Sales: (315)-859-0703

Practice Agreement Additional Terms & Conditions

US | Canada | UK | Spain | France | Italy | Germany | Ireland | Netherlands

US Terms of Service

These Terms & Conditions (“Terms”) to the Practice Agreement (“Agreement”) are entered into by and between Dandy (“Dandy” or “we”) and you and your dental practice or office (“You”) and are effective as of the date the Practice Agreement is entered into (“Effective Date”). If you accept these Terms on behalf of an entity, partnership, corporation, or organization “you” includes you, that entity, and all entity users and you hereby represent that you have the authority to bind all such users. Dandy and you will each be referred to as a “Party” and together, the “Parties.”  For good and valuable consideration as set forth in the Agreement, the Parties agree to the following:

  1. Amendment. These Terms and the Agreement cannot be changed unless we both agree in writing. If Dandy makes material changes to either the Terms or the Agreement, Dandy will notify you of such change. Any material change will become effective thirty (30) days after we notify you, unless you notify us in writing that you wish to terminate the Agreement. In that case, the change will not take effect and Dandy will honor the existing Agreement for 60 days or until you return the scanner and any other Dandy equipment that may be in your possession.
  2. Entire Agreement. The Practice Agreement, these Terms, the Business Associates Agreement, and the IT Policy for Practice-Provided Equipment, if applicable, constitute our entire agreement. Anything communicated in any other method outside of these documents is not binding. This Agreement supersedes any other conflicting agreement we may have made in the past.
  3. Non-assignability. Dandy is partnering with you, so you may not transfer or assign the Agreement and Terms to a third-party unless we both agree in writing.
  4. Legal Compliance. Both Parties agree to comply with all applicable health laws and regulations in the United States, including HIPAA, among others.
  5. Indemnity. You will indemnify, defend, and hold harmless Dandy against and from all claims, causes of actions, damages, debts, liabilities, losses, obligations, payments, costs, and expenses (including legal expenses), arising from or relating to: (a) your breach of any term of the Agreement, these Terms and/or the Business Associates Agreement; (b) your breach of any term of any agreement between you and any patient, or any negligent, reckless or willful acts or failures with respect to your care of a patient; (c) your provision of incorrect or incomplete information, scans, documents, or data to Dandy, or any failure to timely provide Dandy with any information it requests from you, your practice, or any of your Dentists; and (d) any and all dealings with federal, state or local administrative agencies, regulators, licensing, or professional bodies.
  6. Arbitration. Dandy hopes that we never encounter any meaningful disagreements about our Agreement, these Terms, and the Business Associates Agreement, and Dandy very much prefers to resolve any disagreements in the most amicable way possible. Dandy’s goal is to work closely with you and Dandy’s mission is to support your practice. If something does arise that we are unable to resolve through amicable problem solving, we both commit to resolve the issue through arbitration with JAMS in the state of New York, under New York law.
  7. Sales Tax. Dandy will charge sales tax, as applicable, on our products, equipment and services based on your geographical location. The amount of sales tax will be presented on your monthly invoice, and payment will be collected as described herein as well as in your Practice Agreement. If you are exempt from paying sales tax, you agree to provide Dandy with a valid exemption certificate acceptable to each taxing jurisdiction where exempt status is claimed.

Business Associate Agreement

This HIPAA BUSINESS ASSOCIATE AGREEMENT (“Addendum”), is effective as of the date the Practice Agreement is entered into (“Effective Date”), between the dental practice identified in the Practice Agreement (“Covered Entity”) and Dandy (“BA”).  This Addendum, which supersedes any previous business associate agreement between the parties, amends, supplements, and is made a part of the Practice Agreement, by and between Covered Entity and BA, as the same may be amended from time to time (the “Agreement”).

RECITALS

WHEREAS, Covered Entity is a “covered entity” as that term is defined at 45 C.F.R. § 160.103;

WHEREAS, BA may, on behalf of Covered Entity, create, receive, maintain, or transmit certain Protected Health Information (as defined below) in order to provide services to Covered Entity pursuant to the Agreement;

WHEREAS, Covered Entity is subject to the Administrative Simplification requirements of the Health Insurance Portability and Accountability Act of 1996 and regulations promulgated thereunder, including the Standards for Privacy of Individually Identifiable Health Information and the Security Standards for the Protection of Electronic Protected Health Information at 45 C.F.R. Parts 160 and 164 (collectively “Privacy and Security Regulations”);

WHEREAS, the Privacy and Security Regulations require Covered Entity to enter into a contract with BA in order to mandate certain protections for the privacy and security of Protected Health Information, and those Regulations prohibit the disclosure of Protected Health Information from Covered Entity to BA if such a contract is not in place;

WHEREAS, this Addendum shall be applicable only in the event that BA meets, with respect to Covered Entity, the definition of “business associate” set forth in 45 C.F.R. § 160.103.

In consideration of the foregoing, and for other good and valuable consideration, the receipt and adequacy of which is hereby acknowledged, the parties agree as follows:

1. Definitions

  1. Breach” shall have the meaning given to the term “breach” at 45 C.F.R. § 164.402, as applied to the Unsecured PHI created, received, maintained, or transmitted by BA from or on behalf of Covered Entity.
  2. Electronic Protected Health Information” or “ePHI” means shall have the meaning given to the term “electronic protected health information” at 45 C.F.R. § 160.103, as applied to the information created, received, maintained, or transmitted by BA from or on behalf of Covered Entity.
  3. Protected Health Information” or “PHI” shall have the meaning given to the term “protected health information” at 45 C.F.R. § 160.103, as applied to the information created, received, maintained, or transmitted by BA from or on behalf of Covered Entity.
  4. Reportable Event” means any (1) use or disclosure of PHI not provided for by this Addendum; (2) Security Incident; (3) Breach of Unsecured PHI; or (4) any data incident involving PHI for which data breach notification is required under applicable foreign, federal, or state law.
  5. Services” mean the services provided by BA to Covered Entity as set forth in the Agreement.
  6. Security Incident” shall have the meaning given to the term “security incident” at 45 C.F.R. § 164.304, as applied to the ePHI created, received, maintained, or transmitted by BA from or on behalf of Covered Entity.

Terms used, but not otherwise defined, in this Addendum shall have the same meaning as those terms in the Privacy and Security Regulations including, but not limited to, 45 C.F.R. Sections 160.103 and 164.501. Any inconsistency in the definition of a term shall be resolved in favor of a meaning that permits compliance with HIPAA.

2. Permitted Uses and Disclosures of PHI

Except as otherwise limited in this Addendum or the Agreement, BA may do any or all of the following:

  1. Use of Disclosure under the Agreement. Use or disclose PHI to perform functions, activities, or services for, or on behalf of Covered Entity, to the extent permitted in the Agreement, provided that such use or disclosure would not violate the Privacy Rule or any applicable state law if done by Covered Entity.  Notwithstanding the above, BA may use and disclose PHI for the purposes identified in paragraphs (2), (3), and (5) of this Section 2, even if Covered Entity could not do so under the Privacy Rule.
  2. Use for Administration or Legal Responsibilities. Use PHI, but only to the minimum extent necessary, for the proper management and administration of BA, for debt collection practices of BA, or to carry out the legal responsibilities of BA.
  3. Disclosure for Administration or Legal Responsibilities. Disclose PHI, but only to the minimum extent necessary, for the proper management and administration of BA or to carry out the legal responsibilities of BA, provided that:
    1. The disclosures are Required by Law; or
    2. BA obtains reasonable assurances from the third party to whom the PHI is disclosed that such information shall remain confidential and shall be used or further disclosed only as Required By Law or for the purpose for which it was disclosed to the person (which purpose must be consistent with the limitations imposed upon BA pursuant to this Addendum), and such person agrees to promptly notify BA of any instance of which it is aware in which the confidentiality of the information has been breached.
  4. Use for Reporting of Violations. Use PHI to report violations of law to appropriate federal, state, and local authorities, consistent with 45 C.F.R. § 164.502(j).
  5. Use for Data Aggregation Services. Use PHI to provide Data Aggregation services relating to the health care operations of Covered Entity, as permitted by 45 C.F.R. §164.504(e)(2)(i)(B).
  6. De-Identified Information. Use PHI to create de-identified information in accordance with 45 C.F.R. §§ 164.502(d) and 164.514(a)-(c).

3.  Obligations of Business Associate

  1. Limited by Agreement and Law.  BA may not use or disclose PHI other than as permitted or required by this Addendum and the Agreement or as Required by Law.
  2. Compliance with HIPAA. To the extent that BA is responsible for carrying out an obligation of Covered Entity under HIPAA pursuant to this Addendum or the Agreement, BA shall comply with the requirements of HIPAA that apply to Covered Entity in the performance of such obligation.
  3. Appropriate Safeguards for PHI. BA shall implement and maintain appropriate safeguards to prevent the Use or Disclosure of PHI in any manner other than as permitted by the Agreement and this Addendum. 

4. Reportable Events

  1. Use of Subcontractors. If BA discloses PHI to a subcontractor or allows a subcontractor to create, receive, maintain, or transmit PHI on its behalf, BA shall require the subcontractor to execute a written agreement obligating the subcontractor to comply with all the terms of this Addendum. If BA becomes aware of a pattern of activity or practice of a subcontractor that would constitute a material breach or violation of the written agreement between BA and subcontractor, BA shall take reasonable steps to cure such breach or end the violation, as applicable, or terminate such written agreement with such subcontractor.
  2. Availability of Internal Practices, Books and Records to Government Agencies. BA agrees to make its internal practices, books and records relating to the Use and Disclosure of PHI that is received from, or created or received by BA on behalf of, Covered Entity available to the Secretary of the United States Department of Health and Human Services for purposes of determining Covered Entity’s compliance with the HIPAA. No attorney-client, accountant-client, or other legal privilege shall be deemed to have been waived by BA by virtue of BA’s compliance with this provision.
  3. Access to and Amendment of PHI. To the extent that BA maintains PHI in a Designated Record Set, BA shall: (a) make the PHI specified by Partner available to the individual(s) identified by Covered Entity as being entitled to access such PHI, and (b) make amendment(s) to such PHI in a Designated Record Set that as directed or agreed to by Covered Entity. BA shall provide such access and incorporate such amendments within the time and in the manner specified by Covered Entity that meets the requirements of 45 C.F.R. § 164.524, § 164.526, and applicable state law.
  4. Accounting of Disclosures. Upon Covered Entity’s request, BA shall provide to Covered Entity an accounting of the disclosures of an Individual’s PHI in a time and manner that meets the requirements of 45 C.F.R. § 164.528 and, as of the applicable effective date, Section 13405(c) of HITECH and any regulations promulgated thereunder.
  5. Minimum Necessary.  BA agrees that it shall comply with HIPAA’s minimum necessary requirements.
  6. Communication with Other Business Associates.  In connection with the performance of its services, activities, and/or functions to or on behalf of Covered Entity, BA may disclose information, including PHI, to other business associates of Covered Entity.  Likewise, BA may use and disclose information, including PHI, received from other business associates of Covered Entity, as if this information was received from, or originated with, Covered Entity.  The parties agree that it is the responsibility of Covered Entity to secure and maintain business associate agreements with its other business associates.
  7. BA shall report to Covered Entity any Reportable Event of which it becomes aware. All such reports shall be made without unreasonable delay and in no case later than fifteen (15) business days after BA’s discovery of a Reportable Event.
  8. BA shall cooperate with Covered Entity in investigating a Reportable Event and assist Covered Entity in determining whether a Reportable Event constitutes a Breach of Unsecured PHI.
  9. BA shall mitigate, to the extent practicable, any harmful effect that is known to BA of a Reportable Event.
  10. The parties acknowledge and agree that this section constitutes notice by BA to Covered Entity of the ongoing existence and occurrence of attempted but unsuccessful Security Incidents that do not result in unauthorized access to, or use, loss, modification, destruction, or disclosure of, PHI, such as pings and other broadcast attacks on BA’s firewall, port scans, unsuccessful log-on attempts, unsuccessful denial of service attacks, or any combination thereof.

5.  Obligations of Covered Entity

  1. Notice of Privacy Practices.  Covered Entity shall notify BA in writing of any limitations in its notice of privacy practices, to the extent that such limitations may affect BA’s use or disclosure of PHI.
  2. Notification of Revocations.  Covered Entity shall notify BA in writing of any changes in, or revocation of, authorization by an Individual to use or disclose PHI, to the extent that such changes or revocation may affect BA’s use or disclosure of PHI.
  3. Notification of Restrictions.  Covered Entity shall notify BA in writing of any restriction to the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by in accordance with 45 C.F.R. § 164.522, to the extent that such restriction may affect BA’s use or disclosure of PHI.
  4. Permissible Requests.  Covered Entity shall not request that BA use or disclose PHI in any manner that would not be permissible under HIPAA or other applicable federal or state law if done by Covered Entity.

6.  Term and Termination

  1. Term. The term of this Addendum shall be the same as the term of the Agreement, but shall terminate as of the earliest occurrence of any of the following:
    1. The Agreement expires or is terminated with or without cause; 
    2. This Addendum is terminated for cause as described in Section 5.2 below; 
    3. The parties mutually agree to terminate this Addendum; or
    4. This Addendum is terminated under applicable federal, state, or local law. 
  2. Termination for Cause.
    1. Upon Covered Entity’s determination of a breach of any material term of this Addendum by BA, Covered Entity shall provide BA written notice of that breach in sufficient detail to enable BA to understand the specific nature of that breach and afford BA an opportunity to cure the breach; provided, however, that if BA fails to cure the breach within thirty (30) days of receipt of such notice, Covered Entity may terminate this Addendum and the Agreement. 
    2. Upon BA’s determination of a breach of a material term of this Addendum by Covered Entity, BA shall provide Covered Entity written notice of that breach in sufficient detail to enable Covered Entity to understand the specific nature of that breach and afford Covered Entity an opportunity to cure the breach; provided, however, that if Covered Entity fails to cure the breach within thirty (30) days of receipt of such notice, BA may terminate this Addendum and the Agreement.
  3. Effect of Termination
    1. Subject to Section 5.3(b) below, upon termination of this Addendum for any reason, BA shall return or destroy all PHI that BA still maintains in any form.  BA shall retain no copies of such PHI. 
    2. If return or destruction of any or all PHI is not feasible, BA shall:
      1. Retain only that PHI for which return or destruction is not feasible;
      2. Return to Covered Entity or destroy the remaining PHI that BA still maintains in any form;
      3. Extend the protections of this Addendum to any retained PHI, continue to use appropriate safeguards, and comply with the Security Rule with respect to ePHI, in order to prevent use or disclosure of the retained PHI other than as provided for in this Addendum for as long as BA retains the PHI;
      4. Not use or disclose the PHI retained by BA other than for the purposes for which such PHI was retained and subject to the same conditions set forth in this Addendum that applied prior to termination; and
      5. Return to Covered Entity or destroy the PHI retained by BA if and when it becomes feasible to do so.
    3. These provisions shall apply to PHI that is in the possession of subcontractors or agents of BA.
    4. This Section 5.3 shall survive termination of this Addendum. 

