Smileline

EU Data Protection Addendum

How the Data Processing Agreement works for a practice in the European Union — the EU GDPR, the Commission's Standard Contractual Clauses, and who to complain to.

Version 2026-08-30 · Last updated 30 August 2026

This EU Data Protection Addendum (the "Addendum") supplements the Data Processing Agreement and the Terms of Service between Smileline Technologies Ltd, company number 17408336, registered in England and Wales with its registered office at 1 Lyric Square, London, England, W6 0NB, and a practice established in the European Union or processing the personal data of people in the EU.

Smileline is established in the United Kingdom, not the EU. The DPA is written primarily against the UK GDPR. This Addendum makes the EU position explicit rather than leaving a practice to read it across. Where this Addendum conflicts with the DPA, this Addendum prevails for EU practices.

1. Regulation (EU) 2016/679 governs

For a practice this Addendum applies to, the processor obligations in the DPA are given under Article 28 of Regulation (EU) 2016/679 (the EU GDPR). Every reference in the DPA to the UK GDPR is read as a reference to the EU GDPR, and every reference to UK data protection law is read as a reference to the EU GDPR and the national law of the practice's member state. The article numbers are the same.

2. Your supervisory authority

The DPA and the Privacy Policy name the UK Information Commissioner's Office. That is our own authority, not yours. A practice in the EU, and any patient whose data it holds, deals with the supervisory authority of its own member state, and may lodge a complaint there. Because Smileline has no establishment in the EU, there is no lead-authority "one-stop shop": your national authority is competent on its own.

3. Our representative in the Union

Under Article 27 of the EU GDPR, Smileline has designated a representative in the Union in writing. The representative can be addressed by supervisory authorities and by data subjects, in addition to or instead of Smileline, on all questions relating to processing.

EU representative: to be named on publication. Until an Article 27 representative is designated and named here, write to privacy@smileline.io and we will respond as if you had reached the representative. Designating one does not create an establishment of Smileline in the Union and does not change which authority is competent.

4. Transfers out of the EEA

Practice Data for EU practices is held in our EU region, with the primary database in Germany. Several sub-processors listed in section 5 of the DPA process personal data outside the EEA — principally the AI providers and parts of telephony and email delivery, in the United States.

For those transfers the parties adopt the Standard Contractual Clauses in the Annex to Commission Implementing Decision (EU) 2021/914, which are incorporated into this Addendum by reference and take effect automatically:

  • Module Two (controller to processor) applies between the Practice as data exporter and Smileline as data importer.
  • Module Three (processor to processor) applies between Smileline and each sub-processor outside the EEA.
  • Clause 7 (docking) applies. Clause 9 uses Option 2, general written authorisation, with the 30 days' notice already set out in DPA section 5. Clause 11's optional independent dispute-resolution body does not apply. Clause 17 selects the law of Ireland. Clause 18(b) selects the courts of Ireland.
  • The Annex I description of the transfer, and the Annex II technical and organisational measures, are those set out in sections 2, 5 and 6 of the Data Processing Agreement.
  • Where an adequacy decision covers a recipient, that decision may be relied on instead. If an adequacy decision is invalidated or lapses, these Clauses apply to the affected transfers from that moment, without further action by either party.

Transfers from the EEA to Smileline in the United Kingdom rely on the European Commission's adequacy decision for the United Kingdom. If that decision lapses or is annulled, the Clauses above apply to those transfers automatically.

Smileline will provide the information a practice needs for its own transfer impact assessment on request, including the sub-processor's location, the categories of data it receives, and what Smileline knows about requests from public authorities.

5. National rules on health data

Article 9(4) of the EU GDPR lets member states impose further conditions on processing health data, and several do. Two are addressed directly:

  • Germany and Austria — professional secrecy. Section 10 of the Data Processing Agreement obliges Smileline to secrecy as a person cooperating in the practice's professional activity, within the meaning of section 203(3) of the German Criminal Code.
  • France — hosting of health data. Article L.1111-8 of the French Public Health Code requires personal health data collected in the course of prevention, diagnosis or care to be hosted by a certified host (Hébergeur de Données de Santé). Smileline's hosting chain does not hold HDS certification. A practice in France must satisfy itself that its intended use of the Service is compatible with Article L.1111-8 before storing patient records in it, and should take its own advice. We will say plainly when that changes.

A practice remains responsible for the conditions its own member state imposes. Tell us if your national law requires something this Addendum does not cover and we will address it.

6. Cloud switching

Under Chapter VI of Regulation (EU) 2023/854 (the Data Act), the Practice may switch to another provider or to its own on-premises system. Smileline will: act on a switching request without undue delay and in any event within 30 days of the end of any transition period; make the Practice's exportable data available in a structured, commonly used, machine-readable format; provide reasonable assistance with the switch; and maintain continuity of the Service during it. Smileline does not charge switching or egress fees.

7. Contact

Smileline Technologies Ltd · Company 17408336 · 1 Lyric Square, London, England, W6 0NB · privacy@smileline.io