Skip to content
CephCalc
  • Features
  • Methods
    Steiner McNamara Downs Tweed Ricketts Holdaway Merrifield McNamara airways Jarabak Björk Slavicek Wits Schwarz Bergen / Hasund Schmüth Tübingen
  • Scenarios
    Skeletal class (adult) Vertical facial pattern Extraction vs non-extraction Extraction in Class II/1 (adult) Class III: camouflage vs surgery Jaw discrepancy localization Dentoalveolar compensation in Class III Deep bite / Class II, division 2 Bimaxillary protrusion
  • Services
    Cephalogram analysis Cephalometrics Orthodontic calculator Orthodontist software CBCT 3D Biometrics 3D analysis Treatment plan Braces calculation Aligners calculation
  • Pricing
  • FAQ
  • Contacts
  • EN
  • USD
EN
USD
Start for free
  1. CephCalc
  2. Data processing agreement

Personal Data Processing Agreement

This document (the "Agreement") sets terms under which the rights holder of CephCalc (the "Processor") processes personal data of patients and other third parties that the User (healthcare professional, medical organization, or authorized representative; the "Data Controller") places in the "CephCalc" software.

Version dated 06.09.2026. Published at: https://cephcalc.com/processing.

1. General

1.1. This Agreement is integral to public offer and applies from offer Acceptance and placement of patient data in the Service.

1.2. The Processor does not determine purposes or legal grounds for patient data. The Data Controller determines purposes, obtains consents (or acts on other lawful grounds), and is responsible for lawful processing.

1.3. The Processor provides technical infrastructure (hosting, storage, backups, computing) and acts on the Data Controller's instruction under Art. 6 of Federal Law No. 152-FZ.

1.4. Processing of the User's (professional's) personal data is governed by privacy policy and consent to personal data processing.

2. Operations and Purposes

2.1. The Processor may perform on data placed by the Data Controller: collection, recording, organization, storage, updating, retrieval, use, transfer (provision, access) to authorized subcontractors, anonymization, blocking, deletion, destruction — with or without automation.

2.2. Purposes on the Data Controller's instruction:

  • providing Service features (patient records, calculations, reports, PDF, 3D analysis and related modules);
  • ensuring data integrity and availability;
  • backup and disaster recovery;
  • technical support upon Data Controller request.

3. Data Categories

3.1. Volume is determined by the Data Controller when filling records and uploading materials. May include: patient name and identifiers; date of birth and sex; contacts (if entered); medical images; calculation and report results; health information (special categories) — only as placed by the Data Controller.

3.2. The Processor does not request patient data beyond Service functionality or use it for own purposes (marketing, sales, analytics outside Service operation).

4. Security

4.1. The Processor applies legal, organizational, and technical measures proportionate to risk, including access control, secure channels, backups, logging, and internal control.

4.2. Details are in privacy policy.

5. Subcontractors

5.1. The Processor may entrust processing to authorized subcontractors (hosting, Prodamus, mail and infrastructure) only for purposes stated herein and in the privacy policy, in compliance with 152-FZ.

5.2. Intentional cross-border transfer of patient data does not occur except where technically necessary and permitted by law in compliance with 152-FZ.

6. Storage Location

6.1. Data placed in the Service is stored and processed on servers in the Russian Federation unless the Processor explicitly notifies otherwise when changing infrastructure in compliance with law.

7. Term and Destruction

7.1. Processing continues while the Data Controller uses the Service and until destruction per the offer, privacy policy, and Data Controller requests.

7.2. Upon patient data deletion, Account deletion, or Agreement termination, the Processor destroys records in active systems per the privacy policy. Backup copies may persist briefly (typically up to 90 calendar days) before rotation without restoring deleted data.

7.3. The Processor may retain anonymized or minimally necessary records (e.g., payment data) if required by law or to protect its rights.

8. Data Controller Obligations

8.1. The Data Controller warrants lawful grounds for processing and transfer of patient personal data to the Processor, including compliance with applicable medical confidentiality and personal data laws (including, where Russian law applies, Art. 13 of Federal Law No. 323-FZ and Federal Law No. 152-FZ); accuracy of data; compliance with professional and medical standards.

8.2. The Data Controller shall not place data in the Service that is not necessary for using Service features (data minimization), shall use anonymized identifiers instead of direct patient personal data where possible, and shall not share Account credentials with third parties.

8.3. For patient or authority requests, the Data Controller interacts directly; the Processor provides technical assistance within Service capabilities and law.

8.4. The Processor does not and is not obliged to verify patient consent or other lawful grounds held by the Data Controller. Confirmation when creating a record or uploading materials in the Service UI records the Data Controller's acknowledgment but does not replace obtaining patient consent where required by law.

9. Liability

9.1. The Data Controller is liable for unlawful purpose/ground determination, including violations related to medical confidentiality. The Processor is liable for processing breaches within limits set by the offer and law.

9.2. Processor liability limits in the offer apply to processing-related claims subject to mandatory law.

10. Changes

The Processor may update this Agreement by publishing a new version on the Website. It applies from publication unless a later date is stated.

11. Processor Details

Denis Timurovich Usmanov, Sole Proprietor

  • TIN: 026705193002
  • OGRN / OGRNIP: 325169000137714
  • Email: support@cephcalc.com

Contacts: https://cephcalc.com/contacts · public offer · privacy policy.

© 2026 CephCalc — All rights reserved
Denis Timurovich Usmanov, Sole Proprietor TIN 026705193002 OGRNIP 325169000137714
Pricing & payment Contacts Terms of service Privacy Personal data consent Data processing agreement support@cephcalc.com
  • Visa
  • Mastercard
  • Maestro

Payment by bank card, Visa, Mastercard and Maestro is processed by Prodamus. You can choose a payment method on the checkout page.

Log in

Forgot password? · No account yet?

We use technical browser data for site operation, authentication, and analytics. Third-party services (including Yandex.Metrica) may also store data in your browser.
Privacy policy Consent to data processing