DentaSuite/Security & Subprocessors

DentaSuite — Security & Subprocessors

DRAFT — publish at dentasuite.com/security. Keep this page

truthful release-by-release; it is referenced by the Privacy Policy,

Terms, and DPA.

How patient data flows

  1. Your practice signs in through one suite account (Supabase

identity). Identity and billing systems never receive patient data.

  1. Files you process (e.g. photos for a montage) travel over TLS to

our EU servers, are processed, and are deleted within 24 hours

unless you save the case.

  1. Saved cases and practice settings live in your practice's own

storage partition, readable only by your practice's signed-in

users.

  1. Model improvement uses your content **only if your practice enables

it** (off by default; logged consent; revocable).

Measures

  • TLS 1.2+ for all transport; HSTS on all public hosts.
  • Encryption at rest on server volumes and backups.
  • Logical per-practice data segregation enforced in the application

layer on every request.

  • Least-privilege access: production access limited to named

administrators with MFA; administrative actions logged.

  • Automated backups with [FILL-IN frequency/retention]; restore tested

[FILL-IN cadence].

  • Dependency and OS patching cadence: [FILL-IN].
  • Incident response: documented runbook with regulator notification

timelines (NDB scheme, GDPR Art. 33/34).

Subprocessors

ProviderRoleLocation
Hetzner Online GmbHapplication hosting & storage (patient-data processing)Germany (EU)
Supabaseidentity, entitlements, app metadata (no patient data)[FILL-IN region]
Stripepayments (no patient data)US/global
Vercelweb hosting for portal apps (no patient data)US/global

Changes announced 30 days in advance at this page.

[FILL-IN: status page / security contact — security@dentasuite.com]

Reporting a vulnerability

Email security@dentasuite.com [FILL-IN]. We acknowledge within 2

business days and do not pursue good-faith researchers.

Privacy PolicyTerms of ServiceData Processing AgreementSecurity & Subprocessors