§LEGALGoverning document

Data Processing Addendum

No-PHI / Prohibited Health Data Version

Effective
August 9, 2026
Updated
August 9, 2026
In this document

This Data Processing Addendum ("DPA") forms part of the agreement between CompliDent, LLC, doing business as CompliDent ("CompliDent," "Processor," "Service Provider," or "Contractor," as applicable), and the customer identified in the applicable Terms of Service, order form, subscription, or other agreement ("Customer" or "Controller," as applicable) governing Customer's use of the CompliDent Services (the "Agreement").

This DPA applies only to the extent CompliDent processes Customer Personal Data on behalf of Customer in connection with the Services and applicable Data Protection Laws require or recognize a controller-processor, business-service provider, business-contractor, or substantially similar contractual relationship.

IMPORTANT - NO PHI OR OTHER PROHIBITED HEALTH DATA. The standard Services are not designed or offered to create, receive, maintain, store, or transmit Protected Health Information ("PHI") or other Prohibited Health Data. Prohibited Health Data is outside the scope of permitted Customer Personal Data and is not authorized for processing under this DPA.

1. Definitions

  • “Applicable Data Protection Laws” means privacy, data-protection, and data-security laws applicable to the processing of Customer Personal Data under this DPA, which may include the Virginia Consumer Data Protection Act, the California Consumer Privacy Act as amended ("CCPA"), the EU General Data Protection Regulation ("EU GDPR"), the UK GDPR, and other applicable comprehensive privacy laws.
  • “Customer Data” has the meaning given in the Agreement and excludes CompliDent Operational Data and Prohibited Health Data.
  • “Customer Personal Data” means Personal Data contained within permitted Customer Data that CompliDent processes on behalf of Customer under this DPA. Customer Personal Data does not include CompliDent Operational Data or Prohibited Health Data.
  • “CompliDent Operational Data” means account, billing, authentication, security, telemetry, diagnostic, performance, usage, and similar data that CompliDent collects or generates to operate, secure, administer, support, analyze, and improve the Services, as described in the Agreement and Privacy Policy.
  • “Personal Data” or “Personal Information” means information relating to an identified or identifiable natural person or household, or other information defined as personal data or personal information under Applicable Data Protection Laws.
  • “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, to the extent defined as a personal-data breach or comparable event under Applicable Data Protection Laws.
  • “PHI” means Protected Health Information as defined by HIPAA and 45 C.F.R. Parts 160 and 164.
  • “Prohibited Health Data” means: (a) PHI; (b) information that identifies, is reasonably capable of being associated with, or could reasonably be linked to an individual and reveals, describes, or relates to the individual's past, present, or future physical or mental health, dental condition, diagnosis, treatment, care, prescription, procedure, health-care services, insurance, or payment for health care; (c) consumer health data, consumer health information, or substantially similar information regulated under applicable state privacy or health-data law; and (d) other identifiable patient information.
  • “Subprocessor” means a third party engaged by CompliDent to process Customer Personal Data on CompliDent's behalf in connection with the Services.

2. Scope, Roles, and Applicability

For Customer Personal Data processed solely on Customer's behalf, Customer acts as controller, business, or equivalent party, and CompliDent acts as processor, service provider, contractor, or equivalent party, as determined by Applicable Data Protection Laws and the actual processing context.

This DPA does not govern information for which CompliDent independently determines the purposes and means of processing, including CompliDent Operational Data to the extent CompliDent acts as a controller or business with respect to such data. CompliDent's independent processing is described in the Privacy Policy and Agreement.

A party's legal role is a fact-based determination under applicable law. Nothing in this DPA changes a party's legal status when applicable law assigns a different role based on the actual processing.

3. Processing Instructions and Permitted Purposes

Customer instructs CompliDent to process Customer Personal Data only as reasonably necessary to provide, configure, maintain, secure, support, and administer the Services purchased or enabled by Customer, including the specific processing activities described in Schedule 1.

Documented instructions include the Agreement, this DPA, Customer's configuration and use of the Services, written support requests, and other written instructions that are consistent with the Agreement and Applicable Data Protection Laws.

CompliDent will process Customer Personal Data only on Customer's documented instructions unless processing is required by applicable law. If legally permitted, CompliDent will notify Customer before processing required by law.

If CompliDent reasonably believes an instruction violates Applicable Data Protection Laws or would require processing prohibited by the Agreement, CompliDent may suspend the affected processing and will inform Customer, unless prohibited by law.

4. Prohibited Health Data; No HIPAA Business-Associate Processing

PHI AND OTHER PROHIBITED HEALTH DATA ARE NOT PERMITTED CUSTOMER PERSONAL DATA.

