DentalX Master Data Processing Agreement
Document ID: MDPA · Version: 1.0 · Language: English · Effective date: [[TO CONFIRM: publication date of v1.0]]
Status: final draft for counsel's review. Not yet published.
Drafting conventions. Text in «guillemets» is a merge field. The DentalX server fills it from the signup or acceptance record before the document is shown, and the filled text is what is hashed and recorded. Text in
[[TO CONFIRM: …]]is a fact that is not yet known; each one is listed at the end of this document. Neither appears in a published version.
Parties
- «Clinic legal name», «Clinic tax identifier type» «Clinic tax identifier», with its address at «Clinic address», «Country» (the "Clinic"); and
- VstreamX Studio Inc., a corporation incorporated under the laws of the Province of Manitoba, Canada, with its registered office at Office B – 1043 Rosser Ave, Brandon, Manitoba R7A 0L5, Canada ("VstreamX").
Each is a "Party".
Background
A. VstreamX provides DentalX, a cloud software service for managing dental clinics, under the DentalX Terms of Service (the "Terms").
B. In providing DentalX, VstreamX processes personal data about the Clinic's patients and others on the Clinic's behalf, including health data.
C. The laws that apply to the Clinic require a written agreement with a provider that processes personal data, and in particular personal health information, on the Clinic's behalf. This Agreement is that agreement. Where a law prescribes content that this Agreement does not carry, the Country Annex or Transfer Instrument for the Clinic's country supplies it.
D. The Parties therefore agree as follows.
1. Definitions and interpretation
1.1 Definitions. In this Agreement:
- "Agreement" means this Master Data Processing Agreement, its Schedules, and the Country Annexes and Transfer Instruments that apply to the Clinic under clause 2.3.
- "Applicable Data Protection Law" means every law and regulation on privacy, data protection, health information or professional secrecy that applies to the processing of Clinic Data under this Agreement, including, as they apply: the EU General Data Protection Regulation 2016/679 ("GDPR"); the UK GDPR and the Data Protection Act 2018; the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA") and the provincial laws named in the Canadian Country Annexes; and the Latin American laws named in the Country Annexes.
- "Clinic Data" means all Personal Data that VstreamX processes on behalf of the Clinic in providing the Service. It includes Patient Data and the personal data of the Clinic's personnel that the Clinic keeps in DentalX. It does not include Account Data.
- "Account Data" means the personal data VstreamX processes as an independent controller to run its relationship with the Clinic: Users' names, email addresses, roles and sign-in and security records; billing contacts; and support correspondence. The VstreamX Privacy Policy governs Account Data.
- "Patient Data" has the meaning given in the Terms. It includes health information, appointments, treatments, odontograms, radiographs, photographs, documents, consent forms and signing evidence, prescriptions, invoices, and messages exchanged with the Clinic.
- "Country Annex" means an annex to this Agreement for a country or a Canadian province, listed in Part B of the Annex Index.
- "Transfer Instrument" means a set of standard contractual clauses or a model contract adopted by a public authority that the Parties enter into through this Agreement: the EU Standard Contractual Clauses (TM-EEA), the UK International Data Transfer Addendum (TM-UK), the ANPD Standard Contractual Clauses (TM-BR) and the Argentine model contract (TM-AR).
- "Data Subject" means an identified or identifiable natural person to whom Clinic Data relates.
- "Instructions" has the meaning given in clause 3.1.
- "Personal Data" means any information relating to a Data Subject, and includes "personal information", "personal health information", "datos personales", "dados pessoais" and "renseignements personnels" as the Applicable Data Protection Law defines them.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Clinic Data that VstreamX or a Sub-processor processes. It includes a "confidentiality incident", "violación de seguridad", "incidente de segurança" and "breach of security safeguards" as the Applicable Data Protection Law defines them.
- "Security Incident" means a Personal Data Breach, or an attempted or suspected one that VstreamX reasonably believes could compromise Clinic Data.
- "Service" means DentalX as defined in the Terms.
- "Sub-processor" means a third party that VstreamX engages to process Clinic Data. The Sub-processors at the Effective Date are listed in Schedule 3.
- "Supervisory Authority" means a public authority with responsibility for data protection or health-information oversight over the Clinic or VstreamX.
- "Users" has the meaning given in the Terms.
