Smileline

Data Processing Agreement

The contract under which Smileline Technologies Ltd processes a practice's patient data — accepted by the practice owner on behalf of the practice during onboarding.

Version 2026-10-03 · Last updated 3 October 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Smileline Technologies Ltd, company number 17408336, with its registered office at 1 Lyric Square, London, England, W6 0NB (the "Processor"), and the practice accepting it (the "Controller" or "Practice"). It is entered into when the Practice owner accepts it in the app, and it governs all processing of Practice Data that contains personal data. It is written to satisfy Article 28 of the UK GDPR and, for a Practice established in the European Union or processing the personal data of people in the EU, Article 28 of Regulation (EU) 2016/679. Where those two differ, whichever applies to the Practice governs; references to "data protection law" mean the one that applies to it.

1. Roles and scope

The Practice is the controller of the personal data it stores in the Service — its patients, leads and contacts. Smileline is the processor and processes that data only to provide the Service, on the documented instructions given through the Practice's use of the platform. Smileline is a separate, independent controller of its own account, billing and security data, as described in the Privacy Policy.

2. Details of the processing

Subject matter Hosting and operating a dental CRM: lead capture, patient records, journeys, messaging, scheduling, reporting and integrations.
Duration The term of the Practice's subscription, plus the deletion window in section 9.
Nature and purpose Storage, retrieval, display, transmission (messages the Practice sends), analysis (reports) and the automated workflows the Practice configures. Where the Practice switches them on, this also covers: visitor tracking on the Practice's own website, including the website tracking script and dynamic insertion of tracking telephone numbers; upload of conversion events derived from Practice Data to the advertising platforms the Practice connects; and the AI voice agent, which holds spoken conversations with patients and prospective patients on the Practice's behalf; and Call AI, for Practices on SmileLine Voice that record their calls: live transcription of recorded calls, live on-screen suggestions for Practice staff drawn from the Practice's own call playbook, and AI analysis of each call and of each week's calls (summaries, outcomes, suggested follow-ups and email drafts for staff to review and send, and coaching for the Practice's team).
Data subjects The Practice's patients, prospective patients (leads/enquiries), their contacts, and Practice staff.
Categories of personal data Contact details, demographic details, enquiry and communication history, appointment and treatment-interest information, payment status, marketing consents, and identifiers from connected systems. Where the Practice uses the Power Dialer: call metadata (the number called, the staff member who called, the time, duration and result of each call) and, where the Practice switches call recording on, the recorded audio of answered calls and, with Call AI, each recorded call's transcript and its AI analysis.
Special category data Data concerning health — dental history, treatment plans and clinical context the Practice records or syncs from its practice management system. Recorded calls are also likely to contain data concerning health, because patients describe symptoms, treatment and medical circumstances on the phone; the Practice decides whether to record calls at all and how long recordings are kept. The Practice is responsible for its Article 9 condition for processing this data (typically the provision of health care, Art. 9(2)(h)) and for telling callers that calls may be recorded.

3. The Processor's obligations

Smileline shall:

  • process Practice Data only on the Practice's documented instructions (the platform's features and settings), including with regard to transfers of Practice Data to a third country or an international organisation, unless required to do so by law to which Smileline is subject — in which case it will inform the Practice of that legal requirement before processing, unless the law prohibits it;
  • immediately inform the Practice if, in Smileline's opinion, an instruction infringes the UK GDPR, the EU GDPR or other applicable data protection law;
  • not process Practice Data for its own purposes, and not use Practice Data — or permit any sub-processor to use it — to train, fine-tune or otherwise improve any artificial-intelligence model;
  • ensure everyone authorised to access Practice Data is bound by confidentiality;
  • implement the technical and organisational measures in section 6;
  • respect the sub-processing conditions in section 5;
  • assist the Practice, taking into account the nature of the processing, in responding to data-subject rights requests and in meeting its obligations on security, breach notification and impact assessments;
  • delete or return Practice Data as set out in section 9;
  • make available the information reasonably necessary to demonstrate compliance with this DPA, and allow audits as set out in section 11.

