EEA Transfer Module (EU Standard Contractual Clauses)

TM-EEA · Draft of October 6, 2026 · revision 1 · version 1.0

Final draft for counsel's review. It is not in effect, and no clinic has accepted it. Items still to be confirmed are highlighted in the text.

This is the controlling text.

SHA-256 of this text: 5c3c85f7d0bd7113f02964dedf8729147bfefd32fa4341bbf852f8c7fa9c5f25

TM-EEA — EEA Transfer Module (EU Standard Contractual Clauses)

Document ID: TM-EEA · Version: 1.0 · Language: English (a courtesy copy in the Clinic's language may be provided; English controls) · Effective date: [[TO CONFIRM: publication date]] Applies to: Clinics established in any EU Member State offered by DentalX, and in Iceland, Liechtenstein and Norway. Part of the Master Data Processing Agreement (the "MDPA"). Terms defined in the MDPA have the same meaning here.


Part 1 — Transfer framework

1.1 The transfers

Clinic Data is transferred in two legs:

  1. Leg 1: from the Clinic in the EEA to VstreamX in Canada.
  2. Leg 2: from VstreamX to its Sub-processors, mainly in the United States.

1.2 Leg 1: adequacy is the primary basis

  • The decision. The European Commission has decided that Canada ensures an adequate level of protection for personal data transferred to recipients subject to PIPEDA (Commission Decision 2002/2/EC). That decision is maintained under GDPR Article 45(9).
  • Why it covers VstreamX. VstreamX is a Manitoba corporation, and it processes Clinic Data in the course of commercial activity. PIPEDA therefore applies to it, and the Clinic's transfer to VstreamX is made under that decision.
  • EFTA states. For Iceland, Liechtenstein and Norway, the decision applies as incorporated into the EEA Agreement.

1.3 The Standard Contractual Clauses are entered into now

By accepting the MDPA, the Clinic and VstreamX hereby enter into the Standard Contractual Clauses in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (transfer controller to processor) (the "Clauses"), completed as set out in Part 2.

The Clauses are entered into now and apply as follows:

  • (a) Whenever leg 1 is not covered by the adequacy decision, to that transfer. This includes where the decision is repealed, suspended or amended so that it no longer covers VstreamX or the Clinic Data, or where a competent authority or court finds that it does not.
  • (b) At all times, to VstreamX's onward transfers (leg 2), through Clause 8.7 of the Clauses. VstreamX gives this commitment as a contractual obligation even while leg 1 relies on adequacy.

1.4 The text of the Clauses

  • The Clauses are incorporated by reference, without modification, in the form published in the Official Journal of the European Union, OJ L 199, 7.6.2021, p. 31.
  • Their full official text is reproduced in the bundle that the Clinic reads before accepting, and in the Executed Copy. [[TO CONFIRM: insert the official EUR-Lex English text of Module Two, Sections I–IV, generated from the official consolidated source file — never retyped]]
  • Only the options and annexes in Part 2 are completed. No other change is made to the Clauses.

1.5 Precedence

  • The Clauses prevail. If the Clauses conflict with the MDPA, a Country Annex or the DentalX Terms of Service, the Clauses prevail (Clause 5).
  • Nothing derogates from them. No provision of those documents is to be read as contradicting the Clauses, directly or indirectly, or as prejudicing the fundamental rights or freedoms of data subjects.
  • Liability. In particular, the limitation of liability in the Terms and in MDPA clause 17 does not apply to liability under Clause 12 of the Clauses towards data subjects.

1.6 Leg 2: onward transfers

  • What VstreamX relies on. For each Sub-processor in Schedule 3, VstreamX relies on:
    • (a) the Sub-processor's certification under the EU-U.S. Data Privacy Framework, where it is certified, under Commission Implementing Decision (EU) 2023/1795; and
    • (b) the Standard Contractual Clauses (Module Three, processor to processor, or the equivalent terms of the Sub-processor's data processing addendum), which the Sub-processor's data processing terms contain as a second layer.
  • Evidence kept. VstreamX keeps a dated record of each Sub-processor's Data Privacy Framework listing, and of its contract terms.

