DentaSuite/Privacy Policy

DentaSuite Privacy Policy

Effective date: 29 July 2026

Operator: J Lee Innovations Pty Ltd (ABN 47 681 160 583),

Victoria, Australia ("DentaSuite", "we", "us").

Contact: privacy@dentasuite.app.

DentaSuite provides software applications to dental practices (the

"Services": DentaSupply, DentaBuild, DentaOrtho, DentaScribe and other

apps listed at dentasuite.app). This policy explains what we collect,

why, and your rights. The English version of this policy is

authoritative.

1. Two kinds of data

Account data — information about you and your practice: name,

email, practice name, subscription and billing status, language and

app preferences, support correspondence. We are the controller of this

data.

Practice content, including patient data — photos, scans, notes

and documents your practice processes through the Services. Your

practice is the controller of this data; we process it only on your

practice's instructions under our Data Processing Agreement.

Your practice is responsible for having a lawful basis (such as

patient consent or care provision) to process it.

2. How patient data is handled

  • Transient by default. Files uploaded for processing (e.g.

photos for a montage) are processed in memory and deleted from our

servers within 24 hours. We do not keep them unless someone at your

practice explicitly saves a case.

  • Saved cases are stored in your practice's own partition,

accessible only to your practice's signed-in users, and can be

deleted by your practice at any time.

  • No training without opt-in. Patient data is never used to

improve our models unless your practice explicitly enables the

improvement programme in settings (off by default; consent is

logged). You can withdraw at any time; withdrawal stops future use.

  • Consultation audio (DentaScribe): audio is sent to our

speech-to-text subprocessor solely to produce a transcript, and is

not retained after transcription. Patient identifiers are then

removed from the transcript on your device before any text is

sent for note generation, and restored locally — the note-generation

provider never receives them.

  • Identity and billing systems never receive patient data.

3. What we collect and why (account data)

DataPurposeLegal basis (GDPR terms)
Name, email, password/SSO identityyour account and sign-incontract
Practice name, ABN/VAT, addressbilling, taxcontract, legal obligation
Payment detailshandled by Stripe; we never store card numberscontract
Usage logs (app events, IP, timestamps)security, abuse prevention, supportlegitimate interests
Preferences (language, settings)operating the Servicescontract
Support messageshelping youcontract

We do not sell personal information and do not use advertising

trackers in the Services.

4. Where data lives

Our servers are hosted in the European Union (Hetzner, Germany) with

identity services provided by Supabase (Sydney, Australia region) and web

hosting by Vercel. If you are in Australia or another country outside

the EU, your data is processed overseas; we protect it with the

safeguards described in our Security page and, for

GDPR-covered practices, standard contractual clauses where required.

5. Subprocessors

Listed publicly with roles at /security (currently:

Hetzner, Supabase, Stripe, Vercel, Resend, Groq, Anthropic, ClickSend). We give 30

days' notice before adding one.

6. Retention

Account data: for the life of the account plus 24 months.

Transient uploads: deleted within 24 hours. Saved cases: until your

practice deletes them or the account closes (then deleted within 30

days, backups within 90). Billing records: as tax law requires.

7. Your rights

Depending on your jurisdiction (including GDPR and the Australian

Privacy Act), you may access, correct, export, delete, or object to

processing of your personal data — email privacy@dentasuite.app.

Patients should direct requests to their dental practice (the

controller); we assist practices in fulfilling them. You may complain

to your regulator (OAIC in Australia; your DPA in the EU/UK).

8. Security

TLS in transit, encrypted volumes at rest, per-practice data

partitioning, least-privilege access, audited administrative access,

and a tested breach-response plan. Details: /security.

If a breach is likely to result in serious harm, we notify affected

practices and regulators as required by law (including Australia's

NDB scheme and GDPR Art. 33 timelines).

9. Connected email accounts (Google & Microsoft)

You can connect your own email account so referral letters and patient

communications are sent from your real address. This is optional and

per-user.

What we request. For Google, only the gmail.send permission (send

email on your behalf) plus your email address to identify the connected

account. We cannot read, browse, delete or modify your mailbox — the

permission does not allow it. For Microsoft 365, the equivalent

Mail.Send permission.

What we store. The OAuth tokens that authorise sending, your

connected email address, and delivery metadata (recipient, subject,

time) for the practice's own communication history. We do not store

copies of your mailbox and never receive any. Tokens are stored

encrypted at rest and are deleted immediately when you disconnect the

account (Account settings → Email), which you can do at any time. You

can also revoke our access from your

Google Account permissions

or Microsoft account settings.

Limited Use. DentaSuite's use and transfer of information received

from Google APIs adheres to the

Google API Services User Data Policy,

including the Limited Use requirements. In plain terms: data obtained

through Google APIs is used only to send the emails you compose or

approve, is never used for advertising, is never sold, and is never

read by humans except with your explicit consent, for security

purposes, or as required by law.

10. Children

The Services are for dental professionals. Practice content may

include minors' clinical photos under the practice's authority as

controller; we apply the same protections to all patient data.

11. Changes

We'll notify account owners by email of material changes at least 14

days before they take effect.

Privacy PolicyTerms of ServiceData Processing AgreementSecurity & Subprocessors