Privacy Policy
What we collect, why we hold it, where it physically lives, who else touches it, and what you can demand from us. Written against UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
In effect from:
1.Two kinds of data, two different roles
Your data — your name, your clinic, your account, your billing record. For this we are the controller: we decide why and how it is processed, and this policy is our commitment to you.
Your patients’ data — everything you import or create inside your clinic workspace. For this your clinic is the controller and we are the processor: we act only on your documented instructions, and we do not decide what happens to it.
This distinction is not paperwork. It means your patient list is not ours to use, sell, mine or move, and never becomes part of another clinic’s workspace.
2.What we collect
- Account and identity: name, email address, phone number where you give one, password hash, role and the clinic you belong to.
- Clinic profile: clinic name, country, plan, subscription status and settings.
- Clinic Scorecard: your answers to the assessment and the contact details you submit to receive the result.
- Patient data you import: patient name, contact number, appointment and treatment-plan history, and campaign status. Deliberately minimal — the platform does not ask for, and is not built to store, clinical notes, diagnoses, radiographs or images.
- Billing metadata from our checkout provider: what was bought, when, for how much, and the buyer’s contact details. Never card numbers, never CVV.
- Communications: emails and messages you send us, and our replies.
- Technical records: IP address, browser and device type, timestamps and error logs, kept for security, fraud prevention and debugging.
3.Why we process it, and on what basis
- To provide the platform and the programs you bought — performance of our contract with you.
- To deliver your Clinic Scorecard result and, only if you ticked the box, the follow-up email series — your consent, withdrawable at any time.
- To send service messages: renewals, security notices, changes to these policies — our legitimate interest in operating the service, and in some cases a legal obligation.
- To issue invoices and meet tax and accounting duties — legal obligation under UAE law.
- To keep the service secure, investigate abuse and prevent fraud — our legitimate interest.
- To improve the product using aggregated, de-identified usage statistics that cannot be traced back to a patient or a clinic.
4.What we do not do with your data
- We do not sell personal data, ever, to anyone.
- We do not share your data or your patients’ data with advertising networks or data brokers, and we run no advertising or analytics trackers on this site.
- We do not send patient data to any third-party artificial-intelligence provider. The Revenue Agent runs on deterministic rules and templates inside our own systems — there is no external model call in the path of your patient list.
- We do not use your patients’ data to train models, and we do not use one clinic’s data to serve another clinic.
5.Who processes data on our behalf
We keep the list of processors short on purpose, and we name every one of them:
- Vercel — application hosting and content delivery.
- Neon — managed PostgreSQL database hosting.
- Resend — transactional email (magic links, results, notifications).
- Kajabi — checkout, course delivery, community and marketing email; it receives the buyer details needed to complete a purchase and open an account.
- Zapier — routes Clinic Scorecard leads into our marketing sequence, where that route is enabled.
- Meta / WhatsApp Business — patient messaging, and only when your clinic enables that channel.
- We may also disclose data where the law requires it, or to establish or defend a legal claim. If we are ever compelled to hand over data, we will tell you unless we are legally barred from doing so.
6.Where your data is stored
The production database is hosted in the European Union (Frankfurt), and application hosting is delivered from the provider’s global network. We state this plainly because it matters and because you deserve to know before you upload anything.
The UAE Personal Data Protection Law permits transfers to jurisdictions that provide an adequate level of protection; the European Union is such a jurisdiction, and its data-protection regime is among the strictest in the world.
We are actively evaluating a UAE-region deployment. Until that is in place, large-scale imports of patient data into production are restricted by design — a limit we enforce in software rather than in a promise. We will notify customers in advance of any change to the storage location.
7.How we protect it
- All traffic is encrypted in transit with TLS; data at rest is encrypted by our hosting providers.
- Every clinic’s data sits in its own tenant boundary, and every query is scoped to the clinic in the signed-in session — never to anything supplied by a browser.
- Role-based access control inside the platform: staff see what their role permits, nothing more.
- Passwords are stored only as salted hashes; sign-in also supports single-use magic links.
- Access to production systems is limited to a minimal number of authorised people and protected by multi-factor authentication.
- No security is absolute. If a breach affects your data, we will notify you and the competent authority as the law requires, with what we know and what we are doing about it.
8.How long we keep it
- Clinic Scorecard leads: up to 24 months from your last interaction, or until you ask us to delete them — whichever comes first.
- Account and clinic data: for the life of your subscription and 90 days after it ends.
- Patient data: exportable for 30 days after termination, then deleted; or deleted within 30 days of a written deletion request while the subscription is live.
- Invoices and tax records: retained for the period UAE law requires, currently five years.
- Security and error logs: up to 12 months.
9.Your rights
Under the UAE Personal Data Protection Law you may ask us to:
- give you a copy of the personal data we hold about you;
- correct data that is wrong or incomplete;
- delete data we no longer have a lawful reason to keep;
- restrict or object to a particular kind of processing;
- transfer your data to you or to another provider in a machine-readable format;
- withdraw a consent you gave — which stops the processing that relied on it, without affecting what was lawful before;
- and to complain to the UAE Data Office if you believe we got it wrong.
- Write to the address at the end of this page. We respond within 30 days, free of charge, and we do not require a phone call to action a request.
10.Patient data — additional commitments to clinics
We will process patient data only on your documented instructions, keep it confidential, and impose equivalent obligations on the processors named above.
We will support you in answering a patient’s access or deletion request, and we will return or delete patient data at the end of our relationship, at your choice.
A written data processing agreement is available on request at no cost — ask, and we send it the same business day.
12.Children
The service is sold to dental professionals and is not directed at children. Where a clinic’s patient records include minors, the clinic remains responsible for the consents required under the law that applies to it.
13.Changes to this policy
We update this policy as the product and the law develop; the date at the top always shows the version in effect. Material changes are emailed to account holders at least fourteen days in advance.
Questions about this document
Write to us before you buy, not after. We answer in writing, in Arabic or English, within one business day — no call required.
avera.uae@gmail.com
See also: Terms of ServiceRefund & Guarantee Policy
Core Dent OS LLC · Registered in the United Arab Emirates · Founded by Dr. Sana Abdalla