Last updated September 2026. This page explains what the platform collects, how it protects it, and — importantly — what compliance does and does not mean.
For clinics: account details of staff users (name, email, hashed password), clinic profile and settings, dentists, services, working hours. For patients: only what is needed to schedule and confirm a visit — name, email, phone, optional date of birth, appointment reason and notes the patient chooses to add. We deliberately do not collect clinical or insurance information during public booking.
Every record carries the identifier of exactly one clinic. Every query in the application is scoped to the clinic of the signed-in user at the database layer, not merely hidden in the interface. A clinic cannot read, search or infer another clinic’s data.
Notifications are sent through the provider configured by the platform operator (SMTP, Resend, SendGrid, Twilio). Message content includes appointment details and the patient’s name. Review the provider’s data-processing terms as part of your compliance work.
Clinics can remove patient records; contact details are erased and upcoming appointments cancelled while anonymised scheduling history is retained for reporting. Clinics can export appointment data as CSV at any time. Platform-level export and deletion requests are handled by the operator.
TeethCare PMS provides the technical controls above. No software is “HIPAA compliant” or “PIPEDA compliant” on its own. Compliance depends on where and how it is hosted (data residency, backups, access to servers), the agreements you hold with vendors, your internal policies and training, breach procedures, and the law that applies to your practice. Treat this platform as a strong foundation and complete the organisational work with your privacy officer.
Questions about privacy on this installation: noreply@dentalwebsitesdesign.com.