Privacy Policy & Data Protection Notice

Version 2026-08-13 · Last updated 13 August 2026

This notice explains what personal data we collect when you use dentalxpert.in, why we collect it, how long we keep it and what you can ask us to do with it. It is issued as a notice under section 5 of the Digital Personal Data Protection Act, 2023 and also meets the requirements of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

The short version. We collect only what is needed to run your consultation. Your health information is seen by your dentist and no one else. We never sell your data, never use it for advertising, and you can download or erase it yourself from your account at any time.

1. Who is responsible for your data

DentalXpert is the Data Fiduciary for the personal data described here. Our legal name, address and contact details are on the Contact page. Questions about this notice, and requests about your data, go to our Grievance Officer — details on the Grievance Redressal page.

2. What we collect

CategoryWhat it includes
Identity & contactName, email address, mobile number. Optionally date of birth, gender, city, state and pincode if you add them to your profile.
Health informationThe dental concern you describe, symptom duration and pain score, drug allergies, medicines you take, medical conditions, tobacco use, pregnancy status, and the dentist's findings, advice and prescription. This is sensitive personal data or information under the SPDI Rules, 2011.
Booking & paymentSlot, booking reference, amount, Razorpay order/payment/refund identifiers, payment status. We never receive or store your card number, UPI ID, CVV or bank credentials — those go directly to Razorpay.
Consent recordThe fact that you consented to a teleconsultation and to these policies, the version you agreed to, the timestamp and the IP address used. This is kept as proof of consent, as the DPDP Act requires.
TechnicalIP address and basic request logs, used for security, rate limiting and fraud prevention.

We do not use advertising trackers, analytics profiling or third-party marketing pixels on this site.

3. Why we use it, and on what basis

PurposeBasis
To schedule, deliver and record your consultation, and to issue your summary and prescriptionYour consent, given at booking
To send booking confirmations, calendar invites, appointment reminders and follow-up remindersYour consent; these are service messages, not marketing
To take payment and issue refundsPerformance of the service you asked for
To keep clinical case records and financial recordsLegal and professional obligations of a registered practitioner and under tax law
To keep the service secure and prevent abuseLegitimate use as permitted under the DPDP Act

We do not use your data to build profiles, to advertise to you, or for any purpose you have not been told about here.

4. Who else sees it

Your health information is available to the consulting dentist and to no other patient or third party. We share limited data with the following processors, strictly to run the service:

  • Razorpay — your name, email, phone and the amount, to process payment and refunds.
  • Google (Calendar and Meet) — your name, email and appointment time, to create the meeting and send the calendar invite. The consultation itself takes place on Google Meet.
  • Our email provider — to deliver confirmations, reminders and your consultation summary.
  • Our hosting and database providers — who store the data on our behalf under contract.

We may disclose data where we are legally required to, for example under a court order or a lawful direction from a government agency. We do not sell or rent personal data to anyone, ever.

5. Where it is stored

Data is stored in managed cloud infrastructure. Some of our processors, including Google and our hosting provider, may process data outside India in accordance with their own contractual and security commitments. The DPDP Act permits such transfers except to countries specifically restricted by the Central Government, and we will comply with any such restriction notified.

6. How long we keep it

DataRetention
Account profile and medical historyUntil you erase your account
Clinical records of a consultation that took place (history, findings, advice, prescription)Retained as a professional record. If you erase your account, these are kept in de-identified form — everything identifying you is deleted.
Payment and refund recordsAs required under tax and accounting law, then deleted or de-identified
Consent recordsFor as long as the related record is retained, as evidence of consent
Sign-in codesDeleted automatically 10 minutes after they are issued
Abandoned bookings that were never paid forRetained briefly for payment reconciliation, then cleared

7. Your rights

As a Data Principal under the DPDP Act, 2023, you have the right to:

  • Access — get a summary of the data we hold and how it is processed. Use Download my data in your account for an immediate copy.
  • Correction and completion — fix anything inaccurate. You can edit your profile and medical history yourself at any time.
  • Erasure — have your personal data deleted, subject to the retention we are legally required to maintain (see section 6). Use Erase my account in your account.
  • Withdraw consent — as easily as you gave it. Withdrawing consent stops future processing; it does not undo processing already carried out lawfully, and it means we can no longer provide consultations to you.
  • Grievance redressal — raise a complaint with our Grievance Officer, who must respond within the prescribed period. See the Grievance Redressal page.
  • Nomination — nominate a person to exercise your rights in the event of your death or incapacity. Write to our Grievance Officer to record a nominee.

If you are not satisfied with our response, you may complain to the Data Protection Board of India once it is operational, and you retain your remedies under the Consumer Protection Act, 2019.

8. Children

Accounts are for adults. A consultation for anyone under 18 must be booked and consented to by a parent or lawful guardian, who must be present for the call. We do not knowingly process a child's personal data without verifiable parental consent, and we never use a child's data for tracking or targeted advertising. If you believe a child's data has been given to us without such consent, contact our Grievance Officer and we will delete it.

9. How we protect it

  • All traffic is encrypted in transit over HTTPS.
  • Passwords, where set, are stored only as salted bcrypt hashes. Sign-in codes are stored only as hashes and expire in 10 minutes.
  • Session cookies are HTTP-only and marked Secure in production, so they cannot be read by scripts.
  • Access to health information is limited to the consulting dentist through an authenticated console.
  • Rate limiting and request validation protect the sign-in, booking and payment endpoints.
  • Payment credentials never touch our systems — they go directly to a PCI-DSS compliant payment gateway.

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board and affected users as required under the DPDP Act.

10. Cookies

We use only what is strictly necessary: a session cookie to keep you signed in, and a separate one for the dentist's console. There are no advertising or analytics cookies. See the Cookie Policy.

11. Changes to this notice

If we change this notice materially we will update the version number and date at the top, and record the version you agreed to against your account and each booking.

12. Contact

For any question about this notice or to exercise a right, contact our Grievance Officer using the details on the Grievance Redressal page.