Trust & Security

Your patients' data, handled the right way.

See exactly how information moves through HeyDenta — from a patient's first hello to a booked appointment — and how it stays protected under the Data Privacy Act.

Incoming call
+63 917 •• •• 42
Consent: recorded notice given
Aria · AI receptionist
Hi po! Anong service po ang kailangan ninyo?
Cleaning, this Friday if pwede 🙂
Book ko po kayo, Friday 2pm ✓
Appointment created
ServiceCleaning
WhenFri · 2:00 PM
ClinicAssigned
✓ Booked · logged
Only the details needed to book are captured
Every access is recorded
Retention controlled by policy
1

Patient contacts clinic

Call, chat or Messenger

2

Aria identifies intent

In Taglish, in real time

3

Only needed details captured

Consent asked at intake

4

Appointment created

Encrypted & access-logged

5

Clinic controls the record

Export or delete any time

Access

How your data is protected

The controls behind every record — no jargon, no overstatement.

01

Encrypted in transit & at rest

TLS in transit, encryption at rest.

02

Every clinic is isolated

Per-clinic separation keeps your patients and records apart from every other clinic's.

03

Least-privilege access, logged

Access is role-based, and system access is logged.

04

Managed, regional hosting

A managed database in Northeast Asia (Seoul), on Supabase & Vercel infrastructure.

AI Handling

How Aria handles calls & messages

The AI receptionist is built to capture only what a booking needs.

01

Recorded-for-quality notice

Every AI call opens by telling the caller it's recorded; identifiers are redacted from stored transcripts; recordings deleted after 30 days.

02

Humans stay in control

Aria handles inquiries, booking and follow-ups; clinically significant questions are escalated to your team. You set what it can do.

03

Consent at intake

Patients consent to how their details are used as part of the intake step.

04

Redacted before any AI abroad

Where a message is processed by an AI provider outside the country, identifying details are redacted first.

Lifecycle

Where your data goes, and when it's gone

Collected
Only booking details
Consent at intake
Transferred
Redacted first
Before any AI abroad
Stored
Seoul, encrypted
Per-clinic isolation
Access
Role-based
Every access logged
Deleted
Recordings: 30 days
Records: on request
RA 10173

Built around the Data Privacy Act

Clear roles, in writing — and fast when it matters.

01

Clear roles

Your clinic is the Controller; HeyDenta is your Processor — spelled out in the agreement you e-sign.

02

Fast breach notification

If a breach affecting your clinic occurs, we notify you within 24 hours so you can meet your reporting obligations to the NPC on time.

03

No selling, no AI training

We never sell patient data, and never use patient messages to train external AI models.

For your DPO or lawyer

Request the Trust Brief

Everything your data-protection officer or counsel needs to review HeyDenta — the documents themselves, not a wall of badges.

Request the Trust Brief →
Straight answers

Compliance, without the overstatement

Compliance is a journey, and we'd rather tell you exactly where we stand than overstate it. Ask us about any certification, registration, or safeguard and you'll get a direct answer — what's in place today, and what's on the roadmap.

Email privacy@getheydenta.com →
© 2026 HeyDenta · Pasig City, Philippines
PrivacyTermsCookies