Data Processing / GDPR
Updated 6 October 2026
NordSmile is developed by Undahealth OÜ in Estonia. This page explains the privacy discussion for a clinic pilot; it is not a signed data processing agreement or a certification of GDPR compliance.
Start with a demonstration
The landing page uses demonstration clinic data. No live patient information is needed for a demo or pilot enquiry. Contact info@undahealth.com with business details only.
Agree responsibilities before using patient data
Where a clinic determines why patient data is used and NordSmile processes it on the clinic’s behalf, the clinic acts as controller and Undahealth OÜ acts as processor for that processing. The actual roles and scope must be documented for the agreed workflow. GDPR Article 28 requires a suitable agreement for controller–processor processing.
What to confirm for your pilot
- The purpose, duration, patient-data fields and people covered by each workflow.
- Instructions, authorised access, confidentiality and the security measures for the agreed setup.
- Hosting locations, subprocessors and any international-transfer arrangements.
- Retention, return or deletion of data when the pilot ends.
- Handling patient requests, incidents and clinic oversight.
- The clinic’s basis for patient communication and the relevant patient notices.
These details should be settled in writing before any live patient data is used. The marketing page does not establish the hosting location or security configuration of a future clinic deployment.
Request the relevant information
Contact the NordSmile team about data processing to discuss your proposed pilot and the documentation required. Website and enquiry handling are described separately in our Privacy Policy.
Reference: GDPR, including Article 28.