LEGAL
Privacy policy
This document explains what data asisDENT collects, why it collects it, who it is passed to, and what you can ask us for. Legal wording is kept where it has to be; everywhere else this is written in plain language.
In short
- Patient data belongs to the clinic, not to us. We hold it and protect it on the clinic's instruction.
- This site sets no cookies: no analytics, no advertising pixel, no tracker. The page makes no request to any address other than its own domain.
- When you send the enquiry form, the data does not reach our server: your own mail program opens with the message ready, and you are the one who sends it.
- A notification sent to a patient carries no diagnosis, no treatment plan and no radiograph — only the appointment time and a confirmation link.
- You can take your data out whenever you want. When a subscription ends the database is not wiped at once; the system switches to read-only.
1. What this policy covers
The policy applies to three surfaces:
- asisdent.az — this marketing site.
- app.asisdent.az — the system the clinic works in: calendar, patient record, dental chart, treatment plan, reports.
- the asisDENT mobile app — the access a dentist or a staff member uses on a phone.
The clinic's own website, its social media pages, any other software it runs and the patient's own messaging app are not covered by this policy: they have terms of their own.
2. The parties: who is responsible for what
This is the most important clause in the document, because everything else follows from it. Patient data is owned by the clinic; we process it on the clinic's instruction.
| Party | Role | Responsible for |
|---|---|---|
| The clinic or dentist | Owner (the data controller) | Chooses what data to collect, obtains the patient's consent, grants and withdraws staff access, and is responsible for the accuracy of the data. |
| asisDENT (techSA) | Processor — processes on the clinic's instruction | Stores the data, protects it, and carries out only the operations the clinic instructs. Does not use it for its own purposes. |
| The patient | Data subject | Has the right to ask what data is held, to have it corrected and to request its deletion. Requests go to the clinic. |
We state this plainly: we do not sell patient data, we do not pass it on for advertising, and we do not show one clinic's data to another.
3. What data we collect
3.1 On this site
- No cookies. No analytics, no advertising pixel, no social media button and no external font. The page contacts no host other than its own domain.
- Browser storage: the light or dark mode you pick is stored in your browser. That value is never sent to us.
- The server's technical log: when you open a page the web server records the time of the request, the IP address, the browser name and the address opened. This is for fault-finding and security; it is not used for advertising.
- The enquiry form: your name, the clinic name, phone, e-mail, the plan you picked and the note you wrote. This data is not sent to our server — pressing the button opens your own mail program with the message ready. So it reaches us only as an e-mail you sent, and it is used only to get back to you.
3.2 In the system
Data held in the system falls into three groups:
- Account data: the user's name, e-mail, phone, role and an irreversible trace of the password (a hash). The password itself is never stored in readable form anywhere.
- Clinic data: the clinic's name, address, contact numbers, opening hours, services, prices, and the list of dentists and staff.
- Patient data: name and surname, contact number, date of birth, appointment history, dental chart, treatment plan and sessions, radiographs and documents, payment records, and notes written by the clinic. This is treated as medical data, and the system handles it accordingly.
Beyond this, the system keeps a trace of every operation: who looked at what, when, and what they changed. That log protects the clinic itself.
4. What it is used for
| Purpose | Legal basis |
|---|---|
| Booking, confirming, reminding about and cancelling appointments | Performance of the contract with the clinic; the patient's consent |
| Holding the patient record, treatment plan and documents | Processing on the clinic's instruction; keeping the medical record |
| Reports and payment records | The clinic's legitimate interests; accounting requirements |
| Protecting the account, detecting misuse | Legitimate interest; security obligation |
| Support and fixing faults | Performance of the contract |
| Contacting you (a message from the enquiry form) | Your consent |
During support we look at a clinic's data only to the extent needed to resolve the matter.
5. Notifications and third parties
Notifications are sent over the channels the clinic chooses — WhatsApp, Telegram, SMS and e-mail — and carry only the minimum needed for the appointment. These channels are not ours, they operate under their own privacy terms, and some of them sit outside Azerbaijan.
What never goes to those channels: diagnoses, treatment plans, radiographs and other images, the clinic's notes, payment amounts, financial reports.
The system runs on a leased server, and traffic passes through a service that protects against attacks. The full list of service providers, and how much data goes to each, is set out in the contract signed with the clinic.
6. Cookies and browser storage
- There are no cookies on the site, so there is no cookie consent banner either. The only value stored is the light or dark mode you picked, and it stays in your browser.
- The system uses one strictly necessary cookie: a session cookie that keeps you signed in. The system does not work without it, so that cookie is not optional. There is no advertising or tracking cookie.
7. Where the data is held
The system and its backups are held on a server dedicated to asisDENT. Data flows that leave the country are limited to the services named in clause 5; the detail is in the contract signed with the clinic.
8. How long it is kept
- While the subscription runs, the data is kept as it is.
- A deleted record does not vanish immediately: it is kept for a period so that something deleted by mistake can be restored, and is then deleted in full.
- When the contract ends the data stays available for one month in read-only mode and can be exported; after that month the account and the data on it are deleted permanently.
- If the clinic asks in writing for the data to be deleted in full, it is deleted taking into account the retention period the law sets for medical records, and the clinic is given confirmation of the deletion.
- The server's technical logs are kept for a limited period and deleted automatically.
The exact periods are set out in the contract signed with the clinic, because they depend on the clinic's own medical record retention duty.
9. Security
- Everything that travels between the browser and the server is encrypted.
- Passwords are stored in an irreversible form. Two-step verification is something you switch on yourself.
- Each clinic's data is separated from every other clinic's.
- Who looked at what, when, and what they changed — all of it is recorded.
No system is completely secure. That is why clause 12 also sets out what we do in the event of a breach.
10. Your rights
As a data subject you have the right:
- to know what data is held and to receive a copy of it;
- to have inaccurate data corrected;
- to request that the data be deleted;
- to withdraw a consent you gave, at any time.
If you are a patient, send your request to the clinic that treated you: the clinic is the owner of the data. If a request reaches us, we forward it to the clinic, and we give the clinic the technical help it needs.
If you are a clinic, you can export your data from the system itself; if you need help, write to the address in the contact section below.
Closing an account and deleting the data on it has its own page: account deletion.
11. Children's data
A child patient's data is processed with the consent of a parent or legal representative. Obtaining that consent is the clinic's responsibility. The system keeps a separate record for a child patient, and the protections listed above apply to it in exactly the same way.
12. Data breach
If unauthorised access to, or disclosure of, data is detected, we investigate the incident immediately, close the cause, and write to the affected clinics explaining what happened. Notifying patients and the competent state authorities is the clinic's duty; we provide the technical information needed for that.
13. Changes and contact
When the policy changes, the "last updated" date on this page is updated. If there is a material change, clinics see the new text at their next sign in to the system and confirm it. You can ask us for an earlier version.
Contact
Write to us with any privacy question. We reply on working days.
- Platform
- asisDENT
- Operated by
- techSA
-
info the sign you know
asisdent dot az
info the sign you know techsa dot az We deliberately do not spell the address out: a legal page is the first stop for address-harvesting robots. Put the signs back in and you have the address. - Requests
- A written request is preferred: it leaves a trace of the answer and of the time it took. If you need to speak on the phone, say so by e-mail and we will call.