Privacy Policy
Last updated: 2026-08-18
1. Who we are
Denta Dynamics ("we", "us", "our") operates a digital services portal for dentists, dental clinics, and dental laboratories. This policy explains what personal data we collect through our website and client portal, why we collect it, and the rights you have over it.
For the purposes of applicable data protection law, including the UK and EU General Data Protection Regulation ("GDPR"), Denta Dynamics is the data controller for account and billing information, and generally acts as a data processor on behalf of clinics for any patient case data uploaded to the portal (see Section 4).
2. Information we collect
Account information: your name, email address, phone/WhatsApp number, clinic or lab name, specialty, city and country, and password (stored as a salted hash, never in plain text).
Billing information: invoices, payment status, and transaction references. Card and PayPal payment details are handled directly by our payment processors: we do not store full card numbers on our servers.
Case and service data: files, notes, images, STL/DICOM scans, and other materials you upload when requesting a service (e.g. Exocad design, implant planning, marketing content).
Usage data: pages visited, general interaction data, and session recordings/heatmaps of how you use our website and portal, via the analytics tools described in Section 7.
Communications: messages you send us through the portal, contact form, or WhatsApp.
3. How we use your information
To create and manage your account and deliver the services you request.
To process payments and issue invoices.
To communicate with you about your requests, orders, and account (service messages are not optional; marketing messages are opt-in where required by law).
To improve our services and troubleshoot issues.
To comply with legal obligations, such as tax and accounting records.
4. Patient and case data uploaded by clinics
Some services (Exocad design, implant planning) involve uploading clinical files that may relate to an identifiable patient (for example, a scan file named with a patient's name, or clinical photographs).
As the clinic or lab submitting this data, you are the data controller for your patients' information, and you are responsible for having a lawful basis (such as patient consent) to share it with us. We act only as your data processor for this material: we use it solely to deliver the requested service, and we do not use patient case data for any other purpose, including marketing or AI model training.
We recommend anonymizing or de-identifying patient files where possible (e.g. using a case reference number instead of a patient's full name) before upload.
Case files are retained only as long as needed to deliver the service and support any revisions, after which they are deleted from active storage in line with our retention schedule (Section 6).
5. Who we share data with
Supabase: our database, authentication, and file storage provider.
PayPal: for processing card and PayPal payments.
Resend: for delivering transactional emails (order updates, receipts, password resets).
Vercel: for hosting the website and application, and for cookieless web analytics.
Microsoft Clarity: for session-replay and heatmap analytics on our public website and client portal (see Section 7).
Meta Platforms, Inc.: for conversion tracking (Meta Pixel) on our public website and client portal, to measure and improve our advertising (see Section 7).
We do not sell your personal data. We only share it with the service providers above, under contracts that require them to protect it, and as required by law.
6. International transfers and data retention
Our infrastructure providers may process and store data in locations outside your country, including the European Economic Area, the United Kingdom, and the United States. Where we transfer personal data out of the UK/EEA, we rely on adequacy decisions or standard contractual clauses with our providers, as applicable.
We retain account data for as long as your account is active, and billing records for as long as required by applicable tax and accounting law. Case files are retained per Section 4. You can request earlier deletion at any time, subject to our legal retention obligations.
7. Cookies and analytics
We use Vercel Web Analytics to understand traffic to our site. This tool is cookieless and does not use any persistent identifiers or local storage to track individual visitors across sessions or sites: it counts page views and aggregate trends without collecting personal data.
We also use Microsoft Clarity, a session-replay and heatmap tool, on our public website and client portal (never on the admin dashboard) to see how visitors navigate the site and where they run into friction. Clarity works by setting a small number of cookies and reconstructing anonymized recordings of on-screen activity. We have configured it to mask sensitive content, such as payment and bank-transfer details, messages, uploaded file names, and personal-profile fields, so that content never appears in a recording.
We also use Meta Pixel on our public website and client portal (never on the admin dashboard) to measure the effectiveness of our advertising and understand how visitors reach us, including when someone registers, submits a service request, or starts checkout. Meta Pixel works by setting cookies and sharing limited technical and usage data with Meta Platforms, Inc.
Clarity's and Meta Pixel's cookies are not strictly necessary to operate the site. If our systems detect that you are visiting from the UK, EEA, or another EU/EEA-adjacent country, we show a consent banner before either tool runs, and neither sets a single cookie or loads until you choose "Accept." If you choose "Decline," they never run for your visit. Visitors elsewhere are not shown this banner, as consent is not required in those jurisdictions, and these tools may run without a prior prompt. You can change your mind at any time by clearing this site's local storage in your browser, or by contacting us at the email below if you would like us to exclude your sessions.
Our authentication system uses one strictly necessary session cookie to keep you logged in, which does not require consent as it is essential to providing the service you requested.
8. Your rights
Depending on your location, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; restrict or object to certain processing; receive a copy of your data in a portable format; and withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at hello@dentadynmaics.com. We will respond within the timeframe required by applicable law (generally one month under GDPR).
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (for example, the ICO in the UK, or your national supervisory authority in the EU).
9. Security
We use industry-standard measures to protect your data, including encryption in transit (HTTPS), encrypted password storage, and row-level access controls in our database restricting each client to their own data.
No system is 100% secure. If we become aware of a data breach affecting your personal data, we will notify you and any relevant authority as required by law.
10. Children's privacy
Our services are intended for licensed dental professionals and businesses, not for individual consumers or children. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new "last updated" date, and for material changes, we will notify active account holders by email.
12. Contact us
Questions about this policy or your data? Email us at hello@dentadynmaics.com.

