Privacy Policy
Effective Date: 26 July 2026 · Last Updated: 26 July 2026 · Version 2.0
Scope & compliance: ORALZY is operated from India and is currently offered to dental clinics and laboratories in India. This Policy is written to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 read with the SPDI Rules, 2011. Sections 6 and 9 describe the additional commitments that apply if and when we serve customers in the European Union, the United Kingdom or the United States.
This Privacy Policy ("Policy") describes how ORALZY ("we", "our", "us", "Service Provider") collects, uses, stores, transfers, discloses and protects information of dental clinics and laboratories ("Customer", "Clinic") and their authorised users, staff and patients ("Data Principal", "Data Subject", "you", "your") who interact with our practice-management software ("Service") via oralzy.com, our Android, Windows and web applications, and the SMS and WhatsApp channels the Service can send through.
By creating an account, subscribing to, or using the Service in any form, you acknowledge that you have read, understood and agreed to this Policy. If you disagree with any part of it, please discontinue use of the Service.
Who is responsible for patient data: The clinic is the Data Fiduciary (Controller) for its patients' records. ORALZY is the Data Processor — we process patient data only on the clinic's instructions. If you are a patient, please raise access, correction or deletion requests with your treating clinic first; we will support the clinic in fulfilling them.
1. Definitions
- Personal Data / Personal Information: Any information relating to an identified or identifiable natural person — DPDP Act §2(t); GDPR Article 4(1).
- Sensitive Personal Data: Includes health, biometric and genetic data. Classified as "Sensitive Personal Data or Information (SPDI)" under the Indian SPDI Rules, 2011 and as "Special Category Data" under GDPR Article 9.
- Protected Health Information (PHI): Individually identifiable health information as defined under HIPAA 45 CFR §160.103 — relevant only to the limited circumstances described in Section 6.
- Data Fiduciary / Data Controller: The entity that determines the purpose and means of processing. The clinic is the Data Fiduciary for its patients' data.
- Data Processor: The entity that processes data on behalf of the Data Fiduciary. ORALZY is a Data Processor in respect of patient data, and a Data Fiduciary only in respect of clinic account and billing data.
- Data Principal / Data Subject: The natural person whose personal data is processed.
2. Information We Collect
2.1 Information you provide
- Clinic account data: Clinic name, registered address, phone, email, owner/dentist name, professional registration numbers (Dental Council of India, state councils), tax identifiers (GSTIN, PAN).
- Staff and user data: Name, email, phone, role and designation, login credentials, employee code, and — where the clinic enables the relevant feature — attendance PIN, face-recognition template for attendance verification, and device fingerprint used to recognise a trusted login device.
- Patient records (entered by the clinic): Name, age, date of birth, gender, contact details, address, UHID, medical and dental history, allergies, treatment plans, prescriptions, intra-oral photographs, X-ray and scan images, consent forms, billing records, insurance and government-scheme details, appointment data.
- Patient face template (optional, opt-out): Where the clinic offers face check-in, a mathematical face template is derived from the patient's photograph and stored to identify them at the front desk. This is biometric data. It is a set of numbers, not an image, and cannot be turned back into a photograph. It is encrypted at rest at the application layer, is never used for surveillance, tracking or attendance, and is never shared outside the treating clinic. The patient may refuse. Consent point 4.10 on the registration form asks this question directly; answering No means no template is ever created, and a patient may also withdraw later — which deletes any template already held. Refusing costs the patient nothing: reception looks them up by name or phone exactly as before, and their treatment is unaffected. The template is also deleted when the patient's record is erased. Patients registered before this question was added to the form are covered by the same right — tell the clinic and it is removed.
- Patient portal (OTP login): Phone number, a one-time-password hash, session token and — if the patient installs the app — a push-notification token.
- Payment information: Subscription plan, billing address, tax identifiers. Card and bank credentials are handled entirely by PCI-DSS certified payment gateways and never reach our servers.
- Communication data: Support messages, SMS and WhatsApp messages routed through the Service on the clinic's behalf, feedback and feature requests.
2.2 Information collected automatically
- Device and usage data: IP address, device type, operating system, app version, log timestamps, feature-usage patterns.
