Back

Privacy Policy

Effective June 7, 2026

This Privacy Policy explains how Dentila handles personal information about dentists, dental laboratories, their staff, and patient details referenced inside cases. Read this together with our Terms of Service.

1. Data We Collect

Account data — full name, email address, password (stored only as a salted hash), preferred language (English, Arabic, or Kurdish), role (dentist, lab, or admin), account status, and timestamps.

Dentist profile — clinic name, specialty, years of experience, phone, address, city, country, bio, website, Instagram handle, accent color, avatar photo, preferred currency (default: IQD), and the syndicate ID document uploaded for verification.

Lab profile — lab name, address, city, country, GPS coordinates, services offered, business hours, logo, wallet balance and credit ledger.

Case data — patient name, optional patient phone number, age, gender, treatment type, tooth numbers (FDI), materials, shade, deadlines, prices, currency, status history, and any files you attach (intra-oral scans, photos, voice notes).

Messaging — chat messages between the dentist and the assigned lab on each case, including text, image attachments, and voice notes. System messages logging status changes are also stored.

Financial data — lab credit transactions, lab payments recorded by labs, and promo code redemptions. Dentila does not store full card or bank account numbers.

Operational data — notifications, support tickets and replies, ratings and reviews, saved/bookmarked labs, and ad impression/click events for sponsored placements.

Email delivery data — delivery status, bounces, complaints, and unsubscribe tokens used to honour opt-outs.

Technical data — IP address, device and browser information, timestamps, and error logs needed to operate, secure, and debug the service.

2. Device Permissions (Mobile App)

The Dentila iOS and Android apps request the following operating-system permissions. Each one is only used for the purpose described below; you can revoke any of them from your device settings at any time.

  • Camera — used only when you choose to take a photo to attach to a case, a chat message, or your profile/lab portfolio. Photos are uploaded to Dentila's private cloud storage and are accessible only to the parties of that case (or to anyone viewing your public profile, in the case of portfolio photos). No background camera access.
  • Photo Library — used only when you pick an existing image to attach to a case, chat, profile avatar, lab logo, lab portfolio, or support ticket. Dentila reads only the image(s) you explicitly select.
  • Photo Library — Add — used to save case PDFs and shared images back to your device when you tap "Save" or "Share". No automatic writes.
  • Microphone — used only while you are actively recording a voice note inside a case chat. Recordings are uploaded to private chat-media storage and shared only with the other party of that case. No background or always-on listening.
  • Location (When In Use) — used only when you tap "Find labs near me" or set your clinic/lab coordinates. The coarse coordinates are used to sort the lab directory by distance and, for labs, to display your lab on the map to authenticated dentists. Location is never tracked in the background and is never shared with advertisers.
  • Notifications — used to deliver case status updates, new chat messages, and support replies. You can disable them anytime in device settings or inside the app.

These same permissions and purposes are declared in the App Store and Google Play data-safety listings.

2. Dentists & Patient Information

  • You are responsible for the lawful collection of patient information you upload to a case (patient consent, professional duty of confidentiality, and local health-data laws).
  • Use the minimum necessary patient identifiers. Initials or chart numbers are preferred over full names where your jurisdiction allows. Phone numbers are optional.
  • Dentila acts as a data processor for case content uploaded by dentists; the dentist remains the data controller for that patient record.
  • Case files are stored in private storage buckets and are accessible only to the case parties (the dentist who created the case and the lab assigned to it) and Dentila admins for support and dispute resolution.

3. Labs & Business Information

  • Lab name, city, country, services, ratings, logo, and GPS location are visible to authenticated dentists browsing the directory.
  • Wallet balance, credit transactions, and internal notes are visible only to the lab itself and Dentila admins.
  • Payments recorded by the lab against a case are visible to that lab, the linked dentist, and Dentila admins.

4. How We Use Data

  • Operate the Platform: route cases between dentists and labs, run chat and notifications, calculate ratings, manage lab credits and payments, deliver sponsorship placements.
  • Send transactional and operational email — case updates, new messages, status changes, approvals, and support replies — using our email infrastructure.
  • Verify accounts (syndicate ID for dentists, business details for labs) and prevent fraud, abuse, and impersonation.
  • Resolve support tickets and case disputes.
  • Improve the product through aggregated, de-identified analytics.
  • Comply with legal, tax, and regulatory obligations.

We do not sell personal data, and we do not use case content for third-party advertising or to train external AI models.

5. Who We Share Data With

  • Other case parties. A case is shared between the dentist who created it and the lab assigned to it.
  • Dentila admins. Limited to support, verification, dispute handling, and abuse prevention.
  • Infrastructure providers. Cloud hosting, managed database, file storage, and transactional email providers acting on our behalf under confidentiality terms.
  • Legal requests. Where required by valid legal process or to protect users and the Platform.
  • Successors. If Dentila is acquired or restructured, account data may transfer subject to this Policy.