1.2 Role names. The Applicable Data Protection Law uses different names for the same roles. In this Agreement, "controller" and "processor" mean the roles in this table, whatever name the Clinic's law uses.
| Jurisdiction | The Clinic is the… | VstreamX is the… |
|---|---|---|
| EEA, United Kingdom | controller | processor |
| Canada (PIPEDA) | organisation that transfers information for processing | third-party service provider |
| Ontario, Nova Scotia | health information custodian / custodian | agent; electronic service provider |
| Quebec | person carrying on an enterprise / body that confides the information | mandatary or service provider (mandataire ou prestataire de services) |
| Alberta, Saskatchewan, Manitoba, New Brunswick | custodian / trustee | information manager / information management service provider |
| Mexico, Colombia, Peru, Chile, Argentina, Ecuador, Costa Rica, Dominican Republic | responsable | encargado |
| Panama | responsable del tratamiento | custodio / encargado |
| Brazil | controlador (exporter) | operador (importer) |
1.3 Interpretation. "Including" means including without limitation. Headings do not affect meaning. A reference to a law includes that law as amended or replaced. "Business day" means a day other than a Saturday, Sunday or public holiday in Manitoba. "In writing" includes email and notices given in the Service.
2. Scope, structure and formation
2.1 Scope. This Agreement applies to every processing of Clinic Data by VstreamX and its Sub-processors in providing the Service to the Clinic. It supplements Section 8 of the Terms. Where they conflict, clause 19 decides which prevails.
2.2 United States. This Agreement does not apply to a Clinic whose country recorded in the Service is the United States. The DentalX Business Associate Agreement governs Clinic Data for those Clinics.
2.3 Annexes that apply. The Country Annexes and Transfer Instruments that form part of this Agreement for the Clinic are those listed for the Clinic's country (and, in Canada, its province) in the Annex Index, as the acceptance certificate in the Executed Copy records them. An annex for another country does not apply to the Clinic.
2.4 Formation. This Agreement is formed when the Clinic's authorised signatory accepts it electronically in the Service. VstreamX accepts it in advance: its electronic signature by an authorised officer appears on the acceptance certificate. Electronic acceptance has the same effect as a handwritten signature, as clause 25.2 provides.
2.5 Executed Copy. On acceptance, VstreamX generates a PDF of the complete text accepted, with the merge fields filled and an acceptance certificate (the "Executed Copy"). VstreamX emails it to the signatory and to the Clinic's owner address, and keeps it available under Settings › Legal in the Service for as long as the Clinic has an account, and afterwards on request.
3. Instructions
3.1 Documented instructions. VstreamX processes Clinic Data only on the Clinic's documented instructions (the "Instructions"). The Instructions are:
- (a) this Agreement and the Terms;
- (b) the Clinic's configuration and use of the Service by its Users, including the features it switches on, the messages it sends, the patients it creates, and the exports and deletions it performs; and
- (c) any further written instruction from the Clinic's owner that is consistent with the Terms and that VstreamX accepts in writing.
3.2 Processing required by law. VstreamX processes Clinic Data otherwise only where a law to which it is subject requires it. In that case it informs the Clinic of the legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3.3 Unlawful instructions. VstreamX informs the Clinic immediately if, in its opinion, an Instruction infringes the Applicable Data Protection Law. VstreamX may suspend the affected processing until the Clinic confirms or changes the Instruction. VstreamX does not give legal advice to the Clinic by doing so.
3.4 The Clinic's responsibilities. The Clinic is responsible for the lawfulness of the Instructions and of its processing. In particular, the Clinic:
- (a) has the legal basis, and any consent the law requires, for the Clinic Data it enters and for the processing the Service performs on its behalf, including storage in the United States as clause 13 describes;
- (b) gives its patients the notices the Applicable Data Protection Law requires, including any notice that their data is processed by a service provider and stored outside the Clinic's country;
- (c) decides how long Clinic Data is kept, as clause 15 provides; and
- (d) completes the steps that its law requires of it and that no agreement with VstreamX can perform for it, as the Country Annex lists them (for example, a privacy impact assessment, a registration, or a notice to an authority).
4. Purpose limitation and no use for VstreamX's own purposes
4.1 VstreamX processes Clinic Data only to provide, secure and support the Service for the Clinic, and as clause 3.2 permits.
4.2 VstreamX does not, and ensures that its Sub-processors do not:
- (a) sell, rent or license Clinic Data, or disclose it to anyone for that person's own purposes;
- (b) use Clinic Data for advertising, marketing, profiling or analytics of its own;
- (c) use Clinic Data, or any output derived from it, to train, fine-tune, evaluate or otherwise improve any artificial-intelligence model, whether its own or a third party's;
- (d) create de-identified, anonymised or aggregated data from Clinic Data for its own use. This does not prevent processing that the Clinic itself performs in the Service, such as anonymising a patient on the Clinic's instruction; or
- (e) combine Clinic Data with personal data from other clinics or other sources, except as the Clinic's own use of the Service requires.
