Privacy & Compliance
DentureFlowPro is built for Canadian denture practices, around Canadian privacy law — including Ontario's Personal Health Information Protection Act (PHIPA). This page sets out, in plain terms, how the platform handles personal health information — what it does, where the data lives, and what we ask of you. Everything below describes how the software actually works today.
Last updated 28 July 2026
Under Canadian health-privacy law, your practice is the health information custodian. The record belongs to your practice, and the obligations to your patients are yours.
DentureFlowPro acts as your electronic service provider — we supply and operate the software that stores and presents that record on your behalf. In that role we:
This distinction matters. It means the record stays yours, and it means you can answer your own patients — and your College — about who holds their information and on what basis.
Two different sets of information, held for two different reasons, under two different responsibilities.
About you, the practitioner using DentureFlowPro. Your account details, and an audit entry for what you do in the record. That is a separate document, because it is a different subject with different obligations — see the privacy policy for practitioners.
About your patients, held on your practice's behalf. Your practice decides what goes into a chart; the system is capable of holding:
What is not collected. There is no advertising or cross-application tracking in this product, and no analytics that follow a person between services. Nothing here is sold or rented. Patient information is not used to train artificial-intelligence models. We do not ask for information we have no use for — there is, for instance, no reason for this system to hold a patient's social insurance number, and it does not.
Personal health information is stored in Canada. Every component that holds patient data sits in Google Cloud's Montréal region (northamerica-northeast1):
Records created in your practice therefore remain in Canada in the ordinary course of operation, rather than being processed in another jurisdiction. Data is encrypted in transit and encrypted at rest under Google-managed keys.
DentureFlowPro uses AI to format dictated notes, read radiographs, draft referral letters and assist with intraoral examinations. That processing runs on Google Cloud Vertex AI, in the same Montréal region as the rest of your data, under our signed agreement with Google Cloud — not through a consumer AI service.
Under PHIPA, being able to answer "who accessed this record, and when" matters as much as preventing improper access in the first place. DentureFlowPro records:
Each entry carries the staff member, the record affected, the originating IP address and a timestamp.
A patient may ask for a copy of their own record, and a patient moving practices is entitled to have their chart follow them. These are two different needs, and the platform serves both:
The record is append-only by design, and there is deliberately no facility to delete a patient chart from the interface.
This is not an oversight. Denturists across Canada are subject to record-retention obligations that outlive most requests to remove information, and a chart that can be erased on impulse is not a legal record. Providing a copy of a record and destroying a record are two different requests, and only the first can be answered on the spot.
Where a genuine erasure obligation arises, it is handled as a deliberate, audited, administrator-level operation with the legal basis recorded against it — never as a button on a chart.
Appointment reminders and recall messaging are off unless deliberately switched on, both at the platform level and again by each individual practice. Nothing is sent by default.
When enabled:
An automated suite of more than a hundred and fifty tests — including browser tests, and covering access control, separation between practices, billing arithmetic, record export and the consent rules above — runs against every change before it can be accepted.
Deployments to production are deliberate and manual. Nothing reaches the live system automatically.
Software is one half of compliance; the practice is the other. To hold up your end:
If you have a privacy question, need documentation for your own compliance review, or wish to report a suspected privacy breach, contact us at privacy@dentureflowpro.ai and we will respond promptly.
We are glad to complete vendor security questionnaires, walk your governance team through the audit trail on a live screen, or provide a sample record export so you can see exactly what a transfer of care produces.
Apply for Beta