Data Processing Addendum

HEY PRESTO LTD – UK GDPR DATA PROCESSING ADDENDUM (DPA)

Last updated: 2026-07-24

This Data Processing Addendum (“DPA”) forms part of the agreement between HEY PRESTO LTD (“Processor”) and the Customer (“Controller”) relating to use of the Presto platform.

“Customer” means any dental practice, dental laboratory, clinician or other organisation that enters into an agreement with Presto for use of the Platform.

“Personal Data” has the meaning given to it under the UK GDPR and applicable data protection legislation.

Relationship with the Terms

This DPA forms part of and is incorporated into the Terms of Use. To the extent of any inconsistency between this DPA and the Terms of Use in relation to the processing of personal data, this DPA shall prevail.

1. PURPOSE

This DPA applies where Presto processes personal data on behalf of a Customer in connection with the Platform.

This DPA applies only to Customer data that the Customer uploads to, stores in, or otherwise instructs Presto to process through the Platform.

2. ROLE OF THE PARTIES

The Customer acts as controller in respect of the personal data it submits to the Platform and determines the purposes and means of such processing where applicable under UK data protection law.

Presto acts as data processor where processing Customer personal data solely on behalf of the Customer.

Nothing in this DPA prevents Presto acting as an independent controller where required for:

  • billing and financial administration;

  • fraud detection and prevention;

  • compliance with legal obligations;

  • maintaining the security and integrity of the Platform;

  • and customer support and account management.

Presto may also create, retain and use anonymised and aggregated datasets derived from Platform data for service improvement, benchmarking, research, analytics, statistical reporting and product development, provided such datasets do not identify any Customer, Practice, Laboratory, Patient or individual and cannot reasonably be used to re-identify them. Further provisions relating to such datasets are set out in Clause 4 (Platform Insights, Benchmarking and Anonymised Data).

3. PROCESSING DETAILS

Subject Matter

Provision of the Presto platform and related workflow/payment facilitation services.

Duration

For the duration of the Customer relationship and any applicable retention period.

Nature and Purpose

Hosting, processing, organisation, storage, communication, workflow facilitation, and payment-related administration.

Categories of Data Subjects

May include:

  • dental professionals;

  • laboratory personnel;

  • practice staff;

  • and patients.

Categories of Personal Data

May include:

  • names;

  • contact details;

  • workflow information;

  • transaction references;

  • appliance/workflow details;

  • and limited patient administrative information, including patient identifiers necessary to identify a laboratory case and facilitate payment.

The Platform is not intended to act as an Electronic Health Record (EHR) system and is designed to process only the minimum clinical and administrative information required to facilitate dental laboratory workflows and payments.

4. PLATFORM INSIGHTS, BENCHMARKING AND ANONYMISED DATA

Presto may create anonymised, aggregated or de-identified datasets derived from information processed through the Platform for purposes including:

  • benchmarking;

  • statistical analysis;

  • product improvement;

  • service optimisation;

  • fraud prevention;

  • market insights;

  • research;

  • machine learning;

  • artificial intelligence;

  • predictive analytics;

  • and publication of industry trends.

Such datasets shall not identify, nor be capable of reasonably identifying, any Customer, Practice, Laboratory, Patient or individual.

Presto may use anonymised and aggregated datasets to develop, train, test and improve analytical models, artificial intelligence and machine learning systems used within the Platform.

Presto may publish reports, benchmarks or market insights derived from anonymised and aggregated datasets, provided no individual, Customer, Practice, Laboratory or Patient can reasonably be identified.

Nothing in this DPA restricts Presto from using information that has been irreversibly anonymised so that it is no longer personal data under applicable data protection legislation.

5. PROCESSING OBLIGATIONS

Presto shall:

  • process Personal Data only on documented instructions from the Customer, unless otherwise required by applicable law;

  • ensure persons authorised to process data are subject to confidentiality obligations, whether contractual or statutory;

  • implement reasonable technical and organisational security measures;

  • and comply with applicable data protection laws relating to processors.

6. CUSTOMER RESPONSIBILITIES

The Customer warrants that it:

  • has a lawful basis for processing personal data;

  • has provided required notices;

  • has obtained required consents where applicable;

  • and may lawfully submit personal data to the Platform.

The Customer shall not submit unnecessary or excessive personal data.

7. SUBPROCESSORS

The Customer authorises Presto to use subprocessors including:

  • Stripe

  • Airtable

  • Fillout

  • MiniExtensions

  • Twilio

  • hosting providers

  • analytics, monitoring and infrastructure providers

Presto may appoint, replace or update subprocessors from time to time and shall maintain an up-to-date list of material subprocessors, which shall be made available on request or published on the Presto website.

Presto shall maintain appropriate contractual protections with subprocessors where required by law.

8. INTERNATIONAL TRANSFERS

Where personal data is transferred outside the United Kingdom, Presto shall implement appropriate safeguards in accordance with applicable data protection laws.

9. SECURITY

Presto shall implement reasonable technical and organisational measures appropriate to:

  • the nature of the processing;

  • the sensitivity of the data;

  • and the risks involved.

Such measures include encryption of personal data in transit and, where appropriate, at rest, role-based access controls, authentication controls, audit logging where appropriate, and regular review and testing of security measures where appropriate.

10. CONTROLLER ASSISTANCE

Where reasonably requested, Presto shall provide reasonable assistance to enable the Customer to comply with its obligations relating to:

  • data subject requests;

  • security of processing;

  • personal data breaches;

  • data protection impact assessments; and

  • consultation with supervisory authorities,

to the extent required by applicable law.

11. PERSONAL DATA BREACHES

Presto shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data where notification is legally required.

12. RETURN AND DELETION

Upon termination of services, Presto may delete or return Customer personal data in accordance with:

  • applicable law;

  • operational requirements;

  • retention obligations;

  • and backup/security procedures.

Presto may retain:

  • securely archived backups;

  • legal compliance records;

  • and anonymised or aggregated data where lawful.

13. AUDITS AND INFORMATION

Presto shall provide reasonable information necessary to demonstrate compliance with this DPA, subject to:

  • confidentiality obligations;

  • security requirements;

  • proportionality;

  • and protection of other customers.

Audits shall be conducted on reasonable notice and during normal business hours.

14. CONTACT AND DATA PROTECTION LEAD

Presto has appointed a Data Protection Lead responsible for overseeing compliance with applicable data protection legislation.

Privacy enquiries: privacy@heypresto.dental

15. GOVERNING LAW

This DPA is governed by the laws of England and Wales.