4.3 If VstreamX determined the purposes or means of a processing of Clinic Data in breach of this Agreement, it would be a controller of that processing, with the liability that follows (clause 17.2(c)).
4.4 Service operation data. VstreamX may process technical and usage metrics, error reports and server logs that the Service generates, only to operate and secure the Service for the Clinic and to fix faults in it. It does not use them for any other purpose of its own, including product development, analytics or benchmarking. They are kept no longer than Schedule 2 states. VstreamX keeps Clinic Data out of them as far as reasonably practicable and does not use them to identify or profile any Data Subject.
5. Confidentiality and professional secrecy
5.1 VstreamX keeps Clinic Data confidential.
5.2 VstreamX allows access to Clinic Data only to its personnel who need it to operate, secure or support the Service, or to answer a request of the Clinic, and only to the extent they need it.
5.3 Each such person is bound, before receiving access, by a written obligation of confidentiality. That obligation is equivalent to the professional secrecy that binds the Clinic's health professionals. It covers all health information and continues after the person's work for VstreamX ends.
5.4 Each Sub-processor is bound, through its contract with VstreamX, by the confidentiality obligations that Schedule 3 records for it, and Clinic Data is protected in its hands by the encryption described in Schedule 2. VstreamX does not represent that a Sub-processor is bound by professional secrecy, or by an obligation of secrecy equivalent to it, unless Schedule 3 says so. VstreamX remains liable for each Sub-processor under clause 7.6.
5.5 DentalX's administrative console does not display patient records to VstreamX's support staff. The persons who administer VstreamX's Google Cloud project can technically reach stored data. They do so only to keep the Service running or secure, at the Clinic's request, or where the law requires it, and each such access is logged under Schedule 2.
5.6 This clause 5 survives the end of this Agreement without limit of time.
6. Security
6.1 VstreamX implements and maintains the technical and organisational measures in Schedule 2. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, and the risks for Data Subjects, those measures ensure a level of security appropriate to the risk, including for health data.
6.2 VstreamX may update the measures. An update must not reduce the overall level of protection of Clinic Data during the term. VstreamX publishes material changes with the current Schedule 2.
6.3 Encryption and key custody. Schedule 2 states which Clinic Data is field-encrypted, with which algorithm, and where the keys are kept. It also states what that encryption does and does not protect against. VstreamX does not describe the encryption as protecting against access by its hosting provider unless the keys are held outside that provider's control.
6.4 Multi-factor authentication. VstreamX makes multi-factor authentication available to every User. Where a Country Annex or the Applicable Data Protection Law requires it, VstreamX enforces it for that Clinic's Users.
6.5 The Clinic's share of security. The Clinic is responsible for:
- (a) the security of its own devices and networks;
- (b) granting each User the least role the User needs, and removing access promptly when it should end;
- (c) requiring multi-factor authentication where its law or risk requires it;
- (d) keeping its Users' credentials confidential; and
- (e) the security of any account it connects to the Service itself (for example its own Google Calendar or WhatsApp Business account), which is not a Sub-processor.
7. Sub-processors
7.1 General authorisation. The Clinic gives VstreamX a general written authorisation to engage Sub-processors. The Clinic specifically authorises the Sub-processors listed in Schedule 3 at the Effective Date.
7.2 Contractual flow-down. VstreamX engages each Sub-processor only under a written contract that imposes on it the same data-protection obligations as this Agreement imposes on VstreamX, as far as they relate to the processing the Sub-processor performs. At a minimum, that contract binds the Sub-processor on each of the matters in GDPR Article 28(3)(a) to (h): instructions, confidentiality, security, the conditions for engaging further sub-processors, assistance with data-subject requests and with security, breaches and assessments, deletion or return at the end, and information and audit. For Brazil, that contract also binds the Sub-processor to the safeguards of the ANPD Standard Contractual Clauses, as TM-BR requires. Schedule 3 names, for each Sub-processor, the contract terms that do so. VstreamX does not route a Clinic's data to a Sub-processor whose contract does not meet this clause. [[TO CONFIRM: the mapping of the Google Cloud Data Processing Addendum, the Google Workspace data processing terms and Meta's WhatsApp Business processing terms against GDPR Article 28(3)(a)–(h) and the ANPD clauses, recorded in Schedule 3]]
7.3 Notice of changes. VstreamX publishes any new or replacement Sub-processor that will process Clinic Data on the DentalX sub-processors page at least 30 days before it starts processing Clinic Data. It also notifies the Clinic's owner by email and in the Service. The notice states the Sub-processor's name, service, location and transfer mechanism.
