DentaSuite Privacy Policy
Effective date: 29 July 2026
Operator: J Lee Innovations Pty Ltd (ABN 47 681 160 583),
Victoria, Australia ("DentaSuite", "we", "us").
Contact: privacy@dentasuite.app.
DentaSuite provides software applications to dental practices (the
"Services": DentaSupply, DentaBuild, DentaOrtho, DentaScribe and other
apps listed at dentasuite.app). This policy explains what we collect,
why, and your rights. The English version of this policy is
authoritative.
1. Two kinds of data
Account data — information about you and your practice: name,
email, practice name, subscription and billing status, language and
app preferences, support correspondence. We are the controller of this
data.
Practice content, including patient data — photos, scans, notes
and documents your practice processes through the Services. Your
practice is the controller of this data; we process it only on your
practice's instructions under our Data Processing Agreement.
Your practice is responsible for having a lawful basis (such as
patient consent or care provision) to process it.
2. How patient data is handled
- Transient by default. Files uploaded for processing (e.g.
photos for a montage) are processed in memory and deleted from our
servers within 24 hours. We do not keep them unless someone at your
practice explicitly saves a case.
- Saved cases are stored in your practice's own partition,
accessible only to your practice's signed-in users, and can be
deleted by your practice at any time.
- No training without opt-in. Patient data is never used to
improve our models unless your practice explicitly enables the
improvement programme in settings (off by default; consent is
logged). You can withdraw at any time; withdrawal stops future use.
- Consultation audio (DentaScribe): audio is sent to our
speech-to-text subprocessor solely to produce a transcript, and is
not retained after transcription. Patient identifiers are then
removed from the transcript on your device before any text is
sent for note generation, and restored locally — the note-generation
provider never receives them.
- Identity and billing systems never receive patient data.
3. What we collect and why (account data)
| Data | Purpose | Legal basis (GDPR terms) |
|---|---|---|
| Name, email, password/SSO identity | your account and sign-in | contract |
| Practice name, ABN/VAT, address | billing, tax | contract, legal obligation |
| Payment details | handled by Stripe; we never store card numbers | contract |
| Usage logs (app events, IP, timestamps) | security, abuse prevention, support | legitimate interests |
| Preferences (language, settings) | operating the Services | contract |
| Support messages | helping you | contract |
We do not sell personal information and do not use advertising
trackers in the Services.
4. Where data lives
Our servers are hosted in the European Union (Hetzner, Germany) with
identity services provided by Supabase (Sydney, Australia region) and web
hosting by Vercel. If you are in Australia or another country outside
the EU, your data is processed overseas; we protect it with the
safeguards described in our Security page and, for
GDPR-covered practices, standard contractual clauses where required.
5. Subprocessors
Listed publicly with roles at /security (currently:
Hetzner, Supabase, Stripe, Vercel, Resend, Groq, Anthropic, ClickSend). We give 30
days' notice before adding one.
6. Retention
Account data: for the life of the account plus 24 months.
Transient uploads: deleted within 24 hours. Saved cases: until your
practice deletes them or the account closes (then deleted within 30
days, backups within 90). Billing records: as tax law requires.
7. Your rights
Depending on your jurisdiction (including GDPR and the Australian
Privacy Act), you may access, correct, export, delete, or object to
processing of your personal data — email privacy@dentasuite.app.
Patients should direct requests to their dental practice (the
controller); we assist practices in fulfilling them. You may complain
to your regulator (OAIC in Australia; your DPA in the EU/UK).
8. Security
TLS in transit, encrypted volumes at rest, per-practice data
partitioning, least-privilege access, audited administrative access,
and a tested breach-response plan. Details: /security.
If a breach is likely to result in serious harm, we notify affected
practices and regulators as required by law (including Australia's
NDB scheme and GDPR Art. 33 timelines).
9. Connected email accounts (Google & Microsoft)
You can connect your own email account so referral letters and patient
communications are sent from your real address. This is optional and
per-user.
What we request. For Google, only the gmail.send permission (send
email on your behalf) plus your email address to identify the connected
account. We cannot read, browse, delete or modify your mailbox — the
permission does not allow it. For Microsoft 365, the equivalent
Mail.Send permission.
What we store. The OAuth tokens that authorise sending, your
connected email address, and delivery metadata (recipient, subject,
time) for the practice's own communication history. We do not store
copies of your mailbox and never receive any. Tokens are stored
encrypted at rest and are deleted immediately when you disconnect the
account (Account settings → Email), which you can do at any time. You
can also revoke our access from your
or Microsoft account settings.
Limited Use. DentaSuite's use and transfer of information received
from Google APIs adheres to the
Google API Services User Data Policy,
including the Limited Use requirements. In plain terms: data obtained
through Google APIs is used only to send the emails you compose or
approve, is never used for advertising, is never sold, and is never
read by humans except with your explicit consent, for security
purposes, or as required by law.
10. Children
The Services are for dental professionals. Practice content may
include minors' clinical photos under the practice's authority as
controller; we apply the same protections to all patient data.
11. Changes
We'll notify account owners by email of material changes at least 14
days before they take effect.