Privacy and data policy
Version 0.2 · last updated September 30, 2026
This text is a draft and has not yet had legal review; it may change.
1. The short version
- Your dental record belongs to you. A clinic sees it only while you have given that clinic permission, and you can take the permission back.
- We use your data to run the service: sign-in, booking, reminders, your record, and improving how clinics manage their work. We do not sell your data and we do not show advertising.
- We do not load third-party trackers, analytics or fonts. The Platform runs on servers we control.
- Every time someone opens a patient record, we log it.
2. Who is responsible
[Company legal name], [address] ("we") decides why and how the data is used and is the data controller for the Platform. A clinic that you book with or that treats you is a controller of the clinical information it creates and holds about you, under its own professional and legal duties.
3. What we collect
You give us: name, mobile number and/or email, password (stored only as a one-way hash), date of birth, national ID number where booking requires it, health information you add to your record (for example conditions, medications, allergies), self-assessment answers, appointments and notes, messages and reviews.
Clinics and dentists give us: their profile, licence and business details, services, prices, schedules, and the clinical entries they make in a patient's record with that patient's permission.
Created by using the Platform: sign-in and security events, device and browser type, IP address, request logs, delivery status of messages sent to you, and audit entries.
Cookies: only what is needed to keep you signed in, remember your language and theme, and protect sign-in (security code). We do not use advertising or cross-site tracking cookies.
4. Why we use it
- to create your account and keep it secure (sign-in codes, security code checks, lockouts);
- to let you find clinics, book, and be reminded of appointments (SMS or email);
- to keep your record and share it with the clinics you allow;
- to let clinics run schedules, queues and promotions;
- to keep the Platform safe, prevent abuse and fraud, and meet legal duties;
- to improve the service using aggregated or de-identified figures.
We rely on your consent and on what is necessary to provide the service you asked for.
5. Who can see it
- Clinics and dentists: only those you booked with or granted access to, and only what the permission covers. Access is time-limited by default and you can end it.
- Emergency access: where the Platform offers an emergency ("break-glass") access to a record, it is limited, requires a reason, and is logged and reviewable.
- Service providers we use: an SMS or email gateway receives the recipient's number or address and the message text needed to deliver it. They may not use it for anything else.
- Authorities: when the law or a valid legal order requires it.
- Nobody else. We do not sell or rent personal data.
6. Audit
Reading a patient record is recorded (who, when, which record) in a tamper-evident audit trail, as is changing settings and sensitive actions.
7. Where it is kept and how it is protected
Data is stored in databases on servers we operate. We use access controls by role, sign-in protections (rate limits, lockouts, optional two-step sign-in), one-way password hashing, encrypted connections, and regular backups. No system is perfectly secure; if a breach affects you we will tell you and the relevant authority as the law requires.
8. How long we keep it
- Your account and record: while your account is open, and afterwards as long as the law or the clinic's professional duties require.
- Message delivery logs: [90] days.
- Backups: about [14] daily copies, then removed.
- Audit entries: [3650] days, because they protect your record.
Periods marked in brackets are configurable and may change; the current values are in our settings.
9. Your choices and rights
You may ask us to: give you a copy of your data; correct it; delete your account or restrict use; stop reminders; or withdraw a clinic's access. Some clinical entries made by a clinic must be kept by that clinic by law, so we may only be able to remove your access to them, not erase them. Raise a ticket from the account you registered with and we will reply within [30] days. You may also complain to the competent authority.
10. Children
A parent or legal guardian must create and manage an account for a child under [18].
11. Changes
We will update this policy when the service or the law changes. The version and date are at the top of the page; for material changes we will notify you in the app.
12. Contact
[Company legal name] · [address]
To contact us, raise a ticket from the account you registered with; that is the only way we handle requests, so we can confirm who you are.