1. Who We Are
DentalReady is operated by Dental Ready Technologies Pty Ltd (ACN 697 960 704) ("we", "us", "our"). It is an operations, screening, and training platform for dental practices. This policy explains how we collect, use, and protect your personal information when you use our website and services at dentalready.com.au.
We handle personal information under applicable Australian privacy laws, including the Privacy Act 1988 (Cth) and Australian Privacy Principles and, where relevant, NSW health-records law. This policy also describes privacy commitments we apply through our agreements with practices.
2. Information We Collect
We collect information that you or an authorised integration provide, including:
- Account information: name, email address, and password when you register
- Profile information: role, employment details, practice affiliation, and any emergency-contact name, phone number, and relationship that an authorised user chooses to provide
- Assessment data: responses to screening questions and learning module progress
- Demo and product activity: demo-request details, approval and invitation status, the demo account linked to a requester, sign-ins and sessions, first and last activity, pages and features used, action counts, account-conversion requests, and responses to onboarding or conversion prompts. Authorised DentalReady administrators may use this information to operate the demo, provide support and understand which demos or practices are actively using the platform. Engagement reporting is designed to use activity metadata rather than expose patient or clinical content.
- Email and communication telemetry: recipient and sender addresses, subject and message content needed for delivery, message purpose or template, provider message ID, send attempts and timestamps, and status events such as accepted, delivered, delayed, bounced, complained about, link clicked or unsubscribed. For demo lifecycle email we deliberately do not subscribe to or store open events. A click event records the message and event time only; we do not retain the destination URL, IP address, browser or device data from that event. Delivery and click signals are operational cues, not definitive proof that a person read a message.
- Agreement and consent evidence: the document type, title, version, effective date, URL and content hash; the acceptance wording or action shown; date and time; user, account and practice identifiers; authority confirmation; and relevant IP address and user-agent evidence. Where you choose to receive commercial communications, we may also record the consent wording, source and time and any later unsubscribe or withdrawal.
- App and device diagnostics: sanitised first-party feature events and, when Android barcode scanning is used, Google ML Kit may collect the app package/version, device model and operating-system/build information, available ML hardware, performance metrics, and device or per-installation identifiers for diagnostics and usage analytics. Barcode images, decoded barcode values, and scan results are processed on-device and are not sent to Google by ML Kit.
- Provider-inferred network location: Service providers that support hosting, security, diagnostics or support may infer and retain a city and latitude/longitude from an IP address or other network-request metadata in their diagnostic and security logs. We conservatively treat those coordinates as potentially precise even though this provider-inferred network location is separate from device GPS. DentalReady Practice for Android does not request device GPS. DentalReady Staff foreground GPS remains separate and is used only after the in-app explanation when a user initiates a protected location or attendance action.
- Attendance and on-site access data: clock-in/out times and workplace photos (if your practice uses the kiosk feature). A practice may allow Staff app attendance without a geofence; in that mode DentalReady does not request or send your location for attendance actions. If your practice requires a Staff app geofence, after an in-app explanation and your consent your device reads its current foreground precise location when you choose Check location. Local checks may repeat while Staff Clock, Personal Stats or Case Tracking remains visible. Protected-tool readings stay on the device. Only when you tap Clock in, Clock out, Start lunch or End lunch/break is a fresh location and accuracy sent securely to DentalReady; the server calculates distance and discards the coordinates, retaining only the fix time, accuracy, calculated distance and configured radius with the attendance event. A linked operational audit may record that protected access was blocked or location permission was denied, but it does not contain coordinates or distance. DentalReady does not access location while the app is in the background.
- Team Pulse data: workplace sentiment ratings and optional written feedback you submit through a Team Pulse round. Response content is stored separately from the participation record used to prevent duplicate submissions.
