Privacy Policy
Applies to the The Dental Code mobile app (Apple App Store and Google Play) and www.thedentalcode.com
Contents
1. Who we are
This Privacy Policy explains how The Dental Code Pty Ltd collects, uses, discloses, stores and protects personal information when you use the The Dental Code mobile application (the "App"), our website at www.thedentalcode.com (the "Site"), and any related services (together, the "Services").
| Entity | The Dental Code Pty Ltd |
|---|---|
| ACN | 695 448 054 |
| ABN | 12 695 448 054 |
| Registered | Victoria, Australia (registered 19 February 2026 under the Corporations Act 2001) |
| Privacy contact | support@thedentalcode.com |
| Distribution | Apple App Store and Google Play, in Australia, the United Kingdom and New Zealand |
In this Policy, "we", "us" and "our" means The Dental Code Pty Ltd. "You" and "your" means the individual dental practitioner or other person using the Services.
We are the data controller (UK) / APP entity (Australia) / agency (New Zealand) responsible for the personal information described in this Policy.
2. The laws that apply to you
The Dental Code is an Australian company. We designed our privacy practices to meet the highest applicable standard across the three markets in which the App is distributed, and to comply with each of the following:
| Where you are | Law we comply with | Your regulator |
|---|---|---|
| Australia | Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs), including the Notifiable Data Breaches scheme and, since 10 June 2025, the statutory tort for serious invasions of privacy | Office of the Australian Information Commissioner (OAIC) — oaic.gov.au |
| United Kingdom | UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR) for cookies and marketing | Information Commissioner's Office (ICO) — ico.org.uk |
| New Zealand | Privacy Act 2020 and the 13 Information Privacy Principles (IPPs), including IPP 12 on offshore disclosure | Office of the Privacy Commissioner (OPC) — privacy.org.nz |
Where a right or protection in one of these laws is stronger than the others, we apply the stronger standard to everyone, unless we say otherwise.
3. Important: The Dental Code is not a clinical record system
Read this before you enter anything into the App
The App is designed so that no patient can be identified from the information it holds.
We do not ask for, and you must not enter, any patient names, initials, dates of birth, contact details, addresses, patient or file numbers, Medicare/NHS/NHI numbers, images, clinical notes, or any free text that could reasonably identify a patient.
The App records de-identified summaries of your working day only — counts, categories, values and your own wellbeing rating.
We hold no patient records, no clinical records, and no patient health information.
You are responsible for the content you enter. If you type identifying information into a free-text field, you may breach your own professional and legal obligations to your patients. If you believe you have entered identifying patient information, delete it in the App or contact us at support@thedentalcode.com and we will remove it.
Because we do not hold patient information, we are not acting as a processor or service provider for your practice in relation to patient data, and no data processing agreement between us and your clinic is required for the App to operate.
4. What personal information we collect
4.1 Information you give us
- Account details — your name, email address, password (stored only as a salted hash), country of practice, and your professional discipline or role.
- Practice profile — the clinic names or labels you create, your working days and sessions, and your revenue and career targets.
- Day-log and practice activity data — de-identified summaries of your working day, including: the number of patients seen; a short summary of an appointment; treatment types and categories; the dollar (or pound) value of an appointment; laboratory fees; rebooking rates; hours worked; and which clinic the day relates to.
- Wellbeing score — a self-reported rating of how you felt on a given day, which you choose to enter. See section 6.
- Support and correspondence — the content of emails, in-app support messages and any feedback or survey responses you send us.
- Marketing sign-ups — your email address and, optionally, your company, if you subscribe to our newsletter on the Site.
4.2 Information collected automatically
- Device and technical data — device model, operating system and version, app version, language and region settings, time zone, and a randomly generated app instance identifier.
- Usage and analytics data — screens viewed, features used, session frequency and duration, and in-app events (for example, that a day-log was saved — not its contents).
- Diagnostics — crash logs, error reports and performance diagnostics.
- Website data — IP address (which indicates approximate country or region), pages viewed, referring URL and cookie identifiers. See section 9.
4.3 Information from third parties
- Apple App Store and Google Play — Apple and Google tell us your subscription status, renewal and cancellation events, and a store-issued transaction identifier. They do not give us your full payment card details — those are handled by Apple and Google under their own privacy policies.
- Analytics and infrastructure providers — aggregated, non-identifying performance data about the App and Site.
4.4 What we do not collect
- Any patient-identifying or patient clinical information.
- Precise GPS or background location. We do not track your location.
- Your contacts, photo library, microphone or camera, unless you explicitly grant permission for a specific feature and we tell you why at the time.
- Advertising identifiers for cross-app or cross-site tracking. We do not track you across other companies' apps or websites, and we do not run third-party advertising in the App.
