Legal
Privacy Policy
For Clinics and Dental Practitioners — Last updated: May 14, 2026
This Privacy Policy describes how the Dental Patient Management System (the “Service”) collects, uses, stores, and protects information when used by dental clinics and practitioners. It is issued in compliance with Republic Act No. 10173 (Data Privacy Act of 2012) and its Implementing Rules and Regulations (IRR).
By subscribing to or using the Service, You acknowledge that You have read and understood this Policy and agree to its terms.
1. Interpretation and Definitions
- Company / We / Us / Our: Dental Patient Management System, acting as Personal Information Controller for Account Data and Personal Information Processor for Client Data.
- Subscriber / You / Clinic: the licensed dental practitioner, clinic owner, or entity that has subscribed to and uses the Service.
- Account Data: personal information about You as a Subscriber (e.g., clinic name, business address, contact details, billing information, PRC license number).
- Client Data / Patient Data: all personal information and sensitive personal information relating to your patients that You upload or generate within the Service — including medical and dental histories, dental charts, treatment records, radiographs (X-rays), clinical photographs, and payment records.
- Sensitive Personal Information (SPI): as defined under Section 3(l) of RA 10173 — includes health and medical records, which constitute the primary content of Patient Data in this Service.
- NPC: the National Privacy Commission, the government agency responsible for administering and implementing RA 10173 in the Philippines.
2. Our Role: Data Controller vs. Data Processor
It is important to distinguish our distinct roles under RA 10173 depending on the type of data involved:
- Account Data — We are the Personal Information Controller (PIC):We determine the purpose and means of processing your clinic’s registration, contact, and billing information in order to operate and manage your subscription.
- Client Data (Patient Records) — We are the Personal Information Processor (PIP): You (the Clinic) are the PIC for all patient data. We process it solely on your behalf and only to the extent required to deliver the Service. We do not own, inspect, sell, or use Patient Data for our own purposes.
This distinction is consistent with NPC Advisory Opinion and the controller-processor framework under RA 10173 and its IRR.
3. Types of Data We Handle
A. Account Data (We are the Controller)
To create and manage your clinic account, We collect:
- Clinic name, business name, and registered address
- Owner / Administrator name and contact details (email, mobile number)
- PRC License Number (for professional verification)
- Business TIN / Tax Identification Number (optional, for billing)
- Payment and billing information
B. Client Data / Patient Data (You are the Controller)
In the course of using the Service, You upload and generate Sensitive Personal Information of your patients, which may include:
- Full name, date of birth, contact details, and address
- Medical and dental history, allergies, and current medications
- Dental charts, treatment records, and clinical notes
- Dental radiographs (X-rays) and clinical photographs
- Payment records and billing history
- Signed consent forms and other clinical documents
Health and dental records constitute Sensitive Personal Information under Section 3(l) of RA 10173 and are subject to stricter processing requirements.
4. Lawful Basis for Processing
We process Account Data on the following lawful bases under RA 10173:
- Contract: processing is necessary to perform your subscription agreement with Us.
- Legal obligation: processing necessary to comply with applicable Philippine laws (e.g., tax, regulatory requirements).
- Legitimate interest: to improve and secure the Service, where such interest is not overridden by your rights.
As the PIC for Patient Data, You are responsible for establishing and documenting the lawful basis (typically patient consent) for processing patient health information consistent with Section 12 and Section 13 of RA 10173.
5. How We Use Information
We use Account Data to:
- Create and manage your clinic account and subscription.
- Process payments and issue billing receipts.
- Send technical notices, security alerts, and product updates.
- Provide customer support and respond to your inquiries.
- Comply with legal obligations.
We use Client Data (Patient Records) solely to:
- Provide and operate the Service features (e.g., displaying patient records, scheduling, dental charting).
- Perform automated backups and maintain data integrity and availability.
- Restore data in the event of a system failure or breach.
- We do not sell, rent, share, mine, or use Patient Data for advertising, analytics, AI training, or any purpose other than delivering the Service to You.
6. Data Subject Rights (Your Patients’ Rights)
As PIC, You are obligated to facilitate your patients’ exercise of their rights as data subjects under Chapter IV, Section 16 of RA 10173, which include:
- Right to be Informed: patients must be informed that their data is being collected and processed, and for what purpose.
- Right to Access: patients may request a copy of their personal data held by your clinic.
- Right to Correction / Rectification: patients may request correction of inaccurate or incomplete data.
- Right to Erasure or Blocking: patients may request deletion or blocking of data that is unlawfully processed, outdated, or no longer necessary, subject to any legal retention obligations.
- Right to Object: patients may object to processing of their personal data under certain circumstances.
- Right to Data Portability: patients may request their data in a structured, machine-readable format.
- Right to File a Complaint: patients may lodge a complaint directly with the National Privacy Commission (NPC) at www.privacy.gov.ph.
We will assist You in responding to verified data subject requests that require access to or deletion of data stored within the Service.
7. Data Retention
Account Data: Retained for the duration of your active subscription and for a period thereafter as required by applicable Philippine tax, accounting, and regulatory laws.
Client Data (Patient Records): Retained only for as long as You maintain an active subscription. Upon termination, You will have a 30-day grace period to export your Patient Data. After this period, We may permanently delete all Patient Data from Our servers. We strongly recommend exporting data before terminating.
Dental Record Retention: Note that PRC and Board of Dentistry guidelines generally recommend retaining patient dental records for a minimum of 10 years from the date of last treatment. You are responsible for maintaining offline or archival copies of records as required by professional regulations.
8. Sharing and Disclosure of Information
We do not sell or trade your information. We may share information only in the following limited circumstances:
- Service Providers (Subprocessors): Third-party vendors who provide infrastructure services (e.g., cloud hosting, file storage, email delivery, payment processing). These parties are contractually bound to process data only as necessary to provide services to Us, and may not use your data for their own purposes.
- Legal Requirements: Where required by Philippine law, valid court order, NPC directive, or other binding governmental process. We will, to the extent permitted by law, notify You before disclosing Your data pursuant to such a request.
- Business Transfer: In the event of a merger, acquisition, or sale of company assets, data may be transferred as part of that transaction. Subscribers will be notified in advance.
9. Data Security
We implement technical and organizational security measures appropriate to the sensitivity of the data we process, including:
- Encryption of data in transit (TLS/HTTPS) and at rest.
- Role-based access controls limiting data access to authorized personnel.
- Regular automated backups stored in geographically separate locations.
- Monitoring for unauthorized access or anomalous activity.
You are responsible for the security of your own login credentials and for ensuring that staff access to the Service is managed appropriately. We recommend enabling all available account security features and revoking access promptly when staff leave your clinic.
10. Data Breach Notification
In the event of a personal data breach involving data We process, We will notify You as the PIC without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with NPC Circular No. 2023-04. Our notification will include:
- A description of the nature and scope of the breach.
- The categories and approximate number of records and data subjects affected.
- The measures taken or planned to contain and remediate the breach.
As PIC, You are responsible for notifying affected patients and the NPC as required under RA 10173 and NPC Circular No. 2023-04.
11. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or applicable law. We will notify You by email or through a prominent in-app notice at least 14 days before material changes take effect. Your continued use of the Service after the effective date of the revised Policy constitutes acceptance.
12. Contact & Data Privacy Officer
For questions, data subject access requests, or privacy concerns:
For unresolved complaints or NPC guidance, contact the National Privacy Commission: www.privacy.gov.ph