Legal

Privacy Policy

Last updated: March 2026

1. Data We Collect

We collect information you provide directly when creating your account (name, email, phone number), lab or clinic profile details, documents uploaded for verification purposes, and order and payment records. We also automatically collect usage data (IP addresses, browser type, pages visited) and device data, and may receive data from payment processors such as Moyasar.

2. How We Use Your Data

We use your data to operate the platform and provide services, process payments and generate VAT-compliant invoices as required by the Saudi Zakat, Tax and Customs Authority, send transactional notifications and operational updates via Resend and Twilio, improve platform performance and user experience, and comply with legal obligations under the Saudi Personal Data Protection Law (PDPL). We do not sell your personal data to third parties.

3. Data Sharing

We share your data with the following trusted service providers as necessary to operate the platform: Moyasar (payment processing, licensed by SAMA), Resend (email delivery), Twilio (SMS/WhatsApp delivery), Turso (hosted LibSQL database). We do not disclose your personal data to any other parties unless required by law or with your explicit consent.

4. Data Retention

We retain your data for as long as your account is active and thereafter for as long as necessary for legal and tax purposes. In accordance with Saudi Zakat, Tax and Customs Authority requirements, financial records and VAT records are retained for seven (7) years. You may request deletion of your account and personal data by contacting us, and we will action your request within 30 days subject to mandatory legal retention requirements.

5. Your Rights (PDPL)

Under the Saudi Personal Data Protection Law (PDPL), you have the right to: access the personal data we hold about you, request correction of any inaccurate data, request deletion of your data (subject to legal obligations), receive a copy of your data in machine-readable format (data portability), and object to certain types of data processing. To exercise any of these rights, please contact our Data Protection Officer.

6. Cookies

We use essential cookies to operate the platform (session management, security) and preference cookies (language, display mode). We do not currently use cookies that track users for advertising purposes. You can manage cookies through your browser settings or refer to our Cookie Policy for more details.

7. International Transfers

Your data is primarily processed within the Kingdom of Saudi Arabia. Some data may be transferred to service providers located outside the Kingdom (such as Resend and Twilio) for the specific operational purposes described above. We ensure that any data transfer is subject to appropriate contractual agreements and consistent with PDPL requirements.

8. Contact & DPO

For any privacy-related inquiries or to exercise your rights under PDPL, please contact our Data Protection Officer at: privacy@dental-sa.com or write to us at: Dintal, Riyadh, Kingdom of Saudi Arabia. We are committed to responding to all privacy requests within 30 days.