D4Dent Logo
Data Protection

Privacy Policy

Standalone notice of how we collect, use, share, and protect your personal data under the DPDP Act, 2023 and DPDP Rules, 2025.

Last Updated: July 20, 2026

Introduction

This Privacy Policy describes how D4dent LLP and its affiliates (collectively "D4dent, we, our, us") collect, use, share, protect, or otherwise process your personal data through our websites and applications including https://d4dent.org and https://www.d4dent.com/ (the "Platform"). For the purposes of the Digital Personal Data Protection Act, 2023, D4dent acts as a Data Fiduciary in respect of personal data it determines the purpose and means of processing for.

Standalone notice. This Policy is presented so you can understand our processing of personal data independently of any other document (including our Terms of Use). You do not need to read the Terms to give informed consent to processing described here. Contractual terms for using the Platform are separate and available at Terms of Use.

You may browse certain public sections without registering. We offer the Platform for use in India, and personal data is primarily stored and processed in India (including application databases on MongoDB Atlas in the Mumbai / India region, and application servers in Google Cloud asia-south1). Use of the Platform is governed by the laws of India, including applicable data protection law. By creating an account or submitting personal data to use a service, you acknowledge this Policy. If you do not agree, please do not register or provide personal data.

Required data for a feature must be provided to use that feature; optional data (for example analytics) may be declined. When a third-party partner collects data directly from you, their privacy policy applies to that collection. We will never ask for your banking passwords or card PINs by email or phone — report such requests to law enforcement.

Itemised personal data we may collect

Depending on your role and the features you use, we may process the following categories of personal data. Not every item applies to every user.

Account & identity

  • Name (first / last)
  • Email address
  • Mobile / telephone number
  • Date of birth
  • Gender (where provided)
  • Postal / clinic address
  • Account credentials (password hash; never plain password)
  • Profile ID, roles, and active role on the Platform
  • Proof of identity or address you voluntarily upload

Guardian / parental (under 18)

  • Parent or legal guardian name
  • Relation to the child
  • Guardian contact number
  • Parental consent acknowledgement / PARENTAL_GUARDIAN consent record

Health & clinical

  • Dental and medical history
  • Dental / periodontal charts and comprehensive dental history
  • Prescriptions and medication details
  • Appointment and token-queue records
  • Teleconsultation notes and related clinical notes
  • Images, X-rays, DICOM, and intraoral / aligner scans
  • Anxiety assessments and similar screening scores
  • Public AI oral symptom assessment answers and narrative (guest sessions, short retention)
  • Optional mouth photos sent for ephemeral assistive screening (not stored as patient records in v1)
  • ABHA number / ABHA address and ABDM-related identifiers you link
  • Lab and imaging orders and results metadata

Payments & billing

  • Order / invoice references
  • Payment status and amount references
  • Refund and payout references
  • Subscription plan and renewal status
  • Payment-gateway transaction IDs (not card PINs or banking passwords)

Communications

  • Support emails and grievance correspondence
  • Transactional SMS / email / push notification tokens
  • WhatsApp number and message content where you opt in
  • Voice-assistant call or transcript fragments where that feature is used

Device, usage & cookies

  • IP address and approximate location derived from network
  • Browser / device type and similar technical metadata
  • Session and authentication cookies
  • Optional analytics events (only after cookie / analytics consent)
  • App crash or diagnostic logs needed to operate the service

Consent & rights artefacts

  • Purpose-specific consent records (e.g. clinical, analytics, ABDM, WhatsApp)
  • Cookie preference choices
  • Data Principal rights requests (export, correction, erasure) and outcomes

Purposes of processing and services enabled

We process personal data only for the specified purposes below. Each purpose is linked to the goods, services, or uses on the Platform that processing enables. We do not treat merely browsing public pages as consent for non-essential purposes such as marketing or non-essential analytics.