- Audio and transcription data: optional voice notes used to draft SOPs, library content, and meeting notes, and performance-review and staff 1:1 check-in recordings. A speaker must consent before an SOP or library voice note starts. Before a meeting recording, the user must confirm that every participant has been informed and consented. Performance-review and 1:1 check-in recordings use a separate participant-consent workflow. Audio is uploaded to secure storage and, on supported surfaces, may be processed to produce a transcript and the requested workflow output. Access is limited to authorised users for the relevant practice; a finalised performance-review or completed check-in recording is shared with the employee only when an authorised reviewer explicitly chooses to share it. DentalReady Staff and DentalReady Practice version 1.0.1 for Android may store and play a consented performance-review or staff 1:1 recording for authorised users, but do not send that recording to an AI processor for transcription or analysis. AI transcription of these recordings is limited to other supported DentalReady surfaces where that feature is available.
- Patient and clinical information: where an authorised practice enables clinical workflows, users may enter patient labels or identifiers, appointment and treatment context, medical alerts, clinical notes, tooth-condition photographs, radiographs, periodontal charts, measurements, and clinician- or AI-generated findings. This health information is used only for the practice workflow selected by an authorised user and is available to authorised users for that practice.
- Android administrative pain intake: the Android apps retain reported facts, pain scores, notes and a follow-up priority affirmatively selected by a human under the practice's approved protocol. The Android form does not calculate or suggest urgency, diagnose, recommend treatment or provide clinical advice.
- Credential, immunisation and serology records: authorised practice administrators may enter a staff member's name and practice affiliation; credential type and label; professional, licence, registration, policy or certificate number; issue and expiry dates; reminder lead time; notes; and any immunisation, vaccination or serology result. When saved, these manual fields are transmitted to and stored in DentalReady's Supabase-hosted practice database. We use them for healthcare operations, professional-credential monitoring, workplace health and safety and compliance, and expiry reminders. Practice owners and authorised Practice Managers can manage all of these records. Other staff can view practice and practitioner credentials and only the immunisation records assigned to them.
- Android credential-document boundary: in DentalReady Staff and DentalReady Practice version 1.0.1 for Android, credential details are entered manually. These Android apps do not let users attach or upload credential certificate photos or PDFs, and do not send credential files or images to Google Vertex AI, Gemini or any other AI processor for extraction. An existing certificate document added through another supported DentalReady service may still be available to a practice owner or authorised Practice Manager under the same practice access controls.
- Previously imported operational call data: historical caller and patient details, call metadata and provider-generated summaries remain subject to our retention and deletion policy. The phone import integration has been retired and these records are no longer shown in Daily Control or used for marketing attribution.
- Lab-invoice upload data: an authorised user may choose to upload a lab-invoice photo or PDF for extraction and review. The selected file and its filename or file type may include a supplier or laboratory name, patient name or initials, case or job reference, tooth or shade reference, invoice number and date, and amount.
- Supplier-invoice and stock-order import data: an authorised Practice app user may choose a supplier invoice or order-confirmation photo or PDF for extraction and review. The full selected file and selected supplier name are sent for that extraction. The file can contain practice or supplier names and contact details, invoice or order identifiers and dates, product names, catalogue codes, quantities, unit and line prices, subtotal, discounts or credits, freight, fees, tax and total. If the related invoice record is saved, the file and any related fields or records already saved are retained. Later stock, order and price-history writes occur separately, so a failure can leave the linked file and only a partial set of reviewed records. The user can retry the import or request authorised support or data deletion. Not every extracted header field is necessarily saved.
- Stock-invoice attachments: authorised Staff and Practice users may also attach ordinary stock-invoice photos, scans or PDFs without AI extraction. A selected attachment is uploaded to DentalReady's Supabase Storage before the related invoice or delivery record is saved. Removing a selected file from the form asks Storage to delete it. If the app is interrupted or a later save is cancelled or fails, an uploaded file may remain until it is removed through an authorised support or data-deletion request.
- Practice, employment, and financial information: practice and document-recipient addresses; rosters; personal and practice calendar events (including event details, notes, attendees, or assignees); timesheets; leave; payroll workflow data; invoices; supplier and stock records; accounting imports (the Xero integration receives Xero's account-list response, but returns only account IDs, codes, and names to the app and does not store bank account numbers through this pathway); operational metrics; and business financial summaries entered or connected by authorised practice users.
- Connected Google Ads information: on a supported web or iOS surface, if an authorised practice administrator connects Google Ads, DentalReady receives and stores the OAuth and refresh tokens needed to maintain the connection, Google Ads customer and login-customer identifiers, and selected campaign names and identifiers, impressions, clicks, conversions, cost and currency. After connection, authorised background synchronisation may refresh those reporting metrics without another action for each sync.