4. The Practice's obligations

The Practice warrants that it has a lawful basis (and, for health data, an Article 9 condition) for the personal data it stores in the Service; that its patient-facing privacy information covers the use of a CRM processor; and that the instructions it gives through the platform comply with UK data protection law. The Practice controls — and is responsible for — who on its team can access what, through the platform's roles.

5. Sub-processors

The Practice gives general authorisation to the sub-processors below. Smileline will give at least 30 days' notice before adding or replacing a sub-processor (by updating this page and notifying account owners), during which the Practice may object on reasonable data-protection grounds; if the objection cannot be resolved, the Practice may terminate and export its data.

Sub-processor Purpose Location
Cloudflare, Inc. Application hosting, networking, storage UK/EU edge; global network
Hetzner Online GmbH Server infrastructure for the primary database and application services in the EU region Germany
PostHog, Inc. Product analytics, masked session replay and error diagnostics for signed-in practice staff, in an EU-hosted project. Patients are never included. EU
Telnyx Telephony for the Practice's calling features — carrying outbound Power Dialer calls and, for Practices on SmileLine Voice, inbound and outbound calls, voicemail capture and call recordings where the Practice switches recording on, and the live transcription of recorded calls for Call AI, which Telnyx performs through AssemblyAI (below). Smileline holds the account with Telnyx; the Practice does not contract with Telnyx. UK/EU carriage; US
AssemblyAI, Inc. (engaged through Telnyx) Live speech recognition of recorded calls for Practices using Call AI on SmileLine Voice. The call audio is processed transiently, while the call is live, to produce the transcript. US
Cloudflare, Inc. (Workers AI) Automatic speech-recognition over stored call recordings and voicemail for Practices on SmileLine Voice and, for Call AI, choosing which of the Practice's prepared suggestions to show staff during a call, using a model hosted on Workers AI (TypeSafe jev) that retains nothing. Audio and text are processed transiently; transcripts are deleted with the recording they came from. UK/EU edge; global network
Stripe Payments Europe, Ltd. Subscription billing EU/US
Resend, Inc. Transactional email delivery EU/US
OpenAI, LLC Inbox AI assistance (drafting and summarising replies to patients) and the search embeddings behind the knowledge base — only where the Practice enables the AI add-on. For Practices on the AI receptionist, also the language model that conducts the call and the written summary produced after it, under OpenAI's zero-data-retention terms: nothing from a call is stored by OpenAI or used to train its models. For Practices using Call AI on SmileLine Voice, also the analysis of each recorded call's transcript after the call, the weekly call insights and the Practice's call playbook; call content sent for analysis is never used to train OpenAI's models. US
LiveKit, Inc. (LiveKit Cloud) Real-time media and hosting for the AI receptionist — only where the Practice enables it. Carries the audio of an AI-answered call between the telephone network and the assistant while the call is live; nothing is retained after the call ends. UK/EU Practices are served from the EU region and US Practices from the US region. EU (UK/EU Practices); US (US Practices)
Cartesia AI, Inc. Speech recognition and speech synthesis for the AI receptionist — turning the caller's words into text for the assistant and the assistant's replies into speech, transiently, during the call. US
xAI The answering model behind the patient-facing chat widget — only where the Practice enables the AI add-on and publishes the widget. Website visitors' messages and the practice content the widget answers from are sent to xAI to generate a reply. xAI is not engaged for telephone calls. US

This list does not include providers the Practice connects with its own account and its own credentials — its messaging providers, its practice management system, its advertising platforms and its payment account for booking deposits. Those act under the Practice's own agreements with them and are not Smileline sub-processors. The carve-out reaches no further than that: where Smileline supplies the account, the credentials and the commercial relationship, the provider is a Smileline sub-processor and is listed above even though the Practice's patients are the data subjects. Power Dialer telephony is the clearest example — the Telnyx account, the numbers, the invoice and the patient telephone numbers dialled through it are all Smileline's responsibility as processor.

