Data Processing Addendum

Toothprint · Version 1.2 · In force since September 11, 2026 · Español

This Addendum is part of the General Terms of Service and applies whenever the Services process personal data on your behalf. It is written to satisfy Article 28 of the GDPR, and Article 25 of Decreto 1377 de 2013 in Colombia, which requires this contract to exist in writing before a responsable hands data to an encargado. Section 17 maps it clause by clause.

You are the controller of your patients' data. We are the processor. The one exception is Section 16, which is not a processing instruction at all, and which is why that Section is written the way it is.

1. Definitions

2. What we process, and why

Element Description
Subject matter Providing the Services described in the General Terms
Duration The term of the contract, plus the wind-down in Section 10
Nature Hosting, transmission, storage, derivation, visualisation, deletion, the analytics copy in BigQuery described in Subprocessors, and — only with the patient's own authorisation — sending a photograph of them to Google's Gemini API for their record-card portrait (Section 6.1)
Purpose To provide, maintain and secure the Services for your own environment, and to troubleshoot them. This purpose does not include developing or training machine-learning models, which is governed exclusively by Section 16
Data subjects Your patients, and the members of your practice
Categories of data Identifiers, device data, intraoral scans, session video of the patient's face, a photograph of the patient where the record-card portrait is used, motion frames, clinical notes, derived analyses

Read the purpose row twice. "Improve the Services" is the phrase that usually carries a training right inside it. Here it is fenced: improvement means your environment, and training has its own Section, its own legal basis and its own signature.

3. Your instructions

We process Customer Personal Data only on your documented instructions, which are: the contract and this Addendum; the configuration choices you make in the Services; and any further written instruction within the scope of the contract. If we believe an instruction breaks a data protection law, we will tell you.

4. Confidentiality

Everyone we authorise to process Customer Personal Data is bound by confidentiality, by contract or by professional duty.

5. Security

We apply the measures in Security Practices, which describe what runs today rather than what is planned.

6. Sub-processors

You authorise the Sub-processors listed at Subprocessors. We will keep that list current, give you at least 30 days' notice before adding one that would process patient material, impose written terms on each that are no less protective than this Addendum, and remain liable to you for what they do. You may object on reasonable grounds; if we cannot resolve it, you may terminate the affected part of the Services.

6.1 The record-card portrait, the one route to a generative model

There is a single path by which a patient's material reaches a third party's generative model, and it goes here because it is a sub-processor question and not a footnote.

When a professional uses the portrait feature, the patient's photograph is sent to Google's Gemini API (generativelanguage.googleapis.com, United States) and the styled image comes back. Only the photograph and the style instruction go: not the name, the identifiers, the scans or the video.

The conditions, which are not negotiable because they are in the code:

Basis The patient's own authorisation, in a box separate from the clinical one and from model development, off by default
Check The server reads the latest receipt before sending anything. Without that box set to true it sends nothing and deletes the uploaded photograph
Scope A portrait for the record card. No analysis, no diagnosis, no training of ours
What we do not control What Google retains on their side is governed by that API's terms and not by this contract. We say so rather than leave it out

If you would rather this never happened in your practice, do not tick that box for any patient. Nothing else in the service changes.

7. Requests from patients and users

We assist you in answering Data Subject Requests, by appropriate technical and organisational measures and taking into account the nature of the processing. If a patient comes to us directly we refer them to you, because you are their controller, and we tell you that they came.

In Colombia the deadlines are short — 10 business days for a consulta, 15 for a reclamo, each extendable once. We answer your requests for assistance within a time that lets you meet them.

8. Breach

We notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notice says what we know at the time: what happened, which categories and roughly how many records and data subjects, the likely consequences, and what we have done.

9. Impact assessments

We give you reasonable help with a DPIA or a prior consultation with a supervisory authority under Articles 35 and 36 GDPR.

10. Return and deletion

When the contract ends you choose: we return Customer Personal Data by export, or we delete it. Where the law requires us to keep something, we keep it confidential and stop processing it for anything else.

Deletion reaches active storage, the GPU compute provider's volumes, and the BigQuery copy described in Subprocessors. Those three do not happen at the same speed and we would rather give you the real numbers than one comforting one:

Where How When
Firestore and file storage Automatic, from the app Immediately
BigQuery analytics copy Automatic, a scheduled job that walks every table in the dataset, verifies by counting rows, and retries Up to 24 hours
GPU compute provider's volumes An operator step, not an automatic one. It is queued and tracked, not left to memory Within 30 days

We do not operate a restorable backup of our own, so there is no backup to wait out. See Security Practices, Section 7.

11. Audit

We give you the information you need to show you comply with this Addendum. Once independent audit reports exist, they satisfy this obligation. Until then, you may audit once a year — or more often after a breach or if an authority requires it — at your expense, with 30 days' notice, under reasonable confidentiality conditions.

12. International transfers

Everything is processed in the United States. The database region and the functions region were fixed when the project was created and cannot be moved.

