Last updated: April 2026
1. Introduction
Smile Genius Dental Limited ("we," "us," "our," "Company") operates the Smile Genius Dental platform (the "Platform" or "Services"), a software-as-a-service application that enables dental laboratories and dental service organisations to manage cases, workflows, and integrations with scanner platforms and practice management systems.
This Privacy Policy explains how we collect, use, share, and protect personal data when you use our Platform. It applies to anyone who accesses the Platform, including laboratory staff, administrative personnel, clinicians, and patients whose data is processed through the Platform.
We are committed to transparency and compliance with:
The EU General Data Protection Regulation (EU 2016/679) ("GDPR")
The UK General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR")
Irish data protection legislation
For legal terms governing your use of the Platform (including data processing), please also read our Terms & Conditions.
2. Who We Are and How to Contact Us
Company Name: Smile Genius Dental Limited
Registered Address: Dublin, Ireland
Email: support@smilegeniusdental.com
Data Protection Contact: Arun Kumar, CTO (support@smilegeniusdental.com)
If you have questions about this Privacy Policy or our data handling practices, please contact us at support@smilegeniusdental.com. You may also lodge a complaint with:
Ireland: Data Protection Commission (www.dataprotection.ie)
UK: Information Commissioner's Office (www.ico.org.uk)
3. What Personal Data We Collect
3.1 Data You Provide Directly
Account Registration:
Name, email address, job title, organisation name, phone number
Password and authentication credentials
Billing and payment information (processed via Stripe; we do not store full payment card details)
Lab and Clinic Information:
Laboratory or clinic name, address, and contact details
Practice management system credentials (if you enable integrations)
Scanner platform credentials (e.g., iTero login credentials, if you opt into Managed Services)
Case and Order Data:
Patient name, date of birth, patient ID
Scan files and imaging data
Prescribing dentist name and contact information
Screening data and clinical notes
Treatment specifications and orders
Communication:
Messages sent via the Platform's messaging or support features
Support requests, feedback, and service inquiries
Email correspondence
3.2 Data Collected Automatically
Usage and System Data:
IP address, browser type, operating system, and device information
Pages visited, features used, time spent on the Platform
Clicks, interactions, and actions within the Platform
Error logs and diagnostic information
Cookies and similar tracking technologies
Managed Services (Scanner Intake Automation):
Scanner notification emails forwarded by your clinic or laboratory
Scanner platform activity logs (if you connect your scanner account)
Extracted case metadata and AI-assisted parsing logs
4. How We Use Your Personal Data
We process personal data for the following purposes:
4.1 Core Service Delivery
Creating and maintaining your account
Delivering the Platform features you've subscribed to
Processing orders and managing case workflows
Enabling integrations with your practice management system or scanner platforms
Providing scanner intake automation (Managed Services) where enabled
Billing and payment processing
Sending service updates, maintenance notices, and Platform-related communications
4.2 Managed Services (Scanner Automation)
Where you've opted into Managed Services, we:
Monitor scanner notifications forwarded by your clinic
Use AI-assisted parsing (via Anthropic) to extract case metadata
Create case records in your Portal on your behalf
Retain forwarded emails and parsing logs to provide the service and comply with legal requirements
We do not:
Perform clinical review or validation of extracted data
Verify data completeness or accuracy
Sync case status updates back to your scanner platform
Complete fields our AI cannot extract
You remain responsible for reviewing extracted data and correcting errors. See Section 6 (Sub-processors) for details on Anthropic's involvement.
4.3 Support and Troubleshooting
Responding to your support inquiries
Diagnosing and resolving technical issues
Providing account or billing assistance
Monitoring Platform security and preventing fraud
4.4 Legal and Compliance Obligations
Complying with legal requests from law enforcement or regulators
Protecting against fraud, abuse, or security threats
Enforcing our Terms & Conditions
Meeting data retention requirements under Irish, UK, and EU law
4.5 Improvement and Analytics
Analyzing how the Platform is used to improve features and performance
Conducting user research and collecting feedback
Creating aggregated or de-identified reports (e.g., usage statistics, feature adoption trends)
Testing new features and optimizing user experience
We do not use personal data for marketing or promotional purposes without your explicit consent.
