Back to home
Privacy

Privacy Policy

Last updated: March 1, 2025 · Effective: March 1, 2025

We never sell your data

Your patient and practice data is yours. We will never sell it to advertisers or third parties.

Bank-level encryption

All data is encrypted at rest (AES-256) and in transit (TLS 1.3).

Full transparency

We clearly explain what data we collect, why, and how long we keep it.

Right to deletion

You can request deletion of your data at any time. We will process it within 30 days.

This policy explains how we handle your data. It covers what CL Dental collects, how it is used, and how it is protected.

1. Information We Collect

We collect information you provide directly to us when you register for an account, create or modify your practice profile, use our features, or communicate with us. This includes:

Practice & Account Data: Practice name, address, contact details, billing information, staff profiles, and account credentials.

Patient Data: Patient names, contact information, appointment history, treatment records, dental charts, medical history, and billing information that you input on behalf of your patients.

Usage Data: Information about how you use our Service, including log data, device information, browser type, IP address, pages visited, and actions taken within the platform.

Communications: Records of support requests, feedback, and any correspondence with our team.

2. How We Use Your Information

We use the information we collect to provide, maintain, and improve our Service. Specifically, we use it to:

  • Process and manage your account and subscription
  • Deliver the features and functionality of the platform
  • Send transactional emails such as appointment confirmations and billing receipts
  • Provide customer support and respond to your inquiries
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations
  • Improve the platform based on aggregated, anonymized usage patterns

We do not use patient data for any purpose other than delivering the Service to you. We do not analyze patient data for advertising, research, or any commercial purpose without your explicit written consent.

3. Patient Data and Regional Healthcare Laws

We process patient clinical records, medical histories, and dental charts as sensitive personal data. We act strictly as a Data Processor for the dental practices utilizing our platform.

For operations based out of our regional headquarters in Rwanda, we manage all sensitive patient information in strict compliance with the data minimization, security, and confidentiality mandates of Law Nº 058/2021 relating to the protection of personal data and privacy. For dental clinics operating across other African jurisdictions, we similarly align our data workflows with respective national health privacy guidelines and medical records laws.

4. Data Sharing and Disclosure

We do not sell, trade, or rent your personal or patient data to third parties. We may share information only in the following limited circumstances:

Service Providers: We work with trusted vendors (such as cloud infrastructure and payment processors) who process data on our behalf under strict data processing agreements.

Legal Requirements: We may disclose information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of CL Dental, our users, or the public.

Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you via email and/or a prominent notice in the Service before such a transfer occurs.

With Your Consent: We may share information with third parties when you explicitly consent to such sharing.

5. Data Retention

We retain your account and practice data for as long as your account is active or as needed to provide the Service. If you close your account, we will retain your data for 30 days to allow for account recovery or data export, after which it will be permanently deleted.

Patient data is retained according to your instructions and applicable medical records laws, which typically require retention for a minimum of 7–10 years depending on jurisdiction. We will not delete patient data before the legally required retention period without your explicit instruction and confirmation of compliance obligations.

6. Security

We apply the following security controls:

  • AES-256 encryption at rest for all stored data
  • TLS 1.3 encryption in transit
  • Multi-factor authentication support
  • Role-based access controls
  • Regular third-party penetration testing
  • SOC 2 Type II compliance (in progress)
  • 24/7 security monitoring and incident response

No method of transmission over the internet or electronic storage is 100% secure, so absolute security cannot be guaranteed.

In the event of a personal data breach that impacts the privacy of our users or their patients, CommitLink will formally notify the Rwanda National Cyber Security Authority (NCSA) or the respective national supervisory body within forty-eight (48) hours of discovery, taking immediate technical steps to mitigate any potential risks.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

Access: Request a copy of the personal data we hold about you. Correction: Request correction of inaccurate or incomplete data. Deletion: Request deletion of your personal data (subject to legal retention requirements). Portability: Receive your data in a structured, machine-readable format. Objection: Object to processing of your personal data for certain purposes. Restriction: Request that we restrict processing of your data.

Our platform respects national data privacy regulations across the African continent. If you or your data subjects are located in Rwanda, your legal rights are anchored under Law Nº 058/2021. If you operate in other African markets (such as Kenya, South Africa, or Nigeria), your data rights are governed by your respective national data protection acts.

You maintain the right to access, rectify, object to processing, or request the permanent erasure of your files. To exercise these regional rights, please contact our response unit at privacy@commitlink.org.

8. Cookies and Tracking

We use cookies and similar tracking technologies to operate and improve our Service. These include:

Essential cookies: Required for the Service to function (authentication, security, preferences). Analytics cookies: Help us understand how users interact with the platform (we use anonymized data only). Performance cookies: Used to monitor and improve platform performance.

You can control cookie settings through your browser. Disabling essential cookies may affect the functionality of the Service. We do not use advertising or third-party tracking cookies.

9. International Data Transfers

Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to, and maintained on computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction.

Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer. The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.

10. Children's Privacy

Our Service is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information without parental consent, please contact us and we will take steps to remove that information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and sending an email notification at least 30 days before the changes take effect.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.

12. Contact & Data Protection Officer

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy Team: privacy@commitlink.org Data Protection Officer: dpo@commitlink.org Postal: CL Dental, 1 KN 78 St, Kigali, Rwanda

You also have the right to lodge a formal complaint regarding our data processing operations directly with your local supervisory body. For practices operating in Rwanda, complaints can be filed with the Data Protection and Privacy Office (DPPO) under the National Cyber Security Authority (NCSA) via their official portal at dpo.gov.rw. For practices operating elsewhere in Africa, complaints should be directed to your local national data protection commission.

Privacy questions

privacy@commitlink.org

Data Protection Officer

dpo@commitlink.org