Privacy Policy

Last updated 2026-09-17. This explains what we hold, why, and what you can ask us to do about it.

1. Who is responsible

iDentist.Live is operated by Vilnek, Gujarat, India. For anything in this policy, write to identist@vilnek.in.

For patient records entered by a clinic, the clinic is the data controller and we are the processor acting on its instructions. If you are a patient, contact your clinic first; we will support them in responding.

2. What we collect

From clinic users

Patient data entered by the clinic

Technical

3. How it is protected

Clinical records are encrypted with AES-256-GCM using a key derived per clinic. Each sealed record is cryptographically bound to its own location, so it cannot be moved to another document or another practice and still be read. Access is enforced on our servers: membership of a clinic is proved before any record is returned.

Face ID runs on your device. Biometric templates are not sent to any external service, are not shared between clinics, and are not used to identify anyone outside the clinic that enrolled them.

4. Why we process it

5. Who we share it with

We do not sell personal data, and we do not use identifiable patient data to train AI models. We share data only with service providers necessary to run the platform:

We may disclose data where legally required, and will tell you unless prohibited from doing so.

6. Where it is stored

Data is stored on Google Cloud infrastructure. Platform functions run in the asia-south1 (Mumbai) region.

7. How long we keep it

Clinical records are kept for as long as the clinic maintains its account, since dental records carry statutory retention periods. If a subscription is suspended for non-payment your data is retained, not deleted. On account closure we delete or return data on request, subject to any legal retention we are bound by.

8. Your rights

Under India's Digital Personal Data Protection Act 2023, and other law that may apply to you, you can ask us to:

Write to identist@vilnek.in. If you are a patient of a clinic using the platform, contact the clinic — they hold the record.

9. Cookies and local storage

We use browser storage to keep you signed in and to cache your practice data for offline use. We do not use advertising or cross-site tracking cookies.

10. Children

The platform is for dental professionals. Children's records may be entered by a clinic as patient data, and are protected on the same basis as all other clinical data, with the clinic responsible for lawful consent.

11. Breach notification

If a breach affects your personal data, we will notify the affected clinic and the relevant authority as required by law, without undue delay.

12. Changes

We will post updates here and change the date at the top. Material changes will be notified in the app or by email.

Questions, or to exercise a right: identist@vilnek.in