1. Scope and Purpose
This Privacy Policy (the "Policy") concerns personal data processed through the website at dentexa.co, the Dentexa AI dashboard and the Dentexa AI WhatsApp AI assistant (the "Service"), operated by Farvex Labs LLC ("Dentexa AI", "we").
The Policy covers (i) dental clinics subscribing to the Service and their authorised users (the "Clinic", "Subscriber"), (ii) patients and prospective patients who contact the Dentexa AI assistant through the Clinic's WhatsApp line (the "End User"), and (iii) all visitors to our website.
Health data notice
By its nature, the Service mediates messages that may contain information about dental health. Health data constitutes a "special category of personal data" under Article 6 of the KVKK and Article 9 of the GDPR and is subject to a separate, stricter protection regime. We recommend reading sections 5 and 6 of this Policy carefully.
2. Data Controller and Our Roles
Dentexa AI acts in two distinct legal capacities depending on the data category. This distinction matters because it determines which party bears which obligation.
| Data category | Our role | Explanation |
|---|---|---|
| Subscriber (clinic) account, billing and usage data | Controller | We determine the purposes and means; obligations of transparency and security rest directly with us. |
| End User (patient) messages, appointment and health information | Processor | We process such data solely on the Clinic's documented instructions and for the purposes it determines. The Clinic is the controller. |
| Visitor and cookie data | Controller | Processed for the operation and security of our website. |
- Legal name
- Farvex Labs LLC
- Address
- 30 N Gould St #57914, Sheridan, WY 82801, Sheridan, Wyoming, United States
- Privacy requests
- support@dentexa.co
- Data protection contact (GDPR)
- support@dentexa.co
Responsibility reminder for clinics
As controller, the Clinic is responsible for informing its patients, obtaining explicit consent where required, and entering into a Data Processing Agreement (DPA) with us. We provide ready-to-use privacy notice, consent and DPA templates to facilitate these obligations.
3. Personal Data We Process
The table below shows the categories of data we process and their source. We process only what is necessary to provide the Service (data minimisation).
| Category | Example data | Source |
|---|---|---|
| Identity and contact | Name, email address, phone number, clinic name, authorised contact | Directly from you (sign-up form) |
| Account and authorisation | Hashed password, session and authentication records, team member roles, invitations | From you / automatic |
| Clinic content | Documents uploaded to the Knowledge Base (treatment and price lists, FAQs, opening hours), assistant behaviour settings | Directly from you |
| End User (patient) data | WhatsApp phone number, profile name, message contents, media, conversation timestamps | From the End User via WhatsApp Business Platform |
| Health data (special category) | Complaints, symptoms, treatment requests or treatment history voluntarily shared by the End User | From the End User |
| Appointment data | Appointment date and time, treatment type, status, approval state, calendar/PMS record identifier | Derived from conversation / Google Calendar / practice management software (PMS) |
| Payment and subscription | Subscription plan, invoice identifier, payment status, subscription period | Stripe (payment provider) |
| Technical and usage | IP address, browser and device information, page views, error and audit logs, message quota usage | Automatically |
| Cookie data | Session identifier, language and theme preference | Automatically (see Cookie Policy) |
We do not process card details
Payment instrument data such as card number, expiry date and CVV never reaches Dentexa AI servers. Payments are processed by our payment service provider Stripe, Inc. on PCI-DSS Level 1 compliant infrastructure.
Practice management software (PMS) integration
If the Clinic chooses to connect a practice management system such as Open Dental or Dentally, ONLY appointments APPROVED by clinic staff are written to that system. The data transferred is limited to the minimum required to create the appointment (name, contact number, appointment date/time and reason); conversation history, health notes and knowledge base content are not transferred. The connection is established by the Clinic and can be removed at any time from the settings screen. These systems are governed by the agreement between the Clinic and the relevant provider.
