Agreements
See the legal agreements in place for your practice — terms, privacy, data processing and the ones specific to your country — with who accepted them and when.
By the end of this page you'll know where to find the practice's legal agreements, how to check they're current, and what happens when a new version is published.
What lives here
Settings → Agreements lists the documents your practice operates under. Three apply everywhere:
- Terms of Service — accepted per account when someone signs up.
- Privacy Policy — accepted alongside the terms at sign-up.
- Data Processing Agreement (DPA) — accepted once by the practice Owner during onboarding, on behalf of the whole practice. This is the contract that authorises Smileline to process your patients' data.
Others depend on where the practice is. You only ever see the ones that apply to you — a practice in Germany is never asked to accept a US healthcare agreement, and a US practice is never asked to accept the EU clauses:
- Business Associate Agreement (BAA) — United States only. Accepted by the Owner. US dental practices are generally covered entities under HIPAA, and a covered entity may not share patient information with a supplier without one of these in place.
- US Communications Compliance Addendum — United States only. Accepted by the Owner. Sets out who is responsible for consent when the practice calls, texts or emails patients, and what Smileline does and does not check on the practice's behalf.
- EU Data Protection Addendum — European Union only. Accepted by the Owner. Applies the EU GDPR to the DPA, adopts the European Commission's Standard Contractual Clauses for transfers, and names the supervisory authority to contact.
For each document the table shows the version accepted, who agreed and the agreed date, with the full acceptance history underneath — click History on a row to expand it. The document title links to the current published text.
Only owners and managers can open this page. Acceptance records are kept as minimised evidence of the agreement — each one stores the accepting user, their signing capacity, the document version and the acceptance time. SmileLine does not attach an IP address or browser user agent to the acceptance.
When a new version is published
Agreement versions are dated. When Smileline publishes a new version of a document:
- The row shows a pending badge next to the version that's now out of date.
- The practice Owner sees a blocking prompt on their next visit and must review and accept the new version to continue.
- Everyone else keeps working normally — they see a small notice once per session that a new agreement is pending the owner's acceptance; dismissing it hides it for good.
Accepting adds a new row to the history; earlier acceptances are never overwritten.
Read the documents
The current published documents are always available on the website:
- Terms of Service
- Privacy Policy
- Data Processing Agreement
- Business Associate Agreement — US practices
- US Communications Compliance Addendum — US practices
- EU Data Protection Addendum — EU practices
- Consumer Health Data Privacy Policy — published for Washington and Nevada residents; nothing to accept
When a document changes
When we publish a new version of a document that applies to your practice, the Owner is asked to accept it the next time they open Smileline. Until they do, the Owner's account can still sign in, read everything, manage billing and practice details, and contact support — but it cannot make other changes, in the app or through the API, and the response explains which document is waiting. Everyone else on the team carries on as normal; they are never blocked by a document only the Owner can accept.