PREAMBLE
This Privacy Policy (the "Policy") is an electronic record within the meaning of the Information Technology Act, 2000 and the rules made thereunder, as amended from time to time, and is published in accordance with the provisions of the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the rules notified thereunder, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules"), and Rule 3(1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (the "Intermediary Rules"). This Policy does not require any physical or digital signature.
This Policy is issued by VILNEK PRIVATE LIMITED, a private limited company incorporated under the laws of India, bearing Corporate Identification Number U72900GJ2020PTC113166 and Goods and Services Tax Identification Number 24AAHCV3518J1Z8, having its registered office at Vilnekplex, Rajmandir Complex, Aaimata Road, Surat, Gujarat 395010, India (the "Company", "we", "us" or "our"), which owns and operates the platform known as iDentist.Live.
This Policy sets out the manner in which personal data is collected, used, stored, disclosed, retained, protected and erased in connection with the Platform, and the rights and remedies available to Data Principals. It shall be read together with, and forms an integral part of, the Terms of Service. By ticking the acceptance box on the sign-in screen, or by otherwise accessing or using the Platform, the User signifies that the User has read, understood and accepted this Policy.
1. DEFINITIONS AND INTERPRETATION
1.1 In this Policy, unless the context otherwise requires:
(a) "Platform" means the software, websites (including identist.live and its sub-domains), web applications, mobile and desktop applications, application programming interfaces and related services made available by the Company under the name iDentist.Live;
(b) "Workspace" means an account of an organisation on the Platform, being a dental clinic or practice ("Clinic"), a dental laboratory ("Laboratory"), a supplier of dental goods ("Supplier"), or an educational account of a student or institution ("Student Workspace");
(c) "User" means any natural person who accesses or uses the Platform, including the owner, administrator, dentist, staff member or other member of a Workspace, a patient using the patient portal, and a student;
(d) "Patient" means a natural person whose health or treatment records are entered into the Platform by a Clinic;
(e) "Personal Data", "Data Principal", "Data Fiduciary", "Data Processor", "Processing", "Consent Manager" and "Personal Data Breach" shall have the meanings assigned to them under the DPDP Act;
(f) "Sensitive Personal Data or Information" shall have the meaning assigned to it under Rule 3 of the SPDI Rules and includes, without limitation, physical, physiological and mental health condition, medical records and history, and biometric information;
(g) "Clinical Records" means all records of a Patient maintained by a Clinic on the Platform, including demographic details, medical and allergy history, findings, dental charts, diagnoses, treatment plans, procedures, prescriptions, consents, clinical images, radiographs, imaging studies, appointments, charges and payments;
(h) "Applicable Law" means all laws, statutes, ordinances, rules, regulations, notifications, guidelines, directions and orders of any governmental or regulatory authority in India, as amended or re-enacted from time to time.
1.2 Headings are for convenience only and shall not affect interpretation. Words importing the singular include the plural and vice versa. The words "include" and "including" shall be construed without limitation.
2. IDENTITY AND CAPACITY OF THE COMPANY
2.1 Clinical Records. In respect of Clinical Records and other Personal Data of Patients entered into the Platform by or on behalf of a Clinic, the Clinic determines the purpose and means of Processing and is the Data Fiduciary. The Company Processes such Personal Data solely on behalf of, and on the documented instructions of, the Clinic, and acts as a Data Processor within the meaning of the DPDP Act. A Patient who wishes to exercise any right in respect of Clinical Records shall in the first instance address the Clinic concerned, and the Company shall render all reasonable assistance to the Clinic in responding thereto.
2.2 Account and Platform Data. In respect of Personal Data relating to the creation and administration of User accounts and Workspaces, sign-in and security records, platform profiles, subscriptions, communications with the Company, and the operation and security of the Platform, the Company is the Data Fiduciary.
2.3 Laboratories and Suppliers. Each Laboratory and Supplier is the Data Fiduciary of the business records it maintains on the Platform, and the Company acts as its Data Processor in respect thereof, save as provided in Clause 2.2.
3. SCOPE AND APPLICABILITY
3.1 This Policy applies to all Personal Data Processed through the Platform within the territory of India, and to Personal Data Processed outside India in connection with the offering of the Platform to Data Principals within India.
3.2 This Policy does not apply to the practices of third parties whose services a User may choose to access through the Platform (including WhatsApp, Google, payment applications, and third-party websites linked from the Platform), whose own privacy terms shall govern.
