Data Processing Agreement

Last updated – Mar 13, 2026

This Data Processing Agreement ("DPA") governs the processing of personal data by KeepTrack Technologies LLC ("KeepTrack") on behalf of its customers in connection with the KeepTrack dental practice management platform.

01

Scope and Purpose

This DPA applies when KeepTrack processes personal data on behalf of a customer as a data processor. It supplements the main Terms of Service and governs all processing activities carried out in the provision of the platform.

02

Data Processing Principles

  • Personal data is processed only for specified, explicit, and legitimate purposes
  • Processing is limited to what is necessary for those purposes
  • Data is kept accurate and up to date
  • Data is not retained longer than necessary
  • Data is protected against unauthorized access, loss, or destruction
03

Customer Responsibilities

Customers acting as data controllers are responsible for ensuring a valid legal basis for processing personal data and for providing appropriate privacy notices to data subjects.

04

Security Obligations

  • AES-256 encryption for stored data
  • TLS 1.3 encryption for data in transit
  • Role-based access controls and multi-factor authentication
  • Regular security audits and vulnerability assessments
  • Incident response and breach notification procedures
05

Sub-processors

KeepTrack may engage sub-processors to assist in delivering its services. Customers will be notified of material changes to approved sub-processors.

  • Amazon Web Services – cloud infrastructure
  • Stripe – payment processing
  • Twilio – communication services
06

Cross-Border Data Transfers

Data may be transferred to and processed in countries outside the European Economic Area. KeepTrack implements appropriate safeguards, including Standard Contractual Clauses, for all such transfers.

07

Data Subject Rights

KeepTrack will assist customers in fulfilling data subject requests, including rights of access, rectification, erasure, and data portability within applicable timeframes.

08

Request a DPA

Customers may request a signed copy of the full Data Processing Agreement by contacting:

keep.track.dental@gmail.com
KeepTrack | Dental Practice Management Software