- Connected Google Business Profile information: on a supported web or iOS surface, if an authorised practice administrator connects Google Business Profile, DentalReady receives and stores the OAuth and refresh tokens, connected account and location identifiers and names needed to maintain the connection. Scheduled review syncs may retrieve and store the reviewer display name and profile photo, rating, comment, practice reply, and publication or update times. Google Ads and Google Business Profile connection, OAuth and synchronisation workflows are supported on DentalReady web and iOS surfaces only. DentalReady Staff and DentalReady Practice version 1.0.1 for Android do not connect, reconnect or synchronise either service.
- Connected Instagram publishing information: On supported DentalReady web and iOS surfaces, an authorised practice administrator may connect an Instagram professional account. DentalReady stores the account and user identifiers, username, account type, profile-picture URL, OAuth access token, token expiry, authorised scopes and connection status needed to maintain that connection. When an authorised user publishes a selected marketing-grid JPEG and caption, DentalReady makes the image available to Meta/Instagram through a 24-hour signed DentalReady Supabase Storage URL, sends the caption and stores the attempt status and returned container or media identifier and permalink. DentalReady Staff and DentalReady Practice version 1.0.1 for Android do not connect, reconnect, refresh or disconnect Instagram and do not publish to it.
- Connected Xero and invoice-delivery information: if an authorised practice administrator connects Xero, DentalReady may store the connection tokens and identifiers needed to send or synchronise selected accounting, payroll, leave, timesheet and receipt records. On supported web and iOS surfaces, an owner may also explicitly send a selected invoice file and its reviewed fields by email to a Hubdoc, Dext or other bookkeeping inbox configured by that practice. DentalReady Practice version 1.0.1 for Android may read and synchronise an existing Xero organisation connected through a supported web or iOS surface and let an authorised user choose among Xero tenants already authorised to DentalReady. The Android app does not offer Xero OAuth connection, reconnection, permission-update or disconnection management; those actions remain available only on supported web and iOS surfaces. Hubdoc, Dext and other bookkeeping-inbox configuration and email delivery are supported on DentalReady web and iOS surfaces only. DentalReady Practice version 1.0.1 for Android retains ordinary invoice upload and storage but does not configure a bookkeeping inbox or send invoice files or fields to one.
- Accountant access information: a practice owner may provide an accountant's name and email address to send an invitation. If accepted, the invited accountant can continue to access the bookkeeping and financial records that the practice authorises until that access is removed.
- Files, documents, and communications: SOPs, library and migration files, meeting material, messages, notes, photos, videos, and other content users choose to upload or create for their practice. Some owner follow-up tools also retain the patient identifier, phone number, message template, and SMS body before opening the device's messaging app. If the audit log cannot be synchronised, the app may keep a plaintext offline copy scoped to that signed-in user and practice. The queue is capped at 50 entries. Each queued entry expires after 12 hours and is cleared on successful synchronisation, sign-out, or account change. If the app is not running at expiry, cleanup occurs the next time it starts. For an uploaded Library PDF, DentalReady creates a DentalReady Supabase Storage signed URL that is valid for one hour. In DentalReady Staff and DentalReady Practice version 1.0.1 for Android, that URL is handed to Android's system browser or PDF viewer only after the user taps Open PDF; Download PDF is a separate user action. This user-initiated handoff lets the user-selected system viewer retrieve the same DentalReady-hosted file and is not a disclosure to a new unrelated data recipient, although the selected browser or viewer processes the URL under its own device and app settings.
- Search and autocomplete queries: authorised owner workflows may send free-text stock-product searches or typed address queries to the configured search or autocomplete service to return relevant results.
- Third-party login data: if you sign in via Google or Facebook, we receive your name and email from those services
We also automatically collect usage data - such as pages visited, browser and device type, and approximate location derived from your IP address - using Google Analytics (GA4) and Vercel Analytics to understand how the platform is used and to improve our services. These tools set cookies or similar identifiers and process this data in aggregate. They run on our web app only (not the native mobile apps), and we do not sell this information.
