Back
Version: 01/10/2026
Data Processing Agreement
Cadmus Labs B.V.
Comprised of:
Part 1: Data Pro Statement
Part 2: Standard Clauses for Data Processing
NLdigital Standard Clauses: March 2025 version
Data Pro Statement version: 1, in force from 1 October 2026
Part 1: Data Pro Statement
Along with the Standard Clauses for Data Processing, this Data Pro Statement constitutes the data processing agreement for the product or service provided by the company that has drawn up this Data Pro Statement.
General information
1. This Data Pro Statement was drawn up by the following data processor (verwerker):
Cadmus Labs B.V.
Moddermanstraat 27
2313 GN Leiden
Nederland
If you have any queries about this Data Pro Statement or data protection in general, please contact: S.L. Dinh, info@cadmuslabs.nl.
2. This Data Pro Statement shall enter into force on 1 October 2026.
We regularly revise the security measures described in this Data Pro Statement to ensure that we are always fully prepared and up to date with regard to data protection. If this document is updated, we shall notify you of the revised versions through our regular channels.
Duration of the processing: The processing takes place for the duration of the Agreement between data processor and Client. This data processing agreement enters into force upon conclusion of the Agreement and remains in effect for as long as data processor processes personal data on behalf of the Client, ending automatically upon termination of the Agreement.
3. This Data Pro Statement applies to the following products and services provided by data processor:
Cadmus Software: a central digital order inbox for dental and orthodontic laboratories, enabling automated and unified digital order processing from multiple intraoral scanner portals.
4. Description of product(s)/service(s)
The Cadmus Software consists of three main components:
Inbox: central reception and unification of digital orders, including a user interface to view and export order files.
Dashboard: interface for monitoring and providing an overview of order volumes and scanner performance.
API: integration facility that enables laboratories to retrieve digital orders in a uniform format and process them within their own digital workflow.
The software is used by dental and orthodontic laboratories to efficiently and uniformly process digital orders placed by dentists and orthodontists. Orders are automatically retrieved from multiple intraoral scanner portals, unified, and made available to the laboratories for further processing.
5. Intended use
Cadmus processes personal data solely on behalf of and on the documented instructions of its Client, as a sub-processor. Google Cloud (including Vertex AI) and TransIP act as Cadmus's sub-processors.
Product/service is designed and built to process the following types of data:
Patient identification data (e.g. name, order reference number, date of birth);
Patient-related medical data (e.g. intra-oral scans, clinical photographs, dental/orthodontic order information);
Contact and practice details of dentists and orthodontists (e.g. name, email address, phone number, practice name).
The Service is specifically designed and built to process special categories of personal data within the meaning of Article 9 GDPR, namely health data, comprising the intra-oral scans, clinical photographs and dental and orthodontic order information relating to patients. This constitutes an explicit arrangement to that effect as referred to in the Standard Clauses for Data Processing, and the general assumption that the Service is not equipped to process special categories of personal data does not apply.
The Service is not designed to process data concerning criminal convictions and offences, or national identification numbers (such as the BSN) issued by the government. The Client shall not use the Service to process such data.
Order data (specifically the textual order information and comments provided by dentists and orthodontists) is automatically classified and enriched using AI (Google Vertex AI) to recognise characteristics such as work type, colour, placement and material, for the purpose of order processing. This classification concerns administrative order characteristics only; it does not involve any medical assessment or diagnosis. The intra-oral scans, clinical photographs and date of birth are received, stored and made available to the laboratory, but are not analysed, enriched, or used to train models.
6. Privacy by design / privacy by default
To provide the Service, Cadmus processes the data provided by dentists, orthodontists and dental laboratories and does not store more personal data than delivered through the relevant scanner portals for that purpose. Any additional data manually added by the Client or authorised third parties is the sole responsibility of the Client. Access to all data is restricted to authorised users via secure login.
The Client remains responsible for implementing privacy by design and privacy by default. Cadmus is not responsible for any additional processing, enrichment, or disclosure of data performed by the Client or third parties on the Client's behalf.
For the avoidance of doubt, the automated classification of order data described in section 5 is a processing activity carried out by Cadmus as part of the Service, and is distinct from any enrichment performed by the Client or third parties.
In addition to processing personal data to provide the Service, Cadmus creates a de-identified dataset by irreversibly removing direct identifiers (including patient names, order reference numbers, dates of birth, and clinician and practice names) and screening free-text order information to remove patient-identifying information, so that the result no longer constitutes personal data and cannot reasonably be traced to any patient, dentist, orthodontist, laboratory or Client. This de-identification is carried out on the Client's instruction. The resulting de-identified data does not constitute personal data and is not processed on the Client's behalf; Cadmus determines the purposes and means of its use, and may use it to improve, develop and analyse its products and services and to train its own models, may share aggregated insights derived from it, and may make the de-identified dataset available to third parties provided it remains de-identified. Until this de-identification is implemented, Cadmus limits such use to operational metadata that is not personal data, and does not use identifiable personal data for these purposes.
7. Standard Clauses for Data Processing
Data processor uses the NLdigital Standard Clauses for Data Processing (March 2025 version), which are attached to the Agreement as an addendum (Part 2).
8. Processing location
Data processor shall process the personal data provided by their clients within the EU/EEA.
9. Sub-processors
Data processor uses the following sub-processors:
Google Cloud (including Vertex AI)
Servers, storage and AI processing (EU/EEA locations). Vertex AI is used to automatically classify and enrich textual order data (recognising work type, colour, placement and material). All processing and storage occur within the EU/EEA, and data provided to Vertex AI is not used by Google to train Google's models. This does not restrict Cadmus's use of de-identified data to train Cadmus's own models as described in section 6. Intra-oral scans and image content are not processed by Vertex AI.
