Privacy Policy

Dentexa AI processes your personal data in accordance with the Turkish Personal Data Protection Law No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR). This policy explains what data we process, why, on which legal basis, and what rights you have.

Last updated: 25 July 2026Version 1.0Effective: 25 July 2026

1. Scope and Purpose

This Privacy Policy (the "Policy") concerns personal data processed through the website at dentexa.co, the Dentexa AI dashboard and the Dentexa AI WhatsApp AI assistant (the "Service"), operated by Farvex Labs LLC ("Dentexa AI", "we").

The Policy covers (i) dental clinics subscribing to the Service and their authorised users (the "Clinic", "Subscriber"), (ii) patients and prospective patients who contact the Dentexa AI assistant through the Clinic's WhatsApp line (the "End User"), and (iii) all visitors to our website.

Health data notice

By its nature, the Service mediates messages that may contain information about dental health. Health data constitutes a "special category of personal data" under Article 6 of the KVKK and Article 9 of the GDPR and is subject to a separate, stricter protection regime. We recommend reading sections 5 and 6 of this Policy carefully.

2. Data Controller and Our Roles

Dentexa AI acts in two distinct legal capacities depending on the data category. This distinction matters because it determines which party bears which obligation.

Data categoryOur roleExplanation
Subscriber (clinic) account, billing and usage dataControllerWe determine the purposes and means; obligations of transparency and security rest directly with us.
End User (patient) messages, appointment and health informationProcessorWe process such data solely on the Clinic's documented instructions and for the purposes it determines. The Clinic is the controller.
Visitor and cookie dataControllerProcessed for the operation and security of our website.
Legal name
Farvex Labs LLC
Address
30 N Gould St #57914, Sheridan, WY 82801, Sheridan, Wyoming, United States
Privacy requests
support@dentexa.co
Data protection contact (GDPR)
support@dentexa.co

Responsibility reminder for clinics

As controller, the Clinic is responsible for informing its patients, obtaining explicit consent where required, and entering into a Data Processing Agreement (DPA) with us. We provide ready-to-use privacy notice, consent and DPA templates to facilitate these obligations.

3. Personal Data We Process

The table below shows the categories of data we process and their source. We process only what is necessary to provide the Service (data minimisation).

CategoryExample dataSource
Identity and contactName, email address, phone number, clinic name, authorised contactDirectly from you (sign-up form)
Account and authorisationHashed password, session and authentication records, team member roles, invitationsFrom you / automatic
Clinic contentDocuments uploaded to the Knowledge Base (treatment and price lists, FAQs, opening hours), assistant behaviour settingsDirectly from you
End User (patient) dataWhatsApp phone number, profile name, message contents, media, conversation timestampsFrom the End User via WhatsApp Business Platform
Health data (special category)Complaints, symptoms, treatment requests or treatment history voluntarily shared by the End UserFrom the End User
Appointment dataAppointment date and time, treatment type, status, approval state, calendar/PMS record identifierDerived from conversation / Google Calendar / practice management software (PMS)
Payment and subscriptionSubscription plan, invoice identifier, payment status, subscription periodStripe (payment provider)
Technical and usageIP address, browser and device information, page views, error and audit logs, message quota usageAutomatically
Cookie dataSession identifier, language and theme preferenceAutomatically (see Cookie Policy)

We do not process card details

Payment instrument data such as card number, expiry date and CVV never reaches Dentexa AI servers. Payments are processed by our payment service provider Stripe, Inc. on PCI-DSS Level 1 compliant infrastructure.

Practice management software (PMS) integration

If the Clinic chooses to connect a practice management system such as Open Dental or Dentally, ONLY appointments APPROVED by clinic staff are written to that system. The data transferred is limited to the minimum required to create the appointment (name, contact number, appointment date/time and reason); conversation history, health notes and knowledge base content are not transferred. The connection is established by the Clinic and can be removed at any time from the settings screen. These systems are governed by the agreement between the Clinic and the relevant provider.

4. Purposes and Legal Bases

Every processing activity rests on a specific legal basis. Our bases under Article 5 KVKK and Article 6 GDPR are set out below:

