1.Scope
MolarPlus is operated by Upclick Labs (OPC) Pvt. Ltd. (“MolarPlus”, “we”). This statement sets out how MolarPlus processes the personal data of individuals in the European Union under Regulation (EU) 2016/679 (the “GDPR”) and, in the United Kingdom, under the UK GDPR and the Data Protection Act 2018. References to the GDPR include the UK GDPR where the context allows.
2.Controller and processor
A dental practice using MolarPlus determines the purposes and means of processing its patients’ data and is the controller. MolarPlus processes that data on the practice’s behalf as a processor under Article 28.
Data concerning health is a special category of personal data under Article 9. The practice is responsible for the lawful basis of its processing, which for the provision of health care is ordinarily Article 9(2)(h).
MolarPlus is the controller of the account data of practice owners and staff, and of enquiries made through this website.
3.Processor obligations
MolarPlus enters into a Data Processing Agreement with each practice that requests one, on the terms Article 28(3) requires. The table below sets out how MolarPlus meets each of them.
4.Security of processing
Article 32 requires technical and organisational measures appropriate to the risk, including encryption, the ongoing confidentiality, integrity and availability of processing systems, and the ability to restore access to data after an incident. MolarPlus applies the following measures.
- Encryption at rest
- Patient and clinic records are held in a managed PostgreSQL database on Amazon RDS, encrypted at rest with AES-256. The storage volumes of the application servers are encrypted in the same way.
- Encryption in transit
- Every connection between a browser or the MolarPlus mobile app and the MolarPlus service is encrypted with TLS.
- Network isolation
- The production database accepts no connections from the public internet. It can be reached only from the MolarPlus application servers.
- Role-based access
- The clinic owner decides, section by section, what each staff member can see and do. Staff are given access to the information their work requires and nothing more.
- Authentication
- Every user signs in with an individual account. Passwords are stored only as bcrypt hashes, sign-in and sign-up are verified with one-time codes, and repeated attempts are rate limited.
- Audit trail
- Actions taken within a clinic account are recorded in an activity log, which the clinic owner can review and export.
- Private document links
- Documents, prescriptions and reports are kept in private object storage and are opened only through signed links that expire shortly after they are issued.
- Backups and recovery
- The database is backed up automatically every day, with point-in-time recovery available across a rolling seven-day window.
- Portability
- A clinic owner can download a complete archive of the clinic’s data at any time and export patient records as a spreadsheet, without contacting MolarPlus.
5.Personal data breaches
MolarPlus will notify the practice without undue delay after becoming aware of a personal data breach, as Article 33(2) requires, and will provide the information described in Article 33(3) as it becomes available, so that the practice can notify its supervisory authority within 72 hours where Article 33(1) requires and communicate the breach to patients where Article 34 requires.
6.International transfers
MolarPlus stores practice data on Amazon Web Services in the Asia Pacific (Mumbai) region, India. India is not the subject of an adequacy decision of the European Commission or an adequacy regulation in the United Kingdom.
Transfers of personal data from the European Economic Area to MolarPlus are therefore made under the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, and transfers from the United Kingdom under the International Data Transfer Addendum issued by the Information Commissioner, each incorporated into the Data Processing Agreement. Onward transfers to sub-processors outside the EEA and the United Kingdom are made under the same safeguards or another mechanism recognised under Chapter V.
7.Rights of data subjects
Patients exercise their rights against the practice, as controller. MolarPlus gives practices the means to act on those requests.
8.Retention and deletion
MolarPlus retains practice data for as long as the practice’s account is active. A practice may download a complete copy of its data at any time. When a practice closes its account and instructs MolarPlus to delete its data, MolarPlus deletes that data from its production systems, and copies held in automated backups expire as the 7-day backup window rolls over.
Practices remain responsible for keeping health records for any period required by the law of their Member State or by their professional regulator, and should export those records before requesting deletion.
9.Contact
Requests for a Data Processing Agreement, and questions about this statement, may be sent to: