top of page

DENTALVERSE PRIVACY NOTICE

Important — Legal Review Candidate

The Korean source document is a legal review candidate for the Dentalverse Privacy Notice used in the dental-clinic signup Legal UI and is not yet effective. This revision integrates Qwen and Claude review of v0.3.0, subsequent cross-review, and GPT final decisions.

This document is a notice concerning processing of personal data and is not, by itself, blanket Consent to personal-data processing. Processing that requires Consent uses a separate Consent document and purpose-specific ConsentEvidence. Marketing uses MarketingConsentEvent, Optional Analytics uses AnalyticsConsentEvent, and purpose-specific patient Consent uses PatientConsentRecord or approved equivalent Evidence.

The Korean source document is for product and legal review. A Bahasa Indonesia version must be prepared and finally reviewed by Indonesian local counsel before publication.

At a minimum, the following must be finalized before publication:

  • Dentalverse Indonesian Controller/contracting entity legal name, registration number, and address;

  • PSE registration/operating entity;

  • responsible privacy function/person and contact details;

  • customer-support, data-subject-rights, and personal-data-incident reporting channels;

  • local legal review of purpose-specific legal bases for Organization User personal data;

  • DPA and Subprocessor authorization structure;

  • actual ThirdPartyProcessor/Subprocessor list;

  • actual processing, storage, backup, logging, support-access, retention, deletion, and training policies for each Processor;

  • Organization User data retention periods;

  • separate Controller/Processor roles and patient notice/Consent documents for Patient, Lab, and AI data; and

  • final Bahasa Indonesia version.

 

Confirmed Canonical Inputs

D-LAB-PATIENT-IDENTITY
= APPROVED

D-LAB-FACIAL-IMAGE
= APPROVED

D-LAB-DERIVED-FACIAL-DATA
= OPTIONAL_SUPPLEMENTARY

D-LAB-ACCESS-MODEL
= CASE_BOUND

D-LAB-PRIVACY-PRINCIPLE
= PURPOSE_LIMITED_MINIMUM_NECESSARY

D-LAB-FACIAL-MEDIA-CLASS
= HIGH_RISK_LAB_MEDIA

D-LAB-LEGAL-ROLE
= OPEN

D-LAB-FACIAL-LEGAL-BASIS
= OPEN / DPIA REQUIRED FOR DESIGN

D-AI-DATA-RESIDENCY
= NOT_VERIFIED

D-CHILD-CONSENT
= PARENT_OR_GUARDIAN_REQUIRED_WHEN_APPLICABLE

D-FACIAL-GOVERNANCE
= SPECIFIC_HIGH_RISK_DEFAULT / CONTROLLER_DPIA_EVIDENCE_REQUIRED

The OPEN status of D-LAB-LEGAL-ROLE, D-LAB-FACIAL-LEGAL-BASIS, and D-AI-DATA-RESIDENCY does not reopen the business decision permitting use of patient name or necessary facial images for Lab work. These open items determine the legal role, legal basis, notice/Consent, security/audit, and regional controls through which the approved workflow will be implemented.

 

0. Role of this Privacy Notice

Dentalverse legal documents and evidence are separated as follows:

Terms of Service + DPA + Pilot Terms
→ Agreement Package
→ AgreementEvidence

Privacy Notice
→ Privacy Notice
→ NoticeDeliveryRecord / NoticeAcknowledgement

AI Patient Consultation Service Guideline
→ Guideline
→ GuidelineAcknowledgement

First-use AI Feature Safety Notice
→ Feature Safety Notice
→ FeatureSafetyNoticeAcknowledgement

Marketing & Promotional Communications
→ Optional Consent
→ MarketingConsentEvent + MarketingPreference

Service Improvement & Statistics Data Use
→ Optional Consent
→ AnalyticsConsentEvent + AnalyticsPreference

Purpose-Specific Patient Consent
→ Patient Consent
→ PatientConsentRecord or approved equivalent Evidence

Acknowledgement of this Privacy Notice does not mean:

  • separate re-acceptance of the Service agreement;

  • blanket Consent to all personal-data processing;

  • written Organization authorization for use of a Subprocessor;

  • patient Consent to processing of Patient Data;

  • patient Consent to facial-image processing for AI image generation; or

  • another Organization User's optional Consent.

 

Article 1. Purpose and Scope

1.1 This Privacy Notice explains how Dentalverse collects, uses, stores, shares, and protects personal data of Dental Organization Representatives and Organization Users.

1.2 The direct data subjects of this Notice are:

  • Organization owner dentist or other authorized Representative;

  • Pay Doctors;

  • administrators;

  • general staff;

  • consultation staff; and

  • other individuals registered by an Organization as Dentalverse Users.

