
DENTALVERSE PRIVACY NOTICE
Important — Legal Review Candidate
The Korean source document is a legal review candidate for the Dentalverse Privacy Notice used in the dental-clinic signup Legal UI and is not yet effective. This revision integrates Qwen and Claude review of v0.3.0, subsequent cross-review, and GPT final decisions.
This document is a notice concerning processing of personal data and is not, by itself, blanket Consent to personal-data processing. Processing that requires Consent uses a separate Consent document and purpose-specific ConsentEvidence. Marketing uses MarketingConsentEvent, Optional Analytics uses AnalyticsConsentEvent, and purpose-specific patient Consent uses PatientConsentRecord or approved equivalent Evidence.
The Korean source document is for product and legal review. A Bahasa Indonesia version must be prepared and finally reviewed by Indonesian local counsel before publication.
At a minimum, the following must be finalized before publication:
-
Dentalverse Indonesian Controller/contracting entity legal name, registration number, and address;
-
PSE registration/operating entity;
-
responsible privacy function/person and contact details;
-
customer-support, data-subject-rights, and personal-data-incident reporting channels;
-
local legal review of purpose-specific legal bases for Organization User personal data;
-
DPA and Subprocessor authorization structure;
-
actual ThirdPartyProcessor/Subprocessor list;
-
actual processing, storage, backup, logging, support-access, retention, deletion, and training policies for each Processor;
-
Organization User data retention periods;
-
separate Controller/Processor roles and patient notice/Consent documents for Patient, Lab, and AI data; and
-
final Bahasa Indonesia version.
Confirmed Canonical Inputs
D-LAB-PATIENT-IDENTITY
= APPROVED
D-LAB-FACIAL-IMAGE
= APPROVED
D-LAB-DERIVED-FACIAL-DATA
= OPTIONAL_SUPPLEMENTARY
D-LAB-ACCESS-MODEL
= CASE_BOUND
D-LAB-PRIVACY-PRINCIPLE
= PURPOSE_LIMITED_MINIMUM_NECESSARY
D-LAB-FACIAL-MEDIA-CLASS
= HIGH_RISK_LAB_MEDIA
D-LAB-LEGAL-ROLE
= OPEN
D-LAB-FACIAL-LEGAL-BASIS
= OPEN / DPIA REQUIRED FOR DESIGN
D-AI-DATA-RESIDENCY
= NOT_VERIFIED
D-CHILD-CONSENT
= PARENT_OR_GUARDIAN_REQUIRED_WHEN_APPLICABLE
D-FACIAL-GOVERNANCE
= SPECIFIC_HIGH_RISK_DEFAULT / CONTROLLER_DPIA_EVIDENCE_REQUIRED
The OPEN status of D-LAB-LEGAL-ROLE, D-LAB-FACIAL-LEGAL-BASIS, and D-AI-DATA-RESIDENCY does not reopen the business decision permitting use of patient name or necessary facial images for Lab work. These open items determine the legal role, legal basis, notice/Consent, security/audit, and regional controls through which the approved workflow will be implemented.
0. Role of this Privacy Notice
Dentalverse legal documents and evidence are separated as follows:
Terms of Service + DPA + Pilot Terms
→ Agreement Package
→ AgreementEvidence
Privacy Notice
→ Privacy Notice
→ NoticeDeliveryRecord / NoticeAcknowledgement
AI Patient Consultation Service Guideline
→ Guideline
→ GuidelineAcknowledgement
First-use AI Feature Safety Notice
→ Feature Safety Notice
→ FeatureSafetyNoticeAcknowledgement
Marketing & Promotional Communications
→ Optional Consent
→ MarketingConsentEvent + MarketingPreference
Service Improvement & Statistics Data Use
→ Optional Consent
→ AnalyticsConsentEvent + AnalyticsPreference
Purpose-Specific Patient Consent
→ Patient Consent
→ PatientConsentRecord or approved equivalent Evidence
Acknowledgement of this Privacy Notice does not mean:
-
separate re-acceptance of the Service agreement;
-
blanket Consent to all personal-data processing;
-
written Organization authorization for use of a Subprocessor;
-
patient Consent to processing of Patient Data;
-
patient Consent to facial-image processing for AI image generation; or
-
another Organization User's optional Consent.
Article 1. Purpose and Scope
1.1 This Privacy Notice explains how Dentalverse collects, uses, stores, shares, and protects personal data of Dental Organization Representatives and Organization Users.
1.2 The direct data subjects of this Notice are:
-
Organization owner dentist or other authorized Representative;
-
Pay Doctors;
-
administrators;
-
general staff;
-
consultation staff; and
-
other individuals registered by an Organization as Dentalverse Users.
