Data Processing Agreement (DPA)
This agreement governs the patient data Perioskoup processes on behalf of your clinic. It forms part of the Professional Terms. Using Perioskoup as a patient? Read the Terms of Service and the Privacy Policy.
Last updated: 4 August 2026
1. Purpose of the agreement
This Data Processing Agreement (hereinafter referred to as the "DPA") sets out the conditions under which Perioskoup SRL (hereinafter referred to as "Perioskoup" or "the Processor") processes personal data, including health data, on behalf of the Client (hereinafter also referred to as "the Controller"), in connection with the provision of the Services. The DPA is concluded on the basis of art. 28 of Regulation (EU) 2016/679 (hereinafter referred to as the "GDPR") and prevails over the other contractual documents as regards the processing of personal data.
2. Definitions
Capitalised terms not defined in the DPA have the meaning given in the Terms and Conditions for Professionals. In addition:
"Client Personal Data" means any Client Data relating to an identified or identifiable natural person, in particular the data of the Client's patients;
"Data Protection Legislation" means the GDPR, Legea nr. 190/2018 [Law No. 190/2018 on measures implementing the GDPR in Romania], Legea nr. 506/2004 [Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector] and any other applicable rules on the protection of personal data;
"Standard Contractual Clauses" means the standard data protection clauses approved by Implementing Decision (EU) 2021/914 of the European Commission, as subsequently amended;
"Sub-processor" means any third party engaged by Perioskoup to carry out processing operations on the Client Personal Data.
The notions "controller", "processor", "processing", "data subject", "data concerning health", "special categories of data" and "personal data breach" have the meaning given in art. 4 GDPR.
3. The roles of the parties and the processing instructions
3.1. As regards the Client Personal Data, the Client acts as controller and Perioskoup as processor. This DPA does not apply to the data in respect of which Perioskoup acts as controller, namely the data of the Client's professional account, governed by the Privacy Notice for Professionals, and the data generated by patients in their own accounts in the mobile application, governed by the Privacy Policy of the application.
3.2. Perioskoup processes the Client Personal Data exclusively on the basis of the Client's documented instructions, as they result from the Agreement, from this DPA and from the configuration and use of the functions of the Services by the Client and its users, including the activation of the artificial intelligence functions (hereinafter referred to as the "Instructions"). Perioskoup will inform the Client without delay if, in its opinion, an Instruction infringes the Data Protection Legislation.
3.3. The Client warrants that the processing of the Client Personal Data through the Services has an adequate legal basis, that the data subjects have been appropriately informed, that the data are accurate and up to date to the extent necessary, and that its Instructions comply with the Data Protection Legislation. For patient health data, the Client's typical legal basis is art. 9 para. (2) point (h) GDPR, the processing being necessary for the provision of health care by a professional subject to the obligation of professional secrecy.
3.4. The parties will cooperate in good faith in fulfilling the obligations incumbent upon them under the Data Protection Legislation, including as regards data subjects' requests, impact assessments and consultation of the supervisory authority.
4. Special categories of data and the prohibition on training
4.1. The parties acknowledge that the Client Personal Data include health data. Perioskoup applies to these data additional protection measures, including encryption in transit and at rest, pseudonymisation prior to transmission to artificial intelligence service providers, role-based access control and access logging, in accordance with Annex 2.
4.2. Perioskoup does not use the Client Personal Data for the training, testing or improvement of any artificial intelligence model, whether its own or that of a third party. Perioskoup maintains, in relation to the artificial intelligence service providers listed in the List of Sub-processors, contractual clauses which prohibit the use of the transmitted data for the training of their models.
5. Confidentiality and security
5.1. Perioskoup ensures that the persons authorised to process the Client Personal Data are subject to appropriate contractual or statutory confidentiality obligations.
5.2. Perioskoup implements and maintains the technical and organisational measures described in Annex 2, designed to protect the Client Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage, taking into account the state of the art, the costs, the nature, scope, context and purposes of the processing, as well as the risks to the rights of data subjects, in accordance with art. 32 GDPR. Perioskoup may update these measures, provided that the overall level of protection is not reduced.
5.3. The Client is responsible for the security of its own systems, devices and networks used to access the Services, for the management of its users' permissions and for the confidentiality of the authentication credentials.
