VstreamX Studio Inc. (“VstreamX”, “we”, “us”) makes DentalX, software that dental clinics use to run their practice. This policy explains what personal information DentalX handles (on the website at dentalx.studio, in the clinic app at app.dentalx.studio, and on the pages patients open from a clinic’s messages), what we do with it, who helps us, where it is kept, and the choices people have.
We operate from Brandon, Manitoba. Manitoba has no private-sector privacy statute in force, so Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) governs how we handle the personal information we are responsible for. A clinic in Canada may also be subject to its province’s health-information law for its patients’ information, such as Manitoba’s Personal Health Information Act or Ontario’s Personal Health Information Protection Act, 2004; we process that information for the clinic as its information manager or agent, under section 8 of our Terms of Service. Section 2 explains the two different roles we play, and section 15 names the person accountable for this policy.
1. Who we are
DentalX is provided by VstreamX Studio Inc., a Manitoba corporation:
VstreamX Studio Inc.
Office B - 1043 Rosser Ave, Brandon MB R7A 0L5, Canada
admin@vstreamx.com
2. Our two roles
Information we decide about
We decide how we handle the information of the people who visit our website, the clinic staff who hold DentalX accounts (owners, managers, dentists and receptionists), the people who manage a clinic’s billing, and anyone who writes to us. For that information VstreamX is the organization accountable under PIPEDA, and this whole policy applies to it.
Patient information we process for clinics
A clinic that uses DentalX enters information about its patients, and patients send it information through DentalX. That information belongs to the clinic, which decides what is collected and why. We process it only on the clinic’s behalf, under our Terms of Service, to provide DentalX to that clinic. The clinic’s own privacy notice governs how it handles its patients’ information, and sections 4 to 11 of this policy describe how we handle it for the clinic.
If you are a patient, please contact your clinic about your information: it can see, correct, export and delete your records, and it can ask us for help. In Mexico, your rights of access, rectification, cancellation and opposition (ARCO rights) are exercised with the clinic, which is responsible for your data. In the United States, your rights under HIPAA are exercised with your dental practice, as its Notice of Privacy Practices explains; VstreamX acts for a United States practice only as its business associate, under the business associate agreement it has signed with that practice. If you write to us about a clinic’s records, we pass your request to that clinic and tell you that we have.
3. What we collect
- Clinic accounts. When a clinic signs up: the clinic’s name and country, and the owner’s name and email address. The owner’s email address also becomes the clinic’s contact address: the pages patients open from the clinic’s messages can show it, and patients’ replies to the emails DentalX sends for the clinic go to it. The clinic’s owner or a manager can change it in Settings. Later, the clinic’s address, telephone, logo, opening hours, currency, tax and printing settings, and its other settings.
- Staff accounts. Each User’s name, email address and role; a telephone number, if the clinic enters one when it invites them or they choose text messages as a second factor; and, for those who prescribe, their professional licence numbers and specialty. Passwords are stored by our sign-in provider in a form we cannot read. A User who signs in with a Google account shares their name, email address and profile photo from it. When a User sets up or uses text messages as a second factor, Google reCAPTCHA checks the browser, which sends Google information about the browser and device (section 8).
- Billing. The clinic’s Plan, billing period and subscription status, Stripe’s references to its customer and subscription, and the clinic name and email address we give Stripe. Card details are entered with Stripe and never reach us (section 7).
- The audit trail. A record of who did what and when in a clinic’s account, such as opening a patient’s chart, exporting or deleting data, changing a patient or treatment record, and changing important settings, and a separate record of what our own staff do in DentalX’s administrative console. Entries identify the person’s account, and many carry their email address; some name the patient concerned. They do not record IP addresses.
- Performance measurements. How long pages of the clinic app take to load: the page, the time, the app’s version, and the clinic and role of the person using it, but not who they are and nothing about patients.
- Error reports. When the clinic app meets an error: the page, the error message, the browser type, and the account, email address, role and clinic of the person using it. Web-address parameters, email addresses and phone-length numbers are removed from the message before it is stored.
- Server logs. Our server functions record what they do, for example that a reminder was sent or failed. They are designed to keep patients’ names, addresses and numbers out of these logs.
