01The short version
You are the controller of your patient’s data. We are your processor. We use what you send us
only to plan and manufacture the case you asked for, we keep it inside the EU, we do not use it
for anything else, and we delete it when you tell us to.
You do not need to send us your patient’s name. A case reference is enough for us to work.
02Why the roles matter
A CBCT volume is health data — a special category of personal data under Article 9 of the
GDPR, protected more strictly than ordinary personal data. When you send us one, the law needs to
know who decides what happens to it.
You do. You are the treating clinician; you determined that the scan was
necessary, you hold the therapeutic relationship, and you are the controller. We only ever act on
your documented instructions, which makes us a processor within the meaning of Article 28.
Practically, that means three things: you are responsible for having a lawful basis for the
imaging in the first place; you are responsible for telling your patient that a dental laboratory
will process their data as part of the treatment; and if your patient exercises a right, they
exercise it against you, not against us — though we will help you answer.
03What you should do before you upload
- Make sure your own patient information covers it. Your practice privacy
notice should say that imaging and model data may be shared with a dental laboratory or planning
service for the purpose of designing a surgical template. Most already do; check the wording
mentions laboratories. - Pseudonymise where you can. Replace the patient name with your own case
reference. DICOM headers routinely carry the full name, date of birth and sometimes the national
health number — if your software can anonymise on export, use it. We will work perfectly
well from a reference alone. - Send only what the case needs. A full jaw volume, the models, the bite and
the relevant photographs. Not the whole patient record. - Ask us for the processing agreement if your practice needs one on file. See
section 10.
If you do send identifying details, that is not a problem — we handle them under the
same terms. It is simply more data than we need.
04What we do with it
Strictly and only the following, because these are the instructions the order gives us:
- segment the volume and register it against your surface scans;
- produce a prosthetically driven implant or osteotomy plan;
- publish that plan to you for review and written approval;
- design and manufacture the template, and the associated protocol sheet;
- retain the manufacturing record we are legally required to keep as the maker of a
custom-made device.
We do not use case data to train software, we do not use it for marketing, and we do not
publish images from a case — not anonymised, not in a lecture, not on this website —
unless you have given us written permission and confirmed your patient consented.
05Where it physically goes
- Our own server, or our own business cloud storage. Uploads land either in a
directory on our server that is not served to the web, or in our own Microsoft 365 tenant
(OneDrive for Business), which is contracted to the European Union and covered by Microsoft’s
data protection addendum and the EU Data Boundary. Which of the two is used depends on the size
of the case. In both places the files sit in a location that cannot be reached by guessing a URL,
and only named members of our team can open them. - Not a consumer file-sharing account. We do not route case files through
personal Dropbox, consumer OneDrive, consumer Google Drive or WeTransfer accounts, and we ask you
not to either. A business tenant governed by a processor contract and a personal cloud account are
not the same thing in law, whatever they look like on screen. - The planning platform for that case — SMOP (Switzerland), R2GATE
(Republic of Korea), coDiagnostix or 3Shape (Denmark). Both Switzerland and the Republic of Korea
are covered by European Commission adequacy decisions, so the transfer is treated in law like a
transfer inside the EU. - Nowhere else. The manufacture is done in-house.
06Sub-processors
The parties below may process case data on our behalf. We will tell you before we add a new
one, so that you can object if your own arrangements require it.
| Who | What for | Where |
|---|---|---|
| Swissmeda AG (SMOP) | Planning and online case review | Switzerland — adequacy decision |
| MegaGen (R2GATE) | Planning | Republic of Korea — adequacy decision |
| Dental Wings / Straumann (coDiagnostix) | Planning and guide design | EU / Switzerland |
| 3Shape | Planning and guide design | Denmark — EU |
| Our hosting provider | Storage of uploaded case files | European Union |
| Microsoft Ireland Operations Ltd | Storage of uploaded case files in our Microsoft 365 tenant (OneDrive for Business) | EU — EU Data Boundary |
07Security measures
- Transfers to the upload endpoint are encrypted in transit (TLS).
- Files are written to storage outside the public web root, with a randomised case directory
name, so no file is reachable by guessing a URL. - Only permitted file types are accepted, and each upload is size-checked chunk by chunk.
- Access is limited to the named members of the team who work on cases.
- Case data is not copied to personal devices or consumer cloud storage.
08How long we keep case data
- Raw uploaded imaging and models — kept while the case is active and for
12 months after delivery, so that a revision, a remake or a query can be answered without asking
you to re-send several gigabytes. Deleted after that. - The plan and the manufacturing record — the design file, the approved
plan and the device record are kept for at least ten years after the template was supplied,
because Regulation (EU) 2017/745 requires the manufacturer of a custom-made device to retain that
documentation. - Earlier, on request. As controller you can instruct us to delete case data at
any point, and we will, except where the device record above must legally be retained. Ask and we
will confirm in writing what was deleted and what was kept.
09If something goes wrong
If we become aware of a breach affecting your case data, we will notify you without undue
delay and give you what you need to make your own assessment — what was affected, when, how
many patients, and what we have done. We notify you, because as controller the 72-hour
duty to notify the supervisory authority is yours, not ours.
10The processing agreement
Article 28 of the GDPR requires the controller–processor relationship to rest on a written
contract. Many clinics in Germany and the Netherlands in particular will want one on file before
sending a first case, and their practice auditors will ask for it.
We have one ready. Ask at info@digitalguides.eu and
we will send it for signature — it takes a day, not a month, and it does not need to be
negotiated before you send us a test case, because this page already describes the terms it
contains.
drafted to be reviewed by your legal adviser rather than to replace one.