SMILE EDITOR โ PRIVACY POLICY
Effective Date: [EFFECTIVE DATE]
Last Revised: 10 August 2026
This Privacy Policy explains how [LEGAL ENTITY NAME], doing business as Smile Editor ("Smile Editor", "we", "us", "our"), collects, uses, discloses and protects personal information when you use our website, application and related services.
This Policy addresses Smile Editor's own processing as a controller/business and explains how patient-related data is handled when Smile Editor acts as a processor/service provider on behalf of professional customers.
1. Roles
1.1 Smile Editor as Controller / Business
Smile Editor generally determines the purposes and means of processing for:
- account registration;
- authentication and security;
- subscriptions and billing records;
- customer support;
- service communications;
- website analytics and marketing, subject to applicable consent requirements;
- fraud prevention and legal compliance.
1.2 Smile Editor as Processor / Service Provider
When a dentist, clinic, laboratory or other professional customer uploads or processes Patient Data for its own professional purposes, the Customer generally determines the purpose of that processing and Smile Editor acts as processor/operator/service provider on the Customer's behalf, subject to the DPA.
2. Categories of Information
2.1 Account and Professional Data
We may collect:
- name;
- professional role and organization;
- email and telephone;
- authentication identifiers;
- billing and subscription information;
- support communications;
- account preferences.
Payment card information should be processed by our payment provider and not stored by Smile Editor except where technically necessary and lawfully configured.
2.2 Technical and Security Data
We may collect:
- IP address;
- device and browser information;
- login timestamps;
- session identifiers;
- security events;
- feature usage;
- crash and error information;
- approximate location derived from IP where used for security or localization.
2.3 Customer and Patient Data
Depending on enabled features, Customer Data may include:
- patient reference identifiers;
- patient name if Customer chooses to provide it;
- STL, OBJ, PLY and similar 3D files;
- intraoral scans;
- photographs;
- facial images;
- DICOM or radiographic information where supported;
- case details and clinical notes;
- digital designs, restorations and derived files;
- other dental or health-related information submitted by Customer.
Patient Data may constitute sensitive personal data, health data, special category data or PHI depending on jurisdiction and context.
2.4 AI Interaction Data
Where AI Features are enabled, Smile Editor may process:
- prompts or instructions;
- selected files or images;
- generated outputs;
- model/version metadata;
- safety and quality logs.
Patient Data is not used to train generalized AI models under the Smile Editor v1.0 AI policy.
3. Data Minimization
Smile Editor is designed to avoid collecting patient identifiers that are not necessary for the requested workflow. Where practical, Customers should use internal patient references rather than full identity information.
Fields such as government IDs, home addresses, insurance numbers and unrelated medical history should not be uploaded unless a specific feature lawfully requires them.
4. Purposes and Legal Bases
Where Smile Editor acts as controller, we process information for:
- Service delivery โ contract / pre-contractual steps;
- Security and fraud prevention โ legitimate interests and/or legal obligation;
- Billing and accounting โ contract and legal obligation;
- Support and operational communications โ contract / legitimate interests;
- Product analytics โ legitimate interests or consent where required;
- Marketing โ consent or other lawful basis permitted locally;
- Compliance and disputes โ legal obligation / legitimate interests;
- Consent-based features โ consent where applicable.
For EEA/UK users, Article 6 GDPR legal bases are applied as appropriate. Special category Patient Data processed on behalf of professional Customers is primarily governed by the Customer's lawful basis and the DPA. Smile Editor does not assume that consent is always the only lawful basis for healthcare processing.
5. How We Use Patient Data
When acting as processor, Smile Editor uses Patient Data only:
- to provide requested CAD, visualization, storage, collaboration or related features;
- to secure, troubleshoot and support the Service;
- as documented by Customer;
- to comply with law;
- as otherwise permitted by the DPA.
Patient Data is not sold. Patient Data is not used for targeted advertising. Patient Data is not used to train generalized AI models under the v1.0 policy.
6. Local Processing and Cloud Processing
Some Smile Editor functions may process files locally in the browser or device without transmitting the file to Smile Editor servers. Other functions may require cloud processing, synchronization or storage.
The user interface should identify material cloud processing where it is not obvious. If "local-only" processing is represented, Smile Editor must ensure the relevant file is not transmitted to its servers or third-party services.
7. Cookies, Analytics and Advertising
We may use:
- necessary cookies for authentication, security and sessions;
- functional cookies for preferences;
- analytics cookies or SDKs where lawful;
- marketing technologies on public marketing pages only where lawful and consented.
Advertising pixels and unnecessary session-replay tools must not be deployed on authenticated clinical pages that may expose Patient Data.
See the Cookie Notice for more information.
8. Sharing
We may share personal information with:
- infrastructure and hosting providers;
- database and storage providers;
- payment providers;
- authentication services;
- transactional email providers;
- security and monitoring providers;
- analytics providers;
- AI providers when an AI Feature is used and legally permitted;
- professional advisers;
- authorities where lawfully required;
- acquirers in a corporate transaction subject to appropriate safeguards.
