Privacy policy

Last updated: August 2026

Dentalynx is operated by EINSPACE Inc. (Montréal, Canada). This policy explains how we collect, use, store, and protect personal information when you use our platform. By using our services, you consent to the practices described here.

Dentalynx is used by regulated workplaces — dental clinics in particular — to train and document their staff. Sections 1, 3, and 4.4 explain who is responsible for what in that arrangement, what staff information we hold, and why patient information must never be placed on the platform.

1. Our role and your role

Two different relationships are covered by this policy:

  • Your own account information. When you sign up, browse our site, or contact us, we handle your personal information for our own purposes as described below. For that information we are the business responsible for it (the "controller", or under Québec law the enterprise responsible for protecting it).
  • Staff records inside a clinic or team account. When a clinic or organization adds its people to Dentalynx and records their training, that organization decides who is enrolled, what is recorded, how long it is kept, and what it is used for. It is responsible for that information; we process it on its behalf and on its instructions (as a processor or service provider).

If you are an employee enrolled in an organization’s account and want your training records corrected or deleted, contact that organization first — they control those records. We will support them in responding, and we will not use their staff data for our own purposes beyond operating, securing, and improving the service.

A data processing agreement is available to organizations on request at contact@dentalynx.ai.

2. Data collection

We collect information to provide and improve our services:

2.1 Account information

  • Email address: account identification, authentication, and communication
  • Name: to personalize your experience on the platform
  • Profile picture: displayed on your profile and within trainings you participate in
  • Password: stored in encrypted form for email/password authentication

2.2 Google authentication data

When you sign in with Google, we access your email address (to create and identify your account), display name (to personalize your profile), and profile photo URL (to display your avatar). We request only the minimum necessary scopes (email and profile). We do not request access to your Google Drive, Gmail, Calendar, or any other Google service.

2.3 Staff records in clinic accounts

When an organization enrolls its people, we hold the information it provides and the activity the platform records, which typically includes:

  • Name, work email address, and mobile phone number, as supplied by the organization or through a bulk import
  • Role or job title, location or clinic, and group assignments (for example a hygienist role or a specific site)
  • Any professional or internal identifier the organization chooses to enter, such as a licence or employee number
  • Assigned training, due dates, completion status and dates, time spent, exercise responses and scores, and certificates or transcripts generated from that activity
  • Messages the person posts in their workspace

Administrators of the organization can see this information for the people in their account, including individual completion status. We do not sell it and we do not use it for advertising.

2.4 Phone numbers and SMS

Where an organization enables it, mobile numbers are used to sign employees in and to send training and deadline reminders by SMS:

  • Numbers are stored in a normalized international format so duplicates can be detected and duplicate messages suppressed
  • Messages are sent through a third-party messaging provider (Twilio) and delivered by mobile carriers, which process the number and message content for delivery
  • We keep delivery records (which message, to whom, when, and its status) for troubleshooting and for the organization’s audit trail
  • Replying STOP (or ARRÊT) stops platform SMS to that number

The organization that supplies a phone number is responsible for having obtained the person’s consent to be contacted at it.

2.5 User-generated content

  • Trainings and educational content you create
  • Documents you upload for training creation
  • Messages and communications within workspaces
  • Exercise responses and progress data

2.6 Usage information

  • Training completion and progress tracking
  • Feature usage and interaction patterns
  • Device and browser information for optimization

2.7 Enquiries and requested diagnostics

If you contact us through a form on this site — for example to book a quality diagnostic for your clinic — we collect the details you submit: name, phone, email, clinic name, team size, and your message, together with the language of the page you used. We use this to respond and prepare for that conversation. We do not sell it or share it for third-party marketing.

3. Information we do not want — patient and clinical data

Dentalynx is a staff-training system, not a clinical or patient-records system. Patient information must not be uploaded to it. That includes patient charts and treatment notes, prescriptions, billing or insurance claims, health-insurance numbers (including RAMQ numbers), and radiographs, intraoral photographs, or other images from which a patient could be identified.

De-identify clinical examples before adding them to training material. We do not act as a HIPAA business associate and have not entered into a business associate agreement or equivalent health-information processing agreement unless one has been signed with you in writing.

If patient information is uploaded by mistake, notify us at contact@dentalynx.ai and we will work with you to remove it from the platform and from our backups on our normal backup cycle.

4. Data storage

4.1 Where we store your data

  • Database: your account information and content are stored in secure PostgreSQL databases hosted by Supabase
  • File storage: documents and media files are stored in encrypted cloud storage
  • Authentication: authentication tokens are managed securely through industry-standard protocols

4.2 Location of your data and cross-border transfers

Our production database and file storage are hosted in the United States (Supabase, AWS us-east-1). Our application, background-job, email, SMS, analytics, and AI providers may also process data in the United States and in other countries where they operate. Personal information you or your organization place on the platform — including staff names, contact details, and training records — is therefore stored and processed outside Québec and outside Canada, and may be subject to the laws of those jurisdictions, including lawful access requests.

We rely on contractual protections with our providers, access controls, and encryption in transit and at rest. Organizations in Québec should take this transfer into account in their own privacy assessment before enrolling staff; contact us at contact@dentalynx.ai for the detail needed for that assessment.

4.3 Security measures

  • All data transmission is encrypted using TLS/SSL
  • Passwords are hashed using industry-standard algorithms
  • Access to data is restricted through role-based permissions, enforced at the database level so one organization cannot read another’s records
  • Access by our staff is limited to what is needed to operate and support the service
  • Regular security audits and monitoring are performed

4.4 Data retention

We retain your data for as long as your account is active or as needed to provide services. You can request deletion of your account and associated data at any time at contact@dentalynx.ai.