1.7 Transfer impact assessment

  • The assessment. VstreamX has assessed the laws and practices of the United States and of Canada that apply to the processing of Clinic Data by VstreamX and its Sub-processors. This includes access by public authorities and the supplementary measures in MDPA Schedule 2. This is the assessment Clause 14 of the Clauses requires.
  • A summary. A summary is attached to this Module as Appendix A and is available in the assessment pack.
  • When it changes. VstreamX updates the assessment when a material change occurs, such as a court decision on the EU-U.S. Data Privacy Framework.

1.8 Commitments of VstreamX for EEA Clinics

In addition to the Clauses and the MDPA, VstreamX commits, for every EEA Clinic:

  • (a) multi-factor authentication is available to every User of the Clinic, and the Clinic's owner can make it mandatory for the Clinic's owners and managers (MDPA Schedule 2, B.8) [[TO CONFIRM: if mandatory MFA for every EEA User ships before publication, this item may say so; until then it must say no more than this]];
  • (b) no AI radiograph analysis ("AI scans") is offered, because it is not CE-marked as a medical device;
  • (c) AI output is labelled as AI-generated, consistent with Article 50 of Regulation (EU) 2024/1689;
  • (d) Prescriptions. Prescriptions produced by DentalX are clinical records or private prescriptions only. They are not electronic prescriptions in any national system, and the Service says so where it shows them;
  • (e) Not the clinic's national record. The Service is not presented as the Clinic's complete legal health record or its connection to a national e-health system. This applies where national law requires reporting to such a system (for example EESZT, eRecept, ESPBI IS, CEZIH, E-veselība or eZdravie);
  • (f) VstreamX appoints, and names in MDPA clause 24.2 and in the Privacy Policy, a representative in the Union under GDPR Article 27 for the processing in which VstreamX is itself subject to the GDPR; and
  • (g) the assistance under MDPA clause 10 includes a pre-filled record of processing (GDPR Article 30) and a DPIA support pack.

Part 2 — Options and Annexes to the Clauses

2.1 Options selected

ClauseSelection
Clause 7 (Docking clause)Included.
Clause 9(a) (Use of sub-processors)Option 2: general written authorisation. The data importer shall specifically inform the data exporter in writing of any intended changes to the list of sub-processors through the addition or replacement of sub-processors at least 30 days in advance. The list agreed at the Effective Date is in Annex III.
Clause 11(a) (Redress)The optional language is not used.
Clause 13(a) (Supervision)The supervisory authority of the EEA State in which the data exporter (the Clinic) is established, as stated in Annex I.C.
Clause 17 (Governing law)Option 1: these Clauses are governed by the law of Ireland.
Clause 18(b) (Choice of forum and jurisdiction)The courts of Ireland.

2.2 How the MDPA implements particular Clauses

The MDPA gives effect to the Clauses as follows, without limiting them:

  • Clause 8.1 (instructions). MDPA clause 3 sets out the instructions.
  • Clause 8.5 (duration and deletion).
    • At the end of the provision of the processing services, the data importer deletes the Clinic Data or returns it, at the exporter's choice, under MDPA clause 14.
    • It certifies the deletion to the Clinic in writing.
    • The only copies retained under MDPA clause 14.5 are database backups that expire within 7 days of the deletion, and data that Union or Member State law requires the data importer to keep. Where local law applicable to the data importer prohibits return or deletion, Clause 8.5 applies as written. All such copies remain protected by the Clauses.
  • Clause 8.6(c) (breach).
    • MDPA clause 9 applies. VstreamX notifies the exporter without undue delay, and in any event within 24 hours of establishing the breach.
  • Clause 8.9 (documentation and compliance).
    • MDPA clause 12 describes how VstreamX makes information available and how audits are carried out.
    • It applies only in so far as it does not restrict the Clinic's rights under Clause 8.9.
    • In particular, those rights include the right to audit at reasonable intervals or where there are indications of non-compliance.
  • Clause 9 (sub-processors). MDPA clause 7 describes the notice and objection process.
  • Clause 10 (data subject rights). MDPA clause 8 describes the assistance, which is given within 5 business days.
  • Clause 15 (government access). MDPA clause 16 implements it.

