Privacy Policy
Concept-stage notice. Fields marked [INSERT] are placeholders to be completed with final legal-entity and contact details before this policy is published live.
1Introduction and Scope
This Privacy Policy explains how [LEGAL COMPANY NAME], Inc., a Delaware corporation doing business as Dental Nexus (“Dental Nexus,” “Company,” “we,” “us,” or “our”), collects, uses, stores, discloses, transfers and protects personal information when individuals and organizations access or use our websites, applications, platform and related services (collectively, the “Services”).
Dental Nexus operates a digital platform that connects clinicians, dental laboratories, treatment planners, designers, manufacturers and other authorized professionals for case coordination, digital dentistry, CAD/CAM services, treatment-planning support, manufacturing workflows, file exchange and related services.
Our Services may be offered to users located in:
- The Middle East and North Africa (“MENA”)
- The United States
- Canada
- The European Economic Area (“EEA”) and United Kingdom
- Latin America
- Asia-Pacific
- Other jurisdictions in which the Services are lawfully made available
Different privacy and health-information laws may apply depending on the country where an individual is located, where a healthcare service is provided, where data originates, where it is stored, and the role performed by Dental Nexus.
Availability of the Services in a country does not necessarily mean that every feature, hosting location, file type or cross-border workflow is available in that country.
2Who We Are
Legal entity: [LEGAL COMPANY NAME], Inc.
Doing business as: Dental Nexus
Jurisdiction of incorporation: Delaware, United States
Registered office: [INSERT REGISTERED OFFICE]
Principal business address: [INSERT BUSINESS ADDRESS]
Privacy email: [INSERT PRIVACY EMAIL]
Data Protection Officer / Privacy Lead: [INSERT NAME/ROLE & CONTACT]
Where required by applicable law, details of our EEA, UK, MENA or other local representatives will be made available in this Privacy Policy or through a jurisdiction-specific privacy notice.
This Privacy Policy must not be published with incomplete contact or legal-entity information.
3Our Data-Protection Roles
3.1 Account, Website, Billing and Business Data
Dental Nexus generally acts as a data controller or equivalent responsible party when it determines why and how personal information is processed for purposes such as:
- Creating and administering user accounts
- Operating the website
- Providing customer support
- Managing subscriptions and payments
- Maintaining security and audit records
- Communicating with users
- Complying with legal obligations
- Improving the Services using non-patient operational data
3.2 Customer Case Data
When a clinic, clinician, laboratory, treatment planner or other customer uploads or submits patient-related data and determines the purpose of the case, that customer will generally act as the controller, responsible party or regulated healthcare entity.
Dental Nexus will generally act as a processor, service provider, contractor or equivalent party and will process Customer Case Data:
- On the customer's documented instructions
- To provide the requested Services
- Subject to the applicable agreement or Data Processing Addendum
- As otherwise required or permitted by law
Dental Nexus may act as an independent controller for limited processing involving platform security, fraud prevention, billing, legal compliance, and the establishment, exercise or defense of legal claims.
3.3 Customer Responsibilities
Customers who submit Customer Case Data are responsible for:
- Establishing an appropriate legal basis for collecting, using, disclosing and transferring the data
- Providing all required notices to patients
- Obtaining valid patient or legal-guardian consent where required
- Ensuring that disclosure to Dental Nexus and other participants is legally permitted
- Uploading only data necessary for the relevant case
- Selecting authorized recipients
- Complying with professional confidentiality and medical-record requirements
- Determining applicable clinical-retention requirements
- Avoiding the inclusion of unnecessary identifiers
Consent is not necessarily the only lawful basis for processing patient data. Customers must determine the correct basis under the laws governing their professional practice and the relevant patient.