TransIP
Hosting, email and domain management (EU/EEA locations). All processing occurs within the EU/EEA.
10. Support for data-subject requests
Data processor shall support their clients as follows when they receive requests from data subjects:
Clients can log in at any time to view and export personal data.
Requests to modify or delete data can be submitted by email to info@cadmuslabs.nl.
11. Support for Data Protection Impact Assessments (DPIA)
If the Client is required to conduct a Data Protection Impact Assessment (DPIA), the Data Processor shall, upon a reasonable request, provide its cooperation in the DPIA.
12. Deletion of personal data
Scan data (intra-oral scans, clinical photographs and other files attached to an order) is deleted twelve (12) months from the date of collection, and all other order data three (3) years from the date of collection, including during the term of the Agreement, in such a manner that the data can no longer be used and is rendered inaccessible. The Client may request deletion of specific data before the end of these periods in accordance with section 10. Upon termination of the Agreement, any remaining personal data is deleted within three (3) months, in accordance with the export procedure set out in section 13.
13. Returning of personal data once the Agreement has been terminated
During the term of the Agreement, the Client can export data at any time via the web portal or API. Upon termination, this export functionality remains available for a period of thirty (30) days. Intra-oral scans, clinical photographs and order forms can be exported via the API within this period. After this thirty-day period, no further export is possible, and any remaining data is deleted within three (3) months of termination.
The Client is responsible for creating timely backups of any data it wishes to retain. Cadmus does not accept responsibility for data loss arising from the Client's failure to do so.
Self-service export via the web portal or API is free of charge. Where the Client requests Cadmus to perform a bulk export on its behalf, Cadmus may provide a quote. Costs will be based on the volume of data, any charges imposed by the cloud or hosting provider, and the time required by Cadmus to perform the export, to the extent permitted by applicable law.
Security policy
14. Data processor has implemented the following security measures to protect their product or service:
Pseudonymisation
Personal data is not pseudonymised, as the platform requires identifiable information for order processing and lab operations. Access is restricted to authorized users.
Secure channels
All personal data is transmitted via secure channels (TLS/HTTPS) to ensure confidentiality and integrity.
Encryption
Personal data is encrypted both in transit (TLS/HTTPS) and at rest. Data stored within the EU/EEA cloud environment is encrypted using industry-standard encryption managed by our sub-processors.
Access control
Access to the platform is restricted via secure login credentials. Role-based access ensures users can only view and process data necessary for their tasks.
Data integrity and availability
Regular backups, redundancy, and monitoring ensure the integrity and availability of data.
Security testing and evaluation
Cadmus Labs periodically reviews and evaluates the effectiveness of its technical and organisational security measures, and adjusts them where necessary (plan-do-check-act).
Incident response and recovery
Cadmus Labs maintains procedures for responding to security incidents. Systems are monitored to detect potential incidents, any suspected or confirmed incident is escalated internally without delay, and affected clients are notified in line with the Data Breach Protocol below. These procedures ensure that, in the event of a security incident:
access to personal data can be restored in a timely manner, and
the continuity of our services is maintained as much as possible.
Organizational measures
All employees and contractors processing personal data are bound by confidentiality agreements.
15. Data processor conforms to the principles of the following Information Security Management System (ISMS):
Cadmus Labs is working to align its internal processes and controls with recognized information security standards, striving to implement appropriate organizational and technical measures within practical possibilities. While no formal certification has been obtained, our internal controls are designed to reflect these standards.
Sub-processors engaged by Cadmus Labs, such as Google Cloud and TransIP, hold official certifications (e.g., ISO 27001, ISO 27701) and operate in compliance with strict security and privacy standards.
Data breach protocol
16. In the event something does go wrong, data processor shall follow the following data breach protocol to ensure that clients are notified of incidents:
Cadmus Labs monitors its systems to detect potential security incidents. Any suspected or confirmed data breach is reported internally immediately.
Clients will be notified as soon as reasonably possible, including:
Nature of the incident;
Categories of personal data affected;
Estimated number of affected data subjects and impacted systems;
Potential consequences for data subjects;
Measures taken to mitigate further damage.
Guidance on actions for the client or data subjects will be provided. Responsibility for notifying authorities or data subjects remains with the client.
Notifications will be sent to the client contact specified in the Agreement without undue delay, and in any event in good time to allow the Client (as controller) to meet its own notification obligations under Articles 33 and 34 GDPR, including the 72-hour deadline for reporting to the Dutch Data Protection Authority. As a rule, Cadmus Labs aims to notify the Client within 24 hours of confirmation of the breach. Further updates will follow as needed.
Part 2: Standard Clauses for Data Processing
Version: March 2025
Part 2 reproduces the NLdigital Standard Clauses for Data Processing (March 2025 version), published by NLdigital and used unmodified under NLdigital’s terms of use. © NLdigital. In case of conflict between the Dutch and English versions of these clauses, the Dutch version prevails.
Along with the Data Pro Statement, these standard clauses constitute the data processing agreement. They also constitute an annex to the Agreement and to the appendices to this Agreement, e.g. any general terms and conditions which may apply.
Article 1. Definitions
The following terms have the following meanings ascribed to them in the present Standard Clauses for Data Processing, in the Data Pro Statement and in the Agreement:
1.1 Dutch Data Protection Authority (AP): the supervisory authority defined in Section 4.21 of the GDPR.
1.2 GDPR: the General Data Protection Regulation.
1.3 Data Processor: the party which, in their capacity as an ICT supplier, processes Personal Data on behalf of their Client as part of the performance of the Agreement.
