Behery Dental DENTAL WORKFLOW PLATFORM
Platform Principles FAQ Private by design
This legal document is available in English only for now.
Private access
Legal

Data Processing Agreement

Last updated: August 22, 2026 · Behery Dental (“the Platform”, “we”, “us”, “our”)
1. Definitions 2. Roles of the Parties 3. Purpose of Processing 4. Categories of Data 5. Sub-processors 6. International Transfers 7. Security Measures 8. Client Responsibilities 9. Processor Responsibilities 10. Breach Notification 11. Retention & Deletion 12. Compliance Assistance 13. Audits 14. Governing Law 15. Term 16. Online Acceptance 17. HIPAA & BAA 18. Contact
⚠

For Clients (Controllers). This DPA governs how Behery Dental processes Personal Data on your behalf. It works alongside our Terms of Service and Privacy Policy. Fields marked [TO BE DETERMINED] are placeholders pending completion.

1Definitions

“Personal Data” — Any information relating to an identified or identifiable individual, including patient data uploaded by the Client.

“Processing” — Any operation performed on Personal Data (storage, access, transmission, deletion, etc.).

“Controller” — The entity that determines the purpose and means of processing Personal Data (you).

“Processor” — The entity that processes Personal Data on behalf of the Controller (Behery Dental).

“Sub-processor” — A third party engaged by Behery Dental to assist with processing.

“Applicable Data Protection Laws” includes:

  • EU GDPR
  • UK GDPR
  • CCPA/CPRA
  • PIPEDA
  • HIPAA (where applicable)
  • APAC privacy frameworks
  • U.S. federal and state privacy law
  • Saudi Arabia's Personal Data Protection Law and Implementing Regulations
  • UAE Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data, and Federal Law No. 2 of 2019 for health data processed in connection with UAE health services (including, where applicable, DIFC and ADGM data protection regimes)
  • Egypt's Personal Data Protection Law No. 151 of 2020
  • Qatar Law No. 13 of 2016 Concerning Personal Data Privacy Protection (and QFC Data Protection Regulations and Rules, where applicable)
  • Bahrain Law No. 30 of 2018 with Respect to Personal Data Protection
  • Oman's Personal Data Protection Law (Royal Decree No. 6 of 2022)
  • Jordan's Personal Data Protection Law No. 24 of 2023
  • Morocco Law No. 09-08 concerning the protection of individuals with regard to the processing of personal data
  • Algeria Law No. 18-07, as amended, concerning the protection of individuals in the processing of personal data
  • Tunisia Organic Law No. 2004-63 concerning personal-data protection
  • Any other laws applicable to the Controller's jurisdiction

“Sensitive Data” — Includes health data, patient identifiers, dental records, STL files, clinical photographs, prescriptions and treatment notes.

“Protected Health Information” or “PHI” — As defined under HIPAA: individually identifiable health information transmitted or maintained in any form.

2Roles of the Parties

You (the Client, meaning the dental clinic that holds a Behery Dental account) act as the Data Controller for all Personal Data uploaded to Behery Dental.

Behery Dental acts as the Data Processor, including for case design and preparation of production files as part of the service. Behery Dental does not manufacture restorations or devices; fabrication is performed by the Client or an independent third-party manufacturer selected by the Client. That work is carried out on the Client's instructions and for the purposes the Client has authorized, and does not make Behery Dental an independent controller of case data. For platform account administration and operational data (e.g., user accounts, billing and platform security logs), Behery Dental may act as an independent Controller as described in our Privacy Policy.

3Purpose of Processing

Behery Dental will process Personal Data solely for the following purposes:

  • Providing access to the Behery Dental platform
  • Case-status workflow tracking and treatment-plan review/approval
  • Secure case-file storage (STLs, images, PDFs, DICOMs, treatment-plan exports, prescriptions)
  • Case-thread and support communication between the Client and Behery Dental
  • Platform security, audit logging and monitoring
  • Backups and disaster recovery
  • Analytics using anonymized or aggregated data only
  • Improving platform performance and features

Behery Dental will not process Personal Data for any purpose other than those instructed or permitted by the Client.

4Categories of Data Processed

4.1 Data Subjects

Patients (referenced by a clinic-assigned identifier, not necessarily by name — see §4.2), and the individual team members of Client clinics (clinicians and clinic staff holding an owner, admin or member role, and other authorized platform users).

4.2 Data Types

Personal Data may include: the case record (a clinic-assigned patient reference, case type, notes, status history), case files the Client uploads (which may include STL/OBJ files, clinical images and photographs, treatment prescriptions, or other clinical documents, depending on what the Client chooses to attach), treatment plans, production files and review notes that Behery Dental adds to the case as part of delivering the service, case-thread messages between the Client and Behery Dental, professional/account details of team members, email addresses, audit logs and activity data.

The platform's own patient-reference field is designed to hold a clinic-assigned identifier (e.g., initials plus a case number) rather than the patient's full legal name, by design. The Client remains responsible for limiting what it enters into case notes, messages, and uploaded files to the minimum necessary, and for not uploading a full patient record — Clients needing to maintain one should keep it in their own practice-management or EHR system.

