Compliance First

Legal, Privacy, and PHIPA commitments

Smile Konnect unifies patient communication, onboarding, and audit defense for multi-clinic dental groups. Review the contractual terms, privacy controls, and PHIPA safeguards that govern every workflow in the platform.

Platform guardrails

Everything inside Smile Konnect is built for PHIPA-class privacy and verifiable audit readiness.

Purpose-built for Canadian clinics

Smile Konnect centralizes secure chat, onboarding, consent workflows, and clinic management for Ontario dental teams.

  • Role-specific workspaces for admin, dentist, and patient cohorts
  • Mock authentication on the frontend with production-ready NestJS API
  • AuditLoggingInterceptor on every backend request

Security & privacy from day one

Encryption keys are managed outside the repo, MFA is required for privileged roles, and consent prompts are enforced for file/image uploads.

  • AES-256 encryption at rest with TLS 1.3 in transit
  • Mandatory consent capture for chat, files, and images
  • Comprehensive export logging and drill-down audit trails

Canadian data residency

All Primary Postgres storage layers run inside Canadian regions with strict firewalling and throttled ingestion.

  • Environment-driven connection strings and role-separated DB credentials
  • Daily encrypted backups with 35-day point-in-time coverage
  • Clinic data segregation via tenant-aware queries

Patient rights & clinic duties

Smile Konnect bakes provincial privacy obligations directly into the workflows clinics use every day.

Transparent consent & revocation

Patients can see every consent they provided across chat threads, uploads, and referrals, and can request revocation via secure messaging.

Access & portability

Export Center tooling lets clinics rapidly produce machine-readable chat transcripts, activation data, and audit logs for patient requests.

Breach notifications

In the event of an incident, Smile Konnect follows PHIPA notification timelines and documents every remediation task in the audit ledger.

Data Residency

Production deployments store PHI on Canadian Postgres clusters behind private networking. Keys are rotated through the encryption toolkit.

Auditability

Every action is piped through the AuditLoggingInterceptor so clinics can evidence PHIPA, HIPAA, and RCDSO controls within minutes.