6. Notification of personal data breaches
In the event of a breach of the security of the Client Personal Data, Perioskoup will notify the Client without undue delay and, in any event, within no more than 48 hours from becoming aware of it, providing the available information concerning the nature of the breach, the categories and approximate number of data subjects and of records affected, the likely consequences and the measures taken or proposed. Perioskoup will cooperate with the Client in the investigation and remediation of the incident and will provide it with reasonable assistance in fulfilling the notification obligations laid down in art. 33 and art. 34 GDPR. The notification of, or the response to, an incident does not constitute an acknowledgement of any fault or liability.
7. Sub-processors
7.1. The Client grants Perioskoup a general written authorisation for having recourse to Sub-processors. The list of the current Sub-processors, with the role and location of each, is published at https://perioskoup.com/legal/subprocessors and is incorporated by reference into this DPA. By accepting the DPA, the Client authorises the Sub-processors existing at the date of acceptance.
7.2. Perioskoup will notify the Client, by e-mail or through the Services, at least 10 days before the addition or replacement of a Sub-processor. The Client may raise justified objections within 7 days of the notification. In the event of an objection, the parties will hold good-faith discussions in order to identify an alternative solution. If no solution is reached within 30 days, the Client may terminate the Agreement without penalties, and Perioskoup will refund on a pro rata basis the fees paid in advance for the remaining period.
7.3. Perioskoup will conclude with each Sub-processor a written agreement imposing data protection obligations at least as protective as those in this DPA, and remains fully liable to the Client for the fulfilment of the obligations by the Sub-processors.
8. Assistance to the Client
8.1. Taking into account the nature of the processing, Perioskoup will assist the Client, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling the obligation to respond to data subjects' requests for the exercise of the rights laid down in Chapter III of the GDPR. If a data subject addresses a request directly to Perioskoup in relation to the Client Personal Data, Perioskoup will forward it to the Client without undue delay and will not respond on the merits without the Client's prior written consent, except in the cases required by law.
8.2. Perioskoup will provide the Client with reasonable assistance in carrying out data protection impact assessments and in the prior consultation of the supervisory authority, insofar as the assistance concerns the processing carried out by Perioskoup. For assistance requests which exceed a reasonable volume, the parties will agree in advance on the scope and the costs.
9. Return and deletion of data
9.1. Upon termination of the Agreement or at the written request of the Client, Perioskoup will, at the Client's choice, return the Client Personal Data in a commonly used, machine-readable format, or delete them securely. The export facility is available for 30 days from termination.
9.2. Perioskoup will delete the Client Personal Data from the production systems within no more than 90 days from the termination of the Agreement or from the deletion request, and the backups are eliminated through the rotation of the backup cycle, which does not exceed 90 days. If a restoration from backup becomes necessary during this period, the restored data which are subject to deletion will be deleted again as soon as it is practically possible. Upon request, Perioskoup will confirm the deletion in writing.
9.3. Perioskoup may retain data to the extent required by law, while maintaining the confidentiality and security obligations under this DPA. The Sub-processors are subject to the same return and deletion obligations.
10. Audits
10.1. Perioskoup will make available to the Client the information necessary to demonstrate compliance with the obligations laid down in art. 28 GDPR, including the documentation of the security measures and, where they exist, third-party certifications or audit reports, subject to the conclusion of a confidentiality undertaking.
10.2. If the information provided is not reasonably sufficient, the Client may carry out, directly or through an agreed independent auditor, an audit of the relevant processing activities, at most once a year, with at least 30 days' prior notice, during working hours and without unduly disrupting Perioskoup's activity and the services provided to other clients. The costs of the audit are borne by the Client. Additional audits are permitted where they are required by the supervisory authority or following a significant personal data breach. The results of the audit are confidential and are communicated to Perioskoup, together with any non-conformities identified, for remediation.
11. International transfers
11.1. Perioskoup processes and stores the Client Personal Data on servers located in the European Union. Transfers to third countries take place only in connection with the Sub-processors indicated in the List of Sub-processors and only on the basis of an adequacy decision of the European Commission, including the EU-US Data Privacy Framework for certified entities, or on the basis of the Standard Contractual Clauses, accompanied, where necessary, by supplementary measures identified through a transfer impact assessment.
