This Data Processing Agreement ("DPA") governs the processing of personal data by LeafletPlan (the "Processor") on behalf of the dental practice (the "Controller") when the practice uses LeafletPlan to prepare and send patient information leaflets. It forms part of, and is subject to, the LeafletPlan Terms of Service.
Subject matter and duration. The Processor processes personal data for the duration of the practice's use of the beta. The data subjects are the practice's patients (including, where paediatric leaflets are sent, children, whose leaflets are addressed to a parent or guardian). The personal data are the patient's name and email address, used only to deliver a leaflet, and the clinical content the clinician selects, which is data concerning health (a special category of data).
Processing on instructions. The Processor processes personal data only on the Controller's documented instructions, including as to any transfer of data outside the UK, and will tell the Controller if it considers an instruction to be unlawful. The service is used solely to render and deliver the leaflets the practice sends. There is no secondary use: no profiling, no analytics on patients, no marketing, no sale of data, and no use of patient data to train AI.
What is and is not stored. The patient's name and email address are held in memory only, to deliver the leaflet, and are not written to the LeafletPlan database. LeafletPlan stores only the rendered leaflet, keyed by a one-way hash of its share link; it holds no patient name, email, or other identifier, and so cannot by itself identify a patient. The identity-linked record of what was sent is the "LEAFLET SENT" summary the clinician saves into the practice's own clinical notes. The Processor does not keep it.
Security. Personal data is protected by TLS in transit and by infrastructure-level encryption at rest. Each practice's data is isolated at the database level, so one practice cannot access another's. Access to production is restricted and logged, and the pseudonymised design means that a compromise of the LeafletPlan database alone would not identify any patient.
Confidentiality. People authorised to process the personal data are bound by an appropriate duty of confidentiality.
Sub-processors. The Processor engages vetted sub-processors strictly to operate the service. Currently these are Mailgun (transactional email delivery), Fly.io (application hosting and database), and Cloudinary (hosting of practice logos and library documents), each under data-protection terms equivalent to this DPA. The Processor keeps a current list of its sub-processors and their processing regions, and gives the Controller advance notice of any change so the Controller can object.
Assisting with individuals' rights. Taking account of the nature of the processing, the Processor assists the Controller in responding to requests from individuals to exercise their rights. Because LeafletPlan cannot identify a patient in its own data, a request is met through the share link held in the practice's clinical notes: with the link, the leaflet that was sent can be viewed. The Processor will delete an individual leaflet on the Controller's request; all data is deleted when the beta ends.
Breaches and impact assessments. The Processor notifies the Controller without undue delay after becoming aware of a personal data breach, and assists the Controller with its obligations on security, breach notification, and data protection impact assessments.
Return and deletion. When the beta ends, the Processor deletes the personal data it holds. The practice's own record of what was sent, the summary saved into its clinical notes, is unaffected and remains subject to the practice's clinical-records retention.
Audit. The Processor makes available to the Controller the information necessary to demonstrate compliance with these obligations, and allows for and contributes to audits.