Privacy Policy
Standalone notice of how we collect, use, share, and protect your personal data under the DPDP Act, 2023 and DPDP Rules, 2025.
Last Updated: July 20, 2026
Introduction
This Privacy Policy describes how D4dent LLP and its affiliates (collectively "D4dent, we, our, us") collect, use, share, protect, or otherwise process your personal data through our websites and applications including https://d4dent.org and https://www.d4dent.com/ (the "Platform"). For the purposes of the Digital Personal Data Protection Act, 2023, D4dent acts as a Data Fiduciary in respect of personal data it determines the purpose and means of processing for.
Standalone notice. This Policy is presented so you can understand our processing of personal data independently of any other document (including our Terms of Use). You do not need to read the Terms to give informed consent to processing described here. Contractual terms for using the Platform are separate and available at Terms of Use.
You may browse certain public sections without registering. We offer the Platform for use in India, and personal data is primarily stored and processed in India (including application databases on MongoDB Atlas in the Mumbai / India region, and application servers in Google Cloud asia-south1). Use of the Platform is governed by the laws of India, including applicable data protection law. By creating an account or submitting personal data to use a service, you acknowledge this Policy. If you do not agree, please do not register or provide personal data.
Required data for a feature must be provided to use that feature; optional data (for example analytics) may be declined. When a third-party partner collects data directly from you, their privacy policy applies to that collection. We will never ask for your banking passwords or card PINs by email or phone — report such requests to law enforcement.
Itemised personal data we may collect
Depending on your role and the features you use, we may process the following categories of personal data. Not every item applies to every user.
Account & identity
- Name (first / last)
- Email address
- Mobile / telephone number
- Date of birth
- Gender (where provided)
- Postal / clinic address
- Account credentials (password hash; never plain password)
- Profile ID, roles, and active role on the Platform
- Proof of identity or address you voluntarily upload
Guardian / parental (under 18)
- Parent or legal guardian name
- Relation to the child
- Guardian contact number
- Parental consent acknowledgement / PARENTAL_GUARDIAN consent record
Health & clinical
- Dental and medical history
- Dental / periodontal charts and comprehensive dental history
- Prescriptions and medication details
- Appointment and token-queue records
- Teleconsultation notes and related clinical notes
- Images, X-rays, DICOM, and intraoral / aligner scans
- Anxiety assessments and similar screening scores
- Public AI oral symptom assessment answers and narrative (guest sessions, short retention)
- Optional mouth photos sent for ephemeral assistive screening (not stored as patient records in v1)
- ABHA number / ABHA address and ABDM-related identifiers you link
- Lab and imaging orders and results metadata
Payments & billing
- Order / invoice references
- Payment status and amount references
- Refund and payout references
- Subscription plan and renewal status
- Payment-gateway transaction IDs (not card PINs or banking passwords)
Communications
- Support emails and grievance correspondence
- Transactional SMS / email / push notification tokens
- WhatsApp number and message content where you opt in
- Voice-assistant call or transcript fragments where that feature is used
Device, usage & cookies
- IP address and approximate location derived from network
- Browser / device type and similar technical metadata
- Session and authentication cookies
- Optional analytics events (only after cookie / analytics consent)
- App crash or diagnostic logs needed to operate the service
Consent & rights artefacts
- Purpose-specific consent records (e.g. clinical, analytics, ABDM, WhatsApp)
- Cookie preference choices
- Data Principal rights requests (export, correction, erasure) and outcomes
Purposes of processing and services enabled
We process personal data only for the specified purposes below. Each purpose is linked to the goods, services, or uses on the Platform that processing enables. We do not treat merely browsing public pages as consent for non-essential purposes such as marketing or non-essential analytics.