4. CATEGORIES OF PERSONAL DATA PROCESSED
4.1 Identity and account data: name, mobile number, electronic mail address, Google account identifier (where the User elects to sign in with Google), photograph (optional), role and membership of Workspaces, and a one-way keyed hash of the verified mobile number or electronic mail address used for look-up.
4.2 Professional and organisational data: for dentists, the State Dental Council or Dental Council of India registration number, qualification, college and specialisation; for Workspaces, the name of the organisation, owner or administrator, address, city, state, postal code, telephone, electronic mail, website, Goods and Services Tax Identification Number and logo; for Students, programme, year of study, specialisation and institution.
4.3 Clinical Records as defined in Clause 1.1(g), entered by a Clinic.
4.4 Biometric data: where a Clinic enables the Face ID feature and the Patient (or the Patient's parent or lawful guardian) has given express consent, a mathematical facial template derived from a photograph of the Patient (Clause 8).
4.5 Orders and commercial data: work orders and supply orders exchanged between Clinics, Laboratories and Suppliers, including case references, items, prices, status, delivery and payment records. Work orders identify a case by reference and do not disclose the Patient's name to the Laboratory.
4.6 Sign-in and security data: each sign-in attempt, successful or unsuccessful, and each sign-out, together with the method used, date and time, Internet Protocol address, the approximate city, region and country derived therefrom, device type, operating system, browser, application version, an identifier generated for each installation of the application, the version of these terms accepted, and the places from which an installation was used on each day; and, when any person opens the demonstration mode of the Platform, the sample role opened, the date and time, the Internet Protocol address, the approximate city, region and country derived therefrom, and the device and browser, without any account or name (Clause 16).
4.7 Payment data: subscription records, order and payment references and status received from the Company's payment service provider. The Company does not receive, store or Process card numbers, card security codes, net-banking credentials or UPI personal identification numbers.
4.8 Learning data: for Users of the Knowledge-base, reading progress, bookmarks, flashcard progress, study time and the number of chapters accessed per day.
4.9 Communications: correspondence addressed to the Company, grievances and support requests.
4.10 Usage statistics: aggregate daily counts of events (for example, the number of times an application was opened on a given day), which do not identify any natural person and are not linked to any Internet Protocol address, device identifier or account.
5. SOURCES OF PERSONAL DATA
5.1 Personal Data is obtained (a) directly from the Data Principal; (b) from the Clinic, Laboratory, Supplier or institution of which the Data Principal is a member or Patient; (c) automatically, from the device and network connection used to access the Platform; (d) from Google, where the User elects to sign in with Google, limited to the account identifier, name and electronic mail address that Google confirms; and (e) from the Company's payment service provider, limited to payment status and references.
6. PURPOSES AND LAWFUL GROUNDS OF PROCESSING
6.1 The Company Processes Personal Data only for lawful purposes, namely:
(a) to provide, operate, maintain and support the Platform and each of its features requested by the User;
(b) to verify identity at sign-in by a one-time code sent by short message service or by Google sign-in, and to secure accounts, Workspaces and devices;
(c) to enable a Clinic to maintain Clinical Records, schedule appointments, issue prescriptions, record charges and payments, generate reports, communicate with its Patients and grant Patients access to their records through the patient portal;
(d) to enable work orders and supply orders between Clinics, Laboratories and Suppliers;
(e) to administer subscriptions, collect fees and comply with tax and accounting obligations;
(f) to detect, prevent and investigate fraud, misuse, unauthorised access, security incidents and violations of the Terms of Service;
(g) to administer the Platform, including onboarding, account support and the preparation of aggregate, non-identifying statistics of the use of the Platform;
(h) to comply with Applicable Law, the orders of courts and the lawful directions of governmental authorities.
6.2 The lawful grounds for such Processing are: the consent of the Data Principal given under Section 6 of the DPDP Act; the legitimate uses specified in Section 7 of the DPDP Act, including use for the purpose for which the Data Principal has voluntarily provided Personal Data, compliance with law and judgments, and responding to medical emergencies; and, in respect of Clinical Records, the instructions of the Clinic as Data Fiduciary under its own lawful basis.
6.3 The Company does not sell Personal Data, does not share Personal Data with advertisers, does not undertake tracking, behavioural monitoring or targeted advertising, and does not use identifiable Clinical Records to train artificial-intelligence models.
7. NOTICE, CONSENT AND WITHDRAWAL
7.1 At the time of sign-in, each User is presented with this Policy and the Terms of Service and is required to signify acceptance by ticking an acceptance box before a one-time code is sent or Google sign-in is initiated. The version accepted, together with the date and time of acceptance, is recorded.
7.2 Consent given under this Policy is free, specific, informed, unconditional and unambiguous, and is limited to the Personal Data necessary for the specified purpose.