1.3 This Notice applies to processing for:
a. Organization signup and representative-authority verification;
b. Organization User account creation, invitation, and authentication;
c. Permission and Clinic Assignment management;
d. service security, audit, and incident response;
e. customer support and complaint handling;
f. optional marketing;
g. service improvement and statistical analysis under separate optional Consent; and
h. other processing for which Dentalverse independently determines the purpose and means with respect to the above data subjects.
1.4 This Notice is not a Privacy Notice directly addressed to patients.
Article 7 explains Dentalverse's baseline role when processing Patient Data, but patient-facing privacy notices, legal bases, and Consent for treatment, consultation, AI, and Lab purposes are managed through the Dental Organization's Controller responsibilities and separate patient workflows.
1.5 This Notice assumes the following current Pilot service areas:
-
Patient Management;
-
AI Patient Consultation; and
-
Lab Orders.
1.6 Production EMR functions, Voice clinical-conversation processing, and the Patient Portal are outside the current Pilot scope. The personal-data processing scope and this Notice will be reassessed if those features are added.
Article 2. Definitions
For purposes of this Notice:
-
Personal Data (Data Pribadi) means information that identifies, directly or indirectly, a natural person.
-
Specific Personal Data (Data Pribadi yang bersifat spesifik) means personal data requiring enhanced protection under applicable UU PDP, including health data and biometric data.
-
Data Subject (Subjek Data Pribadi) means the natural person to whom personal data relates.
-
Controller (Pengendali Data Pribadi) means a person/entity that determines and controls the purposes and means of personal-data processing.
-
Processor (Prosesor Data Pribadi) means a person/entity that processes personal data on behalf of a Controller.
-
Subprocessor (Subprosesor) means another Processor engaged by a Processor to perform part of the processing on behalf of the Controller.
-
Organization User means an individual registered/invited by a Dental Organization and granted an account and Permissions in Dentalverse.
-
Patient Data (Data Pasien) means patient personal data processed in connection with Patient Management, consultation, Lab Orders, and related dental operations.
-
NIK (Nomor Induk Kependudukan) means the Indonesian national population identification number.
-
Facial Image means an image containing an identifiable patient's face. Until local legal review confirms a narrower treatment, Dentalverse conservatively treats identifiable patient facial images in dental/clinical/fabrication contexts as SPECIFIC/HIGH_RISK for Governance purposes. Final legal classification under UU PDP as biometric and/or health data will be determined by local counsel in light of processing purpose, technology, and identification function.
-
Intraoral Photo means an image of the inside of the mouth, teeth, gingiva, occlusion, or similar content used for fabrication or consultation, classified separately from a facial image.
-
Essential Telemetry means minimum technical/operational events necessary for security, incident detection, performance, and service stability.
-
Optional Analytics Data means usage-behavior and analytics data processed for service improvement/statistics under separate optional Consent.
-
NoticeAcknowledgement means evidence that a Privacy Notice was delivered, available, or acknowledged; it is not Consent.
-
ConsentEvidence means the high-level evidence concept proving a data subject's choice for processing where Consent is required by law or product policy. Purpose-specific concrete objects include PatientConsentRecord for patient Consent, MarketingConsentEvent for Marketing, and AnalyticsConsentEvent for Optional Analytics.
Article 3. Dentalverse Personal-Data Processing Roles
3.1 Organization User Personal Data
To the extent Dentalverse determines the purpose and means for processing personal data relating to the accounts, authentication, support, and Service use of Representatives, Pay Doctors, employees, and other Organization Users, Dentalverse is responsible as Controller of that personal data.
3.2 Patient Data
When a dental clinic uses Dentalverse for Patient Management, consultation, or Lab Orders and Dentalverse processes Patient Data under the clinic's documented instructions, the following generally applies:
Dental Organization
→ Controller
Dentalverse
→ Processor
The DPA governs specific processing purposes, data categories, processing period, Subprocessors, return/deletion, audit, and incident response.
3.3 Role Change or Independent-Purpose Processing
If Dentalverse determines an independent purpose and means for Patient Data outside the dental clinic's instructions and the purposes of the DPA, that processing is not treated merely as Processor processing.
Before such processing is performed, Dentalverse must establish a separate role analysis, lawful basis, notice, contractual basis, and Consent where required.
3.4 Roles of Labs and Third-Party AI
The Controller/Processor status of external recipients, including Labs, CAD Organizations, and third-party AI Providers, is determined by the actual processing purpose, instruction relationship, and contractual structure.
This Notice does not categorically fix every external recipient as Controller or Processor.
