🔐

Your patient data is safe with us

We treat patient data the same way you treat your patients — with complete care, privacy, and respect. Here is exactly how we protect it.

✅ Encrypted at rest & in transit ✅ Daily automated backups ✅ Role-based access control ✅ Full audit trail ✅ DPDP Act compliant

How we protect your data

Security is not an afterthought at DentalCarePro — it is built into every layer of the platform.

🔐

Encrypted in Transit & at Rest

All data is transmitted over HTTPS/TLS. Patient records, invoices, and clinical notes are encrypted at rest on our servers.

🏗️

Enterprise Cloud Infrastructure

DentalCarePro runs on enterprise-grade cloud infrastructure with 99.9% uptime SLA, automatic failover, and redundant storage.

🔒

Multi-Tenant Data Isolation

Every clinic's data is completely isolated at the database level. No clinic can ever see another clinic's patients, records, or billing.

👥

Role-Based Access Control

Assign doctors, receptionists, and admins with precise permissions. Staff can only access what they need for their role.

📋

Full Audit Trail

Every action — record created, invoice edited, appointment changed — is logged with the user, timestamp, and IP address.

💾

Automated Daily Backups

Your data is backed up automatically every day. We retain backups for 30 days, with point-in-time recovery available.

Who can see what

Fine-grained role-based permissions mean your staff only see what they need to do their job.

Role What they can access
Clinic Owner Full access to all modules, settings, billing, and staff management
Doctor Patient records, appointments, treatment plans, and clinical notes
Receptionist Appointments, patient registration, billing, and OPD queue
Manager Day-to-day operations across all modules — patients, billing, inventory, reports
Custom roles Configurable — assign exactly the permissions each staff member needs

Staff access is revoked immediately when removed from a clinic — no waiting, no delays.

🤝

Your data. Your control. Always.

We are only the custodians of your patient data — not the owners. You can export, move, or delete it at any time.

  • Export all patient records, billing history, and reports as Excel or PDF at any time
  • Request complete data deletion — we will remove all your clinic data within 7 business days
  • Your patient data is never sold, shared with advertisers, or used for any purpose other than running your clinic
  • No third-party analytics tools have access to your patient data
  • You own your data. We are only the custodians.

Compliance

🇮🇳

DPDP Act 2023 (India)

Compliant with India's Digital Personal Data Protection Act. Patient consent is collected at registration. Data is processed only for clinic management purposes.

🌍

International Clinics

For clinics outside India, we follow the data protection principles of your country. Contact us if you have specific compliance requirements for your region.

🔍

Audit Trail

Every data change — who did it, when, from which device — is logged and accessible to the clinic owner. Useful for compliance inspections and staff accountability.

🔔

Breach Notification

In the unlikely event of a security incident, we will notify affected clinics within 72 hours and provide a full incident report as required by law.

Security FAQs

Where is my clinic's data stored? +
Your data is stored on secure cloud servers. Authentication is handled by Supabase (SOC 2 Type II certified). Files and documents are stored on AWS S3 with server-side encryption.
Who at DentalCarePro can see my patient data? +
Only authorised engineers with a specific business need (e.g., debugging a support issue you reported) can access data, and only with your permission. All internal access is logged.
What happens to my data if I cancel? +
Your data is retained for 30 days after cancellation so you can export it. After 30 days, it is permanently deleted from our servers. You can also request immediate deletion.
Is DentalCarePro compliant with data protection laws? +
Yes. We are compliant with India's Digital Personal Data Protection (DPDP) Act 2023. For clinics outside India, we follow the data protection principles of the respective country.
Can my staff access data from a previous clinic they worked at? +
No. Access is completely scoped to the clinic. When a staff member is removed from a clinic, their access is immediately revoked across all devices.
What if there's a security breach? +
We will notify affected clinics within 72 hours of becoming aware of any security incident, in line with data protection regulations. We maintain an incident response plan and conduct regular security reviews.

Have a security concern?

Found a vulnerability or have a specific compliance question? We respond to all security reports within 24 hours.

Chat with us on WhatsApp →