Version 2026-09-09
Data Processing Agreement (DPA) — version 2026-09-09. Forms part of TrazaLab’s Terms of Service.
This agreement is between the professional customer who creates a TrazaLab account (the Controller) and TrazaLab, operating under the TrazaLab brand (the Processor). Contact: [email protected] · [email protected].
The Processor processes personal data on behalf of the Controller to provide the SaaS case-coordination platform for dental clinics and laboratories (orders, digital Rx, files, TrazaChat, and related features). Duration matches the Controller’s active account plus any legally required retention.
Electronic processing of account data and clinical data that the Controller or authorized users upload or generate on the platform, for the purpose of operating the Service under the Controller’s documented instructions (use of the platform and account configuration).
Account data (name, email, role, organization). Clinical data the Controller chooses to upload (e.g. photographs, radiographs/CBCT, STL, Rx, notes, audio). Usage metadata (access logs, timestamps). Data subjects: professional users; patients or others whose data appears in files or cases uploaded by the Controller.
The Controller warrants a lawful basis for processing, obtains required consents or other grounds for patient data, manages team access, and does not instruct processing that is unlawful or incompatible with these terms.
Where processing involves transfers outside the EEA, the Processor will apply GDPR-required safeguards (e.g. standard contractual clauses or other valid measures) with respect to subprocessors that require them.
The Processor will notify the Controller without undue delay, and in any event within timelines compatible with Art. 33 GDPR, of personal data breaches of which it becomes aware, with reasonably available information.
This DPA is incorporated into the Terms of Service. On personal-data matters this DPA prevails. For U.S. HIPAA PHI, the Business Associate Agreement (BAA) also applies.
List may be updated; see also privacy.html.