On our public marketing pages we also use advertising measurement tools - the Meta Pixel and Google Ads conversion tracking - to measure the effectiveness of our advertising (for example, which campaign led a dental practice to request a demo or sign up). These set cookies and may share limited event data (such as a page visit or a completed demo request) with Meta and Google. They run on our public website only - never in the native mobile apps, and never on pages that carry patient or account access links - and we do not sell this information.
3. How We Use Your Information
- To provide and maintain the DentalReady platform
- To authenticate your identity and manage your account
- To assess demo and beta engagement, provide onboarding support, invite an approved requester, and ask whether a practice wants to set up or discuss a dedicated account
- To send and troubleshoot account, security, invitation, support and other service messages, and to monitor delivery, bounce and complaint events
- To facilitate candidate screening, training, and staff management
- To generate analytics for practice owners about their team
- To provide privacy-protected Team Pulse results and support practice follow-up actions
- To support authorised clinical workflows, including AI-assisted decision support that a treating clinician must independently verify
- To provide practice operations, employment, payroll, invoicing, accounting, stock, and reporting workflows
- To create reliable evidence of the legal documents, authority, choices and consents associated with an account or subscription
- To send product news, offers or conversion follow-ups where you have consented or another permission under applicable law, and to honour unsubscribe requests
- To understand adoption, security, reliability and feature value and improve the platform, including AI-assisted screening and training functions
4. How We Share Your Information
We do not sell your personal information. We share data only in these circumstances:
- With your practice: practice owners can view data for staff and candidates affiliated with their practice. Team Pulse is an exception: DentalReady does not show individual response content or responder identities to practice leaders. Results are released only after a round closes and its configured threshold of at least three staff responses is met. Cohorts of three or four reveal rounded averages only; detailed score distributions and optional verbatim comments require at least five responses. A comment may identify you if you include identifying details.
- Service providers: we use Supabase for data hosting and platform infrastructure; Resend and related delivery infrastructure for transactional and permitted commercial email; Google and Meta for authentication; Google Analytics and Vercel Analytics for web usage and performance analytics; Meta and Google for advertising measurement on our public website; Google ML Kit for on-device Android barcode scanning and its associated diagnostics and model updates; and the AI processors described below. We require service providers that process information for us to handle it under appropriate confidentiality, security and data-processing terms
- Google Ads connections: on supported web and iOS surfaces, when an authorised practice administrator connects Google Ads, DentalReady exchanges and refreshes OAuth credentials with Google and sends the relevant connected customer and login-customer identifiers to retrieve the campaign performance fields described above. The connection may continue syncing automatically until it is disconnected.
- Google Business Profile connections: on supported web and iOS surfaces, DentalReady exchanges and refreshes OAuth credentials with Google and sends the relevant account and location identifiers to retrieve the connected profile and review information described above. Scheduled review syncs may continue while the connection remains authorised. Google Ads and Google Business Profile connection, OAuth and synchronisation workflows are supported on DentalReady web and iOS surfaces only. DentalReady Staff and DentalReady Practice version 1.0.1 for Android do not connect, reconnect or synchronise either service.
- Instagram connections and publishing: on supported web and iOS surfaces, DentalReady exchanges and refreshes OAuth credentials with Meta/Instagram to maintain the connected professional account. When an authorised user chooses to publish, DentalReady sends the selected marketing-grid image and caption to Meta/Instagram and receives publication status, identifiers and any returned permalink. The Android boundary is described above.
- Xero connections: when an authorised practice administrator connects Xero, DentalReady sends the selected accounting, payroll, leave, timesheet and receipt records needed for the enabled synchronisation. Automatic synchronisation and retries may continue while the connection remains enabled. The Android connection-management boundary is described above.
- User-directed bookkeeping delivery: on supported web and iOS surfaces, when a practice owner chooses Send, DentalReady uses Resend as an email delivery processor to send the selected invoice file and reviewed invoice fields to the Hubdoc, Dext or other recipient inbox that the practice configured. DentalReady does not make that transfer without the owner's explicit send action. Hubdoc, Dext and other bookkeeping-inbox configuration and email delivery are supported on DentalReady web and iOS surfaces only. DentalReady Practice version 1.0.1 for Android retains ordinary invoice upload and storage but does not configure a bookkeeping inbox or send invoice files or fields to one.
