Last updated: [insert date] · Applies to dmdent.com and the dmdent platform
This Privacy Policy explains how dmdent.com ("dmdent," "we," "us," or "our") collects, uses, stores, and protects personal data through the dmdent website and platform (the "Service"). It applies to:
For patient data, your clinic is the data controller — the party that decides what patient data is collected and why. dmdent acts as a data processor, handling that data only to provide the Service and only on the clinic's instructions. If you are a patient with questions about your own records, please contact your dental clinic directly; they control that data, not dmdent.
| Category | Examples |
|---|---|
| Account information | Name, email, username, password (stored as a secure hash, never in plain text), role (staff, clinic-admin, super-admin) |
| Clinic business information | Clinic name, address, logo, business details used for invoicing and branding |
| Billing information | Subscription plan, payment method details as needed to process payment, billing history |
| Usage data | Login activity, feature usage, and technical logs used for security and support purposes |
| Category | Examples |
|---|---|
| Identity and contact information | Name, contact details, date of birth |
| Health information | Allergies, blood type, visit history, tooth-by-tooth dental chart records, freehand annotations, clinical notes entered by clinic staff |
| Consent and intake records | Digital intake form responses, e-signatures, consent confirmations, stored as signed PDF records |
| Appointment data | Booking dates, times, and preferences submitted through the online booking page |
| Billing records tied to visits | Itemized invoices, discount classifications (e.g., senior citizen/PWD), payment method and status |
Patient data is entered into the Service by clinics or submitted directly by patients through a clinic's booking and intake pages. dmdent does not independently collect patient data outside of what a clinic's use of the Service generates.
We process personal data only for purposes necessary to provide and support the Service, including:
We do not sell personal or patient data, and we do not use patient health data for advertising or marketing purposes.
Where the Data Privacy Act of 2012 or similar law applies, we and our clinic customers rely on the following legal bases:
No system can guarantee absolute security. If we become aware of a data breach affecting your information, we will notify affected clinics without undue delay and, where required by law, notify the National Privacy Commission and affected data subjects.
We do not sell personal data. We share data only with:
We do not share patient data across unrelated clinics, and we do not share patient data with third parties for their own marketing purposes.
Our infrastructure provider (Google Cloud) may process or store data in data centers located outside the Philippines. Where this involves a cross-border transfer of personal data, we take reasonable steps to ensure the receiving party maintains a comparable standard of data protection, consistent with the requirements of the Data Privacy Act of 2012. [Data center region is us-central1, located in Iowa, United States.]
Subject to applicable law, including the Data Privacy Act of 2012, you may have the right to:
If you are a patient, requests about your health records should generally go to your dental clinic first, since they control that data. If you are a clinic or staff user, contact us directly using the details below.
Our website may use cookies or similar technologies for basic functionality and, if enabled, analytics to understand website usage.
The Service is intended for use by dental clinics and their staff, not directly by children. Patient records may include minors' health information entered by a clinic on behalf of a parent or guardian; clinics are responsible for ensuring appropriate parental/guardian consent is obtained in accordance with applicable law before entering a minor's data.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be communicated by email or in-app notice at least [14] days before taking effect.
Contact us at [privacy/support email] or via the channels listed on our Support page. If you have a designated Data Protection Officer, list their contact details here as required under the Data Privacy Act.