- Security telemetry: Login attempts, audit logs of record access and modification, and error reports used to diagnose crashes.
- Cookies and local storage: Session management and user preferences — see Section 13.
2.3 Information from third parties
- WhatsApp Business Platform (Meta): Patient phone numbers, message content and delivery status, where the clinic has enabled WhatsApp.
- SMS providers: Delivery receipts for DLT-registered transactional messages.
- Payment gateways: Transaction status, reference numbers and settlement details.
3. Legal Basis for Processing
We process personal data only where one or more of the following applies:
| Basis | Framework reference | When applied |
| Consent | DPDP §6; GDPR Art 6(1)(a), Art 9(2)(a) | Marketing communications, optional features, and processing of sensitive data where consent is the applicable basis |
| Performance of contract | DPDP §7(a); GDPR Art 6(1)(b) | Providing the subscribed Service to the clinic |
| Legal obligation | IT Act §43A; GDPR Art 6(1)(c) | Tax and accounting records, breach notification, lawful requests |
| Vital interests | GDPR Art 6(1)(d), Art 9(2)(c) | Medical emergencies |
| Legitimate use / legitimate interest | DPDP §7; GDPR Art 6(1)(f) | Service security, fraud prevention, debugging |
| Provision of health services | DPDP §7(b); GDPR Art 9(2)(h) | Patient record management carried out on the clinic's instructions |
4. How We Use Information
- To provide, maintain and improve the Service — appointments, clinical records, imaging, billing, inventory, payroll and reporting.
- To send appointment reminders, treatment follow-ups, payment reminders and clinic announcements by SMS, WhatsApp, email or push, on behalf of the clinic, to its own patients.
- To provide AI-assisted features (Section 5).
- To process subscription payments and issue tax-compliant invoices.
- To prevent fraud and abuse, secure accounts and diagnose crashes.
- To produce aggregated, de-identified analytics for product improvement.
- To comply with applicable law and respond to lawful requests from authorities.
We do not sell personal data. We do not use patient data for behavioural advertising, for marketing our own products to patients, or to train foundation AI models.
5. AI Features & Automated Processing
Important: ORALZY's AI features — treatment suggestions, X-ray and intra-oral image analysis, voice-to-notes transcription, communication drafts and similar — are decision-support tools, not medical advice or diagnosis. Every AI output must be reviewed and validated by a qualified dental practitioner before any clinical action is taken. We do not guarantee the accuracy of AI outputs and are not liable for clinical decisions made using them.
AI sub-processors. Cloud AI features use Google's Gemini API; voice transcription uses Sarvam AI. Under these providers' commercial API terms, data sent for inference is not used to train their models. Where a feature can run locally on our own infrastructure, we prefer that path and only fall back to a cloud model when necessary.
Minimisation. Prompts sent to cloud AI providers are constructed to carry the clinical detail needed for the task and to avoid direct patient identifiers wherever the feature allows it.
No solely-automated decisions. The Service does not make solely automated decisions producing legal or similarly significant effects on any individual. All AI-assisted clinical recommendations require practitioner review. (Corresponds to GDPR Article 22 where applicable.)
6. Customers Outside India (GDPR / HIPAA)
The Service is presently offered to clinics and laboratories operating in India, and all customer data is stored in the Mumbai region (Section 8).
European Union / United Kingdom. If we onboard a Customer established in the EU or UK, we will enter into a GDPR Article 28 data-processing agreement with that Customer, and any transfer of personal data out of the EEA or UK will be governed by the European Commission's Standard Contractual Clauses (Module Two: Controller-to-Processor) together with the UK International Data Transfer Addendum where applicable.
United States. ORALZY does not currently process the Protected Health Information of US persons and does not hold itself out as HIPAA-compliant today. Before processing any PHI for a US Covered Entity we will (a) execute a Business Associate Agreement (BAA) with that Customer, (b) move the account onto a HIPAA-eligible deployment of our infrastructure providers, and (c) put downstream BAAs in place with every sub-processor that would handle PHI. Until all three are complete, US Covered Entities should not enter PHI into the Service.
7. Data Sharing, Sub-Processors & Disclosure
We do not sell personal data. We share information only as set out below.