6. Security measures

  • Encryption in transit (TLS 1.2+) and at rest;
  • per-practice data isolation enforced at the application layer on every query;
  • role-based access control within the Practice, and audit logging of actions taken in the platform;
  • additional envelope encryption for stored channel credentials and secrets;
  • restricted, credentialed access to production systems for Smileline staff, limited to what operating the Service requires;
  • backups and tested restore procedures.

7. Hosting location and international transfers

Practice Data is held in the service region fixed by the Practice's legal country at sign-up. Practices in the United Kingdom and the European Union are served from the EU region, with the primary database in Germany. Practices in the United States are served from the US region, with Practice Data held in the United States.

Several sub-processors in section 5 process personal data outside that region. Where Practice Data originating in the UK is transferred outside the UK, the transfer relies on UK adequacy regulations or on standard contractual clauses with the UK International Data Transfer Addendum. Where Practice Data originating in the EEA is transferred outside the EEA, the transfer relies on an adequacy decision or on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), which are incorporated into this DPA by reference and take effect automatically for any such transfer. Smileline will supply the Practice with a copy of the safeguards applying to a given transfer, and with the information the Practice needs for its own transfer risk assessment, on request.

8. Personal data breaches

Smileline will notify the Practice without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Practice Data, and will provide the information the Practice needs for its own notification obligations, cooperating in the investigation and remediation.

9. Return and deletion

The Practice can export its data from the platform at any time, and the export tools stay available for 30 days after the subscription ends so nothing has to be retrieved in a hurry.

At the Practice's choice, Smileline will either return Practice Data to the Practice or delete it. Tell us which you want before the end of that 30-day window. If you ask for a return, we provide the data in a structured, commonly used, machine-readable format and delete our copies afterwards. If you ask for deletion, or if the window passes without a choice, Smileline deletes Practice Data from production systems within 90 days of the subscription ending, and from backups as they expire on their rotation schedule. We keep data only where storage is required by law, and only for as long as that law requires.

Deleting Practice Data from Smileline does not discharge the Practice's own duty to keep dental records for the period its regulator requires, which is considerably longer than we hold anything. Export what you are required to keep before asking us to delete.

10. Professional secrecy (Germany and Austria)

This section applies where the Practice is bound by a professional secrecy obligation under section 203 of the German Criminal Code (Strafgesetzbuch) or an equivalent provision of Austrian law.

Smileline acts as a person cooperating in the Practice's professional activity (mitwirkende Person) within the meaning of section 203(3) StGB. Smileline is obliged to secrecy in respect of all Practice Data covered by that obligation, and this obligation continues after this DPA ends. Smileline will disclose such data only where necessary to provide the Service, will oblige every person and every sub-processor it gives access to in the same terms before access is granted, and will remain responsible for their compliance. Smileline will notify the Practice without undue delay of any breach of this obligation of which it becomes aware, and of any legal demand for the disclosure of such data, unless prohibited by law from doing so.

11. Audits

Smileline will make available documentation demonstrating compliance with this DPA. Where that is insufficient, the Practice (or its appointed auditor, not a Smileline competitor) may audit once in any 12-month period, on 30 days' notice, during business hours, without disrupting the Service, and subject to confidentiality.

12. Liability and precedence

The liability provisions of the Terms of Service apply to this DPA. If this DPA conflicts with the Terms on data-protection matters, this DPA prevails. This DPA is governed by the laws of England and Wales.

13. Record of acceptance

The Practice owner accepts this DPA in the app during onboarding (and again when a new version is published). Smileline records who accepted, the signing capacity, the version and the time as minimised evidence. It does not attach an IP address or browser user agent to the acceptance. The Practice can view its acceptance record at any time in Settings → Agreements.