4Information We Collect
4.1 Account and Profile Information
- Name, business email address, telephone number
- Country, region and preferred language
- Account username and hashed authentication credentials
- Business name, professional role and registration/credentials
- Profile photograph, account settings and security information
4.2 Business and Professional Information
- Services offered or requested; planning, design, laboratory or manufacturing capabilities
- Software and hardware used; CAD/CAM workflows
- Areas of professional expertise, estimated case volumes and availability
- Pricing or service information; professional certifications
- Business addresses; contract and subscription details
4.3 Customer Case Data and Sensitive Information
Customer Case Data may include STL, OBJ, PLY, DICOM, CBCT or similar digital files; intraoral scans; dental models; clinical photographs; radiographic or diagnostic images; treatment prescriptions; clinical notes; patient identifiers; patient age or date of birth; medical or dental history; treatment-planning information; case communications; and files or deliverables produced by clinicians, planners, laboratories, designers or manufacturers.
Depending on the jurisdiction and the content of the file, Customer Case Data may constitute health data, medical information, biometric data, sensitive personal data, special-category data, protected health information, or data relating to a child.
Customers should use coded case identifiers instead of patient names whenever reasonably possible, and must not upload genetic information, government identification documents, financial information or unrelated medical information unless strictly necessary, legally permitted and expressly supported by the Services.
4.4 Payment and Transaction Information
Billing name and address, subscription or transaction history, tax information, payment status and limited payment-method information supplied by a payment provider. Payment-card information may be processed directly by a third-party payment processor; unless expressly stated otherwise, Dental Nexus does not store full card numbers or security codes.
4.5 Usage, Device and Security Information
IP address, browser and device type, operating system, device identifiers, login times, session information, pages or features accessed, case-access records, upload/download events, authentication events, audit logs, error and diagnostic logs, approximate location derived from IP address, and security alerts or suspected misuse.
4.6 Communications
Messages exchanged through the platform, support requests and tickets, emails and other communications with Dental Nexus, meeting records (where notice and consent have been provided), feedback, survey responses, and complaints or privacy requests.
4.7 Cookies and Similar Technologies
Information collected through cookies, pixels, local storage, SDKs and similar technologies, as described in Section 16.
4.8 Information Received from Third Parties
We may receive information from a user's employer, clinic or laboratory; another authorized case participant; identity or authentication providers; payment processors; referral partners; integration providers; public professional registries; and other sources authorized by the individual or permitted by law.
5Legal Bases for Processing
Where applicable law requires a legal basis, Dental Nexus may process personal information based on:
5.1 Contract
Processing necessary to provide the Services, administer an account, perform a contract, or take requested steps before entering into a contract.
5.2 Consent
Processing based on freely given, specific, informed and unambiguous consent, including explicit or written consent where required for sensitive data, marketing, cookies or cross-border transfers. Consent may be withdrawn at any time, without affecting processing lawfully performed before withdrawal.
5.3 Legitimate Interests
Processing necessary for legitimate business interests, where permitted and not overridden by individual rights, including platform administration, service improvement, network and information security, fraud prevention, customer support, internal reporting, and protection of legal rights.
5.4 Legal Obligations
Processing necessary to comply with laws, regulations, court orders, tax requirements, professional obligations, sanctions or lawful government requests.
5.5 Vital Interests and Other Legal Grounds
Processing necessary to protect a person's life or physical safety, establish or defend legal claims, or satisfy another lawful ground recognized in the applicable jurisdiction.
For Customer Case Data, the customer is responsible for determining and documenting the applicable legal basis unless Dental Nexus is independently responsible for the relevant processing.
6How We Use Information
6.1 Provide the Services
Register and authenticate users; create and administer accounts; facilitate case collaboration; connect authorized professionals; assign or accept cases; enable secure file exchange; provide case-status updates; facilitate treatment-planning, design, laboratory or manufacturing workflows; process payments; generate invoices; and provide customer support.
6.2 Operate and Improve the Platform
Maintain functionality and reliability; diagnose errors; monitor performance; develop new features; conduct quality assurance; understand non-patient usage patterns; maintain audit trails; and improve accessibility and user experience.
6.3 Communicate with Users
Send account and security notices; provide case notifications; respond to support requests; send operational messages; communicate policy or contractual changes; and send marketing communications where permitted.