1.4 Data Pro Statement: statement issued by Data Processor in which they provide information such as the intended use of their products and/or services, any security measures which have been implemented, sub-processors, data breach, certification and dealing with the rights of Data Subjects.
1.5 Data Subject: a natural person who can be identified, directly or indirectly.
1.6 Client: the party on whose behalf Data Processor processes Personal Data. Client can either be the controller (the party who determines the purpose and means of the processing) or another data processor.
1.7 Agreement: the agreement concluded between Client and Data Processor, based on which the ICT supplier provides services and/or products to Client, the data processing agreement forming part of this agreement.
1.8 Personal Data: any and all information regarding a natural person who has been or can be identified, as defined in Article 4.1 of the GDPR, processed by Data Processor as required under the Agreement.
1.9 Data Processing Agreement: the present Standard Clauses for Data Processing, which, together with Data Processor's Data Pro Statement (or similar such information), constitute the data processing agreement within the meaning of Article 28.3 of the GDPR.
Article 2. General provisions
2.1 The present Standard Clauses for Data Processing apply to all Personal Data processing operations carried out by Data Processor in providing their products and services, as well as to all Agreements and offers. The applicability of Client's data processing agreements is explicitly rejected.
2.2 The Data Pro Statement, and particularly the security measures described in it, may be adapted from time to time to changing circumstances by Data Processor. Data Processor shall notify Client in the event of significant revisions. If Client in all reasonableness cannot agree to the revisions, Client shall be entitled to terminate the data processing agreement in writing, stating their reasons for doing so, within thirty days of having been served notice of the revisions.
2.3 Data Processor shall process the Personal Data on behalf of Client, in accordance with the written agreed upon instructions provided by Client to Data Processor.
2.4 Client or their customer shall serve as the controller within the meaning of the GDPR, shall have control over the processing of the Personal Data and shall determine the purpose and means of processing the Personal Data.
2.5 Data Processor shall serve as the processor within the meaning of the GDPR and shall therefore not determine the purpose and means of processing the Personal Data, and shall not make any decisions on the use of the Personal Data and other such matters.
2.6 Data Processor shall implement the GDPR as laid down in the present Standard Clauses for Data Processing, the Data Pro Statement and the Agreement. It is up to Client to assess, on the basis of this information, whether Data Processor is providing sufficient guarantees with regard to the implementation of appropriate technical and organisational measures in order to ensure that the processing operations meet the requirements of the GDPR and that Data Subjects' rights are sufficiently protected.
2.7 Client shall guarantee Data Processor that they act in accordance with the GDPR, that they provide a high level of protection for their systems and infrastructure at all times, that the nature, use and/or processing of the Personal Data are not unlawful and that they do not violate any third party's rights.
2.8 Administrative fines imposed on Client by the Dutch Data Protection Authority cannot be recovered from Data Processor.
Article 3. Security
3.1 Data Processor shall implement the technical and organisational security measures set out in their Data Pro Statement. In implementing the technical and organisational security measures, Data Processor shall take into account the state of the art and the costs of implementation, as well as the nature, scope, context and purposes of the processing and the intended use of their products and services, and the risk in processing the data of varying likelihood and severity inherent to the rights and freedoms of Data Subjects that are to be expected considering the nature of the intended use of Data Processor's products and services.
3.2 Unless explicitly stated otherwise in the Data Pro Statement, the products and services provided by Data Processor shall not be equipped to process special categories of personal data or data relating to criminal convictions and offences.
3.3 Data Processor seeks to ensure that the security measures they shall implement are appropriate for the manner in which Data Processor intends to use the products and services.
3.4 In Client's opinion, said security measures provide a level of security that is tailored to the risk inherent in the processing of the Personal Data used or provided by Client, taking into account the factors referred to in Article 3.1.
3.5 Data Processor shall be entitled to adjust the security measures they have implemented if to their discretion such is necessary for a continued provision of an appropriate level of security. Data Processor shall record any significant adjustments they choose to make, e.g. in a revised Data Pro Statement, and shall notify Client of said adjustments where relevant.
3.6 Client may request Data Processor to implement further security measures. Data Processor shall not be obliged to honour such requests to adjust their security measures. If Data Processor makes any adjustments to their security measures at Client's request, Data Processor is entitled to invoice Client for the costs associated with said adjustments. Data Processor shall not be required to actually implement the requested security measures until both Parties have agreed upon them in writing.
Article 4. Data breaches
4.1 Data Processor does not guarantee that their security measures shall be effective under all circumstances. If Data Processor discovers a data breach within the meaning of Article 4 sub 12 of the GDPR, they shall notify Client without undue delay. The “Data Breach Protocol” section of the Data Pro Statement outlines the way in which Data Processor shall notify Client of data breaches.
4.2 It is up to the Controller (the Client or their customer) to assess whether the data breach of which Data Processor has notified the Controller must be reported to the Dutch Data Protection Authority or to the Data Subject concerned. The Controller (Client or their customer) shall at all times remain responsible for reporting data breaches which must be reported to the Dutch Data Protection Authority and/or Data Subjects pursuant to Articles 33 and 34 of the GDPR. Data Processor is not obliged to report data breaches to the Dutch Data Protection Authority and/or to the Data Subject.
4.3 Where necessary, Data Processor shall provide further information on the data breach and shall assist Client to meet their breach notification requirements within the meaning of Articles 33 and 34 of the GDPR by providing all the necessary information available to Data Processor.
