Toothvity · India
Privacy Policy
Last updated: June 2026. This policy describes how Toothvity handles information when your clinic uses our software. It is not legal advice — consult qualified counsel for your practice's compliance obligations.
Who we are
Toothvity provides cloud-based clinic management software for dental practices in India. For privacy questions contact support@toothvity.com.
What data we collect
When your clinic uses Toothvity, the service may process:
- Account data — staff names, email addresses, authentication credentials, role assignments (Growth and above), and clinic profile fields (name, contact numbers).
- Patient records — demographics, contact details, visit history, and clinical notes you enter for patients under your clinic workspace.
- Prescriptions — medication lines, instructions, and doctor details stored as structured records in your clinic database.
- Invoices — line items, amounts, patient linkage, and invoice metadata created in your clinic account.
- Clinical modules (Growth and above) — consent form records and treatment plan items when your plan includes those features.
- Appointments and operational data — scheduling information tied to patients and staff workflows.
- Support and feedback — support ticket subjects, messages, and attachments you upload; product feedback you submit.
- Billing information — subscription plan, payment status, and identifiers from our payment processor (Razorpay or Stripe, depending on configuration). We do not store full payment card numbers on Toothvity servers.
- Technical data — IP addresses, browser type, and security event logs used to protect accounts (for example rate-limit and access-control telemetry).
Files and uploads
Toothvity handles three categories of files differently:
- Clinic branding assets — logo, banner, and signature images you upload in Settings. Stored in private cloud storage and subject to per-plan quotas. Replacing an asset removes the previous file from active storage.
- Support attachments — PNG, JPEG, or PDF files (up to 5 MB each, max 3 per message) attached to in-app support tickets. Stored in private cloud storage, scoped to your clinic, and subject to per-plan quotas. Removed when attachments or tickets are deleted per our retention policy.
- Generated PDFs — prescription, invoice, consent, and treatment plan PDFs are rendered on demand from your database records and streamed to your browser. They are not stored as permanent upload files in cloud storage.
Storage quotas and per-file limits are described on our Pricing page and in Data Retention.
Cookies and session storage
Toothvity uses cookies and browser session storage to keep you signed in, enforce security controls, and remember essential preferences. These are required for the authenticated product to function. We do not use third-party advertising cookies in the clinic application.
Data ownership
Patient and clinic operational records are created for your clinic's use. Your clinic owns the business content you enter and is responsible for lawful collection, accuracy, professional record-keeping, and patient notices under applicable Indian law.
Toothvity acts as a technology service provider processing data on your instructions to operate the service — not as the primary custodian of clinical decision-making.
How we use information
- Provide, maintain, and improve the Toothvity service
- Authenticate users, enforce role-based access, and isolate clinic workspaces
- Process subscriptions and billing events through our payment partner
- Generate PDFs you request from data in your clinic account
- Respond to support requests and investigate security incidents
- Comply with lawful requests where required
We do not sell patient lists or clinical content to advertisers. We do not use patient data to train public AI models unless we explicitly offer and you opt in to a separate feature with clear terms.
Staff access
On Growth and above, clinic owners control which staff receive access through role-based permissions. Starter includes an owner login. You are responsible for provisioning and revoking access when staff join or leave, and for limiting shared logins on front-desk devices.
Security and encryption
Connections to Toothvity use HTTPS (encryption in transit). Access to production data is restricted to authorised personnel and infrastructure roles required to operate the service. See our Security page for a plain-language overview. We do not claim HIPAA, SOC 2, or ISO certification.
Backups
We maintain operational database backups as part of hosted cloud infrastructure to support reliability and disaster recovery. Storage objects (branding and support attachments) can be exported manually by platform operators — there is no automated clinic-facing restore for individual file changes. Backups are not a substitute for your clinic's own record-keeping duties or statutory retention requirements.
Retention and deletion
We retain account and clinic data while your subscription is active and for a period afterward to allow export, resolve disputes, and meet legal obligations. Soft-deleted clinical rows may remain in primary database storage; there is no automated purge of patient charts — see our Data Retention policy. Support attachments follow the ticket lifecycle described there.
Clinic owners may request workspace offboarding from Settings → Danger zone in the dashboard. Requests require platform admin approval, a recent data export (within 72 hours before execution), and result in workspace soft-delete plus support-attachment purge — not permanent erasure of all clinical database rows. You may also contact support@toothvity.com if you cannot access the product.
Export files you download are your responsibility to store securely. We honour verified offboarding requests subject to minimum retention required for billing, security logs, or law.
Service providers
Toothvity uses reputable infrastructure and payment providers (cloud hosting, database, authentication, Razorpay/Stripe for subscriptions). These providers process data only as needed to deliver the service under contractual safeguards.
Changes
We may update this policy as the product or law evolves. Material changes will be posted on this page with an updated date.
Contact
Privacy: support@toothvity.com. General support: Contact us.