Where that means transferring data out of the EEA, the UK or Switzerland, we rely on the Standard Contractual Clauses (Module Two, controller-to-processor) plus encryption in transit and at rest, and we will execute the SCCs and any country addendum on request. In Colombia, a transfer to a encargado abroad is a transmisión under Article 3 of Decreto 1377 and is covered by this contract under Article 25, not by the authorisation regime of Article 26 of Ley 1581.

If your regulator requires the data to stay in Europe, we cannot serve you today. We prefer to lose the customer than to write a sentence about region pinning that is not true.

13. Liability

Liability under this Addendum is subject to the caps in the General Terms, except where the law does not allow a cap.

14. Order of precedence

If this Addendum conflicts with the General Terms, this Addendum wins for anything concerning the processing of personal data.

15. Health data

Customer Personal Data includes data about patients' health. In Colombia this is a dato sensible under Article 5 of Ley 1581; in the EU it is a special category under Article 9 GDPR. You warrant that you hold a valid basis for the processing you instruct — in practice, the patient's explicit authorisation, which is the only basis that Article 6 of Ley 1581 offers for this.

We do not accept customers who are Covered Entities under HIPAA, because we do not yet hold a Business Associate Agreement with every subprocessor that would touch Protected Health Information. Do not route PHI through the Services.

16. Transfer for model development

This Section is the only route by which any patient material may be used to develop or train machine-learning models. Nothing else in this Addendum, in the contract, or in any setting in the app authorises it.

16.1 What changes hands, and when

Where — and only where — a patient has given a separate, specific, written and revocable authorisation for their material to be used to develop or train models, and you have recorded that authorisation through the Services, the material covered by it is transferred to Toothprint as an independent controller of its own purpose.

It is a transfer to a new controller, not an instruction to a processor. We record it as such because calling it anything else would misdescribe what happens.

Recipient Toothprint, the provider identified in the Privacy Policy
Purpose Developing, training and evaluating our own models for markerless registration, segmentation and motion prediction
Legal basis The patient's explicit authorisation: Article 6(a) of Ley 1581 de 2012 in Colombia; Article 9(2)(a) GDPR in the EU and the UK
Status under this Addendum That material stops being Customer Personal Data processed on your behalf, and becomes our own responsibility as controller

Everything the patient has not authorised for this purpose stays exactly where it was: you remain its controller and we remain your processor under the rest of this Addendum.

16.2 What you warrant

That the authorisation was obtained before the material was captured; that it was separate from the clinical consent and from accepting this contract; that it was opt-in, never pre-ticked and never bundled; that the patient was told that refusing changes nothing in their care; and that you hold the signed record and will produce it on request.

16.3 What we commit to

16.4 Minors

Where the patient is a minor, the authorisation under this Section is given by their legal representative, and you warrant that you verified that representation. When the patient reaches majority they may revoke it themselves, with the effects in Section 16.3.

16.5 Nothing has been trained yet

As of the date of this version, no model has been trained, fine-tuned or evaluated on patient material. We say it here because it is the kind of statement that is only worth anything if it is made before it stops being true.

17. Colombia — the transmission contract

Article 25 of Decreto 1377 de 2013 requires a contract between responsable and encargado, with specific content. This Addendum is that contract. Where it lives:

What Article 25 requires Where it is
The scope and purposes of the processing Section 2
The activities the encargado will carry out on behalf of the responsable Section 2, and the General Terms, Section 2
The obligations of the encargado toward the titular and the responsable Sections 3 to 12
That the encargado applies the responsable's security policy Section 5 and Security Practices
That the encargado keeps the information confidential Section 4

Two more things Colombian law makes explicit, and that we would rather write down than leave implied. Processing patient health data has one lawful basis here and it is the titular's prior, express and informed authorisation: Article 6 of Ley 1581 has no medical exception, and Ley 1581 contains no "legitimate interest". And a clinical record has its own retention rules — Resolución 1995 de 1999 and Resolución 839 de 2017 — which belong to you, not to us; nothing in Section 10 overrides your duty to keep a historia clínica for as long as those require.


In force since September 11, 2026 · Version 1.2

Version 1.1 supersedes the unpublished drafts of May 2026. What changed: the product is named across its three surfaces, the BigQuery copy is disclosed, the region-pinning claim was removed because it was not true, the HIPAA route was closed rather than promised, and Section 17 maps the document to Colombian law.

Version 1.1, amended 12 September 2026. Version 1.0 was published on 11 September and contained statements that a review against the running system showed to be wrong. They are corrected here rather than quietly edited, because a published document that changes without saying so is worth less than one that admits it changed: a page that said no third party ran AI inference on patient material, while a patient-photo feature was sending faces to a generative model; a security page that claimed point-in-time recovery and 12-month backups that were never configured; a deletion promise that gave one timeline for three destinations that do not run at the same speed; and a three-year destruction promise with no machinery behind it.

Version 1.2, amended September 12, 2026. The analytics export to BigQuery stopped carrying the raw sessions collection — which holds patient identifiers and download links inside it, and a download link is a credential — and now carries a derived collection with nothing identifiable in it. The history already exported is kept separately, pseudonymised. This is written down because version 1.1 described the previous export, and describing it wrongly after fixing it would be version 1.0's mistake in reverse.