Privacy
Privacy Policy
Last updated: July 2026
Dentvora Technologies (OPC) Private Limited ("Dentvora", "we", "our", "us") operates the Dentvora platform, a software solution designed to help dental clinics manage patient engagement, marketing, and online presence.
This Privacy Policy explains how we collect, use, and protect user, clinic, and patient data — including data obtained from third-party platforms such as Meta (Facebook, Instagram, WhatsApp), Google APIs (Sign-In, YouTube, and Business Profile), and AI providers (OpenAI, Google Gemini).
1. Who We Are and Our Role
Dentvora Technologies (OPC) Private Limited ("Dentvora", "we", "our", "us") operates the Dentvora platform — a software-as-a-service solution designed to help dental clinics manage patient engagement, marketing, online presence, and clinic operations.
Under the Digital Personal Data Protection Act, 2023 of India ("DPDP Act"), we act as a Data Fiduciary for the personal data of our direct users (clinic owners, staff, administrators). For Patient Data submitted to the platform by a Clinic, we act as a Data Processor on the Clinic's instructions — the Clinic remains the Data Fiduciary for its patients' personal data.
Where applicable, we align our practices with the EU General Data Protection Regulation (GDPR) for users located in the European Economic Area.
2. Information We Collect
Account and Profile Information — name, email address, phone number, role within the clinic, business/clinic details, and authentication identifiers.
Clinic Operational Data — clinic profile, branch details, working hours, services offered, staff records (entered by the Clinic), pricing inputs, and configuration choices.
Patient Data submitted by the Clinic — patient names, contact details, appointment history, communication preferences, treatment categories, before-and-after photographs (where uploaded by the Clinic with patient consent), and case-study material.
Social Media Data (via Meta APIs) — when a user connects a Facebook or Instagram account, we may access: public profile information (name, profile picture), Instagram account data, Facebook Page details, social-media insights (reach, engagement, impressions), and Page/account performance analytics. We access only data necessary to provide Dentvora services.
WhatsApp Business API Data — phone numbers a Clinic enters for patient messaging, message-template content the Clinic submits, message-delivery status, and limited engagement metadata required by Meta for the WhatsApp Business Platform.
Google Account Data (via Google APIs, with your OAuth consent) — basic Google profile (name, email address, profile picture) for "Sign in with Google"; read-only YouTube channel statistics (subscribers, views, engagement) when a Clinic connects its YouTube channel; and Google Business Profile performance metrics (searches, views, calls, direction requests, reviews) when a Clinic connects its Business Profile. We never access Gmail, Google Drive, Calendar, Contacts, or Photos data.
AI Processing Inputs — prompts, topic descriptions, photos uploaded for AI enhancement, structured fields (headline, captions, hashtags) sent to AI providers to generate creative output.
Usage and Telemetry Data — platform usage activity, feature usage patterns, device and browser identifiers, IP address, approximate location derived from IP, and interaction logs used for security, debugging, and product analytics.
Payment Data — handled by third-party payment processors (e.g., Razorpay). We receive transaction status and a tokenized reference but do not store full card data on our infrastructure.
3. How We Use Information
To provide and operate the Services — appointments, recalls, marketing automation, analytics dashboards, AI-assisted content generation, integrations with Meta and Google.
To display social-media insights and analytics dashboards, improve clinic marketing performance, and enable account integration with Facebook and Instagram.
To deliver patient communications (WhatsApp, email, in-app messages) on the Clinic's instructions and only to recipients for whom the Clinic represents valid consent exists.
To enhance platform functionality, fix bugs, and improve user experience — using aggregated, de-identified usage signals where possible.
To monitor system performance, prevent abuse, and respond to security incidents.
To comply with legal obligations, enforce our Terms, and protect the rights and safety of users and patients.
4. AI Processing — OpenAI and Google Gemini
Dentvora uses third-party AI providers — currently OpenAI (text and image models) and Google (Gemini models) — to generate captions, content plans, image enhancements, and image creations.
What is sent: when a Clinic triggers an AI action, the relevant text inputs (topic, brand tone, audience, prompt) and, for image enhancement, the specific image bytes are transmitted to the AI provider over an encrypted connection.
What is NOT sent: we do not send patient personal data, identifiable patient records, treatment history, or appointment data to AI providers as part of routine AI generation.
Training opt-out: we operate AI integrations under provider configurations that, where available, prevent our prompts and outputs from being used to train foundational models. Where a provider's enterprise no-training default is not yet available, we will note that in this policy.
Cross-border processing: AI providers process inputs on their own infrastructure, which is generally located outside India. By using AI features you acknowledge this transfer. Indian DPDP rules permit such transfers except to countries specifically restricted by the Central Government; no restrictions currently apply.
AI-generated content may contain inaccuracies. The Clinic is responsible for reviewing AI Output before approval and publication.
5. Meta Platforms (Facebook, Instagram, WhatsApp Business)
Dentvora integrates with Meta platforms in compliance with the Meta Platform Terms, Meta Business Tools Terms, and the WhatsApp Business Solution Terms.