Article 4. Organization User Personal Data Collected
4.1 Representative/Applicant Information
Category Examples
Account identifiers name, email, User ID
Authentication information password hash, authentication method, authentication status
Organization information Organization name, Clinic, position or relationship within Organization
Representative-authority information Representative qualification, relationship to Organization, verification materials
Contact information phone number, WhatsApp number
Professional qualification information dentist license number, qualification verification
4.2 Pay Doctor, Staff, and Other Organization User Information
When the Organization registers or invites a User, the following may be processed:
-
name;
-
business email;
-
Organization/Clinic affiliation;
-
User ID;
-
Provider linkage information, where applicable;
-
Permission, Role, and Clinic Assignment;
-
healthcare-professional qualification or license information, where needed;
-
account active/inactive status; and
-
invitation, signup, and first-login times.
Where an Organization enters another person's personal data into Dentalverse, the Organization must verify that the registration is lawful and limited to what is necessary.
4.3 Service-Use and Security Information
The following may be generated through use of the Service:
-
login/logout times;
-
session identifiers;
-
technical device/browser/app information;
-
IP address or network-security information, if collected;
-
successful/failed authentication history;
-
Permission change history;
-
command, approval, and security-related Audit Events;
-
essential Telemetry such as error codes, service status, and response times; and
-
customer-support tickets and request history.
4.4 Optional Information
Where the individual has provided separate optional Consent, Dentalverse may process:
Marketing and Promotions
-
email;
-
phone number;
-
WhatsApp number;
-
selected marketing channels; and
-
opt-in/withdrawal records.
Service Improvement and Statistics
Within the scope specified in the separate Consent document:
-
frequency of feature use by the Organization User;
-
screen/feature usage events;
-
optional analytics cookies or similar identifiers; and
-
usage-behavior data used to create aggregates/statistics.
By default, this optional Consent does not include:
-
raw Patient Data;
-
patient name, NIK, or contact information;
-
patient facial images;
-
patient intraoral scans or photographs;
-
Lab Case content;
-
pseudonymized Patient Data;
-
EMR clinical records; or
-
Voice audio or conversation content.
If Patient Data is to be used separately for service improvement or statistics, Dentalverse will not rely on this Organization-User optional Consent alone and will separately review role, legal basis, notice, Consent, and anonymization requirements.
Article 5. Sources of Personal Data
Dentalverse may collect Organization User personal data from:
-
information entered directly by the Representative or User;
-
information provided by the Organization Representative/administrator when registering Organization Users;
-
information automatically generated during login, authentication, and Service use;
-
information provided during customer support or complaint handling;
-
official or contractual verification sources used for lawful professional/Organization verification; and
-
Marketing/Analytics information provided under separate optional Consent.
Dentalverse generally does not expand collection beyond what is necessary for the applicable purpose.
Article 6. Purposes and Legal Bases for Processing Organization User Personal Data
6.1 General Principle
Dentalverse applies an appropriate legal basis to each personal-data processing activity under UU PDP Article 20.
The applicable legal basis may vary according to the data subject's status, processing purpose, and actual contractual relationship. Final mapping of legal bases in this Candidate must be confirmed through Indonesian local legal review before publication.
6.2 Purpose-Specific Mapping
Processing Purpose : Data Subject / Proposed Legal Basis / Notes
Organization signup and Representative account creation : Representative / PENDING LOCAL COUNSEL MAPPING — candidates include legitimate interests, an applicable pre-contract request, or another appropriate Article 20 basis / The contracting party is the Dental Organization, so contract-performance basis is not automatically applied to the Representative personally
Representative authority and Organization verification : Representative / PENDING LOCAL COUNSEL MAPPING — legitimate interests, or legal obligation where an identified law imposes one, etc. / Product/KYB necessity alone does not automatically establish a legal obligation; the specific law and verification scope must be identified first
Pay Doctor/staff account provision : Organization User / legitimate interests or another appropriate Article 20 basis / User may not be a direct party to the Organization contract, so contract performance is not applied categorically
Authentication, Permission, Clinic Assignment : Organization User / legitimate interests, contract-related operations, or legal obligation / least privilege and security purposes
Service security and abuse prevention : All Users / legitimate interests or legal obligation / balancing assessment applies
Audit/compliance : All Users / legal obligation or legitimate interests / depends on applicable law/contract
Customer support/complaint handling : Requester / contract-related processing or legitimate interests / depends on request
Essential service Telemetry : Organization User / legitimate interests / minimum necessary for service stability/security
Marketing/promotional communications : Relevant individual recipient / explicit Consent / MarketingConsentEvent + MarketingPreference
Optional service-improvement/statistics analysis ; Relevant data subject / explicit Consent / AnalyticsConsentEvent + AnalyticsPreference
6.3 Legitimate-Interest Processing
Where legitimate interests are used as the legal basis, Dentalverse evaluates the processing purpose, necessity, impact on the data subject, and the data subject's rights and interests through an appropriate balancing assessment.
