Trust & transparency
Data safety at DentaSK
Last updated: 23 September 2026
This page describes DentaSK's current software safeguards and customer controls in plain language. It is not a certification, a guarantee against incidents, or the app-specific Data safety declaration that a developer must separately complete in Google Play Console.
Access is scoped to the right team
DentaSK authenticates users and uses organization, franchise, branch and role permissions to decide which records and actions each person may access. Clinic administrators manage staff assignments; organization-level visibility can differ from franchise and branch access. Clinics should promptly remove departing staff and regularly check who can access clinical and connected-service data.
Sensitive data is handled deliberately
- Passwords are stored as hashes rather than plain text.
- Integration credentials and selected sensitive patient information are encrypted in the application database.
- Access and activity events help the service audit changes and investigate problems.
- Production services should be reached over HTTPS. Customers should verify that their deployed domain shows a valid certificate before entering information.
These measures reduce risk but cannot remove it completely. Not every field has the same at-rest protection: some operational fields must remain searchable to provide the service. Do not interpret “encrypted” here as a claim of end-to-end encryption of all clinic data.
Connected accounts stay under customer control
A clinic or authorized asset owner decides whether to connect Google, Meta, Instagram or WhatsApp. Provider approval and ownership control what data can be retrieved and what actions can be performed. DentaSK stores the authorized connection and selected asset IDs; the owner can remove an asset binding or disconnect a provider in the application and revoke DentaSK in the provider's own security settings.
Removing a connection stops later access but does not automatically delete messages, reviews or reports already imported into the DentaSK workspace. A verified deletion request is needed for eligible stored copies. Provider-held data remains under that provider's own deletion process.
AI, voice and messaging require configuration
AI-generated suggestions, replies and voice features are optional. They may involve sending the relevant prompt, conversation or call information to a configured provider. Clinical judgment, consent, patient communication and final approval remain the clinic's responsibility. Customers should avoid sharing unnecessary patient-sensitive detail in prompts and use only channels for which they have permission.
Sharing and retention in brief
| Data | Who may receive it | Customer control |
|---|---|---|
| Clinic and patient records | Authorized staff and service infrastructure; configured processors only when a feature needs them | Roles, correction requests and clinic-led record requests |
| Social, Google and WhatsApp data | Authorized clinic users, relevant connected provider and service infrastructure | Asset selection, disconnect, provider revocation and deletion request |
| Demo form details | DentaSK's authorized team and service infrastructure | Ask DentaSK to correct or remove the enquiry |
| Logs and security records | Authorized support/security personnel and infrastructure providers | Contact support; some records must be retained for investigation or law |
We do not publish a blanket retention deadline because healthcare, financial, security and backup records have different requirements. We do not sell personal data. Read the full Privacy Policy and the Data Collection guide for more detail.
What to do if something looks wrong
- Remove access for an account that should no longer be active, and change its provider password if you suspect compromise.
- Disconnect the affected integration and revoke DentaSK access at the provider if appropriate.
- Email support@dentask.in with the organization name, affected account and a description. Do not email patient records or passwords.
For deletion, follow our Data Deletion Instructions. DentaSK will verify authority before making changes to another person's or a clinic's records.