Back to home

    Privacy Policy

    Last updated: 7 August 2026

    1. Who We Are

    DentalReady is operated by Dental Ready Technologies Pty Ltd (ACN 697 960 704) ("we", "us", "our"). It is an operations, screening, and training platform for dental practices. This policy explains how we collect, use, and protect your personal information when you use our website and services at dentalready.com.au.

    2. Information We Collect

    We collect information that you or an authorised integration provide, including:

    • Account information: name, email address, and password when you register
    • Profile information: role, employment details, practice affiliation, and any emergency-contact name, phone number, and relationship that an authorised user chooses to provide
    • Assessment data: responses to screening questions and learning module progress
    • App and device diagnostics: sanitised first-party feature events and, when Android barcode scanning is used, Google ML Kit may collect the app package/version, device model and operating-system/build information, available ML hardware, performance metrics, and device or per-installation identifiers for diagnostics and usage analytics. Barcode images, decoded barcode values, and scan results are processed on-device and are not sent to Google by ML Kit.
    • Attendance and on-site access data: clock-in/out times and workplace photos (if your practice uses the kiosk feature). If your practice enables a Staff app geofence, after an in-app explanation and your consent your device reads its current foreground precise or approximate location when you choose Check location. Local checks may repeat while Staff Clock, Personal Stats or Case Tracking remains visible. Protected-tool readings stay on the device. Only when you tap Clock in or Clock out is a fresh location and accuracy sent securely to DentalReady; the server calculates distance and discards the coordinates, retaining only the fix time, accuracy, calculated distance and configured radius with the attendance event. A linked operational audit may record that protected access was blocked or location permission was denied, but it does not contain coordinates or distance. DentalReady does not access location while the app is in the background.
    • Team Pulse data: workplace sentiment ratings and optional written feedback you submit through a Team Pulse round. Response content is stored separately from the participation record used to prevent duplicate submissions.
    • Audio and transcription data: optional voice notes used to draft SOPs, library content, and meeting notes, and performance-review recordings. A speaker must consent before an SOP or library voice note starts. Before a meeting recording, the user must confirm that every participant has been informed and consented. Performance-review recordings use their separate participant-consent workflow. Audio is uploaded to secure storage and processed to produce a transcript and the requested workflow output. Access is limited to authorised users for the relevant practice; a finalised performance-review recording is shared with the employee only when an authorised reviewer explicitly chooses to share it.
    • Patient and clinical information: where an authorised practice enables clinical workflows, users may enter patient labels or identifiers, appointment and treatment context, medical alerts, clinical notes, tooth-condition photographs, radiographs, periodontal charts, measurements, and clinician- or AI-generated findings. This health information is used only for the practice workflow selected by an authorised user and is available to authorised users for that practice.
    • Android administrative pain intake: the Android apps retain reported facts, pain scores, notes and a follow-up priority affirmatively selected by a human under the practice's approved protocol. The Android form does not calculate or suggest urgency, diagnose, recommend treatment or provide clinical advice.
    • VoiceStack operational call data: where a practice connects VoiceStack, DentalReady may receive caller and patient names and phone numbers, call metadata, provider-supplied summaries and transcript excerpts, sentiment, follow-up cues, treatment categories, and conversion probability. During backend ingestion, DentalReady may compare an external patient identifier, phone number, or name with the practice's existing patient records to associate the call with the correct operational follow-up. Authorised users, including Android app users, can view the stored information in Daily Control.
    • Lab-invoice upload data: an authorised user may choose to upload a lab-invoice photo or PDF for extraction and review. The selected file and its filename or file type may include a supplier or laboratory name, patient name or initials, case or job reference, tooth or shade reference, invoice number and date, and amount.
    • Supplier-invoice and stock-order import data: an authorised Practice app user may choose a supplier invoice or order-confirmation photo or PDF for extraction and review. The full selected file and selected supplier name are sent for that extraction. The file can contain practice or supplier names and contact details, invoice or order identifiers and dates, product names, catalogue codes, quantities, unit and line prices, subtotal, discounts or credits, freight, fees, tax and total. If the related invoice record is saved, the file and any related fields or records already saved are retained. Later stock, order and price-history writes occur separately, so a failure can leave the linked file and only a partial set of reviewed records. The user can retry the import or request authorised support or data deletion. Not every extracted header field is necessarily saved.
    • Stock-invoice attachments: authorised Staff and Practice users may also attach ordinary stock-invoice photos, scans or PDFs without AI extraction. A selected attachment is uploaded to DentalReady's Supabase Storage before the related invoice or delivery record is saved. Removing a selected file from the form asks Storage to delete it. If the app is interrupted or a later save is cancelled or fails, an uploaded file may remain until it is removed through an authorised support or data-deletion request.
    • Practice, employment, and financial information: practice and document-recipient addresses; rosters; personal and practice calendar events (including event details, notes, attendees, or assignees); timesheets; leave; payroll workflow data; invoices; supplier and stock records; accounting imports (the Xero integration receives Xero's account-list response, but returns only account IDs, codes, and names to the app and does not store bank account numbers through this pathway); operational metrics; and business financial summaries entered or connected by authorised practice users.
    • Files, documents, and communications: SOPs, library and migration files, meeting material, messages, notes, photos, videos, and other content users choose to upload or create for their practice. Some owner follow-up tools also retain the patient identifier, phone number, message template, and SMS body before opening the device's messaging app. If the audit log cannot be synchronised, the app may keep a plaintext offline copy scoped to that signed-in user and practice. The queue is capped at 50 entries. Each queued entry expires after 12 hours and is cleared on successful synchronisation, sign-out, or account change. If the app is not running at expiry, cleanup occurs the next time it starts.
    • Search and autocomplete queries: authorised owner workflows may send free-text stock-product searches or typed address queries to the configured search or autocomplete service to return relevant results.
    • Third-party login data: if you sign in via Google or Facebook, we receive your name and email from those services

