DentralSuite

Data Protection & Medical Records

Effective date: July 11, 2026

Version 1 — this document is an initial draft published for transparency and is subject to formal legal review. The current terms of your use of Dentral remain as described here until an updated version is published.

This statement describes how Dentral stores, protects and handles the medical records and health data that dental clinics manage on the platform. It complements our Privacy Policy and reflects our obligations awareness under the Egyptian Personal Data Protection Law No. 151 of 2020 (PDPL), which treats health data as sensitive personal data.

1. Roles: clinic and platform

The clinic (the healthcare provider) is the data controller of its patients' records: it decides what is collected and why, and it owns the therapeutic relationship. Dentral is the data processor: we store and process patient data on the clinic's documented instructions, embodied in the platform's features, and for no other purpose.

Dentral personnel do not access patient records except where strictly necessary for support or incident response, and such access is logged.

2. Where data lives

Patient records, appointments, clinical notes, dental charts, prescriptions, uploaded images and receipts are stored on Dentral-managed servers in a dedicated database per platform, with strict tenant isolation enforced at the application layer — every query is scoped to the requesting organization.

Uploaded files (patient imaging, consent documents, payment receipts) are stored in a dedicated storage volume separate from the database.

3. Safeguards

Key technical measures currently in place:

  • TLS encryption for all traffic between your browser and our servers, including tenant booking subdomains.
  • Passwords stored as salted hashes; platform integration secrets encrypted at rest (AES-256-GCM).
  • Role-based access control: staff see only what their role in their organization permits.
  • Rate limiting and abuse protection on authentication endpoints.
  • Automated daily database backups with rotation, and restore procedures tested by the operations team.
  • Audit logging of platform-administration actions.

4. Sensitive data under the PDPL

Health data is sensitive personal data under Egyptian law and requires heightened care. Clinics remain responsible for obtaining any patient consents required for their own processing, for the accuracy of records they enter, and for honoring patients' rights over their records. Dentral provides the tools — export, correction, access control — to help clinics meet these obligations.

5. Retention and deletion

Patient records are retained as long as the clinic's account holds them. Clinics may correct or delete records subject to their own legal record-keeping duties. When an organization is permanently deleted at the owner's written request, its patient data and uploaded files are removed from the live systems, and expire from backup rotation within the backup retention window (currently 14 days).

6. Incident response

If we become aware of a breach affecting personal data, we will investigate promptly, take containment measures, and notify affected clinics without undue delay together with the information they need for their own notification obligations under the PDPL.

7. Sub-processors

We use a small set of infrastructure and communications providers (hosting, transactional email, SMS/WhatsApp delivery, card payment processing where enabled). Sub-processors receive only the data needed for their function — for example, a patient's phone number to deliver an appointment reminder — and never the clinical record itself.

8. Contact

For data protection questions, records requests or security reports: support@dentral.co. Patients should first contact their treating clinic, which controls their records.

Questions?

Contact us at support@dentral.co