4. Purposes and Legal Bases
Every processing activity rests on a specific legal basis. Our bases under Article 5 KVKK and Article 6 GDPR are set out below:
| Purpose | KVKK basis | GDPR basis |
|---|---|---|
| Account creation, provision of the Service, subscription management | Art. 5(2)(c) — performance of a contract | Art. 6(1)(b) — performance of a contract |
| Invoicing, collection and keeping financial records | Art. 5(2)(a) and (ç) — legal obligation | Art. 6(1)(c) — legal obligation |
| AI assistant generating responses to patient messages | On the Clinic's instruction; explicit consent under Art. 6(2) at Clinic level | Art. 6(1)(b) and Art. 9(2)(a) — explicit consent |
| Creating appointments and calendar synchronisation | Art. 5(2)(c) — performance of a contract | Art. 6(1)(b) — performance of a contract |
| Service security, abuse and fraud prevention, audit logs | Art. 5(2)(f) — legitimate interest | Art. 6(1)(f) — legitimate interest |
| Measuring service quality, statistics and product development (aggregated) | Art. 5(2)(f) — legitimate interest | Art. 6(1)(f) — legitimate interest |
| Handling support requests and communication | Art. 5(2)(c) — performance of a contract | Art. 6(1)(b) — performance of a contract |
| Marketing and commercial electronic messages | Art. 5(1) — explicit consent (incl. Law No. 6563 and IYS registration) | Art. 6(1)(a) — consent |
| Exercising the right of defence in legal disputes | Art. 5(2)(e) — establishment or protection of a right | Art. 6(1)(f) — legitimate interest |
Legitimate interest balancing
For every processing based on legitimate interest we perform a balancing test confirming that our interest does not override the fundamental rights and freedoms of the data subject. A summary of that assessment is available on request.
5. Special Category Health Data
When a patient sends a message such as "my tooth hurts" or "I would like an implant", the content may qualify as health data. Additional safeguards we apply to such data include:
- Conversations containing health data are visible only to authorised users of the relevant Clinic and are technically isolated from other clinics through tenant-based row level security policies.
- TLS 1.2+ in transit and encryption at rest for storage.
- Health data is never used for marketing, never sold and never shared with advertising networks.
- A redaction layer masks direct identifiers such as national ID numbers, card numbers, emails and phone numbers before any text is sent to the AI provider.
- Staff with access to health data sign perpetual confidentiality undertakings and their access is recorded in audit logs.
- Access rights follow the need-to-know principle, in line with the adequate measures prescribed by the Turkish Data Protection Board for special categories of data.
We do not provide diagnosis or treatment
Dentexa AI is not a medical device or a healthcare provider. The assistant does not diagnose, prescribe or give medical advice; it only provides information based on what the Clinic supplies and directs patients to appointments. In an emergency, call your local emergency number.
6. Use of Artificial Intelligence and Automated Decisions
The Service uses large language model (LLM) infrastructure to generate responses to patient messages. In the interest of transparency, we explain how this works:
- 1The patient's message reaches our system via the WhatsApp Business Platform.
- 2The redaction layer detects direct identifiers and removes or pseudonymises them before the text is sent to the model.
- 3The message is passed to the model provider together with relevant excerpts retrieved from the Clinic's Knowledge Base.
- 4The generated answer is enriched where needed with the appointment tool (Google Calendar) and delivered to the patient.
- 5The conversation record is stored in the Clinic's dashboard for review.
- Your data is not used to train third-party AI models. We rely on contractual arrangements with our model providers prohibiting the use of submitted data for training.
- The assistant does not take fully automated decisions producing legal or similarly significant effects (Art. 22 GDPR). All final treatment decisions are made by a dentist.
- A patient may at any time request to be transferred to a human; the Clinic can take over the conversation.
- AI output may contain errors. Prices, availability and treatment information should be confirmed by the Clinic.
7. Data Transfers
We do not sell your personal data. Data is transferred only in the following cases and limited to the purpose:
- To service providers strictly necessary to deliver the Service (sub-processor list below),
- To team members and integrations authorised by the Subscriber,
- To competent public authorities, courts or administrative bodies where legally required,
- To our lawyers and accountants for the establishment, exercise or defence of legal claims,
- To an acquirer in the event of a merger, transfer or acquisition (you will be informed in advance).
International transfers: some of our providers are established outside Türkiye. Transfers abroad are carried out primarily on the basis of the standard contracts or undertakings published by the Turkish Data Protection Board and, where these are unavailable, on the explicit consent of the data subject. For EU-originating data we rely on the European Commission's Standard Contractual Clauses (SCCs) together with supplementary technical measures where necessary.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication and file storage | UK (London) |
| Meta Platforms, Inc. (WhatsApp Business Platform) | Message delivery over WhatsApp | USA / EU |
| OpenRouter, Inc. ve bağlı model sağlayıcıları | Generation of AI (LLM) responses | USA |
| Google LLC (Google Calendar API) | Appointment calendar synchronization | EU / USA |
| Open Dental Software, Inc. (yalnızca bu PMS'i bağlayan klinikler için) | Writing the approved appointment into the practice management software | USA |
| Dentally Ltd. (yalnızca bu PMS'i bağlayan klinikler için) | Writing the approved appointment into the practice management software | United Kingdom / EU |
| DodoPayments Ltd. | Payment processing and subscription management | United Kingdom |
| Railway Inc. | Application hosting and infrastructure | USA / EU |
Changes to the sub-processor list are published on this page. Subscribers may object to a new sub-processor on reasonable grounds within the period set out in the agreement.