    We also automatically collect usage data — such as pages visited, browser and device type, and approximate location derived from your IP address — using Google Analytics (GA4) and Vercel Analytics to understand how the platform is used and to improve our services. These tools set cookies or similar identifiers and process this data in aggregate. They run on our web app only (not the native mobile apps), and we do not sell this information.

    On our public marketing pages we also use advertising measurement tools — the Meta Pixel and Google Ads conversion tracking — to measure the effectiveness of our advertising (for example, which campaign led a dental practice to request a demo or sign up). These set cookies and may share limited event data (such as a page visit or a completed demo request) with Meta and Google. They run on our public website only — never in the native mobile apps, and never on pages that carry patient or account access links — and we do not sell this information.

    3. How We Use Your Information

    • To provide and maintain the DentalReady platform
    • To authenticate your identity and manage your account
    • To facilitate candidate screening, training, and staff management
    • To generate analytics for practice owners about their team
    • To provide privacy-protected Team Pulse results and support practice follow-up actions
    • To support authorised clinical workflows, including AI-assisted decision support that a treating clinician must independently verify
    • To provide practice operations, employment, payroll, invoicing, accounting, stock, and reporting workflows
    • To send service-related notifications (e.g. roster updates, reminders)
    • To improve our AI screening and training algorithms

    4. How We Share Your Information

    We do not sell your personal information. We share data only in these circumstances:

    • With your practice: practice owners can view data for staff and candidates affiliated with their practice. Team Pulse is an exception: DentalReady does not show individual response content or responder identities to practice leaders. Results are released only after a round closes and its configured threshold of at least three staff responses is met. Cohorts of three or four reveal rounded averages only; detailed score distributions and optional verbatim comments require at least five responses. A comment may identify you if you include identifying details.
    • Service providers: we use Supabase for data hosting, Google and Meta for authentication, Google Analytics and Vercel Analytics for web usage and performance analytics, Meta and Google for advertising measurement on our public website, Google ML Kit for on-device Android barcode scanning and its associated diagnostics/model updates, and the AI processors described below, all under strict data processing terms
    • Legal requirements: if required by Australian law or to protect our legal rights

    5. Third-Party AI Processors

    Some DentalReady features use artificial intelligence to classify, summarise, or draft operational content. We send only the data needed for the specific feature being used. Current AI-backed surfaces include:

    The production Android apps do not currently include the patient-specific AI pain-triage, Morning Huddle, patient-recap, tooth-condition, periodontal, or radiograph tools described below. Those tools remain limited to authorised users on supported web or iOS surfaces and are not part of the Android data flows covered by the Google Play declarations.

    The Android apps do retain the VoiceStack operational call data and lab-invoice extraction described below. The Android Practice app also retains the supplier-invoice and stock-order extraction described below. These retained workflows support call follow-up, stock management and accounting administration; DentalReady does not use them to calculate clinical urgency, diagnose a patient, or recommend treatment.

