Legal

Data Processing Agreement

Version 2026-09-09

Data Processing Agreement (DPA) — version 2026-09-09. Forms part of TrazaLab’s Terms of Service.

This agreement is between the professional customer who creates a TrazaLab account (the Controller) and TrazaLab, operating under the TrazaLab brand (the Processor). Contact: [email protected] · [email protected].

1. Subject matter and duration

The Processor processes personal data on behalf of the Controller to provide the SaaS case-coordination platform for dental clinics and laboratories (orders, digital Rx, files, TrazaChat, and related features). Duration matches the Controller’s active account plus any legally required retention.

2. Nature and purpose

Electronic processing of account data and clinical data that the Controller or authorized users upload or generate on the platform, for the purpose of operating the Service under the Controller’s documented instructions (use of the platform and account configuration).

3. Types of personal data and data subjects

Account data (name, email, role, organization). Clinical data the Controller chooses to upload (e.g. photographs, radiographs/CBCT, STL, Rx, notes, audio). Usage metadata (access logs, timestamps). Data subjects: professional users; patients or others whose data appears in files or cases uploaded by the Controller.

4. Processor obligations (GDPR Art. 28(3))

  1. Process personal data only on documented instructions from the Controller, unless required to do otherwise by Union or Member State law.
  2. Ensure persons authorized to process the data are under confidentiality commitments.
  3. Implement appropriate technical and organizational measures under Art. 32 GDPR, including encryption in transit (TLS) and at rest (AES-256 GCM on Cloudflare R2), role-based access control, and audit logging, as described in the Privacy Policy.
  4. Not engage another processor without the Controller’s prior general or specific authorization. General authorization is granted for subprocessors in Annex A; TrazaLab will give reasonable advance notice of material changes so the Controller may object.
  5. Assist the Controller, insofar as possible, with data-subject rights under Chapter III GDPR.
  6. Assist the Controller with Arts. 32–36 GDPR, taking into account the nature of processing and information available.
  7. At the end of the Service, at the Controller’s choice and where feasible, return or delete personal data and delete copies, unless law requires retention.
  8. Make available information necessary to demonstrate Art. 28 compliance and contribute to reasonable audits agreed in writing.

5. Controller obligations

The Controller warrants a lawful basis for processing, obtains required consents or other grounds for patient data, manages team access, and does not instruct processing that is unlawful or incompatible with these terms.

6. International transfers

Where processing involves transfers outside the EEA, the Processor will apply GDPR-required safeguards (e.g. standard contractual clauses or other valid measures) with respect to subprocessors that require them.

7. Personal data breaches

The Processor will notify the Controller without undue delay, and in any event within timelines compatible with Art. 33 GDPR, of personal data breaches of which it becomes aware, with reasonably available information.

8. Relationship to other documents

This DPA is incorporated into the Terms of Service. On personal-data matters this DPA prevails. For U.S. HIPAA PHI, the Business Associate Agreement (BAA) also applies.

Annex A — Subprocessors

  • Cloudflare, Inc. — object storage (R2), CDN, and network infrastructure.
  • Stripe, Inc. / Stripe affiliates — payment processing and billing (billing data).

List may be updated; see also privacy.html.