Dr.AlignNavi
Privacy Policy
Effective date: 2026-05-29
1. Data we collect
- Account and contact data: user ID, name, email address, organization or clinic information, role, login and account status.
- Billing data: selected plan, payment status, transaction ID, subscription ID, customer ID, billing email, invoice and receipt records.
- Service data: simulation case identifiers, case status, usage history, uploaded case materials, dental records, images, scans, notes, or other materials submitted by authorized users.
- Technical data: IP address, device and browser information, access logs, security events, error logs, and operational monitoring records.
- Support data: inquiries, refund requests, troubleshooting records, and communications with our support team.
2. Purpose of processing
- Providing, maintaining, securing, and improving Dr.AlignNavi.
- Account verification, access control, subscription management, billing support, and payment status synchronization.
- Simulation workflow operation, case management, customer support, troubleshooting, and fraud or abuse prevention.
- Compliance with legal, tax, accounting, audit, dispute-resolution, and security obligations.
3. Patient and clinic data responsibility
- When a clinic uploads patient-related information, the clinic is responsible for obtaining and maintaining any patient consent, authorization, notice, or legal basis required by applicable law.
- We process submitted case materials to provide the service, support the clinic account, maintain security, and improve service quality where permitted by law.
- Users should avoid uploading unnecessary patient identifiers or materials unrelated to the requested simulation workflow.
4. Controller, processor, and regional compliance
- For our website, billing platform, sales inquiries, account administration, and support operations, we generally act as an independent data controller for the personal data we determine how to process.
- For patient data, health records, dental images, scans, and case materials uploaded by a clinic, the clinic is generally responsible for deciding the purpose and legal basis of processing, and we process that information to provide the service to the clinic.
- Where required by applicable law or customer agreement, patient data processing may be governed by a Data Processing Agreement, Business Associate Agreement, standard contractual clauses, or other written data protection terms.
- If a patient or end user asks us to exercise rights over patient data controlled by a clinic, we may direct the request to the relevant clinic or support the clinic in responding as required by law.
5. International transfers and service providers
- The billing platform is operated from the Republic of Korea, and some service providers, payment processors, support systems, or infrastructure providers may process data in other countries.
- Where international transfer rules apply, we take steps intended to use lawful transfer mechanisms or contractual safeguards required by applicable law.
- For customers subject to GDPR, UK GDPR, HIPAA, Korea PIPA, or other healthcare or privacy laws, additional notices, consent records, transfer terms, or contractual documents may be required before patient data is uploaded.
6. Payment processing and third parties
- Payments are processed through Paddle. Paddle may handle checkout, payment method data, fraud prevention, taxes, invoices, receipts, and refund processing as merchant of record where supported.
- We do not store full card numbers or payment authentication credentials on our servers.
- We may use hosting, security, monitoring, email, customer support, and analytics service providers as needed to operate the service.
7. AI-assisted features and human review
- AI-assisted simulation features are used to support dental and orthodontic professionals, not to make legally or clinically binding decisions without human review.
- Clinics remain responsible for reviewing outputs, communicating with patients, and making treatment-related decisions.
8. Retention and deletion
- Personal data is retained for as long as necessary to provide the service, manage billing, resolve disputes, maintain security, or meet legal obligations.
- Billing, tax, accounting, and audit records may be retained for the period required by applicable law.
- When retention is no longer required, data is deleted, anonymized, or securely isolated according to operational and legal requirements.
9. Security measures
- We apply reasonable technical and administrative safeguards, including HTTPS transport protection, access control, logging, backup, and monitoring.
- No internet-based service can be guaranteed to be completely secure, but we work to reduce risks and respond to security events in a timely manner.
10. User rights and requests
Users may request access, correction, deletion, suspension of processing, or other rights where permitted by applicable law. Requests can be sent to contact@innodtech.co.kr. We may need to verify the requester's identity and authority before processing a request.
11. Privacy contact
- Company
- 이노디테크 주식회사 (Innodtech)
- CEO
- 주보훈
- Business registration no.
- 306-81-37665
- Registered office
- 광주 북구 첨단과기로 123, 기업지원센터 A동 312호(오룡동, 광주과학기술원)
Room 312, Building A, Business Support Center, 123 Cheomdangwagi-ro, Buk-gu, Gwangju, Republic of Korea - Research office
- 서울특별시 강남구 강남대로 94길 27-11 투명교정센터 3층
3F, Transparent Orthodontic Center, 27-11 Gangnam-daero 94-gil, Gangnam-gu, Seoul, 06130, Republic of Korea - Contact
- contact@innodtech.co.kr / 02.501.2801