the nature of the breach, categories of data affected, and approximate number of data subjects
  • Describe mitigation and containment steps taken or proposed
  • Provide reasonable assistance to the Controller in meeting its own notification obligations to supervisory authorities and data subjects

The Client retains responsibility for required notifications to supervisory authorities or data subjects, unless otherwise agreed in writing.

11Data Retention and Deletion

Retention: Dental Nexus retains Personal Data for the duration of the active service relationship and as required by applicable law. Payment and audit records may be retained beyond account closure in pseudonymized form to meet tax, regulatory and legal obligations.

Deletion requests: Upon account closure or written request, Dental Nexus will delete or anonymize Personal Data within 30 days. Deletion requests are currently fulfilled via a managed manual process. An automated deletion pipeline is under active development. Requests should be submitted in writing to [EMAIL TO BE DETERMINED].

Important: Deleting a case record initiates the deletion workflow for associated files. File deletion from storage is included in the 30-day process. Backup copies may persist for a short period following deletion in accordance with standard infrastructure practices.

Backups: Automated database backups are managed by Supabase and are subject to their retention schedule. These backups will be purged on their standard cycle following deletion.

Export: Client data exports are available upon written request and will be fulfilled within 30 days. A self-service data export feature is on the Dental Nexus product roadmap. You may request an export at any time prior to or following account closure.

12Compliance Assistance

Dental Nexus will provide reasonable assistance to help Controllers:

  • Respond to GDPR/UK GDPR data subject access, erasure, rectification and portability requests
  • Meet CCPA/CPRA obligations
  • Support PIPEDA compliance
  • Meet obligations under Saudi Arabia's PDPL, the UAE's Federal Decree-Law No. 45 of 2021 (including applicable health-data rules), and the data protection laws of Egypt, Qatar, Bahrain, Oman, Jordan, Morocco, Algeria and Tunisia
  • Respond to requests or notifications from a competent MENA data-protection or health-sector regulator, where Dental Nexus holds relevant information
  • Document data processing activities for regulatory purposes

Data subject requests received by Dental Nexus that relate to Client data will be forwarded to the Controller. Assistance is currently provided via a manual process and Dental Nexus will respond to written requests within 30 days.

Additional assistance beyond standard scope may be subject to reasonable fees, agreed in advance.

13Audits

Upon reasonable written notice (minimum 30 days), Dental Nexus will:

  • Provide documentation demonstrating compliance with this DPA
  • Provide details of active Sub-processors and their roles
  • Provide summaries of available independent audit reports (e.g., Supabase SOC 2)
  • Respond to reasonable written information security questionnaires

Physical or on-site audits of Dental Nexus systems are not permitted unless legally required and mutually agreed in writing.

14Governing Law

This DPA is governed by the laws of the State of Delaware, USA, unless superseded by mandatory applicable local privacy law. For EU/UK Clients, mandatory provisions of the GDPR and UK GDPR take precedence where they conflict with this DPA.

15Term

This DPA remains in effect for so long as: (a) the Client uses the Dental Nexus platform, or (b) Dental Nexus processes Personal Data on behalf of the Client. Obligations regarding data confidentiality and security survive termination.

16Online Acceptance

By clicking “I agree to the Data Processing Agreement” or continuing to use the platform, the Client confirms that:

  • They have read and understood this DPA
  • They have authority to bind their organization to these data processing terms
  • They accept the terms of this Agreement

Where a terms acceptance record cannot be confirmed at the time of signup (for example, where onboarding is not completed), continued use of the platform constitutes acceptance of the then-current DPA.

17HIPAA and Business Associate Agreement

For Clients in the United States who handle Protected Health Information (PHI) as defined by HIPAA, a Business Associate Agreement is available. Clients subject to HIPAA should review and accept the BAA before uploading any PHI to the platform. For questions, contact [EMAIL TO BE DETERMINED].

18Contact

For data protection enquiries, requests, or to exercise data subject rights:

Email: [EMAIL TO BE DETERMINED]
Company: Dental Nexus

Questions about this DPA?

Contact us through the early access form and our team will follow up directly.

Dental Nexus DIGITAL DENTISTRY INFRASTRUCTURE

A concept-stage B2B platform designed to connect and protect the Middle East’s digital dentistry ecosystem.

Platform

How it works For professionals Trust & security

Company

Vision The opportunity Early access Terms of Service Privacy Policy Service Agreement Data Processing Agreement

Launch market

Middle East B2B digital dentistry Concept stage
© 2026 Dental Nexus. Working name and concept prototype. Trademark and domain availability must be verified before launch.