Privacy Policy
At Dantasutra, we treat clinical data with highest priority. This policy outlines how dental clinics, dental practitioners, and patient records are safeguarded across our AI practice management software and Meta WhatsApp Cloud API communications.
Zero Sale of Data
Patient health histories, contact numbers, and clinical charts are strictly protected. We never sell, lease, or monetize medical data.
Meta WhatsApp Verified
Outbound patient messages adhere to official Meta WhatsApp Cloud API standards with explicit patient opt-ins and instant STOP opt-out rights.
Tenant Isolated Security
Every clinic’s database is cryptographically segregated across Dedicated and Shared cloud modes with end-to-end TLS 1.3 and AES-256 encryption.
1. Our Role: Data Fiduciary vs. Data Processor
To ensure transparency under India's Digital Personal Data Protection Act, 2023 (DPDPA) and global data privacy standards, our legal relationship depends on the nature of information processed:
For Dental Clinics (Customers)
When practitioners register, configure clinic profiles, or subscribe to billing plans, Dantasutra acts as a Data Fiduciary regarding the clinic owner's administrative account details, billing contact, and staff credentials.
For Patients & Clinical Records
The respective Dental Clinic is the Data Fiduciary that gathers clinical consent and oversees patient care. Dantasutra acts strictly as a Data Processor providing cloud EMR charting, automated communications, and AI practice tools on the clinic's behalf.
2. Information We Collect and Process
We collect only the minimum necessary information required to facilitate dental clinic operations, appointment workflows, and digital compliance:
Dentist name, medical registration/council credentials, phone numbers, clinic physical address, GSTIN (for GST-compliant billing), and user login credentials.
Patient name, contact number, age, gender, medical/dental history, dental charts, odontogram findings, treatment plans, periodontal statuses, X-ray/intraoral images, doctor prescriptions, and itemized billing receipts recorded by clinic doctors.
Voice inputs processed during hands-free dental charting or AI receptionist inbound patient calls, converted to structured clinical notes via private transcription APIs.
Browser type, device metadata, IP address, and timestamped audit logs of record modifications to ensure clinical liability protection and prevent unauthorized tampering.
3. How Collected Data Is Used
Information managed through Dantasutra is used strictly for legitimate healthcare and operational service delivery:
- Facilitating clinical charting, electronic dental prescriptions, and dental lab order tracking.
- Generating GST-compliant invoices and digital payment receipts for dental treatments.
- Automating 24-hour and 2-hour appointment reminder notifications via WhatsApp and SMS to reduce patient no-shows.
- Enabling multi-tenant clinic portal administration across dedicated and shared deployment modes.
- Processing patient inquiries through 24/7 AI voice receptionist agents configured for the clinic.
4. WhatsApp Business & Meta Cloud API Messaging Policy
Dantasutra interfaces directly with the official Meta WhatsApp Cloud API to facilitate transparent clinical communication. We strictly uphold Meta's Business Messaging Terms:
consultation_v1, appointment_reminder_24h, and payment_receipt_v1).5. AI Voice Receptionist & Clinical Dictation
Dantasutra incorporates artificial intelligence tools (voice-to-chart dictation, receptionist call handling, clinical note formatting) under strict boundaries:
- Voice dictation audio streams are processed in transient memory to generate clinical text charts and are not retained for general public AI model training.
- Dentists maintain full manual override: every AI-assisted chart, prescription, or clinical note must be reviewed and confirmed by the attending dentist before finalization.
- Patient privacy is preserved through anonymized API pipelines.
6. Authorized Sub-Processors & Service Providers
We collaborate with enterprise-grade infrastructure providers that comply with SOC2, ISO 27001, and HIPAA-level security standards:
| Sub-Processor | Service Purpose | Data Location | Security Compliance |
|---|---|---|---|
| Google Cloud Platform (GCP) / Firebase | Encrypted Cloud DB, Authentication & Hosting | India / Global Multi-region | ISO 27001, SOC 1/2/3, AES-256 |
| Meta Platforms, Inc. (WhatsApp Cloud API) | Patient appointment reminders & WhatsApp notifications | Global Infrastructure | Meta Business Privacy Standards |
| Razorpay / Stripe | Payment processing & digital clinic consultation receipts | India / Global | PCI-DSS Level 1 Compliant |
| Fast2SMS | DLT-approved transactional OTP & SMS delivery | India | TRAI DLT Registered |
7. Data Security & Multi-Tenant Isolation
We implement comprehensive technical and organizational measures (TOMs) to safeguard patient data:
All data in transit is protected using modern TLS 1.3 cryptography. All databases, patient EMR documents, and digital scans are encrypted at rest using AES-256.
Every clinic operates in a verified security scope. Queries are bounded to the clinic's verified tenant ID, preventing cross-tenant leakage between clinics.
8. Rights of Data Principals (Patients & Clinic Users)
In accordance with the Digital Personal Data Protection Act, 2023, individuals whose data is processed have the right to:
- Right to Access: Request a summary of personal data being processed by their clinic.
- Right to Correction & Updating: Request correction of inaccurate or outdated medical and personal records.
- Right to Erasure (Data Deletion): Request deletion of personal information, subject to statutory medical record-keeping laws mandated by the Dental Council of India and State Health Authorities.
- Right of Grievance Redressal: Submit a complaint regarding data handling directly to our designated Grievance Officer.
User Data Deletion Request & Callback Mechanism
In compliance with Meta Platform Policies and Indian DPDP Regulations, Dantasutra provides an automated data deletion request callback endpoint as well as self-service instructions for patients and clinics to request full erasure of their stored data.
View Data Deletion Instructions & Check Deletion Status →9. Grievance Redressal & Contact Officer
In compliance with the Information Technology Act, 2000, the rules made thereunder, and the DPDPA 2023, queries or grievances regarding data privacy may be addressed to:
Dantasutra Technologies
Plot 14, D.C.C.B Colony,
Srikakulam, Andhra Pradesh 532001, India.
10. Modifications to This Privacy Policy
We reserve the right to modify this Privacy Policy to accommodate changes in clinical workflows, technological updates, Meta platform terms, or new regulatory mandates. Significant modifications will be highlighted through in-app dashboard notices or website updates.