Schedule 1: Description of the processing

MDPA-S1 · Draft of October 6, 2026 · revision 1 · version 1.0

Part of Master Data Processing Agreement

Final draft for counsel's review. It is not in effect, and no clinic has accepted it. Items still to be confirmed are highlighted in the text.

Which language controls depends on the clinic's country: English, Español, Português, Français.

Read in: English · Español · Português · Français

SHA-256 of this text: 1cfbbc60f2670fb22b42e9067c205be1102219cebf745ece3f085f1297633881

Schedule 1 — Description of the processing

ItemDescription
Subject matterVstreamX's hosting and processing of Clinic Data to provide DentalX, a dental-clinic management service, to the Clinic.
DurationThe term of the Clinic's use of the Service, followed by the periods in clause 14.
FrequencyContinuous.
Nature of the processingCollection through the Clinic's Users and through patients' own actions (such as signing a consent or confirming an appointment from a link); recording; organisation; structuring; storage; field encryption; retrieval; consultation; use; adaptation (such as drafting by the AI features at a User's request); transmission by email and WhatsApp at the Clinic's instruction; export; backup and restoration; restriction; anonymisation; erasure and destruction.
Purposes(1) Providing the Service's features to the Clinic: patient records and charting (including the odontogram), scheduling, treatments and treatment plans, radiographs and photographs, consent forms with on-screen signatures, prescriptions (recetas), invoices and payments, reminders and recalls by email and WhatsApp, reports, inventory and lab orders, and AI-assisted drafting and reading. (2) Securing the Service, including access control, logging and incident response. (3) Backup and recovery. (4) Support requested by the Clinic. (5) Compliance with the law, as clause 3.2 provides.
Categories of Data Subjects(a) the Clinic's patients, including minors; (b) patients' parents, guardians and legal representatives; (c) emergency contacts; (d) insurance policyholders, where different from the patient; (e) the Clinic's personnel, including dentists and other health professionals, managers and receptionists, as recorded in the Clinic's own records; (f) referring professionals, laboratories and suppliers' contact persons; and (g) persons who correspond with the Clinic through the Service.
Categories of Personal DataIdentification: name, date of birth, sex or gender, identity-document numbers where the Clinic records them (including data read from identity cards by an AI scan), photographs. Contact: telephone, email, postal address, emergency contact. Insurance: insurer, plan and policy details. Appointments: dates, times, practitioner, status and confirmations. Financial: invoices, payments, balances, cash-register lines, treatment prices, and practitioners' commissions. Communications: emails, WhatsApp messages and the files patients send, reminders and recall notices. Consent and signing evidence: consent texts, on-screen signatures, the typed name, the time, a fingerprint (hash) of the exact text signed, the browser used and the network address recorded with the request. Professional: practitioners' names, roles and the licence numbers they print on prescriptions. Audit trail: which User did what and when, including the opening of a patient's chart, exports, deletions and changes to patient and treatment records.
Special categories (sensitive data)Data concerning health: medical and dental history, allergies, medications, diagnoses, odontogram and periodontal charting, clinical notes, treatment plans and treatments, radiographs and intra-oral and facial photographs, documents, prescriptions, consent forms, and AI drafts and readings about them. Data about minors. National identification numbers where the Clinic records them. On-screen signatures are stored as images and are not processed for the purpose of uniquely identifying a person; they are not processed as biometric data.
Restrictions and safeguards for sensitive dataField encryption of the identifying and history fields, consents and prescriptions (Schedule 2); role-based access in which clinical AI features are limited to owners, managers and dentists; audit trail; the confidentiality and secrecy obligations in clause 5; no use for VstreamX's own purposes (clause 4).
Sub-processorsSchedule 3.
LocationsClause 13.1 and Schedule 3.
RetentionSet by the Clinic while the account is active (clause 15). After the end, clause 14 and the Country Annex.