4.4 If Data Processor incurs any reasonable costs in doing so, they are entitled to invoice Client for these, at the rates applicable at the time.
Article 5. Confidentiality
5.1 Data Processor shall ensure that the persons processing Personal Data acting under its authority have committed themselves to confidentiality.
5.2 Data Processor shall be entitled to provide third parties with Personal Data if and insofar as such is necessary due to a court order, statutory provision or order issued by a competent government authority.
5.3 Any and all access and/or identification codes, certificates, information regarding access and/or password policies provided by Data Processor to Client, and any and all information provided by Data Processor to Client detailing the technical and organisational security measures included in the Data Pro Statement are confidential and shall be treated as such by Client and shall only be disclosed to authorised employees of Client. Client shall ensure that their employees comply with the requirements described in this article.
Article 6. Term and termination
6.1 This data processing agreement constitutes part of the Agreement, and any new or subsequent agreement arising from it, and shall enter into force at the time of the conclusion of the Agreement and shall remain effective for an indefinite period.
6.2 This data processing agreement shall end by operation of law upon termination of the Agreement or upon termination of any new or subsequent agreement arising from it between parties.
6.3 If the data processing agreement is terminated, Data Processor shall delete all Personal Data they currently store and which they have obtained from Client within the timeframe laid down in the Data Pro Statement, in such a way that the Personal Data can no longer be used and shall have been rendered inaccessible. Alternatively, if such has been agreed, Data Processor shall return the Personal Data to Client in a machine-readable format.
6.4 If Data Processor incurs any costs associated with the provisions of Article 6.3, they shall be entitled to invoice Client for said costs. Further arrangements relating to this subject can be laid down in the Data Pro Statement.
6.5 The provisions of Article 6.3 do not apply if Data Processor is prevented from removing or returning the Personal Data in full or in part by a statutory provision. In such instances, Data Processor shall only continue to process the Personal Data insofar as such is necessary by virtue of their statutory obligations. Furthermore, the provisions of Article 6.3 shall not apply if Data Processor is the Controller of the Personal Data within the meaning of the GDPR.
Article 7. The rights of Data Subjects, Data Protection Impact Assessments (DPIA) and auditing rights
7.1 Where possible, Data Processor shall cooperate with reasonable requests made by Client relating to Data Subjects who invoke their rights from Client. If Data Processor is directly approached by a Data Subject, they shall refer the Data Subject to Client where possible.
7.2 If Client is required to carry out a Data Protection Impact Assessment or a subsequent consultation within the meaning of Articles 35 and 36 of the GDPR, Data Processor shall cooperate with such, following a reasonable request to do so.
7.3 Data Processor will lend their cooperation to Client's requests for the deletion of personal data insofar as Client cannot carry this out themself.
7.4 Data Processor shall be able to demonstrate their compliance with their requirements under the data processing agreement by means of a valid Data Processing Certificate or an equivalent certificate or audit report (third-party memorandum) issued by an independent expert.
7.5 In addition, at Client's request, Data Processor shall provide all other information that is reasonably required to demonstrate compliance with the arrangements made in this data processing agreement. If, in spite of the foregoing, Client has grounds to believe that the Personal Data are not processed in accordance with the data processing agreement, Client shall be entitled to have an audit performed (at their own expense) not more than once every year by an independent, certified, external expert who has demonstrable experience with the type of data processing operations carried out under the Agreement. The scope of the audit shall be limited to verifying that Data Processor is complying with the arrangements made regarding the processing of the Personal Data as set forth in the present data processing agreement. The expert shall be subject to a duty of confidentiality with regard to his/her findings and shall only notify Client of matters which cause Data Processor to fail to comply with their obligations under the data processing agreement. The expert shall furnish Data Processor with a copy of his/her report. Data Processor shall be entitled to reject an audit or instruction issued by the expert if to their discretion the audit or instruction is inconsistent with the GDPR or any other law, or that it constitutes an unacceptable breach of the security measures they have implemented.
7.6 The parties shall consult each other on the findings of the report at their earliest convenience. The parties shall implement the measures for improvement suggested in the report insofar as they can be reasonably expected to do so. Data Processor shall implement the proposed measures for improvement insofar as to their discretion such are appropriate, taking into account the processing risks associated with their product or service, the state of the art, the costs of implementation, the market in which they operate, and the intended use of the product or service.
7.7 Data Processor shall be entitled to invoice Client for any costs they incur in implementing the measures referred to in this article.
Article 8. Sub-processors
8.1 Data Processor has specified in the Data Pro Statement whether Data Processor uses any third parties (sub-processors) to help them process the Personal Data, and if so, which third parties.
8.2 Client hereby authorises Data Processor to hire other sub-processors to meet their obligations under the Agreement.
8.3 Data Processor shall notify Client of any changes concerning the addition or replacement of the third parties (sub-processors) hired by Data Processor, e.g. through a revised Data Pro Statement. Client shall be entitled to object to such changes. Data Processor shall ensure that any third parties they hire shall commit to ensuring the same level of Personal Data protection as the security level Data Processor is bound to provide to the Client pursuant to the Data Pro Statement.
Article 9. Other provisions
These Standard Clauses for Data Processing, along with the Data Pro Statement, constitute an integral part of the Agreement. Therefore, any and all rights and obligations arising from the Agreement, including any applicable general terms and conditions and/or limitations of liability, shall also apply to the data processing agreement.
Data Processing Agreement
Cadmus Labs B.V.