Customer must not instruct CompliDent to collect, receive, maintain, store, transmit, access, or otherwise process Prohibited Health Data. No instruction, order form, support request, integration, configuration, or provision of this DPA authorizes Prohibited Health Data.

The standard Services are not offered as a HIPAA business-associate service. CompliDent does not enter into a Business Associate Agreement ("BAA") for the standard Services, and this DPA is not a BAA.

If content is derived from PHI, Customer must de-identify it before transmission to CompliDent in accordance with 45 C.F.R. § 164.514, including the Safe Harbor or Expert Determination method, as applicable. For other Prohibited Health Data, Customer must de-identify the information as required by applicable law so that it is no longer identifiable or reasonably linkable to an individual.

If Prohibited Health Data is submitted in violation of the Agreement, it does not become authorized Customer Personal Data under this DPA. Customer must follow the removal and notification requirements in the Terms and Acceptable Use Policy. CompliDent may restrict access to, quarantine, securely return, delete, or destroy such data as provided in the Agreement and applicable law.

Nothing in this DPA limits any obligation that applicable law may impose based on information CompliDent actually receives or maintains.

5. Customer Responsibilities

Customer is responsible for:

  • ensuring that its instructions comply with Applicable Data Protection Laws and the Agreement;
  • having all rights, lawful bases, notices, authorizations, and consents required to provide Customer Personal Data to CompliDent and instruct its processing;
  • determining whether the Services and CompliDent's security measures are appropriate for Customer's intended processing;
  • ensuring that Customer and Authorized Users do not submit Prohibited Health Data or other information prohibited by the Agreement;
  • responding to data-subject or consumer requests when Customer acts as controller or business, except for assistance CompliDent is required to provide under this DPA;
  • maintaining accurate account and administrator information and implementing appropriate access controls within Customer's organization; and
  • not using the Services to process categories of sensitive data that the Services are not designed or authorized to process.

6. CompliDent Processing Obligations

When acting as Customer's processor, service provider, or contractor, CompliDent will:

  • process Customer Personal Data only in accordance with documented instructions and this DPA, except as required by law;
  • ensure personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations;
  • implement and maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of Customer Personal Data and risks of processing;
  • provide reasonable assistance with data-subject and consumer rights requests, security obligations, breach response, and legally required data-protection assessments, taking into account the nature of processing and information available to CompliDent;
  • make information reasonably necessary to demonstrate compliance with applicable processor obligations available to Customer, subject to confidentiality, security, privilege, and proportionality limitations;
  • notify Customer if CompliDent determines that it can no longer meet a material obligation imposed on it as a processor, service provider, or contractor under Applicable Data Protection Laws; and
  • take reasonable and appropriate steps to stop and remediate unauthorized processing identified by CompliDent or validly identified by Customer.

7. Security Measures

CompliDent will maintain safeguards designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, alteration, or disclosure, appropriate to the nature, volume, sensitivity, and risks of the processing.

Depending on the systems and data involved, safeguards may include:

  • logical access controls, authentication controls, and role-based permissions;
  • encryption in transit and encryption at rest where applicable to the relevant system;
  • logging, monitoring, and security-event review;
  • backup, recovery, and availability measures;
  • vulnerability management and secure configuration practices;
  • workforce confidentiality and security measures;
  • incident-response procedures; and
  • vendor and Subprocessor oversight.

Customer acknowledges that no security program can guarantee absolute security and that the Services are not approved, certified, or offered as a repository or transmission system for Prohibited Health Data.

8. Personal Data Breaches and Security Incidents

CompliDent will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data when notification to Customer is required by Applicable Data Protection Laws or this DPA.

To the extent reasonably available, the notice will describe the nature of the incident, the categories of Customer Personal Data affected, reasonably known consequences, and measures taken or proposed to address the incident. Information may be provided in phases as facts become available.

CompliDent will take reasonable steps to contain, investigate, remediate, and document the incident and will reasonably cooperate with Customer's legally required breach-response obligations, taking into account the nature of processing and information available to CompliDent.

Notification under this Section is not an admission of fault, liability, or violation of law. Incidents involving Prohibited Health Data submitted in violation of the Agreement will also be handled under the Terms, Acceptable Use Policy, and Privacy Policy.

9. Subprocessors

Customer grants CompliDent general authorization to engage Subprocessors to support the Services. CompliDent will maintain a current list of material Subprocessors or otherwise make such information available to Customer.