6.4 Separation of Consent
Where Consent is the legal basis, it is:
-
separated by specific purpose;
-
provided in writing or a recordable electronic form;
-
separated from the basic Service Agreement;
-
capable of refusal;
-
capable of withdrawal; and
-
not used to impose an unfair disadvantage on use of basic services unrelated to the optional processing.
Article 7. Patient Data — Dentalverse as Processor
7.1 The direct data subjects of this Notice are Organization Users, not patients.
7.2 Dentalverse may process patient personal data while a Dental Organization uses Patient Management, AI Patient Consultation, and Lab Order services.
7.3 To the extent Dentalverse processes Patient Data under the dental clinic's documented instructions, the following generally applies:
Dental Organization
→ Controller
Dentalverse
→ Processor
The DPA governs processing purpose, data categories, retention/deletion, Subprocessors, audit, and incident response.
7.4 Depending on the activated service purpose, Patient Data may include patient identifiers, appointment/check-in information, media such as intraoral scans, intraoral photographs, and facial images, consultation information, and Lab Order data.
7.5 Article 7.4 does not mean all Patient Data is available to every function or recipient. Actual processing is restricted by the relevant feature purpose, dental-clinic instructions, lawful patient-processing basis, Permissions, DataSharingGrant, and applicable service-specific Gates.
7.6 Dentalverse does not rely solely on its Processor status to independently use Patient Data for:
-
Dentalverse's own marketing;
-
sale of data;
-
creation of an independent patient database;
-
unauthorized AI-model training/retraining; or
-
independent service-improvement or commercial purposes unrelated to dental-clinic instructions.
7.7 Specific Patient Data purposes, categories, recipients, legal bases, retention/deletion, and patient rights are governed by the DPA, patient-facing notice/Consent documents provided by the dental clinic, Lab/CAD agreements, and authoritative service rules.
7.8 Requests by patients concerning access, correction, deletion, or processing of their Patient Data should generally be submitted to the relevant Dental Organization as Controller. Dentalverse supports the Organization under the DPA.
Article 8. AI Patient Consultation and Third-Party AI Processing
8.1 Nature of the Function
The current Pilot may include AI Patient Consultation functions that use patient facial images to generate expected or simulated post-orthodontic images.
This processing primarily concerns Patient Data, not Organization User personal data. It is not legitimized by Organization User acknowledgement of this Notice or an Organization-User optional Consent.
8.2 Third-Party AI Processing Gate
A function processing patient facial images through third-party AI is activated only after the applicable requirements are met, including:
-
lawful basis of the dental Controller;
-
purpose-specific patient Consent or lawful representative Consent required by Dentalverse Pilot policy;
-
third-party Processor/Subprocessor contract and necessary authorization;
-
identification of the exact Provider, Model, and Endpoint;
-
verification of actual inference, storage, backup, logging, and support-access regions;
-
retention verification;
-
verification of model training/retraining use;
-
deletion and Provider data-handling policy;
-
personal-data classification and risk assessment for facial images;
-
DPIA where required;
-
security, audit, and Provenance; and
-
AI-generated-content disclosure and patient explanation.
Internal CMP numbers or machine-verification IDs are not exposed in the user-facing Privacy Notice and remain in the internal Compliance Gate Matrix.
8.3 Data Residency Status
Dentalverse has Indonesia domestic processing as a preferred deployment objective for Patient Data.
However, until the exact third-party AI Provider, Model, Endpoint, and actual inference, storage, backup, logging, and support-access regions are verified, the AI processing is not treated as Indonesia-only.
The current legal/product Governance state is:
D-AI-DATA-RESIDENCY
= NOT_VERIFIED
8.4 If Indonesia-Only Processing Is Verified
If actual inference, storage, backup/replication, logs containing Patient Data, and Provider support/operations access for a specific AI function are all verified to occur within Indonesia, the function may operate without a cross-border-transfer structure.
The availability of a Jakarta or Indonesia region setting alone does not establish that all processing for a specific AI model remains in Indonesia.
8.5 If Cross-Border Transfer Is Identified
If personal data is transferred, replicated, or backed up outside Indonesia or accessible from abroad, Dentalverse evaluates the applicable cross-border requirements under UU PDP Article 56 and implementing rules.
Dentalverse does not state that explicit Consent is always the only lawful mechanism for cross-border transfer. The legally required sequence—applicable protection level, appropriate binding safeguards, and, where required, data-subject Consent—is evaluated.