- Invited accountants: when a practice owner invites an accountant, DentalReady sends the invitation to the name and email address supplied by the owner. An accountant who accepts has continuing access to the authorised bookkeeping records until the practice removes that access.
- Legal requirements: if required by Australian law or to protect our legal rights
5. Third-Party AI Processors
Some DentalReady features use artificial intelligence to classify, summarise, or draft operational content. We send only the data needed for the specific feature being used. Current AI-backed surfaces include:
The production Android apps do not currently include the patient-specific AI pain-triage, Morning Huddle, patient-recap, tooth-condition, periodontal, or radiograph tools described below, or the unfinished Hiring and candidate-screening, assessment, recommendation and hiring-decision surfaces. Those tools remain limited to authorised users on supported web or iOS surfaces and are not part of the Android data flows covered by the Google Play declarations.
The Android apps retain the lab-invoice extraction described below. The Android Practice app also retains the supplier-invoice and stock-order extraction described below. These retained workflows support stock management and accounting administration; DentalReady does not use them to calculate clinical urgency, diagnose a patient, or recommend treatment.
DentalReady Staff and DentalReady Practice version 1.0.1 for Android do not upload credential certificate photos or PDFs and do not use AI extraction for credential, immunisation or serology records. Those Android records use manually entered fields as described above.
- Android training review: In DentalReady Staff and DentalReady Practice version 1.0.1 for Android, a learner may explicitly request optional training feedback after completing a module. The request is limited to the module title, score, question and correct-answer counts, and completion time; individual answer selections are not sent. A DentalReady Supabase function uses this limited result with Google Vertex AI/Gemini to return learner feedback, which is stored with the module progress and shown to the learner. The Android Hiring and candidate-screening, assessment, recommendation and hiring-decision surfaces are not included in this release.
- Candidate screening: on supported non-Android surfaces, candidate chat transcripts, screening answers, assessment notes, and staff-reviewed recommendation inputs may be processed by Google Gemini or Google Vertex AI. The unfinished Hiring and candidate workflow is web/iOS only and is excluded from Android version 1.0.1.
- Android accreditation evidence mapping: In DentalReady Practice version 1.0.1 for Android, an authorised user may ask for draft accreditation evidence mappings. The request may include the selected accreditation framework and up to 150 currently unmapped SOP, library-document, compliance-document, meeting and registration titles, together with limited type, category, description, supplier, meeting-date or expiry metadata. File bodies are not included. A DentalReady Supabase function sends this limited text and the applicable accreditation clause text to Google Vertex AI/Gemini. DentalReady stores the model identifier and the returned draft clause suggestions, confidence and reasons; an authorised user must review and confirm a suggestion before it becomes linked evidence.
- Morning huddle and clinical workflow summaries: where a practice has enabled huddle features, patient names, appointment details, medical alerts, treatment context, recall status, and provider schedule data may be processed by Google Vertex AI, including Gemini and Anthropic Claude models available through Vertex. Anthropic's direct API may be used as a fallback if the Vertex route is unavailable.
- Tooth-condition photo classification: uploaded tooth-condition photos, condition options, and generated labels may be processed by Google Vertex AI/Gemini Vision.
- Periodontal and radiograph analysis: when an authorised clinician chooses these tools, periodontal-chart screenshots or dental radiographs, together with the patient age, risk factors, measurements, prior-chart context, and other clinician-entered patient context supplied for that analysis, are processed by Google Vertex AI/Gemini Vision. The service returns structured periodontal stage, grade, findings, confidence and decision-support summaries. These outputs are not a final diagnosis and must be independently reviewed by the treating clinician before they are used for patient care.
- Front-desk assistance and patient recaps: on supported non-Android surfaces, authorised practice users may choose tools that process patient identity and contact details, reported symptoms, pain scores, appointment and treatment context, manual staff notes, and relevant practice-record facts through Google Vertex AI/Gemini. The tools return staff-reviewable urgency or next-action suggestions, communication drafts, and patient-recap drafts. They do not replace professional clinical judgement, and a practice user must review every output before it is used or sent.