1.3 This Notice applies to processing for:

a. Organization signup and representative-authority verification;

b. Organization User account creation, invitation, and authentication;

c. Permission and Clinic Assignment management;

d. service security, audit, and incident response;

e. customer support and complaint handling;

f. optional marketing;

g. service improvement and statistical analysis under separate optional Consent; and

h. other processing for which Dentalverse independently determines the purpose and means with respect to the above data subjects.

1.4 This Notice is not a Privacy Notice directly addressed to patients.

Article 7 explains Dentalverse's baseline role when processing Patient Data, but patient-facing privacy notices, legal bases, and Consent for treatment, consultation, AI, and Lab purposes are managed through the Dental Organization's Controller responsibilities and separate patient workflows.

1.5 This Notice assumes the following current Pilot service areas:

  • Patient Management;

  • AI Patient Consultation; and

  • Lab Orders.

1.6 Production EMR functions, Voice clinical-conversation processing, and the Patient Portal are outside the current Pilot scope. The personal-data processing scope and this Notice will be reassessed if those features are added.

 

Article 2. Definitions

For purposes of this Notice:

  1. Personal Data (Data Pribadi) means information that identifies, directly or indirectly, a natural person.

  2. Specific Personal Data (Data Pribadi yang bersifat spesifik) means personal data requiring enhanced protection under applicable UU PDP, including health data and biometric data.

  3. Data Subject (Subjek Data Pribadi) means the natural person to whom personal data relates.

  4. Controller (Pengendali Data Pribadi) means a person/entity that determines and controls the purposes and means of personal-data processing.

  5. Processor (Prosesor Data Pribadi) means a person/entity that processes personal data on behalf of a Controller.

  6. Subprocessor (Subprosesor) means another Processor engaged by a Processor to perform part of the processing on behalf of the Controller.

  7. Organization User means an individual registered/invited by a Dental Organization and granted an account and Permissions in Dentalverse.

  8. Patient Data (Data Pasien) means patient personal data processed in connection with Patient Management, consultation, Lab Orders, and related dental operations.

  9. NIK (Nomor Induk Kependudukan) means the Indonesian national population identification number.

  10. Facial Image means an image containing an identifiable patient's face. Until local legal review confirms a narrower treatment, Dentalverse conservatively treats identifiable patient facial images in dental/clinical/fabrication contexts as SPECIFIC/HIGH_RISK for Governance purposes. Final legal classification under UU PDP as biometric and/or health data will be determined by local counsel in light of processing purpose, technology, and identification function.

  11. Intraoral Photo means an image of the inside of the mouth, teeth, gingiva, occlusion, or similar content used for fabrication or consultation, classified separately from a facial image.

  12. Essential Telemetry means minimum technical/operational events necessary for security, incident detection, performance, and service stability.

  13. Optional Analytics Data means usage-behavior and analytics data processed for service improvement/statistics under separate optional Consent.

  14. NoticeAcknowledgement means evidence that a Privacy Notice was delivered, available, or acknowledged; it is not Consent.

  15. ConsentEvidence means the high-level evidence concept proving a data subject's choice for processing where Consent is required by law or product policy. Purpose-specific concrete objects include PatientConsentRecord for patient Consent, MarketingConsentEvent for Marketing, and AnalyticsConsentEvent for Optional Analytics.

 

Article 3. Dentalverse Personal-Data Processing Roles

3.1 Organization User Personal Data

To the extent Dentalverse determines the purpose and means for processing personal data relating to the accounts, authentication, support, and Service use of Representatives, Pay Doctors, employees, and other Organization Users, Dentalverse is responsible as Controller of that personal data.

3.2 Patient Data

When a dental clinic uses Dentalverse for Patient Management, consultation, or Lab Orders and Dentalverse processes Patient Data under the clinic's documented instructions, the following generally applies:

Dental Organization
→ Controller

Dentalverse
→ Processor

The DPA governs specific processing purposes, data categories, processing period, Subprocessors, return/deletion, audit, and incident response.

3.3 Role Change or Independent-Purpose Processing

If Dentalverse determines an independent purpose and means for Patient Data outside the dental clinic's instructions and the purposes of the DPA, that processing is not treated merely as Processor processing.

Before such processing is performed, Dentalverse must establish a separate role analysis, lawful basis, notice, contractual basis, and Consent where required.

3.4 Roles of Labs and Third-Party AI

The Controller/Processor status of external recipients, including Labs, CAD Organizations, and third-party AI Providers, is determined by the actual processing purpose, instruction relationship, and contractual structure.

This Notice does not categorically fix every external recipient as Controller or Processor.