- Government identifiers, biometric data, or your race, religion, political opinions, sexual orientation, union membership or criminal record.
5. Why we use your information, and our legal basis
If you are in the United Kingdom, UK GDPR requires us to identify a lawful basis for each purpose. That basis is set out in the right-hand column below. If you are in Australia or New Zealand, we collect and use your information only for the purposes below, which are the purposes we told you about when we collected it, or purposes you would reasonably expect.
| What we do | Why | UK GDPR lawful basis |
|---|---|---|
| Create and run your account; deliver the App's core features | So you can log your day and see your analytics | Performance of a contract (Art 6(1)(b)) |
| Generate your analytics, trends, benchmarks and career-alignment insights | This is the product you signed up for | Performance of a contract (Art 6(1)(b)) |
| Manage your subscription and confirm entitlement with Apple or Google | To give you access to paid features | Performance of a contract (Art 6(1)(b)) |
| Store and display your wellbeing score | So you can see how you are tracking over time | Explicit consent (Art 9(2)(a)) — see section 6 |
| Provide customer support and respond to your messages | To help you when something goes wrong | Performance of a contract; legitimate interests (Art 6(1)(b), (f)) |
| Measure feature usage, fix crashes and improve the App | To keep the App stable and make it better | Legitimate interests (Art 6(1)(f)); consent where analytics cookies or device-storage access are involved |
| Produce aggregated, de-identified statistics and benchmarks across our user base | To show you how your practice compares, and to develop the product | Legitimate interests (Art 6(1)(f)) — output cannot identify you |
| Send you service messages (security, billing, changes to terms) | We are required to, or you need to know | Performance of a contract; legal obligation (Art 6(1)(b), (c)) |
| Send you marketing emails and product news | To tell you about features and offers | Consent, or soft opt-in for existing customers (Art 6(1)(a)/(f); PECR reg 22) |
| Detect and prevent fraud, abuse and security incidents | To protect you, us and other users | Legitimate interests; legal obligation (Art 6(1)(f), (c)) |
| Comply with law, respond to lawful requests, establish or defend legal claims | We have to | Legal obligation; legitimate interests (Art 6(1)(c), (f)) |
Where we rely on legitimate interests, we have assessed that our interest does not override your rights and freedoms. You can object to that processing at any time — see section 13.
We will not use your personal information for a new, unrelated purpose without telling you and, where required, obtaining your consent.
6. Your wellbeing score — special handling
The wellbeing score is a rating you give about how you felt on a particular day. Because it relates to your own state of health, it is treated as:
- sensitive information (health information) under the Privacy Act 1988 (Cth) in Australia;
- special category data concerning health under Article 9 of the UK GDPR;
- health information under the Privacy Act 2020 and the Health Information Privacy Code 2020 in New Zealand.
This means we apply extra protections:
- Entering a wellbeing score is entirely optional. The App works without it.
- We collect it only with your express, informed consent, which you give the first time you use the feature.
- It is used solely to show you your own wellbeing trend inside your own account.
- It is never disclosed to your clinic, your employer, a regulator, an insurer, a recruiter or any other third party.
- It is not used for marketing, profiling or automated decision-making.
- If it is ever included in aggregated statistics, it is irreversibly aggregated so that no individual can be identified, and only where a cohort is large enough to prevent re-identification.
- You can withdraw your consent at any time in the App's settings, or by emailing support@thedentalcode.com. Withdrawing consent deletes your wellbeing history and does not affect the lawfulness of what we did before you withdrew it.
7. Who we share your information with
We do not sell your personal information
We have never sold personal information and we do not do so. We do not share it with data brokers, and we do not disclose it for third-party advertising.
We do not disclose your individual practice data or wellbeing data to any clinic, practice owner, employer, dental board, insurer or professional association.
We disclose personal information only to the following categories of recipient, and only as far as is necessary:
| Recipient | What they receive and why |
|---|---|
| Google LLC / Google Cloud Platform and Firebase | Hosting, database, authentication, crash reporting and analytics. Your account data and day-log data are stored in Google data centres. |
| Apple Inc. and Google LLC (as app store operators) | Purchase, subscription and entitlement data, so your subscription works. Governed by their own privacy policies. |
| Email and communications providers | Your email address and message content, to deliver service and marketing emails. |
| Professional advisers | Lawyers, accountants, auditors and insurers, where genuinely necessary and under a duty of confidence. |
| Law enforcement, courts and regulators | Only where we are required or authorised by law, or where disclosure is necessary to prevent a serious threat to life, health or safety. |
| A purchaser or successor | If we merge, restructure, or sell all or part of our business, your information may transfer with it. We will notify you, and the recipient will remain bound by this Policy or a policy at least as protective. |
All service providers are bound by contract to use your information only on our instructions, keep it confidential and secure, and delete or return it when the engagement ends.
