Smileline

Legal

Data Processing Agreement

The contract under which Smileline Ltd processes a practice's patient data — accepted by the practice owner on behalf of the practice during onboarding.

Version 2026-08-02 · Last updated 2 August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Smileline Ltd (the "Processor") and the practice accepting it (the "Controller" or "Practice"). It is entered into when the Practice owner accepts it in the app, and it governs all processing of Practice Data that contains personal data. It is written to satisfy Article 28 of the UK GDPR.

1. Roles and scope

The Practice is the controller of the personal data it stores in the Service — its patients, leads and contacts. Smileline is the processor and processes that data only to provide the Service, on the documented instructions given through the Practice's use of the platform. Smileline is a separate, independent controller of its own account, billing and security data, as described in the Privacy Policy.

2. Details of the processing

Subject matter Hosting and operating a dental CRM: lead capture, patient records, journeys, messaging, scheduling, reporting and integrations.
Duration The term of the Practice's subscription, plus the deletion window in section 9.
Nature and purpose Storage, retrieval, display, transmission (messages the Practice sends), analysis (reports) and the automated workflows the Practice configures.
Data subjects The Practice's patients, prospective patients (leads/enquiries), their contacts, and Practice staff.
Categories of personal data Contact details, demographic details, enquiry and communication history, appointment and treatment-interest information, payment status, marketing consents, and identifiers from connected systems. Where the Practice uses the Power Dialer: call metadata (the number called, the staff member who called, the time, duration and result of each call) and, where the Practice switches call recording on, the recorded audio of answered calls.
Special category data Data concerning health — dental history, treatment plans and clinical context the Practice records or syncs from its practice management system. Recorded calls are also likely to contain data concerning health, because patients describe symptoms, treatment and medical circumstances on the phone; the Practice decides whether to record calls at all and how long recordings are kept. The Practice is responsible for its Article 9 condition for processing this data (typically the provision of health care, Art. 9(2)(h)) and for telling callers that calls may be recorded.

3. The Processor's obligations

Smileline shall:

  • process Practice Data only on the Practice's documented instructions (the platform's features and settings), unless required by law to do otherwise — in which case it will inform the Practice unless the law prevents it;
  • ensure everyone authorised to access Practice Data is bound by confidentiality;
  • implement the technical and organisational measures in section 6;
  • respect the sub-processing conditions in section 5;
  • assist the Practice, taking into account the nature of the processing, in responding to data-subject rights requests and in meeting its obligations on security, breach notification and impact assessments;
  • delete or return Practice Data as set out in section 9;
  • make available the information reasonably necessary to demonstrate compliance with this DPA, and allow audits as set out in section 10.

4. The Practice's obligations

The Practice warrants that it has a lawful basis (and, for health data, an Article 9 condition) for the personal data it stores in the Service; that its patient-facing privacy information covers the use of a CRM processor; and that the instructions it gives through the platform comply with UK data protection law. The Practice controls — and is responsible for — who on its team can access what, through the platform's roles.

5. Sub-processors

The Practice gives general authorisation to the sub-processors below. Smileline will give at least 30 days' notice before adding or replacing a sub-processor (by updating this page and notifying account owners), during which the Practice may object on reasonable data-protection grounds; if the objection cannot be resolved, the Practice may terminate and export its data.

Sub-processor Purpose Location
Cloudflare, Inc. Application hosting, networking, storage UK/EU edge; global network
Managed PostgreSQL provider Primary database hosting EU
Telnyx Outbound telephony for the Power Dialer — carrying calls, presenting the Practice's caller ID, and producing call recordings where the Practice switches recording on. Smileline holds the account with Telnyx; the Practice does not contract with Telnyx. UK/EU carriage; US
Stripe Payments Europe, Ltd. Subscription billing EU/US
Resend, Inc. Transactional email delivery EU/US
OpenAI, LLC Inbox AI assistance (drafting and summarising replies to patients) and the search embeddings behind the knowledge base — only where the Practice enables the AI add-on US
xAI The answering model behind the patient-facing chat widget — only where the Practice enables the AI add-on and publishes the widget. Website visitors' messages and the practice content the widget answers from are sent to xAI to generate a reply. US

This list does not include providers the Practice connects with its own account and its own credentials — its messaging providers, its practice management system, its advertising platforms and its payment account for booking deposits. Those act under the Practice's own agreements with them and are not Smileline sub-processors. The carve-out reaches no further than that: where Smileline supplies the account, the credentials and the commercial relationship, the provider is a Smileline sub-processor and is listed above even though the Practice's patients are the data subjects. Power Dialer telephony is the clearest example — the Telnyx account, the numbers, the invoice and the patient telephone numbers dialled through it are all Smileline's responsibility as processor.

6. Security measures

  • Encryption in transit (TLS 1.2+) and at rest;
  • per-practice data isolation enforced at the application layer on every query;
  • role-based access control within the Practice, and audit logging of actions taken in the platform;
  • additional envelope encryption for stored channel credentials and secrets;
  • restricted, credentialed access to production systems for Smileline staff, limited to what operating the Service requires;
  • backups and tested restore procedures.

7. International transfers

Practice Data is hosted in the UK/EU where the provider allows it. Where a sub-processor processes personal data outside the UK, the transfer is protected by UK adequacy regulations or standard contractual clauses with the UK International Data Transfer Addendum.

8. Personal data breaches

Smileline will notify the Practice without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Practice Data, and will provide the information the Practice needs for its own notification obligations, cooperating in the investigation and remediation.

9. Return and deletion

The Practice can export its data from the platform at any time. Following termination of the subscription, Smileline will delete Practice Data from production systems within 90 days, and from backups as they expire on their rotation schedule, unless retention is required by law.

10. Audits

Smileline will make available documentation demonstrating compliance with this DPA. Where that is insufficient, the Practice (or its appointed auditor, not a Smileline competitor) may audit once in any 12-month period, on 30 days' notice, during business hours, without disrupting the Service, and subject to confidentiality.

11. Liability and precedence

The liability provisions of the Terms of Service apply to this DPA. If this DPA conflicts with the Terms on data-protection matters, this DPA prevails. This DPA is governed by the laws of England and Wales.

12. Record of acceptance

The Practice owner accepts this DPA in the app during onboarding (and again when a new version is published). Smileline records who accepted, the signing capacity, the version and the time as minimised evidence. It does not attach an IP address or browser user agent to the acceptance. The Practice can view its acceptance record at any time in Settings → Agreements.