7.  Miscellaneous

  1. Regulatory References.  A reference in this Addendum to a section in HIPAA means the section as in effect or as amended at the time this Addendum is executed or amended.
  2. Amendment; No Waiver.  Upon the effective date of any federal statute amending or expanding HIPAA, any guidance or temporary, interim final or final regulations promulgated under HIPAA, or under any federal statute amending or expanding HIPAA (collectively, the “HIPAA Regulations”) that are applicable to this Addendum or any amendments to the HIPAA Regulations, this Addendum shall be automatically amended, such that the obligations imposed on Covered Entity and BA shall remain in compliance with such requirements, unless the parties agree otherwise by mutual consent.  The parties shall take all necessary action to expressly reflect such automatic amendments to this Addendum from time to time.  Except as provided otherwise in this paragraph (B), no waiver, change, modification, or amendment of any provision of this Addendum shall be made unless it is in writing and is signed by the parties hereto.  The failure of either party at any time to insist upon strict performance of any condition, promise, agreement, or understanding set forth herein shall not be construed as a waiver or relinquishment of the right to insist upon strict performance of the same condition, promise, agreement, or understanding at a future time.
  3. Interpretation.  Any ambiguity in this Addendum shall be resolved in favor of a meaning that permits compliance with HIPAA. The titles and headings set forth at the beginning of each section hereof are inserted for convenience of reference only and shall in no way be construed as a part of this Addendum or as a limitation on the scope of the particular provision to which it refers.  In the event of an inconsistency between the provisions of this Addendum and the mandatory terms of HIPAA, as may be expressly amended from time-to-time by the Secretary, or as a result of interpretations by the Secretary, a court, or another regulatory agency with authority over the parties, the interpretation of the Secretary, such court, or regulatory agency shall prevail.
  4. Relationship to Agreement Provisions. In the event that a provision of this Addendum is contrary to a provision of the Agreement, the provision of this Addendum shall control. Otherwise, this Addendum shall be construed under, and in accordance with, the terms of the Agreement.
  5. Relationship of Parties.  The parties to this Addendum are independent contractors.  None of the provisions of this Addendum are intended to create, nor shall they be interpreted or construed to create, any relationship between Covered Entity and BA other than that of independent contractors.  Except as otherwise expressly set forth herein, neither party, nor any of its representatives, shall be deemed to be the agent, employee, or representative of the other party.
  6. No Third Party Beneficiaries.  This Addendum is between the parties hereto.  Nothing express or implied in this Addendum is intended to confer, nor shall anything herein confer, any rights, remedies, obligations, or liabilities whatsoever upon any person other than Covered Entity and BA and any respective successors and assigns.
  7. Invalid or Unenforceable Provision.  The provisions of this Addendum shall be severable.  The invalidity or unenforceability of any particular provision or portion of such provision of this Addendum be construed, in all respects, as if such invalid or unenforceable provision or portion of such provision had been omitted, and shall not affect the validity and enforceability of the other provisions hereof or portions of that provision.
  8. Assignment.  The parties’ rights and obligations with respect to assignment of this Addendum shall be subject to the assignment provision set forth in the Agreement. In the event that the Agreement does not contain an assignment provision, neither party may assign its rights, or delegate its duties or obligations, under this Addendum without the prior written consent of the other party, which consent shall not be unreasonably withheld.  This Addendum shall be binding upon, and shall inure to the benefit of, the parties hereto and their respective successors.
  9. Applicable Law.  This Addendum shall be construed, administered, and governed by the governing law set forth in the Agreement, except to the extent preempted by applicable federal law.  In the event that the Agreement does not identify the governing law, this Addendum shall be construed, administered, and governed under the laws of the State of New York, except to the extent preempted by applicable federal law.
  10. Notices.  All notices hereunder shall be in writing, and either delivered by hand, or sent by mail, or delivered in such other manner as the parties may agree upon, to the following:

To Covered Entity: Practice’s Email Address Identified in the Practice Agreement

To BA: Dandy

Attention: Legal Department

11 Park Place, Suite 502

New York, NY 10007

[email protected]

Each party reserves the right to change address for receiving notice during the term of this Addendum upon written notice to the other parties.

  1. Counterparts.  This Addendum may be executed in separate counterparts, none of which need contain the signatures of both parties, and each of which, when so executed, shall be deemed to be an original, and such counterparts shall together constitute and be one and the same instrument.

IT Policy for Practice-Provided Equipment

This policy applies only to practices that use their own laptop and scanner as part of their relationship with Dandy.

Standard Systems Policy:

To ensure the quality and consistency of case submission to Dandy Labs, you agree to comply with the following requirements regarding your IT infrastructure:

  1. You agree to use the 3Shape TRIOS 3, TRIOS 4, or TRIOS 5 intraoral scanner only.
  2. You agree to provide a consistent Wi-Fi connection of at least 15 Mbps upload and 15 Mbps download in all locations where case submission occurs.
  3. You agree to use a computer with the 3Shape intraoral scanner that meets the following system requirements:
  4. PC Minimum:

PC Recommended:

  1. You agree to upgrade the Trios software to a minimum version of 1.7.19.1.
  2. You agree to save and submit all case files to the local storage of the computer.
  3. You agree to grant EasyAccess to Splashtop to Dandy’s customer service team with a mutually agreed-upon shared password that will exist for the duration of the relationship.
  4. You agree to install the DandyUploader to a local user’s profile and you will use this local profile in connection with your use of the TRIOS software.
  5. You agree to grant permission to the following file path if you are using antivirus software:
  1. Should your practice have a network firewall, either physical or web-based, please allow all traffic on the following domains:

Canadian Terms of Service, including Data Privacy Agreement

These Terms & Conditions (“Terms”) to the Practice Agreement (“Agreement”) are entered into by and between Zima Labs Canada, ULC d/b/a Dandy (“Dandy” or “we”) and you and your dental practice or office (“You”) and are effective as of the date the Practice Agreement is entered into (“Effective Date”). If you accept these Terms on behalf of an entity, partnership, corporation, or organization “you” includes you, that entity, and all entity users and you hereby represent that you have the authority to bind all such users. Dandy and you will each be referred to as a “Party” and together, the “Parties.”  For good and valuable consideration as set forth in the Agreement, the Parties agree to the following:

  1. Amendment. These Terms and the Agreement cannot be changed unless we both agree in writing. If Dandy makes material changes to either the Terms or the Agreement, Dandy will notify you of such change. Any material change will become effective thirty (30) days after we notify you, unless you notify us in writing that you wish to terminate the Agreement. In that case, the change will not take effect and Dandy will honor the existing Agreement for 60 days or until you return the scanner and any other Dandy equipment that may be in your possession.
  2. Entire Agreement. The Practice Agreement, these Terms, the Data Privacy Agreement, and the IT Policy for Practice-Provided Equipment, if applicable, constitute our entire agreement. Anything communicated in any other method outside of these documents is not binding. This Agreement supersedes any other conflicting agreement we may have made in the past.
  3. Non-assignability. Dandy is partnering with you, so you may not transfer or assign the Agreement and Terms to a third-party unless we both agree in writing.
  4. Legal Compliance. Both Parties agree to comply with all applicable health laws and regulations in Canada, including the applicable Federal and Provincial data privacy laws, among others.
  5. Indemnity. You will indemnify, defend, and hold harmless Dandy against and from all claims, causes of actions, damages, debts, liabilities, losses, obligations, payments, costs, and expenses (including legal expenses), arising from or relating to: (a) your breach of any term of the Agreement, these Terms and/or the Data Privacy Agreement; (b) your breach of any term of any agreement between you and any patient, or any negligent, reckless or willful acts or failures with respect to your care of a patient; (c) your provision of incorrect or incomplete information, scans, documents, or data to Dandy, or any failure to timely provide Dandy with any information it requests from you, your practice, or any of your Dentists; and (d) any and all dealings with federal, state or local administrative agencies, regulators, licensing, or professional bodies.
  6. Arbitration. Dandy hopes that we never encounter any meaningful disagreements about our Agreement, these Terms, and the Data Privacy Agreement, and Dandy very much prefers to resolve any disagreements in the most amicable way possible. Dandy’s goal is to work closely with you and Dandy’s mission is to support your practice. If something does arise that we are unable to resolve through amicable problem solving, we both commit to resolve the issue through arbitration with the Canadian Arbitration Association in the city of Toronto, under Ontario law.  The language of the arbitration shall be English.
  7. Sales Tax. Dandy will charge sales tax, as applicable, on our products, equipment and services based on your geographical location. The amount of sales tax will be presented on your monthly invoice, and payment will be collected as described herein as well as in your Practice Agreement. If you are exempt from paying sales tax, you agree to provide Dandy with a valid exemption certificate acceptable to each taxing jurisdiction where exempt status is claimed.
  8. The Parties acknowledge and agree that because Dandy will be receiving and processing Personal Health Information on behalf of the Counterparty, a Data Privacy Agreement (the “DPA”) is a mandatory and integral part of this Agreement. The DPA, attached hereto as Schedule A, sets out the Parties’ obligations with respect to the collection, use, disclosure, and protection of Personal Information and Personal Health Information. Counterparty acknowledges and agrees that it will not provide any Personal Health Information to Dandy unless and until the DPA is executed by both Parties.

Schedule A – Data Privacy Agreement

This Data Privacy Agreement (“DPA”) applies to the Practice (“Agreement”) between Dandy and you and your dental practice or office (“Counterparty”) and is incorporated by reference when the Applicable Laws (defined below) cover Counterparty’s use of the Services and the processing of Personal Data. This DPA ensures that Dandy’s processing of Personal Information complies with Applicable Laws. 

Capitalized Terms not defined herein shall have the definitions set forth in the Agreement.

1. Definitions

Applicable Laws” means all laws, regulations, and regulatory guidance applicable to the processing of Personal Information under this DPA, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and, specifically for Personal Health Information, the Ontario Personal Health Information Act, 2004 (PHIPA) and any other applicable provincial privacy laws.

Data Breach” means any unauthorized access, use, or disclosure of Personal Health Information that is in the custody or control of Dandy, and which poses a real risk of significant harm to the individual, as defined by PHIPA. the actual loss, theft, unavailability or misuse of, or unlawful or unauthorized access to, use, disclosure or processing of Personal Information or any actual or suspected violation of the requirements of this Agreement or Applicable Laws

Personal Information” means identifying information about an individual in oral or recorded form, as defined by PHIPA, that is collected, used, or disclosed in the course of providing health care, including but not limited to health card numbers, treatment information, and dental records.

means any information relating to an identified or identifiable individual, as defined under the applicable data protection laws in Canada, including the PIPEDA and any applicable provincial privacy laws.

2. Scope and Purpose

Dandy agrees to process Personal Information only on behalf of and under the documented instructions of the Counterparty, except where required by Applicable Laws.

Dandy shall not process Personal Information for any purpose other than to perform the Services described in the Agreement, or as otherwise expressly authorized by the Counterparty.

3. Obligations of Dandy

Dandy shall comply with all Applicable Laws concerning the processing of Personal Information. Dandy shall treat Personal Information as confidential and only disclose Personal Information to its employees or subcontractors who are subject to binding confidentiality obligations in respect of Personal Information (and whose use of that Personal Information relates to their job function), and ensure that those individuals only process the Personal Information on instructions from the Counterparty and in accordance with the Agreement (including this DPA).  Dandy shall ensure that all personnel authorized to process Personal Information are bound by confidentiality obligations and have received appropriate training on data protection.

If subcontractors are engaged, Dandy shall contract with such subcontractors to ensure they comply with this DPA and Applicable Laws. Dandy will remain to the Counterparty for any breach of the Agreement that is caused by an act, error or omission of the subcontractor to the same extend Dandy would be liable for its own acts, errors, or omissions.

Dandy shall not transfer Personal Information outside Canada and the United States without Counterparty’s prior written consent.

Dandy will provide the Counterparty with reasonably necessary assistance in order to assist with any requests by any individual to access, correct, amend or delete their Personal Information. Any such requests will be directed by Dandy to the Counterparty, as the custiodian of the Personal Health Information,, or relating to the processing of the individual’s Personal Information in any manner, will be directed by Dandy to the Counterparty and Dandy will not take action with respect to any such request absent instructions from the Counterparty except to the extent required by law; 

Dandy will provide the Counterparty with reasonable notice of any intended disclosure of the Personal Information that is required by law, unless the provision of such notice would violate applicable laws. Should a law enforcement agency send a request to Dandy or its subcontractors regarding Personal Information, Dandy will attempt to redirect the law enforcement agency’s request to the Counterparty.  

Dandy will notify the Counterparty of any notice, inquiry, investigation or the receipt of a complaint from any individual or regulatory authority which relates directly or indirectly to the processing of Personal Information, and reasonably cooperate with the Counterparty where required by the Counterparty  to meet its obligations under Applicable Laws.

  1. Security

Dandy has implemented and will maintain commercially reasonable and appropriate technical and organizational measures to protect Personal Information against unauthorized access, loss, destruction, or alteration taking into account the sensitivity of the Personal Information. This includes measures relating to the physical security of facilities used to deliver Services, measures to control access rights to assets and relevant networks, and processes for testing these measures.

  1. Data Breach

If Dandy becomes aware of adetects that a Data Breach, has occurred, Dandy shall:(i) take all reasonable steps necessary to investigate, contain, and mitigate the Data Breach; and (ii) notify the Counterparty without unreasonable delay after Dandy becomes aware of the breach. Dandy shall promptly provide the Counterparty with all relevant information gathered by Dandy in connection therewith to allow the Counterparty to fulfill its own legal notification obligations under PHIPA.of the Data Breach, and promptly provide the Counterparty with all relevant information gathered by Dandy in connection therewith

  1. Compliance

Upon request by the Counterparty, Dandy will make available to Counterparty information demonstrating and verifying that Dandy uses the Personal Information in a manner consistent with its obligations under this DPA and Applicable Laws.

  1. General

This DPA shall remain in force until the earlier of: (i) the termination or expiry of the Agreement or (ii) Dandy ceasing to process Personal Information. Upon termination, at Counterparty’s request Dandy will return Personal Information to Counterparty or delete Personal Information. 

If any part of this DPA is found by any court or administrative body of competent jurisdiction to be invalid, unenforceable, or illegal, the other terms shall remain in force. Any invalid, unenforceable, or illegal term will be interpreted to give effect to the Parties’ commercial intention. If that is not possible, it will be severed but the rest shall remain in full force.

Except where this DPA conflicts with the Agreement, all other provisions of the Agreement remain unchanged. In the event of conflict between this DPA and the terms of the Agreement, this DPA shall prevail so far as the subject matter concerns the processing of Counterparty Personal Information. This DPA together with the Agreement is the final, complete, and exclusive agreement of the Parties with respect to the subject matter of it and supersedes and merges all prior discussions and agreements between the Parties with respect to such subject matter. No other representations or terms shall apply or form part of this DPA. 

Dandy’s total aggregate liability for any claims arising under or in connection with this DPA is subject to and limited by the limitations on liability contained in the Agreement.

This DPA and the Agreement shall be interpreted as broadly as necessary to implement and comply with the mandatory provisions of Applicable Laws. The Parties agree that this DPA shall be interpreted in favor of their intent to comply with Applicable Laws and therefore any ambiguity shall be resolved in favor of a meaning that complies and is consistent with Applicable Laws.

This DPA shall be governed by the governing law of the Province of Ontario.