Separately, Dentalverse may require purpose-specific explicit patient Consent or lawful representative Consent as a product-safety Activation Hard Gate for third-party AI processing of patient facial images.
8.6 Feature Disablement
If required patient-processing requirements or third-party AI Gates are not met, only the relevant third-party AI image-generation function is disabled.
This does not automatically block Dental Organization signup, general Patient Management, or Lab Order functions that do not depend on the AI feature.
Article 9. Lab Orders and Patient Data Processing
9.1 Patient personal data may be processed or provided when a Dental Organization transmits a fabrication Case through Dentalverse to a Lab or CAD Organization.
9.2 Dentalverse designs Lab Data processing according to:
CASE_BOUND
+
PURPOSE_LIMITED
+
MINIMUM_NECESSARY
Only Patient Data necessary for design, fabrication, esthetic evaluation, quality assurance, delivery, and related business communication for the applicable Case should be available to the recipient Organization and authorized Users assigned to that Case.
9.3 In actual Lab operations, patient name may be used for Case identification and clinic–lab communication, and patient facial images may be processed/provided when necessary for fabrication accuracy, esthetic design, facial balance, facial midline, smile line, lip support, or implementation of treatment planning.
9.4 These business requirements do not authorize unrestricted disclosure of patient names or facial images to every Lab or every Case.
The specific permitted-data scope, recipient Lab, purpose, Permission, retention/deletion, patient processing basis, and required notice/Consent are governed by authoritative documents and system controls including:
-
DPA;
-
Patient Privacy Notice / Consent;
-
Lab/CAD Terms;
-
DataSharingGrant;
-
Patient Management / Lab Shared Contract; and
-
Development Standard and approved Compliance Gates.
9.5 Patient facial images used for fabrication purposes are protected at the HIGH_RISK_LAB_MEDIA level, with enhanced purpose, Case, recipient, authority, audit, retention/deletion, and out-of-purpose-use controls.
9.6 Derived Facial Data, such as facial measurements, landmarks, midline, or smile-line analysis, may be used as optional supplementary information, but is not a mandatory substitute Gate for the original facial image.
9.7 Whether a Lab acts as Processor, Independent Controller, or has activity-specific mixed roles is determined separately based on actual manufacturing, quality-control, retention, onward-processing, and legal-responsibility structures. That role determination does not reopen the existence of the legitimate Lab workflow recognized in Article 9.3.
9.8 This Privacy Notice does not define detailed field-level Lab Allowlist/Denylist rules. Those details are maintained in authoritative patient/clinic documents and service-specific data policies.
Article 10. Third-Party Disclosure, Processors, and Subprocessors
10.1 External Processing of Organization User Personal Data
Dentalverse may use approved external providers for:
-
infrastructure/cloud;
-
authentication/security;
-
email/messaging;
-
customer support;
-
incident monitoring;
-
third-party AI; and
-
other approved providers necessary for service operation.
The actual provider list and processing scope must be finalized before publication.
10.2 Patient Data Subprocessors
When Dentalverse, as Processor for a dental clinic, involves another Processor in Patient Data processing, it follows the Organization's prior written authorization procedure under applicable UU PDP and the DPA.
10.3 Separation Between Privacy Notice and Subprocessor Authorization
Acknowledgement of this Privacy Notice is not the Dental Organization's written approval of a Subprocessor.
Privacy Notice
→ NoticeAcknowledgement
Subprocessor Authorization
→ DPA / Contractual Written Authorization
10.4 Change Notice
If addition/change of a Subprocessor, recipient scope, processing region, or processing purpose materially affects Organization or data-subject rights or risk, applicable advance notice, disclosure, authorization, or reassessment is performed under the DPA and applicable law.
Article 11. Domestic Processing and Cross-Border Transfers
11.1 Dentalverse has domestic Indonesian processing of personal data as a preferred system-deployment objective.
11.2 Selection of an Indonesia/Jakarta region for a particular Cloud or AI service does not automatically guarantee Indonesia-only data residency for all processing.
For each service, Dentalverse verifies, as applicable:
-
Provider and Service;
-
Model and Endpoint;
-
application processing region;
-
Database/Object Storage;
-
Backup/Replication;
-
Log/Telemetry;
-
AI inference/storage;
-
Provider Support/Operations Access; and
-
Subprocessor Processing Region.
11.3 Processing remains NOT_VERIFIED until validation is complete. Only processing for which actual processing, storage, backup, logging, and support access are all verified within Indonesia is classified as Indonesia-only.
11.4 Where personal data is neither transferred outside Indonesia nor accessed from abroad, cross-border procedures do not apply to that processing.