 

Article 4. Organization User Personal Data Collected

4.1 Representative/Applicant Information

Category                                                               Examples                                                                                                  

Account identifiers                                              name, email, User ID                                                                                                    

Authentication information                               password hash, authentication method, authentication status                         

Organization information                                  Organization name, Clinic, position or relationship within Organization            

Representative-authority information             Representative qualification, relationship to Organization, verification materials

Contact information                                            phone number, WhatsApp number

Professional qualification information             dentist license number, qualification verification

4.2 Pay Doctor, Staff, and Other Organization User Information

When the Organization registers or invites a User, the following may be processed:

  • name;

  • business email;

  • Organization/Clinic affiliation;

  • User ID;

  • Provider linkage information, where applicable;

  • Permission, Role, and Clinic Assignment;

  • healthcare-professional qualification or license information, where needed;

  • account active/inactive status; and

  • invitation, signup, and first-login times.

Where an Organization enters another person's personal data into Dentalverse, the Organization must verify that the registration is lawful and limited to what is necessary.

4.3 Service-Use and Security Information

The following may be generated through use of the Service:

  • login/logout times;

  • session identifiers;

  • technical device/browser/app information;

  • IP address or network-security information, if collected;

  • successful/failed authentication history;

  • Permission change history;

  • command, approval, and security-related Audit Events;

  • essential Telemetry such as error codes, service status, and response times; and

  • customer-support tickets and request history.

4.4 Optional Information

Where the individual has provided separate optional Consent, Dentalverse may process:

Marketing and Promotions

  • email;

  • phone number;

  • WhatsApp number;

  • selected marketing channels; and

  • opt-in/withdrawal records.

Service Improvement and Statistics

Within the scope specified in the separate Consent document:

  • frequency of feature use by the Organization User;

  • screen/feature usage events;

  • optional analytics cookies or similar identifiers; and

  • usage-behavior data used to create aggregates/statistics.

By default, this optional Consent does not include:

  • raw Patient Data;

  • patient name, NIK, or contact information;

  • patient facial images;

  • patient intraoral scans or photographs;

  • Lab Case content;

  • pseudonymized Patient Data;

  • EMR clinical records; or

  • Voice audio or conversation content.

If Patient Data is to be used separately for service improvement or statistics, Dentalverse will not rely on this Organization-User optional Consent alone and will separately review role, legal basis, notice, Consent, and anonymization requirements.

 

Article 5. Sources of Personal Data

Dentalverse may collect Organization User personal data from:

  1. information entered directly by the Representative or User;

  2. information provided by the Organization Representative/administrator when registering Organization Users;

  3. information automatically generated during login, authentication, and Service use;

  4. information provided during customer support or complaint handling;

  5. official or contractual verification sources used for lawful professional/Organization verification; and

  6. Marketing/Analytics information provided under separate optional Consent.

Dentalverse generally does not expand collection beyond what is necessary for the applicable purpose.

 

Article 6. Purposes and Legal Bases for Processing Organization User Personal Data

6.1 General Principle

Dentalverse applies an appropriate legal basis to each personal-data processing activity under UU PDP Article 20.

The applicable legal basis may vary according to the data subject's status, processing purpose, and actual contractual relationship. Final mapping of legal bases in this Candidate must be confirmed through Indonesian local legal review before publication.

6.2 Purpose-Specific Mapping

Processing Purpose : Data Subject / Proposed Legal Basis / Notes

Organization signup and Representative account creation : Representative / PENDING LOCAL COUNSEL MAPPING — candidates include legitimate interests, an applicable pre-contract request, or another appropriate Article 20 basis / The contracting party is the Dental Organization, so contract-performance basis is not automatically applied to the Representative personally

Representative authority and Organization verification : Representative / PENDING LOCAL COUNSEL MAPPING — legitimate interests, or legal obligation where an identified law imposes one, etc. / Product/KYB necessity alone does not automatically establish a legal obligation; the specific law and verification scope must be identified first

Pay Doctor/staff account provision : Organization User / legitimate interests or another appropriate Article 20 basis / User may not be a direct party to the Organization contract, so contract performance is not applied categorically

Authentication, Permission, Clinic Assignment : Organization User / legitimate interests, contract-related operations, or legal obligation / least privilege and security purposes

Service security and abuse prevention : All Users / legitimate interests or legal obligation / balancing assessment applies

Audit/compliance : All Users / legal obligation or legitimate interests / depends on applicable law/contract

Customer support/complaint handling : Requester / contract-related processing or legitimate interests / depends on request

Essential service Telemetry : Organization User / legitimate interests / minimum necessary for service stability/security

Marketing/promotional communications : Relevant individual recipient / explicit Consent / MarketingConsentEvent + MarketingPreference

Optional service-improvement/statistics analysis ; Relevant data subject / explicit Consent / AnalyticsConsentEvent + AnalyticsPreference

 

6.3 Legitimate-Interest Processing

Where legitimate interests are used as the legal basis, Dentalverse evaluates the processing purpose, necessity, impact on the data subject, and the data subject's rights and interests through an appropriate balancing assessment.