Material processors are listed in the Subprocessors page.
9. Subprocessors
When Smile Editor acts as processor, subprocessors may process Customer Data only under written terms imposing appropriate privacy and security obligations.
Where required, Customers will receive notice of material new subprocessors and an opportunity to object in accordance with the DPA.
10. International Transfers
Personal information may be processed outside the country where it originated.
Where GDPR, UK GDPR, LGPD or another law requires transfer safeguards, Smile Editor will use lawful mechanisms as applicable, which may include:
- adequacy decisions;
- Standard Contractual Clauses;
- UK transfer mechanisms;
- contractual safeguards under Brazilian law;
- other legally recognized transfer mechanisms.
The exact transfer mechanism depends on the entities, regions and subprocessors actually used.
11. Data Retention
We retain personal information only as long as reasonably necessary for stated purposes, contractual commitments, security, dispute resolution and legal obligations.
Patient Data processed on behalf of Customer is retained according to the DPA, Customer configuration and Data Retention & Deletion Policy.
Where data remains in backups after active deletion, it must be isolated from ordinary use and expire according to the documented backup cycle.
12. Security
Smile Editor implements and maintains technical and organizational measures appropriate to risk. Only measures that have actually been implemented may be represented publicly.
Target controls include:
- encryption in transit and at rest;
- tenant isolation;
- role-based access;
- row-level security where applicable;
- private object storage;
- signed, expiring URLs;
- multi-factor authentication for privileged access;
- audit logging;
- vulnerability management;
- secure backups and restoration procedures;
- incident response;
- staff confidentiality and least privilege.
See the Security Measures / TOMs document.
13. Privacy Rights
Depending on jurisdiction, individuals may have rights to:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability;
- withdraw consent;
- information about processing;
- challenge certain automated decisions;
- complain to a regulator.
Requests may be submitted to [PRIVACY EMAIL] or through [PRIVACY REQUEST URL].
Patient requests
If a patient contacts Smile Editor about Patient Data that we process for a Customer, Smile Editor will generally direct or relay the request to the relevant Customer/Controller and assist that Customer under the DPA, unless law requires Smile Editor to act directly.
14. Brazil โ LGPD
Where the Brazilian General Data Protection Law (LGPD) applies, data subjects may exercise rights provided by applicable Brazilian law. Smile Editor will identify its role as Controller or Operator according to the processing context and will provide contact details for the responsible privacy function / Encarregado where required.
International transfers involving Brazilian personal data will be handled using mechanisms permitted by applicable Brazilian law and regulation.
15. EEA, UK and Switzerland
Where GDPR or UK GDPR applies:
- Smile Editor will identify the applicable controller;
- processing will rely on a lawful basis under Article 6 and, where relevant, an Article 9 condition;
- processor relationships will be governed by an Article 28-compliant DPA;
- international transfers will use applicable lawful safeguards;
- individuals may complain to their competent supervisory authority.
Contact for privacy matters: [PRIVACY EMAIL].
16. United States
Applicable US state privacy rights may include rights to know/access, correct, delete, obtain portability, opt out of certain sale/sharing or targeted advertising, and limit certain uses of sensitive personal information.
Smile Editor does not sell Patient Data and does not use Patient Data for targeted advertising.
Where HIPAA applies to Smile Editor's processing as a Business Associate, the applicable BAA governs PHI to the extent required by HIPAA.
17. Canada
Where Canadian private-sector privacy law applies, Smile Editor follows principles of accountability, identified purposes, appropriate consent where required, collection limitation, limited use/disclosure/retention, accuracy, safeguards, openness, individual access and complaint handling.
The applicable Canadian statute may vary by province and context.
18. Minors
Smile Editor user accounts are intended for adults and authorized professionals. However, professional Customers may lawfully process Patient Data relating to minors in pediatric or other dental care.
Customer is responsible for the legal authority, notices and consents required for minor Patient Data. Smile Editor handles such data under the same heightened Patient Data protections.
19. Automated Decision-Making
Smile Editor does not intend AI or automated outputs to replace professional clinical judgment. Where applicable law grants rights regarding solely automated decisions with legal or similarly significant effects, Smile Editor will support appropriate review mechanisms for processing under its control and assist Customers when acting as processor.
20. Corporate Transactions and Legal Requests
Data may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization or sale of assets, subject to applicable law and appropriate confidentiality/data protection measures.
We may disclose information in response to valid legal process or where necessary to protect rights, safety or security.
21. Changes
Material changes to this Policy will be communicated by reasonable means. Where required, Smile Editor will request renewed consent or acceptance.
22. Contact
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
Privacy: [PRIVACY EMAIL]
DPO/Privacy Officer: [DPO/PRIVACY OFFICER]
Support: [SUPPORT EMAIL]