01Scope — which properties this covers
This policy applies to all of the following (together, the “Platform”):
| Property | What it is | Who uses it |
|---|---|---|
| www.dentoze.com | Public directory for finding dental clinics and specialists and booking appointments | Patients and the public |
| www.dentozehub.com and its subdomains | Practice-management software for appointments, patient records, treatment plans, prescriptions, inventory and billing | Dental clinics, dentists and clinic staff |
| DentozeHub mobile applications (Android and iOS) | Mobile access to the above | Patients, clinicians and clinic staff |
Both platforms are owned and operated by Morphosistec. Where this policy says “we”, it means Morphosistec acting through whichever of these properties you are using.
02Two different roles — please read this section
Our responsibilities depend on whose data is involved. This distinction determines who you contact to exercise your rights.
| Data | Our role | Who is responsible |
|---|---|---|
| Your account with Dentoze, clinic staff accounts, subscription and billing records, Platform usage and diagnostics | Data Fiduciary (we decide the purpose) |
Dentoze — this policy governs |
| Patient clinical records entered by a clinic: dental charts, clinical notes, diagnoses, treatment plans, prescriptions, imaging | Data Processor (we act on the clinic's instructions) |
The treating clinic — their own privacy notice governs |
03Data we collect
3.1 Information you give us
- Account: name, mobile number, email address, password (stored only as a cryptographic hash), role, and associated clinic.
- Patient profile: name, contact details, date of birth, gender, and address, where you book through the Platform.
- Health information: medical and dental history, allergies, current medications, dental charts, diagnoses, treatment plans and estimates, prescriptions, clinical notes, and dental imaging.
- Appointment data: requested clinic, doctor, service, date and time, and appointment status.
- Communications: support enquiries and correspondence.
3.2 Information generated automatically
- IP address, device type, operating system, browser, and app version.
- Log data: pages and screens accessed, features used, and timestamps.
- Authentication tokens and session records.
- Cookies and similar technologies (section 10).
3.3 Payment information
Payments are processed by Razorpay Software Private Limited, a PCI-DSS compliant payment gateway. Card numbers, UPI credentials, and bank details are submitted directly to Razorpay and are never stored on Dentoze systems. We retain only the transaction reference, amount, status, and timestamp.
04Why we process it
| Purpose | Data used |
|---|---|
| Creating and securing your account | Account details, credentials, device and log data |
| Booking, confirming, rescheduling and cancelling appointments | Profile, appointment, clinic and doctor data |
| Enabling clinics to deliver and record dental care | Health information, on the clinic's instructions |
| Processing payments and issuing invoices | Transaction records, billing details |
| Sending service communications (confirmations, reminders, OTPs) | Contact details, appointment data |
| Security, fraud prevention, and abuse detection | Log, device and authentication data |
| Diagnosing faults and improving the Platform | Aggregated and de-identified usage data |
| Meeting legal, tax and regulatory obligations | As required by applicable law |
05Automated and AI-assisted processing
DentozeHub offers clinicians optional AI-assisted features that support clinical documentation and record-keeping. When a clinician uses one of these features, only the content relevant to that task is processed. Depending on the feature used, this may include:
- clinical notes and examination findings;
- diagnoses, procedures and treatment history;
- medication and prescription details; and
- dental images, including radiographs.
5.1 How it works
- These features run only when a clinician actively invokes them. No clinical data is sent for AI processing in the background.
- Output is a suggestion. A qualified clinician reviews it and makes the decision. No diagnosis, treatment or clinical decision is made automatically by the system.
- We record that an AI feature was used, by whom and when, for auditing and billing. This record does not contain the clinical content.
5.2 AI processing partner
AI processing is carried out by a third-party enterprise AI service provider engaged by us under a commercial agreement, which may process the content outside the country in which it was collected. Under that agreement, content sent for processing is not used to train the provider's models, is deleted from the provider's systems within 30 days (subject to exceptions for legal requirements and misuse prevention), and is not reviewed by humans in the ordinary course. Clinics are informed of our sub-processors under their agreement with us; individuals may request this information by writing to us at the address in section 14.
06Who we share it with
| Recipient | Purpose |
|---|---|
| Your dental clinic and its authorised staff | Delivering and recording your care |
| Razorpay | Payment processing |
| Cloud infrastructure and hosting providers | Hosting, storage and backup |
| Email service provider | Transactional email — one-time passwords, appointment confirmations and reminders |
| Enterprise AI service provider | Processing clinical content to generate AI-assisted suggestions, when a clinician invokes an AI feature (section 5) |
| Professional advisers, auditors | Legal, accounting and audit obligations |
| Government or judicial authorities | Where required by law or valid legal process |
Each processor is bound by contract to process data only on our instructions and to apply appropriate security safeguards. We do not permit them to use your data for their own marketing.