5. Our Legal Basis for Processing
Under GDPR/UK GDPR, we process personal data on the following legal bases:
For any processing beyond the above, we will seek your explicit consent and inform you via email or in-Platform notice.
6. Sub-Processors and Data Sharing
We do not sell personal data. We share data only with third parties who assist us in delivering the Services and operate under data processing agreements.
6.1 Sub-Processors
We currently engage the following sub-processors to handle personal data:
Anthropic's Data Processing Addendum: https://www.anthropic.com/legal/data-processing-addendum
6.2 Right to Object to Sub-Processors
Under GDPR Article 28(4), you have the right to object to our use of sub-processors on data protection grounds. If you have concerns about any sub-processor, contact us at support@smilegeniusdental.com within 14 days of notification of the sub-processor addition. We remain fully liable for all sub-processors' compliance.
6.3 International Transfers
Data transferred to Anthropic (United States) and Stripe (where applicable) is protected by:
Standard Contractual Clauses (SCCs) under GDPR Chapter V
UK International Data Transfer Addendum (UK IDTA) for UK GDPR compliance
Anthropic's and Stripe's commitment to data protection safeguards aligned with GDPR standards
You can request copies of these transfer mechanisms at support@smilegeniusdental.com.
6.4 Other Sharing
We may share personal data where:
Required by law (e.g., court orders, law enforcement requests)
Necessary to protect safety or legal rights
As part of a merger, acquisition, or sale of assets (with notice)
With your explicit consent
7. Data Retention and Deletion
7.1 Retention Periods
We retain personal data for as long as necessary to provide the Services and comply with legal obligations:
7.2 Deletion Upon Termination
When your subscription terminates:
First 30 days: Case data remains accessible to you for download/retrieval
Days 31–90: Case data is deleted from production systems
Days 91–180: Backup copies are retained for disaster recovery only
Day 181: All personal data is permanently deleted
Exceptions:
Data required by law is retained for the minimum legally required period
Aggregated/de-identified data may be retained indefinitely
Backup copies may be kept for up to 90 additional days in secure offline storage per Section 7.1
7.3 Your Right to Erasure ("Right to be Forgotten")
Under GDPR Article 17, you may request deletion of your personal data, except where we must retain it by law or to provide Services. Submit erasure requests to support@smilegeniusdental.com.
8. Your Rights Under GDPR / UK GDPR
As a Data Subject under GDPR/UK GDPR, you have the following rights:
8.1 Right of Access (Article 15)
You have the right to obtain a copy of your personal data and information about how we process it.
8.2 Right of Rectification (Article 16)
You have the right to correct inaccurate or incomplete personal data. You can update much of this information directly in your account settings; for assistance, contact support@smilegeniusdental.com.
8.3 Right of Erasure (Article 17)
You have the right to request deletion of your personal data, subject to legal retention requirements.
8.4 Right to Restrict Processing (Article 18)
You have the right to request that we limit processing of your personal data to storage only (e.g., while a dispute is resolved).
8.5 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
8.6 Right to Object (Article 21)
You have the right to object to processing of your personal data for certain purposes, particularly for legitimate-interest-based processing.
8.7 Rights Related to Automated Decision-Making (Article 22)
You have the right to request human review of decisions that have legal or similarly significant effects on you, if made solely by automated means (e.g., AI).
8.8 How to Exercise Your Rights
To exercise any of the above rights, submit a request to: support@smilegeniusdental.com
Subject line: "GDPR Data Subject Request — [Type: Access / Rectification / Erasure / etc.]"
