Privacy Policy
Last updated: June 1, 2026
This Privacy Policy explains how Imdent ("we") handles personal data when you use the platform. We act as a processor of patient data on behalf of clinics (the controllers), and as a controller for account and billing data.
1. Data we collect
- Account data: name, email, phone, role, and authentication details.
- Clinic / supplier data: business details, location, licensing, services, products, and media you upload.
- Patient data entered by clinics: contact details, appointments, visits, treatment and medical notes. Sensitive medical fields are encrypted at rest.
- Billing data: subscriptions, payment receipts, top-ups, and ledger entries (we do not store full card numbers).
- Usage and device data: log data, IP, and analytics needed to operate and secure the Service.
2. How we use data
- To provide and maintain the Service, including appointments, messaging, billing, and the marketplace.
- To process payments and prevent fraud and abuse.
- To send transactional and, where you opt in, marketing messages — you can unsubscribe at any time.
- To improve, secure, and troubleshoot the Service.
3. Security
We use encryption in transit and encrypt sensitive medical fields at rest. Access is restricted by role and tenant isolation so a clinic can only see its own data. No system is perfectly secure, but we work to protect your information using industry-standard measures.
4. Sharing
We share data only as needed to run the Service:
- Service providers: payment processors, messaging (WhatsApp/Meta), hosting, email, and analytics — bound to process data on our instructions.
- Between clinics and suppliers/labs for transactions you initiate.
- When required by law, or to protect rights, safety, and the integrity of the Service.
We do not sell your personal data.
5. Retention
We keep data for as long as your account is active and as needed to comply with legal, accounting, and dispute-resolution obligations. Clinics control patient-record retention within the Service; on account closure you may request export or deletion subject to legal limits.
6. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, and you may object to or restrict certain processing. For patient data, requests are directed to the clinic that controls it. Contact us to exercise these rights.
7. Cookies
We use essential cookies for sign-in, security, and preferences (such as language), and limited analytics. You can control cookies in your browser; disabling essential cookies may break core features.
8. Children and changes
The Service is intended for dental professionals and businesses, not for direct use by children; records about minors are entered and controlled by clinics under their own legal basis. We may update this Policy; material changes will be notified in-product.
This is a draft template and does not constitute legal advice. Have it reviewed by qualified counsel before relying on it.