Trust

Security & data

Last updated: 7 October 2026

How patient and clinic data is stored, who processes it, and how long it is kept.

01.Who runs Dentalys

Dentalys.ai is operated by C-Vids Productions (UEN 53119647W), Singapore. Questions about security or data can be sent to support@dentalys.ai.

02.Where data lives

Clinic and patient data is stored in Supabase Postgres on AWS in the Tokyo region (ap-northeast-1). The application’s server functions run on Vercel, also in Tokyo. Data is encrypted at rest and in transit.

03.Sub-processors

  • Supabase — Database and authentication (Postgres on AWS, Tokyo).
  • Vercel — Hosting and application functions (Tokyo).
  • OpenAI — Generating the AI receptionist’s replies. Conversation content is sent to its API for each reply.
  • Resend — Sending email, such as appointment reminders.
  • Telegram — Delivering messages when a clinic uses a Telegram bot.
  • Meta — Delivering messages, only when a clinic connects Instagram or Messenger.
  • Google — Calendar availability and booking sync, only when a clinic connects Google Calendar.
  • Stripe — Subscription billing. Card details are handled by Stripe and never stored by us.

04.What the AI will not do

The AI receptionist answers questions about the clinic, its services and prices, and books appointments. It does not diagnose, prescribe, or give clinical advice. Clinical questions are answered only from the clinic’s own FAQs; otherwise the patient is told the dentist will go through it at the visit. Urgent symptoms are handed to the clinic’s team, and the clinic owner gets an email. When asked, it says it is the clinic’s AI assistant, not a person.

05.Retention

Conversation logs and handoff requests are deleted automatically after 12 months. Booking records remain available to the clinic while its account is active. When a clinic deletes its account, its data is removed within 30 days.

06.PDPA

Patient data is collected only for the clinic’s appointment purpose. The clinic is the data controller and Dentalys is its data processor. Patients may request access to, or deletion of, their data through their clinic, and we act on the clinic’s instructions.

07.Backups and access

Row-level security is enabled on every database table, so a signed-in clinic can reach only its own data. Server-side jobs use a service-role key that exists only in server configuration and is never sent to a browser. Database backups are managed by Supabase.