- Usage counts. Each month, how many AI requests and messages a clinic used and how much storage it holds, to apply its Plan’s limits.
- Support and messages to us. Support requests a clinic opens in the app, the messages in them, and emails people send us. Please leave patient information out of a support request unless we need it to help.
- Website visitors. The website sets no analytics or advertising cookies and loads no tracking scripts. Our hosting provider receives the technical information any website receives, such as the IP address and browser type, to deliver the page. Some photographs on dentalx.studio are loaded from Unsplash, so your browser sends your IP address and browser details to Unsplash when you open that page.
4. Patient information we process for clinics
Depending on what a clinic records and which features it uses, this can include:
- identity and contact details: name, date of birth, gender, telephone, email, address, emergency contact and insurance details;
- medical and dental history, allergies and medicines, appointments, treatments and treatment plans, dental and periodontal charts, clinical notes, prescriptions and lab orders;
- radiographs, clinical photographs, a profile photograph and documents;
- consent forms and their signatures. When a patient signs from a link, the record also keeps the name they typed, how they signed, a fingerprint of the exact text they signed, the browser they used, the network address recorded with the request (which may not identify the patient’s device) and the time, as evidence of the signature;
- invoices, payments, balances and cash-register lines;
- messages exchanged with the clinic over WhatsApp, including photographs, voice notes and documents a patient sends (not available in the United States), a patient’s reply of STOP or START with their phone number, and the emails the clinic sends through DentalX; and
- what a patient does on the pages opened from the clinic’s messages: confirming, cancelling, booking or rescheduling an appointment, and signing a consent form.
5. How we use information
We use the information we decide about to:
- provide DentalX, create and secure accounts, and confirm email addresses and second factors;
- bill subscriptions and keep the business records the law requires;
- answer support requests and messages;
- send service messages, such as sign-in and security emails, notices about changes to DentalX or to a clinic’s billing, and the monthly summary a clinic owner can choose to receive;
- keep DentalX secure, investigate misuse, measure its performance and fix errors; and
- comply with the law.
We use patient information only to provide DentalX to the clinic that holds it: to store and show it to that clinic’s Users, to send the messages the clinic asks DentalX to send, to run the AI features its staff ask for, to back it up and keep it secure, to support the clinic when it asks us to, and where the law requires. DentalX’s administrative console does not show patient records to our support staff. The people who administer our Google Cloud project can technically reach stored data; they do so only to keep DentalX running or secure, at a clinic’s request, or where the law requires.
We do not sell personal information, use it for advertising or share it for anyone else’s marketing, and we do not use patient information to train AI models or for any purpose of our own.
6. AI features
DentalX’s AI features draft clinical notes, treatment plans and visit summaries, summarize documents, analyse radiographs, answer questions in an assistant, and read identity cards, insurance cards and supply invoices to fill in forms. They run only when a clinic’s User asks, on a Plan that includes them. The text, image or document sent with that request goes to Google’s Gemini models through Vertex AI, from DentalX’s own Google Cloud project, and to no other AI provider. A visit summary is drafted from the treatment record without the patient’s name, contact details or date of birth.
Every answer is a draft for a person to check, and is labelled as AI output. A radiograph reading and a document summary are saved with that radiograph or document, labelled as AI output; other drafts enter a record only when a person adds them. The clinical AI features, which draft clinical notes, treatment plans and visit summaries, summarize documents and analyse radiographs, are available only to owners, managers and dentists. The AI assistant, which answers general clinical and practice questions, and the scans that read identity cards, insurance cards and supply invoices into forms, are available to every User of a clinic. The clinical AI features and the AI assistant are instructed never to originate a medicine dose. Radiograph analysis is not available to clinics in the United States. Our support staff may also use the same models to draft a reply to a support request, which a person reviews before it is sent.
Dictation. The microphone button in the clinic app uses the speech recognition built into your browser, which sends the audio to the company that makes the browser (for example, Google for Chrome) under that company’s terms. We never receive the audio, only the text the browser returns. Dictation is off for clinics in the United States, and anyone can type instead.