11.5 If personal data is transferred, replicated, or backed up to a Controller/Processor outside Indonesia or accessed from abroad, Dentalverse performs cross-border-transfer validation under UU PDP Article 56 and applicable implementing law.
11.6 If a new cross-border transfer arises or there is a material change to the purpose, recipient, or region, the Privacy Notice, DPA, Patient Notice/Consent, or optional Consent is updated before the change to the extent required.
Article 12. Retention and Deletion
12.1 General Principle
Dentalverse generally does not retain personal data longer than necessary for the processing purpose and applicable legal/contractual retention obligations.
Some specific periods must still be finalized before publication.
12.2 Organization User Data
Data Proposed Retention Basis Status
Organization Representative/account data account/contract relationship + applicable statutory retention detailed period TBD
Pay Doctor/staff account data required account/audit period after Organization-User detailed period TBD
relationship ends
Authentication/security logs limited period for security/audit TBD
Audit Events period necessary for contract/security/compliance evidence TBD
Customer-support records period necessary for request handling and dispute response TBD
MarketingConsentEvent / Withdrawal period necessary to prove Consent/withdrawal and comply TBD
Evidence with law
AnalyticsConsentEvent period necessary to prove Consent/withdrawal and comply with TBD
/ Withdrawal Evidence law
12.3 Patient Data
Patient Data retention follows the dental Controller's instructions, the DPA, applicable medical/lab statutory retention duties, and applicable Country Policy.
This Privacy Notice does not arbitrarily set statutory retention periods for patient clinical or Lab Data.
12.4 Deletion/Destruction
When the retention purpose and legal obligation end, personal data is deleted or destroyed in a form that cannot reasonably be restored, according to applicable procedures.
Where retention is legally required, the data is retained only for the required period with out-of-purpose use restricted.
Article 13. Rights of Organization Users
13.1 Subject to applicable scope and limitations under UU PDP, an Organization User may exercise rights relating to the User's personal data, including:
-
requesting information about processing;
-
completion, update, or correction;
-
access and a copy;
-
termination of processing, deletion, or destruction;
-
withdrawal of Consent for consent-based processing;
-
restriction of processing;
-
objection to automated decision-making and other statutory rights;
-
transfer of personal data where legally recognized; and
-
damages or other applicable legal remedies.
13.2 The scope and limitations of each right are governed by UU PDP and other applicable law.
13.3 Where a lawful ground such as contract performance, legal obligation, security, or establishment/exercise/defense of legal claims applies, a particular request may not be fulfilled immediately or in full. Dentalverse will provide the reason as required by applicable law.
13.4 How to Exercise Rights
Requests may be submitted through:
-
in-service privacy/account settings: [TBD]
-
email: [TBD]
-
customer support: [TBD]
-
privacy function/person: [TBD]
Dentalverse may perform reasonable identity verification before processing a rights request.
13.5 Patient Rights
Requests concerning patient personal data should generally be submitted to the relevant Dental Organization.
Dentalverse supports the dental Controller's response under the DPA.
Article 14. Security and Personal-Data Protection Measures
14.1 Dentalverse applies technical and organizational safeguards proportionate to the nature, scope, and risk of processing.
Examples include:
-
protection of data in transit and at rest;
-
authentication and session controls;
-
least-privilege Permissions;
-
Tenant/Clinic Scope validation;
-
audit logging;
-
device/access controls;
-
encrypted backups;
-
security-incident detection/response;
-
separation of development/operations access; and
-
vulnerability management.
14.2 NIK Protection
Patient NIK is treated as requiring enhanced protection.
Dentalverse applies these principles:
-
no plaintext NIK in DB, Search Index, Event, Audit, Application Log, URL, or Telemetry;
-
encryption where authoritative storage is required;
-
separately protected lookup mechanisms or equivalent protections where search is necessary;
-
minimized and masked display;
-
least-privilege access; and
-
auditing of relevant access/conflicts.
Specific encryption, search-token, and key-management implementations are governed by applicable privacy, security, and development standards.
14.3 Facial Images and High-Risk Media
Because patient facial images have high identifiability and are used in healthcare/fabrication contexts, Dentalverse conservatively treats them as SPECIFIC/HIGH_RISK under Governance until local legal review determines a narrower treatment, and applies stronger access, transmission, retention, and audit controls than for ordinary files.
At a minimum, purposes are separated as follows:
AI_CONSULTATION
→ generation of consultation images using third-party AI
LAB_FABRICATION
→ fabrication purposes such as facial balance / facial midline /
smile line / lip support / smile design / implementation of treatment plan
Original facial images needed for LAB_FABRICATION are managed as HIGH_RISK_LAB_MEDIA. The underlying business approval for this use remains in effect.