2.3 Signature

The Parties sign the Clauses by the electronic acceptance described in MDPA clause 2.4. The acceptance certificate in the Executed Copy states, for each Party, the name, position and date that Annex I.A requires.


ANNEX I

A. List of parties

Data exporter

FieldValue
Name«Clinic legal name»
Address«Clinic address», «Country»
Contact person's name, position and contact details«Signatory name», «Signatory role», «Signatory email»; privacy contact: «Clinic privacy contact»
Activities relevant to the data transferred under these ClausesProvision of dental care and management of the dental practice, using DentalX for patient records, scheduling, treatments, imaging, consents, prescriptions, invoicing and patient communications.
Signature and dateElectronic acceptance by «Signatory name» on «Acceptance date (UTC)»
RoleController
EU representative (where applicable)Not applicable (the exporter is established in the EEA).

Data importer

FieldValue
NameVstreamX Studio Inc.
AddressOffice B – 1043 Rosser Ave, Brandon, Manitoba R7A 0L5, Canada
Contact person's name, position and contact detailsRicardo Javier Sandoval Sandoval, Chief Financial Officer, accountable individual for privacy · admin@vstreamx.com [[TO CONFIRM: dedicated privacy address and DPO contact, if appointed]]
Representative in the Union[[TO CONFIRM: name and address of the EU Article 27 representative]]
Activities relevant to the data transferred under these ClausesProvision of DentalX, a cloud dental-practice management service, to the data exporter, including hosting, storage, backup, communications and AI-assisted features.
Signature and dateElectronic signature of VstreamX's authorised officer on the acceptance certificate, on «Acceptance date (UTC)»
RoleProcessor

B. Description of transfer

ItemDescription
Categories of data subjectsPatients of the exporter, including minors; patients' parents, guardians and legal representatives; emergency contacts; insurance policyholders; the exporter's personnel as recorded in its own records; referring professionals, laboratories and suppliers' contact persons; persons who correspond with the exporter through the Service.
Categories of personal dataIdentification (name, date of birth, sex or gender, identity-document numbers where recorded, photographs); contact details; insurance details; appointments; financial data (invoices, payments, balances, cash-register lines, prices, practitioners' commissions); communications (emails, WhatsApp messages and attached files, reminders); consent texts and signing evidence (on-screen signature, typed name, time, hash of the text signed, browser, network address); practitioners' names, roles and licence numbers; audit-trail entries.
Sensitive data transferred, and restrictions and safeguards appliedData concerning health (GDPR Article 9): medical and dental history, allergies, medications, diagnoses, odontogram and periodontal charting, clinical notes, treatment plans, radiographs and photographs, documents, prescriptions, consent forms, and AI drafts and readings about them. Data concerning minors. Safeguards: AES-256-GCM field encryption of the patient's identifying fields, medical history, insurance details, consent forms and prescriptions; strict purpose limitation and no use for the importer's own purposes, including no AI training (MDPA clause 4); access limited by role, with clinical AI features restricted to owners, managers and dentists; staff bound by an obligation of secrecy equivalent to professional secrecy (MDPA clause 5); audit trail of chart openings, exports, deletions and changes; multi-factor authentication available to every User, which the exporter can make mandatory for its owners and managers; onward transfers only under Clause 8.7; the measures in Annex II.
Frequency of the transferContinuous, for the duration of the exporter's use of DentalX.
Nature of the processingHosting, storage, field encryption, organisation, retrieval, consultation, use to provide the Service's features, transmission by email and WhatsApp at the exporter's instruction, AI-assisted drafting and reading at a User's request, backup and restoration, export, anonymisation and erasure.
Purpose(s) of the data transfer and further processingTo provide DentalX to the exporter (MDPA Schedule 1), to secure it, to back it up and restore it, to provide support the exporter requests, and to comply with law as Clause 8.1 allows.
Period for which the personal data will be retainedFor the duration of the exporter's use of the Service, as the exporter decides. After the end: 60 days' retention with export, then deletion within 30 days of the 90th day after the end (or 30 days after a written deletion instruction), with backups expiring within 7 days of deletion. The audit trail is returned in the export, and the importer's copy is deleted or anonymised on the deletion date (MDPA clause 14.5).
Transfers to (sub-)processors: subject matter, nature and durationAs Annex III states for each sub-processor, for the same duration as the processing by the importer.