Comprised of:
Part 1: Data Pro Statement
Part 2: Standard Clauses for Data Processing
NLdigital Standard Clauses: March 2025 version
Data Pro Statement version: 1, in force from 1 October 2026
Part 1: Data Pro Statement
Along with the Standard Clauses for Data Processing, this Data Pro Statement constitutes the data processing agreement for the product or service provided by the company that has drawn up this Data Pro Statement.
General information
1. This Data Pro Statement was drawn up by the following data processor (verwerker):
Cadmus Labs B.V.
Moddermanstraat 27
2313 GN Leiden
Nederland
If you have any queries about this Data Pro Statement or data protection in general, please contact: S.L. Dinh, info@cadmuslabs.nl.
2. This Data Pro Statement shall enter into force on 1 October 2026.
We regularly revise the security measures described in this Data Pro Statement to ensure that we are always fully prepared and up to date with regard to data protection. If this document is updated, we shall notify you of the revised versions through our regular channels.
Duration of the processing: The processing takes place for the duration of the Agreement between data processor and Client. This data processing agreement enters into force upon conclusion of the Agreement and remains in effect for as long as data processor processes personal data on behalf of the Client, ending automatically upon termination of the Agreement.
3. This Data Pro Statement applies to the following products and services provided by data processor:
Cadmus Software: a central digital order inbox for dental and orthodontic laboratories, enabling automated and unified digital order processing from multiple intraoral scanner portals.
4. Description of product(s)/service(s)
The Cadmus Software consists of three main components:
Inbox: central reception and unification of digital orders, including a user interface to view and export order files.
Dashboard: interface for monitoring and providing an overview of order volumes and scanner performance.
API: integration facility that enables laboratories to retrieve digital orders in a uniform format and process them within their own digital workflow.
The software is used by dental and orthodontic laboratories to efficiently and uniformly process digital orders placed by dentists and orthodontists. Orders are automatically retrieved from multiple intraoral scanner portals, unified, and made available to the laboratories for further processing.
5. Intended use
Cadmus processes personal data solely on behalf of and on the documented instructions of its Client, as a sub-processor. Google Cloud (including Vertex AI) and TransIP act as Cadmus's sub-processors.
Product/service is designed and built to process the following types of data:
Patient identification data (e.g. name, order reference number, date of birth);
Patient-related medical data (e.g. intra-oral scans, clinical photographs, dental/orthodontic order information);
Contact and practice details of dentists and orthodontists (e.g. name, email address, phone number, practice name).
The Service is specifically designed and built to process special categories of personal data within the meaning of Article 9 GDPR, namely health data, comprising the intra-oral scans, clinical photographs and dental and orthodontic order information relating to patients. This constitutes an explicit arrangement to that effect as referred to in the Standard Clauses for Data Processing, and the general assumption that the Service is not equipped to process special categories of personal data does not apply.
The Service is not designed to process data concerning criminal convictions and offences, or national identification numbers (such as the BSN) issued by the government. The Client shall not use the Service to process such data.
Order data (specifically the textual order information and comments provided by dentists and orthodontists) is automatically classified and enriched using AI (Google Vertex AI) to recognise characteristics such as work type, colour, placement and material, for the purpose of order processing. This classification concerns administrative order characteristics only; it does not involve any medical assessment or diagnosis. The intra-oral scans, clinical photographs and date of birth are received, stored and made available to the laboratory, but are not analysed, enriched, or used to train models.
6. Privacy by design / privacy by default
To provide the Service, Cadmus processes the data provided by dentists, orthodontists and dental laboratories and does not store more personal data than delivered through the relevant scanner portals for that purpose. Any additional data manually added by the Client or authorised third parties is the sole responsibility of the Client. Access to all data is restricted to authorised users via secure login.
The Client remains responsible for implementing privacy by design and privacy by default. Cadmus is not responsible for any additional processing, enrichment, or disclosure of data performed by the Client or third parties on the Client's behalf.
For the avoidance of doubt, the automated classification of order data described in section 5 is a processing activity carried out by Cadmus as part of the Service, and is distinct from any enrichment performed by the Client or third parties.
In addition to processing personal data to provide the Service, Cadmus creates a de-identified dataset by irreversibly removing direct identifiers (including patient names, order reference numbers, dates of birth, and clinician and practice names) and screening free-text order information to remove patient-identifying information, so that the result no longer constitutes personal data and cannot reasonably be traced to any patient, dentist, orthodontist, laboratory or Client. This de-identification is carried out on the Client's instruction. The resulting de-identified data does not constitute personal data and is not processed on the Client's behalf; Cadmus determines the purposes and means of its use, and may use it to improve, develop and analyse its products and services and to train its own models, may share aggregated insights derived from it, and may make the de-identified dataset available to third parties provided it remains de-identified. Until this de-identification is implemented, Cadmus limits such use to operational metadata that is not personal data, and does not use identifiable personal data for these purposes.
7. Standard Clauses for Data Processing
Data processor uses the NLdigital Standard Clauses for Data Processing (March 2025 version), which are attached to the Agreement as an addendum (Part 2).
8. Processing location
Data processor shall process the personal data provided by their clients within the EU/EEA.
9. Sub-processors
Data processor uses the following sub-processors:
Google Cloud (including Vertex AI)
Servers, storage and AI processing (EU/EEA locations). Vertex AI is used to automatically classify and enrich textual order data (recognising work type, colour, placement and material). All processing and storage occur within the EU/EEA, and data provided to Vertex AI is not used by Google to train Google's models. This does not restrict Cadmus's use of de-identified data to train Cadmus's own models as described in section 6. Intra-oral scans and image content are not processed by Vertex AI.
TransIP
Hosting, email and domain management (EU/EEA locations). All processing occurs within the EU/EEA.
