Privacy Policy
Last updated: July 5, 2026
1. Our role: controller and processor
DentaBook is used by dental clinics to manage their practice. Our privacy role depends on the type of data:
- Account and clinic data (the information clinics and staff give us to create and run their accounts), we act as the data controller, and this Policy governs how we handle it.
- Patient records that a clinic enters into the Service, the clinic is the data controller and we act as its data processor, handling that data on the clinic’s behalf and under its instructions, as set out in our Data Processing Agreement. If you are a patient, please direct requests about your records to your dental clinic.
2. Information we collect
Account and staff information
- Names, email addresses, and phone numbers of clinic owners and staff (doctors, secretaries).
- Role and permission settings, and whether an account is active.
- Passwords, which are handled and stored in hashed form by our authentication provider, we never see your plain-text password.
Clinic information
- Clinic name and contact phone number.
- Subscription plan, status, trial and billing period dates, and approval status.
- Practice settings and preferences you configure.
Patient records entered by clinics
When a clinic uses the Service, it may enter patient information such as name, phone number, date of birth, dental and medical history, allergies and medical alerts, appointments, tooth-by-tooth clinical records, treatments, payments and balances, uploaded images or X-rays, and internal notes. This data is provided and controlled by the clinic; we process it on the clinic’s behalf to provide the Service.
Technical and usage data
- Log and device data (such as IP address, browser type, and access times) generated when you use the Service, largely through our hosting providers.
- Data stored locally on your device to enable offline use, see our Cookie & Storage Policy.
3. How we use information
- To provide, operate, maintain, and secure the Service, including authentication and offline sync;
- To manage subscriptions, trials, approvals, and billing;
- To communicate with you, for example, sign-up alerts to the administrator and clinic approval or trial-status emails to doctors;
- To provide support and respond to your requests;
- To detect, prevent, and address security issues, fraud, or misuse;
- To improve and develop the Service;
- To comply with legal obligations and enforce our Terms.
4. Legal bases
Where applicable law requires a legal basis for processing, we rely on: performance of our contract with you (to provide the Service); your consent (where requested); our legitimate interests (to secure, operate, and improve the Service); and compliance with legal obligations. For patient records, the clinic is responsible for establishing the appropriate legal basis and any patient consent.
5. How we share information
We do not sell your personal information. We share it only as follows:
- Service providers (sub-processors) who help us run the Service: Supabase (database, authentication, and file/image storage hosting), Vercel (application hosting and delivery), and Resend (transactional email delivery). These providers process data on our behalf under their own security and privacy commitments.
- Legal and safety reasons: when required by law, legal process, or to protect the rights, safety, and property of us, our users, or others.
- Business transfers: if the Service is involved in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction, subject to this Policy.
6. The patient portal
Clinics can generate a read-only patient portal link. When shared, it lets a patient view a limited, read-only summary of their own information (such as upcoming appointments, treatment history, balance, and images). The portal is designed to exclude internal staff notes and the clinic’s internal cost figures, and it only ever shows the single patient associated with that link. Access is controlled by a unique token, which the clinic can regenerate at any time to revoke an old link.
7. Data storage and security
Data is stored using our hosting providers’ infrastructure. We use measures designed to protect it, including row-level access controls that scope each clinic’s data to that clinic, encryption of data in transit, and hashed password storage handled by our authentication provider. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Data retention
We retain account and clinic data for as long as your account is active and as needed to provide the Service and comply with our legal obligations. Patient records are retained on behalf of the clinic for as long as the clinic maintains them in the Service. When an account is terminated, we will retain, export, or delete data in accordance with our Terms and Data Processing Agreement, after which residual copies may persist for a limited time in backups before being overwritten.
9. International transfers
Our providers may store and process data on servers located outside Lebanon. Where data is transferred across borders, it remains subject to this Policy and to the security commitments of the providers involved.
10. Your rights
Depending on your location and applicable law, you may have rights to access, correct, update, delete, or restrict the use of your personal information, to object to certain processing, or to request a copy of your data. To exercise these rights over account or staff data, contact us using the details below. If you are a patient, your records are controlled by your dental clinic, please contact the clinic directly, and we will support the clinic in responding to your request.
11. Children
The Service is intended for use by dental professionals, not directly by children. A clinic may enter records for patients who are minors as part of providing dental care; that data is entered under the clinic’s responsibility and applicable law.
12. Third-party links
The Service may contain links to third-party websites or services (for example, our hosting provider or the “Powered by” link). We are not responsible for the privacy practices of those third parties, and we encourage you to review their policies.
13. Changes to this Policy
We may update this Policy from time to time. We will revise the “Last updated” date above and, for material changes, make reasonable efforts to notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
14. Contact
Questions about this document? Contact us at dentabooklb@gmail.com.