C. Competent supervisory authority

The supervisory authority of the EEA State in which the data exporter is established. It is filled from the Clinic's country, for example:

  • Ireland: Data Protection Commission
  • Spain: Agencia Española de Protección de Datos
  • Italy: Garante per la protezione dei dati personali
  • Netherlands: Autoriteit Persoonsgegevens
  • Belgium: Autorité de protection des données / Gegevensbeschermingsautoriteit
  • Austria: Datenschutzbehörde
  • Poland: Prezes Urzędu Ochrony Danych Osobowych
  • Sweden: Integritetsskyddsmyndigheten
  • Norway: Datatilsynet
  • Portugal: Comissão Nacional de Proteção de Dados
  • Denmark: Datatilsynet
  • Iceland: Persónuvernd
  • Liechtenstein: Datenschutzstelle
  • the other states: their national authority

The exact authority is printed in the Executed Copy as «Competent supervisory authority». Where the Clinic's Member State has more than one competent authority (for example the regional authorities in Germany, which is not offered at present), it is the authority competent for the Clinic.


ANNEX II — Technical and organisational measures including measures to ensure the security of the data

The technical and organisational measures are those in MDPA Schedule 2, which is incorporated here. The table maps them to the categories the Commission's template lists.

CategoryMeasures (MDPA Schedule 2 item)
Pseudonymisation and encryptionTLS in transit (A.1); provider encryption at rest (A.2); AES-256-GCM field encryption (A.3); key custody (A.4)
Ongoing confidentiality, integrity, availability and resilienceTenant isolation by deny-by-default rules (B.5); role-based access (B.6); daily backups and 7-day point-in-time recovery (D.15); file version history (D.16)
Ability to restore availability and access in a timely mannerBackups and point-in-time recovery (D.15)
Regular testing and evaluationDependency vulnerability audit before every production deployment (F.19); controlled deployment (F.20)
User identification and authorisationIndividual logins (B.7); multi-factor authentication (B.8); role-based access (B.6)
Protection of data during transmissionTLS (A.1); expiring links and single-use consent links (B.10)
Protection of data during storageProvider and field encryption (A.2, A.3); isolation (B.5)
Physical security of locationsProvided by Google Cloud data centres under Google's certifications (G.25)
Events loggingAudit trail (C.12, C.13); server logs (C.14)
System configuration, including default configurationDeny-by-default rules (B.5); Content-Security-Policy (F.21); no advertising or analytics tools (E.17)
Internal IT and IT security governance and managementAccountable individual (G.24); incident-response procedure (G.23)
Certification and assurance of processes and productsHosting provider certifications (G.25)
Data minimisationNo analytics (E.17); clinical AI features limited by role (B.6); purpose limitation (MDPA clause 4)
Data qualitySelf-service correction by the exporter (MDPA clause 8.1)
Limited data retentionMDPA clauses 14 and 15; logs 30/90 days (C.14)
AccountabilityProcessor record (MDPA clause 11); breach register (MDPA clause 9.5)
Allowing data portability and ensuring erasureWhole-clinic and per-patient export; deletion and anonymisation (MDPA clauses 8 and 14)
Measures of sub-processors to assist the controllerEach sub-processor's contract binds it on each matter in GDPR Article 28(3)(a)–(h), including assistance to the importer, and through it the exporter, with security and data-subject requests; MDPA Schedule 3 names the terms (MDPA clause 7.2).