5Sub-processors

Behery Dental uses the following vetted Sub-processors to provide platform services. Where Sub-processors have access to Personal Data or PHI, appropriate data processing agreements are maintained with each.

Sub-processor Purpose Personal/PHI Data Access
Supabase, Inc. Cloud database (PostgreSQL), file storage, authentication Yes. Hosts all structured data and clinical files. AES-256 at rest, TLS in transit.
Resend, Inc. Transactional email delivery (case status-change notices, new-message notices, invoice notices, team invites) Limited. Case-status and new-message emails include the case's patient reference and, for new-message notices, a short preview of the message text — which may reference Personal Data depending on what the Client enters into the case record or a message. Resend does not receive uploaded case files.
Vercel, Inc. Application hosting (Next.js) Server log level only. Request and response metadata.
Google LLC OAuth sign-in, address autocomplete during onboarding Identity only. No PHI.

Behery Dental does not use a payment processor anywhere in the platform — organization billing is manual (an invoice with a hosted payment-link page; the organization pays by bank transfer or another means arranged directly, and Behery Dental staff mark the invoice paid by hand). No payment-processing Sub-processor is engaged, and none holds or transmits Personal Data on Behery Dental's behalf.

The platform does not currently include any AI-assisted feature that processes case data, so no AI Sub-processor is engaged. If that changes, this table will be updated first, before such a feature is enabled for any Client, and Behery Dental will not use identifiable patient data for AI model training.

Behery Dental will maintain an up-to-date list of active Sub-processors and will notify Clients of material additions or changes with reasonable notice.

6International Data Transfers

Because Behery Dental serves global users, data may be transferred outside your home country. Transfer mechanisms include:

  • EU/UK transfers — Governed by Standard Contractual Clauses (SCCs) in accordance with GDPR Article 46 and UK equivalent provisions.
  • Canada — Transfers comply with PIPEDA and applicable provincial privacy law.
  • United States — Transfers comply with CCPA/CPRA and applicable U.S. federal privacy law.
  • Middle East and North Africa — Transfers involving Saudi Arabia comply with the Regulation on Personal Data Transfer Outside the Kingdom, relying on a permitted purpose, appropriate safeguards and a documented risk assessment. Transfers involving the UAE follow Federal Decree-Law No. 45 of 2021, and health information relating to UAE health services is not stored, processed, generated or transferred outside the UAE unless a specific legal exception, decision or authorization permits it — which may require an approved in-country hosting environment. Transfers involving Egypt, Qatar, Bahrain, Oman, Jordan, Morocco, Algeria and Tunisia rely on the applicable local transfer mechanism (which may include explicit consent, adequacy of the receiving jurisdiction, contractual safeguards, or prior regulatory authorization), consistent with each country's law as described in our Privacy Policy.

Supabase supports regional hosting options. Behery Dental will use commercially reasonable efforts to support regional data residency upon written request, including for Clients subject to UAE health-data localization or other MENA data-residency requirements.

7Security Measures

Behery Dental implements appropriate technical and organizational security measures, which are continuously reviewed and improved. Current measures include:

  • Encryption of data in transit (TLS) and at rest (AES-256 via Supabase)
  • Postgres Row-Level Security (RLS) enforcing organization-scoped data access as the primary security boundary
  • Server-side authentication checks on all data mutations
  • HTTP-only session cookies for authentication tokens
  • Multi-factor authentication for internal administrative systems
  • Audit logging of all material platform events (case status changes, invoice status changes, admin actions)
  • Secure development and deployment practices
  • Regular vulnerability assessment and remediation
  • Firewall and network safeguards

Infrastructure certification: Supabase, our primary infrastructure provider, maintains SOC 2 Type II and ISO 27001 alignment. Behery Dental follows secure development practices aligned with these standards. Behery Dental does not currently hold its own SOC 2 certification; documentation of our security posture is available upon request.

Known remediation in progress: Behery Dental has identified and is actively remediating a number of Row-Level Security policy gaps across internal tables. These are documented in our internal security register and do not affect the primary data access boundary for Client data.

A detailed summary of security measures is available upon reasonable request.

8Client Responsibilities (Controller)

The Client agrees to:

  • Obtain all required patient consent before uploading data to Behery Dental
  • Ensure all uploads comply with applicable medical and privacy laws in the Client's jurisdiction
  • Limit Personal Data uploads to what is clinically necessary
  • Maintain accuracy of data submitted to the platform
  • Ensure authorized users comply with this DPA
  • Submit data deletion and export requests in writing to Behery Dental

Behery Dental is not responsible for Personal Data uploaded unlawfully by the Client or its users.

