Privacy Policy

Last updated: April 10, 2026

DentalFlow dental laboratory cloud management platform (operating entity information will be announced upon company registration, hereinafter referred to as "the Platform") has established this Privacy Policy in accordance with Taiwan's Personal Data Protection Act (PDPA) and related regulations. This policy explains how we collect, process, use, and protect your personal data. It applies to all users of the Platform, including dental laboratory administrators, technicians, partner clinic personnel, and other authorized users.

1. Data We Collect

In accordance with Article 8 of the PDPA, the categories of personal data we collect are as follows:

  • Account data: Name, email address, phone number, organization name, job title
  • Authentication data: Password (stored in encrypted form), login credentials
  • Business data: Order records, order details, billing information, worker settlement records, clinic invoicing records
  • Usage logs: Login timestamps and IP addresses, feature usage records, browser type and version
  • Cookies and technical data: Session identifiers, language preferences, device information

If you do not provide the required personal data listed above, we may be unable to provide you with account registration or related service features.

2. Purposes of Data Collection

In accordance with the notification obligations under Article 8 of the PDPA, the specific purposes of data collection are:

  • Providing and operating the Platform's cloud-based dental lab management services (including order management, process tracking, worker settlement, clinic invoicing, and reporting)
  • User identity verification and account security management
  • Billing and fee collection
  • Service notifications (system announcements, maintenance notices, account change alerts)
  • Customer technical support and troubleshooting
  • Service quality improvement and usage analysis (processed in anonymized or de-identified form)
  • Compliance with legal obligations and regulatory requirements

3. Data Protection Measures

We employ industry-standard technical and organizational measures to protect your personal data:

  • Encryption in transit: All data transmissions use TLS 1.2 or higher (HTTPS)
  • Storage security: Data is hosted on Google Cloud Platform (GCP), with data centers certified under ISO 27001, SOC 2, and other international security standards
  • Access control: Role-Based Access Control (RBAC) ensures only authorized personnel can access specific categories of personal data
  • Password protection: User passwords are stored using one-way hashing (bcrypt); we cannot recover your plaintext password
  • Regular backups: Automatic daily backups ensure data recoverability
  • Security audits: Periodic review of access logs and security configurations to continuously improve data protection

4. Third-Party Services

To provide comprehensive services, we use the following third-party service providers. These providers process your data only to the extent necessary for service delivery:

  • Google Cloud Platform (GCP): Cloud infrastructure and data storage
  • Google Cloud Storage (GCS): File storage (e.g., images, 3D files)
  • Google Analytics: Website traffic analysis (collects only anonymized browsing behavior data)
  • Elastic APM: Application performance monitoring (collects only technical performance data)

5. Data Sharing and Disclosure

We do not sell, trade, or rent your personal data to third parties. We disclose your data only in the following circumstances:

  • With your explicit written or electronic consent
  • As required by law, judicial authorities, or competent regulatory agencies
  • As necessary for service delivery, delegated to the third-party service providers listed above (all bound by contractual obligations not to use data for other purposes)
  • When reasonably necessary to protect the rights and interests of the Platform, other users, or the public

6. Data Retention

We retain your personal data according to the following principles:

  • Account data: Deleted 90 days after account deactivation or deletion; you may request data export during this period
  • Business data: 1 to 5 years depending on the service plan; however, accounting-related records are retained for a minimum of 10 years in accordance with Article 38 of the Business Accounting Act
  • Usage logs: Retained for 12 months for security auditing and troubleshooting
  • Cookie data: Retained according to each cookie's expiration period, not exceeding 24 months

7. Your Rights

Under Article 3 of the PDPA, you have the following rights regarding your personal data collected by the Platform:

  • Right to inquire and review (Article 10 of the PDPA)
  • Right to request copies of your data
  • Right to request supplementation or correction (Article 11, Paragraph 1 of the PDPA)
  • Right to request cessation of collection, processing, or use (Article 11, Paragraph 4 of the PDPA)
  • Right to request deletion (Article 11, Paragraph 3 of the PDPA)
  • Right to export your business data (provided in a commonly used format)

8. Cookie Policy

The Platform uses cookies and similar technologies to provide, secure, and improve our services:

  • Essential cookies: Required to maintain login sessions and session security; cannot be disabled
  • Functional cookies: Store user preferences such as language settings
  • Analytics cookies: Collect anonymized usage statistics through Google Analytics; you may disable these via browser settings

9. Children's Privacy

The Platform is a business-to-business (B2B) professional management tool and is not designed for general consumers or children. We do not knowingly collect personal data from children under the age of 16. If you become aware that a child's data has been collected, please notify us immediately and we will promptly delete it.

10. Cross-Border Data Transfers

The Google Cloud Platform data centers used by the Platform are located in Taiwan (asia-east1) and other GCP regions. Due to operational necessity, your data may be transferred to GCP data centers outside of the Republic of China (Taiwan). In accordance with Article 21 of the PDPA, we have confirmed that the data protection standards in these regions meet international standards.

In accordance with Article 21 of the PDPA, if the competent authority restricts personal data transfers to specific countries or regions, the Platform will comply with such restrictions and take necessary measures, including but not limited to data localization.

11. Policy Updates

We reserve the right to update this Privacy Policy. Material changes will be communicated to you at least 30 days before they take effect via Platform announcements or email notification. Continued use of the Platform constitutes acceptance of the updated policy. You may review the latest version of this Privacy Policy on this page at any time.

For questions about this Privacy Policy, or to exercise your personal data rights, please contact [email protected].

We use cookies to improve your browsing experience. By continuing to use this site, you agree to our cookie policy.