Privacy Policy
Last updated: August 31, 2026
1. Who we are
dentAI is AI-powered dental practice management software. This policy explains what personal data is collected through the dentai.gr website and through the dentAI app used by client dental practices, how it is used, who it is shared with, and what rights you have.
Data controller: Rea Lytra, sole proprietorship trading as "dentAI", based in Athens, Greece. Contact: pol@dentai.gr.
2. Two different roles
With respect to website visitors of dentai.gr (the "Book a demo" form, the demo chat widget), dentAI is the data controller.
With respect to patient data inside a specific client practice's app instance, the practice itself is the data controller. dentAI acts as a data processor on its behalf, under a data processing agreement (DPA). For a request about your own data as a patient, please contact your practice first.
3. Data from the dentai.gr website
- "Book a demo" form: full name, phone number, optionally email. Used only so we can contact you about the demo.
- Demo chat widget: conversations happen with a demo AI assistant. No account is required; a random session identifier is stored locally on your device (localStorage) so it can remember the conversation — not for tracking or advertising.
- We do not use third-party cookies for advertising or visitor tracking on the website.
- IP address is kept temporarily only to prevent abuse of the form (rate limiting), not stored long-term.
4. Data inside the dentAI app
We process the following on behalf of client practices, depending on what each practice has enabled:
- Patient details: full name, phone, email, appointment history, dental chart/clinical notes, X-rays if uploaded.
- Phone/AI assistant and SMS: the content of calls and messages related to booking or reminding appointments.
- Visit recording (where a practice has enabled ambient documentation): audio of the visit, only with the patient's explicit consent, automatically deleted once the doctor signs the clinical note.
- Google Calendar sync: see §5.
- The practice's own website/ads analytics (Google Analytics/Ads), if the practice connects its own account — dentAI displays the data, it doesn't collect it itself.
5. Google data (Calendar)
When a doctor connects their personal Google Calendar from the app's Settings:
- We request read access (
calendar.readonly) to detect times already booked on the doctor's calendar, and write access (calendar.events) only if the doctor chooses to have dentAI appointments recorded there. - For each booked time, we store the event's title, time, location, and notes, so the doctor can see with one click why a time is blocked, not just that it is. This data is transient: it is replaced on every sync and deleted immediately on disconnect - we never keep anything beyond what Google Calendar itself shows at that moment.
- Calendar data is used solely to avoid double-bookings and keep appointments in sync. It is never used for advertising, never sold to third parties, and never used to train general-purpose AI models.
- Access tokens are stored on our server, not in the browser.
- The connection can be revoked at any time from the app's Settings ("Disconnect"), which immediately revokes the token with Google as well.
6. Providers who process data on our behalf
| Provider | Purpose |
|---|---|
| Hostinger | Hosting and database (EU) |
| Calendar sync, reading a practice's own Google Analytics/Ads | |
| Anthropic (Claude) | AI assistant (chat / front-desk) |
| OpenAI | Voice phone agent and audio-to-text transcription |
| Yuboto / Twilio / Routee / Telnyx | Sending and receiving SMS, depending on each practice's configuration |
| Brevo | Sending notification emails |
| VAPI | Outbound reminder/recall calls, where enabled |
Some of these providers process data outside the European Union (e.g. the US), under standard contractual clauses or equivalent safeguards of their own.
7. Data retention
- Visit recordings: automatically deleted after the clinical note is signed.
- Calendar data (busy slots): transient, replaced on every sync.
- Patient details: for as long as the practice's relationship with dentAI lasts, in line with the medical record-keeping obligations that apply to the practice itself.
- Website leads (demo form): deleted within a reasonable period after we've been in contact.
8. Security
Encrypted connections (HTTPS) on all pages, data separated per practice, access tokens stored server-side only, backups taken before any change to the system.
9. Your rights
You have the right to access, rectify, erase, restrict, port, and object to the processing of your data (GDPR Articles 15-21).
If this concerns your data as a patient of a practice, please contact that practice first. If this concerns your data as a website visitor, write to pol@dentai.gr.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority.
10. Changes to this policy
We will update this page whenever how we process data changes materially. The date at the top shows the last update.
11. Contact
For any privacy question: pol@dentai.gr