Data Processing Addendum
Last updated: July 20, 2026
Version: 2026-07-20
1. Scope and status
This Data Processing Addendum ("DPA") forms part of the Terms of Service between SimplyRoots Limited trading as SmadiDesk and each subscribing dental practice that uses our service.
It applies whenever a customer uses SmadiDesk to process personal data for receptionist, caller-management, appointment, or related operational workflows. If there is a conflict between this DPA and the Terms on data protection matters, this DPA takes precedence for those matters.
2. Roles of the parties
The subscribing dental practice is the data controller for customer, patient, caller, and staff personal data submitted to or collected through the service.
SimplyRoots Limited acts as the data processor and will process personal data only on documented customer instructions, including the customer's configuration of the service and any support or integration requests the customer authorises.
3. Details of processing
- Subject matter: AI voice receptionist services, lead capture, appointment handling, analytics, and connected practice workflows.
- Duration: For the duration of the customer relationship, plus any limited retention period required for security, audit, billing, or legal compliance.
- Nature of processing: Collection, use, storage, organisation, transmission, retrieval, and deletion of relevant service data.
- Purpose: Delivering AI receptionist functionality, supporting customer operations, detecting urgent call scenarios, maintaining the platform, and fulfilling billing, security, and support obligations.
- Data subjects: Practice users and staff, patients, prospective patients, callers, and other contacts whose data is submitted through the service.
- Categories of personal data: Names, contact details, phone numbers, recordings, transcriptions, appointment requests, call metadata, integration records, and billing contact information.
4. Processor obligations
- Process personal data only on documented instructions from the customer, unless required otherwise by applicable law
- Ensure personnel with access to personal data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures
- Assist the customer, taking into account the nature of the processing, with data subject requests, DPIAs, and regulator enquiries where reasonably required
- Notify the customer without undue delay after becoming aware of a confirmed personal data breach affecting customer personal data
5. Customer obligations
- Ensure there is a lawful basis for the collection and use of personal data through SmadiDesk
- Provide appropriate privacy information to callers and patients, including notice that calls may be recorded or handled by AI
- Avoid sending unlawful instructions or using the service for purposes outside legitimate practice operations
- Remain responsible for the accuracy, quality, and legality of the data and instructions provided to us
6. Security measures
We maintain a security programme designed to protect personal data against unauthorised access, loss, alteration, or disclosure. Current measures include encryption in transit, encryption at rest where supported by our infrastructure, access controls, environment segregation, logging and monitoring, and least-privilege access to production systems.
We review and improve these controls over time based on the sensitivity of the data we process, the risks presented, and the maturity of the platform.
7. Subprocessors
We may use carefully selected subprocessors to support delivery of the service. Our current public subprocessor set includes:
- Supabase for application data storage and authentication
- Retell AI, Deepgram, OpenAI, and ElevenLabs for voice and AI services
- Twilio for telephony services
- Stripe for billing services
- Dentally where the customer enables practice management sync
- Resend for transactional email services
- Vercel for application hosting
We require subprocessors to protect personal data through written agreements and appropriate security obligations. Our Privacy Policy provides the corresponding public processor summary.
8. International transfers
Where personal data is transferred outside the UK, we will ensure appropriate safeguards are in place, such as adequacy regulations, approved contractual clauses, or other lawful transfer mechanisms.
9. Deletion and return
"Customer Personal Data" means personal data that we process on the customer's behalf as processor.
At the end of the processing services, at the customer's choice and on its documented instructions, we will delete or return Customer Personal Data and delete existing copies unless applicable law requires storage. Data retained because applicable law requires storage will remain protected and restricted to that required purpose and will be deleted when the obligation ends.
This section does not govern separate personal data that we process as an independent controller for our own billing, security, or legal-compliance purposes; that data is handled under our Privacy Policy and applicable law.
10. Audit and information rights
We will make available information reasonably necessary to demonstrate compliance with this DPA. Where a customer has a legitimate and proportionate need for further assurance, we will work in good faith on a reasonable information request or compliance review process that protects the confidentiality and security of other customers and our systems.
11. Contact
If you need a signed copy of this DPA, have procurement questions, or need to discuss data protection terms for your practice, please contact us at [email protected].
SimplyRoots Limited, registered in England and Wales (company no. 10404398). Registered office: 14 Hill Top, London, NW11 6EE.
Existing customers can also request and track signed DPA copies from the dashboard DPA tab once they're signed in.