Derived data such as facial landmarks, midline, and smile-line measurements may be used as optional supplementary information, but are not a mandatory replacement Gate for original facial images.
A legal basis, Consent, or authorization for one purpose does not automatically authorize processing for another purpose.
Where a DPIA is required for specific/high-risk processing, the DPIA that must be performed by the relevant Controller must be completed or completion Evidence must be verified, and Dentalverse, as Processor or platform provider, verifies that Evidence as a Gate before activating the relevant feature. Final legal classification of biometric/health data and detailed responsibility for the DPIA are to be confirmed by local counsel and the DPA/patient documents.
Article 15. Cookies, Telemetry, and Analytics
15.1 Essential Cookies / Local Storage
The Service may use cookies or similar technologies necessary for login, security, session maintenance, and essential settings.
These technologies are used only to the extent necessary for service provision.
15.2 Essential Telemetry
Dentalverse may classify and process minimum Telemetry necessary for service stability, security, incident response, and Release Health as ESSENTIAL_OPERATIONAL.
Examples include:
-
error codes;
-
server/app status;
-
authentication/security events;
-
feature failure information;
-
Health Gate / Release Health / Rollback Readiness; and
-
response-time and compatibility information needed for Service operations.
Essential Telemetry generally excludes patient name, NIK, facial images, intraoral scans, and raw consultation content where not required for the purpose.
15.3 Optional Analytics
Optional analysis of feature-usage patterns, UX Funnel, screen transitions, or user behavior is classified as OPTIONAL_ANALYTICS and governed by the separate Service Improvement & Statistics Data Use Consent.
The same technical metric may be classified differently according to processing purpose. For example, response time processed for outage/SLO monitoring is ESSENTIAL_OPERATIONAL, while response time processed for user-dropoff or UX analysis is OPTIONAL_ANALYTICS.
ESSENTIAL_OPERATIONAL
→ service / security / Health operational basis
OPTIONAL_ANALYTICS
→ separate Consent
Telemetry collected for essential operational purposes is not arbitrarily reused for optional behavioral analysis.
15.4 Refusal of Optional Analytics
Refusal or withdrawal of Optional Analytics Consent does not prevent use of basic Service functions that do not depend on Optional Analytics. If the SIDC is not effective or Retention/Provider Gates are unresolved, only Optional Analytics Consent collection and the related analytics function are disabled; this alone does not automatically block Core Organization Signup.
Article 16. Personal-Data Breach and Incident Notification
16.1 Organization User Personal Data Where Dentalverse Is Controller
Where Dentalverse acts as Controller of Organization User personal data and a personal-data breach occurs, Dentalverse provides required notice to affected data subjects and competent authorities under UU PDP Article 46 and applicable implementing rules.
The applicable statutory recipients, timing, and content depend on incident type and applicable law.
16.2 Patient Data Where Dentalverse Is Processor
If Dentalverse becomes aware of a personal-data breach involving Patient Data or a material security incident reasonably likely to affect personal data, Dentalverse will, under the DPA, provide initial notice to the Dental Organization:
without undue delay and, in any event, within 12 hours after awareness.
This 12-hour period is a contractual Processor→Controller initial-notification SLA and is not the statutory notification period applicable to the Controller under UU PDP.
16.3 Supplemental Notice
The initial notice may be preliminary based on information then available.
Dentalverse will provide supplemental information concerning scope, impact, response, and recovery without undue delay as further facts become available.
Article 17. Privacy Function/Responsible Person and Contacts
17.1 Where the designation requirements of UU PDP Article 53 apply, Dentalverse will designate a person or responsible function to perform personal-data protection functions.
17.2 Whether the Article 53 criteria apply based on Dentalverse's actual processing scale, Specific Personal Data processing, regular monitoring, or other factors will be confirmed in the Compliance Review before publication.
17.3 The following contact information will be included before publication:
Item Details
Controller legal entity [TBD]
Address [TBD]
Privacy function/person [TBD]
Privacy inquiry email [TBD]
Data-subject rights email [TBD]
Personal-data-incident reporting channel [TBD]
Customer support [TBD]
Article 18. Child Patient Data
18.1 Dentalverse Organization User accounts are intended for business users of Dental Organizations. Independent patient accounts and a Patient Portal are not included in the current Pilot.
18.2 Personal data of a Child Patient under applicable law is treated as a category of Specific Personal Data requiring enhanced protection under UU PDP.
18.3 Where Consent is used as a legal or product-policy requirement for processing Child Patient personal data, the dental Controller must verify valid Consent of a parent and/or lawful guardian under applicable UU PDP Article 25 and related law.
