Privacy Policy
Last updated August 11, 2026 · Operated by Emmanuel Alcorin Valdez (DentGeniePH)
DentGeniePH is the software a dental clinic uses to answer patients on Messenger and Instagram, take bookings, send reminders and keep dental records. This policy explains what personal data passes through it, who is answerable for that data, and what you can ask us to do about it. It is written to the Data Privacy Act of 2012 (RA 10173) and its Implementing Rules.
1. Who is answerable for your data
This matters more than it sounds, because it decides who you send a request to.
- The clinicPersonal Information Controller. Your dentist's clinic decides what to collect, treats you, and owns your dental record. Requests about your records go to them.
- DentGeniePHPersonal Information Processor. We store and move the data on the clinic's instruction. We do not sell it, and we do not use one clinic's patient data for anything outside that clinic.
Each clinic on DentGeniePH is walled off from every other clinic at the database level. A clinic cannot see, search or message another clinic's patients.
2. What we collect
If you are a patient
- Who you are — first and last name, mobile number, email, birthday, gender and address.
- Health information — medical alerts and allergies, the services you booked, visit and treatment history, prescriptions written for you, and files your clinic uploads such as X-rays, signed consent forms and clinical photos. Under RA 10173 this is sensitive personal information and we treat it as such.
- Money — invoices, payments, installment schedules, and the payment screenshot you send to confirm a reservation fee. Our assistant reads the amount off that screenshot so the clinic can credit it correctly.
- Booking behaviour — appointments kept, cancelled and missed. Repeated no-shows can require a deposit for your next booking, or move you to booking by phone only.
- Your preferences — whether you have opted out of reminders, recall and follow-up messages.
- Family links — if a parent or guardian books for you, we record that link so the right person is contacted.
If you message the clinic on Messenger or Instagram
- Your platform ID— the Page-Scoped ID or Instagram-Scoped ID Meta gives us. It is specific to that clinic's Page. It is not your Facebook or Instagram account, and it cannot be used to find your profile elsewhere.
- Your public display name — used to greet you. Until you actually book, this is held only in a short-lived session that expires on its own; it is not written to a patient record.
- The messages you send to the clinic, and the replies sent back to you, so the clinic has a history of what was agreed.
We do not read your Facebook or Instagram profile, your friends, your posts or any conversation you have with anyone other than this clinic's Page.
If you are clinic staff
- Name, email, role and login credentials, handled by our authentication provider.
- For dentists: PRC and PTR licence numbers and a signature image, because a prescription is not valid without them.
- An audit trail of changes made in the dashboard — who changed what, and when.
3. Why we process it, and on what legal ground
We process personal data to do the things the clinic hired the software to do:
- Answer your questions about services, prices, hours, HMO coverage and location.
- Take, move, confirm and cancel your appointments, and hold the slot while you pay.
- Send you booking confirmations, reminders, follow-ups and recall notices.
- Keep your dental record so the dentist treating you knows your history and allergies.
- Bill you, record payments, and issue prescriptions and receipts.
- Keep the service secure and working, and investigate problems when a message fails to send.
For ordinary personal data we rely on your consent and on the necessity of processing to carry out the booking you asked for. For sensitive personal information — anything health-related — we rely on your consent and on the ground in Section 13 of RA 10173 that permits processing for purposes of medical treatment, carried out by a medical practitioner or treatment institution under confidentiality safeguards.
Marketing-style messages — recall reminders, promos, follow-up campaigns — are separate. You can stop those at any time without affecting your treatment, and stopping them never stops your appointment confirmations.
4. The AI assistant
The clinic's replies on Messenger and Instagram are generated by a large language model. Being plain about what that means:
- The model is given your message, the recent conversation, and the clinic's own published information — services, prices, hours, accepted HMOs, address, payment methods — so it can answer accurately.
- It does not diagnose you and it does not decide your treatment. Anything clinical is decided by your dentist. Bookings still go to the clinic for approval.
- We only use model providers whose business terms bar your messages from being used to train their models.
- A staff member can take over the conversation at any point, which silences the assistant for that thread.
Not for emergencies. If you have severe bleeding, facial swelling, difficulty breathing or swallowing, or a serious injury, go to the nearest emergency room. Do not wait for a reply here.