ANNEX III — List of sub-processors

The controller has authorised the use of the sub-processors listed in MDPA Schedule 3 (version 1.0), which is incorporated here. For each, Schedule 3 states the name and contracting entity, the processing (service and data), its location (the country or countries, and for Vertex AI the named Google Cloud region), the contract terms that bind it, and the transfer basis. Contact details are those published by each sub-processor for privacy matters. [[TO CONFIRM: add each sub-processor's privacy contact address to Schedule 3 before publication]] [[BLOCKING TO CONFIRM: no row may say 'other countries' without naming them; the Vertex AI regional endpoint and the Google Workspace sending account must be live before publication]]


Appendix A — Summary of the transfer impact assessment

  1. The actual data flow. Clinic Data does not pass through Canada. The Clinic's browsers send it directly, over TLS, to Google LLC's infrastructure in the United States (MDPA clause 13.1), where VstreamX processes it as importer and Google processes it as VstreamX's sub-processor. VstreamX's personnel reach it remotely from Canada. The assessment therefore covers two things at once: VstreamX's position as importer (leg 1) and Google's and Meta's position as sub-processors in the United States (leg 2).
  2. Leg 1 (EEA → VstreamX).
    • Covered by Decision 2002/2/EC, because PIPEDA applies to VstreamX.
    • Canadian public-authority access is subject to the Canadian Charter of Rights and Freedoms and judicial oversight, which the Commission's 2024 review of the existing adequacy decisions confirmed.
  3. Leg 2 (sub-processors in the United States).
    • Where. Every sub-processor location is named in MDPA Schedule 3. AI requests are processed in the named Google Cloud region, not through a global endpoint, so no unassessed country receives Clinic Data. [[BLOCKING TO CONFIRM: regional endpoint live before publication]]
    • The laws assessed. FISA Section 702 and Executive Order 12333. Google LLC is an "electronic communication service provider" within the meaning of FISA Section 702.
    • The safeguards that apply. Executive Order 14086 (necessity and proportionality, and redress before the Data Protection Review Court), on which the Commission based Decision (EU) 2023/1795.
    • The providers. Google LLC and Meta Platforms, Inc. are certified under the EU-U.S. Data Privacy Framework, with a dated record kept. Their data processing terms also contain the SCCs (Module Three) as a second layer.
    • The litigation. Further litigation on the Data Privacy Framework is possible before the Court of Justice. If the framework falls, the sub-processors' SCCs remain as the basis, and this assessment applies to them as written.
  4. Supplementary measures (documented, not subjective).
    • TLS in transit, and field encryption of the identifying and health-history fields, consents and prescriptions.
    • Strict access control, purpose limitation, no use for own purposes, and the challenge-and-notify commitments in MDPA clause 16.
    • The field-encryption key is held within Google Cloud (MDPA Schedule 2, A.4). The encryption is therefore not relied on against access compelled from Google. VstreamX is assessing Cloud External Key Manager with keys held outside Google's control, which would let the encryption count as a supplementary measure against such access. [[TO CONFIRM: owner's decision on external key custody]]
    • In line with EDPB Recommendations 01/2020, the assessment does not rely on the subjective likelihood that public authorities would seek dental-practice records. It relies on the legal safeguards above and on the documented measures in MDPA Schedule 2.
  5. Conclusion.
    • The transfers can proceed with the measures stated.
    • VstreamX reviews this assessment at least yearly, and on any material legal change.

[[TO CONFIRM: the full TIA document, dated and signed off by counsel, from which this summary is drawn]]


Items to confirm before publication (TM-EEA)

  1. Publication date.
  2. The official EUR-Lex text of Module Two to be embedded from the official source file (Part 1.4).
  3. Release date of mandatory MFA for EEA tenants (Part 1.8(a)).
  4. Dedicated privacy address and DPO contact for Annex I.A.
  5. Name and address of the EU Article 27 representative (Annex I.A).
  6. Each sub-processor's privacy contact address (Annex III).
  7. The full TIA document, dated and signed off (Appendix A).
  8. Incorporation of Decision 2021/914 and of the Canada adequacy decision into the EEA Agreement for Iceland, Liechtenstein and Norway, and EEA incorporation of the EU-U.S. Data Privacy Framework decision (Parts 1.2 and 1.6).
  9. Blocking: the Vertex AI regional endpoint and the Google Workspace sending account live, and every sub-processor location named (Annex III; Appendix A).
  10. The owner's decision on external key custody (Cloud EKM) (Appendix A).