| Specified purpose | Goods, services, or uses enabled | Data typically used |
|---|---|---|
| Account registration and administration | Create and manage your user account; role selection (patient, doctor, clinic, lab, dealer, X-ray centre); profile setup; login and session management | Account & identity; credentials; roles |
| Appointments and clinic queue | Book, reschedule, and track appointments; walk-in and token queue; clinic / doctor schedules | Identity; appointments; guardian fields if under 18 |
| Clinical care and dental records | Dental charts, medical / dental history, prescriptions, anxiety screening, treatment documentation shared with your chosen care providers on the Platform | Health & clinical; identity |
| Imaging, scans, and AI-assisted tools | Upload and view X-rays / scans; aligner planning workspace; AI tooth segmentation and related assistive diagnostics you request | Health & clinical images/scans; identity |
| Public AI oral symptom assessment | Interactive symptom checker on Oral Health → AI assessment of reported symptoms (and optional ephemeral photo screening); encourage account registration to continue on D4Dent | Symptom answers; triage narrative; optional photo bytes processed ephemerally (guest session TTL) |
| Teleconsultation | Video consultation rooms (e.g. Jitsi), teleconsult notes, related prescriptions and billing hooks | Identity; clinical notes; session metadata |
| ABHA / ABDM health ID | Link or create ABHA, view health-ID card features, and related NDHM flows you initiate under Patient → Health ID | ABHA identifiers; identity; consents |
| Lab and X-ray centre workflows | Lab orders, imaging centre orders, status tracking, and result metadata between doctors, clinics, labs, and centres | Identity; clinical order metadata |
| Payments, subscriptions, and shop | Checkout via payment partners (e.g. Razorpay / PhonePe); invoices; refunds; subscription plans; in-app shop purchases | Payments & billing; contact details |
| Security, fraud prevention, and Terms enforcement | Authenticate users; detect abuse; lock accounts after failed logins; protect the Platform and other users | Account; device/usage; security logs |
| Customer support and grievances | Respond to support tickets and Data Principal / IT Act grievances; verify identity for rights requests | Communications; identity; rights artefacts |
| Service communications (transactional) | Appointment reminders, OTP / security messages, order and payment confirmations, and other messages needed to deliver a service you requested | Contact details; appointment / order refs |
| Optional product analytics | Understand feature usage to improve the Platform (e.g. Google Analytics); enabled only after cookie banner accept and/or ANALYTICS_* consent — not for signed-in patients under 18 | Device/usage; analytics events |
| Optional marketing / WhatsApp care messages | Promotional emails or WhatsApp messages only where you have opted in; you may withdraw via Consents, Cookies, or the Grievance Officer | Contact details; consent artefacts |
| Legal retention and compliance | Retain clinical, billing, or audit records where law requires (including erasure holds); respond to lawful government / Board requests | Clinical; billing; audit / consent logs |
Security Precautions
We adopt reasonable security practices and procedures to protect personal data against unauthorised access, disclosure, loss, or misuse, including access controls, encryption in transit, and audit logging for access to health-related information where implemented. Transmission over the internet cannot be guaranteed as completely secure. You are responsible for keeping your login credentials confidential.
Data Deletion and Retention
You may request deletion (erasure) or account closure from Patient → Rights → Delete / erase my account (type DELETE to confirm), or by writing to the Grievance Officer with the subject line "Request for erasure / account deletion". We will verify your identity before acting on email requests. Erasure deactivates login, removes personal identifiers, and revokes active consents. We may retain clinical, billing, and audit records under a legal retention hold (typically up to 8 years) where required by applicable law. After that hold expires, those retained records are purged by an automated job. We may refuse or delay complete erasure where needed for pending claims, fraud prevention, or legal obligations. We may retain anonymised data that no longer identifies you for analytics or research.