7.4 Objection. The Clinic may object to the change on reasonable grounds relating to data protection, in writing, before the change takes effect. The Parties will discuss the objection in good faith. If they cannot resolve it, the Clinic may terminate the affected Service before the change takes effect. In that case it keeps its right to export its data under clause 14, and VstreamX refunds the fees prepaid for the period after termination.
7.5 Affirmative consent where the law requires it. Where a Country Annex or Transfer Instrument requires the Clinic's prior specific or written consent to a new Sub-processor, VstreamX asks for that consent in the Service before routing the Clinic's data to the new Sub-processor. If the Clinic does not consent, VstreamX does not route the Clinic's data to it. If that is not technically feasible, VstreamX offers the Clinic termination with export, and a refund under clause 7.4, before the change takes effect.
7.6 Liability for Sub-processors. VstreamX remains fully liable to the Clinic for the performance of each Sub-processor's obligations, as if they were its own.
7.7 Emergency suspension. If a Sub-processor's processing puts the security of Clinic Data at risk, VstreamX may suspend the flow of Clinic Data to that Sub-processor at once, and notifies the Clinic as soon as possible. Suspension adds no new recipient of Clinic Data. Any new or replacement Sub-processor is engaged only under clause 7.3, or clause 7.5 where it applies, with the full advance notice and the right to object or to consent that those clauses give.
8. Assistance with Data Subject requests
8.1 Self-service. The Service lets the Clinic's owner and managers export, correct, delete and anonymise a patient's record, and export all of the Clinic's data, in structured, commonly used, machine-readable formats. Most requests from Data Subjects can therefore be answered by the Clinic without VstreamX.
8.2 Further assistance. Where the Clinic needs information or action that only VstreamX can provide to answer a Data Subject's request (access, rectification, erasure, restriction or blocking, portability, objection, withdrawal of consent, or any equivalent right under the Applicable Data Protection Law, including ARCO and habeas data rights and the rights under Article 18 of Brazil's LGPD), VstreamX provides it within 5 business days of the Clinic's written request, or sooner where the Country Annex requires it.
8.3 Requests received by VstreamX. If VstreamX receives a request directly from a Data Subject about Clinic Data, it forwards the request to the Clinic within 2 business days and does not answer it, except to confirm that it was forwarded or where the law requires VstreamX to answer.
8.4 Assistance under this clause is provided at no additional charge.
9. Personal Data Breaches
9.1 Notice to the Clinic. VstreamX notifies the Clinic of a Personal Data Breach affecting Clinic Data without undue delay after becoming aware of it. In any event, VstreamX gives an initial notice within 24 hours after it has established, with a reasonable degree of certainty, that a Personal Data Breach has occurred and that it affects Clinic Data. Where a Country Annex sets a shorter period or an earlier trigger, that Annex applies.
9.2 Content. The notice describes, to the extent then known:
- (a) the nature of the breach, including where possible the categories and approximate number of Data Subjects and of records concerned;
- (b) the name and contact details of VstreamX's contact point from whom more information can be obtained;
- (c) the likely consequences of the breach; and
- (d) the measures taken or proposed to address the breach and to mitigate its possible adverse effects.
Where the information cannot be provided at the same time, VstreamX provides it in phases, without undue further delay, as it becomes available.
9.3 Assistance. VstreamX:
- (a) takes reasonable steps to contain, investigate and remediate the breach;
- (b) assists the Clinic in notifying Supervisory Authorities and Data Subjects where the Clinic must do so, including by providing the information it holds and, at the Clinic's request, a draft of the factual sections of those notices; and
- (c) does not notify the Clinic's patients or the Clinic's Supervisory Authority about the breach on the Clinic's behalf without the Clinic's instruction, unless the law requires VstreamX to do so.
9.4 VstreamX's own duties. Nothing in this clause limits a duty that the law places on VstreamX itself, such as its duties under PIPEDA as an organisation or a processor's own reporting duty under the Applicable Data Protection Law. Where VstreamX must report in its own name, it tells the Clinic before reporting, where the law allows.
9.5 Register. VstreamX keeps a register of every Personal Data Breach affecting Clinic Data: the facts, its effects and the remedial action taken. It keeps each entry for at least 24 months, or longer where the law requires. On request, it gives the Clinic the entries that concern the Clinic.
