PRIVACY POLICY

PRIVACY POLICY

Last updated: April 2026

1. Introduction


Smile Genius Dental Limited ("we," "us," "our," "Company") operates the Smile Genius Dental platform (the "Platform" or "Services"), a software-as-a-service application that enables dental laboratories and dental service organisations to manage cases, workflows, and integrations with scanner platforms and practice management systems.


This Privacy Policy explains how we collect, use, share, and protect personal data when you use our Platform. It applies to anyone who accesses the Platform, including laboratory staff, administrative personnel, clinicians, and patients whose data is processed through the Platform.


We are committed to transparency and compliance with:


  • The EU General Data Protection Regulation (EU 2016/679) ("GDPR")

  • The UK General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR")

  • Irish data protection legislation


For legal terms governing your use of the Platform (including data processing), please also read our Terms & Conditions.


2. Who We Are and How to Contact Us


Company Name: Smile Genius Dental Limited
Registered Address: Dublin, Ireland
Email: support@smilegeniusdental.com
Data Protection Contact: Arun Kumar, CTO (support@smilegeniusdental.com)

If you have questions about this Privacy Policy or our data handling practices, please contact us at support@smilegeniusdental.com. You may also lodge a complaint with:

  • Ireland: Data Protection Commission (www.dataprotection.ie)

  • UK: Information Commissioner's Office (www.ico.org.uk)


3. What Personal Data We Collect


3.1 Data You Provide Directly


Account Registration:

  • Name, email address, job title, organisation name, phone number

  • Password and authentication credentials

  • Billing and payment information (processed via Stripe; we do not store full payment card details)

Lab and Clinic Information:

  • Laboratory or clinic name, address, and contact details

  • Practice management system credentials (if you enable integrations)

  • Scanner platform credentials (e.g., iTero login credentials, if you opt into Managed Services)

Case and Order Data:

  • Patient name, date of birth, patient ID

  • Scan files and imaging data

  • Prescribing dentist name and contact information

  • Screening data and clinical notes

  • Treatment specifications and orders

Communication:

  • Messages sent via the Platform's messaging or support features

  • Support requests, feedback, and service inquiries

  • Email correspondence


3.2 Data Collected Automatically


Usage and System Data:

  • IP address, browser type, operating system, and device information

  • Pages visited, features used, time spent on the Platform

  • Clicks, interactions, and actions within the Platform

  • Error logs and diagnostic information

  • Cookies and similar tracking technologies

Managed Services (Scanner Intake Automation):

  • Scanner notification emails forwarded by your clinic or laboratory

  • Scanner platform activity logs (if you connect your scanner account)

  • Extracted case metadata and AI-assisted parsing logs


4. How We Use Your Personal Data


We process personal data for the following purposes:


4.1 Core Service Delivery

  • Creating and maintaining your account

  • Delivering the Platform features you've subscribed to

  • Processing orders and managing case workflows

  • Enabling integrations with your practice management system or scanner platforms

  • Providing scanner intake automation (Managed Services) where enabled

  • Billing and payment processing

  • Sending service updates, maintenance notices, and Platform-related communications


4.2 Managed Services (Scanner Automation)

Where you've opted into Managed Services, we:

  • Monitor scanner notifications forwarded by your clinic

  • Use AI-assisted parsing (via Anthropic) to extract case metadata

  • Create case records in your Portal on your behalf

  • Retain forwarded emails and parsing logs to provide the service and comply with legal requirements

We do not:

  • Perform clinical review or validation of extracted data

  • Verify data completeness or accuracy

  • Sync case status updates back to your scanner platform

  • Complete fields our AI cannot extract

You remain responsible for reviewing extracted data and correcting errors. See Section 6 (Sub-processors) for details on Anthropic's involvement.


4.3 Support and Troubleshooting

  • Responding to your support inquiries

  • Diagnosing and resolving technical issues

  • Providing account or billing assistance

  • Monitoring Platform security and preventing fraud


4.4 Legal and Compliance Obligations

  • Complying with legal requests from law enforcement or regulators

  • Protecting against fraud, abuse, or security threats

  • Enforcing our Terms & Conditions

  • Meeting data retention requirements under Irish, UK, and EU law


4.5 Improvement and Analytics

  • Analyzing how the Platform is used to improve features and performance

  • Conducting user research and collecting feedback

  • Creating aggregated or de-identified reports (e.g., usage statistics, feature adoption trends)

  • Testing new features and optimizing user experience

We do not use personal data for marketing or promotional purposes without your explicit consent.


