SmileyWay
Back to site

Data Processing Addendum

Last updated 20 September 2026

For clinics. The written terms on which SmileyWay processes your patients’ records on your behalf — what we may do with them, how we protect them, and what happens when you leave.

1. What this is

This Addendum forms part of the Terms of Service and applies whenever a clinic uses SmileyWay to hold records about its patients. Where it conflicts with the Terms of Service on the handling of patient data, this Addendum wins.

It is written for Jordan’s Personal Data Protection Law No. 24 of 2023.

2. Roles

The clinic is the controller of its patient records. SmileyWay is the processor. The clinic decides what patient data is collected, why, and for how long; SmileyWay processes it only to provide the service and only on the clinic’s documented instructions, which include the instructions given through the ordinary use of the software.

SmileyWay will tell the clinic if, in its opinion, an instruction would breach the law — though it is not SmileyWay’s role to audit the clinic’s legal basis for holding a record.

3. Scope of the processing

Subject matter: providing dental clinic management software.

  • Duration: for as long as the clinic’s account is open, plus thirty days.
  • Nature: storage, organisation, retrieval, display, transmission of reminders and messages, backup, and deletion.
  • Purpose: running the clinic — records, scheduling, treatment planning, billing and communication with patients.
  • Categories of data subject: the clinic’s patients and their guardians, and the clinic’s own practitioners and staff.
  • Categories of data: identity and contact details, date of birth, health data (medical history, allergies, medications, clinical notes, treatment plans, tooth charts, clinical images), appointment and attendance records, and payment records.

Health data is sensitive personal data under the PDPL. Both parties treat it as such throughout.

4. What SmileyWay undertakes

  • To process patient data only on the clinic’s instructions, and never for its own purposes.
  • Never to sell patient data, share it with advertisers, or use it to train machine learning models.
  • To keep it confidential, and to bind every person with access to a duty of confidentiality.
  • To apply the security measures set out in the Privacy Policy, and not to weaken them during the term.
  • To restrict access to staff who need it to run or support the service, and to log every access to a patient record, including its own.
  • To assist the clinic, so far as it reasonably can, in answering a patient’s request to see, correct or erase their data, and in any consultation with the regulator.
  • To notify the clinic without undue delay on becoming aware of a breach affecting its data, with what is known about what happened, who is affected, and what is being done.
  • To make available the information the clinic reasonably needs to satisfy itself that this Addendum is being met.

5. What the clinic undertakes

  • To have a lawful basis for each record it puts into SmileyWay, and to obtain and record consent where consent is the basis — including a guardian’s consent for a patient under 18.
  • To tell its patients how their data is used, and that it is held in software provided by a third party.
  • To give each member of staff their own account, and to remove accounts promptly when people leave.
  • Not to enter data that is unlawful, or that the clinic has no right to hold.

6. Sub-processors

The clinic authorises SmileyWay to engage the sub-processors listed in the Privacy Policy. Each is bound by terms no less protective than this Addendum, and SmileyWay remains responsible to the clinic for what they do.

SmileyWay will give the clinic at least thirty days’ notice before adding or replacing a sub-processor. If the clinic reasonably objects on data protection grounds, it may terminate the affected service without penalty and export its records.

7. International transfers

The infrastructure SmileyWay runs on may be located outside Jordan, which makes this a cross-border transfer of sensitive personal data under the PDPL. The clinic should satisfy itself that this is acceptable for its patients before it begins, and SmileyWay will provide the information it needs to make that assessment on request.

8. Return and deletion

At any time while the account is open, and for thirty days after it closes, the clinic may export its records in a usable format.

After those thirty days SmileyWay deletes the clinic’s patient data from its live systems, and from backups within the normal backup rotation. The exception is the patient-record access log, which is retained as a safety record and is not deleted on request.

9. Liability

The limits of liability in the Terms of Service apply to this Addendum. Nothing here limits either party’s liability to a patient under the Personal Data Protection Law.

10. Contact

For anything under this Addendum, including a breach notification or a signed copy: privacy@smiley-way.com.

This page is provided for information. It is not legal advice and it does not create a lawyer–client relationship. If you need advice about your own obligations, speak to a lawyer qualified in Jordan.