9Processor Responsibilities (Behery Dental)

Behery Dental will:

  • Process Personal Data only on documented Client instructions or as permitted by this DPA
  • Maintain confidentiality and implement appropriate security measures
  • Ensure Sub-processors are bound by obligations at least equivalent to this DPA
  • Notify the Controller without undue delay of any legally binding governmental or law enforcement request for Client data
  • Provide reasonable assistance to the Controller in meeting regulatory obligations

Behery Dental will not:

  • Sell Personal Data to any third party
  • Share data for advertising or marketing purposes
  • Use identifiable patient data for AI model training
  • Access case files except for purposes of support, diagnostics, platform security, or as required by law

10Data Breach Notification

If Behery Dental becomes aware of a confirmed Personal Data Breach affecting Client data, we will:

  • Notify the Client without undue delay and, where required by GDPR Article 33, within 72 hours of becoming aware
  • Provide available details of the nature of the breach, categories of data affected, and approximate number of data subjects
  • Describe mitigation and containment steps taken or proposed
  • Provide reasonable assistance to the Controller in meeting its own notification obligations to supervisory authorities and data subjects

The Client retains responsibility for required notifications to supervisory authorities or data subjects, unless otherwise agreed in writing.

11Data Retention and Deletion

Retention: Behery Dental retains Personal Data for the duration of the active service relationship and as required by applicable law. Payment and audit records may be retained beyond account closure in pseudonymized form to meet tax, regulatory and legal obligations.

Deletion requests: Upon account closure or written request, Behery Dental will delete or anonymize Personal Data within 30 days. Deletion requests are currently fulfilled via a managed manual process. An automated deletion pipeline is under active development. Requests should be submitted in writing to [email protected].

Important: Deleting a case record initiates the deletion workflow for associated files. File deletion from storage is included in the 30-day process. Backup copies may persist for a short period following deletion in accordance with standard infrastructure practices.

Backups: Automated database backups are managed by Supabase and are subject to their retention schedule. These backups will be purged on their standard cycle following deletion.

Export: Client data exports are available upon written request and will be fulfilled within 30 days. A self-service data export feature is on the Behery Dental product roadmap. You may request an export at any time prior to or following account closure.

12Compliance Assistance

Behery Dental will provide reasonable assistance to help Controllers:

  • Respond to GDPR/UK GDPR data subject access, erasure, rectification and portability requests
  • Meet CCPA/CPRA obligations
  • Support PIPEDA compliance
  • Meet obligations under Saudi Arabia's PDPL, the UAE's Federal Decree-Law No. 45 of 2021 (including applicable health-data rules), and the data protection laws of Egypt, Qatar, Bahrain, Oman, Jordan, Morocco, Algeria and Tunisia
  • Respond to requests or notifications from a competent MENA data-protection or health-sector regulator, where Behery Dental holds relevant information
  • Document data processing activities for regulatory purposes

Data subject requests received by Behery Dental that relate to Client data will be forwarded to the Controller. Assistance is currently provided via a manual process and Behery Dental will respond to written requests within 30 days.

Additional assistance beyond standard scope may be subject to reasonable fees, agreed in advance.

13Audits

Upon reasonable written notice (minimum 30 days), Behery Dental will:

  • Provide documentation demonstrating compliance with this DPA
  • Provide details of active Sub-processors and their roles
  • Provide summaries of available independent audit reports (e.g., Supabase SOC 2)
  • Respond to reasonable written information security questionnaires

Physical or on-site audits of Behery Dental systems are not permitted unless legally required and mutually agreed in writing.

14Governing Law

This DPA is governed by the laws of [TO BE DETERMINED], unless superseded by mandatory applicable local privacy law. For EU/UK Clients, mandatory provisions of the GDPR and UK GDPR take precedence where they conflict with this DPA.

15Term

This DPA remains in effect for so long as: (a) the Client uses the Behery Dental platform, or (b) Behery Dental processes Personal Data on behalf of the Client. Obligations regarding data confidentiality and security survive termination.

16Online Acceptance

By clicking “I agree to the Data Processing Agreement” or continuing to use the platform, the Client confirms that:

  • They have read and understood this DPA
  • They have authority to bind their organization to these data processing terms
  • They accept the terms of this Agreement

Where a terms acceptance record cannot be confirmed at the time of signup (for example, where onboarding is not completed), continued use of the platform constitutes acceptance of the then-current DPA.

17HIPAA and Business Associate Agreement

For Clients in the United States who handle Protected Health Information (PHI) as defined by HIPAA, a Business Associate Agreement is available. Clients subject to HIPAA should review and accept the BAA before uploading any PHI to the platform. For questions, contact [email protected].

18Contact

For data protection enquiries, requests, or to exercise data subject rights:

Email: [email protected]
Company: Behery Dental

Questions about this DPA?

Contact us through the early access form and our team will follow up directly.

Behery Dental DENTAL WORKFLOW PLATFORM

A private workflow platform for dental teams managing restoration cases with clarity, continuity and care.

Platform

Platform Workflow Principles FAQ

Company

Private by design Private access Terms of Service Privacy Policy Service Agreement Data Processing Agreement Business Associate Agreement

For teams

Clinics Production teams Digital dental teams
© 2026 Behery Dental. All rights reserved.