01Introduction & Who We Are
This Privacy Policy explains how Ark Dental Global ("we," "us," "our," or the "Clinic"), operating from R-27, 1st Floor, Greater Kailash 1, New Delhi โ 110048, India, collects, uses, shares, and protects personal information of patients, website visitors, and prospective patients.
This policy applies to all interactions with us โ whether you visit our clinic, browse www.arkdentalglobal.com, contact us via WhatsApp, email, phone, social media, or submit any form on our website.
By using our services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not provide personal information to us or use our services.
Legal Basis: This policy is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002.
02Information We Collect
We collect different types of information depending on how you interact with us.
2.1 Information You Provide Directly
- Contact details: Name, phone number, email address, WhatsApp number, postal address
- Demographic information: Age, gender, date of birth, nationality (for international patients)
- Medical history: Existing conditions, medications, allergies, dental history, family medical history
- Dental records: Clinical examinations, treatment plans, X-rays, CBCT scans, intraoral photographs, 3D scans (iTero), shade matches
- Financial information: Payment method, billing address, GST details (for invoicing), insurance details
- Communication records: WhatsApp messages, emails, call recordings (where lawfully recorded), form submissions
- Booking preferences: Treatment interests, preferred appointment times, contact method preferences
2.2 Information Collected Automatically
- Device information: Browser type, operating system, device type, screen resolution
- Usage data: Pages viewed, time spent, click patterns, scroll depth, referring website
- Network information: IP address (anonymised), approximate geographic location, internet service provider
- Cookies and similar technologies: See Section 6 below
2.3 Information from Third Parties
- Referrals: Information shared by referring physicians or other dental specialists
- Insurance providers: Coverage details and authorisations (with your consent)
- Marketing platforms: Lead data from Google Ads, Meta (Facebook/Instagram), justdial, Practo, NoBroker (where applicable)
03How We Use Your Information
We use your information only for legitimate purposes connected to providing dental care and improving our services:
- Treatment delivery: Diagnosing dental conditions, planning treatment, performing procedures, managing recovery
- Appointment management: Scheduling, reminders, follow-ups, rescheduling, post-treatment check-ins
- Communication: Responding to enquiries, sending consultation reports, treatment quotes, aftercare instructions
- Billing & payments: Processing payments, issuing invoices, managing EMI arrangements, insurance claims
- Quality improvement: Internal training, clinical audits, peer review (with identifiers removed)
- Legal compliance: Maintaining medical records as required by law, responding to legal requests
- Marketing (with consent): Sending newsletters, treatment offers, educational content via email or WhatsApp โ opt-out anytime
- Website analytics: Understanding which pages help patients, fixing technical issues, improving user experience
Our promise: We never use your medical information for advertising or commercial purposes. We never sell your data to third parties. We never share your records with any party without your explicit consent, except where required by law.
04Sensitive Personal Data & Medical Records
Under Indian law, certain categories of your information are classified as sensitive personal data and receive additional protection. This includes your medical and dental records, biometric information (intraoral scans, 3D dental models), financial information, and any health-related data.
4.1 Special Protections for Medical Data
- Doctor-patient confidentiality is maintained as per the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002
- Medical records are encrypted in transit and at rest
- Access is restricted to treating clinicians and authorised clinical staff only
- Records are stored on secured servers located in India
- Physical records are kept in locked, access-controlled storage
- Disposal of records follows secure shredding/permanent deletion protocols
4.2 Limited Use of Medical Data
Your medical information is used only for clinical care. We do not use medical data for any marketing, profiling, advertising, or non-clinical purpose. Sharing with third parties occurs only when:
- You provide explicit written consent (e.g., for sharing with another doctor)
- Required by law (court orders, regulatory authorities)
- Necessary for emergency medical treatment
- Required for working with our authorised dental laboratories (with anonymisation where possible)
05Photography & Smile Gallery
As a cosmetic dental practice, we frequently take clinical photographs as part of treatment. This includes before-and-after smile transformations, intraoral views, smile design simulations, and X-rays.
5.1 Clinical Photography
All patients undergoing cosmetic, restorative, or orthodontic treatment will have clinical photographs taken as part of standard treatment documentation. These are stored in your patient file and used solely for:
- Treatment planning and progress monitoring
- Before-and-after comparison
- Internal clinical review and quality assurance
- Continuing education (with identifying features removed)
5.2 Smile Gallery & Marketing Use
Important โ Opt-in only: Your photographs will never appear on our website, social media, marketing materials, or printed brochures without your separate, explicit written consent. Standard clinical photography (for your file) does not authorise marketing use.