7.3 A Data Principal may withdraw consent at any time by written communication to the Grievance Officer or by erasing the account through the Platform. Withdrawal shall not affect the lawfulness of Processing undertaken before withdrawal, nor Processing that is permitted without consent under Applicable Law, and the consequences of withdrawal (including the inability to use the Platform) shall be borne by the Data Principal.
7.4 The obtaining of consent of Patients for the Processing of Clinical Records, including consent for treatment, for clinical photography and for biometric enrolment, is the responsibility of the Clinic as Data Fiduciary. The Platform provides the means of recording such consent.
8. SENSITIVE PERSONAL DATA AND BIOMETRIC DATA
8.1 Clinical Records and biometric data constitute Sensitive Personal Data or Information and are Processed with the highest standard of care described in Clause 12.
8.2 The Face ID feature is disabled by default and may be enabled only by the administrator of a Clinic. A facial template is created only where the Patient's recorded consent expressly permits facial data. The facial template is computed on the device of the Clinic; it is stored only within the Patient's encrypted record, so that the devices of the same Clinic may recognise the Patient; it is never disclosed to any other Clinic, Laboratory, Supplier or third party, is never made available to the patient portal, and is never used to identify any person outside the Clinic that enrolled it. Withdrawal of consent for facial data causes the template to be erased.
9. CHILDREN AND PERSONS WITH DISABILITY
9.1 The Platform is not directed at children for the purpose of creating accounts. Where Clinical Records of a person below the age of eighteen years, or of a person with disability who has a lawful guardian, are entered by a Clinic, the Clinic shall obtain the verifiable consent of the parent or lawful guardian in accordance with Section 9 of the DPDP Act and the rules made thereunder.
9.2 The Company does not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.
10. DISCLOSURE OF PERSONAL DATA
10.1 Within a Workspace. Personal Data is disclosed to the members of a Workspace only to the extent permitted by the role assigned by the Workspace's administrator.
10.2 Between Workspaces. Personal Data is disclosed by one Workspace to another only upon the deliberate act of a User (for example, the sending of a work order to a Laboratory, which carries a case reference but not the Patient's name, or the placing of a supply order).
10.3 Data Processors engaged by the Company. The Company engages the following categories of Data Processors, each bound by contract to Process Personal Data only on the Company's instructions and to maintain appropriate security safeguards:
(a) Amazon Web Services (AWS) — hosting of the database, encrypted files, backups and key-management infrastructure in the Mumbai region, with backup copies in the Hyderabad region, India;
(b) Cloudflare — secure network connection between devices and the Company's servers, protection against attacks, and the derivation of the approximate location of an Internet Protocol address;
(c) Walkover Web Solutions Private Limited (MSG91) — transmission of one-time sign-in codes by short message service in accordance with the regulations of the Telecom Regulatory Authority of India;
(d) Razorpay — collection of subscription fees by a payment aggregator regulated by the Reserve Bank of India;
(e) Google — confirmation of the identity of a User who elects to sign in with Google; and, where the Company commissions it, a standby copy of the database hosted in India.
10.4 Services opened by the User. Where a User elects to open a message in WhatsApp, to pay or receive payment through a Unified Payments Interface application, or to use the voice-input facility of the User's browser or device, the relevant data passes to the provider of that service under its own terms, and not through the Company. In particular, where a User uses voice input, or selects a network voice for reading text aloud (including in the clinical assistant and the Knowledge-base), the spoken words or the text read may be processed by the speech service of the provider of the User's browser or device. The clinical assistant itself operates on the User's device and does not transmit Clinical Records to any artificial-intelligence service.
10.5 Legal disclosure. The Company may disclose Personal Data where required by Applicable Law, by an order of a court or tribunal, or by a lawful request of a governmental agency authorised under Applicable Law, including under Section 69 of the Information Technology Act, 2000 and the directions of the Indian Computer Emergency Response Team (CERT-In). Save where prohibited by law, the Company shall notify the affected Clinic of any such disclosure of Clinical Records.
10.6 Corporate transactions. In the event of a merger, amalgamation, restructuring or transfer of the whole or part of the business of the Company, Personal Data may be transferred to the successor entity, which shall be bound by obligations no less protective than this Policy.
11. LOCATION OF STORAGE AND TRANSFER
11.1 Personal Data, including all Clinical Records, is stored in data centres located in India. Encrypted backup copies are maintained in a second region in India.
11.2 Data in transit may pass through the global network of the Company's network provider, in encrypted form, solely for the purpose of delivery. Identity confirmation by Google and messages opened by Users in third-party services may be Processed by those providers outside India under their own terms.
