Smile Konnect Privacy

Privacy Policy

We built Smile Konnect so Canadian dental teams can coordinate care without compromising privacy. This policy describes what personal information we collect, how we use it, and the safeguards that keep clinics compliant with PHIPA.

Last updated: November 17, 2025

1. Information we collect

We only collect data needed to deliver secure messaging, onboarding, and compliance tooling.

Account & profile data

Names, roles, clinic affiliations, contact details, MFA preferences, and audit metadata captured during authentication workflows.

  • Patient onboarding questionnaires and referral data collected through the introductory inquiry flows
  • Clinic settings such as consent templates, notification rules, and export preferences

Clinical communications

Secure chat transcripts, file uploads, images, activation notes, and change logs generated inside Smile Konnect features.

  • Each chat thread is tied to a clinic and retains timestamps, participants, and consent references
  • File metadata includes checksum, uploader, and purpose tags for auditability

Telemetry & device context

Browser fingerprints, IP addresses, device IDs, and MFA trust decisions that help detect fraud and meet PHIPA safeguards.

  • Session manager captures login history, throttling, and logout reasons
  • Virtual care questionnaires log form drafts to local storage until submission

2. How we use information

We process PHI strictly within the patient\'s circle of care and to maintain the safety of the platform.

Care coordination

Dentists and clinic staff use PHI to manage activation workflows, review patient intake history, and follow up on secure messages.

Security & compliance

AuditLoggingInterceptor, Consent domains, and Export controls all rely on system metadata to evidence PHIPA, HIPAA, and RCDSO compliance.

Product research

Aggregated, de-identified metrics help us understand feature adoption (e.g., video consults vs. secure chat). We do not sell PHI or share it for advertising.

3. Retention & deletion

Retention policies balance regulatory minimums with patient choice.

Default retention windows

We follow the longer of PHIPA or RCDSO retention requirements. Clinic-specific retention rules can be configured per export type.

  • Chat transcripts, audit logs, and export events: minimum seven (7) years
  • Consent artifacts: retained for the life of the patient record plus seven (7) years
  • Account metadata: retained while the user has an active clinic relationship and up to 24 months after inactivity

Deletion requests

When legal retention allows, we delete or anonymize PHI within 30 days of clinic confirmation. Backups roll off after 35 days.

4. Data sharing & processors

We never sell PHI. Limited sharing occurs only to deliver the services or satisfy legal requirements.

Sub-processors

Email, SMS, and push notification providers process limited PHI (names, appointment context) to deliver patient outreach. Each provider signs PHIPA/HIPAA agreements and undergoes security reviews.

Regulatory & legal disclosures

We may disclose PHI when required by law, court order, or to report privacy breaches to the Office of the Information and Privacy Commissioner of Ontario (IPC).

Clinic integrations

If a clinic connects Smile Konnect to other systems (e.g., PMS, analytics), the clinic remains responsible for configuring those integrations and honouring PHI obligations.

5. Security safeguards

Security is embedded in every layer of Smile Konnect.

Encryption & key management

Data in transit uses TLS 1.3 while data at rest is encrypted with AES-256. Keys are rotated with backend/scripts/generate-encryption-keys.js and stored outside the repo.

Access controls

RBAC in the NestJS API restricts endpoints by role. Multi-factor authentication, device trust, and throttling guard patient accounts.

Monitoring & response

Real-time alerts flag suspicious exports, mass downloads, or login anomalies. Incidents trigger a documented response plan and notification workflow.

6. Your rights

We help clinics honour PHIPA patient rights quickly and transparently.

Request access or copies

Patients may request a digital export of their records through their clinic. Smile Konnect provides the Export Center tooling so clinics can respond within statutory timelines.

Withdraw consent

Patients can pause chat threads, revoke specific consents, or close their account. Clinics remain responsible for legal retention minimums.

Report a concern

Contact privacy@smilekonnect.ca with the clinic name, your contact details, and a description of the concern. We acknowledge requests within two business days.

For PHIPA escalations you can also contact the Information and Privacy Commissioner of Ontario.