DentivaDentiva
Dentiva
FeaturesProductPricing
Solo Practice (1 Chair)Growing Clinic (2–4 Chairs)Multi-Branch Network (5+ Chairs)
LoginStart Free Trial
Start Free Trial
Data Protection

Privacy Policy

Last updated: August 2026

This policy explains what information Dentiva holds, why we hold it, where it is stored, and what you can ask us to do with it. We have written it in plain English on purpose.

The short version

  • Your clinic owns its patient records. We only hold them so we can run the software for you.
  • We never sell patient data, and we never use patient health information to advertise.
  • Patient records and files are stored in India. A few supporting services (messaging, email, payments, error monitoring, website analytics) process limited data outside India. All of them are listed below.
  • If your subscription ends, we keep your data for 90 days so you can export it, and then we delete it permanently.
  • You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Contact details are at the bottom.

1. Who we are, and who is responsible for what

Dentiva is software operated by Dentiva Clinical Systems, Goa, India. In this policy "we" and "Dentiva" mean that company.

Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), responsibility is split in two:

  • Your dental clinic is the Data Fiduciary for its patients. The clinic decides what patient information to collect, why, and who at the clinic may see it. If you are a patient, your clinic is the first place to go with a question about your records.
  • Dentiva is the Data Processor for that patient information. We store and process it only to run the service the clinic has asked us to run. We do not decide what goes into a patient record.
  • Dentiva is the Data Fiduciary for a smaller set of information: clinic and staff account details, subscription and payment records, support conversations, and enquiries from our own marketing website.

2. If you are a patient at a clinic using Dentiva

Your clinic entered your details into Dentiva so it could book your appointments, keep your treatment records, bill you, and send you reminders. We hold that information on the clinic's behalf.

  • We do not contact you for our own purposes. Messages you receive are sent by your clinic, using our software.
  • You can stop appointment and recall messages at any time by replying STOP on WhatsApp, or by telling your clinic.
  • To see, correct, or delete your records, contact your clinic first, since they control them. If the clinic does not respond, you can contact us and we will help.
  • We never sell your information and never use your health information for advertising.

3. If you are a clinic owner, doctor, or staff member

For your own account we hold your name, mobile number, email address, role, and (for dentists) your specialisation and professional registration number. If you use two-factor authentication we also store the security key for it.

We use this to sign you in, apply the right permissions, send service notices, handle support requests, and bill your subscription. We also keep an activity log of significant actions taken in your clinic account, which includes the IP address the action came from. That log exists for security and for the audit trail that clinical and billing records require.

4. If you are just visiting our website

On our public website (dentiva.in) we collect what you type into our contact, demo, and offer forms, and we use analytics and advertising cookies to understand which pages bring us enquiries. See section 12 for the details and how to opt out.

5. Exactly what information we hold

The DPDP Rules require us to list this item by item rather than in general terms. Depending on which features your clinic uses, we may hold:

  • Clinic details: clinic and branch name, address, phone, GST number, website, logo, working hours, and holidays.
  • Staff details: name, mobile, email, role, branch, dentist specialisation and registration number, login and two-factor credentials.
  • Patient details: record number, name, mobile, date of birth, gender, branch, and communication preferences.
  • Clinical records: medical alerts, dental history, visit notes, treatment performed, tooth charts, treatment plans and estimates, and prescriptions.
  • Images and documents: x-rays, clinical photographs, and any file your clinic uploads to a patient record.
  • Billing records: invoices, line items, discounts, payments, payment method, and outstanding balances.
  • Messages and communications: which reminders, recalls, review requests, and emails were sent to whom, and whether they were delivered, read, or replied to.
  • Enquiries and reviews: leads captured by your clinic, follow-up notes, feedback responses, and Google Business Profile reviews if you connect that account.
  • Pharmacy and supplier records: medicine stock, vendors, purchase orders, and vendor payments.
  • Technical data: IP address in the activity log, browser and device information, pages visited, and anti-spam signals collected on public booking and feedback forms.
  • Subscription and support: plan, usage against plan limits, payment history, support tickets and their contents.

6. Where your data is stored

Your patient database and uploaded files are stored in India (Mumbai region). That is where clinical records, billing records, x-rays, and documents live.

We want to be straightforward about the exception. Some of the services that support Dentiva process limited information outside India, for example message delivery, email delivery, payment processing, error monitoring, and website analytics. Section 7 names every one of them and says where it operates.

The DPDP Act permits this. It does not require all personal data to be kept inside India; it only allows the Government to restrict transfers to specific countries, and no such restriction currently affects our providers.

Data is encrypted in transit using TLS and encrypted at rest by our storage providers. Each clinic's data is separated at the database level so one clinic can never read another's.

