Version 1.5. Effective July 30, 2026.
This Data Processing Addendum ("DPA") forms part of the ReadyMaxer Terms of Service between SmileMaxer LLC ("SmileMaxer", the "Processor") and the Practice (the "Controller") and applies whenever SmileMaxer processes personal data on the Practice's behalf that is subject to the GDPR, the UK GDPR, the Swiss FADP, or similar data protection laws ("Data Protection Laws"). It is automatically incorporated into the Terms for such Practices; no signature is required. Practices that need a countersigned copy can email legal@readymaxer.com.
1. Scope and roles
For team data the Practice enters or generates in ReadyMaxer (member names, departments, rooms, devices, signals, activity logs, and digital-line entries), the Practice is the controller and SmileMaxer is the processor. For admin accounts, billing, website data, and the crash diagnostics a person on a device chooses to send us, SmileMaxer is an independent controller under its Privacy Policy, and this DPA does not apply.
2. Details of processing
- Subject matter and duration: providing the ReadyMaxer service for the term of the Practice's subscription.
- Nature and purpose: hosting, storing, transmitting, and displaying team-signaling data; delivering push notifications; sign-in and device pairing; operating the Practice's anonymous digital lines; the Practice's own activity log.
- Categories of data subjects: the Practice's staff members and admins; visitors who join the Practice's digital line.
- Categories of personal data: first names or display names; department and shift status; device names, models, and push tokens; signal records with timestamps and optional short notes; server-generated nonidentifying digital-line aliases, SHA-256 browser-token hashes, queue status, and timestamps. Digital Line does not request or accept a visitor's name, contact details, or account. No special categories of data: the service prohibits entering patient or health information, and the Practice agrees not to submit any.
- Not included: device crash diagnostics. When an app stops unexpectedly it can send us a machine-generated report, and only if the person holding that device reads it and agrees, every time (Privacy Policy Section 2). Such a report names no member, no room, no device, no Practice, and no note, so it carries nothing the Practice controls. SmileMaxer processes it as controller, on that person's consent, to fix its own software (Section 1). Office admins never see these reports.
3. Processor obligations
SmileMaxer will:
- process personal data only on the Practice's documented instructions (the Terms, this DPA, and the Practice's use of the service's controls constitute those instructions), unless required by law, in which case SmileMaxer will inform the Practice unless the law forbids it;
- ensure persons authorized to process the data are bound by confidentiality;
- implement appropriate technical and organizational measures, as described in Annex II;
- respect the subprocessor conditions in Section 4;
- taking into account the nature of the processing, assist the Practice with data subject requests (access, erasure, and the other rights in Chapter III GDPR) and, considering the information available to it, with the Practice's obligations on security, breach notification, and data protection impact assessments;
- notify the Practice without undue delay after becoming aware of a personal data breach affecting the Practice's data, with the information reasonably available;
- at the end of the service, delete the Practice's personal data from the live service within 60 days (except where law requires retention), consistent with the Privacy Policy; deleted data may remain in encrypted disaster-recovery backups for no more than 30 days after deletion from the live service, those backups are not used for ordinary operations, and if a backup is restored, applicable deletion and account-closure obligations are reapplied; and
- make available the information reasonably necessary to demonstrate compliance with this DPA and, at the Practice's cost and no more than once per year, allow for audits (which SmileMaxer may satisfy with documentation, security summaries, or third-party reports).
4. Subprocessors
The Practice gives general authorization for the subprocessors listed at readymaxer.com/subprocessors. SmileMaxer will update that page at least 15 days before adding or replacing a subprocessor; the Practice may object on reasonable data-protection grounds by emailing legal@readymaxer.com, and if no resolution is found may cancel its subscription. SmileMaxer imposes data protection obligations on subprocessors consistent with this DPA and remains responsible for their performance.
5. International transfers
The service is hosted in the United States. Where transfers of EEA, UK, or Swiss personal data to SmileMaxer require a transfer mechanism, the parties incorporate by reference the EU Standard Contractual Clauses (Commission Decision 2021/914, Module Two, controller to processor), with the Practice as data exporter and SmileMaxer as data importer, and:
- Clause 7 (docking) included; Clause 9(a) Option 2 with 15 days' notice; Clause 11 optional language omitted; Clause 17 Option 1 with Irish law; Clause 18 courts of Ireland;
- Annex I is Section 2 of this DPA plus the parties' details from the Practice's account; Annex II is Annex II below; Annex III is the subprocessors page;
- for UK transfers, the UK International Data Transfer Addendum (version B1.0) applies with the table details completed by the foregoing; for Swiss transfers, the Clauses apply with the adaptations required by the FDPIC.
6. Liability and order of precedence
Each party's liability under this DPA is subject to the limitations of liability in the Terms, except where Data Protection Laws do not permit that. If this DPA conflicts with the Terms, this DPA controls for data protection matters; if the Standard Contractual Clauses conflict with this DPA, the Clauses control.
Annex II: Technical and organizational measures
- All transport encrypted with HTTPS/TLS.
- Passwords hashed with argon2id; session, device, and QR tokens stored only as SHA-256 hashes; pairing codes stored only as versioned, keyed HMAC-SHA-256 digests and single-use with short expiry.
- Data minimization by design: no member phone numbers or emails; Digital Line accepts no visitor identity and uses only server-generated random queue aliases; notes capped at 200 characters and labeled to exclude patient information; no analytics in the signed-in service.
- Tenant isolation enforced at the application layer; role-based access (owner, admin, member).
- Optional platform attestation on sensitive endpoints (Apple App Attest, Google Play Integrity, Cloudflare Turnstile).
- Hosting on Google Cloud with provider physical and network security; access to production limited to authorized personnel.
- Encrypted daily disaster-recovery backups in Google Cloud, retained for no more than 30 days and accessible only for disaster recovery; backups are not used for ordinary operations, and deletion and account-closure obligations are reapplied after a restore.
- IP addresses processed transiently in memory for rate limiting; not persisted.
- Automated retention enforcement: finished signals and digital-line entries purged after 90 days, activity log after 12 months, removed members anonymized after 60 days (Privacy Policy §8).
- Practice-facing controls: device revocation, member deactivation, room and data deletion, activity log.
Contact
SmileMaxer LLC, 11 S Eutaw St, Apt 915, Baltimore, MD 21201, USA, legal@readymaxer.com