PurposeKVKK basisGDPR basis
Account creation, provision of the Service, subscription managementArt. 5(2)(c) — performance of a contractArt. 6(1)(b) — performance of a contract
Invoicing, collection and keeping financial recordsArt. 5(2)(a) and (ç) — legal obligationArt. 6(1)(c) — legal obligation
AI assistant generating responses to patient messagesOn the Clinic's instruction; explicit consent under Art. 6(2) at Clinic levelArt. 6(1)(b) and Art. 9(2)(a) — explicit consent
Creating appointments and calendar synchronisationArt. 5(2)(c) — performance of a contractArt. 6(1)(b) — performance of a contract
Service security, abuse and fraud prevention, audit logsArt. 5(2)(f) — legitimate interestArt. 6(1)(f) — legitimate interest
Measuring service quality, statistics and product development (aggregated)Art. 5(2)(f) — legitimate interestArt. 6(1)(f) — legitimate interest
Handling support requests and communicationArt. 5(2)(c) — performance of a contractArt. 6(1)(b) — performance of a contract
Marketing and commercial electronic messagesArt. 5(1) — explicit consent (incl. Law No. 6563 and IYS registration)Art. 6(1)(a) — consent
Exercising the right of defence in legal disputesArt. 5(2)(e) — establishment or protection of a rightArt. 6(1)(f) — legitimate interest

Legitimate interest balancing

For every processing based on legitimate interest we perform a balancing test confirming that our interest does not override the fundamental rights and freedoms of the data subject. A summary of that assessment is available on request.

5. Special Category Health Data

When a patient sends a message such as "my tooth hurts" or "I would like an implant", the content may qualify as health data. Additional safeguards we apply to such data include:

  • Conversations containing health data are visible only to authorised users of the relevant Clinic and are technically isolated from other clinics through tenant-based row level security policies.
  • TLS 1.2+ in transit and encryption at rest for storage.
  • Health data is never used for marketing, never sold and never shared with advertising networks.
  • A redaction layer masks direct identifiers such as national ID numbers, card numbers, emails and phone numbers before any text is sent to the AI provider.
  • Staff with access to health data sign perpetual confidentiality undertakings and their access is recorded in audit logs.
  • Access rights follow the need-to-know principle, in line with the adequate measures prescribed by the Turkish Data Protection Board for special categories of data.

We do not provide diagnosis or treatment

Dentexa AI is not a medical device or a healthcare provider. The assistant does not diagnose, prescribe or give medical advice; it only provides information based on what the Clinic supplies and directs patients to appointments. In an emergency, call your local emergency number.

6. Use of Artificial Intelligence and Automated Decisions

The Service uses large language model (LLM) infrastructure to generate responses to patient messages. In the interest of transparency, we explain how this works:

  1. 1The patient's message reaches our system via the WhatsApp Business Platform.
  2. 2The redaction layer detects direct identifiers and removes or pseudonymises them before the text is sent to the model.
  3. 3The message is passed to the model provider together with relevant excerpts retrieved from the Clinic's Knowledge Base.
  4. 4The generated answer is enriched where needed with the appointment tool (Google Calendar) and delivered to the patient.
  5. 5The conversation record is stored in the Clinic's dashboard for review.
  • Your data is not used to train third-party AI models. We rely on contractual arrangements with our model providers prohibiting the use of submitted data for training.
  • The assistant does not take fully automated decisions producing legal or similarly significant effects (Art. 22 GDPR). All final treatment decisions are made by a dentist.
  • A patient may at any time request to be transferred to a human; the Clinic can take over the conversation.
  • AI output may contain errors. Prices, availability and treatment information should be confirmed by the Clinic.

7. Data Transfers

We do not sell your personal data. Data is transferred only in the following cases and limited to the purpose:

  • To service providers strictly necessary to deliver the Service (sub-processor list below),
  • To team members and integrations authorised by the Subscriber,
  • To competent public authorities, courts or administrative bodies where legally required,
  • To our lawyers and accountants for the establishment, exercise or defence of legal claims,
  • To an acquirer in the event of a merger, transfer or acquisition (you will be informed in advance).

International transfers: some of our providers are established outside Türkiye. Transfers abroad are carried out primarily on the basis of the standard contracts or undertakings published by the Turkish Data Protection Board and, where these are unavailable, on the explicit consent of the data subject. For EU-originating data we rely on the European Commission's Standard Contractual Clauses (SCCs) together with supplementary technical measures where necessary.

Sub-processorPurposeLocation
Supabase Inc.Database, authentication and file storageUK (London)
Meta Platforms, Inc. (WhatsApp Business Platform)Message delivery over WhatsAppUSA / EU
OpenRouter, Inc. ve bağlı model sağlayıcılarıGeneration of AI (LLM) responsesUSA
Google LLC (Google Calendar API)Appointment calendar synchronizationEU / USA
Open Dental Software, Inc. (yalnızca bu PMS'i bağlayan klinikler için)Writing the approved appointment into the practice management softwareUSA
Dentally Ltd. (yalnızca bu PMS'i bağlayan klinikler için)Writing the approved appointment into the practice management softwareUnited Kingdom / EU
DodoPayments Ltd.Payment processing and subscription managementUnited Kingdom
Railway Inc.Application hosting and infrastructureUSA / EU

Changes to the sub-processor list are published on this page. Subscribers may object to a new sub-processor on reasonable grounds within the period set out in the agreement.