United Kingdom Terms of Service, including Data Privacy Agreement

These Terms & Conditions (“Terms”) to the Practice Agreement (“Agreement”) are entered into by and between Zima Labs GB Ltd. d/b/a Dandy (“Dandy” or “we”) and you and your dental practice or office (“You”) and are effective as of the date the Practice Agreement is entered into (“Effective Date”). If you accept these Terms on behalf of an entity, partnership, corporation, or organization, “you” includes you, that entity, and all entity users and you hereby represent that you have the authority to bind all such users. Dandy and you will each be referred to as a “Party” and together, the “Parties.”  For good and valuable consideration as set forth in the Agreement, the Parties agree to the following:

1. Amendment. These Terms and the Agreement cannot be changed unless both Parties agree in writing. Dandy will notify You of any material changes. Changes become effective thirty (30) days after notification unless You terminate in writing. In such cases, Dandy will honor existing terms for 60 days or until the Hardware is returned.

2. Entire Agreement. The Practice Agreement, these Terms, the Data Privacy Agreement (Schedule A), and the IT Policy constitute the entire agreement. This Agreement supersedes all prior conflicting agreements.

3. Non-assignability. You may not transfer or assign this Agreement to a third party without Dandy’s prior written consent.

4. Legal Compliance. Both Parties agree to comply with all applicable health and data laws in the United Kingdom, including the UK GDPR, the Data Protection Act 2018,relevant NHS/GDC regulatory standards, and the Care Quality Commission (CQC).

5. Indemnity. You will indemnify, defend, and hold harmless Dandy from all claims or losses arising from: (a) Your breach of this Agreement or the DPA; (b) negligence or willful acts regarding patient care; (c) provision of incorrect clinical data; and (d) dealings with UK regulators (e.g., CQC, GDC, or the ICO).

6. Governing Law & Dispute Resolution. This Agreement is governed by the laws of England and Wales. Any disputes shall be resolved through arbitration under the Rules of the London Court of International Arbitration (LCIA). The seat of arbitration shall be London.

7. VAT & Tax. Dandy will charge Value Added Tax (VAT) at the prevailing rate, where applicable. If You are exempt, You must provide a valid VAT exemption certificate or evidence satisfactory to HMRC.

8. Data Privacy.  Because Dandy processes Special Category Data (Personal Health Data) on Your behalf, the Data Privacy Agreement (DPA) at Schedule A is a mandatory and integral part of this Agreement.

Data Protection Roles. The Parties acknowledge that:

Data Protection Contact. Any privacy-related notices or requests under this Agreement should be directed to Dandy’s Data Protection Officer (DPO) Tony Riesen at [email protected].


Schedule A: Data Privacy Agreement

This DPA is incorporated into the Agreement where Dandy acts as a Processor on behalf of the Practice (Controller). The nature, purpose, and duration of the processing are set out in Appendix 1 (Data Processing Details).

1. Definitions

2. Subject Matter & Instructions

Dandy shall process Personal Data only on the documented instructions of the Controller (the Practice), including with regard to transfers of personal data to a third country, unless required to do so by UK law. If Dandy believes any instruction infringes Applicable Laws, it shall immediately inform the Controller.

The Controller shall ensure it has a lawful basis for all sharing of Personal Data and a lawful ground for processing all Special Category Data.

3. Obligations of Dandy (The Processor)

4. International Transfers

Dandy shall not transfer Personal Data outside the UK or the EEA unless it ensures that the transfer is subject to “appropriate safeguards” (such as the UK International Data Transfer Agreement (IDTA) or an adequacy decision of the UK government).

5. Breach Notification

Dandy shall notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a Personal Data Breach affecting Personal Data, providing sufficient information to allow the Controller to meet any reporting obligations to the relevant data protection authority.

6. Deletion or Return

At the choice of the Controller, Dandy shall delete or return all Personal Data to the Controller after the end of the provision of services, and delete existing copies unless UK law requires storage.


APPENDIX 1: DATA PROCESSING DETAILS


Términos de servicio, incluido el Acuerdo de privacidad de datos

Los presentes términos y condiciones (“Condiciones”) del Acuerdo de Colaboración se suscriben entre Dandy Labs Europe SAS (anteriormente denominada Dandy Labs France SAS) (“Dandy” o “Nosotros”) y usted y su consulta o clínica dental (“Usted” o la “Clínica Dental”) y surtirán efecto a partir de la fecha en que se formalice el Acuerdo de Colaboración (“Fecha de Entrada en Vigor”). Si Usted acepta estas Condiciones en nombre de una entidad, sociedad, corporación u organización, el término “Usted” le incluye a Usted, a dicha entidad y a todos los usuarios de la entidad, y Usted declara que tiene autoridad para vincular a todos y a cada uno de dichos usuarios. Dandy y Usted serán denominados individualmente como “Parte” y conjuntamente como las “Partes”. Teniendo presente la contraprestación, válida y suficiente, establecida en el Acuerdo de Colaboración, las Partes establecen lo siguiente:

1. Modificación. Estas Condiciones y el Acuerdo de Colaboración podrán ser modificados mediante acuerdo mutuo por escrito entre las Partes. Estas Condiciones y el Acuerdo de Colaboración podrán también ser modificados por Dandy, y se le notificará cualquier cambio sustancial. Dichos cambios sustanciales surtirán efecto treinta (30) días después de su notificación, salvo que Usted resuelva el contrato mediante notificación por escrito dentro de dicho plazo. En tales casos, Dandy respetará las Condiciones vigentes durante sesenta (60) días o hasta la devolución del Equipo.

2. Acuerdo íntegro: El Acuerdo de Colaboración, estas Condiciones, la Política de Privacidad de la UE, el Acuerdo de Tratamiento de Datos (“ATD”) (Anexo A) y la Política de TI conforman el “Contrato“. El presente Contrato sustituye a todos los acuerdos anteriores con disposiciones que entren en conflicto con el mismo.

3. Intransmisibilidad. Usted no podrá ceder ni transmitir el Acuerdo de Colaboración a un tercero sin el consentimiento previo y por escrito de Dandy.

4. Cumplimiento normativo. Ambas partes se comprometen a cumplir todas las leyes aplicables en materia de salud y protección de datos en la jurisdicción en la que tanto Usted como Dandy estén establecidos, las normas reglamentarias pertinentes dictadas por las autoridades europeas y nacionales, y las directrices establecidas por los organismos reguladores profesionales.

5. Exención de responsabilidad. Usted indemnizará, defenderá y eximirá de responsabilidad a Dandy frente a cualquier reclamación o pérdida que se derive de: (a) el incumplimiento por su parte del Acuerdo; (b) negligencia o actos deliberados en relación con la atención al paciente; (c) el suministro de datos clínicos incorrectos; y (d) las relaciones con los organismos reguladores de la UE o nacionales.

6. Ley Aplicable y Jurisdicción.

  1. Ley Aplicable. Usted acepta que estas Condiciones se regirán e interpretarán de conformidad con la legislación de la jurisdicción en la que esté establecida la Clínica Dental.
  2. Jurisdicción. Cualquier controversia que surja de o en relación con estas Condiciones se someterá a la jurisdicción exclusiva de los tribunales de la jurisdicción correspondiente donde esté establecida la Clínica Dental, conforme a la siguiente tabla:
PaísJurisdicción
FranciaTribunal des Activités Économiques de Paris
EspañaJuzgados y Tribunales de Madrid

7. IVA e Impuestos. Dandy repercutirá el Impuesto sobre el Valor Añadido (“IVA”) al tipo impositivo aplicable, además de cualquier precio, cargo o cantidad adeudada en virtud del Contrato, y dicho IVA será a cargo de Usted, cuando proceda. Si Usted está exento, deberá aportar un certificado válido de exención de IVA o la documentación satisfactoria ante la administración tributaria correspondiente, cuando esté disponible, o justificar la base de la exención del IVA.

8. Protección de Datos. Teniendo en consideración que Dandy trata datos, incluidos datos de salud (“Datos Personales”), en nombre de Usted:

Funciones en materia de Protección de Datos: Las Partes reconocen que:

Contacto de Protección de Datos. Cualquier notificación o solicitud relativa a la privacidad en virtud de este Contrato deberá dirigirse al Delegado de Protección de Datos (“DPD”) de Dandy, Tony Riesen, a la dirección [email protected]

Anexo A: Acuerdo de Tratamiento de Datos (ATD)

     El presente ATD se incorpora al Contrato en los supuestos en que Dandy actúe como encargado del tratamiento en nombre de la Clínica Dental como responsable del tratamiento. La naturaleza, la finalidad y la duración del tratamiento se establecen en el Apéndice 1 (“Detalles del Tratamiento de Datos”).

1. Definiciones

2. Objeto e Instrucciones

Dandy tratará los datos personales únicamente siguiendo las instrucciones documentadas de la Clínica Dental, incluso en lo que respecta a las transferencias de datos personales a un tercer país, salvo que así lo exijan las leyes aplicables. Si Dandy considerase que alguna instrucción infringe la Ley Aplicable, informará inmediatamente a la Clínica Dental. 

La Clínica Dental se asegurará de contar con una base legal, de conformidad con el artículo 6 del RGPD, para el tratamiento de datos personales, así como con una exención, de conformidad con el artículo 9 del RGPD, para el tratamiento de Datos de Categoría Especial, en el contexto contemplado en el presente ATD.

3. Obligaciones de Dandy (el “Encargado del Tratamiento”)

4. Transferencias Internacionales

Dandy no transferirá datos personales fuera del EEE salvo que se garantice que la transferencia esté sujeta a “garantías adecuadas” (como una decisión de adecuación de la Comisión Europea).

5. Notificación de Violación de Seguridad de los Datos Personales

Dandy notificará a la Clínica Dental sin demora injustificada (y, en todo caso, en un plazo máximo de cuarenta y ocho (48) horas) tras tener conocimiento de una Violación de Seguridad de los Datos Personales que afecte a los Datos Personales, proporcionando información suficiente para que la Clínica Dental pueda cumplir con sus obligaciones de notificación ante la autoridad de control competente.

6. Supresión o devolución. 

A elección de la Clínica Dental, Dandy suprimirá o devolverá todos los Datos Personales a la Clínica Dental una vez finalizada la prestación de los servicios, y suprimirá las copias existentes, salvo que la Ley Aplicable exija su conservación.

Política de TI para el Equipo Proporcionado por Dandy a la Clínica Dental

La presente política se aplica únicamente a las Clínicas Dentales que utilizan su propio ordenador portátil y escáner como parte de su relación con Dandy.

Política de Sistemas Estándar:

Para garantizar la calidad y la coherencia del envío de casos a Dandy Labs, Usted se compromete a cumplir los siguientes requisitos relativos a su infraestructura de TI:

  1. Usted se compromete a utilizar únicamente el escáner intraoral 3Shape TRIOS 3, TRIOS 4 o TRIOS 5.
  2. Usted se compromete a proporcionar una conexión Wi-Fi estable de al menos 15 Mbps de subida y 15 Mbps de descarga en todas las ubicaciones donde se realice el envío de casos.
  3. Usted se compromete a utilizar un ordenador con el escáner intraoral 3Shape que cumpla los siguientes requisitos de sistema:
  4. PC Mínimo:

PC Recomendado:

  1. You agree to upgrade the Trios software to a minimum version of 1.7.19.1. Usted se compromete a actualizar el software Trios a una versión mínima de 1.7.19.1
  2. Usted se compromete a guardar y enviar todos los archivos de casos al almacenamiento local del ordenador.
  3. Usted se compromete a conceder EasyAccess a Splashtop al equipo de servicio de asistencia al cliente de Dandy con una contraseña compartida acordada mutuamente que se mantendrá durante la vigencia de la relación.
  4. Usted se compromete a instalar el DandyUploader en un perfil de usuario local y utilizará este perfil local en relación con su uso del software TRIOS.
  5. Usted se compromete a conceder permiso a las siguientes rutas de archivo si utiliza software antivirus:
  1. Si su Clínica Dental dispone de un cortafuegos de red, ya sea físico o basado en web, permita todo el tráfico en los siguientes dominios:

Conditions Générales + ADP

Les présentes conditions générales (« Conditions Générales ») de l’Accord de Collaboration sont conclues entre Dandy Labs Europe SAS (anciennement Dandy Labs France SAS) (« Dandy » ou « Nous ») et vous, ainsi que votre cabinet ou clinique dentaire (« Vous » ou le « Cabinet »), et prennent effet à la date de la conclusion de l’Accord de Collaboration (la « Date d’Entrée en Vigueur »). Si Vous acceptez les présentes Conditions Générales pour le compte d’une entité, d’une société de personnes, d’une société ou d’une organisation, « Vous » désigne Vous, ladite entité et l’ensemble des utilisateurs de l’entité, et Vous déclarez disposer du pouvoir de lier l’ensemble de ces utilisateurs. Dandy et Vous seront chacun désignés comme une « Partie » et, ensemble, les « Parties ». En contrepartie des stipulations de l’Accord de Collaboration, les Parties conviennent de ce qui suit :

1. Amendement. Les présentes Conditions Générales et l’Accord de Collaboration peuvent être modifiés d’un commun accord écrit entre les Parties. Elles peuvent également être modifiées par Dandy, qui Vous informera de toute modification substantielle. Ces modifications substantielles prendront effet trente (30) jours après leur notification, sauf si Vous résiliez le contrat par notification écrite dans ce délai. Dans ce cas, Dandy continuera d’appliquer les Conditions Générales en vigueur pendant soixante (60) jours ou jusqu’à ce que l’Équipement soit restitué.

2. Intégralité du Contrat. L’Accord de Collaboration, les présentes Conditions Générales, la Politique de Confidentialité, l’Accord de Protection des Données (« APD ») (Annexe B) et les Politiques Informatiques constituent l’intégralité du contrat (le « Contrat »). Le présent Contrat remplace et annule tout accord antérieur incompatible.

3. Incessibilité. Vous ne pouvez pas transférer ni céder l’Accord de Collaboration à un tiers sans l’accord écrit préalable de Dandy.

4. Conformité légale. Les Parties conviennent de se conformer à l’ensemble des lois applicables en matière de santé et de données dans la juridiction où Vous et Dandy êtes tous deux établis, aux normes réglementaires pertinentes édictées par les autorités européennes et nationales, ainsi qu’aux orientations publiées par les organismes de réglementation professionnelle.

5. Indemnisation. Vous vous engagez à indemniser, défendre et dégager Dandy de toute responsabilité au titre de toute réclamation ou perte résultant : (a) de votre violation du Contrat ; (b) de toute négligence ou de tout acte intentionnel relatif aux soins prodigués aux patients ; (c) de la fourniture de données cliniques inexactes ; et (d) de vos relations avec des autorités de régulation de l’Union européenne ou nationales.

6. Droit applicable et Compétence juridictionnelle. 

  1. Droit applicable. Vous acceptez que les présentes Conditions Générales soient régies par et interprétées conformément aux lois de la juridiction dans laquelle Vous êtes établi(e).
  1. Compétence juridictionnelle. Tout litige découlant des présentes Conditions Générales ou en lien avec celles‑ci sera soumis à la compétence exclusive des tribunaux de la juridiction applicable dans laquelle Vous êtes établi(e), comme indiqué dans le tableau ci‑dessous.
PaysJuridiction compétente
FranceTribunal des Activités Économiques de Paris
EspagneCours et tribunaux de Madrid

7. TVA & fiscalité. Dandy facturera la taxe sur la valeur ajoutée (« TVA ») au taux applicable, en sus de tout prix, frais, charge ou montant dû au titre du Contrat, et ladite TVA sera, le cas échéant, payable par Vous. Si Vous bénéficiez d’une exonération, Vous devrez fournir un certificat d’exonération de TVA valable ou tout justificatif jugé satisfaisant par l’administration fiscale compétente, lorsqu’un tel document est disponible, ou justifier le fondement de toute exonération de TVA.