CompliDent will impose written data-protection obligations on each Subprocessor that are materially protective of Customer Personal Data and appropriate to the Subprocessor's services, including confidentiality, security, processing-purpose limitations, and applicable downstream processor obligations.

Where Applicable Data Protection Laws require notice of new Subprocessors, CompliDent will provide notice through its published Subprocessor List, email, in-product notice, or another reasonable mechanism. If applicable law grants Customer a right to object, Customer must raise a reasonable data-protection objection within the legally applicable or stated notice period. The parties will work in good faith to address a valid objection.

CompliDent remains responsible for its Subprocessors to the extent required by Applicable Data Protection Laws and the Agreement.

10. Data-Subject and Consumer Requests

If CompliDent receives a request from an individual concerning Customer Personal Data for which Customer is the controller or business, CompliDent may direct the individual to Customer unless Applicable Data Protection Laws require CompliDent to respond directly.

Taking into account the nature of processing, CompliDent will provide reasonable technical or organizational assistance to enable Customer to respond to applicable requests to access, know, correct, delete, restrict, object, opt out, or obtain portability of Customer Personal Data, to the extent required by law and reasonably available through the Services.

Customer is responsible for verifying requests and determining whether a request is valid, subject to Applicable Data Protection Laws.

11. Compliance Information, Assessments, and Audits

Upon reasonable request, CompliDent will provide information reasonably necessary to demonstrate compliance with applicable processor obligations under this DPA. CompliDent may satisfy this obligation through security documentation, questionnaires, independent assessment reports, certifications, summaries, or other appropriate evidence.

Where Applicable Data Protection Laws require Customer to have assessment or audit rights, Customer may conduct a reasonable assessment of CompliDent's compliance, subject to reasonable advance notice, confidentiality and security requirements, protection of other customers' information, and avoidance of unreasonable disruption.

Unless required by law, a regulator, or a material Personal Data Breach, on-site or bespoke audits will be limited to no more than once in any twelve-month period and will be at Customer's reasonable expense. CompliDent may satisfy an audit request by providing a recent independent assessment report where legally sufficient.

12. Return and Deletion

During the subscription term, Customer may access, export, correct, or delete permitted Customer Data through available Service functionality, subject to the Agreement.

Upon termination or expiration of the Services and at Customer's direction, CompliDent will delete or return Customer Personal Data as required by Applicable Data Protection Laws and the Agreement, unless retention is required by law or reasonably necessary for a legally permitted purpose.

Data remaining in backups may be retained until overwritten or securely deleted through ordinary backup cycles, provided it remains protected and is not used for unrelated purposes.

Prohibited Health Data is not subject to a Customer export or retention right and will be addressed under the Terms and Acceptable Use Policy.

If CompliDent receives a legally binding request from a governmental or law-enforcement authority for Customer Personal Data, CompliDent may disclose information as required by law. Where legally permitted and reasonably practicable, CompliDent will notify Customer before disclosure and may seek to narrow or challenge overbroad or unlawful requests.

14. California Service Provider and Contractor Terms

This Section applies only to processing subject to the CCPA for which Customer is a 'business' and CompliDent acts as a 'service provider' or 'contractor' as those terms are defined by the CCPA.

For such processing, CompliDent agrees that:

  • Customer discloses Customer Personal Data to CompliDent only for the limited and specific business purposes identified in Schedule 1;
  • CompliDent will not sell or share Customer Personal Data received pursuant to this DPA;
  • CompliDent will not retain, use, or disclose Customer Personal Data for purposes other than the limited and specific business purposes identified in this DPA or as otherwise permitted by the CCPA;
  • CompliDent will not retain, use, or disclose Customer Personal Data for a commercial purpose outside the direct business relationship with Customer except as expressly permitted by the CCPA;
  • CompliDent will not combine Customer Personal Data received from Customer with Personal Information received from another person or collected through CompliDent's own interaction with a consumer except as permitted by the CCPA;
  • CompliDent will comply with applicable CCPA obligations and provide the level of privacy protection required of service providers and contractors for Customer Personal Data;
  • Customer may take reasonable and appropriate steps to help ensure CompliDent uses Customer Personal Data consistently with Customer's CCPA obligations, including reasonable compliance inquiries and assessments as described in Section 11;
  • CompliDent will notify Customer if it determines it can no longer meet applicable CCPA obligations, and Customer may take reasonable and appropriate steps to stop and remediate unauthorized use;
  • CompliDent will provide reasonable assistance necessary for Customer to respond to applicable consumer requests as described in Section 10; and
  • any Subprocessor processing CCPA-covered Customer Personal Data will be subject to a written contract imposing applicable downstream restrictions.

