Dental ERPDental ERPPractice Management Platform← Return to website
Privacy by design

Privacy, Confidentiality & GDPR

Dental ERP is designed to keep clinic operations and patient information private, controlled and available only through authenticated, role-based access.

Private by default.Patient records, invoices, documents and credentials are not public pages. They are protected within authenticated clinic and patient workspaces.
01Clinic records are separated by clinic workspace.
02Patients must sign in to view their own available records.
03Information is not sold or shared for advertising.
04Access is limited according to authorised roles.
01 — OUR COMMITMENT

Confidential clinic information stays confidential.

Dental ERP provides digital tools for clinics to manage appointments, patients, clinical records, dental charts, treatment plans, prescriptions, documents, invoices and communication. These records are intended for the relevant clinic and the individuals authorised by that clinic.

No public patient directory

Dental ERP does not publish patient profiles, clinical histories, invoices, prescriptions, uploaded files or login credentials on public pages.

02 — INFORMATION HANDLED

Information necessary to operate a dental practice.

Depending on the features used by a clinic, the platform may handle:

  • Patient identity and contact information.
  • Appointments, clinical notes, dental charts, treatment plans and prescriptions.
  • Patient-uploaded or clinic-uploaded documents.
  • Invoices, estimates, payment records and applicable tax information.
  • Doctor, receptionist and clinic-administrator account information.
  • Login, notification, email-queue and activity records used for security and operations.

Clinics remain responsible for entering information lawfully, maintaining appropriate patient consent and configuring access for their team.

03 — ACCESS CONTROL

Access follows the clinic relationship and assigned role.

Clinic workspace

Clinic owners and administrators

Access their own clinic’s operational records and manage authorised team access.

Clinical team

Doctors and receptionists

Access only the areas permitted by their clinic role and configured permissions.

Patient portal

Authenticated patients

View only their own records made available within their clinic’s patient portal.

A patient cannot browse another patient’s records. A clinic user is not intended to access another clinic’s workspace. Record URLs are not designed as public document links.

04 — SHARING & DISCLOSURE

We do not sell patient or clinic information.

Dental ERP does not sell patient information, invoices, credentials or clinical records, and does not share them for behavioural advertising.

Limited disclosure may occur only where necessary to provide or protect the service—for example hosting infrastructure, email delivery, payment processing selected by the clinic, backup operations, authorised technical support, security investigation, or a valid legal requirement. Such access should be limited to what is reasonably necessary for that purpose.

Credentials remain private

Users should never share passwords. Passwords are stored using secure hashing where implemented; password-reset and invitation links should be treated as confidential and used only by the intended recipient.

05 — SECURITY SAFEGUARDS

Layered controls protect private workspaces.

Dental ERP includes or supports password hashing, role-based access, clinic-aware records, restricted document delivery, activity and login records, HTTPS-compatible deployment, backup workflows and controlled notification queues.

No internet-connected service can promise absolute security. Clinics must use HTTPS, secure hosting, strong passwords, current software, protected email accounts, appropriate staff permissions and reliable backup procedures.

06 — PATIENT & GDPR RIGHTS

Supporting transparent and accountable data handling.

Where GDPR or similar privacy laws apply, individuals may have rights to request access, correction, restriction, portability, objection or deletion, subject to clinical-record retention duties and other legal requirements.

Patients should normally contact their clinic first because the clinic determines why and how patient information is used. Dental ERP can support the clinic’s response through authenticated records and administrative workflows.

07 — RETENTION & DELETION

Clinical obligations may require records to be retained.

Each clinic is responsible for defining lawful retention periods for clinical, financial and communication records. A deletion request may not always result in immediate removal where medical, tax, contractual, security or legal-retention requirements apply.

Where appropriate, access may be restricted, records may be archived, or information may be anonymised instead of being immediately erased.

08 — PRIVACY CONTACT

Questions about a record should begin with the clinic.

For access to, correction of or questions about patient records, contact the dental clinic that created or manages the record. For platform privacy or security enquiries, contact the Dental ERP support team.

Dental ERP privacy contact

Email: hello@dentalerp.in
Product provider: Manish Web Studio, Bengaluru, India