How we process data on your behalf.
For organisations that need a data-processing agreement. It covers the account data you give us; the public facts in DentalGraph are processed by us as controller.
1. Roles
The DentalGraph database itself (facts read from public registers and websites, and the calculated figures built on them) is processed by DentalGraph as controller. The details you and your colleagues enter (accounts, territories, lists, notes) are processed by DentalGraph as your processor.
2. What we process for you
Account details; the territories, lists and notes your people save.
3. How
Facts are added, never overwritten, so every change can be traced. Access is by account; admin access is logged.
4. Sub-processors
- Supabase holds the database and handles sign-in.
- Vercel hosts the website and the product.
5. Security, breach, deletion, audit
Security. Access is by account, and admin access is logged. Every connection is encrypted in transit, and the database is encrypted at rest by the company that hosts it.
Breach. If we learn that your account data has been exposed, we tell you without undue delay and give you what you need to meet your own obligations.
Deletion. When you close your account we delete your account details and the territories, lists and notes your people saved, within 30 days. Facts read from public registers and websites stay, because we hold them as controller and they are not about you.
Audit. On request we give you the information needed to show we meet our obligations as your processor, and we cooperate with an audit you commission, at reasonable notice.