Back to home
Privacy

Privacy Policy

Last updated: March 1, 2025 · Effective: March 1, 2025

We never sell your data

Your patient and practice data is yours. We will never sell it to advertisers or third parties.

Bank-level encryption

All data is encrypted at rest (AES-256) and in transit (TLS 1.3).

Full transparency

We clearly explain what data we collect, why, and how long we keep it.

Right to deletion

You can request deletion of your data at any time. We will process it within 30 days.

Your privacy matters to us. This policy explains how DentalCare collects, uses, and protects your information when you use our platform. We've written it to be clear and readable — not just legal boilerplate.

1. Information We Collect

We collect information you provide directly to us when you register for an account, create or modify your practice profile, use our features, or communicate with us. This includes:

Practice & Account Data: Practice name, address, contact details, billing information, staff profiles, and account credentials.

Patient Data: Patient names, contact information, appointment history, treatment records, dental charts, medical history, and billing information that you input on behalf of your patients.

Usage Data: Information about how you use our Service, including log data, device information, browser type, IP address, pages visited, and actions taken within the platform.

Communications: Records of support requests, feedback, and any correspondence with our team.

2. How We Use Your Information

We use the information we collect to provide, maintain, and improve our Service. Specifically, we use it to:

  • Process and manage your account and subscription
  • Deliver the features and functionality of the platform
  • Send transactional emails such as appointment confirmations and billing receipts
  • Provide customer support and respond to your inquiries
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations
  • Improve the platform based on aggregated, anonymized usage patterns

We do not use patient data for any purpose other than delivering the Service to you. We do not analyze patient data for advertising, research, or any commercial purpose without your explicit written consent.

3. Patient Data and HIPAA

We understand that much of the data processed through DentalCare constitutes Protected Health Information (PHI) under HIPAA. As a Business Associate, we are committed to safeguarding PHI in accordance with HIPAA requirements.

We offer a Business Associate Agreement (BAA) to all customers who process PHI through our platform. If you require a BAA, please contact us at legal@dentalcare.com.

We implement administrative, physical, and technical safeguards to protect PHI, including access controls, audit logs, encryption, and regular security assessments.

4. Data Sharing and Disclosure

We do not sell, trade, or rent your personal or patient data to third parties. We may share information only in the following limited circumstances:

Service Providers: We work with trusted vendors (such as cloud infrastructure and payment processors) who process data on our behalf under strict data processing agreements.

Legal Requirements: We may disclose information if required by law, court order, or governmental authority, or to protect the rights, property, or safety of DentalCare, our users, or the public.

Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you via email and/or a prominent notice in the Service before such a transfer occurs.

With Your Consent: We may share information with third parties when you explicitly consent to such sharing.

5. Data Retention

We retain your account and practice data for as long as your account is active or as needed to provide the Service. If you close your account, we will retain your data for 30 days to allow for account recovery or data export, after which it will be permanently deleted.

Patient data is retained according to your instructions and applicable medical records laws, which typically require retention for a minimum of 7–10 years depending on jurisdiction. We will not delete patient data before the legally required retention period without your explicit instruction and confirmation of compliance obligations.

6. Security

We take the security of your data seriously and implement industry-standard measures including:

  • AES-256 encryption at rest for all stored data
  • TLS 1.3 encryption in transit
  • Multi-factor authentication support
  • Role-based access controls
  • Regular third-party penetration testing
  • SOC 2 Type II compliance (in progress)
  • 24/7 security monitoring and incident response

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

Access: Request a copy of the personal data we hold about you. Correction: Request correction of inaccurate or incomplete data. Deletion: Request deletion of your personal data (subject to legal retention requirements). Portability: Receive your data in a structured, machine-readable format. Objection: Object to processing of your personal data for certain purposes. Restriction: Request that we restrict processing of your data.

For GDPR rights (EU/EEA residents) or CCPA rights (California residents), please contact privacy@dentalcare.com. We will respond to all requests within 30 days.

8. Cookies and Tracking

We use cookies and similar tracking technologies to operate and improve our Service. These include:

Essential cookies: Required for the Service to function (authentication, security, preferences). Analytics cookies: Help us understand how users interact with the platform (we use anonymized data only). Performance cookies: Used to monitor and improve platform performance.

You can control cookie settings through your browser. Disabling essential cookies may affect the functionality of the Service. We do not use advertising or third-party tracking cookies.

9. International Data Transfers

DentalCare is headquartered in France and our primary data centers are located in the European Union. If you are accessing our Service from outside the EU, your data may be transferred to and processed in the EU.

For transfers from the EU/EEA to other countries, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other appropriate transfer mechanisms, to ensure adequate protection of your data.

10. Children's Privacy

Our Service is not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information without parental consent, please contact us and we will take steps to remove that information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and sending an email notification at least 30 days before the changes take effect.

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.

12. Contact & Data Protection Officer

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy Team: privacy@dentalcare.com Data Protection Officer: dpo@dentalcare.com Postal: DentalCare SAS, 123 Avenue des Champs-Élysées, 75008 Paris, France

For EU residents, you also have the right to lodge a complaint with your local supervisory authority (for France, this is the CNIL at www.cnil.fr).

Privacy questions

privacy@dentalcare.com

Data Protection Officer

dpo@dentalcare.com