This Policy explains how the Company handles information in connection with the SmileStudio platform (the "Service") and the website at simulateasmile.com. The Service is a sales tool provided to licensed dental and orthodontic practices ("Practices"). Where materials reach a Practice's patients, they do so at the Practice's decision and direction.
At a glance: we process patient information only on a Practice's behalf and instruction · we do not sell personal information or use it for advertising · we do not use patient information to train AI models · we do not track email opens or clicks · patients should contact their own dental practice about their information.
Website visitors. For information collected on our public website, the Company is the controller.
Practices (our customers). For the account and billing information of a Practice and its staff, the Company is the controller.
Patients of a Practice. Patient information is provided to us by the Practice and processed only on the Practice's behalf and instruction. The Practice is the controller and the Company acts as processor. Where the Practice is a HIPAA covered entity, we act as its Business Associate under a signed Business Associate Agreement ("BAA"). Patients who have questions about their information should contact their dental practice, which controls that information.
The Company is established in Spain. Where the General Data Protection Regulation (EU) 2016/679 ("GDPR") applies to our processing, this Policy is written to meet its transparency requirements alongside our obligations under HIPAA.
We do not collect or store patient phone numbers. Where a Practice chooses to message a patient by SMS or WhatsApp, that message is sent from the Practice's own device and number; it does not pass through our systems.
Standard server logs (IP address, browser type, and pages requested), used for security and troubleshooting, and any information you choose to send us through a contact form or by email. The website does not use analytics or advertising trackers.
Where we are the controller, our lawful bases under Article 6 GDPR are:
| What | Why | Lawful basis |
|---|---|---|
| Practice and staff account data | To create and operate the account, authenticate users, and provide support | Art. 6(1)(b) — contract |
| Subscription billing data | To take payment and meet accounting and tax obligations | Art. 6(1)(b) contract; 6(1)(c) legal obligation |
| Security audit logs, session records, IP addresses | To protect a system that holds health information, detect misuse, and meet our security obligations | Art. 6(1)(f) — legitimate interests |
| Website server logs | Security and troubleshooting | Art. 6(1)(f) — legitimate interests |
| Service-related messages to Practices | To notify about the Service, security, and billing | Art. 6(1)(b); 6(1)(f) |
Where we are the processor — that is, for all patient information — we process only on the Practice's documented instructions. The Practice determines the purpose and the legal basis, including any condition required for health data under Article 9.
We use patient information only to provide the Service to the Practice. We do not use it for our own marketing, we do not sell it, and we do not use it to train artificial-intelligence models.
We use a small number of vetted providers to operate the Service. Each receives only the minimum information needed for its function, under written data-protection terms — including, where PHI is concerned, the protections required by our BAA.
Cloud hosting and storage. Patient records and photographs are stored in per-Practice isolated storage. Our hosting provider acts as our processor under a data processing agreement, and a Business Associate Agreement is in force.
Email delivery. Service and patient-facing email is delivered by our mail provider, which acts as our processor under a data processing agreement, with a Business Associate Agreement in force.
AI processing. Patient photographs are never provided to any text-AI provider. The AI processing that generates the visualization receives only a cropped region of the photograph centred on the mouth, not the whole face, and uses it solely to generate the requested visualization, under contractual data-protection terms and without using it to train its models. No name, case reference, date or file metadata travels with the image, and location metadata is removed before storage. The complete image a Practice sees is assembled on our own systems; the AI provider neither receives nor produces it. The AI processing that drafts letter text receives no images at all, receives a placeholder in place of the patient's name, and receives clinical notes only after automated removal of identifying details.
Payments. Card data never touches our servers. Our payment provider processes billing information partly as our processor and partly as an independent controller in its own right — for fraud prevention, anti-money-laundering and know-your-customer screening, regulatory compliance, and improving its own services. For that part of the processing, the payment provider determines its own purposes and means, and its own privacy policy applies.
A current, detailed list of subcontractors that may handle PHI, including the specific safeguards applied to each, is available to Practices on request via legal@simulateasmile.com. Practices under a BAA are notified of material changes in accordance with that agreement.
When a Practice shares results with a patient, the patient receives a private link containing a long, randomly generated code. The link requires no account and is valid for 30 days, after which it expires. Anyone in possession of the link can view the preview during that period; the Practice controls to whom the link is given. Preview pages are served over encrypted connections and are not indexed.
Where a BAA applies, retention and return or destruction of PHI on termination follow the BAA.
The Service is built with layered safeguards, including: two-factor authentication required for all password-based accounts (accounts that sign in with Google or Microsoft inherit that provider's authentication in place of a separate app code); automatic account lockout after repeated failed attempts; request rate limiting; protection against cross-site request forgery on all state-changing actions; encryption in transit (TLS 1.2+) and at rest (AES-256); per-Practice isolated storage — data is never commingled; location metadata (EXIF/GPS) stripped from all uploaded photographs before storage; hashed password storage; session inactivity timeouts; role-based access controls that isolate each Practice's data; and comprehensive security audit logging.
We test these controls rather than assume them: our storage isolation, data-destruction, privilege-boundary and backup-restore procedures are exercised against the live system and the results recorded.
No system is perfectly secure, and we encourage Practices to report suspected issues to legal@simulateasmile.com.
If you are a patient of a Practice, the Practice controls your information. Please direct requests to access, correct, delete, or restrict the use of your information to your dental practice. When a Practice instructs us to act on such a request, we do so within fifteen (15) business days, consistent with the BAA where applicable. If you contact us directly, we will forward your request to the Practice and tell you that we have done so.
If you are a Practice, a member of Practice staff, or a website visitor, and the GDPR applies to your data, you have the right to:
To exercise any of these, contact legal@simulateasmile.com. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.
In plain terms. To delete your account and the data associated with it, e-mail privacy@simulateasmile.com. To ask what we hold about you, or to have it corrected or exported, use the same address. We reply within fifteen business days.
You also have the right to complain to a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD), www.aepd.es. You may also complain to the authority in your country of residence or place of work.
The Service records whether a patient is a minor so that Practices can apply appropriate care. Obtaining any parental or guardian consent required for a minor's photographs and information is the responsibility of the Practice. The Service is not offered to consumers and is not directed at children.
The Company is established in Valencia, Spain. Service data, including patient information and photographs, is hosted in data-center regions located in the United States.
Where personal data protected by the GDPR is transferred outside the European Economic Area, we rely on the transfer mechanisms permitted under Chapter V — principally the Standard Contractual Clauses adopted by the European Commission, and, where the recipient is certified, the EU–U.S. Data Privacy Framework. Our hosting, email and payment providers are each covered by such a mechanism. A copy of the relevant safeguards is available on request via legal@simulateasmile.com.
Information may also be processed in other locations where our providers operate, subject to the same safeguards and, for PHI, the BAA.
The Service uses strictly necessary cookies only: a session cookie that keeps staff signed in securely, and related security tokens. We do not use advertising or cross-site tracking cookies, and no consent banner is required for cookies that are strictly necessary to provide a service you have requested.
We may update this Policy from time to time. The effective date above reflects the latest revision. Material changes will be notified to Practices.
Privacy questions and requests: legal@simulateasmile.com
Ibercom Comercio Industrial, S.L. (operating as SmileStudio)
C/ Marina Alta 4, Esc. 12, 8, 46015 Valencia, Spain
Leave your details and we will find a 20 minute slot that fits around your clinic day.
We will be in touch shortly to book your session.