7. Payments
Subscription payments are processed by Stripe, and VstreamX Studio Inc. is the merchant. A clinic enters its card details on Stripe’s checkout and billing pages; they go directly to Stripe and never reach DentalX’s servers. Stripe handles them under Stripe’s privacy policy. We keep the business record: the Plan, the subscription’s status and Stripe’s references to the customer and the subscription. No patient information is sent to Stripe.
8. Service providers
These are the companies that process data for DentalX, in the same three groups as our Sub-processors page, which also shows them in tables.
Our sub-processors
The providers we engage to deliver DentalX:
- Google Cloud / Firebase. Hosting, database, file storage, sign-in (including the text messages that carry a second-factor code), server functions, backups and server logs. Receives: All Customer Data, including patient health information, and the accounts of clinic staff. Where: The United States, with the database in Google’s United States multi-region (nam5) and files and server functions in Iowa (us-central1). Firestore, Cloud Storage and Cloud Functions are covered by the Google Cloud Business Associate Agreement.
- Google Vertex AI (Gemini). The AI features a clinic’s staff choose to use, and drafts of our replies to support tickets. Receives: The text, image or document sent with each AI request. Where: The United States and other countries: Vertex AI’s global endpoint lets Google serve a request from a data centre outside the United States. Called from DentalX’s own Google Cloud project. Radiograph analysis is off for United States clinics.
- Google (Gmail). Reminders, recall notices, consent links, prescriptions and treatment plans sent by email. Receives: The recipient’s email address and the message, with its PDF attachment where there is one. Where: The United States and other countries where Google operates. One DentalX sender address sends for every clinic. It also sends the monthly summary a clinic owner can choose to receive.
- Meta (WhatsApp Business Platform). Reminders, recall notices and the two-way inbox over WhatsApp, for a clinic that sends through DentalX’s own WhatsApp Business account rather than one it connects itself. Receives: The patient’s phone number, the messages sent and received, and the files a patient sends. Where: The United States and other countries where Meta operates. Not available to clinics in the United States. A clinic that connects its own WhatsApp Business account is listed under services you connect instead.
- Google reCAPTCHA. Checking that a person, not a program, is at the browser when a User sets up or uses a text-message second factor. Receives: Information about the User’s browser and device and how the page is used, which the browser sends to Google; no patient data. Where: The United States and other countries where Google operates. Loaded only on the screens where a text-message second factor is set up or used.
The payment processor for our own billing
- Stripe. Payment processor for VstreamX’s own billing: clinic subscriptions and their payments. Receives: The clinic’s name, billing email and payment details; no Patient Data. Where: The United States and other countries where Stripe operates. VstreamX Studio Inc. is the merchant. Card details are entered on Stripe’s pages and never reach DentalX.
Services a clinic connects
Accounts a clinic connects itself. The clinic’s own agreement with the provider governs each one, and they are not our sub-processors:
- Your Google Calendar. Appointment sync, only for a clinic that connects its own Google account. Receives: Appointment time, the treatment, the dentist and the patient’s name. Where: Your Google account, which Google keeps in the United States and other countries where it operates. No phone numbers or clinical notes. Your own agreement with Google governs that account.
- Your WhatsApp Business account (Meta). Reminders, recall notices and the two-way inbox over WhatsApp, for a clinic that connects its own WhatsApp Business account, where DentalX offers it. Receives: The patient’s phone number, the messages sent and received, and the files a patient sends. Where: The United States and other countries where Meta operates. Not available to clinics in the United States. Your own agreement with Meta governs that account, its number and its bill. Connecting it loads Meta’s sign-up script, which can set Meta’s cookies in that browser.
Each receives only what its purpose needs. We use no analytics or advertising provider. Your browser’s speech recognition (section 6) and Unsplash (section 3) are not engaged by us, and are described where they apply. When a new sub-processor will receive patient information, we publish it on the sub-processors page before it starts.
9. Where information is kept, and transfers across borders
DentalX stores its data on Google Cloud in the United States: the database in Google’s United States multi-region and files and server functions in Iowa. Its backups are kept in the same Google Cloud project. AI requests may be served by Google from a data centre outside the United States. Email is delivered by Google, WhatsApp messages by Meta and payments by Stripe, in the United States and the other countries where those companies operate.