CompliDent certifies that it understands and will comply with the restrictions applicable to it as a service provider or contractor under the CCPA when this Section applies.

15. Virginia Controller-Processor Terms

This Section applies to processing subject to the Virginia Consumer Data Protection Act for which Customer acts as controller and CompliDent acts as processor.

The processing instructions, nature and purpose, categories of Personal Data and data subjects, duration, and parties' rights and obligations are set out in this DPA and Schedule 1.

For such processing, CompliDent will:

  • adhere to Customer's instructions;
  • ensure persons processing Customer Personal Data are subject to confidentiality obligations;
  • at Customer's direction, delete or return Customer Personal Data at the end of the Services unless retention is required by law;
  • upon reasonable request, make available information necessary to demonstrate compliance with applicable Virginia processor obligations;
  • allow and cooperate with reasonable assessments, or provide an appropriate independent assessment report, as permitted by Virginia law;
  • engage Subprocessors under written contracts imposing applicable processor obligations;
  • provide reasonably practicable assistance with consumer-rights requests, security obligations, breach notification, and data-protection assessments, taking into account the nature of processing and information available to CompliDent.

16. Other U.S. State Privacy Laws

If another U.S. state comprehensive privacy law applies to Customer Personal Data and requires contractual terms between a controller and processor, business and service provider, or substantially similar parties, this DPA will be interpreted to include the mandatory terms required by that law to the extent applicable. The parties will cooperate in good faith to execute reasonable amendments required by a change in applicable law.

17. International Data Transfers

Customer acknowledges that Customer Personal Data may be processed in the United States and other jurisdictions where CompliDent or its Subprocessors operate, as described in the Privacy Policy.

If Applicable Data Protection Laws require a specific transfer mechanism for Customer Personal Data transferred from the EEA, United Kingdom, Switzerland, or another jurisdiction, the parties will use an applicable lawful transfer mechanism, which may include an adequacy decision, approved standard contractual clauses, a UK addendum, or another legally recognized safeguard.

This DPA does not by itself modify or replace the text of any mandatory standard contractual clauses. Where such clauses are legally required, the applicable clauses and completed annexes may be executed or incorporated through a separate transfer addendum, order form, or other legally effective mechanism.

18. De-identified, Aggregated, and Operational Data

This DPA does not restrict CompliDent's use of information that has been lawfully aggregated or de-identified so that it cannot reasonably be linked to an identified or identifiable individual, subject to Applicable Data Protection Laws and contractual restrictions.

CompliDent Operational Data is outside the scope of processor obligations under this DPA to the extent CompliDent independently determines its purposes and means of processing. CompliDent will not use identifiable Customer Personal Data for unrelated advertising or marketing and will use identifiable Customer Personal Data for product improvement only as permitted by the Agreement, Privacy Policy, and Customer's documented instructions.

19. Artificial Intelligence and Automated Processing

Unless an applicable Service feature, order form, or written agreement expressly states otherwise, CompliDent will not use identifiable Customer Personal Data to train a general-purpose artificial-intelligence or machine-learning model for unrelated purposes.

If CompliDent introduces a feature that materially changes how Customer Personal Data is used for artificial intelligence, automated decision-making, or model training, CompliDent will provide any notice, contractual terms, instructions, or choices required by Applicable Data Protection Laws before such processing.

20. Order of Precedence

If this DPA conflicts with the Agreement regarding processing of Customer Personal Data, this DPA controls solely with respect to the conflicting data-processing obligation. The Agreement otherwise remains in effect.

No-PHI precedence. Nothing in this DPA, including any international-transfer provision, authorizes submission or processing of Prohibited Health Data. The No-PHI restrictions in the Terms and Acceptable Use Policy remain fully effective unless CompliDent expressly agrees in a separate written agreement signed by an authorized representative that specifically authorizes different processing. The standard Services do not include such authorization or a BAA.

21. Liability

The limitations of liability, exclusions, indemnification provisions, and remedies in the Agreement apply to this DPA to the maximum extent permitted by Applicable Data Protection Laws. Nothing in this Section limits liability that cannot lawfully be limited.

22. Term and Changes

This DPA becomes effective when the Agreement becomes effective or when CompliDent first processes Customer Personal Data subject to this DPA, whichever is later, and remains in effect for as long as CompliDent processes Customer Personal Data on Customer's behalf.

CompliDent may update this DPA when reasonably necessary to reflect changes in Applicable Data Protection Laws, the Services, or processing practices. Material changes will be handled in accordance with the Agreement and applicable law.

