Data Processing Addendum
HEY PRESTO LTD – UK GDPR DATA PROCESSING ADDENDUM (DPA)
Last updated: 2026-07-24
This Data Processing Addendum (“DPA”) forms part of the agreement between HEY PRESTO LTD (“Processor”) and the Customer (“Controller”) relating to use of the Presto platform.
“Customer” means any dental practice, dental laboratory, clinician or other organisation that enters into an agreement with Presto for use of the Platform.
“Personal Data” has the meaning given to it under the UK GDPR and applicable data protection legislation.
Relationship with the Terms
This DPA forms part of and is incorporated into the Terms of Use. To the extent of any inconsistency between this DPA and the Terms of Use in relation to the processing of personal data, this DPA shall prevail.
1. PURPOSE
This DPA applies where Presto processes personal data on behalf of a Customer in connection with the Platform.
This DPA applies only to Customer data that the Customer uploads to, stores in, or otherwise instructs Presto to process through the Platform.
2. ROLE OF THE PARTIES
The Customer acts as controller in respect of the personal data it submits to the Platform and determines the purposes and means of such processing where applicable under UK data protection law.
Presto acts as data processor where processing Customer personal data solely on behalf of the Customer.
Nothing in this DPA prevents Presto acting as an independent controller where required for:
billing and financial administration;
fraud detection and prevention;
compliance with legal obligations;
maintaining the security and integrity of the Platform;
and customer support and account management.
Presto may also create, retain and use anonymised and aggregated datasets derived from Platform data for service improvement, benchmarking, research, analytics, statistical reporting and product development, provided such datasets do not identify any Customer, Practice, Laboratory, Patient or individual and cannot reasonably be used to re-identify them. Further provisions relating to such datasets are set out in Clause 4 (Platform Insights, Benchmarking and Anonymised Data).
3. PROCESSING DETAILS
Subject Matter
Provision of the Presto platform and related workflow/payment facilitation services.
Duration
For the duration of the Customer relationship and any applicable retention period.
Nature and Purpose
Hosting, processing, organisation, storage, communication, workflow facilitation, and payment-related administration.
Categories of Data Subjects
May include:
dental professionals;
laboratory personnel;
practice staff;
and patients.
Categories of Personal Data
May include:
names;
contact details;
workflow information;
transaction references;
appliance/workflow details;
and limited patient administrative information, including patient identifiers necessary to identify a laboratory case and facilitate payment.
The Platform is not intended to act as an Electronic Health Record (EHR) system and is designed to process only the minimum clinical and administrative information required to facilitate dental laboratory workflows and payments.
4. PLATFORM INSIGHTS, BENCHMARKING AND ANONYMISED DATA
Presto may create anonymised, aggregated or de-identified datasets derived from information processed through the Platform for purposes including:
benchmarking;
statistical analysis;
product improvement;
service optimisation;
fraud prevention;
market insights;
research;
machine learning;
artificial intelligence;
predictive analytics;
and publication of industry trends.
Such datasets shall not identify, nor be capable of reasonably identifying, any Customer, Practice, Laboratory, Patient or individual.
Presto may use anonymised and aggregated datasets to develop, train, test and improve analytical models, artificial intelligence and machine learning systems used within the Platform.
Presto may publish reports, benchmarks or market insights derived from anonymised and aggregated datasets, provided no individual, Customer, Practice, Laboratory or Patient can reasonably be identified.
Nothing in this DPA restricts Presto from using information that has been irreversibly anonymised so that it is no longer personal data under applicable data protection legislation.
5. PROCESSING OBLIGATIONS
Presto shall:
process Personal Data only on documented instructions from the Customer, unless otherwise required by applicable law;
ensure persons authorised to process data are subject to confidentiality obligations, whether contractual or statutory;
implement reasonable technical and organisational security measures;
and comply with applicable data protection laws relating to processors.
6. CUSTOMER RESPONSIBILITIES
The Customer warrants that it:
has a lawful basis for processing personal data;
has provided required notices;
has obtained required consents where applicable;
and may lawfully submit personal data to the Platform.
The Customer shall not submit unnecessary or excessive personal data.
7. SUBPROCESSORS
The Customer authorises Presto to use subprocessors including:
Stripe
Airtable
Fillout
MiniExtensions
Twilio
hosting providers
analytics, monitoring and infrastructure providers
Presto may appoint, replace or update subprocessors from time to time and shall maintain an up-to-date list of material subprocessors, which shall be made available on request or published on the Presto website.
Presto shall maintain appropriate contractual protections with subprocessors where required by law.
8. INTERNATIONAL TRANSFERS
Where personal data is transferred outside the United Kingdom, Presto shall implement appropriate safeguards in accordance with applicable data protection laws.
9. SECURITY
Presto shall implement reasonable technical and organisational measures appropriate to:
the nature of the processing;
the sensitivity of the data;
and the risks involved.
Such measures include encryption of personal data in transit and, where appropriate, at rest, role-based access controls, authentication controls, audit logging where appropriate, and regular review and testing of security measures where appropriate.
10. CONTROLLER ASSISTANCE
Where reasonably requested, Presto shall provide reasonable assistance to enable the Customer to comply with its obligations relating to:
data subject requests;
security of processing;
personal data breaches;
data protection impact assessments; and
consultation with supervisory authorities,
to the extent required by applicable law.
11. PERSONAL DATA BREACHES
Presto shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data where notification is legally required.
12. RETURN AND DELETION
Upon termination of services, Presto may delete or return Customer personal data in accordance with:
applicable law;
operational requirements;
retention obligations;
and backup/security procedures.
Presto may retain:
securely archived backups;
legal compliance records;
and anonymised or aggregated data where lawful.
13. AUDITS AND INFORMATION
Presto shall provide reasonable information necessary to demonstrate compliance with this DPA, subject to:
confidentiality obligations;
security requirements;
proportionality;
and protection of other customers.
Audits shall be conducted on reasonable notice and during normal business hours.
14. CONTACT AND DATA PROTECTION LEAD
Presto has appointed a Data Protection Lead responsible for overseeing compliance with applicable data protection legislation.
Privacy enquiries: privacy@heypresto.dental
15. GOVERNING LAW
This DPA is governed by the laws of England and Wales.