10. Support for data-subject requests
Data processor shall support their clients as follows when they receive requests from data subjects:
Clients can log in at any time to view and export personal data.
Requests to modify or delete data can be submitted by email to info@cadmuslabs.nl.
11. Support for Data Protection Impact Assessments (DPIA)
If the Client is required to conduct a Data Protection Impact Assessment (DPIA), the Data Processor shall, upon a reasonable request, provide its cooperation in the DPIA.
12. Deletion of personal data
Scan data (intra-oral scans, clinical photographs and other files attached to an order) is deleted twelve (12) months from the date of collection, and all other order data three (3) years from the date of collection, including during the term of the Agreement, in such a manner that the data can no longer be used and is rendered inaccessible. The Client may request deletion of specific data before the end of these periods in accordance with section 10. Upon termination of the Agreement, any remaining personal data is deleted within three (3) months, in accordance with the export procedure set out in section 13.
13. Returning of personal data once the Agreement has been terminated
During the term of the Agreement, the Client can export data at any time via the web portal or API. Upon termination, this export functionality remains available for a period of thirty (30) days. Intra-oral scans, clinical photographs and order forms can be exported via the API within this period. After this thirty-day period, no further export is possible, and any remaining data is deleted within three (3) months of termination.
The Client is responsible for creating timely backups of any data it wishes to retain. Cadmus does not accept responsibility for data loss arising from the Client's failure to do so.
Self-service export via the web portal or API is free of charge. Where the Client requests Cadmus to perform a bulk export on its behalf, Cadmus may provide a quote. Costs will be based on the volume of data, any charges imposed by the cloud or hosting provider, and the time required by Cadmus to perform the export, to the extent permitted by applicable law.
Security policy
14. Data processor has implemented the following security measures to protect their product or service:
Pseudonymisation
Personal data is not pseudonymised, as the platform requires identifiable information for order processing and lab operations. Access is restricted to authorized users.
Secure channels
All personal data is transmitted via secure channels (TLS/HTTPS) to ensure confidentiality and integrity.
Encryption
Personal data is encrypted both in transit (TLS/HTTPS) and at rest. Data stored within the EU/EEA cloud environment is encrypted using industry-standard encryption managed by our sub-processors.
Access control
Access to the platform is restricted via secure login credentials. Role-based access ensures users can only view and process data necessary for their tasks.
Data integrity and availability
Regular backups, redundancy, and monitoring ensure the integrity and availability of data.
Security testing and evaluation
Cadmus Labs periodically reviews and evaluates the effectiveness of its technical and organisational security measures, and adjusts them where necessary (plan-do-check-act).
Incident response and recovery
Cadmus Labs maintains procedures for responding to security incidents. Systems are monitored to detect potential incidents, any suspected or confirmed incident is escalated internally without delay, and affected clients are notified in line with the Data Breach Protocol below. These procedures ensure that, in the event of a security incident:
access to personal data can be restored in a timely manner, and
the continuity of our services is maintained as much as possible.
Organizational measures
All employees and contractors processing personal data are bound by confidentiality agreements.
15. Data processor conforms to the principles of the following Information Security Management System (ISMS):
Cadmus Labs is working to align its internal processes and controls with recognized information security standards, striving to implement appropriate organizational and technical measures within practical possibilities. While no formal certification has been obtained, our internal controls are designed to reflect these standards.
Sub-processors engaged by Cadmus Labs, such as Google Cloud and TransIP, hold official certifications (e.g., ISO 27001, ISO 27701) and operate in compliance with strict security and privacy standards.
Data breach protocol
16. In the event something does go wrong, data processor shall follow the following data breach protocol to ensure that clients are notified of incidents:
Cadmus Labs monitors its systems to detect potential security incidents. Any suspected or confirmed data breach is reported internally immediately.
Clients will be notified as soon as reasonably possible, including:
Nature of the incident;
Categories of personal data affected;
Estimated number of affected data subjects and impacted systems;
Potential consequences for data subjects;
Measures taken to mitigate further damage.
Guidance on actions for the client or data subjects will be provided. Responsibility for notifying authorities or data subjects remains with the client.
Notifications will be sent to the client contact specified in the Agreement without undue delay, and in any event in good time to allow the Client (as controller) to meet its own notification obligations under Articles 33 and 34 GDPR, including the 72-hour deadline for reporting to the Dutch Data Protection Authority. As a rule, Cadmus Labs aims to notify the Client within 24 hours of confirmation of the breach. Further updates will follow as needed.
Part 2: Standard Clauses for Data Processing
Version: March 2025
Part 2 reproduces the NLdigital Standard Clauses for Data Processing (March 2025 version), published by NLdigital and used unmodified under NLdigital’s terms of use. © NLdigital. In case of conflict between the Dutch and English versions of these clauses, the Dutch version prevails.
Along with the Data Pro Statement, these standard clauses constitute the data processing agreement. They also constitute an annex to the Agreement and to the appendices to this Agreement, e.g. any general terms and conditions which may apply.
Article 1. Definitions
The following terms have the following meanings ascribed to them in the present Standard Clauses for Data Processing, in the Data Pro Statement and in the Agreement:
1.1 Dutch Data Protection Authority (AP): the supervisory authority defined in Section 4.21 of the GDPR.
1.2 GDPR: the General Data Protection Regulation.
1.3 Data Processor: the party which, in their capacity as an ICT supplier, processes Personal Data on behalf of their Client as part of the performance of the Agreement.
1.4 Data Pro Statement: statement issued by Data Processor in which they provide information such as the intended use of their products and/or services, any security measures which have been implemented, sub-processors, data breach, certification and dealing with the rights of Data Subjects.
