Toothvity · India

Privacy Policy

Last updated: August 2026. This policy describes how Toothvity handles information when your clinic uses our software. It is not legal advice. Consult qualified counsel for your practice's compliance obligations.

← Back to Home

Who We Are

Toothvity provides cloud-based clinic management software for dental practices in India. For privacy questions contact support@toothvity.com.

Data Ownership

Patient and clinic operational records are created for your clinic's use. Your clinic owns the business content you enter and is responsible for lawful collection, accuracy, professional record-keeping, and patient notices under applicable Indian law.

Toothvity acts as a technology service provider processing data on your instructions to operate the service, not as the primary custodian of clinical decision-making.

What Data We Collect

When your clinic uses Toothvity, the service may process the categories below. Clinical content is entered by your clinic; Toothvity processes it to run the software.

Categories of data Toothvity may process, with examples, source, and purpose
CategoryExamplesSourcePurpose
Account dataStaff names, email addresses, authentication credentials, role assignments (Growth and above), clinic profile fields (name, contact numbers)Clinic staff and owners during signup and settingsAuthenticate users, provision access, and identify the clinic workspace
Patient recordsDemographics, contact details, visit history, and clinical notes you enterClinic staff enter data in the clinic workspaceOperate day-to-day clinic workflows for your practice
PrescriptionsMedication lines, instructions, and doctor details as structured recordsClinic staff create prescriptions in the productStore and generate prescription records and PDFs you request
InvoicesLine items, amounts, patient linkage, and invoice metadataClinic staff create invoices in the clinic accountBilling workflows within your clinic workspace
Clinical modules (Growth and above)Consent form records and treatment plan items when your plan includes those featuresClinic staff using Growth+ featuresProvide optional clinical modules included in your plan
Appointments and operational dataScheduling information tied to patients and staff workflowsClinic staff using scheduling featuresSupport clinic operations and calendars
Support and feedbackSupport ticket subjects, messages, attachments you upload, and product feedbackYou when contacting support or submitting feedbackRespond to support requests and improve the product
Billing informationSubscription plan, payment status, and identifiers from our payment processor (Razorpay or Stripe, depending on configuration). We do not store full payment card numbers on Toothvity serversSubscription checkout and payment webhooksProcess subscriptions and billing events
Technical dataIP addresses, browser type, and security event logs (for example rate-limit and access-control telemetry)Product usage and security controlsProtect accounts and operate the service securely

Files and Uploads

Toothvity handles three categories of files differently:

  • Clinic branding assets: logo, banner, and signature images you upload in Settings. Stored in private cloud storage and subject to per-plan quotas. Replacing an asset removes the previous file from active storage.
  • Support attachments: PNG, JPEG, or PDF files (up to 5 MB each, max 3 per message) attached to in-app support tickets. Stored in private cloud storage, scoped to your clinic, and subject to per-plan quotas. Removed when attachments or tickets are deleted per our retention policy.
  • Generated PDFs: prescription, invoice, consent, and treatment plan PDFs are rendered on demand from your database records and streamed to your browser. They are not stored as permanent upload files in cloud storage.

Storage quotas and per-file limits are described on our Pricing page and in Data Retention.

Cookies and Session Storage

Toothvity uses cookies and browser session storage to keep you signed in, enforce security controls, and remember essential preferences. These are required for the authenticated product to function. We do not use third-party advertising cookies in the clinic application.

How We Use Information

  • Provide, maintain, and improve the Toothvity service
  • Authenticate users, enforce role-based access, and isolate clinic workspaces
  • Process subscriptions and billing events through our payment partner
  • Generate PDFs you request from data in your clinic account
  • Respond to support requests and investigate security incidents
  • Comply with lawful requests where required

We do not sell patient lists or clinical content to advertisers. We do not use patient data to train public AI models unless we explicitly offer and you opt in to a separate feature with clear terms.

Staff Access

On Growth and above, clinic owners control which staff receive access through role-based permissions. Starter includes an owner login. You are responsible for provisioning and revoking access when staff join or leave, and for limiting shared logins on front-desk devices.

Security and Encryption

Connections to Toothvity use HTTPS (encryption in transit). Access to production data is restricted to authorised personnel and infrastructure roles required to operate the service. See our Security page for a plain-language overview of access control, isolation, and logging. We do not claim HIPAA, SOC 2, or ISO certification.

Retention and Deletion

We retain account and clinic data while your subscription is active and for a period afterward to allow export, resolve disputes, and meet legal obligations. Soft-deleted clinical rows may remain in primary database storage; there is no automated purge of patient charts. Support attachments follow the ticket lifecycle. Full schedules and offboarding steps are on our Data Retention policy.

Clinic owners may request workspace offboarding from Settings → Danger Zone in the dashboard. Requests require platform admin approval, a recent data export (within 72 hours before execution), and result in workspace soft-delete plus support-attachment purge, not permanent erasure of all clinical database rows. You may also contact support@toothvity.com if you cannot access the product.

We maintain operational database backups for reliability and disaster recovery. Storage objects (branding and support attachments) can be exported manually by platform operators. There is no automated clinic-facing restore for individual file changes. Backups are not a substitute for your clinic's record-keeping duties. See Data Retention for backup windows.

Export files you download are your responsibility to store securely. We honour verified offboarding requests subject to minimum retention required for billing, security logs, or law.

Service Providers

Toothvity uses reputable infrastructure and payment providers (cloud hosting, database, authentication, Razorpay/Stripe for subscriptions). These providers process data only as needed to deliver the service under contractual safeguards.

Changes

We may update this policy as the product or law evolves. Material changes will be posted on this page with an updated date.

Contact

Privacy: support@toothvity.com. General support: Contact us.