7.1 Sub-processors
| Sub-processor | Purpose | Region | When it applies |
| MongoDB Atlas | Primary database — all clinic and patient records | Mumbai (ap-south-1) | Always |
| Amazon Web Services (Lightsail) | Application runtime | Mumbai (ap-south-1) | Always |
| Amazon Web Services (S3) | Document, photograph and imaging storage | Mumbai (ap-south-1) | Always |
| Google (Gemini API) | AI inference — clinical assistant, scribe, image analysis | Multi-region | When a cloud AI feature is used |
| Sarvam AI | Voice transcription (Hindi / Hinglish / English) | India | When voice dictation is used |
| Meta (WhatsApp Business Platform) | Patient messaging | Multi-region | When the clinic enables WhatsApp |
| 2Factor.in | OTP and transactional SMS (DLT-registered) | India | Login OTP and patient SMS |
| VilPower | DLT template registration and SMS routing | India | Patient SMS |
| Razorpay / Cashfree | Subscription and patient payment processing | India | When online payments are enabled |
| Google Firebase Cloud Messaging / Expo | Mobile push notifications | Multi-region | When the mobile app is installed |
| Google Drive / Microsoft OneDrive | Clinic-controlled backup copies | Per the clinic's own account | Only if the clinic connects its own account |
We maintain a current sub-processor list at /subprocessors.html and will notify Customers of material changes at least 30 days before they take effect, giving an opportunity to object.
7.2 Other disclosures
- Legal compliance: Where required by a valid legal order or court direction, or to protect rights, safety or property.
- Business transfer: In a merger, acquisition or asset sale, with prior notice to Customers.
- With your consent: For any other disclosure not covered above.
8. Where Data Lives, Isolation & Security
8.1 Location
Clinic and patient records are stored in MongoDB Atlas clusters in the Mumbai (ap-south-1) region. The application runs on AWS Lightsail in the same region, and documents, photographs and imaging are stored in AWS S3 in the same region. This keeps primary storage within India, consistent with DPDP Act localisation expectations.
8.2 Tenant isolation
Every clinic is a separate tenant. Records are scoped to their tenant at the database layer, so a clinic's staff can only ever see that clinic's patients. ORALZY engineers can access raw customer data only for a documented support ticket or a security incident, and such access is logged.
8.3 Technical measures
- Encryption: TLS 1.2+ in transit; encryption at rest for the database and object storage. Sensitive fields such as biometric templates are additionally encrypted at the application layer.
- Credentials: Passwords, OTPs and action PINs are stored only as bcrypt hashes — never in plain text.
- Access control: Role-based permissions with least privilege, optional per-user TOTP two-factor authentication for staff, new-device verification, and a per-action PIN gate for sensitive operations.
- Audit logging: Record access and modification is written to a tamper-evident, hash-chained audit log.
- Backups: Nightly encrypted backups retained for 30 days, with periodic restore verification.
- Vulnerability management: Automated dependency scanning, secret-scanning on every commit, and a responsible-disclosure channel at [email protected].
Our infrastructure providers (AWS and MongoDB Atlas) maintain their own SOC 2 Type II and ISO 27001 certifications for the platforms they operate. These are their certifications, not ORALZY's.
Despite reasonable safeguards, no system is absolutely secure. We will notify affected parties of any breach within the timelines in Section 14.
9. International Data Transfers
Primary storage is in India. Some sub-processors listed in Section 7.1 — notably the cloud AI, WhatsApp and push-notification providers — operate multi-region infrastructure, so data sent to those specific services may be processed outside India.
- From India: Transfers are carried out in accordance with §16 of the DPDP Act, 2023 and any restrictions notified by the Central Government.
- From the EU/UK (if applicable in future — see Section 6): Standard Contractual Clauses and the UK Addendum.
Customers may request a copy of the relevant transfer mechanism by writing to [email protected].
10. Data Retention
- While the subscription is active: Data is retained for as long as the account is active.
- After cancellation: Customer data is retained for 90 days so the account can be restored, then permanently deleted — except where law requires longer retention (for example, financial records for 7 years).
