Privacy Policy
Last updated: September 11, 2026 · Applies to dmdent.com and the dmdent platform
1. Who this policy covers
This Privacy Policy explains how dmdent.com ("dmdent," "we," "us," or "our") collects, uses, stores, and protects personal data through the dmdent website and platform (the "Service"). It applies to:
- Clinics and staff who register for and use the Service, and
- Patients whose information is entered into the Service by a clinic, including through online booking and digital intake.
For patient data, your clinic is the data controller — the party that decides what patient data is collected and why. dmdent acts as a data processor, handling that data only to provide the Service and only on the clinic's instructions. If you are a patient with questions about your own records, please contact your dental clinic directly; they control that data, not dmdent.
One exception, and it is set out in full in section 10: when you send an appointment enquiry to a clinic through our public clinic directory at /dentists, dmdent is the data controller for that enquiry. We collect it, for our own purpose, before you are any clinic's patient — so for that one thing, the questions in section 9 come to us and not to a clinic.
2. What data we collect
2.1 Data from clinics and staff
| Category | Examples |
|---|---|
| Account information | Name, email, username, password (stored as a secure hash, never in plain text), role (staff, clinic-admin, super-admin) |
| Clinic business information | Clinic name, address, logo, business details used for invoicing and branding |
| Billing information | Subscription plan, payment method details as needed to process payment, billing history |
| Usage data | Login activity, feature usage, and technical logs used for security and support purposes |
2.2 Patient data entered by clinics
| Category | Examples |
|---|---|
| Identity and contact information | Name, contact details, date of birth |
| Health information | Allergies, blood type, visit history, freehand dental chart annotations and the written findings saved with them, clinical notes entered by clinic staff |
| Clinical images (where the clinic uses the Orthodontics features) | Photographs of the face and teeth, X-rays, study-model images and scans taken as part of orthodontic treatment, each tagged with the view, the stage of treatment and the date; adjustment-visit records (wires, procedures, elastics, hygiene and cooperation ratings). Used only for the patient's own treatment record. Any use beyond the record — for example a before-and-after picture in the clinic's marketing — is a separate decision for the patient and needs the patient's separate, specific permission, which the clinic is responsible for obtaining. |
| Consent and intake records | Digital intake form responses, e-signatures, consent confirmations, stored as signed PDF records |
| Appointment data | Booking dates, times, and preferences submitted through the online booking page |
| Billing records tied to visits | Itemized invoices, discount classifications (e.g., senior citizen/PWD), payment method and status |
| HMO coverage and claims (where the clinic uses the HMO features) | HMO name, member number and plan name; Letter of Authorization (LOA) numbers, validity dates, approved procedures and amounts, and scanned copies of LOAs; the HMO share of an invoice; claim reference numbers, statuses and remittance records entered by clinic staff |
Patient data is entered into the Service by clinics or submitted directly by patients through a clinic's booking and intake pages. dmdent does not independently collect patient data outside of what a clinic's use of the Service generates.
3. Why we collect this data
We process personal data only for purposes necessary to provide and support the Service, including:
- Creating and maintaining clinic and staff accounts
- Storing and displaying patient records, dental charts and clinical images for the clinic's use
- Operating online booking and digital intake features
- Generating invoices, tracking payments, and producing financial reports for the clinic
- Recording Letters of Authorization and preparing HMO claim documents and statements for the clinic to submit to a patient's HMO
- Processing your clinic's subscription billing
- Maintaining account security, including login protection and session management
- Providing customer support when you contact us
- Improving the reliability and functionality of the Service
We do not sell personal or patient data, and we do not use patient health data for advertising or marketing purposes.
4. Legal basis for processing
Where the Data Privacy Act of 2012 or similar law applies, we and our clinic customers rely on the following legal bases:
- Contractual necessity — processing needed to provide the Service a clinic has subscribed to.
- Consent — for patient data, obtained by the clinic at the point of intake or booking; clinics are responsible for securing this consent.
- Legal obligation — where processing or retention is required by applicable healthcare or financial recordkeeping laws.
- Legitimate interest — for account security, fraud prevention, and service improvement, balanced against user rights.
5. How we store and protect data
- Data is stored in an encrypted, managed database (Google Cloud SQL for PostgreSQL), encrypted at rest, with automated backups. Files uploaded to a patient's record — scanned documents, images, signed forms — are stored in Google Cloud Storage, also encrypted at rest, in a private bucket that cannot be made public; the database holds only a reference to each file. Both are in the same region (see section 7).
- An uploaded file is never given a public or shareable link. Every request for one is served through the Service, so it is subject to the same sign-in, the same clinic-ownership check and the same audit trail as the record it belongs to.
- All data in transit is encrypted via HTTPS.
- Each clinic's records are logically isolated — staff at one clinic location cannot access another clinic's data, even within a shared multi-location account.
- Access is role-based: staff, clinic-admin, and cross-clinic super-admin roles see only what their role permits.
- Passwords require a 12-character minimum and are checked against known weak/common passwords; accounts lock for 15 minutes after 5 failed login attempts.
- Staff sessions expire automatically after a period of inactivity.
No system can guarantee absolute security. If we become aware of a data breach affecting your information, we will notify affected clinics without undue delay and, where required by law, notify the National Privacy Commission and affected data subjects.
