✦SmileStudio Schedule a free demo
  • ✦SmileStudio
  • How it works
  • Pricing
  • Insights
  • Contact
  • Schedule a free demo

Privacy Policy

Privacy policy SmileStudio
Last update, 30 August 2026

On this page

1. The three roles we play 2. Information we collect 3. Why we process it 4. Service providers & AI 5. What we never do 6. Patient preview links 7. Retention 8. Security 9. Your rights 10. Minors 11. International transfers 12. Cookies 13. Changes 14. Contact

This Policy explains how the Company handles information in connection with the SmileStudio platform (the "Service") and the website at simulateasmile.com. The Service is a sales tool provided to licensed dental and orthodontic practices ("Practices"). Where materials reach a Practice's patients, they do so at the Practice's decision and direction.

At a glance: we process patient information only on a Practice's behalf and instruction · we do not sell personal information or use it for advertising · we do not use patient information to train AI models · we do not track email opens or clicks · patients should contact their own dental practice about their information.

1. The three roles we play

Website visitors. For information collected on our public website, the Company is the controller.

Practices (our customers). For the account and billing information of a Practice and its staff, the Company is the controller.

Patients of a Practice. Patient information is provided to us by the Practice and processed only on the Practice's behalf and instruction. The Practice is the controller and the Company acts as processor. Where the Practice is a HIPAA covered entity, we act as its Business Associate under a signed Business Associate Agreement ("BAA"). Patients who have questions about their information should contact their dental practice, which controls that information.

The Company is established in Spain. Where the General Data Protection Regulation (EU) 2016/679 ("GDPR") applies to our processing, this Policy is written to meet its transparency requirements alongside our obligations under HIPAA.

2. Information we collect

From Practice staff (our direct users)

  • Name, email address, and password (passwords are stored only in hashed form)
  • Two-factor authentication enrollment data and one-time recovery codes
  • Session records, IP address, and login timestamps
  • A security audit log of relevant actions (sign-ins, failed attempts, administrative changes)

From Practices about their patients (processed on the Practice's behalf)

  • Patient first and last name
  • Date of birth (optional, if the Practice records it)
  • The Practice's own internal patient reference (optional)
  • Preferred language
  • Photographs uploaded by the Practice (before/after images and generated visualizations)
  • Treatment type and notes entered by Practice staff

We do not collect or store patient phone numbers. Where a Practice chooses to message a patient by SMS or WhatsApp, that message is sent from the Practice's own device and number; it does not pass through our systems.

From website visitors

Standard server logs (IP address, browser type, and pages requested), used for security and troubleshooting, and any information you choose to send us through a contact form or by email. The website does not use analytics or advertising trackers.

3. Why we process it, and on what legal basis

Where we are the controller, our lawful bases under Article 6 GDPR are:

WhatWhyLawful basis
Practice and staff account dataTo create and operate the account, authenticate users, and provide supportArt. 6(1)(b) — contract
Subscription billing dataTo take payment and meet accounting and tax obligationsArt. 6(1)(b) contract; 6(1)(c) legal obligation
Security audit logs, session records, IP addressesTo protect a system that holds health information, detect misuse, and meet our security obligationsArt. 6(1)(f) — legitimate interests
Website server logsSecurity and troubleshootingArt. 6(1)(f) — legitimate interests
Service-related messages to PracticesTo notify about the Service, security, and billingArt. 6(1)(b); 6(1)(f)

Where we are the processor — that is, for all patient information — we process only on the Practice's documented instructions. The Practice determines the purpose and the legal basis, including any condition required for health data under Article 9.

We use patient information only to provide the Service to the Practice. We do not use it for our own marketing, we do not sell it, and we do not use it to train artificial-intelligence models.

4. Service providers and AI processing

We use a small number of vetted providers to operate the Service. Each receives only the minimum information needed for its function, under written data-protection terms — including, where PHI is concerned, the protections required by our BAA.

Cloud hosting and storage. Patient records and photographs are stored in per-Practice isolated storage. Our hosting provider acts as our processor under a data processing agreement, and a Business Associate Agreement is in force.

Email delivery. Service and patient-facing email is delivered by our mail provider, which acts as our processor under a data processing agreement, with a Business Associate Agreement in force.

AI processing. Patient photographs are never provided to any text-AI provider. The AI processing that generates the visualization receives only a cropped region of the photograph centred on the mouth, not the whole face, and uses it solely to generate the requested visualization, under contractual data-protection terms and without using it to train its models. No name, case reference, date or file metadata travels with the image, and location metadata is removed before storage. The complete image a Practice sees is assembled on our own systems; the AI provider neither receives nor produces it. The AI processing that drafts letter text receives no images at all, receives a placeholder in place of the patient's name, and receives clinical notes only after automated removal of identifying details.

Payments. Card data never touches our servers. Our payment provider processes billing information partly as our processor and partly as an independent controller in its own right — for fraud prevention, anti-money-laundering and know-your-customer screening, regulatory compliance, and improving its own services. For that part of the processing, the payment provider determines its own purposes and means, and its own privacy policy applies.

A current, detailed list of subcontractors that may handle PHI, including the specific safeguards applied to each, is available to Practices on request via legal@simulateasmile.com. Practices under a BAA are notified of material changes in accordance with that agreement.

5. What we deliberately do not do

  • We do not sell personal information, and we do not share it for advertising.
  • We do not use patient information to train AI models.
  • We do not track whether patients open or click emails transmitted at a Practice's direction (engagement tracking is disabled by design).
  • We do not send SMS or WhatsApp messages to patients; the Practice does, from its own device.
  • We do not carry out automated decision-making that produces legal or similarly significant effects (Art. 22 GDPR). Any AI-generated visualization or draft letter is reviewed and approved by the Practice before a patient sees it.