Users may unsubscribe from marketing communications, but they may continue to receive essential service, account, security or case-related messages.
6.4 Protect the Platform
Verify identity and professional credentials; detect and prevent fraud; investigate misuse; enforce agreements; prevent unauthorized access; maintain business continuity; protect patients, users and third parties; and comply with legal obligations.
7Artificial Intelligence and Product Development
7.1 AI-Assisted Features
The Services may include AI-assisted or automated features used to support workflow organization, file review, quality checks, case routing, communication or other requested functions. Where an AI-assisted feature processes Customer Case Data solely to provide the requested service, such processing will be performed under the applicable customer agreement and documented instructions.
7.2 No General Training on Identifiable Patient Data
Dental Nexus does not use identifiable patient information or identifiable Customer Case Data to train general-purpose, shared or publicly available artificial-intelligence models.
We will not permit a third-party AI provider to use identifiable Customer Case Data for its independent model training unless: the customer has separately and expressly authorized the use; all required patient authorizations have been obtained; the use is lawful in every relevant jurisdiction; appropriate contractual protections are in place; and the use is clearly described before it occurs.
7.3 Anonymized, Aggregated and Synthetic Data
We may use aggregated, synthetic or irreversibly anonymized information for analytics, security, research, product development and service improvement where individuals cannot reasonably be reidentified, applicable anonymization requirements have been met, the information is not subject to customer restrictions prohibiting such use, and the use is otherwise lawful.
Pseudonymized or coded information will continue to be treated as personal information where reidentification remains reasonably possible.
8How We Disclose Information
8.1 Authorized Case Participants
Customer Case Data may be made available to authorized participants selected or approved by the customer, including clinicians, dental laboratories, treatment planners, designers, manufacturers, reviewers and other professionals involved in the case. Access is limited according to account permissions, case assignments and applicable contractual terms.
8.2 Service Providers and Subprocessors
We may engage providers for database hosting, object and file storage, authentication, cloud infrastructure, email, customer support, security monitoring, error reporting, analytics, payment processing, communications, document signing, and AI-assisted functionality.
Our providers may include Supabase and other providers listed in our then-current Subprocessor List. Where required, providers will be subject to written agreements requiring confidentiality, appropriate security, limited processing purposes, deletion or return obligations, and assistance with privacy requests and security incidents.
The use of a provider does not transfer Dental Nexus's legal responsibilities to that provider.
8.3 Corporate Transactions
Information may be disclosed in connection with a merger, financing, acquisition, reorganization, due-diligence process, sale of assets or similar transaction, subject to confidentiality and applicable law. Customer Case Data will not be transferred to a new owner for unrelated purposes without an appropriate legal basis.
8.4 Legal and Safety Disclosures
We may disclose information when reasonably necessary to comply with applicable law; respond to a valid court order, subpoena or lawful government request; protect a person's health or safety; investigate fraud, abuse or security threats; enforce our agreements; or establish, exercise or defend legal claims. Where legally permitted, we will notify the affected customer before disclosing Customer Case Data in response to a government request.
8.5 No Sale of Patient Data
We do not sell Customer Case Data or patient information, and we do not sell personal information in exchange for money. Certain analytics or advertising technologies could be considered "sharing," "targeted advertising" or a similar activity under some U.S. state laws. Where applicable, we will provide the required notice and opt-out mechanism.
9Data Processing Agreements
Customers submitting Customer Case Data may be required to enter into a Data Processing Addendum or other appropriate agreement. Depending on the jurisdiction and service, this may include:
- GDPR Article 28 processor terms
- Standard Contractual Clauses
- A UK international-transfer addendum or agreement
- A Business Associate Agreement under HIPAA
- Saudi PDPL processor and transfer terms
- UAE health-data requirements
- Local transfer clauses, confidentiality requirements and security schedules
- Instructions governing deletion, return, retention and subprocessors
10International Data Transfers
10.1 General Transfer Mechanisms
Because Dental Nexus may serve users in multiple countries, information may be accessed, hosted or processed in a country different from the one in which it was collected. Before making a restricted international transfer, we may use one or more of the following, where legally available: an adequacy decision or recognized adequate jurisdiction; European Commission Standard Contractual Clauses; the UK International Data Transfer Agreement or UK Addendum; contractual transfer safeguards recognized by the relevant regulator; binding corporate rules, where applicable; a data-transfer impact or risk assessment; explicit consent where consent is a valid and appropriate transfer mechanism; local hosting; regulatory notification, registration, license, permit or approval; or another legally recognized exception or safeguard.
