Terms of Service    Home
Legal

Privacy Policy

Effective date: 1 June 2026  ·  Last updated: 16 June 2026

Plain-language summary: We collect only what's needed to run the platform. We never sell your data. Patient health data stays encrypted at rest. You can request deletion at any time.

1. Who Controls Your Data

DentaPro Ltd ("we", "us") operates Dental Assistant Pro at dentapro.org. For clinic staff and owners, we are the data controller. For patient data entered by clinics, the clinic is the data controller and we are the data processor.

Contact our data protection contact at: privacy@dentapro.org

2. What Data We Collect

CategoryDataWho it applies to
Account dataName, email address, password (hashed), role, clinic nameClinic staff / owners
Patient recordsName, email, phone, date of birth, address, medical history, appointments, invoices, X-rays, prescriptions, consent recordsPatients (entered by clinic)
Usage dataLogin timestamps, audit log entries, IP addressAll users
Payment dataBilling name, email — card details are handled by Stripe and never stored by usClinic owners
Portal dataMessages, appointment requests, intake forms submitted by patients via the patient portalPatients

3. How We Use Your Data

We do not use patient health data for advertising, profiling, or sale to third parties.

4. Legal Basis for Processing (GDPR)

Processing activityLegal basis
Running the Service for clinic staffContract (Art. 6(1)(b))
Processing patient health recordsExplicit consent + health care exemption (Art. 9(2)(h))
Billing and fraud preventionLegitimate interests (Art. 6(1)(f))
Legal complianceLegal obligation (Art. 6(1)(c))

5. Data Storage and Security

All data is stored on Amazon Web Services (AWS) servers in the EU West (Ireland) region. Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

Access to production databases is restricted to authorised personnel only. We use row-level security (RLS) to ensure each clinic can only access its own data.

We maintain backups with a 30-day retention period.

6. Data Retention

7. Third-Party Processors

ProcessorPurposeLocation
Amazon Web ServicesCloud hosting, database, file storageEU (Ireland)
StripePayment processingEU / USA
SendGrid / SMTP providerTransactional emailEU / USA

All processors are contractually bound to process data only on our instructions and in compliance with GDPR.

8. Cookies

We use only essential cookies and browser storage (localStorage, sessionStorage) to maintain your login session and application preferences. We do not use tracking cookies or third-party analytics.

9. Your Rights (GDPR)

If you are located in the EU/EEA, you have the following rights:

To exercise any of these rights, email privacy@dentapro.org. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.

10. Patient Portal

Patients access the portal by providing their email address and date of birth — no password is required. The portal is scoped to the specific clinic the patient registered with. Patients may send messages and appointment requests; these are stored and visible to clinic staff.

11. Children's Privacy

The patient portal is not intended for use by children under 16 without parental consent. Clinics are responsible for obtaining appropriate consent when entering records for minors.

12. Changes to This Policy

We may update this policy from time to time. We will notify account holders by email at least 14 days before material changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact

For privacy questions or to exercise your rights: privacy@dentapro.org
For general support: support@dentapro.org