8. Retention and Erasure

We retain personal data for as long as the processing purpose requires and for the minimum periods prescribed by law. Once the period expires, data is deleted, destroyed or anonymised in accordance with our Retention and Destruction Policy.

Data typeRetention periodBasis
Account and profile dataFor the subscription term and 10 years thereafterGeneral statute of limitations
Conversation and message records24 months by default; the Subscriber may set a shorter periodContractual necessity / Subscriber instruction
Conversations containing health dataPeriod set by the Subscriber; 24 months absent instructionController instruction of the Clinic
Appointment records24 months from the appointment dateContractual necessity
Invoices and financial records10 yearsTax and commercial law
Audit and security logs12 monthsLegitimate interest / information security
Cookie dataSession to 12 months depending on cookie typeSee Cookie Policy
Marketing consentsUntil withdrawn; 3 years thereafter for evidentiary purposesElectronic communications legislation

You may export your data for 30 days after your subscription ends. After that period, data belonging to your account is deleted, subject to the statutory retention obligations above. Deletion from backups is completed within 90 days at the latest.

9. Security Measures

We implement appropriate technical and organisational measures pursuant to Article 12 KVKK and Article 32 GDPR:

  • TLS 1.2+ encryption in transit; encryption at rest for database and file storage.
  • Tenant-based Row Level Security isolating data between clinics.
  • Role-based access control and least-privilege principle, with separate permission levels for team members.
  • Passwords stored using one-way, salted hash functions.
  • Signature verification on WhatsApp webhooks; signature and replay protection on payment webhooks.
  • Monitoring of access and change events through audit logs.
  • Regular encrypted backups and restore drills.
  • Confidentiality undertakings and data protection awareness training for staff.
  • KVKK- and GDPR-compliant data processing agreements with all sub-processors.

Breach notification

If we detect a personal data breach we notify the Turkish Data Protection Board within 72 hours and inform affected individuals as soon as reasonably possible. Where we act as processor, we notify the controlling Clinic without undue delay.

10. Your Rights

Under Article 11 KVKK and Articles 15–22 GDPR you have the right to:

  • Learn whether your personal data is processed and request information about it,
  • Learn the purpose of processing and whether the data is used accordingly,
  • Know the third parties to whom data is transferred domestically or abroad,
  • Request rectification of incomplete or inaccurate data,
  • Request erasure or destruction of your data (right to be forgotten),
  • Request that rectification, erasure or destruction be notified to third-party recipients,
  • Object to a result adverse to you arising from analysis exclusively by automated means,
  • Claim compensation for damage suffered due to unlawful processing,
  • Additionally under the GDPR: restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent at any time without retroactive effect (Art. 7(3)).

How to apply: send your request by email to support@dentexa.co or in writing to "30 N Gould St #57914, Sheridan, WY 82801, Sheridan, Wyoming". Your application should state your full name, signature (for written applications), national ID or passport number, address for service, email and phone where applicable, and the subject of your request.

We conclude your request free of charge as soon as possible and within 30 days at the latest. Where the operation entails an additional cost, a fee at the tariff set by the Board may apply. If your request is rejected, our response is unsatisfactory or no response is given in time, you may lodge a complaint with the Turkish Data Protection Board within 30 days of becoming aware and in any case within 60 days. If you are in the EU, your right to complain to the supervisory authority of your member state is reserved.

Important note for patients

If you are a patient who reached us through a clinic's WhatsApp line, your counterparty as a rule is the clinic acting as controller. If you contact us directly, we will forward your request to the relevant clinic without delay and inform you accordingly.

11. Cookies

Our website uses cookies for session management, security and remembering your preferences. Non-essential cookies are only activated with your consent. See our Cookie Policy for details.

12. Children's Data

The Service is not directed at persons under 18. Communication regarding the treatment of a minor should be conducted by a parent or legal guardian. We do not offer information society services directly to children under Article 8 GDPR. If we learn that a child's data has been processed without valid consent, we delete it without delay.

13. Changes to this Policy

This Policy may be revised due to legislative changes or updates to the Service. For material changes we will notify you by email and/or in-app notice at least 15 days before the effective date. The current version is always published on this page.

Version
1.0
Last updated
25 July 2026
Effective date
25 July 2026

14. Contact

For any question or request regarding this Policy or the processing of your personal data:

Legal name
Farvex Labs LLC
Address
30 N Gould St #57914, Sheridan, WY 82801, Sheridan, Wyoming, United States
Email
support@dentexa.co
Privacy
support@dentexa.co
Phone
+1 (210) 996-5020
This document is provided for information only and does not constitute legal advice. Fields marked in brackets will be completed once the legal entity details are finalised.