- Patient clinical records: Retained for the period mandated by the applicable state dental council — 10 years from the last visit by default — or as otherwise instructed by the clinic as Data Fiduciary.
- Face templates (staff and patients): Kept only while the consent that created them stands. Withdrawal of consent, deletion of the underlying photograph, erasure of the person's record, or removal of the staff member deletes the template.
- Audit logs: 2 years.
- Backups: 30 days, after which they expire automatically.
- Patient portal session tokens: 24 hours.
- Chairside voice recordings: Audio captured by the chairside scribe is stored so the dentist can re-check a transcript, then automatically deleted after the clinic's chosen retention window — 30 days by default, 90 days maximum. The resulting transcript and clinical notes are retained with the patient's record.
11. Your Rights
Subject to applicable law and verification of your identity, you have the following rights.
11.1 Rights available to everyone
- Access: Confirmation of whether we process your data, and a copy of it.
- Correction: Have inaccurate or incomplete data corrected.
- Erasure: Request deletion, subject to legal and clinical retention obligations.
- Withdraw consent: Turn off SMS, WhatsApp or push communications at any time, without affecting the lawfulness of prior processing.
- Grievance redressal: Complain to our Grievance Officer (Section 15), and to the Data Protection Board of India.
11.2 DPDP Act rights (§§11–14)
- Right to access a summary of personal data being processed and the sub-processors it has been shared with.
- Right to correction, completion, updating and erasure.
- Right to nominate another individual to exercise your rights in the event of death or incapacity.
- Right to grievance redressal within the prescribed timeline.
11.3 GDPR rights (Articles 15–22) — where applicable
- Restriction of processing; data portability in a structured, machine-readable format; objection to processing based on legitimate interests; and not being subject to solely automated decision-making with significant effects.
11.4 How to exercise your rights
If you are a patient: contact your treating clinic first — the clinic is the Data Fiduciary for your records and can act on your request directly inside the Service. We will assist the clinic where needed.
If you are a clinic, staff member or account holder: email [email protected] from the address associated with your account. We respond within 30 days.
12. Children's Data
Patient records may include minors, entered by the treating clinic, usually under a parent's or guardian's own record. Under DPDP §9, verifiable consent of a parent or lawful guardian is required for a Data Principal under 18 in India; the clinic, as Data Fiduciary, is responsible for obtaining it. Where applicable in other jurisdictions the relevant thresholds are GDPR Article 8 (under 16 in the EU) and COPPA (under 13 in the US).
We do not knowingly collect data directly from children, we do not market to children, and we do not use children's data for tracking or advertising.
13. Cookies & Tracking Technologies
We use the following categories of cookies and local storage:
- Strictly necessary: Authentication, session management, CSRF protection. These cannot be disabled.
- Functional: Language, theme and user preferences. Optional.
- Analytics: Aggregated, de-identified usage patterns. Optional.
We do not use third-party advertising or behavioural-tracking cookies. Where a cookie consent banner is required for visitors in the EU/UK, non-essential categories are opt-in. See also /cookie.html.
14. Breach Notification
In the event of a personal data breach:
- DPDP Act: We will notify the Data Protection Board of India and the affected Data Principals as prescribed under §8(6).
- CERT-In: Reportable cyber security incidents will be reported to CERT-In within 6 hours of becoming aware, consistent with the CERT-In Directions of 28 April 2022.
- Affected clinics: We will notify the affected Customer without undue delay so it can meet its own obligations to its patients.
- GDPR (Art 33–34), where applicable: Supervisory authority within 72 hours; affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
15. Grievance Officer & Data Protection Contacts
Full statutory Grievance Officer details are also published at /grievance.html.
16. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated by email and in-app notice at least 30 days before they take effect. The "Last Updated" date at the top reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance.
17. Governing Law & Jurisdiction
This Policy is governed by the laws of India. The courts at the place of registration of the Service operator shall have exclusive jurisdiction, without prejudice to mandatory consumer-protection rights in your jurisdiction of residence.
Data Principals in India retain the right to complain to the Data Protection Board of India. Where Section 6 applies, data subjects in the EU/UK retain the right to lodge a complaint with their local supervisory authority.