We may restrict access to particular Services or require a jurisdiction-specific hosting environment where international transfer requirements cannot be satisfied.
10.2 Middle East and North Africa
Depending on where an individual resides, where a healthcare service is provided, and where data originates, Dental Nexus may be subject to laws including:
Saudi Arabia
The Saudi Personal Data Protection Law, its Implementing Regulations, and the Regulation on Personal Data Transfer Outside the Kingdom may apply to processing of personal data relating to individuals residing in Saudi Arabia, including processing performed by an organization located outside Saudi Arabia. Saudi personal data will be transferred outside the Kingdom only where a permitted purpose, appropriate safeguards, risk assessment and any other required conditions have been satisfied.
United Arab Emirates
UAE Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data may apply to personal data processed in or relating to the UAE. Health information relating to health services provided in the UAE may also be governed by Federal Law No. 2 of 2019 Concerning the Use of Information and Communication Technology in Health Fields and applicable health-authority rules. Where those health-data rules apply, Dental Nexus will not store, process, generate or transfer the relevant health information outside the UAE unless an applicable legal exception, decision or authorization permits it.
Dental Nexus may therefore require an approved in-country hosting environment, disable international access, restrict certain workflows, require evidence of regulatory approval, or decline to accept a case.
Organizations established in or operating from the Dubai International Financial Centre or Abu Dhabi Global Market may also be subject to the DIFC Data Protection Law or ADGM Data Protection Regulations.
Egypt
Egyptian Personal Data Protection Law No. 151 of 2020 and its implementing requirements may apply to personal data relating to individuals in Egypt. Health data, biometric data and children's data may constitute sensitive personal data. Processing, hosting, disclosure or international transfer may require explicit written consent, a license, permit, local representative, Data Protection Officer or other regulatory measure. Dental Nexus may delay or restrict Egyptian processing until all applicable regulatory steps have been completed.
Qatar
Qatar Law No. 13 of 2016 Concerning Personal Data Privacy Protection may apply to processing involving individuals in Qatar. Organizations established in the Qatar Financial Centre may also be subject to the QFC Data Protection Regulations and Rules.
Bahrain
Bahrain Law No. 30 of 2018 with Respect to Personal Data Protection and related resolutions may apply to processing involving individuals in Bahrain. Processing sensitive data, engaging certain processors, or transferring data internationally may require additional safeguards or regulatory procedures.
Oman
Royal Decree No. 6 of 2022 issuing the Oman Personal Data Protection Law and its implementing requirements may apply to processing involving individuals in Oman. Dental Nexus will obtain consent, implement transfer safeguards, and complete any approval or notification required by applicable Omani law.
Jordan
Jordan Personal Data Protection Law No. 24 of 2023 may apply to processing involving individuals in Jordan. Dental Nexus and its customers will apply appropriate security, controller-processor terms, lawful-processing grounds and cross-border-transfer requirements.
Morocco
Morocco Law No. 09-08 concerning the protection of individuals with regard to the processing of personal data may apply. Certain processing activities and international transfers may require declarations, authorization or approval from the Moroccan data-protection authority.
Algeria
Algeria Law No. 18-07, as amended, concerning the protection of individuals in the processing of personal data may apply. Processing sensitive information and transferring information abroad may require express consent and procedures before the Algerian data-protection authority.
Tunisia
Tunisia Organic Law No. 2004-63 concerning personal-data protection may apply. International transfers may require express consent, an adequate destination and prior authorization from the Tunisian data-protection authority.