- Supplier-invoice and stock-order extraction: when an authorised Practice app user selects a supplier invoice or order-confirmation photo or PDF, the full selected file and selected supplier name are sent through a DentalReady Supabase function to Google Vertex AI/Gemini. The service may extract supplier, invoice/order, date, product or SKU, quantity, unit and line price, subtotal, discounts or credits, freight or fees, tax and total. The user reviews and matches the extracted lines before completing the import. A completed import retains the selected file and the reviewed fields needed for stock, order, invoice and price-history records; other extracted fields are processed only for review and are not necessarily saved.
- Lab-invoice extraction: when an authorised user selects a lab-invoice photo or PDF, the full selected file is sent through a DentalReady Supabase function to Google Vertex AI/Gemini. The service extracts accounting fields and may extract a patient name or initials, case or job reference, and tooth or shade reference when those details appear on the invoice. The user is shown the extracted fields for review before saving them.
- Financial improvement planning: when an authorised practice owner asks DentalReady to draft action ideas, a limited set of aggregate financial metrics, reporting dates, data-quality indicators, and owner-entered target candidates may be processed by Google Vertex AI/Gemini. Raw Xero reports, transactions, account or vendor names, bank details, patient information, and staff identities are excluded from this AI request.
- Bug and feature reports: report text, bug clarifications, feature-request questionnaire answers, and related page, app, browser and role context may be processed by Google Vertex AI/Gemini to classify, summarise or evaluate the report. Any bug screenshot the user chooses to attach may also be processed for that workflow. Optional in-app bug and feature reports, follow-up answers, generated classification or evaluation, and page, app, browser and role context are stored in DentalReady for support and triage. Bug reports can include optional screenshots; feature requests do not attach files. New reports are no longer mirrored to Trello. Historical records created before this integration was retired may remain subject to the applicable retention arrangements.
- Practice assistant tools: SOP drafts, library uploads, meeting notes, migration files, dashboard insight inputs, clinician coaching inputs, and stock-management prompts or search queries may be processed by Google Vertex AI, including Gemini and Anthropic Claude models where appropriate. Android version 1.0.1 excludes the content-agent, migration, dashboard-insight, equipment-assistant and Marketing Studio AI surfaces described here; its retained Android AI workflows are described separately above.
- Audio transcription: consented SOP and library voice notes, meeting recordings made after confirmation that all participants consented, and, on supported non-Android surfaces, consented performance-review or 1:1 check-in recordings, together with the minimum workflow context needed to interpret them, may be processed by Google Vertex AI/Gemini to create transcripts, summaries, or draft operational content. DentalReady Staff and DentalReady Practice version 1.0.1 for Android may store and play a consented performance-review or staff 1:1 recording for authorised users, but do not send that recording to an AI processor for transcription or analysis. AI transcription of these recordings is limited to other supported DentalReady surfaces where that feature is available.
We do not use these AI processors to sell personal information. Outputs are returned to DentalReady and shown only to authorised users for the relevant practice or workflow.
6. Data Storage and Security
Our primary production database and object storage are configured in Supabase's Sydney, Australia region. We use encryption in transit (TLS) and at rest. Access to personal data is restricted through role-based access controls and row-level security policies. On Android, persisted sign-in session credentials are encrypted with AES-GCM using keys held by the Android Keystore and are excluded from device backups.
We also use access logging, monitoring, backup, incident-response, secure-development and service-provider review measures appropriate to the information and risks. No internet service can guarantee absolute security. If an incident is an eligible data breach, we will assess and notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
7. Australia and Overseas Processing
Sydney hosting does not mean every processing activity occurs only in Australia. We use providers with personnel, systems or subprocessors in other countries. Personal information is likely to be disclosed to or processed by recipients in the United States, particularly for email delivery, analytics, advertising measurement and some AI-assisted features. Provider routing, support and subprocessors may involve other countries disclosed in those providers' current terms.
Before disclosing personal information to an overseas recipient, we take reasonable steps required by Australian Privacy Principle 8, including appropriate contractual and security safeguards where they apply. Contact us if you need the current provider or likely-country information for a particular feature before using it with sensitive or health information.