11.3 The Company shall not transfer Personal Data to any country or territory notified as restricted by the Central Government under Section 16 of the DPDP Act.
12. SECURITY SAFEGUARDS
12.1 The Company maintains reasonable security practices and procedures commensurate with the nature of the Personal Data, in compliance with Rule 8 of the SPDI Rules and Section 8(5) of the DPDP Act, including:
(a) encryption of Clinical Records and business records on the User's device before transmission, by AES-256-GCM, under a separate data key for each Workspace, such that the Company's servers store only the encrypted form, each sealed record being bound to its own location so that it cannot be moved or substituted;
(b) protection of the data keys by a master key held in a managed secrets service; disclosure that, because the Company's infrastructure holds the key-protection material in order to release keys to authorised devices, the Platform is not a "zero-knowledge" service;
(c) release of keys only to signed-in Users of the Workspace on devices that have not been revoked; remote sign-out and wiping of a lost device's copy, with rotation of the Workspace keys;
(d) enforcement of access on the Company's servers by role and Workspace membership, with every addition, alteration and deletion of a record logged by the server;
(e) encryption of the copy of data kept on a device for offline use, and sealing of the browser's copy of keys by a non-extractable key of the browser;
(f) encryption of all data in transit by Transport Layer Security; database encryption at rest; restriction of access to production systems to authorised personnel on a need-to-know basis; and
(g) one-time sign-in codes stored only as keyed one-way hashes, valid for ten minutes, limited in attempts and in number per day.
12.2 No method of transmission or storage is wholly secure. A User is responsible for the security of the User's devices, mobile number, Google account and electronic mail, and shall promptly inform the Company of any suspected compromise.
13. RETENTION AND ERASURE
13.1 Clinical Records are retained for so long as the Clinic maintains its Workspace and thereafter for such period as the Clinic instructs or as Applicable Law requires for medical records. The Company shall not erase Clinical Records for reason of non-payment of subscription fees.
13.2 Sign-in and device records are retained for one (1) year from the date of the event and are thereafter erased automatically.
13.3 Account data is retained while the account subsists. A User may erase the User's account at any time through the Platform; upon erasure, the User's personal account data is erased or anonymised, save where retention is required by Applicable Law or where the data forms part of the records of a Workspace (for example, the audit log of a Clinic's records), which the Workspace is entitled to retain.
13.4 Payment, tax and accounting records are retained for the period prescribed under the Companies Act, 2013, the Central Goods and Services Tax Act, 2017 and other Applicable Law.
13.5 Usage statistics are retained only as aggregate daily totals.
13.6 Upon the expiry of the applicable period, Personal Data is erased, unless its retention is necessary for compliance with Applicable Law, in accordance with Section 8(7) of the DPDP Act.
14. RIGHTS OF DATA PRINCIPALS
14.1 Subject to the DPDP Act, a Data Principal has the right:
(a) to obtain a summary of the Personal Data Processed and of the Processing activities, and the identities of Data Fiduciaries and Data Processors with whom it has been shared (Section 11);
(b) to the correction, completion, updating and erasure of Personal Data (Section 12);
(c) to have readily available means of grievance redressal (Section 13);
(d) to nominate any other individual to exercise these rights in the event of death or incapacity (Section 14); and
(e) to withdraw consent (Section 6(4)).
14.2 Requests in respect of Clinical Records shall be addressed to the Clinic concerned (Clause 2.1). Other requests may be addressed to the Grievance Officer (Clause 22). The Company may verify the identity of the person making a request before acting upon it.
15. DUTIES OF DATA PRINCIPALS
15.1 Every Data Principal shall comply with the duties prescribed by Section 15 of the DPDP Act, including the duty not to impersonate another person, not to suppress material information while providing Personal Data, not to register a false or frivolous grievance or complaint, and to furnish only verifiably authentic information when exercising the right to correction or erasure.
16. SIGN-IN RECORDS, DEVICES AND ACTIVITY LOGS
16.1 For the security of Workspaces and of Clinical Records, the Platform records the information described in Clause 4.6. A User may view the User's own sign-in history. The administrators of a Workspace may view the sign-in records and devices of the members of that Workspace and may sign out any device. The administrators of a Clinic may view the dates, devices and approximate locations at which its Patients opened the patient portal.
16.2 Each opening of the demonstration mode is recorded as described in Clause 4.6, for the purposes of securing the Platform against abuse and of measuring, in aggregate, the number of persons who try the Platform and the places from which they do so. Such records identify no account, are retained for one (1) year, and are available only to the Company's internal administration.