8. Where your information is stored and sent overseas
We host the Services on Google Cloud Platform and Firebase. Depending on the region assigned to your account, your data may be stored and processed in Google data centres located in Australia, the European Economic Area, the United Kingdom, or the United States, and our service providers may access it from other countries in which they operate.
If you are in Australia
This is a disclosure of personal information to overseas recipients for the purposes of APP 8. By using the Services you acknowledge that overseas recipients may be located in countries whose privacy laws differ from Australia's. We take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles, including by imposing contractual obligations on them.
If you are in the United Kingdom
Where we transfer personal data outside the UK, we rely on either a UK adequacy decision for the destination country, or the ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. You may request a copy of the relevant safeguards by emailing support@thedentalcode.com.
If you are in New Zealand
Before disclosing personal information to a recipient outside New Zealand, we satisfy ourselves under IPP 12 that the recipient is required to protect the information with safeguards comparable to those in the Privacy Act 2020, whether by contract, binding scheme, or the law of the destination country.
9. Analytics, cookies and tracking
9.1 In the App
We use Google Analytics for Firebase and Firebase Crashlytics to understand how the App is used and to diagnose crashes. These tools record events such as which screens you open and how long a session lasts, together with device and app version data. They do not record the contents of your day-logs or your wellbeing score.
You can turn optional analytics off at any time in the App's privacy settings. Turning analytics off does not affect your ability to use the App.
We do not use the Advertising Identifier (IDFA) or Google Advertising ID, and we do not track you across other companies' apps or websites. Because of this, the App does not present the Apple App Tracking Transparency prompt.
9.2 On the website
The Site uses cookies and similar technologies. Strictly necessary cookies keep the Site working and are always on. Analytics and preference cookies are optional; if you are in the UK, we set them only after you consent through our cookie banner, and you can change your choice at any time. You can also block or delete cookies in your browser settings, though parts of the Site may then not work.
- Strictly necessary and session cookies — keep your session working and remember your choices during a visit.
- Preference cookies — remember settings such as light or dark mode.
- Analytics cookies — help us count visits and understand which pages are useful.
10. How long we keep your information
| Information | Retention period |
|---|---|
| Account details | For as long as your account is active, then deleted within 30 days of account closure |
| Day-log and practice activity data | For as long as your account is active, then deleted within 30 days of account closure |
| Wellbeing score history | Until you delete it, withdraw consent, or close your account — then deleted within 30 days |
| Encrypted backups | Backups containing deleted data are overwritten on a rolling cycle and fully purged within 90 days |
| Support correspondence | 24 months from the date the matter is closed |
| Marketing preferences and unsubscribe records | Kept as long as needed to honour your opt-out |
| Billing and transaction records | 7 years, as required by Australian tax and corporations law |
| Aggregated, irreversibly de-identified statistics | Retained indefinitely — this information cannot be linked back to you and is no longer personal information |
We will keep information for longer only where we are required to by law, or where it is needed to establish, exercise or defend a legal claim. When we no longer need personal information, we destroy it or irreversibly de-identify it.
11. Deleting your account and your data
How to delete your account
In the App: open More, then Edit (top right), then Delete account, and confirm. This deletes your account and all associated data.
By email: send a request from your registered email address to support@thedentalcode.com and we will action it within 30 days.
Deletion is permanent. Your day-logs, analytics history and wellbeing history cannot be recovered afterwards. Export your data first if you want to keep it.
Cancelling your subscription through the App Store or Google Play stops future billing but does not by itself delete your account. To delete your data, use one of the methods above.
A small amount of information may survive account deletion where the law requires it — for example, billing records we must keep for tax purposes, and records of your unsubscribe request so we do not email you again.
12. How we protect your information
We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These include:
- encryption in transit using TLS, and encryption at rest for stored data;
- authentication controls, with passwords stored only as salted hashes;
- role-based access controls, so our personnel can access personal information only where they need it to do their job;
- logging and monitoring of access to production systems;
- infrastructure hosted with a provider that maintains recognised international security certifications;
- regular patching, dependency updates and review of our security posture;
- confidentiality obligations and privacy training for our personnel.
No method of transmission or storage is completely secure. You also play a part: use a strong, unique password, keep your device locked and up to date, and tell us immediately at support@thedentalcode.com if you think your account has been compromised.
If a data breach happens
We maintain a data breach response plan. If a breach is likely to cause serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. If UK personal data is affected, we will notify the ICO within 72 hours of becoming aware where the breach is likely to result in a risk to individuals' rights and freedoms, and notify you where the risk is high. If New Zealand personal information is affected, we will notify the Office of the Privacy Commissioner and affected individuals as required by the Privacy Act 2020.
