Back to home

Privacy Policy

Last updated: January 2026 · Version 1.0

1. Introduction

DentalAI ("we", "us", "the Platform") is committed to protecting your personal data and health information. This Privacy Policy explains how we collect, use, store, and protect your data in accordance with international privacy laws.

This Privacy Policy complies with:

  • GDPR — EU General Data Protection Regulation (Regulation 2016/679)
  • ePrivacy Directive — Directive 2002/58/EC
  • UK GDPR & Data Protection Act 2018
  • Council of Europe Convention 108+
  • National privacy laws of the user's country of residence

2. Data Controller

Entity: Dent-Selfy Dental Clinic

Location: Baku, Azerbaijan

Email (DPO): artipylon@gmail.com

Contact: +90 532 059 2605

For any questions about your data or to exercise your GDPR rights, contact our Data Protection Officer (DPO) at the email above.

3. Legal Basis for Processing (GDPR Art. 6 & Art. 9)

We process your data on the following legal grounds:

  • Explicit Consent (Art. 9(2)(a)) — for processing health data (dental images, symptoms)
  • Contract Performance (Art. 6(1)(b)) — to provide AI analysis service
  • Legal Obligation (Art. 6(1)(c)) — for record keeping
  • Legitimate Interest (Art. 6(1)(f)) — for fraud prevention, security

4. Data We Collect

4.1 Account Information

  • First and Last Name
  • Email address (encrypted with AES-256-GCM)
  • Phone number (encrypted)
  • Age, Country of residence
  • Preferred language

4.2 Health Data (Special Category - GDPR Art. 9)

  • Dental photographs (encrypted, temporarily stored)
  • Patient symptoms (pain, sensitivity, etc.)
  • Pain level (0-10 scale)
  • Patient-marked affected teeth (FDI notation)
  • Treatment goals and additional notes
  • AI analysis results and recommendations

4.3 Technical Data

  • IP address (for security audit logs)
  • Browser type and version
  • Device information
  • Login timestamps

5. How We Use Your Data

  • AI Dental Analysis: Your images and symptoms are processed by AI to provide an indicative analysis
  • Clinic Communication: Optional WhatsApp redirect to connect you with Dent-Selfy Clinic
  • Account Management: Authentication, security, account recovery
  • Service Improvement: Aggregated, anonymized analytics
  • Legal Compliance: Audit logs for regulatory requirements

6. Data Sharing with Third Parties

We share your data with the following processors, all of whom are GDPR-compliant:

⚠ Important: International Data Transfers

Your data may be transferred outside the EEA. We use Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection.

  • OpenAI (USA): Dental images sent for AI analysis under SCCs. Data is not used for AI training.
  • SendGrid (USA): Email delivery for verification and notifications
  • DigitalOcean (EU - Frankfurt): Primary data storage in EEA
  • Dent-Selfy Clinic: Only if you initiate WhatsApp contact, your selected information is shared

We do not sell your data to advertisers or third parties.

7. Your Rights Under GDPR

You have the following rights regarding your personal data:

Right to Access (Art. 15)
Request a copy of your data
Right to Rectification (Art. 16)
Correct inaccurate data
Right to Erasure (Art. 17)
"Right to be forgotten"
Right to Restrict Processing (Art. 18)
Limit how we use your data
Right to Data Portability (Art. 20)
Receive data in machine-readable format
Right to Object (Art. 21)
Object to certain processing
Right to Withdraw Consent
At any time
Right to Lodge a Complaint
With supervisory authority

To exercise any of these rights, email us at artipylon@gmail.com. We will respond within 30 days as required by GDPR Art. 12(3).

8. Data Retention

  • Dental images: Retained for 12 months, then automatically deleted
  • Analysis results: Retained as long as your account is active
  • Account data: Until you request deletion
  • Audit logs: 24 months for security and legal compliance
  • Deleted data: Permanently removed within 30 days of deletion request

9. Security Measures

We implement industry-standard security measures:

  • Encryption at rest: AES-256-GCM for sensitive data
  • Encryption in transit: TLS 1.3
  • Password hashing: Argon2id
  • Access controls: Role-based with multi-factor where applicable
  • Audit logging: All data access tracked
  • Regular security assessments

10. Children's Privacy

Our service is not intended for users under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.

11. Cookies and Tracking

We use essential cookies and local storage that the service needs to work: sign-in (JWT tokens), security, your language preference and a record of your cookie choice. These are always active.

Only with your consent, we also use: (1) analytics cookies from Google Analytics 4 to understand how our public pages are used; and (2) marketing cookies from Meta (Meta Pixel) and Google Ads to measure the effectiveness of our advertising. These tools are not loaded at all until you consent, and you can accept or reject each category separately.

Even with your consent, we never run analytics or advertising tools on pages related to your dental analysis, results, dashboard or account, and we never share your photos, symptoms, analysis results or any other health information with analytics or advertising providers.

You can change or withdraw your consent at any time via “Cookie settings” at the bottom of every page. When you withdraw consent, the related cookies are deleted from your browser. We ask for your choice again after 12 months.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users at least 30 days before taking effect. Continued use of the service after changes constitutes acceptance.

13. Supervisory Authority

If you believe your rights have been violated, you have the right to lodge a complaint with the supervisory authority in your country:

  • EU: Your national Data Protection Authority (DPA)
  • UK: Information Commissioner's Office (ICO)
  • Azerbaijan: Ministry of Digital Development and Transport

14. Contact Us

Data Protection Officer (DPO)

Email: artipylon@gmail.com

Response time: Within 30 days (GDPR Art. 12(3))

15. Service Providers

We use carefully selected service providers (processors) that act on our instructions and only for the purposes listed below:

  • OpenAI (United States) — AI analysis of your dental photos and answers from our AI assistant.
  • DigitalOcean (Frankfurt, EU) — hosting of our servers and database.
  • Twilio (United States) — SMS verification codes, if you choose to verify your phone number.
  • Google — sign-in with Google (if you choose it); Google Analytics and Google Ads only with your consent.
  • Meta — advertising measurement (Meta Pixel) only with your consent and never on pages about your dental analysis or account.
  • WhatsApp — only when you choose to contact the clinic; the message you send is shown to you before sending.

Where data is transferred outside the EU, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or the EU–US Data Privacy Framework.