8. Protection des données. Dans la mesure où Dandy traite, pour votre compte, des données à caractère personnel (« Données à Caractère Personnel »), y compris des données de santé, le contrat de sous-traitance en matière de protection des données figurant en Annexe B constitue une section obligatoire et fait partie intégrante du présent Contrat.

Rôles en matière de protection des données. Les Parties reconnaissent que :

Contact pour la protection des données. Toute notification ou demande relative à la protection des données au titre du présent Contrat doit être adressée au Délégué à la Protection des Données de Dandy (« DPD »), Tony Riesen, à l’adresse [email protected].

Annexe B : Contrat de sous-traitance en matière de protection des données 

Le présent contrat de sous-traitance en matière de protection des données (« DPA ») est incorporé au Contrat lorsque Dandy agit en qualité de sous-traitant pour le compte du Cabinet, agissant en qualité de responsable du traitement. La nature, la finalité et la durée du traitement sont précisées à l’Annexe B(1) (« Détails du Traitement de Données »).

1. Définitions

2. Objet & Instructions

Dandy ne traite les Données à Caractère Personnel que sur instructions documentées du Cabinet, y compris en ce qui concerne les transferts de Données à Caractère Personnel vers un pays tiers, et ce à moins que les Lois Applicables ne l’obligent à d’autres traitements. Si Dandy estime qu’une instruction du Cabinet enfreint les Lois Applicables, elle en informe immédiatement le Cabinet.

Le Cabinet veille à disposer d’une base légale au titre de l’article 6 du RGPD pour le traitement de toutes Données à Caractère Personnel, ainsi que d’une dérogation au titre de l’article 9 du RGPD pour le traitement de Données à Caractère Personnel Sensibles, dans le cadre de tout traitement envisagé par le présent DPA.

3. Obligations de Dandy (le « Sous-Traitant »)

4. Transferts Internationaux

Dandy ne transférera pas de Données à Caractère Personnel en dehors de l’Espace Economique Européen (« EEE ») à moins qu’elle ne s’assure que le transfert est soumis à des « garanties appropriées » (telles qu’une décision d’adéquation de la Commission Européenne).

5. Notification d’une Violation de Données à Caractère Personnel

Dandy notifiera le Cabinet sans retard injustifié (et en tout état de cause dans un délai de quarante-huit (48) heures) après avoir eu connaissance d’une Violation de Données à Caractère Personnel affectant des Données à Caractère Personnel, en fournissant des informations suffisantes pour permettre au Cabinet de satisfaire à toute obligation de notification auprès de l’autorité de protection des données compétente.

6. Suppression ou restitution

Au choix du Cabinet, Dandy supprimera ou restituera au Cabinet l’ensemble des Données à Caractère Personnel à l’issue de la fourniture des services, et supprimera les copies existantes, sauf si les Lois Applicables exigent une conservation continue.


Annexe B(1): DÉTAILS DU TRAITEMENT DES DONNÉES


Annexe B(2): MESURES DE SÉCURITÉ 

Politique informatique relative à l’équipement fourni aux cabinets et dentistes

Cette politique s’applique uniquement aux cabinets et aux dentistes qui utilisent leur propre ordinateur portable et leur propre scanner dans le cadre de leur relation avec Dandy.

Politique relative aux systèmes standards :

Afin de garantir la qualité et la cohérence des dossiers soumis à Dandy Labs, vous vous engagez à respecter les exigences suivantes concernant votre infrastructure informatique :

  1. Vous acceptez d’utiliser uniquement le scanner intra-oral 3Shape TRIOS 3, TRIOS 4 ou TRIOS 5.
  2. Vous acceptez de fournir une connexion Wi-Fi stable d’au moins 15 Mbps en débit montant et 15 Mbps en débit descendant dans tous les lieux où des dossiers sont soumis.
  3. Vous acceptez d’utiliser, avec le scanner intra-oral 3Shape, un ordinateur qui répond aux exigences système suivantes :
  4. PC (configuration minimale) :
    • Processeur : i7-10850H
    • Mémoire : 16 Go DDR4
    • Disque dur : 256 Go
    • Carte graphique : Quadro T1000 (4 Go)
    • Système d’exploitation : Windows 11 Pro

PC Recommandé:

  1. Vous acceptez de mettre à jour le logiciel TRIOS vers une version minimale 1.7.19.1.
  2. Vous acceptez d’enregistrer et de transmettre tous les dossiers vers le stockage local de l’ordinateur.
  3. Vous acceptez d’accorder à l’équipe du service client de Dandy un accès EasyAccess à Splashtop, grâce à un mot de passe partagé convenu d’un commun accord, qui restera valable pendant toute la durée de la relation.
  4. Vous acceptez d’installer DandyUploader dans le profil d’un utilisateur local et d’utiliser ce profil local dans le cadre de votre utilisation du logiciel TRIOS.
  5. Si vous utilisez un logiciel antivirus, vous acceptez d’autoriser l’accès au chemin d’accès suivant :
  1. Si votre cabinet dispose d’un pare-feu réseau, qu’il soit physique ou en ligne, veuillez autoriser tout le trafic vers les domaines suivants :

Termini e Condizioni all’Accordo di Collaborazione

I presenti termini e condizioni (“Termini”) all’Accordo di Collaborazione sono stipulati tra Dandy Labs Europe SAS (già Dandy Labs France SAS) (“Dandy” o “Noi”), e Lei e il Suo studio o ambulatorio odontoiatrico (“Lei” o “Studio”), dall’altro, e hanno efficacia a decorrere dalla data di efficacia dell’Accordo di Collaborazione (“Data di Efficacia”). Qualora Lei accetti i presenti Termini per conto di un ente, società di persone, società di capitali o altra organizzazione, il termine “Lei” comprende Lei, tale ente e tutti gli utenti che fanno riferimento all’ente, e Lei dichiara di avere l’autorità per vincolare tali utenti. Dandy e Lei saranno di seguito indicati singolarmente come “Parte” e congiuntamente come “Parti”. In considerazione del corrispettivo previsto nell’Accordo di Collaborazione, le Parti convengono quanto segue:

1. Fatturazione e Pagamenti: Tutti gli importi dovuti ai sensi del presente Contratto sono espressi in Euro (€) e potranno essere corrisposti esclusivamente mediante trasferimento in Euro (con eventuali commissioni di cambio e commissioni bancarie, ove applicabili, a Suo carico) e al netto dell’Imposta sul Valore Aggiunto (IVA) applicabile, che sarà, ove prevista, addebitata in aggiunta agli importi fatturati e corrisposta da Lei, previa ricezione di fattura valida ai sensi delle Leggi Applicabili. Accettiamo pagamenti tramite addebito diretto SEPA, bonifico bancario, carta di debito o carta di credito, e Lei è tenuto a mantenere un metodo di pagamento valido sempre disponibile. Il rispetto dei termini di pagamento è essenziale. Fermo restando quanto precede, le Parti convengono che tutte le fatture saranno pagate entro un termine massimo di trenta (30) giorni dalla data di ricevimento della fattura o, se successiva, dalla data di ricevimento dei beni o servizi. Sconti e promozioni non possono essere utilizzati per il pagamento di spese di elaborazione, spedizione, cancellazione o altri oneri. Dandy ha il diritto di addebitare (e Lei accetta di corrispondere) l’importo massimo di interessi consentito dalle Leggi Applicabili, ovvero l’1,5% mensile qualora le Leggi Applicabili non prevedano alcuna disposizione in merito. Gli interessi matureranno giornalmente dalla data di scadenza fino all’effettivo pagamento, sia prima che dopo l’eventuale pronuncia giudiziale. Dandy non accetta assegni cartacei, carte di credito prepagate, pagamenti peer-to-peer o criptovalute come metodi di pagamento validi. Qualora Lei abbia saldi insoluti per sessanta (60) giorni o più, ovvero l’importo dovuto a Dandy sia pari o superiore a 10.000 € (EUR), Dandy si riserva il diritto di sospendere il Suo account fino al saldo di tutti gli importi insoluti. In caso di persistente inadempimento, Dandy potrà risolvere o sospendere uno o tutti i contratti con Lei, senza che ciò comporti l’estinzione del debito o la cessazione della maturazione degli interessi. Lei è tenuto a gestire le aspettative dei Suoi pazienti in merito ai tempi di consegna dei Prodotti Dandy ordinati per loro conto.

Salvo quanto diversamente previsto di seguito, ciascuna Parte sarà esclusivamente responsabile dei propri obblighi fiscali derivanti dal presente Contratto. Tutti i pagamenti da Lei effettuati ai sensi del presente Contratto saranno corrisposti senza deduzione o ritenuta per imposte, salvo quanto richiesto dalle Leggi Applicabili. Nella misura in cui qualsiasi pagamento ai sensi del presente Contratto dia luogo a un obbligo a Suo carico di dedurre, trattenere o versare qualsiasi importo a qualsiasi autorità governativa ai sensi delle Leggi Applicabili, gli importi dovuti e pagabili ai sensi del presente Contratto saranno aumentati in modo che Noi riceviamo un importo pari a quello che avremmo ricevuto qualora tale deduzione o ritenuta non fosse stata effettuata. Ai fini della rendicontazione, Lei accetta di consegnare a Dandy la prova che tali imposte sono state versate a un’autorità governativa, incluso l’originale o una copia autenticata di una ricevuta rilasciata da tale autorità attestante il pagamento.

Lei riconosce altresì che Dandy ha comunicato la possibilità di commissioni di elaborazione e ha offerto l’opportunità di porre eventuali domande relative a tali commissioni prima della stipula del presente Contratto. Lei accetta di manlevare e tenere indenne Dandy da qualsiasi pretesa, danno o perdita derivante da eventuali sovraprezzi imposti da fornitori di servizi terzi. Dandy si riserva il diritto di modificare i prezzi dei Prodotti Dandy (come definiti di seguito) in qualsiasi momento, con un preavviso di quarantacinque (45) giorni. Lei accetta di non avere alcun diritto di compensazione, domanda riconvenzionale, deduzione o ritenuta a fronte di importi dovuti da Dandy a Lei. Lei accetta che Dandy possa in qualsiasi momento, e senza limitare altri diritti o rimedi di cui possa disporre, compensare qualsiasi importo da Lei dovuto con qualsiasi importo pagabile da Dandy a Lei. Dandy non accetta pagamenti da parte dei pazienti, inclusi i pagamenti a nome del paziente da Lei inoltrati.

2. Attrezzatura. Il rischio di perdita, furto, danno o distruzione dell’Attrezzatura passerà a Lei al momento della Consegna. L’Attrezzatura rimarrà a Suo esclusivo rischio per tutta la durata del presente Contratto e per qualsiasi ulteriore periodo durante il quale l’Attrezzatura sia in Suo possesso, custodia o controllo (il “Periodo di Rischio”) fino alla riconsegna dell’Attrezzatura a Dandy. Lei dovrà dare immediata comunicazione scritta a Dandy in caso di perdita, incidente o danno all’Attrezzatura derivante da o connesso al Suo possesso o utilizzo dell’Attrezzatura.

3. Requisiti IT. Lei accetta di fornire e mantenere una connessione internet ad alta velocità da utilizzare in connessione con l’Attrezzatura, e Lei accetta di rispettare le Policy IT incluse nei termini e condizioni online.

4. Manleva: Lei manleverà, terrà indenne, difenderà e terrà indenne Dandy da e contro qualsiasi pretesa, causa d’azione, danno, debito, responsabilità, perdita, obbligo, pagamento, costo e spesa (incluse le spese legali), derivanti da o relativi a: (a) una Sua violazione di qualsiasi termine di qualsiasi contratto con Dandy; (b) una Sua violazione di qualsiasi termine di qualsiasi contratto tra Lei e il Suo paziente o qualsiasi atto o omissione nei confronti di un paziente (incluse azioni da parte di qualsiasi organismo professionale che La regola o di qualsiasi autorità regolatoria o organismo di abilitazione nazionale) ivi inclusi, senza limitazione alcuna, gli atti di negligenza o dolosi relativi all’assistenza al paziente ovvero alla fornitura di dati clinici inesatti; e (c) fornitura da parte Sua di informazioni, documenti, scansioni o impronte inesatti o incompleti o mancata tempestiva fornitura a Dandy di qualsiasi informazione da Noi richiesta.

5. Cambio di Controllo dello Studio: Qualora il Suo studio odontoiatrico subisca un Cambio di Controllo dal punto di vista proprietario, Lei accetta di informare Dandy mediante comunicazione scritta entro cinque (5) giorni lavorativi prima della data in cui tale Cambio di Controllo diventi efficace. Ai fini della presente clausola, una situazione di “Cambio di Controllo” includerà qualsiasi operazione o serie di operazioni che comporti un cambiamento nella titolarità diretta o indiretta di oltre il cinquanta percento (50%) dei diritti di voto o del capitale sociale del Suo studio odontoiatrico, ovvero qualsiasi fusione, consolidamento o vendita di sostanzialmente tutti i suoi asset.

6. Esclusione di Responsabilità Medica: Il Suo studio è l’unico responsabile del trattamento dei pazienti mediante l’utilizzo di qualsiasi Offerta Dandy, e della fornitura ai Suoi pazienti di tutte le informazioni pertinenti relative alle Offerte Dandy e a qualsiasi rischio correlato, prima e dopo il trattamento. Le Offerte Dandy sono offerte esclusivamente come supplemento al Suo studio odontoiatrico e non costituiscono consulenza medica, odontoiatrica o di altro tipo sanitario, diagnosi o trattamento per i Suoi pazienti. Lei accetta di non rilasciare alcuna dichiarazione o garanzia ai Suoi pazienti in merito alle Offerte Dandy. Lei dichiara a Dandy che il Suo studio rispetterà tutte le Leggi Applicabili, i regolamenti, le linee guida e i codici deontologici professionali relativi ai professionisti autorizzati a esercitare l’odontoiatria e a effettuare scansioni intraorali sui pazienti dello studio. Salvo quanto diversamente ed espressamente previsto nel presente documento, le Offerte Dandy a Lei fornite ai sensi del presente Contratto sono fornite “COSÌ COME SONO” e sono fornite ai sensi della Sua prescrizione per il singolo paziente.

Le Parti riconoscono che il presente Contratto non crea alcun rapporto contrattuale diretto tra Dandy e i Suoi pazienti. Qualsiasi pretesa, richiesta o azione promossa da un paziente o da un’autorità regolatoria derivante dalle Sue decisioni cliniche, dalla gestione del trattamento, da errori di prescrizione o dalla fornitura di dati errati (quali scansioni o impronte difettose) sarà soggetta ai Suoi pieni obblighi di manleva di cui alla sezione 4.