8. Retention and Erasure
We retain personal data for as long as the processing purpose requires and for the minimum periods prescribed by law. Once the period expires, data is deleted, destroyed or anonymised in accordance with our Retention and Destruction Policy.
| Data type | Retention period | Basis |
|---|---|---|
| Account and profile data | For the subscription term and 10 years thereafter | General statute of limitations |
| Conversation and message records | 24 months by default; the Subscriber may set a shorter period | Contractual necessity / Subscriber instruction |
| Conversations containing health data | Period set by the Subscriber; 24 months absent instruction | Controller instruction of the Clinic |
| Appointment records | 24 months from the appointment date | Contractual necessity |
| Invoices and financial records | 10 years | Tax and commercial law |
| Audit and security logs | 12 months | Legitimate interest / information security |
| Cookie data | Session to 12 months depending on cookie type | See Cookie Policy |
| Marketing consents | Until withdrawn; 3 years thereafter for evidentiary purposes | Electronic communications legislation |
You may export your data for 30 days after your subscription ends. After that period, data belonging to your account is deleted, subject to the statutory retention obligations above. Deletion from backups is completed within 90 days at the latest.
9. Security Measures
We implement appropriate technical and organisational measures pursuant to Article 12 KVKK and Article 32 GDPR:
- TLS 1.2+ encryption in transit; encryption at rest for database and file storage.
- Tenant-based Row Level Security isolating data between clinics.
- Role-based access control and least-privilege principle, with separate permission levels for team members.
- Passwords stored using one-way, salted hash functions.
- Signature verification on WhatsApp webhooks; signature and replay protection on payment webhooks.
- Monitoring of access and change events through audit logs.
- Regular encrypted backups and restore drills.
- Confidentiality undertakings and data protection awareness training for staff.
- KVKK- and GDPR-compliant data processing agreements with all sub-processors.
Breach notification
If we detect a personal data breach we notify the Turkish Data Protection Board within 72 hours and inform affected individuals as soon as reasonably possible. Where we act as processor, we notify the controlling Clinic without undue delay.
10. Your Rights
Under Article 11 KVKK and Articles 15–22 GDPR you have the right to:
- Learn whether your personal data is processed and request information about it,
- Learn the purpose of processing and whether the data is used accordingly,
- Know the third parties to whom data is transferred domestically or abroad,
- Request rectification of incomplete or inaccurate data,
- Request erasure or destruction of your data (right to be forgotten),
- Request that rectification, erasure or destruction be notified to third-party recipients,
- Object to a result adverse to you arising from analysis exclusively by automated means,
- Claim compensation for damage suffered due to unlawful processing,
- Additionally under the GDPR: restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent at any time without retroactive effect (Art. 7(3)).
How to apply: send your request by email to support@dentexa.co or in writing to "30 N Gould St #57914, Sheridan, WY 82801, Sheridan, Wyoming". Your application should state your full name, signature (for written applications), national ID or passport number, address for service, email and phone where applicable, and the subject of your request.
We conclude your request free of charge as soon as possible and within 30 days at the latest. Where the operation entails an additional cost, a fee at the tariff set by the Board may apply. If your request is rejected, our response is unsatisfactory or no response is given in time, you may lodge a complaint with the Turkish Data Protection Board within 30 days of becoming aware and in any case within 60 days. If you are in the EU, your right to complain to the supervisory authority of your member state is reserved.
Important note for patients
If you are a patient who reached us through a clinic's WhatsApp line, your counterparty as a rule is the clinic acting as controller. If you contact us directly, we will forward your request to the relevant clinic without delay and inform you accordingly.
12. Children's Data
The Service is not directed at persons under 18. Communication regarding the treatment of a minor should be conducted by a parent or legal guardian. We do not offer information society services directly to children under Article 8 GDPR. If we learn that a child's data has been processed without valid consent, we delete it without delay.
13. Changes to this Policy
This Policy may be revised due to legislative changes or updates to the Service. For material changes we will notify you by email and/or in-app notice at least 15 days before the effective date. The current version is always published on this page.
- Version
- 1.0
- Last updated
- 25 July 2026
- Effective date
- 25 July 2026
14. Contact
For any question or request regarding this Policy or the processing of your personal data:
- Legal name
- Farvex Labs LLC
- Address
- 30 N Gould St #57914, Sheridan, WY 82801, Sheridan, Wyoming, United States
- support@dentexa.co
- Privacy
- support@dentexa.co
- Phone
- +1 (210) 996-5020