If you choose to share your transformation with our Smile Gallery, you will sign a separate Photography & Marketing Consent Form with these options:
- Choose what to publish: face vs. mouth-only crops
- Choose attribution: full name, first name only, initials, or anonymous
- Choose channels: website only, social media only, printed materials, all
- Choose duration: 1 year, 3 years, indefinite (with revocation rights)
5.3 Right to Withdraw Photo Consent
You can withdraw photography consent at any time by writing to care@arkdental.in or our Grievance Officer (Section 14). Upon receiving your withdrawal:
- Photos will be removed from our website within 14 working days
- Photos will be removed from active social media accounts within 14 working days (we cannot guarantee removal from third-party reposts/screenshots already in circulation)
- Photos will be permanently deleted from marketing archives
- Clinical photos in your medical file are retained per medical record retention requirements (Section 12)
06Cookies & Website Analytics
Our website uses cookies and similar technologies to provide a better user experience and understand site usage.
6.1 Types of Cookies We Use
- Essential cookies: Required for site functionality (form submissions, language preferences). Cannot be disabled.
- Analytics cookies: Google Analytics 4 โ helps us understand which pages are useful. Anonymised IP addresses; no personal identification.
- Advertising cookies: Google Ads, Meta Pixel โ used to measure ad campaign effectiveness and show relevant ads. Opt-in via consent banner.
- Functionality cookies: Remember your preferences (e.g., closed pop-ups, video play state).
6.2 Managing Cookies
You can control cookies through:
- Our cookie consent banner (shown on first visit)
- Your browser settings (block, delete, or limit cookies)
- Industry opt-out tools: youronlinechoices.com, Google Ad Settings
Note: Disabling essential cookies may prevent forms from working correctly.
6.3 Do Not Track
We respect "Do Not Track" browser signals for analytics where technically feasible. Marketing cookies require explicit opt-in regardless of DNT.
07Third-Party Services & Sharing
We share specific information with carefully selected service providers under contractual data protection obligations. We do not sell your data.
7.1 Categories of Third-Party Recipients
- Dental laboratories: For manufacturing veneers, crowns, dentures, aligners. Receive only clinical data needed (impressions, scans, shade) โ never your contact details.
- Payment processors: Razorpay, PayU, bank gateways โ for processing card payments and UPI transactions. They receive only payment-relevant data.
- Communication services: Twilio (SMS), WhatsApp Business API (Meta), email services for appointment reminders and notifications.
- Analytics providers: Google Analytics, Microsoft Clarity, Hotjar โ receive anonymised website usage data, never medical information.
- Advertising platforms: Google Ads, Meta โ receive only conversion event data (e.g., "someone booked") for campaign optimisation, never your identity.
- IT & cloud services: Hosting providers, backup services, email providers โ bound by Data Processing Agreements.
- Professional services: Chartered accountants, lawyers โ only when specifically required and bound by professional confidentiality.
7.2 When We May Be Required to Disclose
- To comply with legal obligations (court orders, regulatory requests)
- To protect our legal rights or defend against legal claims
- In the event of medical emergencies where consent cannot be obtained
- To prevent fraud or harm to patients, staff, or third parties
- In the event of a business transition (merger, acquisition) โ with patient notification
08International Patient Data Transfer
We serve patients from over 40 countries. When you contact us as an international patient or undergo treatment, your data may be transferred internationally.
8.1 What This Involves
- Video consultation platforms (Zoom, WhatsApp, Google Meet) may route data through servers outside India
- Email correspondence may transit through international email services
- If you provide insurance details from outside India, we may communicate with your home-country insurance provider
- Your medical records may be shared with your home-country dentist for continuity of care (with your written consent)
8.2 Safeguards in Place
- All transfers use encrypted channels (SSL/TLS, end-to-end where available)
- Recipients are bound by data protection obligations
- You consent to international transfer when sharing data with us
- EU/UK patients: Standard Contractual Clauses (SCCs) are used where applicable
09Data Security & Storage
We implement reasonable security practices and procedures in compliance with IT Rules 2011 and IS/ISO/IEC 27001 standards.
9.1 Technical Safeguards
- SSL/TLS encryption for all data in transit
- AES-256 encryption for data at rest
- Multi-factor authentication for clinical staff accessing records
- Role-based access controls (only authorised personnel access relevant data)
- Regular security audits and vulnerability assessments
- Encrypted backups stored in geographically separate locations
- Secure firewalls, intrusion detection, anti-malware on all systems
9.2 Organisational Safeguards
- Staff confidentiality agreements (NDAs)
- Regular data protection training for all employees
- Clean-desk policy at the clinic
- Visitor access controls
- CCTV monitoring of clinical areas (footage retained 30 days)
Important: While we implement industry-standard security measures, no system is 100% secure. We cannot guarantee absolute security of data transmitted over the internet. In the event of a data breach affecting your information, we will notify affected individuals and the Data Protection Board within 72 hours, as required by law.