6.4 Separation of Consent

Where Consent is the legal basis, it is:

  • separated by specific purpose;

  • provided in writing or a recordable electronic form;

  • separated from the basic Service Agreement;

  • capable of refusal;

  • capable of withdrawal; and

  • not used to impose an unfair disadvantage on use of basic services unrelated to the optional processing.

 

Article 7. Patient Data — Dentalverse as Processor

7.1 The direct data subjects of this Notice are Organization Users, not patients.

7.2 Dentalverse may process patient personal data while a Dental Organization uses Patient Management, AI Patient Consultation, and Lab Order services.

7.3 To the extent Dentalverse processes Patient Data under the dental clinic's documented instructions, the following generally applies:

Dental Organization
→ Controller

Dentalverse
→ Processor

The DPA governs processing purpose, data categories, retention/deletion, Subprocessors, audit, and incident response.

7.4 Depending on the activated service purpose, Patient Data may include patient identifiers, appointment/check-in information, media such as intraoral scans, intraoral photographs, and facial images, consultation information, and Lab Order data.

7.5 Article 7.4 does not mean all Patient Data is available to every function or recipient. Actual processing is restricted by the relevant feature purpose, dental-clinic instructions, lawful patient-processing basis, Permissions, DataSharingGrant, and applicable service-specific Gates.

7.6 Dentalverse does not rely solely on its Processor status to independently use Patient Data for:

  • Dentalverse's own marketing;

  • sale of data;

  • creation of an independent patient database;

  • unauthorized AI-model training/retraining; or

  • independent service-improvement or commercial purposes unrelated to dental-clinic instructions.

7.7 Specific Patient Data purposes, categories, recipients, legal bases, retention/deletion, and patient rights are governed by the DPA, patient-facing notice/Consent documents provided by the dental clinic, Lab/CAD agreements, and authoritative service rules.

7.8 Requests by patients concerning access, correction, deletion, or processing of their Patient Data should generally be submitted to the relevant Dental Organization as Controller. Dentalverse supports the Organization under the DPA.

 

Article 8. AI Patient Consultation and Third-Party AI Processing

8.1 Nature of the Function

The current Pilot may include AI Patient Consultation functions that use patient facial images to generate expected or simulated post-orthodontic images.

This processing primarily concerns Patient Data, not Organization User personal data. It is not legitimized by Organization User acknowledgement of this Notice or an Organization-User optional Consent.

8.2 Third-Party AI Processing Gate

A function processing patient facial images through third-party AI is activated only after the applicable requirements are met, including:

  • lawful basis of the dental Controller;

  • purpose-specific patient Consent or lawful representative Consent required by Dentalverse Pilot policy;

  • third-party Processor/Subprocessor contract and necessary authorization;

  • identification of the exact Provider, Model, and Endpoint;

  • verification of actual inference, storage, backup, logging, and support-access regions;

  • retention verification;

  • verification of model training/retraining use;

  • deletion and Provider data-handling policy;

  • personal-data classification and risk assessment for facial images;

  • DPIA where required;

  • security, audit, and Provenance; and

  • AI-generated-content disclosure and patient explanation.

Internal CMP numbers or machine-verification IDs are not exposed in the user-facing Privacy Notice and remain in the internal Compliance Gate Matrix.

8.3 Data Residency Status

Dentalverse has Indonesia domestic processing as a preferred deployment objective for Patient Data.

However, until the exact third-party AI Provider, Model, Endpoint, and actual inference, storage, backup, logging, and support-access regions are verified, the AI processing is not treated as Indonesia-only.

The current legal/product Governance state is:

D-AI-DATA-RESIDENCY
= NOT_VERIFIED

8.4 If Indonesia-Only Processing Is Verified

If actual inference, storage, backup/replication, logs containing Patient Data, and Provider support/operations access for a specific AI function are all verified to occur within Indonesia, the function may operate without a cross-border-transfer structure.

The availability of a Jakarta or Indonesia region setting alone does not establish that all processing for a specific AI model remains in Indonesia.

8.5 If Cross-Border Transfer Is Identified

If personal data is transferred, replicated, or backed up outside Indonesia or accessible from abroad, Dentalverse evaluates the applicable cross-border requirements under UU PDP Article 56 and implementing rules.

Dentalverse does not state that explicit Consent is always the only lawful mechanism for cross-border transfer. The legally required sequence—applicable protection level, appropriate binding safeguards, and, where required, data-subject Consent—is evaluated.

Separately, Dentalverse may require purpose-specific explicit patient Consent or lawful representative Consent as a product-safety Activation Hard Gate for third-party AI processing of patient facial images.