07Retention
| Category | Retained for |
|---|---|
| Account data | While the account is active, then 90 days after closure |
| Appointment records | 3 years, for continuity of care |
| Clinical records | As instructed by the clinic and as required by medical records law — retention obligations may prevent immediate deletion |
| Transaction and invoice records | 8 years, tax law |
| Access and security logs | 1 year (DPDP Rules 2025, Rule 6) |
When a retention period ends, data is deleted or irreversibly anonymised.
08Your rights
Under the Digital Personal Data Protection Act, 2023, you may:
- Access a summary of the personal data we process about you.
- Correct inaccurate or incomplete data, and complete or update it.
- Erase your data where we are not required to retain it.
- Withdraw consent at any time, as easily as it was given. Withdrawal does not affect processing already carried out.
- Nominate another individual to exercise your rights if you die or become incapacitated.
- Complain to us, and then to the Data Protection Board of India if unsatisfied.
To exercise these rights, email info@morphosistec.com. We respond within 30 days. We may ask you to verify your identity.
8.1 Deleting your account and data
In the app: Profile → Settings → Delete Account.
By email: write to info@morphosistec.com from the email address registered to your account, with the subject “Account Deletion Request”. Include your registered name and mobile number so we can verify the request.
What happens when you request deletion:
- We verify that the request comes from the account holder.
- Your account, login credentials and profile are deleted within 30 days.
- Associated data — appointment history, preferences and communications — is deleted or irreversibly anonymised.
- Clinical records held on behalf of a clinic are subject to that clinic's instructions and to medical records retention law. We forward such requests to the treating clinic, which decides in accordance with its legal obligations.
- Transaction and invoice records are retained where tax law requires.
We confirm completion by email. If you do not receive confirmation within 30 days, contact the Grievance Officer (section 14).
09Children’s data
Dental care is provided to children, and the Platform is used to record paediatric patients’ treatment.
- Accounts may only be created by individuals aged 18 or over.
- A parent or lawful guardian may register a child as a patient and provide verifiable consent for the processing of that child's data.
- Where a clinic enters a child's records, the clinic is responsible for obtaining verifiable parental consent.
- We do not carry out behavioural tracking, profiling, or targeted advertising directed at children.
10Cookies
We use:
- Strictly necessary — authentication, session management, security. These cannot be disabled without breaking the Platform.
- Functional — remembering preferences such as language and selected clinic.
11Security
- Encryption in transit (TLS) and at rest.
- Role-based access control; staff access limited to what their role requires.
- Passwords stored only as salted cryptographic hashes.
- Audit logging of access to clinical records, retained for 1 year.
- Regular backups and tested restore procedures.
No system is perfectly secure. If a personal data breach occurs, we will notify affected individuals and the Data Protection Board of India in accordance with the DPDP Rules, 2025, and inform the relevant clinic without undue delay.
12Data location and cross-border transfers
Personal data, including clinical records, is stored on servers in a region we select for the relevant deployment. You may request the storage region applicable to your account or your clinic by writing to us at the address in section 14.
Some processing takes place outside the country in which data is collected. In particular, where a clinician invokes an AI-assisted feature, the relevant clinical content is transmitted to our AI processing partner for processing and the response is returned to us. Certain infrastructure, backup and support functions may also be performed from other locations.
Where we transfer personal data across borders, we do so in accordance with applicable law, including the Digital Personal Data Protection Act, 2023, and under contractual safeguards requiring the recipient to protect the data and to process it only on our instructions.
13Changes to this policy
We may update this policy. Where changes are material, we will notify you by email or in-app notice before they take effect. The effective date at the top of this page always reflects the current version.
14Grievance Officer
In accordance with the Information Technology Act, 2000 and rules made thereunder, and the Digital Personal Data Protection Act, 2023:
MORPHOSIS TECHNOLOGIES PRIVATE LIMITED
No. 43, 2nd Cross, 3rd Main, RT Nagar, Bengaluru, Karnataka 560032, India
Email: info@morphosistec.com
Telephone: +91 80 6217 9825 · Hours: Monday to Friday, 10:00–18:00 IST
We acknowledge grievances within 24 hours and resolve them within 15 days. If you are not satisfied, you may complain to the Data Protection Board of India.
15Contact
Privacy and data-protection queries: info@morphosistec.com
Platform support: info@morphosistec.com
Dentoze and DentozeHub are products of Morphosistec. Correspondence about either platform is handled by Morphosistec at the address above.
16Governing law
This policy is governed by the laws of India. Disputes are subject to the exclusive jurisdiction of the courts at Bengaluru, Karnataka.