1. Roles of the parties
The Clinic is the data controller of all patient personal data entered into Enamela (for example patient records, appointment history, odontogram and treatment charting, billing records, and messages). [Company legal name] (Enamela) is the data processor, processing that data solely to provide the service described in the Terms of Service and on the Clinic's documented instructions.
2. Subject matter and duration
This DPA applies for as long as Enamela processes patient personal data on behalf of the Clinic, starting when the Clinic's account is created and ending when all patient personal data has been deleted or returned in accordance with Section 8.
3. Nature and purpose of processing
Enamela processes patient personal data to provide clinic management functionality: scheduling and booking, patient records and odontogram/treatment charting, billing, appointment reminders and messages (including via WhatsApp), and related storage, backup, and support functions.
4. Categories of data and data subjects
- Data subjects: patients of the Clinic, and where relevant their guardians.
- Categories of data: contact details, appointment and booking history, treatment and odontogram records, billing and payment references, and communications sent through the platform.
5. Enamela's obligations
- Process patient personal data only on the Clinic's documented instructions, including as set out in the Terms of Service, unless required otherwise by law.
- Ensure personnel who access patient data are subject to confidentiality obligations.
- Implement appropriate technical and organizational security measures, described in Section 6.
- Assist the Clinic in responding to data subject requests and in meeting its own data protection obligations, to the extent reasonably possible given the nature of the processing.
- Notify the Clinic without undue delay after becoming aware of a personal data breach affecting patient data.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
6. Security measures
- Encryption of data in transit and at rest.
- Daily backups.
- Role-based access permissions so staff only see what their role requires.
- An audit log of access to clinic and patient records.
- Support access to a clinic account only with the clinic's consent, and such access is logged.
Enamela does not currently hold formal certifications such as SOC 2, ISO 27001, or HIPAA certification. These security measures reflect our current practices as of the effective date above.
7. Subprocessors
The Clinic authorizes Enamela to engage the subprocessors listed on the Subprocessors page to provide the service. Enamela will impose data protection obligations on subprocessors consistent with this DPA and will provide reasonable notice before adding a new subprocessor, so the Clinic may object on reasonable grounds.
8. Data location, deletion, and export
Patient data is currently hosted with our database provider in the ap-southeast-1 (Singapore) region [confirm]. Some markets may require in-country hosting for health data; where that applies, hosting arrangements will be confirmed with counsel before the Clinic's data is stored (see the Localize guidance for Gulf markets).
On termination of the Clinic's account, the Clinic may export its patient data for a reasonable period [confirm export window], after which Enamela will delete the data from active systems and, in due course, from backups, in line with our retention and backup cycle [confirm backup deletion timeline].
9. Breach notification
If Enamela becomes aware of a personal data breach affecting patient data, it will notify the affected Clinic without undue delay, describing the nature of the breach, the data affected, and the steps being taken, so the Clinic can meet its own notification obligations to patients or regulators.
10. International transfers
Where patient data is transferred across borders (for example to our hosting region), Enamela will use appropriate safeguards as required by applicable law. Specific transfer mechanisms are being finalized with counsel [confirm transfer mechanism].
11. Liability and precedence
This DPA forms part of the Terms of Service. In case of conflict between this DPA and the Terms regarding the processing of patient personal data, this DPA controls. Liability under this DPA is subject to the limitations in the Terms of Service.
12. Contact
Questions about this DPA, or requests to sign a separate DPA document, can be sent to privacy@enamela.app [confirm address].