Skip to content
DentaDeck

Effective August 18, 2026

Privacy Policy

This Policy explains what data DentaDeck processes, why it is needed, and the rights available to clinics, their staff, and patients.

1. Who is responsible for data

For patient and staff data, the clinic is the data controller and determines the purposes of processing. DentaDeck acts as processor and follows the clinic's documented instructions.

The DentaDeck operator is LIMITED LIABILITY COMPANY "Smart Grow Technologies" (EDRPOU 46273199). For registration, service billing, security, and support data, the operator may determine the processing required.

2. Data we process

DentaDeck processes data submitted by a clinic, its staff, or services it connects while using the system.

  • account and clinic data: name, work contact details, role, settings, and membership information;
  • patient data: name, contact details, date of birth, address, insurance, and other identifying information entered by the clinic;
  • health data: medical history, dental charts, treatment plans and records, prescriptions, notes, photos, videos, documents, and DICOM studies;
  • operational data: appointments, reminders, shifts, rooms, comments, and service messages;
  • financial data: amounts, discounts, balances, payment method and status, cash and fiscal records, and provider references; DentaDeck does not require a full payment-card number;
  • technical data: IP address, browser or app, sign-in time, audit trail, errors, and information needed to protect the service.

3. How we use data

Processing is based on performing the clinic agreement, legitimate interests in operating a secure service, legal obligations, or consent where the law requires it. The clinic is responsible for a valid basis to enter patient data.

  • provide scheduling, patient charts, medical records, finances, files, migration, and other ordered features;
  • authenticate users, manage access rights, and protect the clinic;
  • send service communications and provide support;
  • process service billing, keep business records, and meet legal obligations;
  • detect errors and abuse and improve reliability without advertising profiles.

4. Sharing and international transfers

DentaDeck does not sell personal data, use it for advertising tracking, or disclose it to advertising networks. Data is disclosed only to operate the service, follow the clinic's instructions, or meet a lawful requirement.

Data may be processed in another country depending on infrastructure location or the integration selected. Contractual and other legally required safeguards are used where applicable.

  • hosting, storage, email, and technical infrastructure providers;
  • services connected by the clinic within the selected integration;
  • professional advisers or public authorities where required by law or needed to protect rights;
  • a successor in a business reorganisation, subject to appropriate continued protection.

5. Integrations and AI features

A clinic may connect external services. Their own terms and policies apply to the data they process.

  • Cliniccards migration transfers data only on the instructions of a clinic entitled to move that data.
  • Telegram, Checkbox, and Monobank receive only the data needed for the feature enabled by the clinic.
  • AI features are off by default. The clinic owner separately chooses a provider; DentaDeck removes the patient's known name and contact details from structured data before transfer, but the clinic must review free text for unnecessary personal data.

6. Retention and security

Data is retained while the clinic account is active and, after termination, for the period needed to return or delete data, cycle backups, resolve disputes, and comply with law. A service agreement and the clinic's policy may set a more specific period.

No system can guarantee absolute security. If an incident affects clinic data, DentaDeck will notify the clinic as required by the agreement and applicable law.

  • logical separation of clinic data;
  • role-based staff access and audit logging of important actions;
  • encrypted connections while data is transmitted;
  • restricted infrastructure access and backups.

7. Your rights

Patients normally exercise their rights through the clinic that holds their record. Account users may contact DentaDeck about their own data. We may verify identity and authority before fulfilling a request.

  • receive information and a copy of your data;
  • correct inaccurate data;
  • request deletion or restriction, or object to processing, where permitted by law;
  • receive a portable copy where data portability applies;
  • withdraw consent without affecting prior lawful processing;
  • complain to the competent data-protection authority.

8. Children's data

DentaDeck is intended for professional clinic operations, not independent use by children. A clinic may keep records about minor patients only with an appropriate legal basis and a legal representative's consent where required.

9. How to contact us

Clinic staff may contact the support channel identified in the account, order, or service agreement, or email [email protected]. A patient should first contact their clinic; DentaDeck will assist the clinic with a verified request.

Identify the clinic, your relationship to it, and the request. Do not send medical documents over an unsecured channel unless necessary.