8.6 Feature Disablement

If required patient-processing requirements or third-party AI Gates are not met, only the relevant third-party AI image-generation function is disabled.

This does not automatically block Dental Organization signup, general Patient Management, or Lab Order functions that do not depend on the AI feature.

 

Article 9. Lab Orders and Patient Data Processing

9.1 Patient personal data may be processed or provided when a Dental Organization transmits a fabrication Case through Dentalverse to a Lab or CAD Organization.

9.2 Dentalverse designs Lab Data processing according to:

CASE_BOUND
+
PURPOSE_LIMITED
+
MINIMUM_NECESSARY

Only Patient Data necessary for design, fabrication, esthetic evaluation, quality assurance, delivery, and related business communication for the applicable Case should be available to the recipient Organization and authorized Users assigned to that Case.

9.3 In actual Lab operations, patient name may be used for Case identification and clinic–lab communication, and patient facial images may be processed/provided when necessary for fabrication accuracy, esthetic design, facial balance, facial midline, smile line, lip support, or implementation of treatment planning.

9.4 These business requirements do not authorize unrestricted disclosure of patient names or facial images to every Lab or every Case.

The specific permitted-data scope, recipient Lab, purpose, Permission, retention/deletion, patient processing basis, and required notice/Consent are governed by authoritative documents and system controls including:

  • DPA;

  • Patient Privacy Notice / Consent;

  • Lab/CAD Terms;

  • DataSharingGrant;

  • Patient Management / Lab Shared Contract; and

  • Development Standard and approved Compliance Gates.

9.5 Patient facial images used for fabrication purposes are protected at the HIGH_RISK_LAB_MEDIA level, with enhanced purpose, Case, recipient, authority, audit, retention/deletion, and out-of-purpose-use controls.

9.6 Derived Facial Data, such as facial measurements, landmarks, midline, or smile-line analysis, may be used as optional supplementary information, but is not a mandatory substitute Gate for the original facial image.

9.7 Whether a Lab acts as Processor, Independent Controller, or has activity-specific mixed roles is determined separately based on actual manufacturing, quality-control, retention, onward-processing, and legal-responsibility structures. That role determination does not reopen the existence of the legitimate Lab workflow recognized in Article 9.3.

9.8 This Privacy Notice does not define detailed field-level Lab Allowlist/Denylist rules. Those details are maintained in authoritative patient/clinic documents and service-specific data policies.

 

Article 10. Third-Party Disclosure, Processors, and Subprocessors

10.1 External Processing of Organization User Personal Data

Dentalverse may use approved external providers for:

  • infrastructure/cloud;

  • authentication/security;

  • email/messaging;

  • customer support;

  • incident monitoring;

  • third-party AI; and

  • other approved providers necessary for service operation.

The actual provider list and processing scope must be finalized before publication.

10.2 Patient Data Subprocessors

When Dentalverse, as Processor for a dental clinic, involves another Processor in Patient Data processing, it follows the Organization's prior written authorization procedure under applicable UU PDP and the DPA.

10.3 Separation Between Privacy Notice and Subprocessor Authorization

Acknowledgement of this Privacy Notice is not the Dental Organization's written approval of a Subprocessor.

Privacy Notice
→ NoticeAcknowledgement

Subprocessor Authorization
→ DPA / Contractual Written Authorization

10.4 Change Notice

If addition/change of a Subprocessor, recipient scope, processing region, or processing purpose materially affects Organization or data-subject rights or risk, applicable advance notice, disclosure, authorization, or reassessment is performed under the DPA and applicable law.

 

Article 11. Domestic Processing and Cross-Border Transfers

11.1 Dentalverse has domestic Indonesian processing of personal data as a preferred system-deployment objective.

11.2 Selection of an Indonesia/Jakarta region for a particular Cloud or AI service does not automatically guarantee Indonesia-only data residency for all processing.

For each service, Dentalverse verifies, as applicable:

  • Provider and Service;

  • Model and Endpoint;

  • application processing region;

  • Database/Object Storage;

  • Backup/Replication;

  • Log/Telemetry;

  • AI inference/storage;

  • Provider Support/Operations Access; and

  • Subprocessor Processing Region.

11.3 Processing remains NOT_VERIFIED until validation is complete. Only processing for which actual processing, storage, backup, logging, and support access are all verified within Indonesia is classified as Indonesia-only.

11.4 Where personal data is neither transferred outside Indonesia nor accessed from abroad, cross-border procedures do not apply to that processing.

11.5 If personal data is transferred, replicated, or backed up to a Controller/Processor outside Indonesia or accessed from abroad, Dentalverse performs cross-border-transfer validation under UU PDP Article 56 and applicable implementing law.

