elefan.appAn elephant never forgets

Data processing agreement

Version 2026-08-05 · between a practice using elefan.app and YDA Ltd

Who is who

The practice is the controller of the personal data it keeps here about its patients and its team: it decides what to record and why. УАЙ ДИ ЕЙ ЕООД (YDA Ltd, “we”) is its processor — we hold and handle that data only to run the service for the practice. This agreement is the contract Article 28(3) of the GDPR requires between the two, and it takes effect when a practice accepts it at sign-up or in its settings. It stands alongside the terms of service; where the two disagree about personal data, this one wins.

What we process, and for how long

Subject matter: running an appointment book and online booking for the practice. Duration: as long as the practice has an account, plus the 30 days afterwards during which its data can still be retrieved. Data subjects: the practice’s patients and the people on its team. Categories: names, phone numbers, email addresses, appointment times and what a visit is about, notes the practice writes, and — where the practice enters one — a national identification number. Appointment and patient records concern health, so they are special-category data under Article 9.

We act on the practice’s instructions

We process that data only to provide the service, and on the practice’s instructions — the settings it chooses and the actions its team takes are those instructions. We do not sell it, we do not use it to train anything, and we do not use it for our own purposes. If a law obliges us to do something else, we tell the practice first unless that law forbids us to.

Confidentiality

The people who can reach practice data on our side are bound to confidentiality and are only those who need it to run or support the service.

Security

Data is stored in the European Union. It is encrypted in transit and at rest by our hosting and database providers. Access inside the app is decided by role — a receptionist, a dentist and an owner do not see the same things — and staff sign-in requires a second factor. Platform administrators can enter a practice to support it; that is recorded, and the practice sees a banner while it happens. We describe what we actually do rather than claim certifications we do not hold.

Sub-processors

The practice authorises us to use the providers listed in our privacy policy, each bound to the same obligations we owe here. We give at least 30days’ notice before adding or replacing one, by email to the practice account. A practice that objects on reasonable data-protection grounds may end its account without penalty and take its data with it.

Helping with patients’ rights

Patients exercise their rights with the practice, not with us — it is their controller. The product does part of that work for it: a patient can download their own account and appointments, and delete their account, from the patient portal; a practice can export everything it holds from Practice settings → Your data. Where a request needs more than those, we help within what the service can technically do.

If there is a breach

We tell the affected practice without undue delay and in any case within 72 hours of becoming aware of a personal data breach involving its data, with what we know: what happened, whose data it touched, and what we are doing about it. The practice notifies its supervisory authority — for a Bulgarian practice, the Commission for Personal Data Protection — and we give it what it needs for that.

Impact assessments

If the practice has to carry out a data protection impact assessment or consult its authority about its use of the service, we provide the information about how the service works that such an assessment needs.

Deletion and return

The practice can take a full copy of its data at any time, in a machine-readable file, without asking us. When its account closes we keep the data for 30 days so it can still be retrieved, then delete it — except where a law requires us to keep something longer, in which case we keep only that, and only for as long as required.

Showing our work

We make available the information a practice needs to check that we are keeping to this agreement, and we allow audits — by the practice or an auditor it mandates — on reasonable notice, during working hours, and without disturbing other practices’ data. In practice, ask us first: most questions are answered faster in writing than by an audit.

Outside the European Union

We do not transfer practice data outside the European Economic Area. If that ever has to change, we will say so in advance, name the country and the safeguard used, and a practice that objects may leave with its data.

Changes to this agreement

This version is dated 2026-08-05. If we change it materially, we publish the new version, tell the practice account by email, and ask for acceptance again — an amended contract that quietly re-uses an old signature is not an agreement.

Questions about this agreement: . See also our privacy policy and terms of service.