We only access data explicitly granted by the user through Meta's official OAuth and permission flows. We do not collect Meta usernames or passwords.
We do not use Meta data for unauthorised purposes. We do not sell, share, or use Meta data for advertising outside Dentvora services.
WhatsApp Business: when a Clinic enables WhatsApp messaging, we send messages on the Clinic's behalf using Meta-approved templates. The Clinic confirms it has obtained explicit opt-in from every patient before adding that patient's number to the platform for marketing communications. Recipients can opt out at any time by replying to the message; we honour opt-outs across the platform.
Dentvora is registered with Meta as a Business Solution Provider partner where required, and accepts the responsibilities described in Meta's developer documentation.
6. Google API Services — Sign-In, YouTube, and Business Profile
Dentvora integrates with Google APIs only through Google's official OAuth 2.0 consent screen. We never ask for or store Google account passwords, and we request the narrowest scopes needed for each feature. We access only three Google surfaces, described below.
Google Sign-In (scopes: openid, email, profile) — when a user chooses "Sign in with Google", we receive the user's name, email address, and profile picture solely to create and authenticate their Dentvora account.
YouTube (scope: youtube.readonly) — when a Clinic connects its YouTube channel from the Social Media dashboard, we read-only access the channel's statistics (subscriber count, video views, and engagement metrics) to display analytics inside Dentvora. We never create, edit, upload, or delete any YouTube content, comments, or subscriptions, and we do not access any other user's YouTube data.
Google Business Profile (scopes: business.manage, userinfo.email) — when a Clinic connects its Google Business Profile from the SEO Control page, we read the profile's performance metrics (searches, views, calls, direction requests, and reviews) to power local-SEO analytics. Google exposes Business Profile performance data only under the business.manage scope; we use it strictly to read these metrics and to identify the connected profile. We do not delete the profile or post on the Clinic's behalf without an explicit, user-initiated action.
How this data is used — Google user data is used only to provide and improve these user-facing features (account sign-in and the marketing / SEO analytics dashboards). It is never used for advertising, credit or lending decisions, or resold.
How this data is shared — raw or derived Google user data is not transferred or sold to any third party, including data brokers, advertisers, or our AI providers, except as strictly necessary to operate the feature for that same user or where required by law.
How this data is protected — Google OAuth access and refresh tokens are encrypted at rest, transmitted only over TLS, and access to production systems is restricted to authorised personnel on a need-to-know basis.
Retention and deletion — a Clinic can disconnect Google at any time from the Social Media or SEO Control page, which immediately revokes and deletes the stored tokens. On account closure, all Google tokens and data derived from these scopes are deleted within 30 days. Users can also revoke Dentvora's access directly at https://myaccount.google.com/permissions.
Limited Use — Dentvora's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used to develop, improve, or train generalized or third-party AI/ML models.
7. Healthcare and Patient Data — Special Handling
Patient Data is treated as sensitive personal information regardless of whether the DPDP Act classifies it as such.
Patient before-and-after photographs, smile-design results, case studies, and any identifiable patient image are accepted only when the Clinic has obtained written informed consent from the patient for use on social media and marketing channels. The platform requires the Clinic to record this consent inside the post workflow before approval is allowed.
Patient images uploaded for before/after posts are never sent to AI providers for transformation or training, and are never AI-altered without the Clinic's explicit choice (Sprint 2 enhance mode preserves identity and is opt-in).
Once a post containing patient imagery is marked as published on social media, the underlying image files are removed from our servers in accordance with our Data Policy. A small audit trail (timestamp, consent record) is retained for legal compliance.
8. Subprocessors and Third-Party Service Providers
We share or process data with the following categories of trusted third parties to deliver the Services:
Cloud hosting and infrastructure providers (servers, storage, content-delivery networks) — for application hosting and data storage.
AI model providers — OpenAI (text + image generation, image editing) and Google (Gemini text generation).
Communication and social-platform providers — Meta Platforms (Facebook, Instagram, WhatsApp Business APIs), Google (Google Sign-In, YouTube Data API, Business Profile APIs).
Payment processors — Razorpay and other RBI-authorised payment aggregators for subscription billing.
Email and notification providers — for transactional email and operational notifications.
Analytics and error-monitoring providers — for security telemetry, performance monitoring, and bug tracking.
Each provider processes data only to support Dentvora functionality, under contractual confidentiality and security obligations.
We do NOT sell personal data to third parties.
9. Cross-Border Data Transfers
Some of our subprocessors (AI providers, Meta, certain analytics tools) operate infrastructure outside India.
Where personal data is transferred outside India for processing, we rely on contractual protections including the provider's standard data processing addendum and, where applicable, EU Standard Contractual Clauses or equivalent safeguards.
Indian DPDP Act §16 currently permits cross-border transfers except to countries the Central Government may restrict by notification. We will update this policy and our subprocessor list if any restriction affects our transfers.
10. Data Storage and Security
Personal and clinic data is stored on infrastructure operated by reputable cloud providers, primarily located in India or the European Economic Area.