9.6 Delivery. Notices under this clause go to the Clinic's owner email address and to the privacy contact the Clinic records in the Service, and appear in the Service. A Country Annex may require an additional address.
9.7 No admission. A notice under this clause is not an admission of fault or liability.
10. Impact assessments and prior consultation
10.1 VstreamX gives the Clinic reasonable assistance with any data protection impact assessment, privacy impact assessment or transfer impact assessment, and with any prior consultation with a Supervisory Authority, that the Applicable Data Protection Law requires of the Clinic for the processing under this Agreement. The obligation is limited to the information VstreamX holds.
10.2 VstreamX makes available in the Service, at no charge, an assessment pack containing:
- (a) a description of the processing and the data flows;
- (b) Schedules 1 to 3;
- (c) a summary of VstreamX's transfer impact assessment for the transfers in clause 13; and
- (d) for the provinces and countries that require one, a pre-filled template in the format the local authority uses.
11. Records and registration support
11.1 VstreamX keeps a record of the categories of processing it carries out on behalf of the Clinic. The record contains the content that GDPR Article 30(2), Article 37 of Brazil's LGPD and any equivalent Applicable Data Protection Law require. VstreamX makes it available to a Supervisory Authority on request.
11.2 Where the Clinic must register a database or file, or describe its processors or transfers to an authority, VstreamX provides on request the information about VstreamX and its Sub-processors that the registration requires: identity, location, processing, transfers and security.
12. Audits and compliance information
12.1 Information. VstreamX makes available to the Clinic all information necessary to demonstrate compliance with this Agreement. It does so first through:
- (a) Schedules 1 to 3 and the assessment pack;
- (b) written answers to the Clinic's reasonable security and privacy questionnaires, once a year or after a Personal Data Breach; and
- (c) summaries of the independent certifications and audit reports of its hosting Sub-processor, and copies where that Sub-processor's terms allow.
12.2 Audits. Where that information is not sufficient to demonstrate compliance, or where a Supervisory Authority requires it, VstreamX allows and contributes to audits, including inspections, by the Clinic or by an independent auditor the Clinic mandates, as follows:
- (a) Notice: at least 30 days' written notice, except after a Personal Data Breach or at the request of a Supervisory Authority.
- (b) Frequency: no more than once in any 12-month period, except after a Personal Data Breach or at the request of a Supervisory Authority.
- (c) Conduct: during business hours and so as not to compromise the security of the Service or the confidentiality of other clinics' data. The auditor is bound by confidentiality and is not a competitor of VstreamX.
- (d) Sub-processors: an audit of a Sub-processor takes place through the audit rights and reports that the Sub-processor makes available to VstreamX.
- (e) Cost: each Party bears its own costs. Where the audit reveals a material breach of this Agreement by VstreamX, VstreamX bears the reasonable costs of the audit.
12.3 Authorities. VstreamX cooperates with any Supervisory Authority competent over the Clinic in the performance of its tasks, and submits to an audit by that authority where the Applicable Data Protection Law requires it.
12.4 Remediation. VstreamX promptly remedies any non-compliance with this Agreement that an audit reveals, and tells the Clinic what it has done.
13. International transfers
13.1 Where Clinic Data is processed. At the Effective Date:
- the database is stored in Google Cloud's United States multi-region;
- files, server functions and backups are in Google Cloud's us-central1 region (Iowa, United States);
- requests to the AI features are processed by Google Vertex AI in the Google Cloud region named in Schedule 3, row 2;
- email is processed by Google under the Google Workspace terms named in Schedule 3, row 3, and WhatsApp messages by Meta, in the countries Schedule 3 states; and
- VstreamX's personnel access the Service from Canada.
Schedule 3 states the location of each Sub-processor.
13.2 Instruction to transfer. By accepting this Agreement, the Clinic instructs VstreamX to transfer Clinic Data to, and process it in, the locations in clause 13.1 and Schedule 3.
13.3 Transfer mechanism. Each transfer of Clinic Data that the Applicable Data Protection Law restricts is made under the mechanism that the Clinic's Country Annex or Transfer Instrument provides. For Quebec, communication outside Québec is made under ANX-CA-QC. VstreamX ensures that each onward transfer to a Sub-processor is made under a mechanism recognised by the Clinic's law, and records it in Schedule 3.
13.4 Change in mechanism. If a transfer mechanism is invalidated, suspended or ceases to cover a transfer, VstreamX promptly:
- tells the Clinic;
- puts in place an alternative mechanism recognised by the Clinic's law, which may be a Transfer Instrument already part of this Agreement; and
- if no alternative is available within a reasonable time, offers the Clinic termination with export and a refund under clause 7.4.