If you are in Canada, Mexico or elsewhere in Latin America, or anywhere outside the United States, this means your information is transferred to and processed in the United States and possibly other countries. While it is there, it is subject to the laws of those countries, and may be accessible to their courts, law enforcement and national security authorities under those laws. We use established providers whose terms with us include security and privacy commitments. Clinics tell their own patients about this in their own privacy notices.
10. Security
- Information travels encrypted (TLS), and Google encrypts everything DentalX stores on Google Cloud.
- In addition, DentalX encrypts the patient record’s name, date of birth, telephone, address, emergency contact, medical history and insurance details with AES-256-GCM before they are stored, under a key kept in Google Secret Manager. The patient’s email address is not encrypted this way. A patient’s name is also copied, without this additional encryption, onto the records that need it, such as appointments, invoices, treatments, recalls, consent forms and prescriptions; appointments also carry the patient’s telephone number and email address, and WhatsApp conversations the patient’s telephone number. Those copies, and other records such as treatment notes, consent forms, images, documents and messages, are protected by Google’s encryption at rest and by the controls below.
- Each clinic’s data is isolated by security rules that refuse access by default, and each User sees and does only what their role allows.
- DentalX asks for a second factor at sign-in from every User who has set one up. A clinic owner can make a second factor required in the app for the clinic’s owners and managers, and clinics in the United States start with that requirement on. Our own staff must use a second factor to open DentalX’s administrative console. DentalX signs a User out after eight hours without activity, including when the browser was closed in the meantime.
- The audit trail records the opening of a patient’s chart, exports and deletions, and changes to patient and treatment records (section 3). It does not record every read, such as opening a stored file.
- The database is backed up daily, with seven days of backups and seven days of point-in-time recovery. Links in patients’ messages expire, and a consent-signing link works once.
No system is perfectly secure. If a breach of the information we are responsible for creates a real risk of significant harm, PIPEDA requires us to report it to the Privacy Commissioner of Canada, to notify the people affected as soon as feasible, and to keep a record of every breach. If a breach affects patient information, we tell the clinic without undue delay so that it can meet its own duties. The individual named in section 15 is responsible for this. If you believe information has been exposed, write to admin@vstreamx.com.
11. How long we keep information
- Patient information is kept for as long as the clinic keeps it in DentalX, until the clinic’s data is deleted after it leaves. DentalX does not delete patient records on a schedule while the clinic’s account is active; the clinic decides how long to keep them, as its law requires, and can delete or anonymize a patient’s records. Consent forms and their signing evidence stay with the record. WhatsApp messages and files stay with the clinic until it deletes the patient or its data is deleted.
- When a clinic leaves, we keep its data for 60 days after its subscription ends, then prepare a complete export of it and make it available to the clinic owner. When 90 days have passed since the subscription ended, or sooner if the clinic instructs us in writing, we delete the clinic’s patient information within 30 days, after telling the clinic owner by email at least 30 days before, as sections 8.11 and 13 of our Terms of Service describe. Deleting it also deletes that export.
- Clinic and staff accounts are kept while the clinic’s account exists. When a clinic’s data is deleted, we keep its account details and staff accounts until we close them; a person can ask us to delete their account at any time (section 12).
- The audit trail is kept for seven years. When a clinic deletes or anonymizes a patient, the entries recording what was done with that patient stay, and some of them name the patient. When a clinic’s data is deleted, its audit trail is kept with the patient details removed. Entries made before the seven-year rule was introduced carry no expiry date yet, and stay until we give them one or remove them.
- Billing records are kept for at least six years, as Canadian tax law requires.
- Error reports and performance measurements are deleted after 90 days, and server logs after 30 days. Error reports made before the 90-day deletion was introduced carry no expiry date, and stay until we remove them.
- WhatsApp opt-outs. When a patient replies STOP or START to a clinic’s WhatsApp messages, we record their phone number with that choice, so that it keeps being honoured. That record has no expiry date and stays when a patient’s records or a clinic’s data are deleted.
