Privacy Policy & Data Protection Notice
Version 2026-08-13 · Last updated 13 August 2026
This notice explains what personal data we collect when you use dentalxpert.in, why we collect it, how long we keep it and what you can ask us to do with it. It is issued as a notice under section 5 of the Digital Personal Data Protection Act, 2023 and also meets the requirements of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
1. Who is responsible for your data
DentalXpert is the Data Fiduciary for the personal data described here. Our legal name, address and contact details are on the Contact page. Questions about this notice, and requests about your data, go to our Grievance Officer — details on the Grievance Redressal page.
2. What we collect
| Category | What it includes |
|---|---|
| Identity & contact | Name, email address, mobile number. Optionally date of birth, gender, city, state and pincode if you add them to your profile. |
| Health information | The dental concern you describe, symptom duration and pain score, drug allergies, medicines you take, medical conditions, tobacco use, pregnancy status, and the dentist's findings, advice and prescription. This is sensitive personal data or information under the SPDI Rules, 2011. |
| Booking & payment | Slot, booking reference, amount, Razorpay order/payment/refund identifiers, payment status. We never receive or store your card number, UPI ID, CVV or bank credentials — those go directly to Razorpay. |
| Consent record | The fact that you consented to a teleconsultation and to these policies, the version you agreed to, the timestamp and the IP address used. This is kept as proof of consent, as the DPDP Act requires. |
| Technical | IP address and basic request logs, used for security, rate limiting and fraud prevention. |
We do not use advertising trackers, analytics profiling or third-party marketing pixels on this site.
3. Why we use it, and on what basis
| Purpose | Basis |
|---|---|
| To schedule, deliver and record your consultation, and to issue your summary and prescription | Your consent, given at booking |
| To send booking confirmations, calendar invites, appointment reminders and follow-up reminders | Your consent; these are service messages, not marketing |
| To take payment and issue refunds | Performance of the service you asked for |
| To keep clinical case records and financial records | Legal and professional obligations of a registered practitioner and under tax law |
| To keep the service secure and prevent abuse | Legitimate use as permitted under the DPDP Act |
We do not use your data to build profiles, to advertise to you, or for any purpose you have not been told about here.
4. Who else sees it
Your health information is available to the consulting dentist and to no other patient or third party. We share limited data with the following processors, strictly to run the service:
- Razorpay — your name, email, phone and the amount, to process payment and refunds.
- Google (Calendar and Meet) — your name, email and appointment time, to create the meeting and send the calendar invite. The consultation itself takes place on Google Meet.
- Our email provider — to deliver confirmations, reminders and your consultation summary.
- Our hosting and database providers — who store the data on our behalf under contract.
We may disclose data where we are legally required to, for example under a court order or a lawful direction from a government agency. We do not sell or rent personal data to anyone, ever.
5. Where it is stored
Data is stored in managed cloud infrastructure. Some of our processors, including Google and our hosting provider, may process data outside India in accordance with their own contractual and security commitments. The DPDP Act permits such transfers except to countries specifically restricted by the Central Government, and we will comply with any such restriction notified.
6. How long we keep it
| Data | Retention |
|---|---|
| Account profile and medical history | Until you erase your account |
| Clinical records of a consultation that took place (history, findings, advice, prescription) | Retained as a professional record. If you erase your account, these are kept in de-identified form — everything identifying you is deleted. |
| Payment and refund records | As required under tax and accounting law, then deleted or de-identified |
| Consent records | For as long as the related record is retained, as evidence of consent |
| Sign-in codes | Deleted automatically 10 minutes after they are issued |
| Abandoned bookings that were never paid for | Retained briefly for payment reconciliation, then cleared |
7. Your rights
As a Data Principal under the DPDP Act, 2023, you have the right to:
- Access — get a summary of the data we hold and how it is processed. Use Download my data in your account for an immediate copy.
- Correction and completion — fix anything inaccurate. You can edit your profile and medical history yourself at any time.
- Erasure — have your personal data deleted, subject to the retention we are legally required to maintain (see section 6). Use Erase my account in your account.
- Withdraw consent — as easily as you gave it. Withdrawing consent stops future processing; it does not undo processing already carried out lawfully, and it means we can no longer provide consultations to you.
- Grievance redressal — raise a complaint with our Grievance Officer, who must respond within the prescribed period. See the Grievance Redressal page.
- Nomination — nominate a person to exercise your rights in the event of your death or incapacity. Write to our Grievance Officer to record a nominee.
If you are not satisfied with our response, you may complain to the Data Protection Board of India once it is operational, and you retain your remedies under the Consumer Protection Act, 2019.
8. Children
Accounts are for adults. A consultation for anyone under 18 must be booked and consented to by a parent or lawful guardian, who must be present for the call. We do not knowingly process a child's personal data without verifiable parental consent, and we never use a child's data for tracking or targeted advertising. If you believe a child's data has been given to us without such consent, contact our Grievance Officer and we will delete it.
9. How we protect it
- All traffic is encrypted in transit over HTTPS.
- Passwords, where set, are stored only as salted bcrypt hashes. Sign-in codes are stored only as hashes and expire in 10 minutes.
- Session cookies are HTTP-only and marked Secure in production, so they cannot be read by scripts.
- Access to health information is limited to the consulting dentist through an authenticated console.
- Rate limiting and request validation protect the sign-in, booking and payment endpoints.
- Payment credentials never touch our systems — they go directly to a PCI-DSS compliant payment gateway.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board and affected users as required under the DPDP Act.
10. Cookies
We use only what is strictly necessary: a session cookie to keep you signed in, and a separate one for the dentist's console. There are no advertising or analytics cookies. See the Cookie Policy.
11. Changes to this notice
If we change this notice materially we will update the version number and date at the top, and record the version you agreed to against your account and each booking.
12. Contact
For any question about this notice or to exercise a right, contact our Grievance Officer using the details on the Grievance Redressal page.