We Protect Your Data
Privacy Policy
How DentalView collects, uses, and protects your data under (Data Privacy Act of 2012).
Last updated:
Introduction
DentalView (“we,” “us,” or “our”) is a dental clinic management platform designed for Philippine dental practices. We are committed to protecting your privacy and complying with (the Data Privacy Act of 2012) and the rules and regulations issued by the .
This Privacy Policy explains how we collect, use, store, and protect personal information when you use our platform. It applies to clinic owners, their staff, and the patients whose data is processed through DentalView.
Our designated can be reached at privacy@dentalview.ph.
What Data We Collect
We collect and process the following categories of personal data:
Clinic & Account Data
- Clinic name, address, and contact information
- Owner and staff names, email addresses, and roles
- Business Tax Identification Number (TIN)
- Subscription and billing preferences
Patient Data (Processed on Behalf of Clinics)
DentalView processes patient data as a data processor on behalf of your clinic (the data controller). This includes:
- Patient names, phone numbers, and email addresses
- Appointment history and scheduling data
- Treatment plans and clinical notes
- Consent records with timestamps and IP addresses
- Engagement scores and communication preferences
Technical & Usage Data
- IP addresses and browser/device information
- Page views and feature usage patterns
- Login timestamps and session metadata
- SMS delivery status and response data
DentalView does NOT store payment card details. compliance for card data is handled entirely by our payment partners.
How We Use Data
We use collected data for the following purposes:
- Providing and maintaining the DentalView platform
- Processing subscription payments and generating invoices
- Sending appointment reminders via SMS on behalf of clinics
- Generating analytics, reports, and Smart Insights for clinic owners
- Improving platform performance, reliability, and features
- Ensuring security, preventing fraud, and detecting anomalies
- Complying with legal obligations under Philippine law
- Communicating service updates and important notices
We do not sell personal data to third parties. We do not use patient data for marketing purposes. Patient data is only processed as instructed by the clinic (data controller).
Data Retention
We retain data for the minimum period necessary to fulfill its purpose, comply with legal obligations, and meet requirements:
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Clinic & Patient Data | Active + 90 days | Operational necessity |
| Audit Logs | 7 years | BIR requirements |
| Financial Records | 10 years | BIR requirements |
| SMS Logs | 2 years | Service quality |
| Consent Records | Relationship + 5 years | RA 10173 compliance |
| Security Logs | 1 year | Threat detection |
| Anonymized Analytics | Indefinite | Product improvement |
Clinic & Patient Data
Active + 90 days
Operational necessity
Audit Logs
7 years
BIR requirements
Financial Records
10 years
BIR requirements
SMS Logs
2 years
Service quality
Consent Records
Relationship + 5 years
RA 10173 compliance
Security Logs
1 year
Threat detection
Anonymized Analytics
Indefinite
Product improvement
After the retention period, data is securely deleted or irreversibly anonymized.
Your Rights
Under Section 16 of , you have the following data subject rights:
Right to Access
You may request a copy of all personal data we hold about you. We will provide this within 30 days of receiving a valid .
Right to Rectification
You may request correction of any inaccurate or incomplete personal data we hold about you.
Right to Erasure
You may request deletion of your personal data, subject to legal retention requirements (e.g., mandated records).
Right to Object
You may object to the processing of your personal data for specific purposes, including direct marketing.
Right to Restrict Processing
You may request that we limit the processing of your personal data while a dispute or verification is being resolved.
Right to Data Portability
You may request your personal data in a structured, machine-readable format (JSON or CSV) to transfer to another service provider.
Right to File a Complaint
If you believe your data privacy rights have been violated, you may file a complaint with the at complaints@privacy.gov.ph.
To exercise any of these rights, contact our at privacy@dentalview.ph. We will respond within 30 days.
Security Measures
We implement comprehensive security measures to protect your data:
Encryption
- All data in transit is encrypted with TLS 1.3
- All data at rest is encrypted with AES-256
- Database connections use encrypted channels
ensures your data is protected during transmission, while protects stored data.
Access Controls
- Role-Based Access Control (RBAC) limits data access by user role
- Row-Level Security (RLS) ensures clinics only see their own data
- Multi-factor authentication available for all accounts
- Automated session timeouts after periods of inactivity
is enforced at the database level, providing an additional layer of tenant isolation.
Monitoring & Auditing
- Comprehensive audit logging of all data access and modifications
- Automated threat detection and anomaly monitoring
- Regular security assessments and penetration testing
- Incident response procedures with 24-hour notification commitment
Third-Party Providers
We work with trusted third-party service providers who process data on our behalf. Each provider is contractually required to protect your data:
| Provider | Purpose | Data Shared | Standard |
|---|---|---|---|
| Railway | Application, database, and authentication hosting | All clinic and patient data, request logs, and IP addresses | |
| PayMongo | Payment processing | Billing information (not card details) | |
| Whop | Payment processing | Billing information (not card details) | |
| Synermaxx | SMS delivery | Phone numbers and message content | Philippine SMS gateway provider |
| Resend | Transactional email delivery | Email addresses and message content |
Railway
Application, database, and authentication hosting
Data: All clinic and patient data, request logs, and IP addresses
SOC 2 Type II
PayMongo
Payment processing
Data: Billing information (not card details)
PCI DSS Level 1
Whop
Payment processing
Data: Billing information (not card details)
PCI DSS Level 1
Synermaxx
SMS delivery
Data: Phone numbers and message content
Philippine SMS gateway provider
Resend
Transactional email delivery
Data: Email addresses and message content
SOC 2 Type II
We do not transfer personal data outside the Philippines unless necessary for service delivery, and any such transfer complies with guidelines on cross-border data transfer.
Contact Us
If you have questions about this Privacy Policy, want to exercise your data subject rights, or need to report a privacy concern:
Data Protection Officer
DentalView Privacy Team
Response Time
Within 30 days for formal requests ()
For complaints about data privacy violations, you may also contact the directly at complaints@privacy.gov.ph.