- Export files a clinic creates are deleted seven days after they are made. The complete export we prepare when a clinic leaves is deleted with the clinic’s data.
- Backups. Deleted information remains in database backups until they expire, within seven days. Earlier versions of deleted files may remain in the storage service’s version history: we remove them on request, and an automatic removal 30 days after deletion is being put in place. Those copies stay under the same protections and are used only to recover from a failure.
12. Your rights
Clinic staff, website visitors and anyone who writes to us may ask for access to, correction of, export of or deletion of their personal information by writing to admin@vstreamx.com. Users can correct much of their own profile in the app; some details are managed by their clinic. You may also withdraw your consent to our use of your personal information, subject to legal or contractual restrictions and reasonable notice; tell us and we will explain what that would mean for your account before it takes effect. We respond within 30 days of receiving your request, as PIPEDA requires; if we need longer, we tell you within those 30 days why, and for how long. Requests reach the individual named in section 15. If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada.
Patients exercise their rights with their clinic, as section 2 explains. A clinic can export a patient’s record, which lists the patient’s files (they can be downloaded from the patient’s chart), and can correct, delete or anonymize it. Deleting a patient also deletes their WhatsApp conversations and the files they sent over them, and takes their name off the clinic’s cash-register lines, whose amounts stay in the cash book; the audit trail of what was done is kept for seven years (section 11). We help clinics answer their patients’ requests.
13. Cookies and browser storage
DentalX itself sets no cookies and uses no browser storage for advertising, analytics or tracking. What it keeps in the browser is what it needs to work:
- the sign-in session, kept by our sign-in provider;
- preferences: the language, the tooth-numbering system, the dictation language, the console theme, whether the side menu is open, the dentist and time last chosen when booking, and which notices have been dismissed;
- a copy of the signed-in User’s own profile (name, email address, role and clinic) and of whether they have and need a second factor, so the app opens quickly;
- the time of the signed-in User’s last activity, a bare timestamp written at most once a minute, so that the sign-out after eight hours without activity applies even after the browser was closed; and
- a working copy of the clinic’s records, so the app loads quickly. The patient record’s encrypted fields stay encrypted in it; the copies of names, telephone numbers and email addresses on other records (section 10), and those other records, are in it as they are stored.
Signing out from the menu erases the working copy, the profile and second-factor copies, and the time of the last activity. The automatic sign-out after eight hours without activity erases the time of the last activity but keeps the other copies for the same User’s return, so always sign out from the menu on a shared computer.
Some screens load another company’s script, which can store information in the browser under that company’s own policies: the screens where a User sets up or uses a text-message second factor load Google reCAPTCHA, and connecting a clinic’s own WhatsApp Business account loads Meta’s sign-up script, which can set Meta’s cookies. The installed app also stores DentalX’s own program files, which hold no clinic data. The pages patients open from a clinic’s messages remember only the language chosen for that visit.
14. Children
DentalX is for clinics. Accounts are for adults who work at or for a clinic, and the website is not directed to children. Clinics record information about patients of every age, including children, and are responsible for the consent of a parent or guardian where their law requires it.
15. Who is accountable
PIPEDA requires an organization to designate an individual who is accountable for its compliance and to make that person’s identity available. For VstreamX Studio Inc. that individual is:
Ricardo Javier Sandoval Sandoval
Chief Financial Officer, VstreamX Studio Inc.
admin@vstreamx.com
Office B - 1043 Rosser Ave, Brandon MB R7A 0L5, Canada
That accountability covers all personal information in our custody, including information we transfer to the providers listed in section 8. Other people at VstreamX handle personal information day to day; delegating the work does not move the accountability.
16. Changes to this policy
We may update this policy. The effective date and revision at the top of this page always identify the current text, and changes are published here. If a change affects how we handle patient information, we tell clinic owners by email before it takes effect.
17. Contact
Questions about privacy, requests about your information, and reports of a suspected breach: admin@vstreamx.com, or by mail to VstreamX Studio Inc., Office B - 1043 Rosser Ave, Brandon MB R7A 0L5, Canada.