13.5 Transfer impact. VstreamX maintains a transfer impact assessment of the laws of the United States as they apply to its Sub-processors and to the Clinic Data, and of the supplementary measures in Schedule 2. It gives the Clinic a summary as part of the assessment pack and updates it when a material change occurs.
14. Return and deletion
This clause restates and implements Sections 8.11 and 13 of the Terms. Where a Country Annex provides otherwise, that Annex applies.
14.1 Export at any time. The Clinic's owner and managers can export the Clinic's data at any time, including after a cancellation and during a suspension. The export contains the patient, clinical, financial and messaging records, the settings and templates, and a list of stored files (radiographs, photographs, documents and signed consent forms). Each file can be opened and downloaded from the Service until the Clinic's data is deleted, except while the Clinic is suspended. An export file the Clinic creates is deleted from VstreamX's servers seven days after it is made.
14.2 After the subscription ends.
- (a) For 60 days after the subscription ends, VstreamX keeps all Clinic Data and the Clinic can export it.
- (b) After those 60 days, VstreamX prepares a complete export of the Clinic's data and makes it available to the Clinic's owner.
- (c) When 90 days have passed since the subscription ended without a new one, VstreamX deletes the Clinic's Patient Data within 30 days.
- (d) VstreamX tells the Clinic's owner by email, at least 30 days before, the date on which the deletion will take place.
- (e) Deleting the Clinic's data also deletes the complete export, so the Clinic must download it before that date.
14.3 Deletion on instruction. When the Clinic's owner instructs VstreamX in writing to delete the Clinic's Patient Data, VstreamX makes the complete export available and deletes the data 30 days after receiving the instruction, unless the instruction names a later date.
14.4 Return instead of deletion. At the Clinic's choice, the complete export under clause 14.2(b) or 14.3 is the return of Clinic Data. VstreamX keeps no copy after deletion except as clause 14.5 allows.
14.5 What remains after deletion.
- (a) Backups. Deleted data remains in VstreamX's database backups until they expire, within seven days of the deletion. Until then the backups stay under the protections of this Agreement and are used only to recover from a failure.
- (b) File version history. Earlier versions of deleted files are removed from the storage service's version history as part of the deletion, on the deletion date. [[TO CONFIRM: automatic removal of non-current file versions at the deletion date is live; until it is, VstreamX removes them manually as part of each deletion, and this sentence must be true before publication]]
- (c) Audit trail. The Clinic's audit trail is part of the Clinic Data. It is included in the complete export, so the Clinic keeps it as its own record. On the deletion date VstreamX deletes its copy, or keeps only aggregate counts from which no patient, User or other individual can be identified. [[TO CONFIRM: product implementation of the deletion or anonymisation of the audit trail at the deletion date]]
- (d) WhatsApp opt-out records. Where a patient replied STOP or START to messages sent for the Clinic from DentalX's shared WhatsApp number, that choice is part of the Clinic Data. It is honoured while the Clinic uses the Service, and is deleted with the rest of the Clinic Data on the deletion date. It is never used for another clinic or for any other purpose. [[TO CONFIRM: product implementation of a clinic-scoped suppression list deleted at the deletion date]]
- (e) Data the law requires VstreamX to keep. VstreamX keeps Clinic Data after the deletion date only where a law requires VstreamX to keep it, only for as long as that law requires, and protects it under this Agreement until it is deleted. For a Clinic in the EEA, that law must be Union or Member State law; for a Clinic in the United Kingdom, the law of the United Kingdom; for a Clinic in Quebec, nothing is kept under this item. VstreamX's own contract records (the acceptance record and the Executed Copy) are not Clinic Data, and are kept as clause 2.5 and the Privacy Policy state.
14.6 Retention the Clinic's law requires. Clinic Data that the law requires the Clinic to keep (for example, clinical records) is returned to the Clinic through the export. VstreamX does not keep it on the Clinic's behalf after the deletion date unless the Parties agree a separate archiving service in writing.
14.7 Certificate. On request, VstreamX confirms the deletion to the Clinic in writing, stating what was deleted, when, and what remains under clause 14.5.
15. Retention while the account is active
15.1 The Clinic decides how long Clinic Data is kept, and is responsible for keeping records for as long as its law and professional rules require.
15.2 While the Clinic's account is active, DentalX does not delete clinical records on a schedule. Where DentalX offers country retention defaults, they are defaults the Clinic may change within the limits of its law. Where DentalX blocks deletion before a statutory minimum period, the Clinic may lift the block only by confirming that the law allows deletion in that case.