1.5 Data Subject: a natural person who can be identified, directly or indirectly.
1.6 Client: the party on whose behalf Data Processor processes Personal Data. Client can either be the controller (the party who determines the purpose and means of the processing) or another data processor.
1.7 Agreement: the agreement concluded between Client and Data Processor, based on which the ICT supplier provides services and/or products to Client, the data processing agreement forming part of this agreement.
1.8 Personal Data: any and all information regarding a natural person who has been or can be identified, as defined in Article 4.1 of the GDPR, processed by Data Processor as required under the Agreement.
1.9 Data Processing Agreement: the present Standard Clauses for Data Processing, which, together with Data Processor's Data Pro Statement (or similar such information), constitute the data processing agreement within the meaning of Article 28.3 of the GDPR.
Article 2. General provisions
2.1 The present Standard Clauses for Data Processing apply to all Personal Data processing operations carried out by Data Processor in providing their products and services, as well as to all Agreements and offers. The applicability of Client's data processing agreements is explicitly rejected.
2.2 The Data Pro Statement, and particularly the security measures described in it, may be adapted from time to time to changing circumstances by Data Processor. Data Processor shall notify Client in the event of significant revisions. If Client in all reasonableness cannot agree to the revisions, Client shall be entitled to terminate the data processing agreement in writing, stating their reasons for doing so, within thirty days of having been served notice of the revisions.
2.3 Data Processor shall process the Personal Data on behalf of Client, in accordance with the written agreed upon instructions provided by Client to Data Processor.
2.4 Client or their customer shall serve as the controller within the meaning of the GDPR, shall have control over the processing of the Personal Data and shall determine the purpose and means of processing the Personal Data.
2.5 Data Processor shall serve as the processor within the meaning of the GDPR and shall therefore not determine the purpose and means of processing the Personal Data, and shall not make any decisions on the use of the Personal Data and other such matters.
2.6 Data Processor shall implement the GDPR as laid down in the present Standard Clauses for Data Processing, the Data Pro Statement and the Agreement. It is up to Client to assess, on the basis of this information, whether Data Processor is providing sufficient guarantees with regard to the implementation of appropriate technical and organisational measures in order to ensure that the processing operations meet the requirements of the GDPR and that Data Subjects' rights are sufficiently protected.
2.7 Client shall guarantee Data Processor that they act in accordance with the GDPR, that they provide a high level of protection for their systems and infrastructure at all times, that the nature, use and/or processing of the Personal Data are not unlawful and that they do not violate any third party's rights.
2.8 Administrative fines imposed on Client by the Dutch Data Protection Authority cannot be recovered from Data Processor.
Article 3. Security
3.1 Data Processor shall implement the technical and organisational security measures set out in their Data Pro Statement. In implementing the technical and organisational security measures, Data Processor shall take into account the state of the art and the costs of implementation, as well as the nature, scope, context and purposes of the processing and the intended use of their products and services, and the risk in processing the data of varying likelihood and severity inherent to the rights and freedoms of Data Subjects that are to be expected considering the nature of the intended use of Data Processor's products and services.
3.2 Unless explicitly stated otherwise in the Data Pro Statement, the products and services provided by Data Processor shall not be equipped to process special categories of personal data or data relating to criminal convictions and offences.
3.3 Data Processor seeks to ensure that the security measures they shall implement are appropriate for the manner in which Data Processor intends to use the products and services.
3.4 In Client's opinion, said security measures provide a level of security that is tailored to the risk inherent in the processing of the Personal Data used or provided by Client, taking into account the factors referred to in Article 3.1.
3.5 Data Processor shall be entitled to adjust the security measures they have implemented if to their discretion such is necessary for a continued provision of an appropriate level of security. Data Processor shall record any significant adjustments they choose to make, e.g. in a revised Data Pro Statement, and shall notify Client of said adjustments where relevant.
3.6 Client may request Data Processor to implement further security measures. Data Processor shall not be obliged to honour such requests to adjust their security measures. If Data Processor makes any adjustments to their security measures at Client's request, Data Processor is entitled to invoice Client for the costs associated with said adjustments. Data Processor shall not be required to actually implement the requested security measures until both Parties have agreed upon them in writing.
Article 4. Data breaches
4.1 Data Processor does not guarantee that their security measures shall be effective under all circumstances. If Data Processor discovers a data breach within the meaning of Article 4 sub 12 of the GDPR, they shall notify Client without undue delay. The “Data Breach Protocol” section of the Data Pro Statement outlines the way in which Data Processor shall notify Client of data breaches.
4.2 It is up to the Controller (the Client or their customer) to assess whether the data breach of which Data Processor has notified the Controller must be reported to the Dutch Data Protection Authority or to the Data Subject concerned. The Controller (Client or their customer) shall at all times remain responsible for reporting data breaches which must be reported to the Dutch Data Protection Authority and/or Data Subjects pursuant to Articles 33 and 34 of the GDPR. Data Processor is not obliged to report data breaches to the Dutch Data Protection Authority and/or to the Data Subject.
4.3 Where necessary, Data Processor shall provide further information on the data breach and shall assist Client to meet their breach notification requirements within the meaning of Articles 33 and 34 of the GDPR by providing all the necessary information available to Data Processor.
4.4 If Data Processor incurs any reasonable costs in doing so, they are entitled to invoice Client for these, at the rates applicable at the time.
Article 5. Confidentiality
5.1 Data Processor shall ensure that the persons processing Personal Data acting under its authority have committed themselves to confidentiality.