Our response timeline:
Acknowledgement: 5 business days
Resolution: 30 calendar days (extendable to 60 days for complex requests, with notice)
9. Security and Data Protection
9.1 Technical and Organisational Measures
We implement appropriate safeguards under GDPR Article 32 to protect personal data:
Encryption in transit (TLS/HTTPS) for all data transmitted to/from the Platform
Encryption at rest for stored personal data
Role-based access controls — users access only data necessary for their role
Authentication controls — strong password requirements, optional multi-factor authentication
Audit logging — all access to personal data is logged
Environment segregation — production, staging, and development environments are isolated
Secure credential management — scanner and practice management system credentials are stored in encrypted vaults
Regular security assessments — penetration testing and vulnerability scans
Personnel training — staff handling personal data receive data protection training
9.2 Incident Response
In the event of a Personal Data Breach, we will:
Notify you within 48 hours of discovery
Provide details of the data affected, affected individuals, and likely consequences
Explain measures taken to mitigate harm
Cooperate with law enforcement or regulators
For credential compromise specifically, we will notify you within 24 hours and immediately rotate/revoke affected credentials.
9.3 Security Certifications and Standards
We align our security controls with:
GDPR Article 32 technical and organisational safeguards
HIPAA Security Rule standards (for alignment with potential US expansions; see Section 9.4)
Industry best practices for SaaS platforms
We can provide a SOC 2 Type II report or equivalent third-party attestation upon request.
9.4 HIPAA Compliance (US Customers Only)
The Health Insurance Portability and Accountability Act (HIPAA) applies only if you are a US Covered Entity or Business Associate and submit Protected Health Information (PHI) to the Platform.
If you are a US Covered Entity or Business Associate:
Do not submit PHI to the Platform without first executing a Business Associate Agreement (BAA)
Request a BAA at support@smilegeniusdental.com
Absent an executed BAA, you must not submit PHI, and we disclaim all HIPAA obligations.
10. Cookies and Tracking Technologies
10.1 What Are Cookies?
Cookies are small text files stored on your device that enable our Platform to remember you and personalize your experience.
10.2 Types of Cookies We Use
10.3 Third-Party Cookies
We use analytics tools (e.g., Mixpanel) that may set cookies to track usage patterns and help us improve the Platform. These tools operate under their own privacy policies.
10.4 Your Cookie Preferences
You can control cookies via your browser settings:
Disable non-essential cookies (though this may affect Platform functionality)
Clear cookies at any time
Opt out of third-party analytics via [Insert Link if applicable]
For detailed cookie management, see our Cookie Policy.
11. Children's Privacy
The Platform is not directed at children under 13. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 13, we will delete it immediately and contact the parent or guardian. Contact support@smilegeniusdental.com if you have concerns.
12. Third-Party Links and Services
The Platform may link to third-party websites (e.g., documentation, integrations, practice management systems). We are not responsible for their privacy practices. Please review their privacy policies before sharing personal data.
13. Data Processing Terms (GDPR Article 28)
For customers who are dental laboratories or clinics (i.e., Data Controllers), the data processing terms are set out in the Terms & Conditions, Section 5. These terms constitute our Data Processing Agreement under GDPR Article 28(3).
Key obligations:
We process personal data only on your documented instructions
We ensure staff confidentiality undertakings
We implement Article 32 safeguards (Section 9.1 above)
We assist with Data Subject rights (Section 8)
We notify you of breaches (Section 9.2)
We delete or return data at subscription end (Section 7.2)
We allow audits and provide compliance evidence (Terms & Conditions, Section 5.3)
14. California Privacy Rights (CCPA/CPRA) — US Users Only
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) may apply. Under CCPA/CPRA, you have rights to:
Know what personal information we collect
Delete personal information
Opt out of certain uses or sales
Non-discrimination for exercising rights
Note: CCPA/CPRA does not apply to B2B data (business contact information). If you believe we are processing your personal information as a consumer under CCPA/CPRA, contact us at support@smilegeniusdental.com.
15. Updates to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or in-Platform notice at least 30 days before the effective date. Continued use of the Platform after the effective date constitutes acceptance of the updated policy.
Current version: January 2026
Next review date: January 2027
16. Contact Us
Questions about this Privacy Policy or our data practices?
Email: support@smilegeniusdental.com
Data Protection Contact: Arun Kumar, CTO
Complaints:
Ireland: Data Protection Commission (www.dataprotection.ie)
UK: Information Commissioner's Office (www.ico.org.uk)
© 2026 Smile Genius Dental Limited. All rights reserved.