23. Governing Law

Unless Applicable Data Protection Laws require otherwise, the governing-law and venue provisions of the Agreement apply to this DPA.

SCHEDULE 1 - DETAILS OF PROCESSING

A. Subject Matter and Duration

Processing of Customer Personal Data as necessary to provide, configure, host, maintain, secure, support, and administer the CompliDent Services for the duration of the Agreement and any legally or contractually permitted post-termination retention period.

B. Nature and Purpose of Processing

  • hosting and storing permitted compliance-management records and content;
  • providing account, organization, role, permission, task, assessment, policy, training, vendor, evidence, audit, reporting, and dashboard functionality;
  • authenticating users and administering Customer-controlled access;
  • providing support and troubleshooting at Customer's request;
  • maintaining backups, resilience, logging, security monitoring, and fraud/abuse prevention;
  • performing Customer-requested exports, corrections, deletion, and other Service functions; and
  • other processing specifically documented in the applicable order form, Service configuration, or written Customer instruction consistent with the Agreement.

C. Categories of Customer Personal Data

  • business contact information, such as names, business email addresses, telephone numbers, job titles, and organization affiliations;
  • Customer workforce and organizational information, such as employee or contractor names, roles, permissions, training completion records, and assignments;
  • vendor and business-contact information submitted for compliance-management purposes;
  • permitted compliance records, assessments, task data, policies, notes, evidence, audit trails, and documents that may contain business-related Personal Data;
  • account-related identifiers and other Personal Data included in permitted Customer Data; and
  • other Personal Data expressly supported by the Services and lawfully submitted under the Agreement.

Excluded categories: Customer Personal Data does not include Prohibited Health Data, including PHI, identifiable patient information, or consumer health data. Customer must not submit those categories.

D. Categories of Data Subjects

  • Customer employees, contractors, administrators, owners, and Authorized Users;
  • representatives and personnel of Customer's vendors, service providers, and business partners;
  • other business contacts whose Personal Data Customer lawfully submits for permitted compliance-management purposes.

Excluded data subjects: Patients and consumers are not intended data subjects of Customer Personal Data in the Services. Customer must not submit identifiable patient or consumer health information.

E. Sensitive Data

The Services are not intended for Customer to submit sensitive categories of Personal Data unless expressly supported and permitted by the Agreement. Prohibited Health Data is always excluded from standard permitted processing. Customer should minimize other sensitive data and submit it only when reasonably necessary and legally authorized.

F. Frequency of Processing

Continuous or intermittent during Customer's use of the Services, depending on Customer activity and enabled features.

G. Customer Instructions

The Agreement, this DPA, Customer's configuration and use of the Services, applicable order forms, documented support requests, and other written instructions consistent with the Agreement.

SCHEDULE 2 - SECURITY FRAMEWORK

CompliDent will maintain a security program appropriate to the nature of permitted Customer Personal Data and the risks of processing. The measures below describe categories of controls and do not represent that every control applies identically to every system.

  • Access management. Role-based access, authentication controls, account administration, and restriction of privileged access as appropriate.
  • Data protection. Encryption in transit and encryption at rest where applicable to the relevant infrastructure and service component.
  • Logging and monitoring. Logging and monitoring designed to support security, troubleshooting, abuse prevention, and incident investigation.
  • Secure operations. Reasonable vulnerability-management, patching, configuration, change-management, backup, and recovery practices appropriate to the Services.
  • Workforce measures. Confidentiality obligations and security practices for personnel with authorized access.
  • Vendor management. Reasonable diligence and contractual protections for Subprocessors that process Customer Personal Data.
  • Incident response. Processes for identifying, containing, investigating, remediating, documenting, and notifying regarding security incidents as required by law and contract.
  • Data minimization. Processing limited to permitted Customer Personal Data and the purposes described in this DPA; Prohibited Health Data is not within the authorized processing scope.

EXECUTION

This DPA is incorporated into the Agreement and does not require a separate signature when the Agreement provides for incorporation of CompliDent's DPA. If the parties execute this DPA separately, the signatures below confirm acceptance.

CUSTOMERCOMPLIDENT, LLC
By: ______________________________By: ______________________________
Name: ____________________________Name: ____________________________
Title: _____________________________Title: _____________________________
Date: ______________________________Date: ______________________________

Contact for DPA Matters

CompliDent, LLC

Attn: Privacy / Legal

Email: getcomplident@gmail.com

Website: https://www.getcomplident.com

For suspected Prohibited Health Data, use the subject line "Prohibited Health Data Removal Request" and do not include PHI, patient-identifying information, or other Prohibited Health Data in the message.