This Privacy Policy explains how DentalOnePlus ("we", "us") collects, uses and protects information when you use the DentalOnePlus website and software (the "Service"). We follow the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 of India.
1. Two kinds of information
- Account information about clinics, colleges and their users — for example clinic name, owner and staff names, email, phone number, GSTIN, address and billing details.
- Clinical information that a clinic or college enters about its own patients — for example demographics, medical and dental history, case sheets, X-rays, photos, prescriptions, consents and invoices.
For clinical information, the clinic or college is the Data Fiduciary — it decides why and how patient data is used. We act only as a Data Processor on the clinic's instructions, to provide the Service. We never use patient data for our own marketing, and we never sell it.
2. What we collect
- Details you give us when you sign up, buy a plan, fill a form on our website or contact support.
- Records your team creates inside the Service.
- Payment confirmations from our payment partner (Razorpay). We do not receive or store your full card, UPI PIN or net-banking credentials.
- Technical information such as IP address, browser type, device, pages used and error logs, to keep the Service secure and working.
- Small browser storage items (for example your login session and theme choice) that the Service needs to work.
3. How we use information
- To provide, maintain and improve the Service, including support and training.
- To process payments, issue GST invoices and manage your subscription.
- To send service messages such as trial reminders, renewal notices, security alerts and replies to your enquiries.
- To keep the Service secure, prevent misuse and meet legal obligations.
4. Who we share information with
We share information only with trusted service providers who help us run the Service, under confidentiality obligations, and only as needed:
- Cloud hosting and backup providers that store the Service's data.
- Razorpay for processing payments.
- Meta (WhatsApp Cloud API) and email providers — only when your clinic connects them and chooses to send messages to patients.
- An AI service provider — only when a user chooses to use the AI assistant; the text of the request and the minimum context needed to answer it are sent to generate a reply.
- YouTube — only when you choose to play a video on our website.
- Government or law-enforcement authorities when required by law.
5. How we protect information
- Each clinic's data is kept logically separate and is visible only to that clinic's authorised users.
- Access inside a clinic is controlled by roles and permissions set by the clinic owner.
- Important actions (such as viewing, editing, approving and exporting records) are logged.
- Databases are backed up daily and uploaded files regularly.
- Connections should always use encrypted HTTPS.
No system is perfectly secure, but we work hard to protect your data and will inform affected clinics without undue delay if a breach affects them, as required by law.
6. How long we keep information
We keep clinic data for as long as the account exists. If a subscription ends, the account becomes read-only and data is kept so that the clinic can renew or export it. We delete a clinic's data on its written request, except where we must keep certain records (such as tax invoices) by law. Backup copies are overwritten on their normal cycle.
7. Your rights
Under the DPDP Act you may ask to access, correct, update or erase your personal data, withdraw consent, and nominate another person to exercise your rights. Clinic users can make these requests to us. Patients should contact their clinic or college first, because the clinic controls their records; we will help the clinic respond.
8. Children
Clinics may record information about patients under 18. The clinic is responsible for obtaining verifiable consent from a parent or lawful guardian where required.
9. Changes to this policy
We may update this policy from time to time. The latest version will always be on this page with its effective date, and we will notify account owners of important changes.
10. Grievance Officer & contact
For any privacy question or complaint, write to the email address shown on our Contact page. We aim to respond within 7 working days and resolve grievances within 30 days.