6. Email & Notifications

  • We send transactional email (verification, password reset, case updates, new messages, support replies, account approvals).
  • Every notification email includes a one-click unsubscribe link. You can also manage in-app push and email categories from your profile.
  • If your address generates a hard bounce or spam complaint, it is suppressed automatically to protect deliverability for everyone else.
  • Security and account-critical messages (password reset, account approval) may still be sent after you unsubscribe from marketing or activity emails.

7. Security

  • Passwords are stored only as salted hashes — we never see your plain password.
  • All traffic is encrypted in transit with TLS. Storage buckets are private by default and protected by row-level security policies in the database.
  • Sensitive operations (account approval, credit top-ups, sponsorship, broadcasts) are restricted to admin roles and audited.
  • No system is perfectly secure. You are responsible for keeping your password and devices safe and for using a strong, unique password.

8. Biometric Login (On-Device Only)

Biometric sign-in (Face ID, Touch ID, Windows Hello, Android biometric) is an optional convenience built on the WebAuthn standard. Your fingerprint, face scan, or any biometric template never leaves your device and is never transmitted to Dentila. We only store a public key reference that lets your device prove it is the same one that enrolled.

9. Data Retention

  • Active account data is kept while your account exists.
  • Case records (including chat, files, and status history) are retained for legal, audit, dispute, and tax purposes — typically up to 7 years after the case closes, or longer if required by law.
  • Support tickets and chat are retained while needed for service operations and reasonable historical reference.
  • Email delivery logs and suppression entries are retained as long as needed to maintain deliverability.
  • Aggregated, de-identified data may be kept indefinitely.

10. Your Rights

Subject to applicable law, you may:

  • Access and update your profile (including avatar and contact details) directly inside the app.
  • Export your cases as CSV from your profile.
  • Request a copy of the personal data we hold about you.
  • Request correction or deletion of personal data, subject to records we must retain by law or for legitimate business purposes (such as closed cases or paid invoices).
  • Withdraw consent for optional processing where consent is the legal basis, and unsubscribe from non-essential email at any time.
  • Lodge a complaint with your local data protection authority.

To exercise these rights, open a support ticket in-app or write to info@dentila.org.

11. Account Deletion

You can permanently delete your Dentila account and the data tied to it directly from inside the app — no email request required. This satisfies Apple App Store Guideline 5.1.1(v) and Google Play's account-deletion requirement.

How to delete your account:

  1. Open the app and sign in.
  2. Go to Profile (bottom tab).
  3. Scroll to the bottom and tap Delete my account.
  4. Type DELETE to confirm.

What gets deleted immediately:

  • Your authentication record (email, password hash, sign-in identities).
  • Your profile: full name, phone, language, avatar, role.
  • Dentist data: clinic name, syndicate ID document, address, bio, specialty, currency.
  • Lab data: lab name, address, GPS, services, business hours, logo, wallet balance, credit history, portfolio images, offers, price list.
  • Cases you created as a dentist, including all attached files, chat messages, status history, and shared links.
  • Chat messages and reactions, notifications, saved labs, ratings you posted, support tickets you opened.
  • Uploaded files in cloud storage (avatars, syndicate IDs, portfolio images, payment receipts, chat media).

What may be retained:

  • Cases where you participated as the assigned lab (not the case owner) remain visible to the dentist who created them; your identifying information is removed where technically possible.
  • Financial records (lab payments, credit transactions, promo redemptions) and audit logs may be retained in anonymised form for up to 7 years to meet legal, tax, and dispute-resolution requirements.
  • Email suppression entries are retained to honour your unsubscribe choice.

If you can't sign in to delete the account yourself, email info@dentila.org from the address on file and we will process the deletion within 30 days.

11. Cookies & Local Storage

We use a small number of strictly necessary cookies and browser storage entries to keep you signed in, remember preferences (language, theme, notification toggle), and maintain session security. We do not use third-party advertising cookies, and we do not run cross-site tracking pixels.

12. International Transfers

Dentila operates from the Kurdistan Region of Iraq and uses cloud infrastructure that may store or process data in regions other than your own. Where required, we use appropriate safeguards (such as standard contractual clauses) for cross-border transfers.

13. Children

Dentila is intended for licensed dental professionals and is not directed at children. Patient information about minors may be uploaded by a treating dentist as part of a case; the dentist remains responsible for the lawful basis for that processing.

14. Changes to This Policy

We may update this Policy as the Platform evolves. Material changes will be announced in-app or by email and become effective on the date posted.

15. Contact

Dentila is developed by Dev Vision. Privacy questions or requests: info@dentila.org.