Privacy policy
Last updated 1 October 2026 · Applies to Dental Software India by AvanceZone
What this policy covers
This policy explains what AvanceZone ("we") collects when you use Dental Software India (the "Service"), dental practice software for clinics in India, why we collect it, how long we keep it and the choices you have. It applies to the public website and to the application used by dental clinics ("workspaces") and their staff. For patient data, the clinic is the data fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDP) and we process that data as its processor, on its instructions.
Information we collect
- Clinic account data: clinic name, address, GSTIN, UPI ID, staff and dentist names, work email, phone, role and password hash.
- Patient records entered by the clinic: name, phone and WhatsApp number, age or date of birth, sex, address, ABHA number if given, medical alerts and allergies, the tooth chart, BPE and periodontal notes, treatment plans and fees, clinical notes and prescriptions, X-rays and photos, invoices, payments, EMI schedules and recall dates.
- Treatment-plan approvals: when a patient opens a plan link and accepts, the items accepted, the payment option, the typed name used as the e-consent signature, the time, IP address, browser user agent and a SHA-256 fingerprint of the consent text; and, if the patient reports a deposit, the UPI transaction reference they enter.
- Lab cases: case type, teeth, material, shade, instructions, due dates, photos and status updates, including the name a dental lab enters when it updates the case through its link.
- Visiting-consultant data: name, speciality, visiting days, split percentage and monthly payout statements.
- Messages: WhatsApp messages sent to and received from patients through the clinic's connected number, with delivery status and cost, so the clinic can see the conversation and we can bill usage.
- Usage and security data: IP address, browser type, actions taken and timestamps, used for security and the audit log.
- Website enquiries: name, clinic, phone, email and message when you fill in a contact or demo form.
Why we use it
- Patient records and approvals: so the clinic can diagnose, plan, treat, bill and follow up its patients, and prove what a patient agreed to.
- Lab cases and consultant data: so the clinic can track outside lab work and pay visiting consultants.
- Messages: to deliver plan links, appointment, EMI and recall reminders and lab-arrival messages that the clinic has chosen to send, only to patients with a WhatsApp opt-in.
- Account, usage and security data: to provide, secure and support the Service, keep the audit log and bill subscriptions and usage.
- Enquiries: to reply to you and, with your consent, send product updates. You can opt out at any time.
- Legal duties: to meet obligations under the DPDP Act 2023 and Indian tax law, and HIPAA where it applies. We never sell personal data or use patient data for advertising.
How long we keep each category
These periods are the same on our Security page and in our FAQs and guides.
| Data | Kept for | Then |
|---|---|---|
| Clinical records (patients, charts, plans, e-consents, notes, images, ledgers, EMI, lab cases, WhatsApp history) | As long as the clinic account is active | Available to export for 30 days after the account closes, then erased from live systems |
| A single patient's record, on the clinic's erasure request | Until the request | Erased from live systems within 30 days of the request (archiving a patient in the app only hides the record) |
| Audit log (who created, edited, deleted, approved or paid what, when and from which IP) | Seven years | Deleted |
| Backups | Encrypted nightly, 30-day rolling cycle | Each backup is overwritten after 30 days, so erased data leaves backups within 30 days |
| Clinic account and subscription invoices | Account life; invoices as long as Indian tax law requires (up to eight years) | Deleted |
| Website enquiries | 24 months | Deleted |
Where data lives and who processes it
Data is hosted in India. Access is limited to our staff who need it to run and support the Service, under confidentiality obligations. We use these sub-processors:
- Hosting and backups: Amazon Web Services, ap-south-1 (Mumbai) region.
- Messaging and voice: AvanceZone's Appointment Reminder App gateway, which delivers through the Meta WhatsApp Business Platform and Indian telecom operators.
- Email delivery: our transactional email provider, for sign-in, billing and system notices.
- Payments: the UPI app or payment gateway the clinic chooses. Patient deposits made by UPI go directly to the clinic's own UPI ID; a gateway only sends us a payment confirmation if the clinic connects one.
A dental lab that a clinic shares a case link with sees only that case (with a patient code, not the patient's name or phone). The current sub-processor list is also available on request at info@radiatus.com.
Your rights
You may ask to access, correct, export or erase your personal data, or withdraw consent, by emailing info@radiatus.com. Patients of a clinic should contact that clinic first; we help the clinic respond within the periods above. You may also complain to the Data Protection Board of India.
Cookies
We use a strictly necessary session cookie for logged-in users and on plan and lab links, and, if enabled, privacy-friendly analytics with IP anonymisation. No advertising cookies.
Security
TLS encryption in transit, encrypted storage, Argon2id password hashing, role-based access, rate limiting, an audit log and nightly encrypted backups. Plan and lab links use long random tokens, are excluded from search engines and can be reissued by the clinic. See our Security page.
Changes and contact
We will post changes here and notify workspace owners of material changes by email. Questions: info@radiatus.com, +91-9585160363, AvanceZone, Coimbatore, Tamil Nadu.
Related: Privacy policy · Terms of service · Refund policy · Security and compliance · Dental Software India pricing · Contact us