We implement administrative, technical, and physical safeguards including encryption in transit (TLS), encryption at rest where supported, role-based access controls, audit logging, network isolation, and periodic credential rotation.
Access to production data is restricted to a small number of authorised personnel on a need-to-know basis.
No system can be fully immune to all security threats. We work to reduce risk and respond rapidly to incidents but cannot guarantee absolute security.
11. Data Retention
Account and operational data is retained while the subscription is active. After termination, we retain data for up to ninety (90) days to allow re-activation and Clinic export, after which it is deleted or anonymized.
Patient images attached to posts are deleted from disk once the post is marked as published, to limit storage exposure.
Communication logs, billing records, and audit trails may be retained for up to seven (7) years to comply with Indian tax, dispute-resolution, and statutory record-keeping requirements.
Backups are rotated on a defined schedule; deleted data may persist in backups for a short period before being overwritten.
12. Your Rights as a Data Principal (DPDP Act 2023)
You have the right to confirm whether we process your personal data and to access a summary of the data we process.
You have the right to correct or update your personal data and to complete any incomplete information.
You have the right to request erasure of your personal data, subject to our legal obligations to retain certain records.
You have the right to nominate another individual to exercise these rights in the event of your death or incapacity.
You have the right to withdraw consent at any time for any processing that relies on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
You have the right to register a grievance with our Grievance Officer (Section 16 below) and to escalate to the Data Protection Board of India if the grievance is not resolved.
To exercise any of these rights, email [email protected] or [email protected], or call/WhatsApp +91 70421 39045. We will acknowledge within 24 hours and respond within 15 days, or earlier if required by applicable rules.
13. GDPR Rights (for EEA users)
If you are located in the European Economic Area, you also have rights under the GDPR including: right of access (Art. 15), right to rectification (Art. 16), right to erasure (Art. 17), right to restriction of processing (Art. 18), right to data portability (Art. 20), right to object (Art. 21), and rights related to automated decision-making (Art. 22).
Where we rely on consent for processing, you may withdraw it at any time. Where we rely on legitimate interest, you may object to the processing.
You may lodge a complaint with your local supervisory authority. We will cooperate fully with any such authority.
14. Children's Data
Dentvora services are intended for clinic professionals over 18 years of age.
We do not knowingly collect or process the personal data of children under 18 as direct users of the platform.
When a Clinic submits Patient Data of minor patients, the Clinic represents that it has obtained verifiable parental or guardian consent in accordance with the DPDP Act §9 and applicable medical law. The Clinic remains responsible for that consent.
We do not track, profile, or behaviourally advertise to children.
15. Cookies and Similar Technologies
Our website uses essential cookies for authentication and session continuity, and limited analytics cookies (such as Google Analytics 4 with IP anonymisation) to understand site usage.
We do not use advertising cookies that share data with external ad networks.
You can disable non-essential cookies in your browser settings; some site features may not work as a result.
16. Data Breach Notification
If we become aware of a personal data breach, we will follow our incident-response procedure (assessment, containment, mitigation).
We will notify the Data Protection Board of India and affected Data Principals as soon as reasonably practicable in line with the DPDP Act and applicable rules.
Where the affected data is processed on behalf of a Clinic (Patient Data), we will promptly notify the Clinic so it can fulfil its own notification obligations.
17. Grievance Officer and Contact
In accordance with the IT (Intermediary Guidelines) Rules 2021 and the DPDP Act 2023, you can contact our Grievance Officer for any privacy or data-protection grievance.
Grievance Officer Contact — Email: [email protected] · Phone / WhatsApp: +91 70421 39045
Acknowledgement timeline: within 24 hours of receipt.
Resolution timeline: within 15 days of receipt, unless a different period applies by law.
18. Data Deletion and Account Closure (including Meta data)
You may request deletion of your account and associated personal data at any time. The fastest paths are documented on our dedicated page at https://dentvora.com/account-deletion — including a pre-filled WhatsApp message and an email template. You can also email [email protected] or [email protected], or call/WhatsApp +91 70421 39045 directly.
We will delete or anonymize personal data within 30 days of verifying the request, subject to retention required by law (tax records, dispute records).
To request deletion of data obtained specifically from Facebook, Instagram, or WhatsApp integrations: email [email protected] with the subject line "Meta Data Deletion Request". Dentvora will process and delete the user data associated with Meta integrations upon request in compliance with Meta Platform policies.
You can also disconnect Dentvora from your Meta account directly at https://www.facebook.com/settings → Apps and Websites; this revokes our access tokens.
19. Policy Updates
We may update this Privacy Policy periodically.
Material changes will be notified via in-product notice or email to the registered account administrator.
Updates will be posted on this page with an updated effective date.
20. Contact Information
For privacy questions, data requests, or general inquiries:
Dentvora Technologies (OPC) Private Limited
Registered Address: Giri Market, Loni, Ghaziabad, Uttar Pradesh, 201102, India
Email: [email protected] (general & grievance)
Email: [email protected] (privacy & support)
Phone / WhatsApp: +91 70421 39045
Website: https://dentvora.com
