Data processing agreement
Last updated: 2 September 2026.
This agreement is an integral part of the terms of service and is accepted together with them when a clinic opens an account. It covers what the Serbian Personal Data Protection Act requires when one party processes data on another party's instructions: the clinic decides what is collected and why, and the platform stores and processes that data on its behalf. It is not aimed at patients booking an appointment — the privacy policy is.
Who agrees with whom
The controller is the clinic using the platform: it decides which patient data it collects, for what purpose and how long it keeps it. The processor is the platform, developed and maintained by Miroslav Roglić, DDS, who processes the data solely on the clinic's instructions. The agreement takes effect when the account is opened and lasts as long as the clinic uses the platform.
What we process and why
The purpose is running the clinic's booking and records: showing free slots, creating and changing appointments, reminders and confirmations by email, and — if the clinic enables the chart module — keeping the health records the clinic itself enters. We do not process the data for any purpose of our own.
Whose data and what kinds
The data concerns the clinic's patients and its staff. For patients we process name and surname, phone, email, date of birth and chart number, appointment data, and — when the chart module is on — health data: history, diagnoses, treatments, images and payments. Health data is a special category and requires stronger protection, which is why the clinic enables the chart module deliberately and separately. For staff we process email, role and sign-in records.
Processing only on the clinic's instructions
We process the data only as needed for the platform to work and only on the clinic's instructions, which are set out in this agreement and in what the clinic does through the application. We do not sell patient data, do not pass it to third parties for their own purposes, do not use it for advertising and do not use it to train artificial intelligence models. If a law required processing beyond those instructions, we would tell the clinic before doing so, unless that notice is itself prohibited.
Confidentiality
Only people who need access have it, and they are bound by confidentiality. Access to a patient chart is logged — who opened, printed or exported which chart and when — and the clinic can see that log in the application.
Security measures
Traffic between the browser and the server is encrypted (HTTPS). Each clinic's data is separated by database-level rules, so one clinic cannot see another's data even if it tried. Passwords are not stored in readable form. Changes to charts and access to charts leave a trail kept for twelve months. Only the platform owner has access to the platform panel. Measures are extended as the platform grows, but no change may lower the level of protection.
Sub-processors
We use the services listed below to run the platform. All of them are bound by a contract imposing the same confidentiality and protection measures. If we change the list, the clinic will be notified by email at least 30 days in advance and may object; if we cannot resolve the objection, the clinic may stop using the platform and take its data with it. Where data is processed outside the European Economic Area, it is done under standard contractual clauses and other appropriate safeguards.
Services we use
- Supabase — database and accounts. Data is stored in the European Union (Frankfurt).
- Vercel — running the application. The server side runs in the European Union (Frankfurt).
- Resend — sending email to patients and the clinic. Processes the recipient address and the message content. The company is based in the United States.
- Sentry — reporting technical errors in the application so faults can be fixed.
- Cloudflare — domain management. Does not process patient data.
Patient rights and helping the clinic
A patient request — for access, correction, deletion or transfer — is handled by the clinic, because the clinic is the controller. We help: the application can export a chart and delete a patient, and if something is needed that the application does not cover, we will do it on the clinic's written request, free of charge and without delay. If a patient contacts us, we refer them to the clinic and tell the clinic about it.
If there is a data breach
If we learn that data has leaked, been lost or been altered without authorisation, we will notify the clinic without delay and no later than 48 hours after becoming aware. The notice states what happened, which data and how many people it concerns, the likely consequences and what we have done. Reporting to the Commissioner and notifying patients, where required, is done by the clinic as controller, and we provide everything it needs for that.
Evidence and audits
On the clinic's written request we provide the information it needs to demonstrate that its legal obligations are met. The clinic may audit how we process the data, with at least 15 days' notice and no more than once a year, except where the audit follows a data breach. Audits are carried out so that other clinics' data is not put at risk.
What happens to the data when a clinic leaves
After termination, the clinic's data remains available for download for 30 days. After that we delete it, unless a law requires us to keep it longer. Copies in backups are deleted in the regular cycle, no later than 30 days after the main data is deleted. We confirm deletion in writing on request.
Duration, changes and governing law
The agreement lasts as long as the platform is used. Every version carries a date, and we notify the clinic by email before a change takes effect. If a provision of this agreement differs from the terms of service, this agreement prevails on matters of data processing. The law of the Republic of Serbia applies.