Privacy Policy
Last updated: 2 September 2026
1. Who we are
DentalApp is a web application for the management of dental practices, provided by DevSoft Express (the “Provider”). For anything in this policy write to devsoftexpress@gmail.com.
Each dental practice that uses DentalApp (the “Practice”) is the data controller of its patients' data; the Provider processes that data on the Practice's behalf as a data processor under a written agreement (Art. 28 GDPR). For the accounts of practice staff and for this website, the Provider is the controller.
2. What data DentalApp handles
- Staff accounts: name, e-mail, role, login records, interface preferences.
- Patient records entered by the Practice: identity and contact details, codice fiscale, clinical notes, appointments, quotes, invoices and payments, prescriptions, consent forms, uploaded files. This is health data (Art. 9 GDPR), processed under the Practice's responsibility for the provision of dental care and its legal record-keeping duties.
- Technical data: server logs (IP address, browser, timestamps) kept for security and troubleshooting.
3. Google user data (Google Calendar)
A Practice may connect a Google Calendar to import its appointments into DentalApp. When it does:
- DentalApp asks Google for read-only access to the calendars of the connected account (scope
https://www.googleapis.com/auth/calendar.readonly). It never writes to, edits or deletes anything in Google Calendar. - What is read: the list of calendars, and event titles, descriptions, times, locations and colours for the date range the Practice chooses to import.
- What is stored: the OAuth refresh token (encrypted at rest), the id of the calendar chosen, the Practice's colour legend, and - only for the events the Practice explicitly ticks and imports - the resulting appointments in the Practice's own DentalApp diary. Events that are previewed but not imported are not stored.
- Google data is used solely to build those appointments for the Practice. It is not used for advertising, not sold, not shared with third parties, not used to develop or train models, and not read by humans except as needed for support at the Practice's request or as required by law.
- The connection can be revoked at any time from DentalApp (delete the calendar connection) or from the Google account's security settings; on revocation DentalApp deletes the stored token. Appointments already imported remain part of the Practice's diary, as the Practice's own records.
DentalApp's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Why, and on what legal basis
- Providing the service to the Practice and its staff (contract, Art. 6(1)(b) GDPR).
- The Practice's provision of dental care and its legal duties (Art. 9(2)(h) and Art. 9(2)(c) GDPR, on the Practice's instruction).
- Security, fraud prevention and troubleshooting (legitimate interest, Art. 6(1)(f) GDPR).
- Legal obligations such as tax record-keeping (Art. 6(1)(c) GDPR).
5. Where data is kept and who can see it
Data is hosted on servers located in the European Union. Access is limited to the Practice's authorised staff (through per-user permissions inside DentalApp) and to the Provider's technicians for maintenance, under confidentiality obligations.
Sub-processors used: hosting provider; e-mail delivery provider; Anthropic (automated reading of supplier documents only - never patient data).
No data is transferred outside the EU/EEA except where a sub-processor listed above operates under EU-approved safeguards (standard contractual clauses).
6. How long
Patient and clinical records: for as long as the Practice's legal retention obligations require (Italian rules on the cartella clinica and on tax documents), then deleted or anonymised according to the Practice's retention settings. Staff accounts: for the life of the account plus 12 months. Server logs: 90 days. Google Calendar tokens: until the connection is removed.
7. Your rights
Patients exercise their rights (access, rectification, erasure, restriction, portability, objection) with their Practice, which is the controller; DentalApp gives the Practice the tools to honour them. Staff and website visitors can write to the Provider at the address above. Anyone may lodge a complaint with the Italian supervisory authority (Garante per la protezione dei dati personali, www.garanteprivacy.it).
8. Cookies
DentalApp uses only technical cookies needed to keep you signed in and to remember interface preferences. No advertising or third-party tracking cookies are set.
9. Security
Encrypted transport (HTTPS), encryption at rest for stored credentials and tokens, per-user permissions, audit logging of server actions, regular backups.
10. Changes
We will post any change to this policy on this page with a new “last updated” date.