PRIVACY NOTICE

How this platform handles personal and dental case information.

Effective 17 August 2026 · Version 1.0 operational draft. Diamond Smile Labs must obtain Botswana legal and privacy approval before enabling live patient-data processing.

1. Who is responsible

Diamond Smile Labs operates this platform for approved dental practices and laboratory personnel. Contact the privacy team at info@diamondsmile.dental or +267 75 933 317. The final registered controller identity, physical address and Data Protection Commission contact route must be inserted after counsel and governance review.

2. Scope and roles

This notice covers the public site and authenticated case workspace. The prescribing practice ordinarily determines why patient information is processed and remains responsible for the information it submits. Diamond Smile Labs processes that information to manufacture and deliver the prescribed laboratory work and may have separate controller obligations for billing, security, quality, legal and business records. These roles must be confirmed in the practice agreement and data-processing terms.

3. Information we process

  • Practice, user, professional-registration, contact, billing and shipping details.
  • Patient references, initials where supplied, prescribed treatment details, tooth and shade information, scans, images, models and other dental case files.
  • Case messages, approvals, production stages, quality records, remakes, shipping and payment records.
  • Authentication, device, network, audit, security-event and malware-scan data.
  • Public-site requests and strictly necessary session-cookie data.

Dental case content can reveal health information and is treated as sensitive personal data. Users must submit the minimum information necessary and should use a practice-defined patient reference instead of a full patient name.

4. Why and on what basis

Information is used to verify practices and users, perform laboratory services, communicate about cases, maintain traceability and quality, bill and receive payment, prevent fraud and malicious uploads, support users, meet legal obligations and establish or defend claims. The appropriate Botswana lawful basis—including contract, legal obligation, legitimate interest, explicit consent or another permitted basis for sensitive data—must be documented by the responsible party for each purpose before live processing.

5. Who receives information

Access is limited by practice and role. Authorized laboratory staff, the submitting practice and approved service providers may receive only the information required for their task. Anticipated providers include hosting and database infrastructure, object storage, transactional email, malware scanning, monitoring, support and professional advisers. Online payment processing is not part of this release. Diamond Smile Labs must complete contracts, security review and a current subprocessor register before those services are enabled.

6. International transfers

Some technical providers may process data outside Botswana. No patient-data transfer should begin until the destination, transfer mechanism, contractual safeguards, security measures and any required authorization or assessment have been approved under Botswana law. The final notice will identify applicable transfer safeguards.

7. Retention and deletion

Account, case, production, financial, security and support records are retained only for their documented purpose and applicable legal, clinical-quality, warranty and dispute periods, then securely deleted or anonymized. A counsel-approved retention schedule and deletion workflow are launch gates; this draft does not invent statutory periods. Backups and immutable security records may follow a controlled delayed-deletion cycle.

8. Your rights

Subject to applicable law, a person may ask for access, correction, deletion, restriction, objection, portability, consent withdrawal, or review of an automated decision. Requests can be sent to info@diamondsmile.dental. Identity and authority will be verified, and the responsible practice may need to coordinate a patient request. A person may also complain to Botswana’s competent data-protection authority; the final notice will add the verified Commission contact details.

9. Security and incidents

Controls include encrypted transport, protected sessions, role-based access, practice isolation, file quarantine, allowlisted uploads, hash verification, dedicated malware-scanner authentication, clean-only signed downloads, audit logs, security headers, rate limits and health monitoring. No system is risk-free. Suspected unauthorized access should be reported immediately by phone and email without sending patient data. Diamond Smile Labs’ incident plan must support required regulator notification without undue delay and, where feasible, within 72 hours when the statutory threshold is met.

10. Cookies, children and automated processing

The platform uses a strictly necessary secure session cookie after sign-in; optional advertising cookies are not part of this release. The service is for approved professionals, not direct use by children. A practice may submit information about a minor only where it has lawful authority and uses the minimum necessary data. The platform does not make treatment decisions; any future AI assistance must remain disabled until separately assessed and approved.

11. Changes and legal status

Material changes will be versioned and communicated through the platform. This notice explains the designed operating model but is not a certification of compliance, legal advice, or a HIPAA representation. Production acceptance must remain disabled until the documented legal and governance launch gates are signed off.