6. Patient preview links

When a Practice shares results with a patient, the patient receives a private link containing a long, randomly generated code. The link requires no account and is valid for 30 days, after which it expires. Anyone in possession of the link can view the preview during that period; the Practice controls to whom the link is given. Preview pages are served over encrypted connections and are not indexed.

7. Retention

  • Patient photographs: stored in the Practice's own isolated storage and retained as part of the Practice's case records until the Practice deletes them or the subscription ends.
  • Case and patient records: retained for the duration of the Practice's subscription; upon cancellation, data is securely deleted within 30 days. A full data export is provided within 15 business days of request.
  • Practice account and billing records: retained as required for legal, accounting, and tax purposes.
  • Security audit logs: retained for a minimum of one (1) year. Audit records are not deleted on request: they are the record of who did what to whom, they are required by law, and deleting them on demand would destroy the very evidence that protects data subjects. This is a lawful restriction on the right to erasure (Art. 17(3)(b) GDPR).
  • Patient preview links: expire automatically after 30 days.

Where a BAA applies, retention and return or destruction of PHI on termination follow the BAA.

8. Security

The Service is built with layered safeguards, including: two-factor authentication required for all password-based accounts (accounts that sign in with Google or Microsoft inherit that provider's authentication in place of a separate app code); automatic account lockout after repeated failed attempts; request rate limiting; protection against cross-site request forgery on all state-changing actions; encryption in transit (TLS 1.2+) and at rest (AES-256); per-Practice isolated storage — data is never commingled; location metadata (EXIF/GPS) stripped from all uploaded photographs before storage; hashed password storage; session inactivity timeouts; role-based access controls that isolate each Practice's data; and comprehensive security audit logging.

We test these controls rather than assume them: our storage isolation, data-destruction, privilege-boundary and backup-restore procedures are exercised against the live system and the results recorded.

No system is perfectly secure, and we encourage Practices to report suspected issues to legal@simulateasmile.com.

9. Your rights

If you are a patient of a Practice, the Practice controls your information. Please direct requests to access, correct, delete, or restrict the use of your information to your dental practice. When a Practice instructs us to act on such a request, we do so within fifteen (15) business days, consistent with the BAA where applicable. If you contact us directly, we will forward your request to the Practice and tell you that we have done so.

If you are a Practice, a member of Practice staff, or a website visitor, and the GDPR applies to your data, you have the right to:

  • access the personal data we hold about you (Art. 15);
  • rectify inaccurate or incomplete data (Art. 16);
  • erase your data, where one of the grounds in Art. 17 applies — noting the audit-log exception in Section 7;
  • restrict processing in the circumstances set out in Art. 18;
  • data portability for data you provided to us, where processing is based on contract or consent and carried out by automated means (Art. 20);
  • object to processing based on our legitimate interests, on grounds relating to your particular situation (Art. 21).

To exercise any of these, contact legal@simulateasmile.com. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.

In plain terms. To delete your account and the data associated with it, e-mail privacy@simulateasmile.com. To ask what we hold about you, or to have it corrected or exported, use the same address. We reply within fifteen business days.

You also have the right to complain to a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD), www.aepd.es. You may also complain to the authority in your country of residence or place of work.

10. Minors

The Service records whether a patient is a minor so that Practices can apply appropriate care. Obtaining any parental or guardian consent required for a minor's photographs and information is the responsibility of the Practice. The Service is not offered to consumers and is not directed at children.

11. International transfers

The Company is established in Valencia, Spain. Service data, including patient information and photographs, is hosted in data-center regions located in the United States.

Where personal data protected by the GDPR is transferred outside the European Economic Area, we rely on the transfer mechanisms permitted under Chapter V — principally the Standard Contractual Clauses adopted by the European Commission, and, where the recipient is certified, the EU–U.S. Data Privacy Framework. Our hosting, email and payment providers are each covered by such a mechanism. A copy of the relevant safeguards is available on request via legal@simulateasmile.com.

Information may also be processed in other locations where our providers operate, subject to the same safeguards and, for PHI, the BAA.

12. Cookies

The Service uses strictly necessary cookies only: a session cookie that keeps staff signed in securely, and related security tokens. We do not use advertising or cross-site tracking cookies, and no consent banner is required for cookies that are strictly necessary to provide a service you have requested.

13. Changes to this Policy

We may update this Policy from time to time. The effective date above reflects the latest revision. Material changes will be notified to Practices.

14. Contact

Privacy questions and requests: legal@simulateasmile.com
Ibercom Comercio Industrial, S.L. (operating as SmileStudio)
C/ Marina Alta 4, Esc. 12, 8, 46015 Valencia, Spain

  • How It Works
  • Insights
  • Pricing
  • Schedule a free demo
  • Privacy Policy
  • Terms & Conditions
  • Contact
in f 𝕏 ig
Schedule a free demo
SmileStudio

SmileStudio by SimulateASmile.com — built in a practice, for practices. Proactively helping orthodontic clinics optimise their processes. HIPAA-ready. No technical setup required.

HIPAA
Ready
AI
Powered
USA
Storage
SmileStudio demo

Schedule a free demo

Leave your details and we will find a 20 minute slot that fits around your clinic day.

HIPAA-ready · we never share your details

Thanks — you are on the list

We will be in touch shortly to book your session.