1. Introduction
We respect your privacy and your patients' privacy. This policy explains what data we collect and how we use and protect it.
2. Our role and the clinic's role
- Patient data: the clinic is the controller and Molarion is a processor acting for the clinic. We store and process it only to provide the service to the clinic and never for any other purpose.
- Clinic account and team data: we are directly responsible for it.
3. What we collect
a. Clinic and team details
- Clinic name, address, phone and email.
- Users' names, phone numbers, emails and roles.
- Passwords, stored hashed so nobody can read them, including us.
b. Data the clinic enters about its patients
- Name, phone and date of birth.
- Medical history, allergies and chronic conditions.
- Dental chart, treatment plans, X-rays and photos.
- Appointments, invoices and payments.
c. Usage data
Each user's last sign-in and a log of important actions in the clinic, for security and so the owner knows who did what.
d. Website visitors
Number of visits and where they came from. We don't store visitors' IP addresses; we turn them into an anonymous code that changes daily and can't identify anyone.
4. Why we use data
- To run the system and provide the service to the clinic.
- To secure accounts and prevent unauthorised access.
- To contact the clinic about its subscription and support.
- To improve the system using general statistics that never identify a patient.
We never sell data and never use patient data for advertising.
5. Who can see the data
- Inside the clinic: each user sees what their role allows; reception doesn't see medical history and a doctor sees only their own patients.
- Other clinics: never. Each clinic has its own address and its users cannot sign in to any other clinic.
- The Molarion team: we only look at a clinic's data when the clinic asks for support, or when the law requires it.
- Service providers: the system runs on a trusted cloud hosting provider bound by security standards and not allowed to use the data for any purpose. We also use a Google font service to display the website; it receives no clinic or patient data.
- WhatsApp: messages the system prepares, such as reminders and treatment plans, are sent from the clinic's own WhatsApp when a user taps send. Molarion never messages patients by itself.
6. How we protect data
- Fully encrypted connections (HTTPS).
- Hashed passwords and protection against password guessing.
- X-ray files have no public links; only a signed-in user with permission can open them.
- Daily backups kept in more than one place.
- Protected servers monitored around the clock.
No system on the internet is 100% secure. If a breach ever affects your data, we will tell the clinic immediately.
7. How long we keep data
- During the subscription: all data is kept.
- After the subscription ends: kept for 90 days, then deleted permanently.
- Backups: deleted automatically after 14 days.
- Website visit records: deleted after 400 days.
8. Your rights
The clinic can at any time ask for a copy of all its data, edit or delete data inside the system, and ask us to delete its account and all its data permanently.
A patient who wants to see, correct or delete their data should contact the clinic treating them, as the clinic controls their data. We will help the clinic carry out the request.
9. Cookies
We only use essential cookies: to keep you signed in, and to remember your language and dark mode. There are no advertising cookies and no third-party trackers.
10. Minors
The system is for clinics, not individuals. Clinics enter data about patients under 18 with a parent's or guardian's consent, under their own responsibility.
11. Changes to this policy
If we make a significant change to this policy we will notify clinics at least 15 days before it applies and update the "last updated" date.
12. Contact
For any privacy question or request about your data:
WhatsApp: +201099373982
Email: info@molarion.com