11.6 If a new cross-border transfer arises or there is a material change to the purpose, recipient, or region, the Privacy Notice, DPA, Patient Notice/Consent, or optional Consent is updated before the change to the extent required.

 

Article 12. Retention and Deletion

12.1 General Principle

Dentalverse generally does not retain personal data longer than necessary for the processing purpose and applicable legal/contractual retention obligations.

Some specific periods must still be finalized before publication.

12.2 Organization User Data

Data                                                                         Proposed Retention Basis                                                                     Status

Organization Representative/account data      account/contract relationship + applicable statutory retention     detailed period TBD

Pay Doctor/staff account data                            required account/audit period after Organization-User                   detailed period TBD
                                                                                 relationship ends 

Authentication/security logs                               limited period for security/audit                                                            TBD

Audit Events                                                           period necessary for contract/security/compliance evidence          TBD

Customer-support records                                  period necessary for request handling and dispute response         TBD

MarketingConsentEvent / Withdrawal               period necessary to prove Consent/withdrawal and comply            TBD
Evidence                                                                  with law

AnalyticsConsentEvent                                         period necessary to prove Consent/withdrawal and comply with   TBD

/ Withdrawal Evidence                                         law        

12.3 Patient Data

Patient Data retention follows the dental Controller's instructions, the DPA, applicable medical/lab statutory retention duties, and applicable Country Policy.

This Privacy Notice does not arbitrarily set statutory retention periods for patient clinical or Lab Data.

12.4 Deletion/Destruction

When the retention purpose and legal obligation end, personal data is deleted or destroyed in a form that cannot reasonably be restored, according to applicable procedures.

Where retention is legally required, the data is retained only for the required period with out-of-purpose use restricted.

 

Article 13. Rights of Organization Users

13.1 Subject to applicable scope and limitations under UU PDP, an Organization User may exercise rights relating to the User's personal data, including:

  • requesting information about processing;

  • completion, update, or correction;

  • access and a copy;

  • termination of processing, deletion, or destruction;

  • withdrawal of Consent for consent-based processing;

  • restriction of processing;

  • objection to automated decision-making and other statutory rights;

  • transfer of personal data where legally recognized; and

  • damages or other applicable legal remedies.

13.2 The scope and limitations of each right are governed by UU PDP and other applicable law.

13.3 Where a lawful ground such as contract performance, legal obligation, security, or establishment/exercise/defense of legal claims applies, a particular request may not be fulfilled immediately or in full. Dentalverse will provide the reason as required by applicable law.

13.4 How to Exercise Rights

Requests may be submitted through:

  • in-service privacy/account settings: [TBD]

  • email: [TBD]

  • customer support: [TBD]

  • privacy function/person: [TBD]

Dentalverse may perform reasonable identity verification before processing a rights request.

13.5 Patient Rights

Requests concerning patient personal data should generally be submitted to the relevant Dental Organization.

Dentalverse supports the dental Controller's response under the DPA.

 

Article 14. Security and Personal-Data Protection Measures

14.1 Dentalverse applies technical and organizational safeguards proportionate to the nature, scope, and risk of processing.

Examples include:

  • protection of data in transit and at rest;

  • authentication and session controls;

  • least-privilege Permissions;

  • Tenant/Clinic Scope validation;

  • audit logging;

  • device/access controls;

  • encrypted backups;

  • security-incident detection/response;

  • separation of development/operations access; and

  • vulnerability management.

14.2 NIK Protection

Patient NIK is treated as requiring enhanced protection.

Dentalverse applies these principles:

  • no plaintext NIK in DB, Search Index, Event, Audit, Application Log, URL, or Telemetry;

  • encryption where authoritative storage is required;

  • separately protected lookup mechanisms or equivalent protections where search is necessary;

  • minimized and masked display;

  • least-privilege access; and

  • auditing of relevant access/conflicts.

Specific encryption, search-token, and key-management implementations are governed by applicable privacy, security, and development standards.

14.3 Facial Images and High-Risk Media

Because patient facial images have high identifiability and are used in healthcare/fabrication contexts, Dentalverse conservatively treats them as SPECIFIC/HIGH_RISK under Governance until local legal review determines a narrower treatment, and applies stronger access, transmission, retention, and audit controls than for ordinary files.

At a minimum, purposes are separated as follows:

AI_CONSULTATION
→ generation of consultation images using third-party AI

LAB_FABRICATION
→ fabrication purposes such as facial balance / facial midline /
  smile line / lip support / smile design / implementation of treatment plan

Original facial images needed for LAB_FABRICATION are managed as HIGH_RISK_LAB_MEDIA. The underlying business approval for this use remains in effect.

Derived data such as facial landmarks, midline, and smile-line measurements may be used as optional supplementary information, but are not a mandatory replacement Gate for original facial images.

A legal basis, Consent, or authorization for one purpose does not automatically authorize processing for another purpose.

