Data Processing Agreement
Effective from August 2026
This Data Processing Agreement ("Agreement") forms part of the Contract for Services under Dev8 Labs' Terms of Service (the "Principal Agreement") between Dev8 Labs (referred to as the "Processor") and the Dental Practice using Dev8 Labs' services (referred to as the "Company").
This Agreement governs the specific requirements of Data Protection Laws to the extent that the Company's use of Dev8 Labs' Services implies the processing of Personal Data subject to Data Protection Laws. This Agreement is complementary to our Privacy Policy, which serves as the primary reference for our data protection practices and measures.
1. Definitions and Interpretation
1.1 "Company Personal Data" means any Personal Data related to the Company or Company's customers (patients) processed in connection with the Principal Agreement.
1.2 "Data Protection Laws" means EU Data Protection Laws and the UK GDPR.
1.3 "Services" means the done-for-you Google Business Profile review monitoring, GDC-compliant response drafting, and publishing services provided by the Processor.
2. Processing of Company Personal Data
Processor shall:
- Comply with all applicable Data Protection Laws in the Processing of Company Personal Data.
- Not process Company Personal Data other than on Controller's documented instructions.
Controller instructs Processor to process Company Personal Data to:
- Provide the Services and related technical support via digital workflows.
- Dispatch review invitation communications (SMS / Email) to patient contact lists uploaded directly by the Company.
- Exercise internal reporting, financial reporting, and other similar administrative tasks.
Zero Direct PMS Access Guarantee: The Processor operates exclusively via secure, practice-initiated file uploads and public review data. The Processor maintains zero direct database integrations, API bridges, or administrative credentials to the Company's internal Patient Management Systems (PMS, such as Dentally or Software of Excellence).
Review Request Data Minimization: Where the Company uploads contact lists for review request dispatch, the Company shall strictly limit uploads to non-sensitive contact details (Patient First Name and Phone Number or Email). The Company explicitly warrants that no clinical treatment notes, diagnostic records, dental charts, or UK GDPR Article 9 Special Category health data are included.
3. Security & Staff Confidentiality
In accordance with Article 32(1) of the UK GDPR, the Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures include TLS 1.3 encryption in transit, Cloudflare Edge security, encrypted database layers, and strict access controls.
The Processor ensures that all personnel authorized to process Company Personal Data are bound by strict contractual confidentiality commitments or statutory obligations of confidentiality.
4. Subprocessing
Subject to this Agreement, the Company grants general authorization to the Processor to engage Subprocessors (such as Cloudflare, Google Cloud, and enterprise payment/AI infrastructure) to deliver the Services. Processor ensures that Subprocessors are subject to data protection obligations no less protective than those set out in this Agreement.
5. Data Subject Rights & DPIA Assistance
Taking into account the nature of the processing, Processor shall reasonably assist Company for the fulfilment of Company's obligations to respond to requests to exercise Data Subject rights under Data Protection Laws. The Processor shall also reasonably assist the Company in ensuring compliance with the Company's obligations regarding security, breach notifications, and Data Protection Impact Assessments (DPIAs) where applicable.
6. Personal Data Breach Notification
The Processor shall manage any Personal Data Breach in compliance with applicable Data Protection Laws. In the event of a confirmed Personal Data Breach affecting Company Personal Data, the Processor shall notify the Company without undue delay, and in any event within 48 to 72 hours of becoming aware of the breach, providing sufficient details to assist the Company in meeting its statutory notification duties.
7. Deletion or Return of Company Personal Data & 14-Day Purge
Automated 14-Day Review Request Data Purge: All patient contact lists, CSV/Excel uploads, and associated telephone numbers or email addresses provided for review invitation dispatch are automatically and permanently purged from the Processor's active servers and databases within fourteen (14) days of processing.
In case of cessation of any Service involving the Processing of Company Personal Data, the Processor shall delete all Company Personal Data to the extent permitted by applicable laws and in accordance with Processor's Privacy Policy.
8. Data Transfer
Because Dev8 Labs operates internationally, personal data collected within the United Kingdom will be securely transferred to and processed within our administrative offices in India. To guarantee your information receives a level of protection equivalent to UK statutory requirements, all intra-entity processing relies on robust technical barriers and the formal UK International Data Transfer Agreement (IDTA).
9. Audit & Compliance Verification
The Processor shall make available to the Company all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the UK GDPR and allow for and contribute to reasonable compliance reviews and audits conducted by the Company or its mandated auditor, upon reasonable prior written notice.
10. General Terms & Governing Law
Compliance with Applicable Laws: Processor will process Company Personal Data in accordance with this Agreement and Data Protection Laws applicable to its role under this Agreement. Processor is not responsible nor liable for complying with Data Protection Laws solely applicable to Company by virtue of its business or industry.
Governing Law and Jurisdiction: This Agreement shall be governed by the laws of England and Wales. Any disputes arising out of or in connection with this Agreement shall be subject to the exclusive jurisdiction of the courts of London, UK.
Schedule 1: Processing Operations Overview
| Element | Details |
|---|---|
| Subject Matter & Purpose | Done-for-you Google Business Profile review monitoring, GDC-compliant response drafting, and patient review request message dispatch. |
| Duration of Processing | For the duration of the service agreement. Patient review request contact lists are permanently purged within 14 days of upload. |
| Categories of Data | Practice staff business contact details (name, email, phone); Review invitation contact details (Patient first name, mobile/email); Public Google review names and star ratings. Strictly zero clinical health records or Special Category health data. |
| Categories of Data Subjects | Practice administrative and clinical staff; Patients receiving review invitation messages; Public online reviewers. |