Smile Konnect Legal

Terms & Conditions

These terms describe how Smile Konnect enables PHIPA-ready communication between dentists, clinic teams, and their patients. By creating an account or using the services you agree to the commitments below.

Last updated: November 17, 2025

1. Purpose & eligibility

Smile Konnect is a PHIPA-aligned workspace for Canadian dental groups. Every workspace is provisioned to a clinic or dental service operator that has executed a services agreement with Smile Konnect.

Circle-of-care collaboration

The platform is designed for intra-clinic messaging, onboarding, and file exchange between dentists, clinic administrators, and their registered patients. Emergency use is prohibited and the platform does not replace in-person clinical judgement.

  • Dentists and administrators must be licensed in their jurisdiction and maintain good standing
  • Patients must be invited by a participating clinic or complete the registration workflow and await activation
  • Third parties (vendors, consultants) require written authorization and least-privilege access profiles

Mock vs. production modes

The Next.js frontend currently runs with mock authentication for demos while the NestJS API enforces JWT, MFA, and audit logging. When connected to production services you must ensure all staff use hardware- or app-based MFA.

2. Account responsibilities

You are responsible for safeguarding credentials, devices, and clinic-issued hardware used to access Smile Konnect.

Secure access

Accounts are role-based (admin, dentist, patient). Users must: (a) configure MFA, (b) only access data for patients under their care, and (c) immediately report suspected compromise to Smile Konnect support at privacy@smilekonnect.ca.

  • Do not share credentials or leave sessions unattended on shared workstations
  • Keep operating systems and browsers patched to supported versions
  • Use approved clinics networks or VPNs when handling PHI

Acceptable use

Prohibited actions include uploading malware, attempting to circumvent security controls, scraping or reselling platform data, or storing non-dental PHI for unrelated clinics. Smile Konnect may suspend access to preserve system integrity.

3. Patient data & consent

Clinic teams must maintain valid consent before collecting or sharing personal health information (PHI).

Ownership & stewardship

Clinics retain ownership of their PHI while granting Smile Konnect a limited licence to host, process, and transmit data solely to provide the services.

  • Audit logs for every chat, export, and notification are retained for at least seven years
  • Uploaded documents and images become part of the patient record and inherit the clinic's retention policy
  • Patients can request exports or deletion subject to PHIPA statutory retention windows

Consent workflows

Clinic action required

Built-in consent modals (EnhancedConsentDialog) capture approvals before starting chat sessions or sharing media. Clinics must configure the wording to reflect their internal policies. Additional consent terms may reference the consent definitions stored in the backend consent domain so that legal language stays versioned.

Need the details on privacy handling? Read our Privacy Policy and PHIPA Compliance Statement.

4. Platform operations

Smile Konnect provides 24/7 infrastructure monitoring with a 99.5% monthly uptime target.

Service changes

We may introduce new features, modify interfaces, or discontinue beta capabilities. Material changes to privacy or data handling will be communicated via in-app notifications and email.

Third-party services

Infrastructure is hosted on Canadian cloud providers with encrypted backups. Email, SMS, and video services rely on audited sub-processors that are contractually bound to PHIPA/HIPAA standards.

5. Suspension & termination

Smile Konnect may suspend or terminate access if accounts become delinquent, breach obligations, or pose a security risk.

Clinic offboarding

Upon termination we provide 30 days of read-only access to export PHI. After that window data moves to encrypted archival storage for the remainder of statutory retention periods.

Patient requests

Patients can deactivate self-service accounts at any time. Clinics remain responsible for downstream medical record retention.

6. Governing law & updates

These terms are governed by the laws of Ontario and the federal laws of Canada as applicable.

Versioning

Revisions take effect 30 days after posting unless they relate to urgent security, compliance, or product updates that require immediate enforcement. The "Last updated" date is noted near the top of every document.

Contact

Questions can be sent to privacy@smilekonnect.ca. Include clinic identifiers, impacted patients (if any), and a callback number so we can respond promptly.