13. Your privacy rights
The rights available to you depend on where you are. Regardless of where you are, we will always try to honour a reasonable request.
| Right | Australia | United Kingdom | New Zealand |
|---|---|---|---|
| Access the information we hold about you | Yes (APP 12) | Yes (Art 15) | Yes (IPP 6) |
| Correct information that is wrong or incomplete | Yes (APP 13) | Yes (Art 16) | Yes (IPP 7) |
| Delete your information | Via account deletion | Yes (Art 17) | Via account deletion |
| Restrict how we use it | On request | Yes (Art 18) | On request |
| Object to processing based on legitimate interests | On request | Yes (Art 21) | On request |
| Receive a portable copy of your data | On request | Yes (Art 20) | On request |
| Withdraw consent (including for wellbeing data) | Yes | Yes (Art 7(3)) | Yes |
| Opt out of marketing | Yes | Yes | Yes |
| Deal with us anonymously or by pseudonym where practicable | Yes (APP 2) | — | — |
| Not be subject to solely automated decisions with legal or similar effects | — | Yes (Art 22) — we do not make such decisions | — |
| Complain to a regulator | OAIC | ICO | OPC |
How to exercise a right
Email support@thedentalcode.com from your registered email address and tell us what you want. We may ask you to verify your identity before we act, so that we do not disclose your information to someone else.
- We respond within 30 days in Australia and the United Kingdom, and within 20 working days in New Zealand.
- There is no charge. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline it, and we will explain why.
- If we refuse a request in whole or in part, we will tell you the reason and how to complain.
14. Marketing communications
We will send you marketing emails only where you have opted in, or where you are an existing customer and the message is about similar products and services (the PECR "soft opt-in" in the UK, and the Spam Act 2003 (Cth) in Australia, and the Unsolicited Electronic Messages Act 2007 in New Zealand).
Every marketing email contains a working unsubscribe link, and we will action unsubscribes promptly. Service messages — billing notices, security alerts, and changes to this Policy or our Terms — are not marketing, and you cannot opt out of them while you have an account.
15. App store disclosures
The App is distributed through the Apple App Store and Google Play. In addition to this Policy:
Apple App Store
- Our App Privacy "nutrition label" on the App Store product page describes the data types the App collects, how they are used, and whether they are linked to your identity. That label is kept consistent with this Policy.
- The App does not track you across apps or websites owned by other companies, so no App Tracking Transparency permission is requested.
- Account deletion is available inside the App, as required by App Store Review Guideline 5.1.1(v). See section 11.
- Subscriptions are billed by Apple. Apple's handling of your payment information is governed by the Apple Privacy Policy at apple.com/legal/privacy.
Google Play
- Our Data safety section on the Google Play listing describes the data the App collects and shares, our security practices, and our deletion options. It is kept consistent with this Policy.
- We handle your data in accordance with the Google Play User Data policy, including the Limited Use requirements where they apply.
- Subscriptions are billed by Google. Google's handling of your payment information is governed by the Google Privacy Policy at policies.google.com/privacy.
Apple and Google are independent controllers of the information they collect from you in connection with your app store account and your purchase. This Policy does not cover their practices.
16. Children
The Services are intended for registered and student dental practitioners and are not directed at anyone under 18. We do not knowingly collect personal information from a child. If you believe a person under 18 has provided us with personal information, contact support@thedentalcode.com and we will delete it.
17. Third-party links
The Site and the App may link to third-party websites and services, including our social media pages and the app stores. We do not control those services and are not responsible for their privacy practices. Read their privacy policies before you give them your information.
18. Changes to this Policy
We may update this Policy from time to time. When we do, we will change the "Last updated" date and post the new version at thedentalcode.com. If the change is significant — for example, a new purpose for using your information — we will tell you by email or by an in-app notice before it takes effect, and where the law requires it, we will ask for your consent.
Please review this Policy periodically. Continuing to use the Services after a change takes effect means you accept the updated Policy.
19. Contact us and how to complain
If you have a question about this Policy, want to exercise a privacy right, or think we have mishandled your personal information, contact us first — we would like the chance to put it right.
| support@thedentalcode.com | |
| Response time | We acknowledge complaints within 5 business days and aim to resolve them within 30 days |
If you are not satisfied with our response, you can escalate to your privacy regulator:
| Australia | United Kingdom | New Zealand |
|---|---|---|
|
Office of the Australian Information Commissioner GPO Box 5288, Sydney NSW 2001 1300 363 992 oaic.gov.au |
Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF 0303 123 1113 ico.org.uk |
Office of the Privacy Commissioner PO Box 10094, Wellington 6143 0800 803 909 privacy.org.nz |