Where a DPIA is required for specific/high-risk processing, the DPIA that must be performed by the relevant Controller must be completed or completion Evidence must be verified, and Dentalverse, as Processor or platform provider, verifies that Evidence as a Gate before activating the relevant feature. Final legal classification of biometric/health data and detailed responsibility for the DPIA are to be confirmed by local counsel and the DPA/patient documents.

 

Article 15. Cookies, Telemetry, and Analytics

15.1 Essential Cookies / Local Storage

The Service may use cookies or similar technologies necessary for login, security, session maintenance, and essential settings.

These technologies are used only to the extent necessary for service provision.

15.2 Essential Telemetry

Dentalverse may classify and process minimum Telemetry necessary for service stability, security, incident response, and Release Health as ESSENTIAL_OPERATIONAL.

Examples include:

  • error codes;

  • server/app status;

  • authentication/security events;

  • feature failure information;

  • Health Gate / Release Health / Rollback Readiness; and

  • response-time and compatibility information needed for Service operations.

Essential Telemetry generally excludes patient name, NIK, facial images, intraoral scans, and raw consultation content where not required for the purpose.

15.3 Optional Analytics

Optional analysis of feature-usage patterns, UX Funnel, screen transitions, or user behavior is classified as OPTIONAL_ANALYTICS and governed by the separate Service Improvement & Statistics Data Use Consent.

The same technical metric may be classified differently according to processing purpose. For example, response time processed for outage/SLO monitoring is ESSENTIAL_OPERATIONAL, while response time processed for user-dropoff or UX analysis is OPTIONAL_ANALYTICS.

ESSENTIAL_OPERATIONAL
→ service / security / Health operational basis

OPTIONAL_ANALYTICS
→ separate Consent

Telemetry collected for essential operational purposes is not arbitrarily reused for optional behavioral analysis.

15.4 Refusal of Optional Analytics

Refusal or withdrawal of Optional Analytics Consent does not prevent use of basic Service functions that do not depend on Optional Analytics. If the SIDC is not effective or Retention/Provider Gates are unresolved, only Optional Analytics Consent collection and the related analytics function are disabled; this alone does not automatically block Core Organization Signup.

 

Article 16. Personal-Data Breach and Incident Notification

16.1 Organization User Personal Data Where Dentalverse Is Controller

Where Dentalverse acts as Controller of Organization User personal data and a personal-data breach occurs, Dentalverse provides required notice to affected data subjects and competent authorities under UU PDP Article 46 and applicable implementing rules.

The applicable statutory recipients, timing, and content depend on incident type and applicable law.

16.2 Patient Data Where Dentalverse Is Processor

If Dentalverse becomes aware of a personal-data breach involving Patient Data or a material security incident reasonably likely to affect personal data, Dentalverse will, under the DPA, provide initial notice to the Dental Organization:

without undue delay and, in any event, within 12 hours after awareness.

This 12-hour period is a contractual Processor→Controller initial-notification SLA and is not the statutory notification period applicable to the Controller under UU PDP.

16.3 Supplemental Notice

The initial notice may be preliminary based on information then available.

Dentalverse will provide supplemental information concerning scope, impact, response, and recovery without undue delay as further facts become available.

 

Article 17. Privacy Function/Responsible Person and Contacts

17.1 Where the designation requirements of UU PDP Article 53 apply, Dentalverse will designate a person or responsible function to perform personal-data protection functions.

17.2 Whether the Article 53 criteria apply based on Dentalverse's actual processing scale, Specific Personal Data processing, regular monitoring, or other factors will be confirmed in the Compliance Review before publication.

17.3 The following contact information will be included before publication:

Item                                                                               Details

Controller legal entity                                                 [TBD]

Address                                                                         [TBD]

Privacy function/person                                             [TBD]

Privacy inquiry email                                                   [TBD]

Data-subject rights email                                            [TBD]

Personal-data-incident reporting channel               [TBD]

Customer support                                                        [TBD]

 

 

Article 18. Child Patient Data

18.1 Dentalverse Organization User accounts are intended for business users of Dental Organizations. Independent patient accounts and a Patient Portal are not included in the current Pilot.

18.2 Personal data of a Child Patient under applicable law is treated as a category of Specific Personal Data requiring enhanced protection under UU PDP.

18.3 Where Consent is used as a legal or product-policy requirement for processing Child Patient personal data, the dental Controller must verify valid Consent of a parent and/or lawful guardian under applicable UU PDP Article 25 and related law.

18.4 Dentalverse technically supports verification of guardian authority and Consent Evidence according to the dental clinic's instructions and approved Patient Workflow, and processes relevant features fail-closed when required Evidence is unavailable.