11.2. Perioskoup may update the transfer mechanisms used, provided that the level of protection of the Client Personal Data is not significantly reduced. The Client will provide the cooperation reasonably necessary for the implementation of the transfer mechanisms.
12. Liability and final provisions
12.1. The liability of each party under this DPA is subject to the exclusions and limitations of liability in the B2B Terms, without prejudice to the liability towards data subjects and to the right of recourse laid down in art. 82 GDPR.
12.2. If Perioskoup is unable to fulfil its obligations under the DPA, it will inform the Client without delay, and the Client may suspend the transmission of data and, if the non-conformity is not remedied within a reasonable period which may not exceed 30 days, may terminate the Agreement as regards the affected processing. Perioskoup may terminate the Agreement if the Client insists upon an Instruction of which it has been informed that it infringes the law.
12.3. This DPA supersedes any prior processing agreements between the parties. The DPA is governed by the law applicable to the Agreement, unless the Data Protection Legislation requires otherwise.
ANNEX 1 — Description of the processing
1. Categories of data subjects
- the Client's patients, including minor patients connected with the consent of the legal representative;
- the Client's personnel and collaborators who use the Services;
- other natural persons whose data are included by the Client in the uploaded documents.
2. Categories of personal data
- identification and contact data: surname, first name, e-mail address, connection code;
- health data: patient records, anamneses, medical history, conditions, medication, allergies, clinical notes, treatment plans with procedures and statuses, medical documents, radiographs, dental scans and photographs, audio recordings of consultations and the transcriptions thereof, the content generated on their basis;
- appointment data: type, date, status, history;
- technical data associated with use: account identifiers, access and modification logs.
3. Special categories of data
Health data. Other special categories of data may not be transmitted by the Client without the prior written consent of Perioskoup.
4. Nature of the processing
Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission to Sub-processors for the functions activated by the Client, including pseudonymisation and transmission to artificial intelligence service providers for document processing, transcription and content generation, alignment, restriction, erasure and destruction.
5. Purpose of the processing
The provision, maintenance, securing and updating of the Services in accordance with the Agreement, the execution of the Client's Instructions, including of the artificial intelligence functions activated by the Client, the provision of technical support, as well as compliance with the legal obligations applicable to Perioskoup.
6. Duration of the processing
For the duration of the Agreement, with deletion of the data from the production systems within no more than 90 days from termination, in accordance with Section 9 of the DPA.
ANNEX 2 — Technical and organisational measures
- Encryption of communications. All communications between the applications and the Services, as well as those to the providers used, take place over encrypted channels, using TLS 1.2 or higher versions. Certificates are managed and renewed automatically.
- Protection of credentials. Passwords are stored exclusively in hashed form, using an algorithm dedicated to this purpose, with a unique salt per user; they are not stored in, and cannot be reconstructed to, clear text. On the user's device, authentication data are kept in the secure storage mechanisms provided by the operating system.
- Document integrity: each uploaded file is assigned a checksum.
- Access control. Access to data is governed by roles. Before access to a patient's data, the existence of the relationship between the requesting dentist and that patient is verified. Sessions have a limited duration and can be revoked. The database and the backups are encrypted.
- Infrastructure segmentation. The databases and internal services are not accessible from the public network. External access takes place exclusively through a dedicated entry component, which handles the termination of encrypted connections.
- Execution isolation and secrets management. The application components run in isolation, with the minimum privileges necessary for their operation. Configuration secrets are managed separately from the application code.
- Pseudonymisation: the data transmitted to artificial intelligence service providers are stripped in advance of names, e-mail addresses and other direct identifiers.
- Location: hosting on a dedicated server in Helsinki, Finland, in the European Union.
- Backups: encrypted, stored separately, with rotation at no more than 90 days and periodic testing of restoration.
- Logging and monitoring: centralised logging, an audit log of changes for treatment plans and anamneses, automatic alerting for unauthorised access.
- Incident management: internal procedures for the detection, escalation, investigation and notification of security incidents.
- Personnel: contractual confidentiality obligations and periodic training on data protection and information security.
- Testing: periodic vulnerability assessment and penetration testing before launch and periodically thereafter.
- Continuity: business continuity and disaster recovery procedures, with documented recovery time objectives.