Specified purposeGoods, services, or uses enabledData typically used
Account registration and administrationCreate and manage your user account; role selection (patient, doctor, clinic, lab, dealer, X-ray centre); profile setup; login and session managementAccount & identity; credentials; roles
Appointments and clinic queueBook, reschedule, and track appointments; walk-in and token queue; clinic / doctor schedulesIdentity; appointments; guardian fields if under 18
Clinical care and dental recordsDental charts, medical / dental history, prescriptions, anxiety screening, treatment documentation shared with your chosen care providers on the PlatformHealth & clinical; identity
Imaging, scans, and AI-assisted toolsUpload and view X-rays / scans; aligner planning workspace; AI tooth segmentation and related assistive diagnostics you requestHealth & clinical images/scans; identity
Public AI oral symptom assessmentInteractive symptom checker on Oral Health → AI assessment of reported symptoms (and optional ephemeral photo screening); encourage account registration to continue on D4DentSymptom answers; triage narrative; optional photo bytes processed ephemerally (guest session TTL)
TeleconsultationVideo consultation rooms (e.g. Jitsi), teleconsult notes, related prescriptions and billing hooksIdentity; clinical notes; session metadata
ABHA / ABDM health IDLink or create ABHA, view health-ID card features, and related NDHM flows you initiate under Patient → Health IDABHA identifiers; identity; consents
Lab and X-ray centre workflowsLab orders, imaging centre orders, status tracking, and result metadata between doctors, clinics, labs, and centresIdentity; clinical order metadata
Payments, subscriptions, and shopCheckout via payment partners (e.g. Razorpay / PhonePe); invoices; refunds; subscription plans; in-app shop purchasesPayments & billing; contact details
Security, fraud prevention, and Terms enforcementAuthenticate users; detect abuse; lock accounts after failed logins; protect the Platform and other usersAccount; device/usage; security logs
Customer support and grievancesRespond to support tickets and Data Principal / IT Act grievances; verify identity for rights requestsCommunications; identity; rights artefacts
Service communications (transactional)Appointment reminders, OTP / security messages, order and payment confirmations, and other messages needed to deliver a service you requestedContact details; appointment / order refs
Optional product analyticsUnderstand feature usage to improve the Platform (e.g. Google Analytics); enabled only after cookie banner accept and/or ANALYTICS_* consent — not for signed-in patients under 18Device/usage; analytics events
Optional marketing / WhatsApp care messagesPromotional emails or WhatsApp messages only where you have opted in; you may withdraw via Consents, Cookies, or the Grievance OfficerContact details; consent artefacts
Legal retention and complianceRetain clinical, billing, or audit records where law requires (including erasure holds); respond to lawful government / Board requestsClinical; billing; audit / consent logs

Sharing of Personal Data

We may share personal data with: • Clinics, doctors, labs, imaging centres, and other healthcare participants you choose to engage with on the Platform, as needed to deliver care. • Service providers who process data on our behalf (for example cloud hosting, payment gateways, messaging, video consultation infrastructure), under contractual obligations to protect the data. • Government or authorised agencies when required by law, court order, or lawful request (including ABDM/NHA flows you initiate). • Affiliates or successors in connection with a corporate transaction, subject to this Policy and applicable law. We do not sell your personal data. Third parties that collect data directly from you are governed by their own policies.

Security Precautions

We adopt reasonable security practices and procedures to protect personal data against unauthorised access, disclosure, loss, or misuse, including access controls, encryption in transit, and audit logging for access to health-related information where implemented. Transmission over the internet cannot be guaranteed as completely secure. You are responsible for keeping your login credentials confidential.

Data Deletion and Retention

You may request deletion (erasure) or account closure from Patient → Rights → Delete / erase my account (type DELETE to confirm), or by writing to the Grievance Officer with the subject line "Request for erasure / account deletion". We will verify your identity before acting on email requests. Erasure deactivates login, removes personal identifiers, and revokes active consents. We may retain clinical, billing, and audit records under a legal retention hold (typically up to 8 years) where required by applicable law. After that hold expires, those retained records are purged by an automated job. We may refuse or delay complete erasure where needed for pending claims, fraud prevention, or legal obligations. We may retain anonymised data that no longer identifies you for analytics or research.