Training and completion records are retained for as long as the organization’s account is active, because organizations commonly need them as evidence for audits, inspections, or professional obligations. The organization decides how long to keep them and when to delete a person’s records. After a subscription is cancelled, the workspace remains available in read-only mode for 30 days so records can be exported; after that, content may be deleted. Backups are retained on a rolling basis for a limited period, so deleted data can persist in backups briefly before it ages out. We may retain a minimal record of billing and account history where required.

5. Data usage

5.1 Core service functionality

  • Authentication: to verify your identity and secure your account
  • Personalization: to display your name and profile picture
  • Training delivery: to provide access to trainings and track progress
  • Training administration: to assign training, calculate completion status for the organization, schedule and send reminders, and produce certificates and transcripts
  • Communication: to send important account and service notifications

5.2 Google user data

  • Your Google email is used solely to create and identify your account
  • Your Google display name sets your initial profile name (changeable)
  • Your Google profile photo is your default avatar (changeable)
  • We do not use your Google data for advertising or sell it
  • We do not transfer your Google data to third parties except as necessary to provide the service

5.3 AI processing

To generate and edit training content, the platform sends your inputs to third-party AI providers (currently Anthropic and OpenAI) and may send search queries to a web-search provider (Exa). What is sent: the instructions you type, the settings you choose, and the text of documents or reference material you attach for generation; for learner-facing AI features, the question or answer being processed.

Our agreements with these providers do not permit them to use the content we send through their APIs to train their models. Do not paste patient information or other data you would not want processed by a third-party provider into AI features — see section 3. AI output can be inaccurate and must be reviewed by a qualified person before it is published.

5.4 Service improvement

  • Analyzing usage patterns to improve features and user experience
  • Troubleshooting technical issues and providing support
  • Developing new features based on user needs

5.5 What we do NOT do with your data

  • We do not sell your personal data
  • We do not use your data for targeted advertising outside our platform
  • We do not share your Google user data with third parties except as required to provide our services
  • We do not use an organization’s staff or training records for our own marketing, and we do not disclose them to other customers
  • We do not use your data for purposes unrelated to providing our services

6. Third-party services and subprocessors

We use trusted third-party services to operate the platform:

  • Supabase: database, authentication, and file storage
  • Vercel: application hosting and delivery
  • Stripe: payment processing (we do not store your payment card details)
  • Anthropic and OpenAI: AI model providers used to generate and edit content
  • Exa: web search used to find reference material
  • Twilio: SMS delivery for sign-in codes and training reminders
  • Loops: transactional and notification email delivery
  • Inngest: background job processing for content generation and scheduled reminders
  • Analytics providers: to understand how the service is used (anonymized or aggregated data)

These providers are bound by confidentiality agreements and their own privacy policies. They only process data as necessary to provide their specific services to us. An up-to-date list of subprocessors is available on request at contact@dentalynx.ai.

7. YouTube API services

Our service uses YouTube API Services for embedding training videos. By using our platform, you agree to be bound by the YouTube Terms of Service. We collect and process data in accordance with the Google Privacy Policy.

Dentalynx does not collect any user information through YouTube API data. The platform only facilitates the display of YouTube videos for training purposes. Our API client may place cookies solely to enable video playback; we do not use them to collect personal data or track behavior.

You can revoke our platform’s access to YouTube services at any time through the Google security settings page.

8. Your rights

You have the right to:

  • Access: request a copy of the personal data we hold about you
  • Correction: request correction of inaccurate personal data
  • Deletion: request deletion of your account and associated data
  • Withdraw consent: withdraw consent where we rely on it, including stopping promotional email and SMS
  • Revoke access: disconnect Google Sign-In through the Google security settings page
  • Data portability: request your data in a portable format

To exercise any of these rights, contact us at contact@dentalynx.ai. If your records sit inside an employer’s workspace, we will direct your request to that organization, which controls those records — see section 1.

In Québec, Law 25 gives you rights of access, rectification, de-indexing, and portability, and the right to complain to the Commission d’accès à l’information du Québec. Elsewhere in Canada, you may complain to the Office of the Privacy Commissioner of Canada. We respond to requests within the timeframes set by applicable law (30 days in Québec).

9. Confidentiality incidents

We maintain a register of confidentiality incidents involving personal information. If we become aware of an incident presenting a risk of serious injury, we will notify the affected organizations and, where required, the individuals concerned and the relevant privacy authority, without unreasonable delay, and we will give the organization the information it needs to meet its own notification obligations. Report a suspected incident to contact@dentalynx.ai.

10. Subscription plans and payments

We offer subscription plans for our services. Payment information is processed securely through Stripe. We do not store your credit card details on our servers. Stripe’s privacy policy governs the handling of your payment information.

11. Email and SMS communications

We may send you emails related to your account, including service updates, security alerts, and promotional content. You can opt out of promotional emails at any time through the unsubscribe link or by contacting us. Transactional messages — sign-in codes, training assignments, deadline reminders, and billing or security notices — are part of the service. SMS reminders can be stopped by replying STOP (or ARRÊT), or by asking your organization’s administrator to remove your number.

12. Children

The platform is intended for use by adults and by people enrolled by an organization. We do not knowingly collect personal information directly from children. If an organization enrolls minors, it is responsible for obtaining any consent required by the law that applies to it.

13. Changes to this policy

We may update this privacy policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the platform after such modifications constitutes acceptance of the updated policy.

14. Contact us

For questions, concerns, or complaints about this policy or our data practices: contact@dentalynx.ai.

The same address reaches the person responsible for the protection of personal information at EINSPACE Inc. Write "Privacy" in the subject line and we will route it accordingly. For questions related to Google user data, include "Google Data Inquiry" in the subject line.