See exactly how information moves through HeyDenta — from a patient's first hello to a booked appointment — and how it stays protected under the Data Privacy Act.
Call, chat or Messenger
In Taglish, in real time
Consent asked at intake
Encrypted & access-logged
Export or delete any time
The controls behind every record — no jargon, no overstatement.
TLS in transit, encryption at rest.
Per-clinic separation keeps your patients and records apart from every other clinic's.
Access is role-based, and system access is logged.
A managed database in Northeast Asia (Seoul), on Supabase & Vercel infrastructure.
The AI receptionist is built to capture only what a booking needs.
Every AI call opens by telling the caller it's recorded; identifiers are redacted from stored transcripts; recordings deleted after 30 days.
Aria handles inquiries, booking and follow-ups; clinically significant questions are escalated to your team. You set what it can do.
Patients consent to how their details are used as part of the intake step.
Where a message is processed by an AI provider outside the country, identifying details are redacted first.
Clear roles, in writing — and fast when it matters.
Your clinic is the Controller; HeyDenta is your Processor — spelled out in the agreement you e-sign.
If a breach affecting your clinic occurs, we notify you within 24 hours so you can meet your reporting obligations to the NPC on time.
We never sell patient data, and never use patient messages to train external AI models.
Everything your data-protection officer or counsel needs to review HeyDenta — the documents themselves, not a wall of badges.
Compliance is a journey, and we'd rather tell you exactly where we stand than overstate it. Ask us about any certification, registration, or safeguard and you'll get a direct answer — what's in place today, and what's on the roadmap.
Email privacy@getheydenta.com →