10Your Rights as a Data Principal
Under the Digital Personal Data Protection Act, 2023, you have specific rights regarding your personal data. You may exercise these by writing to our Grievance Officer.
10.1 Right to Access
Obtain a copy of the personal information we hold about you, along with details of how it's being processed.
10.2 Right to Correction
Update incorrect, incomplete, or outdated information in your records.
10.3 Right to Erasure
Request deletion of your personal data when no longer required for the purpose it was collected (subject to medical record retention requirements โ Section 12).
10.4 Right to Withdraw Consent
Revoke previously given consent for processing (including marketing, photography, etc.). Withdrawal does not affect the lawfulness of processing before withdrawal.
10.5 Right to Data Portability
Receive your data in a structured, commonly-used, machine-readable format. Useful when switching dental practitioners.
10.6 Right to Grievance Redressal
If we have not addressed your concern satisfactorily, you may contact the Data Protection Board of India (when established under DPDPA 2023).
10.7 Right to Nominate
You may nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
How to exercise your rights: Email
care@arkdental.in with the subject "Privacy Rights Request" or write to our Grievance Officer (Section 14). We respond to all requests within
30 working days. Identity verification may be required to protect your records.
11Children's Privacy & Minors
We provide paediatric dental care for children of all ages. For patients under 18 years:
- Treatment requires parental or legal guardian consent
- Personal data is collected from the guardian, not directly from the child
- Marketing communications are sent only to parents/guardians, never to minors
- Photographs of minors require both parental written consent and appropriateness review
- Children's identifying information is never used in marketing materials without explicit guardian consent
- Records of paediatric patients are retained until the patient reaches age 25 (per medical record requirements) and may be transferred to them upon adulthood with their consent
12Data Retention Periods
We retain personal information only as long as necessary for the purposes outlined.
- Medical & dental records: Minimum 10 years from last treatment, or until patient is 25 (whichever is later) โ per Indian medical record retention guidelines
- Cosmetic dental records (veneers, implants): Lifetime of restoration plus 10 years
- Financial records: 8 years (income tax requirement)
- Marketing communications data: Until you opt out + 6 months
- Website form submissions (non-patient): 12 months
- Cookies: Session cookies โ until browser closed; persistent cookies โ 1-24 months depending on type
- CCTV footage: 30 days unless required for investigation
- Call recordings (where applicable): 90 days
After retention periods expire, data is securely deleted (digital) or shredded (physical).
13Updates to This Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in law or regulatory guidance
- Changes in our services or operations
- Improvements in privacy practices
- Patient feedback
How we notify you of changes:
- The "Last updated" date at the top of this policy will change
- For material changes affecting your rights, we will notify you via email or WhatsApp (if you've shared these), display a banner on our website for 30 days, and request renewed consent where required by law
- Continued use of our services after notification implies acceptance
14Grievance Officer & Contact
As required by India's IT Rules 2011 and DPDPA 2023, we have designated a Grievance Officer to address privacy concerns and data protection requests. All complaints are acknowledged within 24 hours and resolved within 15 working days where possible.
Designated Grievance Officer
For privacy concerns, data access requests, complaints, or to exercise your rights under DPDPA 2023:
Officer Name
Dr. Ameet S. Dixit
Director & Data Protection Officer
Postal Address
Ark Dental Global
R-27, 1st Floor, GK-1
New Delhi โ 110048
14.1 What to Include in Your Privacy Request
- Your full name and contact details
- Patient ID (if applicable)
- Specific right you wish to exercise (access, correction, deletion, etc.)
- Details of your concern or request
- Proof of identity (PAN, Aadhaar, passport โ for security verification)
14.2 If You're Not Satisfied
If our response does not satisfy your concerns, you may escalate to:
- Data Protection Board of India (under DPDPA 2023, once operational)
- Ministry of Electronics and Information Technology (MeitY)
- Dental Council of India for clinical record-related grievances
- Consumer courts for service-related disputes
Document Version: 2.1 ยท Effective: 1 January 2026 ยท Last Updated: 22 May 2026
ยฉ 2026 Ark Dental Global. This privacy policy is a legal document. For any clarifications, please contact our Grievance Officer.