7. Companies that help us run Dentiva

We use the following providers. They may only process data to deliver their part of the service, and never for their own purposes.

ProviderWhat it doesWhere
SupabaseMain database and login systemIndia
CloudflareHosting, file storage, security, bot protection on public formsIndia + global network
Meta (WhatsApp Cloud API)WhatsApp messages to patientsOutside India
MSG91SMS one-time passcodes for loginIndia
Zoho ZeptoMailTransactional email deliveryIndia
RazorpaySubscription and patient paymentsIndia
GoogleSign in with Google; Business Profile reviews if you connect itOutside India
SentryError monitoringOutside India
PostHogProduct usage analyticsOutside India
Meta (Pixel)Advertising measurement on our marketing websiteOutside India

We will update this list before adding a new provider that handles personal data. We do not sell data to anyone, and we do not share patient data with advertisers.

8. Children's records

Dental clinics treat children, so children's records are held in Dentiva. Indian law normally requires a parent's verified consent before a child's data is processed, but it makes an exception for healthcare providers treating that child. Your clinic relies on that exception, and we process the records on the clinic's behalf.

That exception only covers providing care. We therefore do notuse children's data for advertising, profiling, or behavioural tracking. Reminders and recall messages relating to a child are sent to the parent or guardian contact number the clinic has recorded.

9. How long we keep data, and what happens if you stop paying

While your subscription is active we keep your records so your clinic has a complete history. Clinical, billing, and audit records are never silently overwritten: corrections are stored as amendments so the original stays intact.

If your trial or subscription ends

  • Your account becomes read-only. You can still view and export.
  • We keep all your data for 90 days so you can export it or restart your subscription.
  • We will email you when the 90 days begin, again with about 30 days left, and at least 48 hours before anything is deleted.
  • After 90 days we permanently delete your patient, clinical, and billing records.

Please read this part carefully

Indian medical regulations require clinics to keep patient records for at least three years, and dental records are often needed for much longer. Exporting your records before your account closes is your clinic's responsibility, not ours. If you need more time, email us before the 90 days run out and we will work something out.

We may keep a small amount of information for longer where the law requires it, for example invoices and tax records we must retain under Indian tax law, and security logs.

10. Your rights

Under the DPDP Act you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything that is wrong or incomplete.
  • Delete data we no longer need, unless the law requires us to keep it.
  • Withdraw consent you previously gave.
  • Nominate someone to exercise these rights if you cannot.

Patients should contact their clinic first, because the clinic controls patient records. Clinic owners and staff can email us directly. We do not yet offer a one-click self-service export of an entire clinic account, so email us and we will prepare it for you, normally within 7 working days.

11. When Dentiva staff can see clinic data

Our support team cannot browse your clinic data freely. Access works like this:

  • Normal support: a clinic owner approves the access, it is limited to a set period, and it ends automatically.
  • Emergency access: in a genuine security or data-integrity incident, access can be granted without owner approval, but it requires two Dentiva administrators to approve it, and a written justification.
  • Always logged: every support session is recorded in a tamper-evident log with who accessed what and when. Owners can request that log at any time.

12. Cookies and tracking

Inside the Dentiva application we use only the cookies needed to keep you signed in and to keep the service secure.

On our marketing website we additionally use PostHog to see which pages are useful, and the Meta Pixel to measure our advertising. These set cookies and share page visit information with those providers.

You can block or delete these cookies in your browser settings, or use your browser's private browsing mode, without losing access to any part of Dentiva. Blocking them does not affect the clinical application.

13. If there is a data breach

If personal data in Dentiva is breached, we will tell the affected clinic within 48 hours of becoming aware of it, with enough detail for the clinic to meet its own 72-hour reporting duty to the Data Protection Board of India. Where we are the responsible party, we will notify the Board and affected individuals ourselves within the timelines the law requires.

14. Contact Us

For any queries or complaints regarding this policy or our data practices, please reach out to us. We acknowledge messages within 24 hours and aim to resolve them within 15 days.

Email: support@dentiva.in
Office: Panjim, Goa, India

15. Changes to this policy

We update this policy as the product changes. If a change materially affects how we handle personal data, we will email clinic account owners before it takes effect rather than relying on you to spot it here. The date at the top always shows the current version.

This Privacy Policy was last updated in August 2026. It should be read together with our Terms of Service.

Dentiva Logo

Modern Clinical Dental Management.

Product

FeaturesPricingProduct

Solutions

Who We HelpSolo PracticeGrowing ClinicMulti-Branch

Resources

BlogHelp & DocsCase StudiesTemplatesSystem Status

Company

About UsContactPrivacy PolicyTerms of Service

Contact Us

support@dentiva.in
Goa, India

© 2026 Dentiva Clinical Systems.Built for Indian Dentists with ❤️

Start Free Trial