Privacy Policy

About you,
not your patients

This policy covers what DentureFlowPro holds about you — the denturist, coordinator, assistant or technologist who signs in and uses the software.

Last updated 14 August 2026

Which document you want

There are two, because there are two different kinds of information and two different sets of obligations. Mixing them makes both harder to check.

  • This page is about you, the practitioner. What is held about your account, what is recorded about what you do in the software, and what is not collected at all.
  • Privacy & PHIPA is about your patients. Your practice is the health information custodian; DentureFlowPro is its electronic service provider. Data residency, AI handling, audit trails, retention and patient access rights all live there.

Patients do not install this app and do not have accounts in it. Their information is in the system because your practice put it there, under the arrangement described on the other page.

What is held about you

Only what the software needs to work and to keep a defensible record of who did what.

  • Your account — your name, the username you sign in with, and your role in the practice.
  • Your password, as a bcrypt hash. It is not stored in a form anyone at DentureFlowPro can read, and it cannot be recovered — only reset.
  • Two-factor authentication, if you turn it on — the secret that generates your codes, and single-use backup codes held as hashes. Off by default.
  • Your acceptance of the staff confidentiality agreement — the name you typed, the date, and the IP address it was signed from.
  • An audit record of what you do in the clinical record — signing in, viewing a chart, creating, changing or deleting an entry, and exporting a record. Each entry carries your identity, the time and the originating IP address.
  • Your sessions — a server-side record of your signed-in session, so you stay signed in between visits.
  • Crash reports — if the app hits an error, the error message, a stack trace and the page address you were on are recorded against your account. Because a chart address contains the patient's internal identifier, that identifier can appear in a crash report. It is a database key, not a name.

Why the audit trail is not optional

The record of what you do is the part of this policy people ask about most, so it is worth being direct: it exists to protect you as much as the patient.

The College of Denturists of Ontario requires an electronic record system to keep an audit trail showing changes and preserving original content. When a chart entry is questioned months later, the trail is what establishes who wrote it, when, and what it said before any correction. A system that let you switch that off would be a worse system, and this one does not offer the option.

The same applies to record exports. Under PHIPA, knowing who took a copy of a record out of the practice is the point — and unlike opening a chart, a download leaves no other trace.

Face ID, Touch ID and the camera

These are the two things the phone app touches that the browser does not.

  • No biometric information is collected, transmitted or stored. When Face ID or Touch ID unlocks the app, iOS performs the match on your device and returns nothing but a yes or no. Your face and fingerprint data never leave the phone and are never available to DentureFlowPro.
  • The app lock is a screen cover, not a sign-in. It hides patient records on a phone that has been put down; it does not replace your password or your two-factor code, both of which are verified by the server.
  • Clinical photographs go to the patient's chart and nowhere else. They are deliberately never saved to your camera roll, because a photograph taken in the operatory is part of a health record and should not end up in your personal photo library or its cloud backup.
  • The app reads no other photos. It can attach an image you explicitly choose; it does not browse or index your library.

What is not collected

Stated plainly, because the absence is as informative as the presence.

  • No advertising, and no advertising identifiers. Nothing here is used to target ads anywhere.
  • No cross-application or cross-site tracking. You are not followed between services.
  • No third-party analytics SDK in the application. There is no product-analytics vendor watching your session.
  • No location tracking. The app never asks for your position and does not record it.
  • No access to your contacts, calendar, messages or files beyond a file you deliberately attach.
  • Nothing is sold or rented, to anyone, at any price.
  • Nothing is used to train artificial-intelligence models — not your data and not your patients'.

Where it is held, and who can see it

Your account information sits in the same place as everything else: Google Cloud's Montréal region, encrypted in transit and at rest. It does not leave Canada in the ordinary course of operation.

  • Your practice's denturist can see the staff accounts in their own clinic, and manage them — that is how a practice runs its own team.
  • DentureFlowPro platform administrators can see account records and the audit trail. That access exists to operate and support the service, and administrative actions are themselves audited.
  • Nobody else. Your information is not disclosed to third parties. There is no data broker, no advertising network, and no analytics vendor in this list because there are none in the product.

App Store review is not an exception to this. Apple has no access to the database or the servers. When an app is submitted, a reviewer signs in with a demonstration account we create for that purpose, in an isolated clinic containing invented patients and nothing else.

How long it is kept

  • Your account is kept while you work at a practice using DentureFlowPro. When you leave, the practice disables it.
  • Audit entries are kept and are not editable or deletable, by anyone, including us. A record of who changed a clinical entry is only worth having if it cannot be quietly removed — and record-retention obligations run for years after the last entry in a chart.
  • Session records expire and are cleared automatically.

This is the one place where your rights over your own information are genuinely limited, so it should not be buried: you cannot have your audit history erased, because it is part of a clinical record your practice is obliged to keep.

Your rights, and how to use them

Under PIPEDA and Ontario privacy law you may ask what personal information we hold about you, ask for a copy, and ask for a correction if something is wrong.

Write to privacy@dentureflowpro.ai. We will answer within thirty days. If a request cannot be met — an audit entry, most likely — you will be told plainly why rather than being ignored.

If you are not satisfied with the answer, you can complain to the Office of the Privacy Commissioner of Canada, or to the Information and Privacy Commissioner of Ontario.

Changes to this policy

If the product starts collecting something it does not collect today, this page changes when the product does, and the date at the top moves. We do not quietly broaden what is gathered and update the policy later.

Questions about your own data

Email privacy@dentureflowpro.ai. For questions about patient information, data residency, AI handling or retention, the detail is on the compliance page.

Privacy & PHIPA compliance