Lei accetta di adempiere ai Suoi obblighi ai sensi del Regolamento (UE) 2017/745 sui dispositivi medici, nella misura applicabile. Lei accetta di gestire tutte le comunicazioni e le altre attività relative a qualsiasi richiamo o altra attività regolatoria in conformità a tutte le Nostre ragionevoli istruzioni e di non contattare o comunicare in altro modo con un’autorità competente prima di averci consultato. Il presente obbligo, nonché le relative disposizioni di manleva di cui alla sezione 5 dei Termini e Condizioni Online, sopravvivranno alla risoluzione del presente Accordo di Collaborazione per il periodo in cui i dispositivi medici da Noi forniti rimarranno in uso.

7. Modifica. I presenti Termini e l’Accordo di Collaborazione potranno essere modificati mediante accordo scritto tra le Parti. I presenti Termini e l’Accordo di Collaborazione potranno altresì essere modificati da Dandy, che Le comunicherà eventuali modifiche sostanziali. Tali modifiche sostanziali acquisteranno efficacia decorsi trenta (30) giorni dalla notifica, salvo che Lei receda dal Contratto mediante comunicazione scritta entro tale termine. In caso di recesso da parte Sua ai sensi della presente clausola, Dandy rispetterà i Termini vigenti per sessanta (60) giorni o fino alla restituzione dell’Attrezzatura.

8. Intero accordo. L’Accordo di Collaborazione, i presenti Termini, l’Informativa sulla Privacy UE, l’Accordo sul Trattamento dei Dati (“DPA”) (Allegato A) e la Policy IT costituiscono l’intero accordo tra le Parti (il “Contratto”). Il presente Contratto sostituisce e supera ogni precedente e confliggente accordo o intesa tra le Parti.

9. Divieto di cessione. Lei non potrà trasferire né cedere l’Accordo di Collaborazione a terzi senza il previo consenso scritto di Dandy.

10. Conformità alla normativa. Le Parti si impegnano a rispettare tutte le leggi applicabili in materia sanitaria e di protezione dei dati applicabili nel Paese dove Lei e Dandy avete sede, gli standard normativi emanati dalle autorità europee e nazionali, nonché le linee guida emanate dagli organismi professionali di regolamentazione.

11. Manleva. Lei manleverà, difenderà e terrà indenne Dandy da qualsiasi pretesa o perdita derivante da fatti, omissioni o violazioni imputabili allo Studio, inclusi: (a) una Sua violazione del Contratto; (b) negligenza o atti dolosi relativi all’assistenza ai pazienti; (c) fornitura di dati clinici inesatti; e (d) rapporti con le autorità regolatorie dell’UE o nazionali.

12. Legge applicabile e foro competente.

  1. Legge applicabile. I presenti Termini sono disciplinati e interpretati in conformità alle leggi della giurisdizione in cui ha sede lo Studio.
  2. Foro competente. Qualsiasi controversia derivante dai presenti Termini o connessa agli stessi sarà devoluta alla giurisdizione dei tribunali del Paese in cui ha sede lo Studio e, nell’ambito di tale giurisdizione, alla competenza esclusiva del foro indicato, per tale Paese, nella tabella seguente.
PaeseGiurisdizione
FranciaTribunal des Activités Économiques de Paris
Irlanda Tribunali competenti di Dublino 
ItaliaTribunale di Milano
Paesi Bassi Il tribunale competente di Amsterdam, Paesi Bassi
SpagnaCorti e tribunal di Madrid 

13. IVA e imposte. Dandy addebiterà l’Imposta sul Valore Aggiunto (“IVA”) all’aliquota applicabile, in aggiunta a qualunque prezzo, onere o importo dovuto ai sensi del Contratto; tale IVA sarà a Suo carico, ove applicabile. Qualora Lei sia esente, dovrà fornire un certificato di esenzione IVA valido o idonea documentazione per la competente amministrazione fiscale, ove disponibile, oppure giustificare la base dell’esenzione IVA.

14. Protezione dei dati personali. La presente clausola disciplina il trattamento da parte di Dandy di dati personali, inclusi dati sanitari (“Dati Personali”), per Suo conto. 

Ruoli in Materia di Protezione dei Dati. Le Parti riconoscono che

Contatto per la Protezione dei Dati. Eventuali comunicazioni o richieste relative  al presente Contratto devono essere indirizzate a Dandyall’indirizzo [email protected].

Allegato A: Accordo sul Trattamento dei Dati (o DPA)

Il presente DPA forma parte del Contratto, ai sensi del quale Dandy opera in qualità di responsabile del trattamento per conto dello Studio, che opera in qualità di titolare del trattamento. La natura, la finalità e la durata del trattamento sono stabilite nell’Appendice 1 (“Dettagli del Trattamento dei Dati”).

1. Definizioni

2. Oggetto e Istruzioni

Dandy tratterà i Dati Personali esclusivamente sulla base delle istruzioni documentate dello Studio, anche per quanto riguarda i trasferimenti di Dati Personali verso un paese terzo, salvo che ciò sia richiesto dalle Leggi Applicabili, alle quali Dandy è soggetto; in tal caso, Dandy informerà lo Studio di tale obbligo di legge prima del Trattamento, salvo che la legge vieti tale informazione per rilevanti motivi di interesse pubblico. Qualora Dandy ritenga che un’istruzione violi le Leggi Applicabili, ne informerà immediatamente lo Studio e avrà il diritto di sospendere l’esecuzione dell’istruzione pertinente fino a quando lo Studio non la confermi, la modifichi o la revochi. Eventuali istruzioni orali dovranno essere confermate dallo Studio per iscritto senza indebito ritardo.

Lo Studio dovrà assicurarsi di disporre di una base giuridica ai sensi dell’Articolo 6 del GDPR per il trattamento dei Dati Personali, nonché di una deroga ai sensi dell’Articolo 9 del GDPR per il trattamento delle Categorie Particolari di Dati, nel contesto previsto dal presente

3. Obblighi di Dandy (il “Responsabile del Trattamento”)      

Sicurezza: Dandy adotterà misure tecniche e organizzative appropriate per garantire un livello di sicurezza adeguato al rischio, tenendo conto dello stato dell’arte, dei costi di attuazione e della natura, dell’ambito, del contesto e delle finalità del Trattamento, come ulteriormente dettagliato nell’Appendice 2. Dandy potrà di volta in volta aggiornare o modificare le misure di sicurezza di cui all’Appendice 2, a condizione che tali aggiornamenti o modifiche non riducano sostanzialmente il livello complessivo di protezione garantito ai Dati Personali.

4. Sub-responsabili

4.1 Con la presente, lo Studio autorizza Dandy in via generale e per iscritto a nominare i sub-responsabili elencati nel Trust Center di Dandy, disponibile all’indirizzo https://trust.meetdandy.com/subprocessors, e in conformità al presente articolo 4.

4.2 Qualora Dandy nomini un nuovo sub-responsabile o intenda apportare modifiche relative all’aggiunta o alla sostituzione di sub-responsabili, ne darà comunicazione scritta allo Studio con un preavviso di venti (20) giorni lavorativi, durante i quali lo Studio potrà opporsi alla nomina o alla sostituzione per motivi ragionevoli e documentati relativi alla riservatezza o alla sicurezza dei Dati Personali o alla conformità del sub-responsabile alle Leggi Applicabili. Qualora lo Studio non si opponga, Dandy potrà procedere con la nomina o la sostituzione. Qualora lo Studio si opponga e Dandy non possa ragionevolmente accogliere l’opposizione, lo Studio potrà risolvere il presente DPA e il Contratto mediante comunicazione scritta. Dandy garantirà di avere in essere un contratto scritto con tutti i sub-responsabili che imponga al sub-responsabile obblighi non meno onerosi di quelli imposti a Dandy ai sensi del presente DPA.

5. Obblighi dello Studio

5.1 Lo Studio garantisce che: (i) la normativa ad esso applicabile non impedisce a Dandy di adempiere alle istruzioni ricevute dallo Studio e di eseguire gli obblighi di Dandy ai sensi del presente DPA; e (ii) ha rispettato e continua a rispettare le Leggi Applicabili, in particolare che ha ottenuto tutti i consensi necessari o ha fornito tutte le comunicazioni necessarie, e dispone comunque di una base legittima per comunicare i dati a Dandy e consentire il Trattamento dei Dati Personali da parte di Dandy come previsto nel presente DPA.

5.2 Lo Studio accetta di manlevare e tenere indenne Dandy, su richiesta, da e contro qualsiasi pretesa, responsabilità, costo, spesa, perdita o danno (incluse perdite consequenziali, perdita di profitto e perdita di reputazione e tutti gli interessi, le penali e i costi e le spese legali e professionali) sostenuti da Dandy derivanti direttamente o indirettamente da una violazione del presente articolo 5.

6. Modifiche alle Leggi Applicabili

Le Parti si impegnano a negoziare in buona fede modifiche al presente DPA qualora siano necessarie affinché Dandy possa continuare a trattare i Dati Personali come previsto dal presente DPA in conformità alle Leggi Applicabili, incluso (i) per conformarsi al GDPR o a qualsiasi normativa nazionale di attuazione dello stesso, e a qualsiasi orientamento sull’interpretazione delle rispettive disposizioni; (ii) qualora le SCC o qualsiasi altro meccanismo o decisione di adeguatezza siano invalidati o modificati; o (iii) qualora modifiche allo status di appartenenza di un paese all’Unione Europea o allo Spazio Economico Europeo richiedano tale modifica.

7. Trasferimenti Internazionali

Dandy non trasferirà Dati Personali al di fuori dello Spazio Economico Europeo a meno che non garantisca che il trasferimento sia soggetto a garanzie adeguate ai sensi dell’Articolo 46 del GDPR. Tali garanzie adeguate possono includere: (a) una decisione di adeguatezza della Commissione Europea ai sensi dell’Articolo 45 del GDPR; (b) SCC adottate dalla Commissione Europea ai sensi dell’Articolo 46(2)(c) del GDPR; (c) certificazione ai sensi del Data Privacy Framework UE-USA; o (d) qualsiasi altro meccanismo di trasferimento valido ai sensi delle Leggi Applicabili.

8. Notifica di Violazione dei Dati Personali

Dandy notificherà lo Studio senza ingiustificato ritardo (e in ogni caso entro 72 ore) nel caso in cui venga a conoscenza di una Violazione dei Dati Personali che interessa i Dati Personali, fornendo informazioni sufficienti per consentire allo Studio di adempiere a eventuali obblighi di segnalazione all’autorità di controllo competente. Ulteriori informazioni sulla Violazione dei Dati Personali saranno fornite gradualmente man mano che ulteriori dettagli saranno disponibili.

9. Cancellazione o Restituzione

A scelta dello Studio, Dandy cancellerà o restituirà tutti i Dati Personali allo Studio al termine della fornitura dei servizi, e cancellerà le copie esistenti salvo che le Leggi Applicabili ne richiedano la conservazione continuata. 

APPENDICE 1: DETTAGLI DEL TRATTAMENTO DEI DATI

APPENDICE 2: MISURE DI SICUREZZA

EU German

Diese Allgemeinen Geschäftsbedingungen („AGB“) zum Praxisvertrag werden zwischen Dandy Labs Europe SAS (vormals Dandy Labs France SAS) („Dandy“ oder „wir“) und Ihnen sowie Ihrer Zahnarztpraxis oder -klinik („Sie“ oder „Praxis“) geschlossen und treten mit Abschluss des Praxisvertrags in Kraft („Inkrafttreten“). Wenn Sie diese AGB im Namen eines Unternehmens, einer Personengesellschaft, einer Kapitalgesellschaft oder einer sonstigen Organisation abschließen, umfasst „Sie“ sowohl Sie persönlich als auch dieses Unternehmen und alle Nutzer des Unternehmens. Sie versichern , dass Sie zur vertraglichen Verpflichtung all dieser Nutzer befugt sind. Dandy und Sie werden jeweils als „Partei“ und gemeinsam als die „Parteien“ bezeichnet. Im Hinblick auf die im festgelegten gegenseitigen Leistungen vereinbaren die Parteien Folgendes:

1. Änderung. Diese AGB und der Praxisvertrag können durch beiderseitige schriftliche Vereinbarung der Parteien geändert werden. Diese AGB und der Praxisvertrag können anderweitig von Dandy geändert werden, und Dandy wird Sie über wesentliche Änderungen informieren. Solche wesentlichen Änderungen treten dreißig (30) Tage nach der Benachrichtigung in Kraft, es sei denn, Sie kündigen den Vertrag innerhalb dieses Zeitraums durch schriftliche Mitteilung. In diesem Fall wird Dandy die bestehenden AGB für sechzig (60) Tage oder bis zur Rückgabe der Ausrüstung einhalten.

2. Vollständiger Vertrag. Der Praxisvertrag, diese AGB, unsere EU-Datenschutzerklärung, der Auftragsverarbeitungsvertrag („AVV“) (Anlage A) und die IT-Richtlinie bilden den „Vertrag“. Dieser Vertrag ersetzt alle früheren entgegenstehenden Vereinbarungen und Absprachen.

3. Abtretungsverbot. Sie dürfen den Praxisvertrag nicht ohne vorherige schriftliche Zustimmung von Dandy an Dritte übertragen oder abtreten.

4. Einhaltung gesetzlicher Vorschriften. Beide Parteien verpflichten sich, alle anwendbaren Gesundheits- und Datenschutzgesetze der Rechtsordnung einzuhalten, in der sowohl Sie als auch Dandy ansässig sind, sowie die einschlägigen regulatorischen Standards, die von europäischen und nationalen Behörden erlassen wurden, und die Leitlinien, die von berufsständischen Aufsichtsbehörden herausgegeben wurden.

5. Freistellung. Sie stellen Dandy von sämtlichen Ansprüchen und Schäden frei, verteidigen Dandy gegen solche Ansprüche und halten Dandy insoweit schadlos, die sich aus Folgendem ergeben: (a) Ihrem Verstoß gegen den Vertrag; (b) Fahrlässigkeit oder vorsätzlichen Handlungen im Zusammenhang mit der Patientenversorgung; (c) der Bereitstellung unrichtiger klinischer Daten; und (d) dem Umgang mit Aufsichtsbehörden auf Unionsebene oder nationaler Ebene.

6. Anwendbares Recht und Gerichtsstand. 

  1. Anwendbares Recht. Sie erklären sich damit einverstanden, dass diese Bedingungen dem Recht der Rechtsordnung unterliegen, in der die Praxis niedergelassen ist, und nach diesem ausgelegt werden.
  2. Gerichtsstand. Für sämtliche Streitigkeiten, die sich aus oder im Zusammenhang mit diesen Bedingungen ergeben, sind ausschließlich die Gerichte der jeweils maßgeblichen Rechtsordnung zuständig, in der die Praxis niedergelassen ist, wie in der nachstehenden Tabelle aufgeführt.
LandZuständigkeit
FrankreichTribunal des Activités Économiques de Paris
SpanienGerichte und Tribunale von Madrid

7. Steuern. Dandy wird die Umsatzsteuer („USt“) zum jeweils geltenden Satz zusätzlich zu jedem Preis, jeder Gebühr oder jedem nach dem Vertrag geschuldeten Betrag berechnen. Diese Umsatzsteuer ist, soweit anwendbar, von Ihnen zu zahlen. Sind Sie von der Steuer befreit, müssen Sie eine gültige Umsatzsteuerbefreiungsbescheinigung oder einen für die zuständige Finanzbehörde zufriedenstellenden Nachweis vorlegen, sofern verfügbar, oder die Grundlage für die Umsatzsteuerbefreiung darlegen.