5. Our Legal Basis for Processing

Under GDPR/UK GDPR, we process personal data on the following legal bases:

For any processing beyond the above, we will seek your explicit consent and inform you via email or in-Platform notice.


6. Sub-Processors and Data Sharing

We do not sell personal data. We share data only with third parties who assist us in delivering the Services and operate under data processing agreements.


6.1 Sub-Processors

We currently engage the following sub-processors to handle personal data:

Anthropic's Data Processing Addendum: https://www.anthropic.com/legal/data-processing-addendum


6.2 Right to Object to Sub-Processors

Under GDPR Article 28(4), you have the right to object to our use of sub-processors on data protection grounds. If you have concerns about any sub-processor, contact us at support@smilegeniusdental.com within 14 days of notification of the sub-processor addition. We remain fully liable for all sub-processors' compliance.


6.3 International Transfers

Data transferred to Anthropic (United States) and Stripe (where applicable) is protected by:

  • Standard Contractual Clauses (SCCs) under GDPR Chapter V

  • UK International Data Transfer Addendum (UK IDTA) for UK GDPR compliance

  • Anthropic's and Stripe's commitment to data protection safeguards aligned with GDPR standards

You can request copies of these transfer mechanisms at support@smilegeniusdental.com.


6.4 Other Sharing

We may share personal data where:

  • Required by law (e.g., court orders, law enforcement requests)

  • Necessary to protect safety or legal rights

  • As part of a merger, acquisition, or sale of assets (with notice)

  • With your explicit consent


7. Data Retention and Deletion


7.1 Retention Periods

We retain personal data for as long as necessary to provide the Services and comply with legal obligations:


7.2 Deletion Upon Termination

When your subscription terminates:

  1. First 30 days: Case data remains accessible to you for download/retrieval

  2. Days 31–90: Case data is deleted from production systems

  3. Days 91–180: Backup copies are retained for disaster recovery only

  4. Day 181: All personal data is permanently deleted


Exceptions:

  • Data required by law is retained for the minimum legally required period

  • Aggregated/de-identified data may be retained indefinitely

  • Backup copies may be kept for up to 90 additional days in secure offline storage per Section 7.1


7.3 Your Right to Erasure ("Right to be Forgotten")


Under GDPR Article 17, you may request deletion of your personal data, except where we must retain it by law or to provide Services. Submit erasure requests to support@smilegeniusdental.com.


8. Your Rights Under GDPR / UK GDPR

As a Data Subject under GDPR/UK GDPR, you have the following rights:


8.1 Right of Access (Article 15)

You have the right to obtain a copy of your personal data and information about how we process it.


8.2 Right of Rectification (Article 16)

You have the right to correct inaccurate or incomplete personal data. You can update much of this information directly in your account settings; for assistance, contact support@smilegeniusdental.com.


8.3 Right of Erasure (Article 17)

You have the right to request deletion of your personal data, subject to legal retention requirements.


8.4 Right to Restrict Processing (Article 18)

You have the right to request that we limit processing of your personal data to storage only (e.g., while a dispute is resolved).


8.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.


8.6 Right to Object (Article 21)

You have the right to object to processing of your personal data for certain purposes, particularly for legitimate-interest-based processing.


8.7 Rights Related to Automated Decision-Making (Article 22)

You have the right to request human review of decisions that have legal or similarly significant effects on you, if made solely by automated means (e.g., AI).


8.8 How to Exercise Your Rights

To exercise any of the above rights, submit a request to: support@smilegeniusdental.com
Subject line: "GDPR Data Subject Request — [Type: Access / Rectification / Erasure / etc.]"

Our response timeline:

  • Acknowledgement: 5 business days

  • Resolution: 30 calendar days (extendable to 60 days for complex requests, with notice)


9. Security and Data Protection


9.1 Technical and Organisational Measures

We implement appropriate safeguards under GDPR Article 32 to protect personal data:

  • Encryption in transit (TLS/HTTPS) for all data transmitted to/from the Platform

  • Encryption at rest for stored personal data

  • Role-based access controls — users access only data necessary for their role

  • Authentication controls — strong password requirements, optional multi-factor authentication

  • Audit logging — all access to personal data is logged

  • Environment segregation — production, staging, and development environments are isolated

  • Secure credential management — scanner and practice management system credentials are stored in encrypted vaults

  • Regular security assessments — penetration testing and vulnerability scans

  • Personnel training — staff handling personal data receive data protection training


9.2 Incident Response

In the event of a Personal Data Breach, we will:

  • Notify you within 48 hours of discovery

  • Provide details of the data affected, affected individuals, and likely consequences

  • Explain measures taken to mitigate harm

  • Cooperate with law enforcement or regulators

For credential compromise specifically, we will notify you within 24 hours and immediately rotate/revoke affected credentials.