Your Rights (Data Principal)
Under the Digital Personal Data Protection Act, 2023 (DPDP Act), the Digital Personal Data Protection Rules, 2025, and other applicable Indian law, you (the Data Principal) may have the right to: • Access the personal data we hold about you. • Correct inaccurate or incomplete personal data. • Request erasure of personal data, subject to legal and clinical retention requirements. • Withdraw consent for processing that is based on consent (withdrawal is not retrospective). • Nominate another person to exercise rights in case of death or incapacity, as provided under applicable law. • Seek grievance redressal as described below, and complain to the Data Protection Board of India if unsatisfied (see Complaint to the Data Protection Board of India). How to exercise rights: • Access / export: Patient → Rights → Download my data (machine-readable JSON), or browse records in the dashboard. • Correction: update demographics where available in the app, or submit a correction request under Patient → Rights. • Erasure: Patient → Rights → Delete / erase my account, or email the Grievance Officer. • Withdraw consent: Patient → Consents, Patient → Rights (analytics), and Cookie preferences on /cookies. • Board complaint: after exhausting our grievance channel (or if we fail to respond in time), use the steps under Complaint to the Data Protection Board of India on this page (https://d4dent.org/privacy#board-complaint). We will acknowledge Data Principal requests within 72 hours of receipt during support hours, and aim to complete verified requests within a reasonable period as required by applicable law (typically within 30 days unless a longer period is permitted, and within 90 days under our grievance redressal system).
Children's Personal Data
If you are under 18, a parent or legal guardian must provide verifiable consent before we process your personal and health data for care on the Platform. Registration and clinic booking flows collect guardian name, phone, and an acknowledgement of parental consent, and record a PARENTAL_GUARDIAN consent artefact. We do not enable non-essential analytics (Google Analytics / ANALYTICS_BASIC / ANALYTICS_DETAILED) for signed-in patient accounts under 18. Guardians or patients may contact the Grievance Officer for questions about children's data.
Consent
Where processing is based on consent, this Privacy Policy is the notice intended to enable specific and informed consent. We seek purpose-specific consent (for example registration acceptance of this Policy, parental/guardian consent for patients under 18, clinical/teleconsultation consent, WhatsApp opt-in, or optional analytics). If you provide personal data about another person, you represent that you are authorised to do so. Transactional and service messages needed to deliver care or operate your account may be sent without marketing consent. To withdraw consent for optional processing, write to the Grievance Officer with the subject line "Withdrawal of consent for processing personal data", or use in-app consent controls where available. We may verify the request. Withdrawal does not affect processing already completed, or processing we continue on another lawful basis (for example to provide a service you still request, or to meet a legal obligation). If you withdraw consent required for a service, we may be unable to continue providing that service.
Changes to this Privacy Policy
Please check this Privacy Policy periodically. We may update it to reflect changes to our practices or the law. Where required, we will notify you of significant changes in an appropriate manner.
Grievance Officer
In accordance with the Information Technology Act, 2000 and rules made thereunder, and for Data Principal grievances under the DPDP Act, 2023, contact:
We will acknowledge grievances within 72 hours during the support hours below, and work to resolve them without undue delay (target completion within a reasonable period, typically within 30 days and not exceeding 90 days under our grievance system). If you are not satisfied after using this channel, you may complain to the Data Protection Board of India as described in the next section.
Complaint to the Data Protection Board of India
Under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, you may make a complaint to the Data Protection Board of India (the "Board") if you are not satisfied with our response to a grievance, or if we do not address it within the period required under applicable law.
Recommended steps:
- First contact our Grievance Officer at [email protected] (subject line: Privacy grievance) or use in-app rights / consent controls where available. Keep copies of your request and our reply.
- If unresolved, file a complaint with the Board through its official digital complaint facility (the Board is constituted to function as a digital office under the DPDP Rules, 2025).
- When filing, typically include: your identity and contact details, a description of the issue, and evidence that you first approached D4dent (emails, ticket reference, screenshots).
The Board's public complaint URL will be published here as soon as an official MeitY / Board portal address is confirmed for Data Principal filings. Until then, use the means below and check MeitY / Board announcements for the live digital office link.
- Monitor official communications from the Ministry of Electronics and Information Technology (MeitY) and the Data Protection Board of India for the complaint portal and filing instructions.
- When the Board publishes a postal or other authorised channel, you may use that channel with the same supporting documents as above.
- Bookmark this page: https://d4dent.org/privacy#board-complaint — we will update the portal link here without requiring you to re-read the full Policy.