16. Requests from public authorities
16.1 If VstreamX receives a request or order from a public authority, including a court or law-enforcement or national-security authority, for disclosure of Clinic Data, VstreamX:
- (a) refers the authority to the Clinic where possible;
- (b) notifies the Clinic promptly, with a copy of the request, unless the law prohibits notification. If notification is prohibited, VstreamX uses reasonable efforts to obtain a waiver of the prohibition;
- (c) assesses the legality of the request and challenges it where, after careful assessment, it concludes that there are reasonable grounds to consider it unlawful or overbroad; and
- (d) discloses the minimum amount of Clinic Data permissible when responding.
16.2 VstreamX keeps a record of such requests and, where the law allows, gives the Clinic aggregate information about them at least once a year on request.
16.3 VstreamX does not voluntarily disclose Clinic Data to any public authority.
17. Liability
17.1 Terms apply. Each Party's liability arising out of or relating to this Agreement is subject to the exclusions and the limitation in Section 18 of the Terms. That limitation is an aggregate limit for the Terms and this Agreement together.
17.2 What the limitation does not limit. In addition to the matters listed in Section 18.3 of the Terms, nothing in the Terms or this Agreement limits or excludes:
- (a) the rights of Data Subjects as third-party beneficiaries under a Transfer Instrument, or a Party's liability towards Data Subjects under one;
- (b) any liability that the law applicable to the Clinic does not allow to be limited or excluded, including joint and several liability towards Data Subjects that the Applicable Data Protection Law imposes; or
- (c) VstreamX's liability for processing Clinic Data outside or contrary to the Instructions, or for its own purposes in breach of clause 4.
17.3 Fines. Each Party bears the administrative fines imposed on it by a Supervisory Authority. Nothing in this Agreement shifts to a Party a fine imposed on the other, except where the law allows recovery and to the extent the other Party caused it.
17.4 Indemnities. The indemnities in Section 19 of the Terms apply to this Agreement.
18. Changes to this Agreement
18.1 Versions. Each document in this Agreement carries its own version number in the form MAJOR.MINOR.
18.2 Minor changes. VstreamX may make a MINOR change, which is a clarification, a correction or an update of contact details that does not reduce the Clinic's rights or increase its obligations. It takes effect when published. VstreamX logs each MINOR change and shows it in the Service.
18.3 Major changes. A MAJOR change is any other change, including to scope, liability, transfers or Sub-processor rights, or a new obligation for the Clinic's country.
- (a) VstreamX notifies the Clinic's owner by email and in the Service at least 30 days before a MAJOR change takes effect, unless the law requires it to take effect sooner.
- (b) The Clinic accepts it in the Service.
- (c) If the Clinic does not accept it by the effective date, the Clinic's access to features that process Patient Data is restricted until it does. The Clinic's export under clause 14.1 remains available throughout.
- (d) If the Clinic does not accept a MAJOR change, it may terminate under clause 7.4 with the same refund.
18.4 Change in law. If a change in the Applicable Data Protection Law, or a decision of a Supervisory Authority, requires additional or different terms, the Parties will adopt them as an amendment or a new Country Annex under clause 18.3. VstreamX may also replace a Transfer Instrument with a newer version adopted by the competent authority.
18.5 Annex independence. A Country Annex or Transfer Instrument may be changed without re-accepting this Master Agreement, and this Master Agreement without re-accepting an annex. The acceptance record identifies the version of each document in force for the Clinic.
19. Precedence
19.1 If documents conflict, the following order of precedence applies, highest first:
- the mandatory provisions of the Applicable Data Protection Law;
- the Transfer Instruments, which no other term of this Agreement or of the Terms may exclude, modify or contradict;
- the Country Annex;
- this Master Agreement and its Schedules; and
- the Terms.
19.2 Nothing in this Agreement or in the Terms is to be read as limiting or derogating from a Transfer Instrument, or as prejudicing the fundamental rights or freedoms of Data Subjects under it.
20. Term and termination
20.1 This Agreement starts when it is formed under clause 2.4. It continues for as long as VstreamX processes Clinic Data for the Clinic, including during the periods in clause 14.
20.2 It ends automatically when VstreamX has deleted the Clinic Data under clause 14, apart from the data clause 14.5 allows it to keep.
20.3 Clauses 5, 14, 16, 17, 19, 23 and 24, and any other clause that by its nature should survive, survive the end of this Agreement. This Agreement continues to apply to any Clinic Data VstreamX keeps under clause 14.5.