18.4 Dentalverse technically supports verification of guardian authority and Consent Evidence according to the dental clinic's instructions and approved Patient Workflow, and processes relevant features fail-closed when required Evidence is unavailable.
18.5 This Notice does not independently designate child assent, acknowledgement of explanations, or participation in decision-making as a separate statutory Hard Gate. The applicable scope will be defined in the Patient Consent Template after review of Indonesian healthcare law, professional standards, ethics requirements, and local legal advice.
18.6 Before publication, local counsel will verify the exact Child age threshold, parent/guardian authority, and the extent to which Government Regulation No. 17 of 2025 and Minister of Communication and Digital Regulation No. 9 of 2026 apply to Dentalverse's patient proxy workflow.
Article 19. Delivery and Acknowledgement of this Notice
19.1 Representative
The Representative receives and can acknowledge this Privacy Notice during Dental Organization signup.
Recommended UI:
[Required acknowledgement] I have reviewed the Dentalverse Privacy Notice.
This is not Consent.
19.2 Pay Doctors, Staff, and Other Organization Users
When the Representative registers a Pay Doctor or employee with the Organization, Dentalverse provides this Notice to that individual through one or more of:
-
invitation email;
-
first-login screen;
-
account settings;
-
Privacy menu within the Service; or
-
another continuously accessible method.
A separate Organization contract or blanket personal-data Consent checkbox is generally not required for those Users.
19.3 Evidence
Delivery/acknowledgement may be recorded as follows:
notice_record:
notice_id: DV-LEGAL-PN-ID-001
notice_version: "0.3.2"
subject_user_id: USER-001
organization_id: ORG-001
delivered_at: "..."
acknowledged_at: "..."
delivery_method: first_login
Where only delivery is required and there is no acknowledged_at, the event may be managed separately as a NoticeDeliveryRecord, subject to legal/UI design.
Article 20. Relationship with Optional Consent
20.1 Marketing and Promotions
Receipt of marketing/promotional communications is a separate optional Consent of the individual recipient.
The Representative's choice does not substitute for the Email/SMS/WhatsApp marketing Consent of another Pay Doctor or employee.
20.2 Service Improvement and Statistics Data Use
This optional Consent applies only to the relevant individual's usage/analytics data defined in a separate document.
Patient Data is not included in the default scope.
20.3 Withdrawal
Optional Consent may be withdrawn at any time using the applicable method.
Withdrawal does not affect the legality of processing lawfully performed before withdrawal. Withdrawal of consent-based processing is handled in accordance with the relevant Marketing/Analytics Consent document's immediate-block product policy and the processing-termination period under UU PDP Article 40.
20.4 Anonymization
The process of converting personal data into truly anonymous data may itself constitute personal-data processing, so a lawful basis must exist for the pre-anonymization processing.
Subsequent processing of data that is truly anonymized so that it cannot reasonably be re-linked to an individual may not be subject to the same withdrawal structure as personal data.
Article 21. Changes to this Privacy Notice
21.1 Dentalverse may update this Notice if law, Service, processing purposes, or Processor configuration changes.
21.2 Material changes such as the following will be notified by an appropriate method before taking effect:
-
new personal-data processing purpose;
-
new category of personal data;
-
new recipient materially affecting data-subject rights or risk;
-
change from an Indonesia-only structure to one involving cross-border transfer;
-
material change to rights or retention periods; or
-
new consent-based processing.
21.3 A processing change requiring new Consent is not implemented merely by changing the Privacy Notice; separate Consent is obtained.
21.4 Historical Privacy Notice IDs, versions, Digests, and delivery records are retained in traceable form.
Article 22. Relationship with Other Legal Documents
22.1 The roles of this Notice and related documents are separated as follows:
Document Primary Role
Terms of Service General Service agreement between Dentalverse and Dental Organization
DPA Patient Data processing agreement between dental Controller and Dentalverse Processor
Pilot Terms Special conditions for Pilot features, duration, pricing, rollback, etc.
This Privacy Notice Notice of Organization User personal data where Dentalverse is Controller
+ high-level explanation of Dentalverse's Patient Processor role
AI Patient Consultation Service Guideline AI-use limitations and safety Guideline
Marketing Consent Individual optional marketing receipt
Service Improvement & Statistics Data Use Individual optional Analytics processing
Consent
Patient Notice/Consent Purpose-specific patient workflow for personal-data processing, AI, Lab, etc.
22.2 Where there is a conflict concerning Patient Data processing, the DPA and the dental clinic's lawful patient-facing notice/Consent structure govern.
22.3 Privacy Notice acknowledgement must not be confused with contract acceptance, DPA Subprocessor Authorization, or Patient Consent.