16.3 Every addition, alteration and deletion of a record of a Workspace is logged by the Company's server with the identity of the User, the time, the device and the fields affected, without the content of encrypted records. Such logs form part of the records of the Workspace.
16.4 The organisation profile of a Workspace and the profile of a User, as described in Clause 4.2, are made available to the Company's internal administration for the purposes of account support, onboarding and aggregate statistics. Clinical Records and the private business data of a Workspace do not form part thereof.
17. COOKIES, LOCAL STORAGE AND OFFLINE COPIES
17.1 The Platform uses the storage of the User's browser or device to keep the User signed in, to retain the User's acceptance of these terms and preferences, and to keep an encrypted copy of the Workspace's data so that the Platform operates without an internet connection. The Platform does not use advertising cookies, cross-site tracking or third-party analytics.
17.2 Data entered while offline is stored on the device and transmitted when connectivity is restored. Data that has not been transmitted may be lost if the device is lost, reset or destroyed, and the User shall take reasonable care accordingly.
18. COMMUNICATIONS
18.1 One-time sign-in codes are sent by short message service from the registered header in accordance with the Telecom Commercial Communications Customer Preference Regulations, 2018. The Company does not send promotional messages by short message service.
18.2 Messages from a Clinic to its Patients through WhatsApp are composed in the Platform and sent by the Clinic from the Clinic's own WhatsApp account; the Company does not send, store or read such messages. The Clinic is responsible for having the Patient's consent to such communication.
19. PAYMENTS
19.1 Subscription fees payable to the Company are collected through Razorpay. The Company receives the status and references of payments but not card or bank credentials.
19.2 Where a Clinic displays a Unified Payments Interface quick-response code through the Platform, the code carries the Clinic's own UPI identifier, the amount, and a remark comprising the Patient's name and file number. The payment is made from the payer's own UPI application directly to the Clinic's bank account. The Company is not a party to, does not receive, and does not hold such payment, and records only the Clinic's entry that the payment was made and, thereafter, the Clinic's verification of it.
20. KNOWLEDGE-BASE AND CONTENT PROTECTION
20.1 To protect the Company's educational content against unauthorised copying, each page of the Knowledge-base displayed to a User bears a faint watermark containing the User's name and mobile number, access is granted through short-lived links issued only to signed-in Users, and the number of chapters accessed per day is limited and recorded. Unusual volumes of access may be reviewed by the Company.
21. PERSONAL DATA BREACH
21.1 In the event of a Personal Data Breach, the Company shall, without delay, intimate the Data Protection Board of India and each affected Data Principal in the form and manner prescribed under Section 8(6) of the DPDP Act and the rules thereunder, report the incident to CERT-In within the period prescribed by its directions, and, where the breach concerns Clinical Records, inform the Clinic concerned, together with the measures taken to mitigate the breach.
22. GRIEVANCE REDRESSAL
22.1 In accordance with Section 8(10) and Section 13 of the DPDP Act, Rule 5(9) of the SPDI Rules and Rule 3(2) of the Intermediary Rules, the Company has designated a Grievance Officer:
The Grievance Officer, VILNEK PRIVATE LIMITED
Vilnekplex, Rajmandir Complex, Aaimata Road, Surat, Gujarat 395010, India
Electronic mail: identist@vilnek.in
Working days: Monday to Saturday, 10:00 to 18:00 IST
22.2 Every grievance shall be acknowledged within twenty-four (24) hours and resolved within fifteen (15) days of its receipt, or within such other period as Applicable Law prescribes. A Data Principal who is not satisfied with the resolution may approach the Data Protection Board of India in accordance with the DPDP Act, after exhausting the remedy before the Company.
23. AMENDMENTS
23.1 The Company may amend this Policy from time to time to reflect changes in the Platform or in Applicable Law. Each amended version shall bear a new version date. Material amendments shall be notified within the Platform, and the User may be required to accept the amended version at the next sign-in before continuing to use the Platform.
24. GOVERNING LAW AND JURISDICTION
24.1 This Policy shall be governed by and construed in accordance with the laws of India. Subject to the dispute-resolution provisions of the Terms of Service, the courts at Surat, Gujarat shall have exclusive jurisdiction.
VILNEK PRIVATE LIMITED
CIN: U72900GJ2020PTC113166 · GSTIN: 24AAHCV3518J1Z8
Registered office: Vilnekplex, Rajmandir Complex, Aaimata Road, Surat, Gujarat 395010, India
Electronic mail: identist@vilnek.in · Website: www.vilnek.in