PricingDownloadsLog in

Data Processing Addendum

Version 1.2. Effective September 4, 2026.

This Addendum forms part of the Terms of Service between SmileMaxer LLC ("SmileMaxer", "we") and the practice that opened a PerioMaxer account ("Customer", "you"). It governs personal data that we process on your behalf when you use PerioMaxer.

How this relates to the BAA

This Addendum and the Business Associate Agreement cover different things, and a practice may need both.

  • The BAA covers protected health information under HIPAA. You sign it once, from the account dashboard, and it applies to the SmileMaxer and PerioMaxer office-link services described in that agreement. It does not extend to other SmileMaxer LLC products that are designed to hold no patient information, and signing it does not permit patient information to be entered into such a product. See the BAA template.
  • This Addendum covers personal data under data-protection law such as the GDPR and the UK GDPR: your staff's account records, billing contacts, and device registrations.

Where the two overlap, the BAA governs protected health information.

1. Roles

You are the controller of the personal data you put into PerioMaxer. We are the processor. We process that data only to provide the service, only on your documented instructions, and never for our own purposes. Using the service is your instruction to process.

Where we decide how and why data is handled on our own account, such as our own billing records and public marketing pages, we act as a controller and the Privacy Policy applies instead.

2. What we process

  • Categories of data subject: your staff. Dentists, hygienists, assistants, office managers, and the account owner.
  • Categories of data: work email, full name, role, password hash, authentication and login-security events, practice name and physical address, billing contact, registered mobile devices and office computers, active-session records, configuration, audit records, support messages, and voluntarily submitted feedback attachments.
  • Purpose: operating the account, licensing, enforcing simultaneous-session limits, billing, support, and security.
  • Duration: the life of your subscription, plus the retention periods in Section 8.

3. What we do not process

The account and licensing interfaces do not accept clinical chart traffic. Voice recognition runs on your device, and Office Link chart entries move between the phone and the paired office computer over your own network. Separately, our support service receives voluntary feedback reports and selected attachments, which may include non-patient test recordings, transcripts, and sandbox logs. Do not put patient information into support messages or attachments. The Privacy Policy describes this support data and its retention.

4. Our obligations

We will:

  • process personal data only on your documented instructions, and tell you if we believe an instruction breaks data-protection law;
  • bind everyone we let near the data to confidentiality;
  • keep the security measures in Section 6;
  • help you answer data-subject requests, run data-protection impact assessments, and deal with regulators, taking into account what we know and what the service can do;
  • give you the information you need to show you comply with this Addendum, and allow audits as described in Section 9.

5. Subprocessors

You give us general authorization to use subprocessors. The current list is published at /subprocessors.

We will update that page at least 15 days before we add or replace a subprocessor that handles practice data. You may object in writing within those 15 days on reasonable data-protection grounds. If we cannot resolve the objection, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees.

Every subprocessor is bound by written terms no weaker than this Addendum. We remain responsible to you for their performance.

6. Security

We maintain technical and organizational measures appropriate to the risk, including:

  • encryption in transit for all cloud traffic, and encryption at rest for the account database;
  • certificate-fingerprint pinning on the phone-to-computer pairing link, which runs directly between your own devices;
  • role-based access control, with multi-factor authentication required for our own administrative access;
  • one-use pairing tickets stored only as cryptographic hashes, expiring after two minutes;
  • audit logging of account changes, device actions, and administrative events;
  • separation of the cloud licensing plane from the local clinical plane, so chart traffic never enters the cloud service.

7. Personal data breaches

We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your data. The notice will describe what happened, the likely consequences, and what we are doing about it, so far as we know at the time. Notice to you is not an admission of fault.

8. Deletion and return

You can request a copy of your account data at any time while the subscription is live by emailing support@periomaxer.com from your account address. We verify the request before providing the copy.

On termination, we delete or return personal data within 90 days, except where law requires us to keep it. Billing and tax records are kept for seven years. Security and audit logs are kept for two years. Backups roll off on their own schedule within 90 days.

Individual accounts can also be deleted at any time; see account deletion.

9. Audits

On reasonable written notice, no more than once a year, we will answer a reasonable security questionnaire and provide the documentation we hold. If a regulator requires more, we will work with you in good faith to arrange it, at your cost, without disturbing other customers.

10. International transfers

We host the service in the United States. Where you transfer personal data out of the EEA, the United Kingdom, or Switzerland to us, the European Commission's Standard Contractual Clauses (Module Two, controller to processor) are incorporated into this Addendum by reference, with the UK Addendum and the Swiss amendments applied as relevant. This Addendum supplies the information those clauses need in their annexes: Sections 1 and 2 describe the parties, data, and purposes; Section 6 describes the security measures; Section 5 points to the subprocessor list.

11. Liability and precedence

Each party's liability under this Addendum is subject to the limits in the Terms of Service. If this Addendum conflicts with the Terms of Service on the processing of personal data, this Addendum wins. If it conflicts with the BAA on protected health information, the BAA wins.

Contact

support@periomaxer.com, SmileMaxer LLC, a Maryland limited liability company.

PerioMaxer
PricingDownloadsThe appFor officesHow it worksSecurity & HIPAADocsLog inTermsPrivacyEULADPASubprocessorsBAADelete accountDSO contactsupport@periomaxer.com
© 2026 SmileMaxer · PerioMaxer is a SmileMaxer app. Voice perio charting for phones, operatory desktops, and your PMS.