8. Datenschutz. Dandy verarbeitet personenbezogene Daten, einschließlich Gesundheitsdaten („Personenbezogene Daten”), in Ihrem Auftrag gemäß diesem Vertrag.

Datenschutzrechtliche Rollenverteilung. Die Parteien erkennen an, dass

Datenschutzbeauftragter. Alle datenschutzbezogenen Mitteilungen oder Anfragen im Rahmen dieses Vertrags sind an den Datenschutzbeauftragten von Dandy („DSB“), Tony Riesen, unter [email protected] zu richten.

Anlage A: Auftragsverarbeitungsvertrag (oder AVV)

Dieser AVV wird in den Vertrag einbezogen, wenn Dandy als Auftragsverarbeiter im Auftrag der Praxis als Verantwortlicher handelt. Gegenstand, Zweck und Dauer der Verarbeitung sind in Anhang 1 („Einzelheiten der Datenverarbeitung”) festgelegt.

1. Begriffsbestimmungen

2. Gegenstand und Weisungen

Dandy verarbeitet Personenbezogene Daten nur auf dokumentierte Weisung der Praxis, auch in Bezug auf die Übermittlung Personenbezogener Daten in ein Drittland, es sei denn, Dandy ist nach dem für Dandy geltenden anwendbaren Recht zur Verarbeitung verpflichtet. Ist Dandy der Ansicht, dass eine Weisung gegen das anwendbare Recht verstößt, unterrichtet es die Praxis unverzüglich.

Die Praxis stellt sicher, dass sie über eine Rechtsgrundlage gemäß Artikel 6 der DSGVO für die Verarbeitung Personenbezogener Daten sowie über eine Ausnahme gemäß Artikel 9 der DSGVO für die Verarbeitung besonderer Kategorien Personenbezogener Daten im Rahmen dieses AVV verfügt.

3. Pflichten von Dandy (dem Auftragsverarbeiter)

4. Internationale Datenübermittlungen

Dandy darf Personenbezogene Daten nicht außerhalb des EWR übermitteln, es sei denn, Dandy stellt sicher, dass die Übermittlung „geeigneten Garantien” unterliegt (z. B. einem Angemessenheitsbeschluss der Europäischen Kommission).

5. Meldung von Verletzungen des Schutzes Personenbezogener Daten

Dandy benachrichtigt die Praxis unverzüglich (und in jedem Fall innerhalb von 48 Stunden) nach Kenntniserlangung von einer Verletzung des Schutzes Personenbezogener Daten und stellt ausreichende Informationen zur Verfügung, damit die Praxis etwaigen Meldepflichten gegenüber der zuständigen Datenschutzbehörde nachkommen kann.

6. Löschung oder Rückgabe

Nach Aufforderung durch die Praxis löscht Dandy alle Personenbezogenen Daten oder gibt sie an die Praxis zurück, nachdem die Erbringung der Dienstleistungen beendet ist, und löscht vorhandene Kopien, es sei denn, nach dem anwendbaren Recht ist eine Aufbewahrung erforderlich.

ANHANG 1: EINZELHEITEN DER DATENVERARBEITUNG

ANHANG 2: TECHNISCHE UND ORGANISATORISCHE MAßNAHMEN

EU Ireland

These additional terms & conditions (“Terms”) to the Practice Agreement including the EU Privacy Policy, and the Data Privacy Agreement form part of the Agreement (together the “Agreement”) are entered into by and between Dandy Labs Europe SAS (“Dandy” or “We”), and you and your dental practice or office (“You” or “Practice”), and are effective as of the date the Practice Agreement is entered into (“Effective Date”). If You accept the Agreement  on behalf of an entity, partnership, corporation, or organization, “You” includes You, that entity, and all entity users and You hereby represent that You have the authority to bind all such users. Dandy and You will each be referred to as a “Party” and together, the “Parties”. Terms defined herein or elsewhere in the Agreement shall have the defined term apply across the Agreement. For good and valuable consideration as set forth in the Practice Agreement, the Parties agree to the following:

1. Billing & Payments: All amounts payable pursuant to this Agreement are in Euros (€) and may be made by transfer of Euros only (with any foreign exchange fees and bank fees, if applicable, borne by You) and exclusive of applicable Value Added Tax (VAT that shall, where applicable, be charged in addition to the invoiced amounts and paid by You, upon receipt of a valid invoice as required by Applicable Law).  We accept payment by SEPA Direct Debit, bank transfer, debit card or credit card, and You are required to keep a valid payment method on file at all times. Time of payment is of the essence. Without prejudice to the foregoing, the Parties agree that all invoices shall be paid within a maximum period of thirty (30) days from the date of receipt of the invoice or, if later, from the date of receipt of goods or services. Discounts and promotions cannot be used to pay for processing, shipping, cancellation, or other fees. Dandy has the right to charge (and You agree to pay) the maximum interest amount allowed by Applicable Law, or 1.5% per month if none is specified by Applicable Law. Interest shall accrue daily from the due date until actual payment, whether before or after judgment. Dandy does not accept paper checks, prepaid credit cards, peer-to-peer payments, or cryptocurrency as valid payment methods. In the event You have any unpaid balances for sixty (60) days or more, or the amount owed to Dandy is 10,000 € (EUR) or more, Dandy reserves the right to pause your account until all unpaid balances are remitted. In the event of continuing non-payment, Dandy may cancel or suspend any or all agreements with You, which shall not extinguish the debt or any accrual of interest. You are expected to manage your patients’ expectations of the timing of the supply of the Dandy Products ordered for them accordingly. 

Except as provided below, each Party shall be solely responsible for its own tax obligations arising in connection with this Agreement. All payments by You under this Agreement shall be made without deduction or withholding for any taxes, except as required by Applicable Law. To the extent any payment under this Agreement gives rise to any obligation on You to deduct, withhold, or remit any amount to any governmental authority under Applicable Law, the amounts due and payable under this Agreement shall be increased so that We receive an amount equal to the amount we would have received had no such deduction or withholding been made. For reporting purposes, You agree to deliver to Dandy evidence that such taxes were paid to a governmental authority, including the original or a certified copy of a receipt issued by that authority evidencing the payment.

You further acknowledge that Dandy has disclosed the possibility of processing fees and has provided the opportunity to ask any questions regarding such fees prior to entering this Agreement. You agree to indemnify and hold Dandy harmless from any claims, damages, or losses arising from any such surcharges imposed by third-party service providers. Dandy reserves the right to change pricing for Dandy Products (defined below) at any time upon forty-five (45) days’ notice. You agree that You shall have no right of set-off, counterclaim deduction or withholding against amounts owed by Dandy to You. You agree that Dandy may at any time and without limiting any other rights or remedies it may have, set-off any amount owing by You against any amount payable by Dandy to You. Dandy does not accept payments from patients, including payments in the patient’s name forwarded by You.

2. Equipment. The risk of loss, theft, damage or destruction of the Equipment shall pass to You on Delivery. The Equipment shall remain at your sole risk during the term of this Agreement and any further term during which the Equipment is in your possession, custody or control (the “Risk Period“) until the Equipment is redelivered to Dandy. You shall give immediate written notice to Dandy in the event of any loss, accident or damage to the Equipment arising out of or in connection with your possession or use of the Equipment.

3. IT Requirements. You agree to provide and maintain a high-speed internet connection for use in connection with the Equipment, and You agree to follow the IT Policies included in the online terms and conditions.

4. Indemnity: You shall indemnify, keep indemnified, defend and hold harmless Dandy against and from any and all claims, causes of actions, damages, debts, liabilities, losses, obligations, payments, costs and expenses (including legal expenses), arising from or relating to: (a) breach by You of any term of any agreement with Dandy; (b) breach by You of any term of any agreement between You and your patient or any acts or failures in respect of a patient (including actions by any professional body regulating You or any national regulator(s) or licensing body), including without limitation, negligence or willful acts regarding patient care or the provision of any incorrect clinical data; and (c) provision by You of incorrect or incomplete information, documents, scans or impressions or failure to timely provide Dandy with any information we request from You.

5. Practice Change of Control: If your dental practice undergoes a Change of Control from an ownership perspective, You agree to inform Dandy with written notice within five (5) business days before the day such Change of Control becomes effective. For the purposes of this clause, a “Change of Control” situation shall include any transaction or series of transactions resulting in a change in the direct or indirect ownership of more than fifty percent (50%) of the voting rights or share capital of your dental practice, or any merger, consolidation, or sale of substantially all of its assets.

6. Medical Disclaimer: Your practice is solely responsible for the treatment of patients using any Dandy Offerings, and for providing your patients with all relevant information about the Dandy Offerings and any related risk prior to and after treatment. The Dandy Offerings are offered solely as a supplement to your dental practice and do not constitute medical, dental or other healthcare advice, diagnosis or treatment to or for your patients. You agree not to make any representations or warranties regarding the Dandy Offerings to your patients. You represent to Dandy that your practice will comply with all Applicable Law, regulations, guidance and professional codes of conduct regarding professionals who are authorized to practice dentistry and to conduct intraoral scans on practice patients. Except as otherwise expressly provided herein, the Dandy Offerings provided to you hereunder are provided “AS IS” and are provided pursuant to your prescription for the individual patient. 

The Parties acknowledge that this Agreement creates no direct contractual relationship between Dandy and Your patients. Any claims, demands, or actions brought by a patient or regulatory body arising out of your clinical decisions, treatment management, prescription errors, or the provision of faulty data (such as defective scans or impressions) shall be subject to your full indemnification obligations as set out in section 4.

You agree to comply with your obligations under Regulation (EU) 2017/745 on medical devices to the extent applicable. You agree to handle all communications and other activities in relation to any recall or other regulatory activity in accordance with all our reasonable instructions and to not reach out or otherwise communicate with a competent authority prior to consultation with us. This obligation as well as related indemnification arrangements of the Online Terms and Conditions shall survive termination of this Practice Agreement for the period medical devices supplied by us remain in use.

7. Amendment. These Terms and the Agreement may be changed by mutual written agreement of the Parties. These Terms and the Agreement may otherwise be amended by Dandy and Dandy will notify You of any material changes. Such material changes shall become effective thirty (30) days after notification unless You terminate by written notice within that period. In such cases, Dandy will honor existing Terms for sixty (60) days or until the Equipment is returned.

8. Entire Agreement. The Practice Agreement, these Terms, the EU Privacy Policy, the Data Privacy Agreement (“DPA”) (Schedule A), and the IT Policy constitute the “Agreement”. This Agreement supersedes all prior conflicting agreements.

9. Non-assignability. You may not transfer or assign the Agreement to a third party without Dandy’s prior written consent.

10. Legal Compliance. Both Parties agree to comply with all applicable health and data laws in the jurisdiction where You and Dandy are both established, relevant regulatory standards issued by European and national authorities, and guidance issued by professional regulatory bodies.

11. Governing Law & Jurisdiction. 

  1. Governing Law. You agree that the Agreement shall be governed by and construed in accordance with the laws of the jurisdiction where the Practice is established. 
  2. Jurisdiction. Any disputes arising out of or in connection with the Agreement shall be submitted to the exclusive jurisdiction of the courts of the applicable jurisdiction where the Practice is established, as set forth in the table below.
CountryJurisdiction
FranceTribunal des Activités Économiques de Paris
IrelandCourts of Dublin 
ItalyTribunal of Milan
The NetherlandsThe competent court in Amsterdam, the Netherlands
SpainCourts and Tribunals of Madrid

12. VAT & Tax. Dandy will charge Value Added Tax (“VAT”) at the applicable rate in addition to any price, charge or amount due under the Agreement and such VAT shall be payable by You, where applicable. If You are exempt, You must provide a valid VAT exemption certificate or evidence satisfactory to the relevant tax administration, when available or justify the basis for the VAT exemption.

13. Data Privacy. Because Dandy processes personal data, including health data (“Personal Data”) on your behalf.

Data Protection Roles. The Parties acknowledge that:

Data Protection Contact. Any privacy-related notices or requests under this Agreement should be directed to Dandy at [email protected]

Schedule A: Data Privacy Agreement (“DPA”)

This DPA is incorporated into the Agreement where Dandy acts as a processor on behalf of the Practice as controller. The nature, purpose, and duration of the processing are set out in Appendix 1 (“Data Processing Details”).

1. Definitions

●      “Applicable Laws” means all applicable laws that govern the processing and security of Personal Data as well as the privacy of electronic communications, including, without limitation, (i) Regulation (EU) 2016/679 of 27 April 2016 (the GDPR), (ii) Directive 2002/58/EC of 12 July 2002 (the ePrivacy Directive), (iii) domestic laws implementing and supplementing the EU laws referred to in this definition, and (iv) the relevant provisions of national health laws, each of (i) to (iv) as amended and/or supplemented from time to time.

●      “Personal Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data, or any other event affecting the integrity, availability or confidentiality of Personal Data.

●      “Special Category Data” means the categories of Personal Data referred to in Article 9 of the GDPR (including but not limited to Personal Data concerning health, biometric data, or data used for the purpose of uniquely identifying a natural person and genetic data).

●      “Personal Data” means personal data (as defined by the GDPR) processed by Dandy on behalf of the Practice.

●      “Data Subject” has the meaning given in the GDPR.

●      “Regulator” means a data protection supervisory authority which has jurisdiction over the Practice’s Processing of Personal Data.

●      “SCCs” means the standard contractual clauses for the transfer of personal data to third countries set out in Commission Decision 2021/914 of 4 June 2021, as amended, updated or replaced from time to time.

●      “Third Country” means any country or territory outside of the scope of the data protection laws of the European Economic Area, excluding countries or territories approved as providing adequate protection for personal data by the European Commission from time to time.

●      “Data Privacy Framework” means, as relevant, the EU-US Data Privacy Framework as administered by the US Department of Commerce and approved by the European Commission as ensuring an adequate level of protection for personal data for the purposes of Article 45 GDPR, as in force, amended, consolidated, re-enacted or replaced from time to time.

2. Subject Matter & Instructions

Dandy shall process Personal Data only on the documented instructions of the Practice, including with regard to transfers of Personal Data to a Third Country, unless required to do so by Applicable Laws, to which Dandy is subject; in such a case, Dandy shall inform the Practice of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. If Dandy believes any instruction infringes Applicable Laws, it shall immediately inform the Practice and shall be entitled to suspend the execution of the relevant instruction until the Practice confirms, amends or withdraws it. Any oral instructions shall be confirmed by the Practice in writing without undue delay.

The Practice shall ensure it has a lawful basis under Article 6 of the GDPR for processing Personal Data, as well as an exemption under Article 9 of the GDPR for processing Special Category Data, in the context contemplated in this DPA.

3. Obligations of Dandy (the “Processor”)

●      Confidentiality: Dandy shall ensure that its personnel authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

●      Data Subject Rights: Dandy shall assist the Practice by appropriate technical and organizational measures for the fulfillment of the Practice’s obligation to respond to requests for exercising Data Subject rights, including rights to rectification, erasure, restriction of processing, access, data portability, objection, and the right not to be subject to automated decision making. Dandy shall respond to any such request from the Practice without undue delay.