Your Rights (Data Principal)

Under the Digital Personal Data Protection Act, 2023 (DPDP Act), the Digital Personal Data Protection Rules, 2025, and other applicable Indian law, you (the Data Principal) may have the right to: • Access the personal data we hold about you. • Correct inaccurate or incomplete personal data. • Request erasure of personal data, subject to legal and clinical retention requirements. • Withdraw consent for processing that is based on consent (withdrawal is not retrospective). • Nominate another person to exercise rights in case of death or incapacity, as provided under applicable law. • Seek grievance redressal as described below, and complain to the Data Protection Board of India if unsatisfied (see Complaint to the Data Protection Board of India). How to exercise rights: • Access / export: Patient → Rights → Download my data (machine-readable JSON), or browse records in the dashboard. • Correction: update demographics where available in the app, or submit a correction request under Patient → Rights. • Erasure: Patient → Rights → Delete / erase my account, or email the Grievance Officer. • Withdraw consent: Patient → Consents, Patient → Rights (analytics), and Cookie preferences on /cookies. • Board complaint: after exhausting our grievance channel (or if we fail to respond in time), use the steps under Complaint to the Data Protection Board of India on this page (https://d4dent.org/privacy#board-complaint). We will acknowledge Data Principal requests within 72 hours of receipt during support hours, and aim to complete verified requests within a reasonable period as required by applicable law (typically within 30 days unless a longer period is permitted, and within 90 days under our grievance redressal system).

Children's Personal Data

If you are under 18, a parent or legal guardian must provide verifiable consent before we process your personal and health data for care on the Platform. Registration and clinic booking flows collect guardian name, phone, and an acknowledgement of parental consent, and record a PARENTAL_GUARDIAN consent artefact. We do not enable non-essential analytics (Google Analytics / ANALYTICS_BASIC / ANALYTICS_DETAILED) for signed-in patient accounts under 18. Guardians or patients may contact the Grievance Officer for questions about children's data.

Cookies and Analytics

We use essential cookies and similar technologies needed for authentication, security, and basic Platform operation. Non-essential analytics (such as Google Analytics) run only if you accept them via the cookie banner. You can choose Essential only to refuse analytics. Signed-in patients under 18 cannot enable analytics. Signed-in patients may also revoke ANALYTICS_BASIC / ANALYTICS_DETAILED consents under Patient → Consents. Details are on our Cookies page.

View Cookies Policy

Changes to this Privacy Policy

Please check this Privacy Policy periodically. We may update it to reflect changes to our practices or the law. Where required, we will notify you of significant changes in an appropriate manner.

Grievance Officer

In accordance with the Information Technology Act, 2000 and rules made thereunder, and for Data Principal grievances under the DPDP Act, 2023, contact:

We will acknowledge grievances within 72 hours during the support hours below, and work to resolve them without undue delay (target completion within a reasonable period, typically within 30 days and not exceeding 90 days under our grievance system). If you are not satisfied after using this channel, you may complain to the Data Protection Board of India as described in the next section.

Grievance Officer NameDr. Jishnu S
DesignationCo-founder & Director
Company Name & AddressD4dent LLP, Arookutty Road, Aroor, Alappuzha, Kerala, 688534
Support HoursMonday - Friday (9:00 - 18:00 IST)

Complaint to the Data Protection Board of India

Under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, you may make a complaint to the Data Protection Board of India (the "Board") if you are not satisfied with our response to a grievance, or if we do not address it within the period required under applicable law.

Recommended steps:

  1. First contact our Grievance Officer at [email protected] (subject line: Privacy grievance) or use in-app rights / consent controls where available. Keep copies of your request and our reply.
  2. If unresolved, file a complaint with the Board through its official digital complaint facility (the Board is constituted to function as a digital office under the DPDP Rules, 2025).
  3. When filing, typically include: your identity and contact details, a description of the issue, and evidence that you first approached D4dent (emails, ticket reference, screenshots).
Official Board complaint portal

The Board's public complaint URL will be published here as soon as an official MeitY / Board portal address is confirmed for Data Principal filings. Until then, use the means below and check MeitY / Board announcements for the live digital office link.

Other means (interim)
  • Monitor official communications from the Ministry of Electronics and Information Technology (MeitY) and the Data Protection Board of India for the complaint portal and filing instructions.
  • When the Board publishes a postal or other authorised channel, you may use that channel with the same supporting documents as above.
  • Bookmark this page: https://d4dent.org/privacy#board-complaint — we will update the portal link here without requiring you to re-read the full Policy.