Skip to main content

Built for Indian dental clinics — Practice Management System + Marketing + SEO in one platform

Data Governance

Data Policy

Last updated: May 2026

How Dentvora stores, secures, and retains business, user, and patient data — including our subprocessor list, breach-response process, and retention timelines. Read this together with our Privacy Policy.

1. Purpose of This Data Policy

This Data Policy is a companion to our Privacy Policy. It focuses on the operational and information-security practices Dentvora applies when handling business, user, and patient data in connection with the Dentvora platform.

Where the Privacy Policy describes what data we collect and why, this Policy describes how we store, secure, retain, and govern that data day-to-day.

2. Types of Data We Handle

Account and authentication data — usernames, password hashes, session tokens, and two-factor secrets.

Clinic operational data — clinic profile, branches, services, working hours, staff records, configuration settings.

Patient data submitted by the Clinic — patient names, contact details, appointment history, treatment categories, and uploaded media (including before-and-after photos where applicable).

Communication data — message templates, message-delivery status, opt-in / opt-out records.

Social-platform data accessed under user authorisation — Facebook Page details, Instagram account data, public insights metrics, WhatsApp Business API metadata.

Google API data accessed under user OAuth authorisation — basic Google profile for Sign-In (name, email, picture), read-only YouTube channel statistics, and Google Business Profile performance metrics. Used only to power sign-in and the marketing / SEO analytics dashboards; not used for advertising and never used to train AI/ML models (Google API Services User Data Policy Limited Use).

AI processing data — prompts, structured fields, and (for image enhancement) the specific image bytes uploaded for an AI action.

Operational telemetry — logs, error traces, performance metrics, security audit trails.

3. Data Storage Practices

Data is stored on managed cloud infrastructure operated by reputable providers, primarily located in India and/or the European Economic Area.

Database storage uses encryption at rest where the underlying provider supports it.

Object storage (uploaded images, generated images) is configured with private access policies; URLs are only shared inside an authenticated Dentvora session.

Backups are stored separately from primary systems and rotated on a defined schedule.

4. Security Controls

Encryption in transit: all data exchanged between the client, our servers, and third-party APIs uses TLS 1.2 or higher.

Encryption at rest: enabled for databases and object storage where the cloud provider supports it.

Access control: production access is limited to a small number of authorised personnel, with role-based permissions, multi-factor authentication, and audit logging.

Network isolation: production services run inside isolated network segments; administrative access is gated behind allow-listed identities.

Credential hygiene: passwords are stored as salted hashes; access tokens for third-party APIs are stored encrypted and rotated as required by the provider.

Code and dependency hygiene: routine vulnerability scanning of dependencies; security-relevant patches are prioritised.

Logging and monitoring: access and security events are logged; suspicious activity triggers alerts to the on-call engineer.

5. Subprocessors (Updated As Needed)

We use the following categories of subprocessors to deliver the Services. Material changes are reflected in our Privacy Policy.

Infrastructure & hosting — managed cloud providers for application hosting, database, and object storage.

AI model providers — OpenAI (text, image generation, image editing models), Google (Gemini models).

Social and messaging platforms — Meta Platforms (Facebook, Instagram, WhatsApp Business APIs), Google (Google Sign-In, YouTube Data API, Business Profile APIs).

Payments — Razorpay and other RBI-authorised payment aggregators.

Email and operational notifications — transactional email providers.

Analytics and error monitoring — for product analytics, performance monitoring, and crash reporting.

Each subprocessor processes data only to support Dentvora functionality, under contractual confidentiality and security obligations.

6. Data Retention and Deletion

Active subscription data is retained while your account is active.

After account closure or termination: account and operational data is retained for up to 90 days to allow re-activation and export, then deleted or anonymized.

Patient images attached to a post: deleted from disk once the post is marked as published, to limit storage exposure.

Communication logs, billing records, and audit trails: retained up to seven (7) years for Indian tax, accounting, and dispute-resolution compliance.

Backups: deleted data may persist briefly in backup snapshots before being overwritten on the standard rotation cycle.

Data Principals can request earlier deletion under the Privacy Policy. We will comply within 30 days of verifying the request, subject to legal retention requirements.

7. Backup and Disaster Recovery

We maintain automated backups of the primary database and durable object storage.

Recovery procedures are exercised periodically to validate that backups are restorable.

Recovery time and point objectives are set proportionate to operational risk; exact outcomes during an incident depend on the scope and root cause.

8. Data Breach Response

Our incident-response process covers identification, classification, containment, eradication, recovery, and post-incident review.

Where a confirmed personal data breach occurs, we will notify the Data Protection Board of India and affected Data Principals as soon as reasonably practicable in accordance with the DPDP Act 2023 and applicable rules.

Where the affected data is processed on behalf of a Clinic, we will promptly notify the Clinic so it can fulfil its own notification obligations.

We work to minimise impact and restore operations as quickly as possible, but no organization can guarantee complete prevention of every security incident.

9. Internal Access and Confidentiality

Only authorised personnel and approved automated service roles have access to production data, and only to the extent needed to operate, support, or improve the Services.

All Dentvora personnel with access to personal data are subject to written confidentiality obligations.

Access is reviewed periodically and revoked promptly when no longer required.

10. Patient Data Special Handling

Patient Data is treated as sensitive even where the DPDP Act does not formally categorise it as such.

Patient images uploaded for before/after, case-study, or carousel posts are stored separately and deleted from disk after the post is published. A small audit record (consent timestamp, post reference) is retained for legal traceability.

Patient images are not used to train AI models. Patient identifiers (names, phone numbers) are not sent to AI providers in routine content generation.

11. AI Inputs and Outputs

Inputs sent to AI providers are limited to what is needed to generate the requested creative output (topic descriptions, brand style fields, and for image enhancement the specific image bytes the Clinic has chosen).

Where the AI provider offers an enterprise no-training default, we operate under those configurations.

AI-generated outputs are stored alongside the Clinic's posts. They are deleted in line with the post lifecycle and our retention rules above.

12. Clinic Responsibilities

Clinics are responsible for the accuracy, lawfulness, and currency of all data they submit to the platform.

Clinics must obtain and maintain patient consent for any Patient Data submitted, particularly for identifiable images used in marketing.

Clinics must promptly notify Dentvora of any unauthorised access to their account or any breach affecting Patient Data they have submitted.

13. Policy Updates and Communication

This Data Policy may be updated to reflect legal, technical, operational, or product changes.

Material changes will be notified to active customers by reasonable means.

Updated versions will be published on this page. Continued use of the Services after publication indicates acceptance of the updated Policy.

14. Contact Information

Dentvora Technologies (OPC) Private Limited

Registered Address: Giri Market, Loni, Ghaziabad, Uttar Pradesh, 201102, India

Email: [email protected] (general and grievance)

Email: [email protected] (data and security)

Phone / WhatsApp: +91 70421 39045