●      Assistance: Each Party shall provide reasonable assistance to the other as necessary to comply with its respective obligations under Applicable Laws, including in relation to the security of processing, notification of a Personal Data Breach to the relevant data protection authority and/or Data Subjects, preparation of data protection impact assessments, prior consultation with the relevant data protection authority, and any assessment, enquiry, notice or investigation by a Regulator. Without limiting the foregoing, the Practice shall cooperate with Dandy in good faith in connection with any regulatory enquiry, audit or investigation that relates to Dandy’s processing of Personal Data under this DPA.

●      Security: Dandy shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purpose of the Processing, as further detailed in Appendix 2. Dandy may update or modify the security measures set out in Appendix 2 from time to time, provided that such updates or modifications do not materially diminish the overall level of protection afforded to Personal Data.

●      Audit & Inspection: Dandy shall upon written request from the Practice from time to time provide the Practice with such information as is reasonably necessary to demonstrate compliance with the obligations laid down in this Agreement. Dandy shall contribute to audits, including inspections of Dandy’s premises, systems, equipment, and data processing facilities, conducted by the Practice or an independent auditor in possession of the required professional qualifications and bound by a duty of confidentiality, appointed by the Practice (“On-Site Audits”). Any On-Site Audits shall be conducted upon a 60 day prior written notice to Dandy (or shorter notice where required by a Regulator or following a Personal Data Breach or another matter of urgency), not more than once every calendar year (unless required by a Regulator or following a Personal Data Breach or another matter of urgency). The Parties shall use reasonable endeavors to ensure any On-Site Audits are conducted during Dandy’s normal business hours and do not unreasonably affect Dandy’s operations. The Practice shall bear the costs of any On-Site Audits, except where an audit reveals a material breach by Dandy of its obligations under this DPA.

4. Sub-Processing

4.1 The Practice hereby grants Dandy general written authorisation to engage the sub-processors listed within Dandy’s Trust Center, which can be found at https://trust.meetdandy.com/subprocessors, and subject to this clause 4.

4.2 If Dandy appoints a new sub-processor or intends to make any changes concerning the addition or replacement of the sub-processors, it shall provide the Practice with twenty (20) business days’ prior written notice, during which the Practice can object against the appointment or replacement on reasonable and documented grounds related to the confidentiality or security of Personal Data or the sub-processor’s compliance with Applicable Laws. If the Practice does not object, Dandy may proceed with the appointment or replacement. If the Practice objects and Dandy cannot reasonably accommodate the objection, the Practice may terminate this DPA and the Agreement upon written notice. Dandy shall ensure that it has a written agreement in place with all sub-processors which imposes obligations on the sub-processor which are no less onerous on the relevant sub-processor than the obligations on Dandy under this DPA.

5. Practice’s Obligations

5.1 The Practice warrants that: (i) the legislation applicable to it does not prevent Dandy from fulfilling the instructions received from the Practice and performing Dandy’s obligations under this DPA; and (ii) it has complied and continues to comply with the Applicable Laws, in particular that it has obtained any necessary consents or given any necessary notices, and otherwise has a legitimate ground to disclose the data to Dandy and enable the Processing of the Personal Data by Dandy as set out in this DPA.

5.2 The Practice agrees that it will indemnify and hold harmless Dandy on demand from and against all claims, liabilities, costs, expenses, loss or damage (including consequential losses, loss of profit and loss of reputation and all interest, penalties and legal and other professional costs and expenses) incurred by Dandy arising directly or indirectly from a breach of this clause 5.

6. Changes in Applicable Laws

The Parties agree to negotiate in good faith modifications to this DPA if changes are required for Dandy to continue to process the Personal Data as contemplated by this DPA in compliance with the Applicable Laws, including (i) to comply with the GDPR or any national legislation implementing it, and any guidance on the interpretation of any of their respective provisions; (ii) if the SCCs or any other mechanisms or findings of adequacy are invalidated or amended; or (iii) if changes to the membership status of a country in the European Union or the European Economic Area require such modification.

7. International Transfers

Dandy shall not transfer Personal Data outside the European Economic Area unless it ensures that the transfer is subject to appropriate safeguards in accordance with Article 46 GDPR. Such appropriate safeguards may include: (a) an adequacy decision of the European Commission pursuant to Article 45 GDPR; (b) SCCs adopted by the European Commission pursuant to Article 46(2)(c) GDPR; (c) certification under the EU-US Data Privacy Framework; or (d) any other valid transfer mechanism under Applicable Laws.

8. Personal Data Breach Notification

Dandy shall notify the Practice without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach, providing sufficient information to allow the Practice to meet any reporting obligations to the relevant data protection authority. Further information about the Personal Data Breach shall be provided in phases as more details become available.

9. Deletion or Return 

At the choice of the Practice, Dandy shall delete or return all Personal Data to the Practice after the end of the provision of services and delete existing copies unless Applicable Laws require continued storage.

APPENDIX 1: DATA PROCESSING DETAILS

●      Subject Matter and Purpose: The provision of the services to You under the Practice Agreement. 

●      Nature: Receipt, secure storage, and transmission of dental scans and clinical records submitted by the Controller via the Dandy platform; cloud hosting of patient data and case files; 3D modelling, digital design, and fabrication of dental prosthetics; case management and workflow routing; onward transmission of case data to Dandy’s authorized sub-processors for design and manufacturing purposes; return of digital case outputs (e.g., design files and treatment plans) to the Controller; customer support and case communication; and shipping and logistics processing for delivery of finished dental restorations to the Controller.

●      Duration: The term of the Practice Agreement plus the period until all data is deleted.

●      Categories of Data Subjects: Patients and authorized end users of the Practice.

●   Types of Personal Data: Names, email addresses, addresses, professional registration numbers, and patients’ health data (including but not limited to appointment data, clinical records, and dental scans).

●      Sensitive Data and Applied Safeguards: Patients’ health data (special category data under Article 9 GDPR). Applied safeguards include: strict purpose limitation to the provision of dental laboratory services; access restrictions to authorized personnel only; encryption of data in transit and at rest; keeping records of access to patient data; and restrictions on onward transfers except as permitted under this DPA.

●      Frequency of Transfer: Continuous, as dental scans and clinical records are transmitted on an ongoing basis as part of the services.

●   Sub-processor Processing: Sub-processors may process Personal Data for the purposes of cloud hosting, data storage, and IT infrastructure services. The subject matter, nature, and duration of sub-processor processing shall be consistent with the processing described above and shall not exceed the term of the Practice Agreement. A list of authorized sub-processors is available via Dandy’s Trust Center at https://trust.meetdandy.com/subprocessors.

APPENDIX 2: SECURITY MEASURES

●  Governance and personnel. Defined accountability for information security across the workforce, endpoints, and infrastructure; documented policies covering acceptable use, access control, incident response, business continuity, and risk management, reviewed periodically; and periodic risk assessments, repeated upon material change to the Services. Personnel are screened where permitted by applicable law, bound by written confidentiality obligations, granted and revoked access through established onboarding and offboarding processes with prompt revocation on termination or role change, and trained on security and data protection at hire and periodically thereafter.

●  Access control. Role-based, least-privilege, need-to-know access to Personal Data, with multi-factor authentication and individually attributable credentials required for production systems, shared production accounts prohibited, system and service credentials managed through controlled mechanisms, access rights reviewed periodically, and access to Personal Data logged and reviewable.

●  Encryption and data protection. Personal Data encrypted in transit using TLS 1.2 or higher and at rest using AES-256 or equivalent industry-standard algorithms, with keys managed under controlled processes providing restricted access and periodic rotation. Customer data is logically separated in multi-tenant environments, limited to what the Services require, and pseudonymized where compatible; production data is not used in development or test environments.

●  Infrastructure, endpoint, and development security. Boundary protection, network segmentation, denial-of-service protection, and multi-factor authentication for administrative access; monitoring and alerting across production infrastructure, with audit logs retained and protected against unauthorized access, modification, and deletion; and managed configuration baselines with change management requiring review and documented approval before production deployment. Endpoints are centrally managed and subject to malware protection, encryption, and patching controls. A documented secure development lifecycle provides for code review, automated security testing of application code and third-party dependencies, environment separation, and controlled deployment, supported by periodic independent penetration testing with findings tracked to remediation.

●  Resilience and incident response. Redundant hosting infrastructure, regular backups of Personal Data with periodic testing of restoration procedures, and a business continuity and disaster recovery plan reviewed and tested periodically. A documented incident response process provides for the identification, escalation, and remediation of security incidents, and for notification to the Controller without undue delay upon the Processor becoming aware of a Personal Data Breach, with reasonable cooperation and such information as is available to the Processor.

●  Hosting, third parties, and cooperation. Personal Data is hosted in third-party facilities that implement physical and environmental controls, including monitored and controlled access. Processor-managed premises at which Personal Data is accessed are subject to physical and environmental security controls appropriate to the nature of the site. Sub-processors undergo security and data protection due diligence before engagement and periodic reassessment, and third-party and open-source components used in the Services are inventoried and monitored for known vulnerabilities. Personal Data is retained only as long as necessary for the purposes for which it is processed and to meet legal, accounting, or reporting obligations, after which it is deleted or returned in accordance with the Agreement. Taking into account the nature of the processing, the Processor provides reasonable assistance to the Controller, insofar as possible, in fulfilling the Controller’s obligations to respond to data subject requests and to ensure compliance with its obligations under Articles 32 to 36 of the GDPR.

EU Netherlands

These additional terms & conditions (“Terms”) to the Practice Agreement including the EU Privacy Policy, and the Data Privacy Agreement form part of the Agreement (together the “Agreement”) are entered into by and between Dandy Labs Europe SAS (“Dandy” or “We”), and you and your dental practice or office (“You” or “Practice”), and are effective as of the date the Practice Agreement is entered into (“Effective Date”). If You accept the Agreement  on behalf of an entity, partnership, corporation, or organization, “You” includes You, that entity, and all entity users and You hereby represent that You have the authority to bind all such users. Dandy and You will each be referred to as a “Party” and together, the “Parties”. Terms defined herein or elsewhere in the Agreement shall have the defined term apply across the Agreement. For good and valuable consideration as set forth in the Practice Agreement, the Parties agree to the following:

1. Billing & Payments: All amounts payable pursuant to this Agreement are in Euros (€) and may be made by transfer of Euros only (with any foreign exchange fees and bank fees, if applicable, borne by You) and exclusive of applicable Value Added Tax (VAT that shall, where applicable, be charged in addition to the invoiced amounts and paid by You, upon receipt of a valid invoice as required by Applicable Law).  We accept payment by SEPA Direct Debit, bank transfer, debit card or credit card, and You are required to keep a valid payment method on file at all times. Time of payment is of the essence. Without prejudice to the foregoing, the Parties agree that all invoices shall be paid within a maximum period of thirty (30) days from the date of receipt of the invoice or, if later, from the date of receipt of goods or services. Discounts and promotions cannot be used to pay for processing, shipping, cancellation, or other fees. Dandy has the right to charge (and You agree to pay) the maximum interest amount allowed by Applicable Law, or 1.5% per month if none is specified by Applicable Law. Interest shall accrue daily from the due date until actual payment, whether before or after judgment. Dandy does not accept paper checks, prepaid credit cards, peer-to-peer payments, or cryptocurrency as valid payment methods. In the event You have any unpaid balances for sixty (60) days or more, or the amount owed to Dandy is 10,000 € (EUR) or more, Dandy reserves the right to pause your account until all unpaid balances are remitted. In the event of continuing non-payment, Dandy may cancel or suspend any or all agreements with You, which shall not extinguish the debt or any accrual of interest. You are expected to manage your patients’ expectations of the timing of the supply of the Dandy Products ordered for them accordingly. 

Except as provided below, each Party shall be solely responsible for its own tax obligations arising in connection with this Agreement. All payments by You under this Agreement shall be made without deduction or withholding for any taxes, except as required by Applicable Law. To the extent any payment under this Agreement gives rise to any obligation on You to deduct, withhold, or remit any amount to any governmental authority under Applicable Law, the amounts due and payable under this Agreement shall be increased so that We receive an amount equal to the amount we would have received had no such deduction or withholding been made. For reporting purposes, You agree to deliver to Dandy evidence that such taxes were paid to a governmental authority, including the original or a certified copy of a receipt issued by that authority evidencing the payment.

You further acknowledge that Dandy has disclosed the possibility of processing fees and has provided the opportunity to ask any questions regarding such fees prior to entering this Agreement. You agree to indemnify and hold Dandy harmless from any claims, damages, or losses arising from any such surcharges imposed by third-party service providers. Dandy reserves the right to change pricing for Dandy Products (defined below) at any time upon forty-five (45) days’ notice. You agree that You shall have no right of set-off, counterclaim deduction or withholding against amounts owed by Dandy to You. You agree that Dandy may at any time and without limiting any other rights or remedies it may have, set-off any amount owing by You against any amount payable by Dandy to You. Dandy does not accept payments from patients, including payments in the patient’s name forwarded by You.

2. Equipment. The risk of loss, theft, damage or destruction of the Equipment shall pass to You on Delivery. The Equipment shall remain at your sole risk during the term of this Agreement and any further term during which the Equipment is in your possession, custody or control (the “Risk Period“) until the Equipment is redelivered to Dandy. You shall give immediate written notice to Dandy in the event of any loss, accident or damage to the Equipment arising out of or in connection with your possession or use of the Equipment.

3. IT Requirements. You agree to provide and maintain a high-speed internet connection for use in connection with the Equipment, and You agree to follow the IT Policies included in the online terms and conditions.

4. Indemnity: You shall indemnify, keep indemnified, defend and hold harmless Dandy against and from any and all claims, causes of actions, damages, debts, liabilities, losses, obligations, payments, costs and expenses (including legal expenses), arising from or relating to: (a) breach by You of any term of any agreement with Dandy; (b) breach by You of any term of any agreement between You and your patient or any acts or failures in respect of a patient (including actions by any professional body regulating You or any national regulator(s) or licensing body), including without limitation, negligence or willful acts regarding patient care or the provision of any incorrect clinical data; and (c) provision by You of incorrect or incomplete information, documents, scans or impressions or failure to timely provide Dandy with any information we request from You.

5. Practice Change of Control: If your dental practice undergoes a Change of Control from an ownership perspective, You agree to inform Dandy with written notice within five (5) business days before the day such Change of Control becomes effective. For the purposes of this clause, a “Change of Control” situation shall include any transaction or series of transactions resulting in a change in the direct or indirect ownership of more than fifty percent (50%) of the voting rights or share capital of your dental practice, or any merger, consolidation, or sale of substantially all of its assets.

6. Medical Disclaimer: Your practice is solely responsible for the treatment of patients using any Dandy Offerings, and for providing your patients with all relevant information about the Dandy Offerings and any related risk prior to and after treatment. The Dandy Offerings are offered solely as a supplement to your dental practice and do not constitute medical, dental or other healthcare advice, diagnosis or treatment to or for your patients. You agree not to make any representations or warranties regarding the Dandy Offerings to your patients. You represent to Dandy that your practice will comply with all Applicable Law, regulations, guidance and professional codes of conduct regarding professionals who are authorized to practice dentistry and to conduct intraoral scans on practice patients. Except as otherwise expressly provided herein, the Dandy Offerings provided to you hereunder are provided “AS IS” and are provided pursuant to your prescription for the individual patient. 

The Parties acknowledge that this Agreement creates no direct contractual relationship between Dandy and Your patients. Any claims, demands, or actions brought by a patient or regulatory body arising out of your clinical decisions, treatment management, prescription errors, or the provision of faulty data (such as defective scans or impressions) shall be subject to your full indemnification obligations as set out in section 4.