Other MENA Jurisdictions
Other national, free-zone, healthcare, telecommunications, cybersecurity and professional-confidentiality laws may also apply. Dental Nexus may introduce country-specific notices, contractual requirements or service restrictions without expanding the purposes for which existing information is processed.
10.3 EEA and United Kingdom
For restricted transfers from the EEA or UK, Dental Nexus may rely on adequacy decisions; Standard Contractual Clauses; the UK Addendum; the UK International Data Transfer Agreement; and supplementary technical and organizational measures. Where required, we will conduct transfer assessments and appoint an EEA or UK representative.
10.4 Canada
Personal information relating to Canadian individuals may be processed under the Personal Information Protection and Electronic Documents Act and applicable provincial laws, including Quebec privacy requirements where applicable.
10.5 Latin America
Depending on the country, processing may be subject to laws including Brazil's Lei Geral de Proteção de Dados; Colombia's Law 1581 of 2012 and related regulations; Mexico's Federal Law on Protection of Personal Data Held by Private Parties; Argentina's Personal Data Protection Law No. 25,326; and other applicable national privacy laws.
10.6 United States
Depending on the individual and context, U.S. federal or state privacy laws may apply, including state consumer-privacy laws and healthcare confidentiality requirements. The handling of information subject to HIPAA will only be permitted through a designated, approved HIPAA-enabled environment and after all required Business Associate Agreements are executed. Users must not upload HIPAA-regulated Protected Health Information into a workspace that has not been approved by Dental Nexus for that purpose.
11Data Storage and Security
11.1 Hosting Infrastructure
Dental Nexus may use Supabase for PostgreSQL database services, authentication, APIs, real-time functionality and object storage. Each production environment will be assigned a primary hosting region; the applicable region or jurisdiction-specific environment should be identified in the customer agreement, Data Processing Addendum, Subprocessor List or service documentation.
Where local health-data or data-residency laws apply, Dental Nexus may use a separate provider, self-hosted environment, local infrastructure or other approved solution. A service provider's security certification does not, by itself, make Dental Nexus or a customer compliant with any privacy or healthcare law.
11.2 Security Measures
Depending on the service and deployment, our safeguards are designed to include: encryption in transit; encryption at rest where supported and configured; role-based access controls; Row-Level Security policies; least-privilege access; multi-factor authentication for privileged accounts; secure password handling; logging and audit trails; network restrictions; secure backup procedures; access reviews; vulnerability management; incident-response procedures; secure development practices; employee and contractor confidentiality obligations; and vendor security assessments.
No internet-based system can be guaranteed to be completely secure. Users must protect their credentials, use strong passwords, enable available security features, and immediately report suspected unauthorized access.
12Data Retention
We retain personal information only for as long as reasonably necessary to provide the Services, fulfill the purposes described in this Privacy Policy, follow customer instructions, maintain security and audit records, satisfy legal, tax, accounting and regulatory obligations, comply with medical-record or professional requirements, resolve disputes, and establish, exercise or defend legal claims.
Retention periods may differ according to the category of information and applicable jurisdiction. Customer Case Data will generally be retained for the period selected or agreed by the customer, for the duration of the relevant contract, until deletion or return is requested by the customer, or for a longer period where legally required.
Deletion requests may be refused or delayed where information must be retained for legal, regulatory, clinical-record, fraud-prevention, backup, security or legal-claims purposes. Deleted information may remain in encrypted backups until the applicable backup cycle expires, after which it will be deleted or rendered inaccessible according to our retention procedures.
Dental Nexus will maintain a separate internal retention schedule identifying retention periods for account data, case data, audit records, support communications, payment records, marketing data and backups.
13Individual Privacy Rights
Depending on the jurisdiction and subject to legal exceptions, individuals may have the right to receive information about processing; access personal information; obtain a copy of it; correct inaccurate or incomplete information; request deletion or destruction; withdraw consent; restrict or suspend processing; object to processing, including direct marketing; receive portable data or request transfer to another controller where technically feasible; object to certain automated decisions; limit certain uses of sensitive information; opt out of sale, sharing or targeted advertising; appeal the denial of a request; be informed of certain security incidents; and file a complaint with a competent data-protection authority.
