Privacy policy

Last updated: July 2026

1. Who we are and what data we process

Plataforma Dental is management software for dental practices in the Dominican Republic. We process two kinds of data: (a) the practice’s account data and its team’s data (name, email, role) and (b) the data the practice records about its patients, including health data, which Law 172-13 classifies as sensitive.

2. The practice is the controller

Each practice is the controller of its patients’ data; Plataforma Dental acts as processor: we store and process that data solely to provide the service, following the practice’s instructions. We do not use patient data for advertising and we do not sell it to third parties.

3. How we protect the data

  • Patient identification data (ID number, phone, address) is stored encrypted with AES-256-GCM — the same standard banks use — with keys derived via HKDF; the master key never leaves our servers.
  • Each practice is isolated at the database level (Row Level Security): no practice can see another’s data.
  • Internal access follows the principle of least privilege: reception and billing do not access clinical information.
  • Every access and modification is recorded in a tamper-proof audit log, as required by the clinical record regulations.
  • Product analytics works only with aggregated data, never with PII.

4. Payments

We do not store card numbers. When a practice purchases a paid plan, the subscription is processed by PCI-DSS certified providers: Polar (international USD payments, which also issues the invoice with your country’s taxes) and, once local billing is enabled, AZUL (DOP payments). As long as a practice doesn’t purchase or activate those features, none of its data reaches these providers.

5. Where your data is processed (international transfer)

To provide the service, Plataforma Dental relies on providers whose infrastructure is located outside the Dominican Republic, in the United States. The database and clinical files (X-rays, photos) reside in AWS region us-west-1 (California). This means the data the practice records — including patients’ health data, which Law 172-13 classifies as sensitive — is transmitted and stored outside the country. Providers include, among others: Supabase (database, authentication and files, on AWS infrastructure), Vercel (hosting) and Resend (email). Others may be added, depending on the features each practice has active: Polar (only when purchasing a paid plan), Alanube (only with e-CF electronic invoicing activated) and AZUL (only with local billing activated) — until those features are activated, these providers receive no data at all. If the practice uses the assisted import of paper forms, Anthropic (transcription of handwritten forms) is added: when choosing “import with a photo”, the image of the filled form — which may contain personal and health data, including clinical checkboxes — is sent to Anthropic for transcription. Using that path is always an explicit action by the operator (there is an alternative template mode in which only text-field crops travel, or nothing at all). Anthropic does not use that data to train its models, per its commercial terms, does not keep it as part of a training corpus, and everything transcribed goes through human review before being saved to the record.

Under Law 172-13, hosting data in the cloud outside the DR constitutes an international transfer; that is why we inform you expressly before you use the platform. As a rule, the law restricts transfers to countries without an adequate level of protection and only allows them through the exceptions it provides, among them the data subject’s consent. This transfer does not rely on an adequacy declaration — we are not aware of one, we do not invoke one, and no authority has approved or registered it — but on the consent exception.

The legal basis distinguishes two kinds of data. (a) For your account and team data: your consent when accepting this policy and the necessity of the transfer to provide the service to you. (b) For patient data: accepting this policy is not the data subject’s consent and does not by itself enable the transfer — the basis is each patient’s express written consent, which the practice, as controller, must obtain.

Although the transfer is real, we apply safeguards: personal identifiers (ID/passport, phone, address) are encrypted with AES-256-GCM before reaching the database, on top of the provider’s encryption at rest. The rest of the clinical content is protected by isolation between practices (RLS), encryption at rest and a private bucket with short-lived links. Added to this are HTTPS/HSTS, least-privilege role-based access, a second factor for clinical staff, and a tamper-proof audit log. These measures mitigate the risk, but they are not the legal basis of the transfer.

With each provider we are formalizing a data processing agreement (DPA) binding it to process data only under our instructions. We do not claim any as signed that is not yet signed.

Health data requires a higher consent — express and written, from the patient. As controller, the practice must obtain it from each patient, including the transmission to these providers outside the country. We, as processor, provide the technical and contractual means.

6. Your rights (Law 172-13)

Data subjects may exercise their rights of access, rectification, cancellation and objection. If you are a patient of a practice that uses the platform, address your request to the practice (the controller); if you are a user of the platform, write to us and we will respond within the legal deadlines. When closing the account, the practice can export its data; we keep what health and tax regulations require us to retain.

7. Cookies

We use only essential session cookies (authentication) and the cookie that remembers your language. We do not use advertising or third-party tracking cookies.

This English translation is provided for convenience only; the Spanish version governs.