PerioMaxer
The appFor officesHow it worksPricingDownloadsLog in

Data Processing Addendum

Version 1.0. Effective July 25, 2026.

This Addendum forms part of the Terms of Service between SmileMaxer LLC ("SmileMaxer", "we") and the practice that opened a PerioMaxer account ("Customer", "you"). It governs personal data that we process on your behalf when you use PerioMaxer.

How this relates to the BAA

This Addendum and the Business Associate Agreement cover different things, and a practice may need both.

  • The BAA covers protected health information under HIPAA. You sign it once, from the account dashboard, and it covers every SmileMaxer app your practice uses. See the BAA template.
  • This Addendum covers personal data under data-protection law such as the GDPR and the UK GDPR: your staff's account records, billing contacts, and device registrations.

Where the two overlap, the BAA governs protected health information.

1. Roles

You are the controller of the personal data you put into PerioMaxer. We are the processor. We process that data only to provide the service, only on your documented instructions, and never for our own purposes. Using the service is your instruction to process.

Where we decide how and why data is handled on our own account, such as our own billing records and public marketing pages, we act as a controller and the Privacy Policy applies instead.

2. What we process

  • Categories of data subject: your staff. Dentists, hygienists, assistants, office managers, and the account owner.
  • Categories of data: work email, full name, role, password hash, authentication and login-security events, practice name and physical address, billing contact, registered mobile devices and office computers, active-session records, configuration, audit records, and support messages.
  • Purpose: operating the account, licensing, enforcing simultaneous-session limits, billing, support, and security.
  • Duration: the life of your subscription, plus the retention periods in Section 8.

3. What we do not process

The cloud service is not designed to receive voice audio, periodontal chart values, or patient names, and we do not ask you to send them. Voice recognition runs on your device. Chart entries move between the phone and the paired office computer over your own network. Do not put patient information into support messages.

4. Our obligations

We will:

  • process personal data only on your documented instructions, and tell you if we believe an instruction breaks data-protection law;
  • bind everyone we let near the data to confidentiality;
  • keep the security measures in Section 6;
  • help you answer data-subject requests, run data-protection impact assessments, and deal with regulators, taking into account what we know and what the service can do;
  • give you the information you need to show you comply with this Addendum, and allow audits as described in Section 9.

5. Subprocessors

You give us general authorization to use subprocessors. The current list is published at /subprocessors.

We will update that page at least 15 days before we add or replace a subprocessor that handles practice data. You may object in writing within those 15 days on reasonable data-protection grounds. If we cannot resolve the objection, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees.

Every subprocessor is bound by written terms no weaker than this Addendum. We remain responsible to you for their performance.

6. Security

We maintain technical and organizational measures appropriate to the risk, including:

  • encryption in transit for all cloud traffic, and encryption at rest for the account database;
  • certificate-fingerprint pinning on the phone-to-computer pairing link, which stays on your local network;
  • role-based access control, with multi-factor authentication required for our own administrative access;
  • one-use pairing tickets stored only as cryptographic hashes, expiring after two minutes;
  • audit logging of account changes, device actions, and administrative events;
  • separation of the cloud licensing plane from the local clinical plane, so chart traffic never enters the cloud service.

7. Personal data breaches

We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your data. The notice will describe what happened, the likely consequences, and what we are doing about it, so far as we know at the time. Notice to you is not an admission of fault.

8. Deletion and return

You can export your account data from the dashboard at any time while the subscription is live.

On termination, we delete or return personal data within 90 days, except where law requires us to keep it. Billing and tax records are kept for seven years. Security and audit logs are kept for two years. Backups roll off on their own schedule within 90 days.

Individual accounts can also be deleted at any time; see account deletion.

9. Audits

On reasonable written notice, no more than once a year, we will answer a reasonable security questionnaire and provide the documentation we hold. If a regulator requires more, we will work with you in good faith to arrange it, at your cost, without disturbing other customers.

10. International transfers

We host the service in the United States. Where you transfer personal data out of the EEA, the United Kingdom, or Switzerland to us, the European Commission's Standard Contractual Clauses (Module Two, controller to processor) are incorporated into this Addendum by reference, with the UK Addendum and the Swiss amendments applied as relevant. This Addendum supplies the information those clauses need in their annexes: Sections 1 and 2 describe the parties, data, and purposes; Section 6 describes the security measures; Section 5 points to the subprocessor list.

11. Liability and precedence

Each party's liability under this Addendum is subject to the limits in the Terms of Service. If this Addendum conflicts with the Terms of Service on the processing of personal data, this Addendum wins. If it conflicts with the BAA on protected health information, the BAA wins.

Contact

support@periomaxer.com, SmileMaxer LLC, a Maryland limited liability company.

PerioMaxer
PricingDownloadsThe appFor officesHow it worksSecurity & HIPAADocsLog inTermsPrivacyEULADPASubprocessorsBAADelete accountDSO contactsupport@periomaxer.com
© 2026 SmileMaxer · PerioMaxer is a SmileMaxer app. Voice perio charting for phones, operatory desktops, and your PMS.