13.1 Requests Relating to Patient Case Data
When Dental Nexus processes patient information solely on behalf of a clinic, clinician, laboratory or other customer, the patient should ordinarily submit the request directly to that customer. Dental Nexus will assist the customer in responding where required by contract or law, and will not independently alter or delete a clinical record contrary to the lawful instructions of the responsible healthcare provider.
13.2 Submitting a Request
Requests may be submitted to [INSERT PRIVACY EMAIL]. We may request information necessary to verify identity, confirm authority to act for another person, locate relevant information, prevent fraudulent requests, and determine the applicable jurisdiction. We will respond within the period required by applicable law.
13.3 Complaints
Individuals may contact Dental Nexus first so that we can attempt to resolve a concern. Individuals may also complain directly to the competent supervisory or data-protection authority in their country.
14U.S. State Privacy Rights
Residents of California and other U.S. states with applicable consumer-privacy laws may have rights to know the categories and specific pieces of personal information collected; access personal information; correct inaccuracies; request deletion; obtain portable data; opt out of sale, sharing, targeted advertising or qualifying profiling; limit certain uses of sensitive personal information; use an authorized agent; and receive equal service without unlawful discrimination.
Dental Nexus does not sell Customer Case Data or patient information. Where our use of analytics or marketing technology constitutes "sharing," targeted advertising or another regulated activity, an applicable opt-out link or preference mechanism will be made available.
15Children and Pediatric Patient Data
15.1 Platform Users
The Services are intended for adult professionals and authorized business representatives who are at least 18 years old. We do not knowingly permit children to create independent user accounts.
15.2 Pediatric Patient Data
The platform may process case information relating to a patient who is under 18 when the information is submitted by an authorized clinician, clinic, laboratory, parent, guardian or other legally authorized party. The submitting customer must have a valid legal basis; obtain consent from a parent or legal guardian where required; comply with pediatric medical-record requirements; limit the information to what is necessary; apply appropriate confidentiality protections; and avoid using a child's data for marketing, profiling or unrelated purposes.
Dental Nexus will treat pediatric case data as sensitive information.
17Data Breaches and Security Incidents
Dental Nexus maintains procedures designed to identify, investigate, contain, document and remediate personal-data incidents.
Where Dental Nexus acts as a processor, we will notify the responsible customer without undue delay after confirming a qualifying incident, as required by the applicable agreement and law. Where Dental Nexus acts as a controller, we will notify affected individuals, customers, data-protection authorities, healthcare regulators and other competent authorities within the time and under the conditions required by applicable law.
Incident notices may include the nature of the incident; categories of information affected; approximate number of affected individuals or records; likely consequences; containment and remediation measures; steps individuals should take; and contact information for further assistance.
18Third-Party Services and Links
The Services may contain links to, or integrations with, third-party websites and services. This Privacy Policy does not govern processing performed independently by those third parties. Users should review the third party's privacy notice before providing information. Where a third party acts as our processor, its processing will remain subject to the applicable contractual and legal requirements.
19Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to the Services; new legal requirements; changes to service providers; new hosting regions; security developments; or changes to our data practices.
We will publish the updated version with a revised "Last Updated" date. For material changes, we will provide additional notice through the platform, by email, or through another appropriate channel.
Where a change requires consent, the change will not apply to the relevant processing until valid consent has been obtained. Continued use of the Services does not replace consent where applicable law requires consent.
20Contact Us
Privacy questions, complaints or requests may be submitted to:
[LEGAL COMPANY NAME], Inc.
Doing business as Dental Nexus
[REGISTERED OR BUSINESS ADDRESS]
Privacy email: [PRIVACY EMAIL]
Requests concerning Customer Case Data may be referred to the clinic, clinician, laboratory or other customer responsible for the relevant patient relationship.
Questions about this Privacy Policy?
Contact us through the early access form and our team will follow up directly.