DPDPA 2023 & Meta WhatsApp API Compliant

Privacy Policy

At Dantasutra, we treat clinical data with highest priority. This policy outlines how dental clinics, dental practitioners, and patient records are safeguarded across our AI practice management software and Meta WhatsApp Cloud API communications.

Effective Date: September 8, 2026Applicable Domain: https://dantasutra.inEntity: Dantasutra Technologies

Zero Sale of Data

Patient health histories, contact numbers, and clinical charts are strictly protected. We never sell, lease, or monetize medical data.

Meta WhatsApp Verified

Outbound patient messages adhere to official Meta WhatsApp Cloud API standards with explicit patient opt-ins and instant STOP opt-out rights.

Tenant Isolated Security

Every clinic’s database is cryptographically segregated across Dedicated and Shared cloud modes with end-to-end TLS 1.3 and AES-256 encryption.

1. Our Role: Data Fiduciary vs. Data Processor

To ensure transparency under India's Digital Personal Data Protection Act, 2023 (DPDPA) and global data privacy standards, our legal relationship depends on the nature of information processed:

For Dental Clinics (Customers)

When practitioners register, configure clinic profiles, or subscribe to billing plans, Dantasutra acts as a Data Fiduciary regarding the clinic owner's administrative account details, billing contact, and staff credentials.

For Patients & Clinical Records

The respective Dental Clinic is the Data Fiduciary that gathers clinical consent and oversees patient care. Dantasutra acts strictly as a Data Processor providing cloud EMR charting, automated communications, and AI practice tools on the clinic's behalf.

2. Information We Collect and Process

We collect only the minimum necessary information required to facilitate dental clinic operations, appointment workflows, and digital compliance:

A. Clinic Administrative Information

Dentist name, medical registration/council credentials, phone numbers, clinic physical address, GSTIN (for GST-compliant billing), and user login credentials.

B. Patient Health Records (EMR)

Patient name, contact number, age, gender, medical/dental history, dental charts, odontogram findings, treatment plans, periodontal statuses, X-ray/intraoral images, doctor prescriptions, and itemized billing receipts recorded by clinic doctors.

C. Audio & Voice Dictations

Voice inputs processed during hands-free dental charting or AI receptionist inbound patient calls, converted to structured clinical notes via private transcription APIs.

D. System & Audit Logs

Browser type, device metadata, IP address, and timestamped audit logs of record modifications to ensure clinical liability protection and prevent unauthorized tampering.

3. How Collected Data Is Used

Information managed through Dantasutra is used strictly for legitimate healthcare and operational service delivery:

  • Facilitating clinical charting, electronic dental prescriptions, and dental lab order tracking.
  • Generating GST-compliant invoices and digital payment receipts for dental treatments.
  • Automating 24-hour and 2-hour appointment reminder notifications via WhatsApp and SMS to reduce patient no-shows.
  • Enabling multi-tenant clinic portal administration across dedicated and shared deployment modes.
  • Processing patient inquiries through 24/7 AI voice receptionist agents configured for the clinic.

4. WhatsApp Business & Meta Cloud API Messaging Policy

Dantasutra interfaces directly with the official Meta WhatsApp Cloud API to facilitate transparent clinical communication. We strictly uphold Meta's Business Messaging Terms:

Patient Opt-in & Explicit Consent: Clinics warrant that patients have given consent during in-clinic registration or appointment scheduling to receive updates on WhatsApp.
Pre-Approved Meta Templates: Broadcasts outside the 24-hour customer care window strictly utilize Meta-approved message templates (such as consultation_v1, appointment_reminder_24h, and payment_receipt_v1).
Instant Opt-Out (STOP): Recipients can opt out of automated WhatsApp messages at any time by replying STOP or contacting their clinic staff.
No Spam or Third-Party Resale: Patient phone numbers are strictly used for the specific clinic’s communication and are never shared across unrelated clinics or third-party marketing brokers.

5. AI Voice Receptionist & Clinical Dictation

Dantasutra incorporates artificial intelligence tools (voice-to-chart dictation, receptionist call handling, clinical note formatting) under strict boundaries:

  • Voice dictation audio streams are processed in transient memory to generate clinical text charts and are not retained for general public AI model training.
  • Dentists maintain full manual override: every AI-assisted chart, prescription, or clinical note must be reviewed and confirmed by the attending dentist before finalization.
  • Patient privacy is preserved through anonymized API pipelines.

6. Authorized Sub-Processors & Service Providers

We collaborate with enterprise-grade infrastructure providers that comply with SOC2, ISO 27001, and HIPAA-level security standards:

Sub-ProcessorService PurposeData LocationSecurity Compliance
Google Cloud Platform (GCP) / FirebaseEncrypted Cloud DB, Authentication & HostingIndia / Global Multi-regionISO 27001, SOC 1/2/3, AES-256
Meta Platforms, Inc. (WhatsApp Cloud API)Patient appointment reminders & WhatsApp notificationsGlobal InfrastructureMeta Business Privacy Standards
Razorpay / StripePayment processing & digital clinic consultation receiptsIndia / GlobalPCI-DSS Level 1 Compliant
Fast2SMSDLT-approved transactional OTP & SMS deliveryIndiaTRAI DLT Registered

7. Data Security & Multi-Tenant Isolation

We implement comprehensive technical and organizational measures (TOMs) to safeguard patient data:

Encryption Standards

All data in transit is protected using modern TLS 1.3 cryptography. All databases, patient EMR documents, and digital scans are encrypted at rest using AES-256.

Tenant Scoping

Every clinic operates in a verified security scope. Queries are bounded to the clinic's verified tenant ID, preventing cross-tenant leakage between clinics.

8. Rights of Data Principals (Patients & Clinic Users)

In accordance with the Digital Personal Data Protection Act, 2023, individuals whose data is processed have the right to:

  • Right to Access: Request a summary of personal data being processed by their clinic.
  • Right to Correction & Updating: Request correction of inaccurate or outdated medical and personal records.
  • Right to Erasure (Data Deletion): Request deletion of personal information, subject to statutory medical record-keeping laws mandated by the Dental Council of India and State Health Authorities.
  • Right of Grievance Redressal: Submit a complaint regarding data handling directly to our designated Grievance Officer.

User Data Deletion Request & Callback Mechanism

In compliance with Meta Platform Policies and Indian DPDP Regulations, Dantasutra provides an automated data deletion request callback endpoint as well as self-service instructions for patients and clinics to request full erasure of their stored data.

View Data Deletion Instructions & Check Deletion Status →

9. Grievance Redressal & Contact Officer

In compliance with the Information Technology Act, 2000, the rules made thereunder, and the DPDPA 2023, queries or grievances regarding data privacy may be addressed to:

Data Protection & Grievance Officer
+91 9492718709
Physical Address for Legal Notices

Dantasutra Technologies
Plot 14, D.C.C.B Colony,
Srikakulam, Andhra Pradesh 532001, India.

Time to Response: Under statutory rules, all formal grievances are reviewed and resolved within 30 business days.

10. Modifications to This Privacy Policy

We reserve the right to modify this Privacy Policy to accommodate changes in clinical workflows, technological updates, Meta platform terms, or new regulatory mandates. Significant modifications will be highlighted through in-app dashboard notices or website updates.

Chat with usWhatsApp