Dentista is a patient-records application for dental clinics. This policy explains what information the application handles, why, and what rights you have under the Philippine Data Privacy Act of 2012 (RA 10173).
This distinction matters, because it determines who you should contact.
About clinic staff who use the app:
About patients. Most of this is entered by clinic staff. Some of it — contact details, health history, allergies and the consent below — is entered by patients themselves, on the clinic's own device, when it is handed to them during a visit.
Health information is sensitive personal information under RA 10173 and is treated accordingly.
Processing rests on the patient's consent, on the legitimate interests of the clinic in providing care, and on the clinic's legal and professional record-keeping obligations.
Records are stored in a managed Supabase PostgreSQL database hosted in the Singapore (ap-southeast-1) region, and are transmitted over encrypted connections. Access is restricted by role: only active staff of a clinic can read that clinic's records, and only an administrator can delete a patient. Signing in is handled by Google.
A backup of the database is taken nightly so that records can be restored if the database is lost. It is encrypted before it leaves the clinic's computer, with a passphrase held only in that computer's keychain, and the encrypted file is then stored in Dropbox.
On your own device, the application stores your sign-in session in the system Keychain and your preferences (appearance, reminder settings, whether the app lock is on). Appointment reminders are scheduled on the device and are not sent to any server.
The application also keeps a copy of your clinic's records on the device itself, so that it continues to work when the internet does not, and so that work recorded without a connection is not lost. That copy is encrypted. The key is generated on the device, held in the system Keychain, marked so that it is never copied to iCloud or to another device, and on iPhone and iPad the file cannot be read at all while the device is locked. The copy and its key are erased when you sign out. Changes made without a connection wait on the device until one returns, and are then sent to the database described above.
Records are not sold, rented, or used for advertising. The application contains no advertising and no third-party analytics or tracking.
Clinical records are kept for at least ten years from the last entry. Under Presidential Decree No. 1575, dental records are then turned over to the National Bureau of Investigation for record purposes, and the clinic may retain copies for its own files. Audit-trail entries are retained as a safeguard and are not edited or deleted.
As a data subject you have the right to:
To exercise these rights over your dental records, contact your clinic as the Personal Information Controller. You may also complain to the National Privacy Commission — privacy.gov.ph.
Records for patients under 18 are entered with the consent of a parent or guardian. A patient under 18 is not asked to consent for themselves: the application records who gave the consent and their relationship to the patient, and keeps the guardian's name with the file.
Safeguards include encrypted connections, encryption of the copy of records held on each device, role-based access controls enforced at the database, optional Face ID / Touch ID locking of the application, and a tamper-proof audit trail. No system is perfectly secure; if a breach affecting sensitive personal information occurs, affected data subjects and the National Privacy Commission will be notified as RA 10173 requires.
If this policy changes, the date at the top will be updated.
Dentista — operated by Dustin Escueta
Data Protection Officer: Dustin Escueta
Email: hello.dentista@clinicaide.app
Patients of a clinic using Dentista should contact their own clinic directly about their records; that clinic is the Personal Information Controller.