This Addendum ("DPA") governs ChairFill's processing of personal data on behalf of a dental practice. It forms part of the Terms of Service and takes effect automatically when you accept them — you do not need to sign or request it.
The parties are:
"DPDP Act" means India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. "GDPR" means the UK GDPR and the EU General Data Protection Regulation, as applicable. "Data Protection Law" means whichever of these, and any other applicable privacy law, applies to your processing.
"Personal Data" means personal data or digital personal data, as defined in the applicable law, that we process on your behalf under the Terms. "Data Principal" and "Data Subject" mean the individual the data relates to — in practice, your patients. "Sub-processor" means a third party we engage to process Personal Data.
Terms not defined here take the meaning given in the Terms of Service.
You are the Data Fiduciary (Data Controller under the GDPR). You determine what Personal Data is collected about your patients and for what purpose.
ChairFill is your Data Processor. We process Personal Data only to provide the Service to you, and only on your instructions.
Section 8(2) of the DPDP Act allows you to engage a processor only under a valid contract, and it keeps you responsible for compliance regardless of what that contract says. This DPA is that contract. It does not, and cannot, move your statutory responsibility onto us. What it does is commit us to specific obligations that make it possible for you to discharge yours.
We act as an independent controller only for our own business data — your account details, billing records and support correspondence. That processing is described in the Privacy Policy, not here.
The subject matter, nature, purpose, data categories and categories of Data Principals are set out in Annex I. This DPA applies for as long as we process Personal Data on your behalf — that is, for the term of the Terms plus the 30-day post-termination window described in section 12 of the Terms.
We process Personal Data only on your documented instructions. Your instructions consist of the Terms, this DPA, and the settings and actions you take in the product — switching on the WhatsApp receptionist, importing a patient list, enabling reminders, connecting Google Calendar, and so on.
We will not sell Personal Data, share it for advertising, or use it to train AI models — neither our own nor a third party's. Our AI processing runs on Google Cloud Vertex AI, which is contractually barred from using the data to train Google's foundation models.
If we are required by law to process Personal Data beyond your instructions, we will tell you first unless the law forbids it. If we believe an instruction breaches Data Protection Law, we will tell you without delay and may pause that processing.
Access to Personal Data is limited to personnel who need it to operate or support the Service. They are bound by confidentiality obligations that survive the end of their engagement, and their access is limited to what their role requires.
We implement appropriate technical and organisational measures to protect Personal Data, described in Annex II. This satisfies the requirement in Rule 6 of the DPDP Rules, 2025 that a Fiduciary–Processor contract mandate reasonable security safeguards, and Article 32 of the GDPR.
We may update these measures as the Service evolves, provided the level of protection is not reduced.
You give general authorisation for us to engage Sub-processors. The current list is published and kept up to date at getchairfill.com/subprocessors.
Each Sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA. We remain fully liable to you for their performance.
Before adding or replacing a Sub-processor we will give at least 30 days' notice. That notice is sent automatically by email to every practice with an active account — you do not need to subscribe to anything to receive it. If you would like it copied to an additional address as well, such as a data protection adviser, tell us at privacy@getchairfill.com.
If you have a reasonable data protection objection, tell us within that notice period and we will work with you in good faith to find an alternative. This applies to every practice, wherever you are.
If no alternative can be found, a practice in the UK or EU may terminate and receive a pro-rata refund of prepaid fees covering the unused remainder of the term. Two things about that refund, so there is no doubt later: it returns only the part you paid for and will not now receive — fees for periods already served are not refunded — and because ChairFill is sold as one plan with no separately priced components, there is no "affected part" that can be cancelled on its own. Termination under this clause ends the subscription as a whole.
Article 28(2) of the GDPR requires that notice, that objection right, and that exit route for practices in the UK and EU. India's DPDP Act contains no equivalent provision — it places the duty on you as Fiduciary instead, and section 8(1) makes that duty non-delegable. So we give the notice and the objection right everywhere, because a Fiduciary carrying absolute responsibility for its patients' data ought to know who touches it whether or not a statute compels us to say so. The termination-with-refund route is offered where the law requires it. Elsewhere you may still cancel at any time under section 8 of the Terms — there is no lock-in and no cancellation fee anywhere; the only difference is whether prepaid fees for the unused remainder come back.