8. Data Retention and Deletion
We retain your data for as long as your account is active or as needed to provide our services. Practice-controlled operational, employment, financial and clinical records may remain available to the relevant practice for its lawful business, patient-care and record-keeping obligations after an individual user account closes. Audio, transcripts, uploaded files and AI outputs are retained with the related practice workflow until an authorised user deletes them, the practice account is deleted, or a different legal or contractual retention requirement applies.
Demo and product-activity records and email delivery events are kept for as long as reasonably needed to administer access, troubleshoot delivery, measure engagement, respect suppression and unsubscribe choices, secure the service and maintain business records. Agreement and consent evidence may be kept for the life of the relevant account or agreement and afterwards for the period reasonably needed to meet legal, audit and dispute requirements.
Manual credential, immunisation and serology records are stored with the relevant practice account and, where applicable, linked to the relevant staff member. Archiving a credential removes it from the active registry and stops its reminders, but does not erase the database record or any existing certificate document added through another supported DentalReady service. The affected individual or an authorised practice representative can request access, correction or deletion through our data-deletion or privacy contact channels. Deletion remains subject to practice control and any lawful workplace, healthcare, professional-registration, audit or contractual retention requirement.
You can ask us to delete your account and associated personal data. We will process a valid request within 30 days, except where the relevant practice controls the record, where deletion would affect another person's rights, or where DentalReady or the practice may or must keep it under law or contract. Residual encrypted backups may remain until overwritten in the ordinary backup cycle.
9. Access, Correction and Complaints
You may:
- ask to access personal information we hold about you;
- ask us to correct inaccurate or out-of-date information;
- ask us to delete information, subject to practice control and legal or contractual retention requirements;
- withdraw a consent where our processing depends on that consent; and
- make a privacy complaint without being treated adversely.
We may need to verify your identity and consult the practice that controls a record. We will explain if we cannot fulfil a request. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner. For NSW health information, you may also be able to contact the Information and Privacy Commission NSW.
10. Service and Commercial Communications
We send service communications needed to administer, secure or support an account, such as access links, invitations, password resets, roster notices and important product or legal changes. You may not be able to opt out of an essential service message while the related account or workflow remains active.
We send commercial electronic messages only with express or inferred consent or another permission under the Spam Act 2003. We keep reasonable evidence of that permission. Each commercial message identifies the sender and provides a clear, functional unsubscribe method. You may unsubscribe through that method or contact us, and we will action the request within five working days. Withdrawing marketing consent does not affect service messages or processing already carried out lawfully.
11. NSW Health Information
Patient and clinical information, and staff immunisation, vaccination and serology information, are health information. To the extent the Health Records and Information Privacy Act 2002 (NSW) applies to us or a NSW practice, health information must be handled consistently with the Health Privacy Principles, including requirements concerning collection, use, disclosure, security, access, correction and retention. The practice generally determines the clinical or workplace compliance purpose and controls the relevant record; DentalReady processes the information to provide the authorised workflow and also meets obligations that apply directly to us.
A practice must not use DentalReady to avoid its professional, patient-notice, consent, records or retention duties. Contact the relevant practice first for a request about a clinical record it controls, or contact us if the issue concerns DentalReady's own handling of the information.
12. Third-Party Services
When you use Google or Facebook to sign in, those providers may collect data according to their own privacy policies. We encourage you to review their policies. We receive the information needed to authenticate you and create or link your account, usually your name, email address and provider account identifier. Other integrations you or your practice choose have their own terms and privacy notices.
13. Changes to This Policy
We may update this policy prospectively to reflect product, provider, legal or operational changes. We will publish the new version and effective date and give additional notice of a material change where appropriate. A prior version continues to describe our handling of information while it applied; a policy update does not retrospectively create consent.
14. Contact and Complaints
If you have questions, want to exercise a privacy right, or wish to complain, email us. Please describe the issue and the account or practice involved without including unnecessary patient or sensitive information. We will acknowledge, investigate and respond within a reasonable period.
Email: privacy@dentalready.com.au
Entity: Dental Ready Technologies Pty Ltd (ACN 697 960 704)