MTS

LEGAL

Data Processing Agreement

Last updated: 20 August 2026

Back to Trust Center
On this page

This Data Processing Agreement (“DPA”) supplements the Terms of Service between a clinic and MTS. Where MTS processes personal data on behalf of a clinic, the clinic generally determines the purposes and means of processing, and MTS processes information according to the applicable service arrangement and documented instructions. Not every MTS service creates the same legal relationship, this DPA applies to the extent the clinic's use of the Service involves MTS processing personal data on the clinic's behalf. Final contractual language should be reviewed before execution.

1. Scope

This DPA governs the processing of personal data by MTS in connection with the AI SDR, AI Receptionist, Appointment Reminder, Recall, Reviews, and related agents, and the supporting dashboard.

2. Processing Instructions

MTS processes personal data only on documented instructions from the clinic, which includes instructions given through the dashboard's configuration (enabling an agent, connecting a CRM, setting communication preferences), unless MTS is required to do otherwise by applicable law.

3. Roles of Controller and Processor

Where MTS processes personal data on behalf of a clinic, the clinic generally acts as the data controller and MTS acts as the data processor, subject to the specific services and processing arrangement in place. For MTS's own staff-account data (the dashboard login a clinic's team uses), MTS acts as controller, see the Privacy Policy.

4. Categories of Personal Data

  • Identity and contact data: name, phone number, email address.
  • Communication content: call recordings and transcripts, SMS, email, and website-chat content.
  • Appointment and treatment-interest data provided by a lead or patient.
  • CRM pipeline data: lead stage, ownership, and notes.
  • Account data for the clinic staff who use the dashboard.

5. Categories of Data Subjects

  • Leads and patients of the clinic.
  • The clinic's own staff who use the dashboard.

6. Purpose of Processing

MTS processes personal data to operate the automation agents a clinic has enabled, to display the resulting activity in the dashboard, and to provide support in connection with the Service.

7. Confidentiality

MTS ensures that personnel authorized to process personal data have committed to confidentiality obligations, and limits access to what is required to provide the Service or resolve a support request.

8. Security

MTS applies the technical and organizational measures described on the Security Overview, limited to controls that are actually implemented.

9. Subprocessors

MTS uses the third-party services listed on the Trust Center (Supabase, Vercel, n8n, Retell, Gemini, OpenRouter, Twilio where enabled, and Google Workspace where used) to provide the Service. Each is engaged only for the purpose needed to perform its function.

10. International Transfers

Where personal data is transferred internationally in connection with the Service, MTS relies on the safeguards required by applicable data protection law.

11. Data Subject Assistance

MTS provides reasonable assistance to a clinic in responding to a data subject request concerning personal data processed through the Service, including access, correction, and deletion requests.

12. Security Incident Assistance

MTS notifies a clinic without undue delay after becoming aware of a personal data breach affecting that clinic's data, and provides information reasonably available to assist the clinic in meeting its own notification obligations.

13. Retention

Retention is described in full on the Data Retention Policy. Specific periods are marked [RETENTION PERIOD TO BE CONFIRMED] until enforcement is built and confirmed.

14. Deletion

Where deletion functionality is available, MTS will delete or remove information from applicable MTS-controlled systems in accordance with the relevant deletion process. Information maintained by connected third-party services, clinic systems, backups, security records, or other systems may be subject to separate retention and deletion requirements.

15. Audits and Compliance Information

MTS makes compliance information available on the Trust Center. Formal audit rights, where applicable, are set out in a clinic's individual service agreement.

16. Controller Responsibilities

The clinic is responsible for determining the lawful basis for its processing, obtaining any consent required from its own patients, and providing MTS with accurate instructions.

17. Processor Responsibilities

MTS is responsible for processing personal data only on the clinic's documented instructions, applying the security measures described on the Security Overview, and engaging subprocessors consistent with this DPA.

18. Termination

On termination of the underlying service agreement, MTS handles the clinic's data as described in the Data Retention Policy.