Rights under the DPDP Act and the GDPR are exercised against you, not us. We help you meet them:
If a patient contacts us directly, we will not respond substantively. We will refer them to your practice and tell you, so that you can answer as the Fiduciary.
If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Personal Data we process for you, we will notify you without undue delay and in any event within 72 hours of becoming aware.
The notice will describe, so far as we know it, the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the steps taken or proposed. Where we cannot provide all of it at once, we will provide it in phases without further undue delay.
We will assist you in meeting your own notification duties — to the Data Protection Board of India, to the ICO or other supervisory authority, and to affected patients. Making those notifications is your obligation as the Fiduciary, and the DPDP Rules require them regardless of how minor the breach appears.
Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority.
On termination, your data remains available for export for 30 days. After that we delete or irreversibly anonymise Personal Data processed on your behalf, including from routine backups within a further 90 days as backups age out.
We may retain Personal Data where the law requires it — principally billing and transaction records kept for tax and accounting. Anything so retained stays subject to this DPA.
We will make available the information reasonably necessary to demonstrate our compliance with this DPA, and will respond to a reasonable security questionnaire once in any 12-month period.
Where that is not enough to satisfy a specific regulatory obligation, you may audit — yourself or through an independent auditor who is not our competitor and who signs a confidentiality agreement — on at least 30 days' notice, no more than once a year (unless a regulator or a confirmed breach requires otherwise), during business hours, and without disrupting the Service or the data of other customers. Each party bears its own costs.
ChairFill runs on globally distributed infrastructure. Personal Data may be processed outside the country where your practice is located, including in the United States and the European Union, by the Sub-processors listed at /subprocessors.
Where Personal Data protected by the UK or EU GDPR is transferred outside the UK or EEA, the transfer is made under the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable. By accepting the Terms, both parties are deemed to have entered into those clauses, with you as data exporter and ChairFill as data importer, populated by Annexes I and II of this DPA.
Under the DPDP Act, transfers out of India are permitted except to territories the Central Government restricts; we will comply with any such restriction when notified.
Each party's liability under this DPA is subject to the limitations in section 15 of the Terms of Service, except where Data Protection Law does not permit that limitation.
If this DPA conflicts with the Terms or the Privacy Policy on the processing of Personal Data, this DPA prevails. Where the Standard Contractual Clauses apply and conflict with this DPA, those Clauses prevail.
We may update this DPA to reflect changes in law, in the Service, or in our Sub-processors. Material changes carry at least 30 days' notice by email or in the app. Each version is dated and numbered at the top of this page.
Provision of the ChairFill platform: automated and staff-assisted patient communication across WhatsApp, SMS, Instagram and voice; appointment scheduling and calendar synchronisation; reminders, recalls and no-show follow-up; review requests and responses; a practice website and CRM.
To enable your practice to receive enquiries, book and manage appointments, and communicate with patients about their visits.
The term of the Terms, plus the 30-day post-termination window, plus backup expiry as described in section 11.
| Category | Examples | Why it is processed |
|---|---|---|
| Identity and contact | Name, phone number, and email address where given | To recognise a returning patient and reply to them |
| Appointment | Date, time, duration, chair, treatment name, status | To book the visit and prevent double-booking |
| Communications | WhatsApp, SMS and Instagram message content and metadata | To continue a conversation and let staff take over from the assistant |
| Voice | Call audio and transcripts, where the voice receptionist is enabled | To answer calls and take bookings by phone |
| Consent record | When and through which channel the person first made contact | To evidence the lawful basis for messaging them |
| Technical | IP address and request metadata | Security, rate limiting and abuse prevention on public booking forms |
| Practice account | Staff login, business details, billing records | To operate and bill the account |
Special-category and health data. ChairFill is not designed to process clinical records, and section 5.4 of the Terms prohibits entering them. A treatment name attached to a booking ("Cleaning", "Root Canal") may nonetheless indicate health status and is treated with the same protections as the rest of the Personal Data. It should be the only clinical detail present.
Continuous, for as long as the Service is in use.
The current list, with each provider's role, the data it receives and where it processes it, is maintained at getchairfill.com/subprocessors and forms part of this DPA.
Data protection contact: privacy@getchairfill.com
Countersigned copy of this DPA: request at the address above
Sub-processor change notices: subscribe at the address above