Legal document

Data Processing Agreement (DPA)

The terms under which Desklly processes personal data on behalf of dental practices, satisfying Article 28 UK GDPR.

Version 1.0Last updated 7 July 2026Governing law England & Wales

1. Roles

The practice is the Controller. Desklly is the Processor. Where Desklly engages sub-processors, they act as sub-processors of Desklly.

2. Subject-matter and duration

Subject-matter: provision of the Desklly AI receptionist service. Duration: for the term of the service agreement and any wind-down period defined below.

3. Nature and purpose of processing

Answering inbound and making outbound calls; booking, rescheduling, and cancelling appointments; sending SMS and email confirmations; taking messages; producing call transcripts and analytics; supporting the practice in patient communications.

4. Types of personal data

Identity data, contact data, appointment data, communications data (call audio, transcripts, SMS/email content), and, where volunteered by the patient, health-related information.

5. Categories of data subject

Patients (including prospective patients), practice staff, and any third parties whose data is captured in the course of a call.

6. Processor obligations

Desklly shall: (a) process personal data only on documented instructions from the Controller; (b) ensure personnel are bound by confidentiality; (c) implement the technical and organisational measures set out in the Information Security Policy; (d) assist the Controller with data subject requests, DPIAs, and consultations with supervisory authorities; (e) notify the Controller of a personal data breach without undue delay and in any event within 24 hours of becoming aware; (f) delete or return all personal data at the end of the service, at the Controller's choice; and (g) make available all information necessary to demonstrate compliance and allow for audits, once per year on reasonable notice.

7. Sub-processors

The Controller provides general written authorisation for Desklly to use the sub-processors listed in the Sub-processor List. Desklly will give the Controller at least 30 days' notice of any intended addition or replacement, and the Controller may object on reasonable data protection grounds.

8. International transfers

Any transfer of personal data outside the UK will be governed by the UK International Data Transfer Agreement, the EU Standard Contractual Clauses with the UK Addendum, or an adequacy decision.

9. Liability and indemnity

Liability under this DPA is subject to the limitations of liability in the main service agreement, save to the extent liability cannot be limited under the UK GDPR or the Data Protection Act 2018.

10. Governing law

This DPA is governed by the laws of England and Wales.