18.5 This Notice does not independently designate child assent, acknowledgement of explanations, or participation in decision-making as a separate statutory Hard Gate. The applicable scope will be defined in the Patient Consent Template after review of Indonesian healthcare law, professional standards, ethics requirements, and local legal advice.

18.6 Before publication, local counsel will verify the exact Child age threshold, parent/guardian authority, and the extent to which Government Regulation No. 17 of 2025 and Minister of Communication and Digital Regulation No. 9 of 2026 apply to Dentalverse's patient proxy workflow.

Article 19. Delivery and Acknowledgement of this Notice

19.1 Representative

The Representative receives and can acknowledge this Privacy Notice during Dental Organization signup.

Recommended UI:

[Required acknowledgement] I have reviewed the Dentalverse Privacy Notice.

This is not Consent.

19.2 Pay Doctors, Staff, and Other Organization Users

When the Representative registers a Pay Doctor or employee with the Organization, Dentalverse provides this Notice to that individual through one or more of:

  • invitation email;

  • first-login screen;

  • account settings;

  • Privacy menu within the Service; or

  • another continuously accessible method.

A separate Organization contract or blanket personal-data Consent checkbox is generally not required for those Users.

19.3 Evidence

Delivery/acknowledgement may be recorded as follows:

notice_record:
  notice_id: DV-LEGAL-PN-ID-001
  notice_version: "0.3.2"
  subject_user_id: USER-001
  organization_id: ORG-001
  delivered_at: "..."
  acknowledged_at: "..."
  delivery_method: first_login

Where only delivery is required and there is no acknowledged_at, the event may be managed separately as a NoticeDeliveryRecord, subject to legal/UI design.

 

Article 20. Relationship with Optional Consent

20.1 Marketing and Promotions

Receipt of marketing/promotional communications is a separate optional Consent of the individual recipient.

The Representative's choice does not substitute for the Email/SMS/WhatsApp marketing Consent of another Pay Doctor or employee.

20.2 Service Improvement and Statistics Data Use

This optional Consent applies only to the relevant individual's usage/analytics data defined in a separate document.

Patient Data is not included in the default scope.

20.3 Withdrawal

Optional Consent may be withdrawn at any time using the applicable method.

Withdrawal does not affect the legality of processing lawfully performed before withdrawal. Withdrawal of consent-based processing is handled in accordance with the relevant Marketing/Analytics Consent document's immediate-block product policy and the processing-termination period under UU PDP Article 40.

20.4 Anonymization

The process of converting personal data into truly anonymous data may itself constitute personal-data processing, so a lawful basis must exist for the pre-anonymization processing.

Subsequent processing of data that is truly anonymized so that it cannot reasonably be re-linked to an individual may not be subject to the same withdrawal structure as personal data.

 

Article 21. Changes to this Privacy Notice

21.1 Dentalverse may update this Notice if law, Service, processing purposes, or Processor configuration changes.

21.2 Material changes such as the following will be notified by an appropriate method before taking effect:

  • new personal-data processing purpose;

  • new category of personal data;

  • new recipient materially affecting data-subject rights or risk;

  • change from an Indonesia-only structure to one involving cross-border transfer;

  • material change to rights or retention periods; or

  • new consent-based processing.

21.3 A processing change requiring new Consent is not implemented merely by changing the Privacy Notice; separate Consent is obtained.

21.4 Historical Privacy Notice IDs, versions, Digests, and delivery records are retained in traceable form.

 

Article 22. Relationship with Other Legal Documents

22.1 The roles of this Notice and related documents are separated as follows:

Document                                                              Primary Role

Terms of Service                                                   General Service agreement between Dentalverse and Dental Organization

DPA                                                                         Patient Data processing agreement between dental Controller and Dentalverse                                                                                               Processor

Pilot Terms                                                              Special conditions for Pilot features, duration, pricing, rollback, etc.

This Privacy Notice                                                Notice of Organization User personal data where Dentalverse is Controller
                                                                                 + high-level explanation of Dentalverse's Patient Processor role

AI Patient Consultation Service Guideline       AI-use limitations and safety Guideline

Marketing Consent                                             Individual optional marketing receipt

Service Improvement & Statistics Data Use    Individual optional Analytics processing

Consent                                                  

Patient Notice/Consent                                        Purpose-specific patient workflow for personal-data processing, AI, Lab, etc.

 

22.2 Where there is a conflict concerning Patient Data processing, the DPA and the dental clinic's lawful patient-facing notice/Consent structure govern.

22.3 Privacy Notice acknowledgement must not be confused with contract acceptance, DPA Subprocessor Authorization, or Patient Consent.

 

DENTALVERSE Inc. #505 Seoul Bio Industry Academic Center, Kyunghee Univ. Seoul, Korea

© 2024 by DENTALVERSE Inc. 

bottom of page