20.4 A termination of the Terms is a termination of the Service for the purposes of clause 14.
21. Authority to bind and custodians
21.1 The person who accepts this Agreement for the Clinic represents and warrants that they are the Clinic's owner, its legal representative or a person with actual authority to bind it.
21.2 Where the Applicable Data Protection Law makes individual professionals the custodians or trustees of health information (as in several Canadian provinces), that person also represents that they accept this Agreement on behalf of each custodian or trustee listed in the acceptance certificate, with their authority. Alternatively, each such custodian accepts it individually.
21.3 A custodian or trustee who joins the Clinic later must accept this Agreement, or be added under clause 21.2, before creating patient records in the Service.
21.4 VstreamX may rely on these representations. The Clinic is responsible to VstreamX if they are untrue.
22. Languages
22.1 This Agreement is drafted in English. VstreamX also publishes it in Spanish, Portuguese and French.
22.2 The controlling language is:
- Spanish for Clinics in Mexico, Colombia, Peru, Chile, Argentina, Ecuador, Guatemala, Costa Rica, Panama, the Dominican Republic and Spain;
- Portuguese for Clinics in Brazil;
- French for Clinics in Quebec, unless the Clinic expressly chose, after the French version was provided to it, to be bound by the English version; and
- English for every other Clinic.
22.3 Translations of the Transfer Instruments are governed by the language rules of the Transfer Instrument itself.
22.4 The French version of this Agreement, its Schedules and ANX-CA-QC is provided free of charge.
23. Governing law and disputes
23.1 This Master Agreement is governed by the law that governs the Terms (the laws of the Province of Manitoba and the federal laws of Canada that apply there), and disputes about it are subject to the courts that the Terms designate, except as follows:
- (a) each Transfer Instrument is governed by the law it designates, and disputes under it go to the courts it designates;
- (b) a Country Annex that designates a governing law or forum for data-protection matters prevails for those matters;
- (c) the mandatory provisions of the Applicable Data Protection Law apply whatever law governs this Agreement, including, for a Clinic in Quebec, the Private Sector Act and articles 1435 to 1437 of the Civil Code of Québec; and
- (d) nothing in this clause deprives a Data Subject of a right to bring proceedings before a Supervisory Authority or court of the place where the Data Subject lives, or that the Applicable Data Protection Law otherwise gives the Data Subject.
24. Contacts and notices
24.1 VstreamX privacy contact. Privacy and data protection, VstreamX Studio Inc., Office B – 1043 Rosser Ave, Brandon, Manitoba R7A 0L5, Canada · admin@vstreamx.com. The individual accountable for VstreamX's compliance is Ricardo Javier Sandoval Sandoval, Chief Financial Officer. [[TO CONFIRM: whether a dedicated privacy@ address and an external privacy office (EU DPO / Brazil encarregado / Panama Oficial / Peru Oficial) will be named at publication]]
24.2 Representatives.
- VstreamX's representative in the European Union under GDPR Article 27: [[TO CONFIRM: name and address of the EU Art. 27 representative]].
- VstreamX's representative in the United Kingdom under UK GDPR Article 27: [[TO CONFIRM: name and address of the UK Art. 27 representative]].
24.3 The Clinic's contacts. The Clinic records its privacy contact (privacy officer, data protection officer, encarregado or equivalent) in the Service and keeps it up to date. Until it does, notices go to the Clinic's owner.
24.4 Notices. Notices under this Agreement are given as Section 22 of the Terms provides, and also in the Service.
25. General
25.1 Entire agreement. This Agreement and the Terms are the entire agreement between the Parties about the processing of Clinic Data. They replace any earlier statement in the Terms that Section 8 of the Terms serves as the written processing or information-manager agreement for the Clinic.
25.2 Electronic acceptance. The Parties agree that this Agreement may be accepted and signed by electronic means (including, for Quebec, under the Act to establish a legal framework for information technology, CQLR c. C-1.1, and, for Brazil, under Article 10, §2 of Provisional Measure 2.200-2/2001), and that the electronic acceptance record and the Executed Copy are a writing signed by each Party.
25.3 Severability. If a provision is found invalid or unenforceable, the rest of this Agreement remains in force. The provision is applied to the fullest extent permitted, in the manner that best achieves the protection of Clinic Data.
25.4 No waiver. A failure or delay in exercising a right is not a waiver of it.
25.5 Assignment. Neither Party may assign this Agreement except together with the Terms and as the Terms allow.
25.6 Third-party rights. Data Subjects have the rights that a Transfer Instrument or the Applicable Data Protection Law expressly gives them. Otherwise, nobody other than the Parties has rights under this Agreement.