5.2 Data Processor shall be entitled to provide third parties with Personal Data if and insofar as such is necessary due to a court order, statutory provision or order issued by a competent government authority.
5.3 Any and all access and/or identification codes, certificates, information regarding access and/or password policies provided by Data Processor to Client, and any and all information provided by Data Processor to Client detailing the technical and organisational security measures included in the Data Pro Statement are confidential and shall be treated as such by Client and shall only be disclosed to authorised employees of Client. Client shall ensure that their employees comply with the requirements described in this article.
Article 6. Term and termination
6.1 This data processing agreement constitutes part of the Agreement, and any new or subsequent agreement arising from it, and shall enter into force at the time of the conclusion of the Agreement and shall remain effective for an indefinite period.
6.2 This data processing agreement shall end by operation of law upon termination of the Agreement or upon termination of any new or subsequent agreement arising from it between parties.
6.3 If the data processing agreement is terminated, Data Processor shall delete all Personal Data they currently store and which they have obtained from Client within the timeframe laid down in the Data Pro Statement, in such a way that the Personal Data can no longer be used and shall have been rendered inaccessible. Alternatively, if such has been agreed, Data Processor shall return the Personal Data to Client in a machine-readable format.
6.4 If Data Processor incurs any costs associated with the provisions of Article 6.3, they shall be entitled to invoice Client for said costs. Further arrangements relating to this subject can be laid down in the Data Pro Statement.
6.5 The provisions of Article 6.3 do not apply if Data Processor is prevented from removing or returning the Personal Data in full or in part by a statutory provision. In such instances, Data Processor shall only continue to process the Personal Data insofar as such is necessary by virtue of their statutory obligations. Furthermore, the provisions of Article 6.3 shall not apply if Data Processor is the Controller of the Personal Data within the meaning of the GDPR.
Article 7. The rights of Data Subjects, Data Protection Impact Assessments (DPIA) and auditing rights
7.1 Where possible, Data Processor shall cooperate with reasonable requests made by Client relating to Data Subjects who invoke their rights from Client. If Data Processor is directly approached by a Data Subject, they shall refer the Data Subject to Client where possible.
7.2 If Client is required to carry out a Data Protection Impact Assessment or a subsequent consultation within the meaning of Articles 35 and 36 of the GDPR, Data Processor shall cooperate with such, following a reasonable request to do so.
7.3 Data Processor will lend their cooperation to Client's requests for the deletion of personal data insofar as Client cannot carry this out themself.
7.4 Data Processor shall be able to demonstrate their compliance with their requirements under the data processing agreement by means of a valid Data Processing Certificate or an equivalent certificate or audit report (third-party memorandum) issued by an independent expert.
7.5 In addition, at Client's request, Data Processor shall provide all other information that is reasonably required to demonstrate compliance with the arrangements made in this data processing agreement. If, in spite of the foregoing, Client has grounds to believe that the Personal Data are not processed in accordance with the data processing agreement, Client shall be entitled to have an audit performed (at their own expense) not more than once every year by an independent, certified, external expert who has demonstrable experience with the type of data processing operations carried out under the Agreement. The scope of the audit shall be limited to verifying that Data Processor is complying with the arrangements made regarding the processing of the Personal Data as set forth in the present data processing agreement. The expert shall be subject to a duty of confidentiality with regard to his/her findings and shall only notify Client of matters which cause Data Processor to fail to comply with their obligations under the data processing agreement. The expert shall furnish Data Processor with a copy of his/her report. Data Processor shall be entitled to reject an audit or instruction issued by the expert if to their discretion the audit or instruction is inconsistent with the GDPR or any other law, or that it constitutes an unacceptable breach of the security measures they have implemented.
7.6 The parties shall consult each other on the findings of the report at their earliest convenience. The parties shall implement the measures for improvement suggested in the report insofar as they can be reasonably expected to do so. Data Processor shall implement the proposed measures for improvement insofar as to their discretion such are appropriate, taking into account the processing risks associated with their product or service, the state of the art, the costs of implementation, the market in which they operate, and the intended use of the product or service.
7.7 Data Processor shall be entitled to invoice Client for any costs they incur in implementing the measures referred to in this article.
Article 8. Sub-processors
8.1 Data Processor has specified in the Data Pro Statement whether Data Processor uses any third parties (sub-processors) to help them process the Personal Data, and if so, which third parties.
8.2 Client hereby authorises Data Processor to hire other sub-processors to meet their obligations under the Agreement.
8.3 Data Processor shall notify Client of any changes concerning the addition or replacement of the third parties (sub-processors) hired by Data Processor, e.g. through a revised Data Pro Statement. Client shall be entitled to object to such changes. Data Processor shall ensure that any third parties they hire shall commit to ensuring the same level of Personal Data protection as the security level Data Processor is bound to provide to the Client pursuant to the Data Pro Statement.
Article 9. Other provisions
These Standard Clauses for Data Processing, along with the Data Pro Statement, constitute an integral part of the Agreement. Therefore, any and all rights and obligations arising from the Agreement, including any applicable general terms and conditions and/or limitations of liability, shall also apply to the data processing agreement.
© 2026 Cadmus Labs B.V.
KVK: 94949816
Terms and Conditions
Cookies
Privacy
© 2026 Cadmus Labs B.V.
KVK: 94949816
© 2026 Cadmus Labs B.V.
KVK: 94949816
Terms and Conditions
Cookies
Privacy
© 2026 Cadmus Labs B.V.
KVK: 94949816
© 2026 Cadmus Labs B.V.
KVK: 94949816
Terms and Conditions
Cookies
Privacy
© 2026 Cadmus Labs B.V.
KVK: 94949816