5. Who else touches your data
We do not sell personal data and we do not share it with advertisers. We do use service providers to run the system. Each is bound to process data only on our instruction:
| Provider | What it does | Where it processes |
|---|---|---|
| Supabase | Database and encrypted file storage | Singapore |
| Vercel | Hosting for the dashboard and booking pages | Global edge network |
| DigitalOcean | Server running the assistant, reminders and notifiers | Singapore |
| Meta Platforms | Delivery of Messenger and Instagram messages | Global |
| Calendar sync, clinic document storage, email delivery | Global | |
| Resend | Transactional email delivery | Global |
| PayMongo | Online payment processing for clinics that enable it | Philippines |
| Anthropic (Claude) | Generates the assistant’s replies | United States |
Because of this, some of your data is processed outside the Philippines. We remain accountable for it under RA 10173 wherever it sits.
We will also disclose data where a law, a court or a lawful order from a government agency requires it, and to establish or defend a legal claim. We do not hand over patient data on request alone. Every request from a public authority is handled the same way:
- We check it is lawfulWe review each request against RA 10173 and the authority the requester is acting under before anything is disclosed.
- We challenge it if it is notWhere we believe a request is unlawful, overbroad or improperly issued, we contest it rather than comply, and tell the clinic concerned unless the law forbids us to.
- We give the least that answers itOnly the specific records named are disclosed — never a whole patient list, a whole clinic, or fields the request did not ask for.
- We write it downEach request, the legal basis claimed, what we disclosed and what we refused is recorded, so there is an account of it afterwards.
6. How long we keep it
- Dental recordsKept by the clinic for as long as its professional and legal obligations require. A dentist is expected to be able to produce your treatment history years after the fact, so these are not deleted on request while that duty stands.
- Chat conversationsKept while you are an active patient of the clinic, and deleted on request.
- Pre-booking sessionsIf you asked questions but never booked, that session expires and is discarded on its own.
- Financial recordsInvoices, payments and receipts are retained for the period Philippine tax regulations require.
- Delivery logsRecords of which message was sent when, kept for troubleshooting, then cleared.
When a clinic stops using DentGeniePH, it gets an export of its data and we delete our copy after the wind-down period in its contract.
7. How we protect it
- Every request is encrypted in transit, and our database provider encrypts data at rest.
- Tenant isolation is enforced in the database itself, not just in the app, so a bug in a screen cannot expose another clinic's patients.
- Clinics can narrow access further so a dentist sees only their own patients and schedule.
- X-rays, consent forms and clinical photos sit in private storage that is not publicly reachable.
- Messaging credentials are held in a secrets vault, not in the workflow files.
- Changes made in the dashboard are written to an audit trail.
If a breach occurs that is likely to seriously harm you, we will notify the affected clinic and, where required, you and the National Privacy Commission within the timeframe the law sets.
8. Your rights
RA 10173 gives you these rights over your personal data:
- Right to be informedTo know that your personal data is being collected, and why.
- Right to accessTo ask for a copy of the personal data a clinic holds about you.
- Right to rectificationTo have wrong or outdated details corrected.
- Right to erasure or blockingTo ask that your data be removed or withheld from further processing, subject to the retention rules below.
- Right to objectTo refuse processing, including reminders and recall messages, at any time.
- Right to data portabilityTo receive your data in a usable electronic format.
- Right to damagesTo be indemnified for damage caused by inaccurate, unlawfully obtained or unauthorised use of your data.
- Right to file a complaintTo bring the matter to the National Privacy Commission if you are not satisfied with how we handled it.
To use any of them, email hello@dentgenieph.com or message the clinic directly. We will acknowledge within five working days and respond within thirty days. We may need to confirm your identity first — that check protects you, not us.
To stop reminders and marketing without deleting anything, reply STOP to any message from the clinic, or tell the clinic. Booking confirmations continue.
To have data removed, see Data Deletion.
If you are not satisfied with how we handled your request, you may complain to the National Privacy Commission. Their current contact details and complaint procedure are published at privacy.gov.ph.
9. Children and dependents
Minors are booked and consented for by a parent or guardian, and the guardian is the one we message about the appointment. A minor's dental record is treated with the same protection as an adult's. If you believe a child's data was collected without a guardian's consent, contact us and we will act on it.
10. Changes to this policy
When we change this policy we update the date at the top of the page. If a change materially affects how your data is used, the clinic will tell you before it takes effect.
How to reach us
Questions, requests and complaints about personal data go to our Data Protection Officer, Emmanuel Alcorin Valdez:
- Emailhello@dentgenieph.com
- AddressQuezon City, Metro Manila, Philippines
- OperatorEmmanuel Alcorin Valdez
If your concern is about your dental records specifically, message the clinic that treated you first — they hold those records and can act on them fastest. We will help if the clinic cannot resolve it.
