1. Who we are
Dentora AI ("Dentora", "we", "us") provides AI-powered front-desk software for dental clinics, including appointment scheduling, patient messaging, and clinic management tools at dentora.vip. For most of the personal data described in this policy, Dentora acts as a data processoron behalf of the dental clinic that operates the account (the "Clinic"), and the Clinic acts as the data controllerfor its patients' data. For account, billing, and usage data tied to the Clinic itself, Dentora acts as the data controller.
2. Data we collect
We collect the following categories of data:
- Account & clinic data: clinic name, staff names, email addresses, phone numbers, role/permissions, and billing details.
- Patient data: entered by the Clinic into Dentora -- patient names, contact details, appointment history, treatment notes, and messages exchanged through the platform (including WhatsApp, when connected).
- Usage data: log data, device/browser information, IP address, and product analytics events (pages viewed, features used) collected via cookies -- see our Cookie Policy.
- Payment data:processed directly by Stripe -- Dentora never stores full card numbers (see "Stripe & payments" below).
3. How we use data
- To provide, operate, and maintain the Dentora platform (scheduling, reminders, messaging, reporting).
- To power AI features such as appointment suggestions, message drafting, and patient-reliability scoring.
- To process subscription payments and send billing communications.
- To secure the platform, prevent fraud and abuse, and enforce our Terms of Service.
- To provide customer support and respond to inquiries.
- To improve the product through aggregated, de-identified product analytics.
4. Legal basis for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases under Article 6 GDPR:
- Contract: to provide the subscription service the Clinic signed up for.
- Legitimate interests: product security, fraud prevention, and service improvement.
- Legal obligation: tax, accounting, and KYC/AML record keeping.
- Consent: optional analytics and marketing communications, where required.
5. Patient and clinic data isolation
Every Clinic's data is logically isolated from every other Clinic's data (multi-tenant isolation enforced at the database level), access to patient records is restricted by role-based permissions, and all administrative actions on patient data are logged in an audit trail. Dentora only accesses Clinic data to provide the service, investigate a support request the Clinic raised, or comply with a legal obligation.
6. AI processing
Dentora uses AI models (including third-party model providers such as Anthropic) to power features like the AI inbox, appointment suggestions, and message drafting. Data sent to an AI provider for these features is transmitted securely, used only to generate the requested output, and is not used by Dentora or its AI providers to train models on Clinic or patient data. AI-generated suggestions (e.g. draft replies, scheduling recommendations) are always reviewable by clinic staff before they take effect on a patient record.
7. Cookies and analytics
We use essential cookies to keep you signed in and remember your language, currency, and theme preferences, and analytics cookies to understand how the product is used so we can improve it. See our full Cookie Policy for details and how to manage your preferences.
8. Stripe and payments
Subscription payments are processed by Stripe, Inc.Stripe collects and stores your payment method details directly; Dentora only receives limited billing metadata (such as subscription status, plan, and the last four digits of a card) needed to manage your account. Stripe's use of your data is governed by Stripe's own privacy policy.
9. Other third-party providers
We share data with a small number of vetted providers, strictly to operate the service:
- Supabase -- database hosting, authentication, and file storage.
- Stripe -- subscription billing and payment processing.
- Resend -- transactional email delivery.
- WhatsApp Business Platform (Meta) -- optional patient messaging, when a Clinic connects its WhatsApp number.
- Vercel -- application hosting and infrastructure.
Each provider processes data solely on our instructions and under a data processing agreement where required.
10. Data retention
We retain Clinic and patient data for as long as the Clinic's subscription is active, plus a reasonable period afterward to allow reactivation and to meet legal, tax, and accounting retention obligations. A Clinic can request deletion of its data at any time by contacting us; we will delete or anonymize it within 30 days, except where retention is legally required.
11. Data security
Data is encrypted in transit (TLS) and at rest, access is protected by role-based permissions and audit logging, and we apply the principle of least privilege to internal access to production data.
12. International transfers
Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards, such as Standard Contractual Clauses or the provider's own adequacy/compliance framework (e.g. Stripe, Supabase, and Vercel each maintain their own GDPR-compliant transfer mechanisms).
13. Your rights
Subject to applicable law (including the GDPR for EU/EEA residents), you may have the right to:
- Access the personal data we (or, for patient data, the Clinic) hold about you.
- Request correction of inaccurate data.
- Request erasure ("right to be forgotten"), subject to legal retention requirements.
- Object to or restrict certain processing.
- Request data portability.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local data protection authority.
If you are a patient of a Clinic using Dentora, please contact the Clinic directly first, since the Clinic controls your patient record. We will support the Clinic in fulfilling that request.
14. Children's privacy
Dentora is a business-to-business product intended for use by dental clinic staff who are adults. Patient records may include minors' data entered by the Clinic in the course of providing dental care; this data is handled under the same safeguards described above, on the Clinic's instructions as data controller.
15. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or an in-app notice before they take effect. The "Effective date" above reflects the latest revision.