EU Data Protection Governance
GDPR Compliance
Effective Date: May 15, 2026. This page outlines how DentistExpand implements GDPR-aligned controls across platform and data operations.
1. GDPR Scope and Commitment
DentistExpand applies GDPR-aligned governance for relevant processing activities involving personal data linked to EU/EEA individuals.
This page summarizes our operational approach to lawful processing, rights handling, and accountability controls for business data workflows.
2. Roles and Responsibilities
Depending on context, DentistExpand may operate as a controller for core account and website operations, and as a processor/service provider for selected customer-configured workflows.
Role allocation is determined by processing purpose, operational control, and contract terms.
3. Lawful Bases for Processing
Where GDPR applies, processing is mapped to recognized lawful bases such as legitimate interests, contractual necessity, and legal obligations.
Lawful basis evaluation is documented at workflow level and reviewed when product capabilities or processing purposes materially change.
4. Data Categories and Minimization
We process only categories relevant to service delivery, including account information, billing records, support interactions, and professional business-contact attributes in eligible data products.
Data minimization principles are applied through schema design, field review, and retention controls.
5. Purpose Limitation
Processing is limited to defined business purposes such as order fulfillment, platform operations, customer support, security controls, and service improvement.
Use outside these defined purposes requires a governance review and appropriate legal basis.
6. Data Subject Rights Operations
We maintain procedures for handling access, correction, deletion, restriction, objection, and portability requests where applicable.
Requests are logged, validated, routed, and resolved within statutory timelines, subject to legal exceptions and verification requirements.
7. Suppression and Objection Controls
Where objections or opt-out requests are received, suppression controls are applied to prevent future use in relevant workflows.
Suppression records are retained only as needed to honor rights requests and ensure continued compliance.
8. Security and Confidentiality Measures
We use layered technical and organizational controls, including access governance, encrypted transport, environment-level monitoring, and least-privilege enforcement.
Security controls are reviewed periodically and updated based on risk posture, vendor changes, and operational requirements.
9. International Data Transfers
Where cross-border processing occurs, we apply transfer safeguards appropriate to applicable legal frameworks and vendor arrangements.
Transfer risk considerations are included in vendor onboarding and periodic compliance reviews.
10. Retention and Deletion Governance
Retention is governed by purpose, legal requirements, contractual obligations, and security needs. Records are deleted or de-identified when no longer required.
Retention schedules are maintained by data category and reviewed for proportionality.
11. Vendor and Subprocessor Oversight
Service providers are selected under security and privacy due diligence standards and are expected to operate under contractual data-protection obligations.
Subprocessor scope is limited to operational necessity and monitored through governance controls.
12. Incident Readiness and Response
We maintain documented incident response workflows covering detection, triage, containment, remediation, and post-incident review.
Where legally required, relevant stakeholders and authorities are notified in line with applicable breach reporting obligations.
13. Contact for GDPR Requests
For GDPR-related rights requests or governance inquiries, contact us via our Contact Us page and include the subject line: GDPR Request.