9.3 Security Certifications and Standards

We align our security controls with:

  • GDPR Article 32 technical and organisational safeguards

  • HIPAA Security Rule standards (for alignment with potential US expansions; see Section 9.4)

  • Industry best practices for SaaS platforms

We can provide a SOC 2 Type II report or equivalent third-party attestation upon request.


9.4 HIPAA Compliance (US Customers Only)

The Health Insurance Portability and Accountability Act (HIPAA) applies only if you are a US Covered Entity or Business Associate and submit Protected Health Information (PHI) to the Platform.

If you are a US Covered Entity or Business Associate:

  • Do not submit PHI to the Platform without first executing a Business Associate Agreement (BAA)

  • Request a BAA at support@smilegeniusdental.com

Absent an executed BAA, you must not submit PHI, and we disclaim all HIPAA obligations.


10. Cookies and Tracking Technologies


10.1 What Are Cookies?

Cookies are small text files stored on your device that enable our Platform to remember you and personalize your experience.


10.2 Types of Cookies We Use


10.3 Third-Party Cookies

We use analytics tools (e.g., Mixpanel) that may set cookies to track usage patterns and help us improve the Platform. These tools operate under their own privacy policies.


10.4 Your Cookie Preferences

You can control cookies via your browser settings:

  • Disable non-essential cookies (though this may affect Platform functionality)

  • Clear cookies at any time

  • Opt out of third-party analytics via [Insert Link if applicable]

For detailed cookie management, see our Cookie Policy.


11. Children's Privacy

The Platform is not directed at children under 13. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 13, we will delete it immediately and contact the parent or guardian. Contact support@smilegeniusdental.com if you have concerns.


12. Third-Party Links and Services

The Platform may link to third-party websites (e.g., documentation, integrations, practice management systems). We are not responsible for their privacy practices. Please review their privacy policies before sharing personal data.


13. Data Processing Terms (GDPR Article 28)

For customers who are dental laboratories or clinics (i.e., Data Controllers), the data processing terms are set out in the Terms & Conditions, Section 5. These terms constitute our Data Processing Agreement under GDPR Article 28(3).

Key obligations:

  • We process personal data only on your documented instructions

  • We ensure staff confidentiality undertakings

  • We implement Article 32 safeguards (Section 9.1 above)

  • We assist with Data Subject rights (Section 8)

  • We notify you of breaches (Section 9.2)

  • We delete or return data at subscription end (Section 7.2)

  • We allow audits and provide compliance evidence (Terms & Conditions, Section 5.3)


14. California Privacy Rights (CCPA/CPRA) — US Users Only

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) may apply. Under CCPA/CPRA, you have rights to:

  • Know what personal information we collect

  • Delete personal information

  • Opt out of certain uses or sales

  • Non-discrimination for exercising rights


Note: CCPA/CPRA does not apply to B2B data (business contact information). If you believe we are processing your personal information as a consumer under CCPA/CPRA, contact us at support@smilegeniusdental.com.


15. Updates to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email or in-Platform notice at least 30 days before the effective date. Continued use of the Platform after the effective date constitutes acceptance of the updated policy.

Current version: January 2026
Next review date: January 2027


16. Contact Us

Questions about this Privacy Policy or our data practices?


Email: support@smilegeniusdental.com
Data Protection Contact: Arun Kumar, CTO

Complaints:

  • Ireland: Data Protection Commission (www.dataprotection.ie)

  • UK: Information Commissioner's Office (www.ico.org.uk)


© 2026 Smile Genius Dental Limited. All rights reserved.

Built to deliver smoother workflows and stronger margins for dental groups and labs.

© 2026 Smile Genius Limited. All rights reserved.

Built to deliver smoother workflows and stronger margins for dental groups and labs.

© 2026 Smile Genius Limited. All rights reserved.

Built to deliver smoother workflows and stronger margins for dental groups and labs.

© 2026 Smile Genius Limited. All rights reserved.