Skip to content

Privacy Policy

Last updated

This Privacy Policy explains how DentoSim ("we") handles personal data when you visit dentosim.com, use the DentoSim application or open a patient simulation link.

Aligner labs and clinics decide what patient data is uploaded to DentoSim and why. For that data, the lab is the controller and we act as its processor, as described in the Data Processing Terms. For account, billing and website data, we are the controller.

Data we collect

  • Account data: name, email address, organisation name, role, password (stored only as a secure hash) and optional two-factor authentication settings.
  • Organisation data: clinics, doctors and their professional details, branding and domains, and billing records such as invoices and payment confirmations.
  • Treatment data: treatment plan files and 3D models, patient references or names entered by the lab, case notes, messages, approvals and change requests.
  • Patient link data: when a patient opens a link, we record the view and, if a PIN is used, PIN attempts.
  • Technical data: IP address, browser and device information, and security logs, used to keep the Service secure and to prevent abuse.

How we use it

  • to provide the Service: process uploads, build simulations, show cases to the right people and send notifications;
  • to secure the Service: authentication, rate limiting, virus scanning of uploads and audit logs;
  • to bill organisations and keep financial records;
  • to provide support and communicate about the Service;
  • to fix errors. Error reports are stripped of patient information before they leave the platform.

Where data protection law requires a legal basis, we rely on performance of our contract with the organisation, our legitimate interests in running and securing the Service, compliance with legal obligations, and, where required, consent. Labs and clinics are responsible for having a valid basis, and patient consent where required, for the patient data they upload.

Sharing

We do not sell personal data. We share it only with people the organisation chooses (its staff, doctors and patients through links), with service providers that help us run the Service, and where required by law.

  • Hosting and storage providers that run our servers and store files.
  • Email delivery providers that send account and notification emails.
  • Error monitoring, which receives technical error data with patient information removed.
  • Push notification services used by the doctor app.

Retention

We keep data for as long as the organisation's account is active, or for the retention period the organisation sets for its cases. When a case or account is deleted, its data is removed from active systems. Backups are overwritten in the normal backup cycle. We keep billing records for as long as the law requires.

Security

Each organisation's data is kept separate. We use encrypted connections, hashed passwords, optional two-factor authentication, role-based access, virus scanning of uploads, private patient links with optional PINs and expiry, and audit logs of important actions.

Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, or to object to or restrict certain processing. If you are a patient, please contact the clinic or lab that shared the simulation with you first, as they control your data. Contact us on WhatsApp at +92 314 1523562.

International transfers

Our servers and service providers may be located in other countries. Where data is transferred internationally, we take steps to protect it as required by applicable law.

Children

The Service is used by dental professionals. Patients who are children view simulations through links shared by their clinic, which is responsible for obtaining any required parental consent.

Cookies

See our Cookie Policy.

Changes and contact

We may update this Privacy Policy and will post the new version here with its date. Contact us on WhatsApp at +92 314 1523562.

Privacy Policy | DentoSim