Privacy Policy
How personal and clinical data is collected, used, protected, and your rights over it.
1. Who we are
This platform ("the Service") provides dental clinic management software. Your dental clinic is the data controller for personal and health data processed about its patients; the platform operator ("we", the Service operator) acts as a data processor / business associate on the clinic's behalf and under contract. For platform-level account data (staff logins, billing), the platform operator is the controller.
Operator: the platform operator, the platform operator. Privacy contact: Ragr.hamad@gmail.com. Data Protection Officer: the platform operator.
2. What we process
Account data: name, email, role, and authentication data. Passwords are stored only as Argon2id hashes; multi-factor secrets are encrypted at rest.
Patient & clinical data (entered by clinic staff, "special category" / PHI): identity and contact details, national ID, appointments, clinical notes, dental charting, treatment plans, prescriptions, documents and imaging, and billing/payment records. The most sensitive identity fields are encrypted at rest (AES-256-GCM).
Technical & security data: IP address, browser/user-agent, a per-request correlation id, and a tamper-evident audit trail of security-relevant events (logins, record access, administrative and export actions).
3. Why we process it (lawful basis)
GDPR Art. 6: performance of our contract with the clinic; compliance with legal obligations (medical record-keeping, tax); and legitimate interests in operating and securing the platform.
For health data specifically (GDPR Art. 9): processing for the provision of health care and management of health-care systems, under contract with the treating clinic. Under HIPAA, we act as a Business Associate of the clinic (the Covered Entity) under a Business Associate Agreement.
Where processing rests on consent, you may withdraw it at any time without affecting prior processing.
4. Cookies & local storage
The Service uses strictly-necessary browser storage only: an authentication token, your "remember me" preference, language and theme settings, and your consent acknowledgement. We do not use advertising or third-party tracking cookies, and there is no cross-site tracking. Because this storage is essential to operate the Service, it is set when you sign in; any non-essential storage added in future would require your opt-in.
5. How long we keep it
Operational logs (communications, notifications) are purged on a configurable retention schedule (default 12 months). Security audit and access trails are retained longer for accountability and are protected by a cryptographic hash chain.
Clinical records are retained for the period required by applicable medical-records law (the platform operator), after which they are deleted or irreversibly de-identified.
6. Your rights
Subject to applicable law you may request access, correction, erasure, restriction, portability (a machine-readable export), and objection to processing. Patients should contact their clinic (the controller); platform-account holders may contact us at Ragr.hamad@gmail.com. We respond within statutory timeframes.
Right to erasure in practice: because medical and tax records carry statutory retention (GDPR Art. 17(3)), an erasure request is fulfilled by irreversibly de-identifying your record — identity and contact details are permanently overwritten and identifying documents destroyed — while the underlying clinical and financial entries required by law are retained in de-identified form. Records under an active legal hold (e.g. ongoing litigation) are retained until the hold is lifted.
7. How we protect it
Role-based access control with least privilege and per-clinic tenant isolation; encryption in transit (TLS) and at rest for the most sensitive fields and object storage; a tamper-evident audit log; a patient-record access trail; multi-factor authentication for administrators; rate limiting; session-bound tokens so access can be revoked immediately; encrypted database backups; and regular security testing. No system is perfectly secure, but we apply industry-standard safeguards.
8. Sharing & sub-processors
We share data only with infrastructure sub-processors under contract — Hostinger (virtual private server hosting). Object storage and database run self-hosted on that server rather than with a third-party provider. No analytics, advertising or tracking processors are used. — and where required by law. We do not sell personal data and do not use it for advertising.
9. International transfers
Data is hosted in a single dedicated virtual private server, with the database, object storage and encrypted backups all held on that host. Where data is transferred across borders, we rely on an appropriate transfer mechanism (e.g. adequacy decision or standard contractual clauses) as required by applicable law.
10. Data breaches
We maintain an incident-response process and will notify the affected clinic (and, where we are the controller, affected individuals and the relevant supervisory authority) of a personal-data breach without undue delay and within the timeframes required by applicable law.
11. Children
The Service is used by clinics that may treat minors. Records about minors are processed on the same lawful bases on behalf of the treating clinic and with the involvement of a parent or guardian as required by local law.
12. Complaints & governing law
This policy is governed by the laws of the platform operator. You have the right to lodge a complaint with your data-protection authority (the platform operator).
13. Changes
We may update this policy; material changes will be notified in-app. Effective / last updated: the platform operator.