    • Candidate screening and training review: candidate chat transcripts, screening answers, assessment notes, and training-review responses may be processed by Google Gemini or Google Vertex AI.
    • Morning huddle and clinical workflow summaries: where a practice has enabled huddle features, patient names, appointment details, medical alerts, treatment context, recall status, and provider schedule data may be processed by Google Vertex AI, including Gemini and Anthropic Claude models available through Vertex. Anthropic's direct API may be used as a fallback if the Vertex route is unavailable.
    • Tooth-condition photo classification: uploaded tooth-condition photos, condition options, and generated labels may be processed by Google Vertex AI/Gemini Vision.
    • Periodontal and radiograph analysis: when an authorised clinician chooses these tools, periodontal-chart screenshots or dental radiographs, together with the patient age, risk factors, measurements, prior-chart context, and other clinician-entered patient context supplied for that analysis, are processed by Google Vertex AI/Gemini Vision. The service returns structured periodontal stage, grade, findings, confidence and decision-support summaries. These outputs are not a final diagnosis and must be independently reviewed by the treating clinician before they are used for patient care.
    • Front-desk assistance and patient recaps: on supported non-Android surfaces, authorised practice users may choose tools that process patient identity and contact details, reported symptoms, pain scores, appointment and treatment context, manual staff notes, and relevant practice-record facts through Google Vertex AI/Gemini. The tools return staff-reviewable urgency or next-action suggestions, communication drafts, and patient-recap drafts. They do not replace professional clinical judgement, and a practice user must review every output before it is used or sent.
    • VoiceStack operational call intelligence: where a practice connects VoiceStack, the provider may supply call summaries, transcript excerpts, sentiment, follow-up cues, treatment categories, and conversion probability together with caller, patient, and call metadata. DentalReady stores these fields for authorised follow-up, may match a call to an existing practice patient record during backend ingestion, and may use conversion probability to rank marketing opportunities. The Android apps display this stored operational information; they do not use it to generate clinical urgency, diagnosis, or treatment advice.
    • Supplier-invoice and stock-order extraction: when an authorised Practice app user selects a supplier invoice or order-confirmation photo or PDF, the full selected file and selected supplier name are sent through a DentalReady Supabase function to Google Vertex AI/Gemini. The service may extract supplier, invoice/order, date, product or SKU, quantity, unit and line price, subtotal, discounts or credits, freight or fees, tax and total. The user reviews and matches the extracted lines before completing the import. A completed import retains the selected file and the reviewed fields needed for stock, order, invoice and price-history records; other extracted fields are processed only for review and are not necessarily saved.
    • Lab-invoice extraction: when an authorised user selects a lab-invoice photo or PDF, the full selected file is sent through a DentalReady Supabase function to Google Vertex AI/Gemini. The service extracts accounting fields and may extract a patient name or initials, case or job reference, and tooth or shade reference when those details appear on the invoice. The user is shown the extracted fields for review before saving them.
    • Financial improvement planning: when an authorised practice owner asks DentalReady to draft action ideas, a limited set of aggregate financial metrics, reporting dates, data-quality indicators, and owner-entered target candidates may be processed by Google Vertex AI/Gemini. Raw Xero reports, transactions, account or vendor names, bank details, patient information, and staff identities are excluded from this AI request.
    • Bug reports: report text, page URL, browser and app metadata, clarifying answers, and any screenshot you choose to attach may be processed by Google Vertex AI/Gemini to classify and summarise the report. Submitted bug reports may also be mirrored to Trello for operational triage.
    • Practice assistant tools: SOP drafts, library uploads, meeting notes, migration files, dashboard insight inputs, clinician coaching inputs, and stock-management prompts or search queries may be processed by Google Vertex AI, including Gemini and Anthropic Claude models where appropriate.
    • Audio transcription: consented SOP and library voice notes, meeting recordings made after confirmation that all participants consented, and consented performance-review recordings, together with the minimum workflow context needed to interpret them, may be processed by Google Vertex AI/Gemini to create transcripts, summaries, or draft operational content.

    We do not use these AI processors to sell personal information. Outputs are returned to DentalReady and shown only to authorised users for the relevant practice or workflow.

    6. Data Storage and Security

    Your data is stored on servers managed by Supabase. We use encryption in transit (TLS) and at rest. Access to personal data is restricted through role-based access controls and row-level security policies. On Android, persisted sign-in session credentials are encrypted with AES-GCM using keys held by the Android Keystore and are excluded from device backups.

    7. Data Retention and Deletion

    We retain your data for as long as your account is active or as needed to provide our services. Practice-controlled operational, employment, financial, and clinical records may remain available to the relevant practice for its lawful business, patient-care, and record-keeping obligations after an individual user account closes. Audio, transcripts, uploaded files, and AI outputs are retained with the related practice workflow until an authorised user deletes them, the practice account is deleted, or a different legal or contractual retention requirement applies. You can request deletion of your account and associated personal data at any time by contacting us. We will action a valid request within 30 days, except where the relevant practice or DentalReady is required by law to retain the information.

    8. Your Rights

    Under the Australian Privacy Act 1988, you have the right to:

    • Access the personal information we hold about you
    • Request correction of inaccurate information
    • Request deletion of your personal information
    • Complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached your privacy

    9. Third-Party Services

    When you use Google or Facebook to sign in, those providers may collect data according to their own privacy policies. We encourage you to review their policies. We only receive the minimum information needed (name and email) to create your account.

    10. Changes to This Policy

    We may update this policy from time to time. We will notify you of significant changes by posting a notice on our platform. Continued use of DentalReady after changes constitutes acceptance of the updated policy.

    11. Contact Us

    If you have questions about this privacy policy or want to exercise your rights, contact us at:

    Email: privacy@dentalready.com.au