Data Processing Agreement
1. Scope and Purpose
This Data Processing Agreement ("DPA") supplements the Provider Service Agreement and applies where FinVerified, Inc. ("Processor") processes personal data on behalf of a dental practice, DSO, or other organisation ("Controller") in connection with the FinVerified Platform. This DPA reflects the parties' agreement with regard to the processing of personal data in accordance with applicable data protection law, including where relevant the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).
2. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person processed by FinVerified under the Provider Service Agreement. "Processing" has the meaning given in applicable data protection law. "Sub-processor" means any third party engaged by FinVerified to process Personal Data.
3. Processing Instructions
FinVerified shall process Personal Data only on documented instructions from the Controller, including as set out in the Provider Service Agreement, unless required to do so by applicable law. FinVerified shall promptly inform the Controller if, in its opinion, an instruction infringes applicable data protection law.
4. Technical and Organisational Measures
FinVerified shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of Personal Data in transit (TLS 1.3) and at rest (AES-256 / AWS KMS)
- Pseudonymisation of patient-level identifiers
- Role-based access controls and least-privilege principles
- Regular penetration testing and vulnerability assessments
- SOC 2 Type II certification (in progress)
5. Sub-processors
The Controller authorises FinVerified to engage sub-processors to assist in providing the Platform. FinVerified shall enter into a written agreement with each sub-processor imposing data protection obligations no less stringent than those in this DPA. FinVerified shall inform the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object. Current sub-processors include AWS (infrastructure), Anthropic (AI services), and Zoho (CRM/support).
6. Data Subject Rights
FinVerified shall assist the Controller in fulfilling its obligations to respond to data subject requests for access, rectification, erasure, restriction, portability, and objection, taking into account the nature of the processing and the information available to FinVerified.
7. Data Breach Notification
FinVerified shall notify the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data breach. Notification shall include the nature of the breach, the categories and approximate number of data subjects concerned, and the measures taken or proposed to address the breach.
8. International Transfers
FinVerified stores and processes Personal Data in the United States. Where the Controller is subject to GDPR or UK GDPR and transfers Personal Data to FinVerified, such transfers are made under the EU Standard Contractual Clauses (Module 2: Controller to Processor), incorporated herein by reference.
9. Deletion and Return
Upon termination of the Provider Service Agreement, FinVerified shall, at the Controller's election, delete or return all Personal Data and certify deletion in writing, unless applicable law requires storage of the Personal Data.
10. Contact
FinVerified Data Protection Contact