انتقل إلى المحتوى

الامتثال للائحة العامة

How Udentis protects the personal data of patients and staff in compliance with GDPR.

Lawful basis for processing

Udentis processes data only on a lawful basis: contract performance, legal obligation, or legitimate interest. Patient health data is processed solely on the instruction of the clinic acting as data controller.

Data minimisation

We collect only the data necessary for the platform to function. Input fields are scoped to clinically relevant information.

Data subject rights

The platform supports GDPR data subject rights: access, rectification, erasure, restriction and portability. The clinic can fulfil any request directly from the interface.

Data Processing Agreement (DPA)

Every customer signs a DPA confirming the controller/processor roles. The DPA sets out purposes, instructions, security measures, and breach procedures.

Data residency

All data is stored and processed on servers within the European Union. No transfers outside the EEA without explicit consent.

Breach notification

In the event of a security breach, we notify affected clinics within 72 hours as required by GDPR, with full details of the nature and scope of the breach.

Need our DPA or additional documentation?

Email us and we will send the full security documentation pack within 24 hours.

[email protected]