6. Who we share data with
We do not sell personal data. We share data only with:
- Infrastructure providers — currently Google Cloud (hosting, database, and storage), which processes data on our behalf under its own data processing and security commitments.
- Payment processors — to process subscription billing; we do not store full payment card details ourselves.
- Other staff within your own clinic — according to the role-based permissions your clinic sets.
- Authorities — where required by law, court order, or valid legal process.
Where a clinic uses the HMO features, the clinic itself submits claims to the patient's HMO or health insurer, using LOAs, claim packets and statements printed or exported from the Service. dmdent does not transmit patient data to any HMO, has no data connection with HMOs, and does not receive or handle HMO payments. HMOs receive only what the clinic chooses to send them, under the consent the patient gave the clinic and the HMO.
Where a clinic switches on Daily backup to your Google Drive (Settings), dmdent writes that clinic’s own records — as spreadsheets — into a folder in a Google account the clinic controls, every night, on the clinic’s instruction. This is a disclosure back to the clinic itself rather than to a new recipient: the destination is their account, the files are theirs, and Google acts for them there and not for us. It is off unless the clinic turns it on, they can disconnect at any time, and dmdent asks Google for the narrowest available permission — access limited to the files dmdent itself creates, with no ability to read anything else in that Drive. Once a copy is in the clinic’s Google account, it is under the clinic’s control and its own arrangements with Google.
We do not share patient data across unrelated clinics, and we do not share patient data with third parties for their own marketing purposes.
7. International data transfer
Our infrastructure provider (Google Cloud) processes and stores data in its us-central1 region, located in Iowa, United States. Where this involves a cross-border transfer of personal data, we take reasonable steps to ensure the receiving party maintains a comparable standard of data protection, consistent with the requirements of the Data Privacy Act of 2012.
8. Data retention
- We retain clinic and patient data for as long as the clinic's subscription is active.
- After a subscription ends, data remains available for export for 30 days, after which it may be deleted from our active systems, except where longer retention is required by applicable healthcare recordkeeping or tax/financial laws.
- Invoices, HMO claim and remittance records form part of the clinic's financial records and may be retained for as long as applicable tax and financial recordkeeping laws require, even after the related appointment or patient record is removed.
- Backup copies may persist for a limited additional period as part of standard backup rotation before being permanently deleted.
9. Your rights
Subject to applicable law, including the Data Privacy Act of 2012, you may have the right to:
- Be informed that your personal data is being processed
- Access the personal data we (or your clinic) hold about you
- Request correction of inaccurate data
- Object to certain processing, or withdraw consent where processing is based on consent
- Request erasure or blocking of data, subject to legal recordkeeping requirements
- Request a copy of your data in a portable format
- File a complaint with the National Privacy Commission
If you are a patient, requests about your health records should generally go to your dental clinic first, since they control that data. If you are a clinic or staff user, contact us directly using the details below.
10. Clinic directory and appointment enquiries
We publish a directory of dental clinics at /dentists so that people looking for a dentist can find one. This section covers it, because our role there is different from our role everywhere else on the platform.
10.1 Clinic listings
A listing carries a clinic's business information: the clinic's name, address, phone number, website, and — where the clinic has told us — its opening hours, the services it offers and the HMOs it accepts. We list clinics from information the clinic itself publishes (its signage, its own website or social media page, or a public business listing), and we record for every listing where that information came from. We do not publish the name of an individual dentist on a listing.
A clinic may claim its listing to correct it, or ask us to remove it. A removal request is honoured immediately, without verification and without argument, and the listing is not restored on a later update. Both links are on the clinic's own listing page, or a clinic can contact us using the details below.
10.2 If you send an enquiry to a clinic
When you use the “Request an appointment” form on a listing, we collect your name, mobile number, optional email address, preferred date and your reason for visiting, and we email them to that clinic so it can contact you. That is the only purpose we use them for. Our legal basis is your own request: you are asking us to pass your details to a named clinic, and the form says so before you send it.
We do not collect HMO or insurance details on a directory enquiry — no card or member number, no policy details. If a clinic uses dmdent for its own bookings, those details are collected on that clinic's own booking page, where the clinic holds them as the controller.
An enquiry is not an appointment. We pass on your request; the clinic decides whether to offer you a time, and nothing is reserved for you until the clinic confirms it with you directly. If the clinic has not been in touch within five days, we will email you to tell you so.
10.3 How long we keep an enquiry
We delete every directory enquiry 90 days after it was sent, whether or not the clinic replied. The clinic will have its own copy in its own email, which is then that clinic's to hold and to delete.
Because dmdent is the controller for these enquiries, requests about them — access, correction, objection, erasure — come to us at the address in the contact box below, and you do not need to go to the clinic first.
11. Cookies and website analytics
Our website may use cookies or similar technologies for basic functionality and, if enabled, analytics to understand website usage.
12. Children's data
The Service is intended for use by dental clinics and their staff, not directly by children. Patient records may include minors' health information entered by a clinic on behalf of a parent or guardian; clinics are responsible for ensuring appropriate parental/guardian consent is obtained in accordance with applicable law before entering a minor's data.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be communicated by email or in-app notice at least 14 days before taking effect.
Questions or data requests
To ask a question about this policy, or to request access to, correction of, or deletion of your personal data, contact us through our Support page. We will respond within the period required by the Data Privacy Act.