You agree to comply with your obligations under Regulation (EU) 2017/745 on medical devices to the extent applicable. You agree to handle all communications and other activities in relation to any recall or other regulatory activity in accordance with all our reasonable instructions and to not reach out or otherwise communicate with a competent authority prior to consultation with us. This obligation as well as related indemnification arrangements of the Online Terms and Conditions shall survive termination of this Practice Agreement for the period medical devices supplied by us remain in use.

7. Amendment. These Terms and the Agreement may be changed by mutual written agreement of the Parties. These Terms and the Agreement may otherwise be amended by Dandy and Dandy will notify You of any material changes. Such material changes shall become effective thirty (30) days after notification unless You terminate by written notice within that period. In such cases, Dandy will honor existing Terms for sixty (60) days or until the Equipment is returned.

8. Entire Agreement. The Practice Agreement, these Terms, the EU Privacy Policy, the Data Privacy Agreement (“DPA”) (Schedule A), and the IT Policy constitute the “Agreement”. This Agreement supersedes all prior conflicting agreements.

9. Non-assignability. You may not transfer or assign the Agreement to a third party without Dandy’s prior written consent.

10. Legal Compliance. Both Parties agree to comply with all applicable health and data laws in the jurisdiction where You and Dandy are both established, relevant regulatory standards issued by European and national authorities, and guidance issued by professional regulatory bodies.

11. Governing Law & Jurisdiction. 

  1. Governing Law. You agree that the Agreement shall be governed by and construed in accordance with the laws of the jurisdiction where the Practice is established. 
  2. Jurisdiction. Any disputes arising out of or in connection with the Agreement shall be submitted to the exclusive jurisdiction of the courts of the applicable jurisdiction where the Practice is established, as set forth in the table below.
CountryJurisdiction
FranceTribunal des Activités Économiques de Paris
IrelandCourts of Dublin 
ItalyTribunal of Milan
The NetherlandsThe competent court in Amsterdam, the Netherlands
SpainCourts and Tribunals of Madrid

12. VAT & Tax. Dandy will charge Value Added Tax (“VAT”) at the applicable rate in addition to any price, charge or amount due under the Agreement and such VAT shall be payable by You, where applicable. If You are exempt, You must provide a valid VAT exemption certificate or evidence satisfactory to the relevant tax administration, when available or justify the basis for the VAT exemption.

13. Data Privacy. Because Dandy processes personal data, including health data (“Personal Data”) on your behalf.

Data Protection Roles. The Parties acknowledge that:

Data Protection Contact. Any privacy-related notices or requests under this Agreement should be directed to Dandy at [email protected]

Schedule A: Data Privacy Agreement (“DPA”)

This DPA is incorporated into the Agreement where Dandy acts as a processor on behalf of the Practice as controller. The nature, purpose, and duration of the processing are set out in Appendix 1 (“Data Processing Details”).

1. Definitions

●      “Applicable Laws” means all applicable laws that govern the processing and security of Personal Data as well as the privacy of electronic communications, including, without limitation, (i) Regulation (EU) 2016/679 of 27 April 2016 (the GDPR), (ii) Directive 2002/58/EC of 12 July 2002 (the ePrivacy Directive), (iii) domestic laws implementing and supplementing the EU laws referred to in this definition, and (iv) the relevant provisions of national health laws, each of (i) to (iv) as amended and/or supplemented from time to time.

●      “Personal Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data, or any other event affecting the integrity, availability or confidentiality of Personal Data.

●      “Special Category Data” means the categories of Personal Data referred to in Article 9 of the GDPR (including but not limited to Personal Data concerning health, biometric data, or data used for the purpose of uniquely identifying a natural person and genetic data).

●      “Personal Data” means personal data (as defined by the GDPR) processed by Dandy on behalf of the Practice.

●      “Data Subject” has the meaning given in the GDPR.

●      “Regulator” means a data protection supervisory authority which has jurisdiction over the Practice’s Processing of Personal Data.

●      “SCCs” means the standard contractual clauses for the transfer of personal data to third countries set out in Commission Decision 2021/914 of 4 June 2021, as amended, updated or replaced from time to time.

●      “Third Country” means any country or territory outside of the scope of the data protection laws of the European Economic Area, excluding countries or territories approved as providing adequate protection for personal data by the European Commission from time to time.

●      “Data Privacy Framework” means, as relevant, the EU-US Data Privacy Framework as administered by the US Department of Commerce and approved by the European Commission as ensuring an adequate level of protection for personal data for the purposes of Article 45 GDPR, as in force, amended, consolidated, re-enacted or replaced from time to time.

2. Subject Matter & Instructions

Dandy shall process Personal Data only on the documented instructions of the Practice, including with regard to transfers of Personal Data to a Third Country, unless required to do so by Applicable Laws, to which Dandy is subject; in such a case, Dandy shall inform the Practice of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. If Dandy believes any instruction infringes Applicable Laws, it shall immediately inform the Practice and shall be entitled to suspend the execution of the relevant instruction until the Practice confirms, amends or withdraws it. Any oral instructions shall be confirmed by the Practice in writing without undue delay.

The Practice shall ensure it has a lawful basis under Article 6 of the GDPR for processing Personal Data, as well as an exemption under Article 9 of the GDPR for processing Special Category Data, in the context contemplated in this DPA.

3. Obligations of Dandy (the “Processor”)

●      Confidentiality: Dandy shall ensure that its personnel authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

●      Data Subject Rights: Dandy shall assist the Practice by appropriate technical and organizational measures for the fulfillment of the Practice’s obligation to respond to requests for exercising Data Subject rights, including rights to rectification, erasure, restriction of processing, access, data portability, objection, and the right not to be subject to automated decision making. Dandy shall respond to any such request from the Practice without undue delay.

●      Assistance: Each Party shall provide reasonable assistance to the other as necessary to comply with its respective obligations under Applicable Laws, including in relation to the security of processing, notification of a Personal Data Breach to the relevant data protection authority and/or Data Subjects, preparation of data protection impact assessments, prior consultation with the relevant data protection authority, and any assessment, enquiry, notice or investigation by a Regulator. Without limiting the foregoing, the Practice shall cooperate with Dandy in good faith in connection with any regulatory enquiry, audit or investigation that relates to Dandy’s processing of Personal Data under this DPA.

●      Security: Dandy shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purpose of the Processing, as further detailed in Appendix 2. Dandy may update or modify the security measures set out in Appendix 2 from time to time, provided that such updates or modifications do not materially diminish the overall level of protection afforded to Personal Data.

●      Audit & Inspection: Dandy shall upon written request from the Practice from time to time provide the Practice with such information as is reasonably necessary to demonstrate compliance with the obligations laid down in this Agreement. Dandy shall contribute to audits, including inspections of Dandy’s premises, systems, equipment, and data processing facilities, conducted by the Practice or an independent auditor in possession of the required professional qualifications and bound by a duty of confidentiality, appointed by the Practice (“On-Site Audits”). Any On-Site Audits shall be conducted upon a 60 day prior written notice to Dandy (or shorter notice where required by a Regulator or following a Personal Data Breach or another matter of urgency), not more than once every calendar year (unless required by a Regulator or following a Personal Data Breach or another matter of urgency). The Parties shall use reasonable endeavors to ensure any On-Site Audits are conducted during Dandy’s normal business hours and do not unreasonably affect Dandy’s operations. The Practice shall bear the costs of any On-Site Audits, except where an audit reveals a material breach by Dandy of its obligations under this DPA.

4. Sub-Processing

4.1 The Practice hereby grants Dandy general written authorisation to engage the sub-processors listed within Dandy’s Trust Center, which can be found at https://trust.meetdandy.com/subprocessors, and subject to this clause 4.

4.2 If Dandy appoints a new sub-processor or intends to make any changes concerning the addition or replacement of the sub-processors, it shall provide the Practice with twenty (20) business days’ prior written notice, during which the Practice can object against the appointment or replacement on reasonable and documented grounds related to the confidentiality or security of Personal Data or the sub-processor’s compliance with Applicable Laws. If the Practice does not object, Dandy may proceed with the appointment or replacement. If the Practice objects and Dandy cannot reasonably accommodate the objection, the Practice may terminate this DPA and the Agreement upon written notice. Dandy shall ensure that it has a written agreement in place with all sub-processors which imposes obligations on the sub-processor which are no less onerous on the relevant sub-processor than the obligations on Dandy under this DPA.

5. Practice’s Obligations

5.1 The Practice warrants that: (i) the legislation applicable to it does not prevent Dandy from fulfilling the instructions received from the Practice and performing Dandy’s obligations under this DPA; and (ii) it has complied and continues to comply with the Applicable Laws, in particular that it has obtained any necessary consents or given any necessary notices, and otherwise has a legitimate ground to disclose the data to Dandy and enable the Processing of the Personal Data by Dandy as set out in this DPA.

5.2 The Practice agrees that it will indemnify and hold harmless Dandy on demand from and against all claims, liabilities, costs, expenses, loss or damage (including consequential losses, loss of profit and loss of reputation and all interest, penalties and legal and other professional costs and expenses) incurred by Dandy arising directly or indirectly from a breach of this clause 5.

6. Changes in Applicable Laws

The Parties agree to negotiate in good faith modifications to this DPA if changes are required for Dandy to continue to process the Personal Data as contemplated by this DPA in compliance with the Applicable Laws, including (i) to comply with the GDPR or any national legislation implementing it, and any guidance on the interpretation of any of their respective provisions; (ii) if the SCCs or any other mechanisms or findings of adequacy are invalidated or amended; or (iii) if changes to the membership status of a country in the European Union or the European Economic Area require such modification.

7. International Transfers

Dandy shall not transfer Personal Data outside the European Economic Area unless it ensures that the transfer is subject to appropriate safeguards in accordance with Article 46 GDPR. Such appropriate safeguards may include: (a) an adequacy decision of the European Commission pursuant to Article 45 GDPR; (b) SCCs adopted by the European Commission pursuant to Article 46(2)(c) GDPR; (c) certification under the EU-US Data Privacy Framework; or (d) any other valid transfer mechanism under Applicable Laws.

8. Personal Data Breach Notification

Dandy shall notify the Practice without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach, providing sufficient information to allow the Practice to meet any reporting obligations to the relevant data protection authority. Further information about the Personal Data Breach shall be provided in phases as more details become available.

9. Deletion or Return 

At the choice of the Practice, Dandy shall delete or return all Personal Data to the Practice after the end of the provision of services and delete existing copies unless Applicable Laws require continued storage.

APPENDIX 1: DATA PROCESSING DETAILS

●      Subject Matter and Purpose: The provision of the services to You under the Practice Agreement. 

●      Nature: Receipt, secure storage, and transmission of dental scans and clinical records submitted by the Controller via the Dandy platform; cloud hosting of patient data and case files; 3D modelling, digital design, and fabrication of dental prosthetics; case management and workflow routing; onward transmission of case data to Dandy’s authorized sub-processors for design and manufacturing purposes; return of digital case outputs (e.g., design files and treatment plans) to the Controller; customer support and case communication; and shipping and logistics processing for delivery of finished dental restorations to the Controller.

●      Duration: The term of the Practice Agreement plus the period until all data is deleted.

●      Categories of Data Subjects: Patients and authorized end users of the Practice.

●   Types of Personal Data: Names, email addresses, addresses, professional registration numbers, and patients’ health data (including but not limited to appointment data, clinical records, and dental scans).

●      Sensitive Data and Applied Safeguards: Patients’ health data (special category data under Article 9 GDPR). Applied safeguards include: strict purpose limitation to the provision of dental laboratory services; access restrictions to authorized personnel only; encryption of data in transit and at rest; keeping records of access to patient data; and restrictions on onward transfers except as permitted under this DPA.

●      Frequency of Transfer: Continuous, as dental scans and clinical records are transmitted on an ongoing basis as part of the services.

●   Sub-processor Processing: Sub-processors may process Personal Data for the purposes of cloud hosting, data storage, and IT infrastructure services. The subject matter, nature, and duration of sub-processor processing shall be consistent with the processing described above and shall not exceed the term of the Practice Agreement. A list of authorized sub-processors is available via Dandy’s Trust Center at https://trust.meetdandy.com/subprocessors.

APPENDIX 2: SECURITY MEASURES

●  Governance and personnel. Defined accountability for information security across the workforce, endpoints, and infrastructure; documented policies covering acceptable use, access control, incident response, business continuity, and risk management, reviewed periodically; and periodic risk assessments, repeated upon material change to the Services. Personnel are screened where permitted by applicable law, bound by written confidentiality obligations, granted and revoked access through established onboarding and offboarding processes with prompt revocation on termination or role change, and trained on security and data protection at hire and periodically thereafter.

●  Access control. Role-based, least-privilege, need-to-know access to Personal Data, with multi-factor authentication and individually attributable credentials required for production systems, shared production accounts prohibited, system and service credentials managed through controlled mechanisms, access rights reviewed periodically, and access to Personal Data logged and reviewable.

●  Encryption and data protection. Personal Data encrypted in transit using TLS 1.2 or higher and at rest using AES-256 or equivalent industry-standard algorithms, with keys managed under controlled processes providing restricted access and periodic rotation. Customer data is logically separated in multi-tenant environments, limited to what the Services require, and pseudonymized where compatible; production data is not used in development or test environments.

●  Infrastructure, endpoint, and development security. Boundary protection, network segmentation, denial-of-service protection, and multi-factor authentication for administrative access; monitoring and alerting across production infrastructure, with audit logs retained and protected against unauthorized access, modification, and deletion; and managed configuration baselines with change management requiring review and documented approval before production deployment. Endpoints are centrally managed and subject to malware protection, encryption, and patching controls. A documented secure development lifecycle provides for code review, automated security testing of application code and third-party dependencies, environment separation, and controlled deployment, supported by periodic independent penetration testing with findings tracked to remediation.

●  Resilience and incident response. Redundant hosting infrastructure, regular backups of Personal Data with periodic testing of restoration procedures, and a business continuity and disaster recovery plan reviewed and tested periodically. A documented incident response process provides for the identification, escalation, and remediation of security incidents, and for notification to the Controller without undue delay upon the Processor becoming aware of a Personal Data Breach, with reasonable cooperation and such information as is available to the Processor.

●  Hosting, third parties, and cooperation. Personal Data is hosted in third-party facilities that implement physical and environmental controls, including monitored and controlled access. Processor-managed premises at which Personal Data is accessed are subject to physical and environmental security controls appropriate to the nature of the site. Sub-processors undergo security and data protection due diligence before engagement and periodic reassessment, and third-party and open-source components used in the Services are inventoried and monitored for known vulnerabilities. Personal Data is retained only as long as necessary for the purposes for which it is processed and to meet legal, accounting, or reporting obligations, after which it is deleted or returned in accordance with the Agreement. Taking into account the nature of the processing, the Processor provides reasonable assistance to the Controller, insofar as possible, in fulfilling the Controller’s obligations to respond to data subject requests and to ensure compliance with its obligations under Articles 32 to 36 of the GDPR.

Ready to talk now?

Give our team a call right now and get your questions answered live
Call Us: (289)-985-0325

Ready to talk now?

Give our team a call right now and get your questions answered live
Call Us: +44 020 4572 6011