Privacy Policy

Last updated: September 2026

Tony OS ("we," "us") provides patient-inquiry response and recall software for dental clinics. This page explains what data we collect and how we actually use it.

What we collect

How it's used

Patient contact data is used to operate the product you signed up for: logging inquiries in your activity feed, drafting replies (reviewed by your staff for anything flagged as higher-risk), and sending recall reminders you've opted into. We do not sell patient or clinic data.

Who we share it with

Only the vendors needed to run the service: Stripe (billing), Resend (transactional email delivery), Twilio (SMS/calling), and Anthropic (drafts AI-assisted reply text — no patient data is used to train third-party models). Each processes data only as needed to provide their service to us.

How long we keep it

By default, for as long as your clinic's account is active, so your activity feed and reporting stay accurate. Clinics can request a configured automatic retention window instead, after which patient records past that window are deleted automatically — contact us to set one for your clinic. If you close your account or ask us to delete your data, we'll remove it.

Security

Data is encrypted in transit, and access to clinic data is restricted to authenticated staff of that clinic plus the Tony OS team for support and operation of the service. We keep an internal log of when a patient's contact details are sent to one of the vendors listed above (e.g. a review-request email or SMS), so we can show, on request, exactly what was sent to whom and when.

Your rights

You can ask to see, correct, or delete the data we hold about your clinic or your patients at any time by emailing raouf@tonyosagency.com. A request to delete a specific patient's records is processed through an erasure tool that removes that patient from our systems — this is a real, working deletion, not a manual best-effort promise.

This page describes our actual data practices in plain language. It is not a substitute for professional legal review, and clinics with their own regulatory obligations (including GDPR as a Danish or EU-based practice) should confirm this fits their own compliance requirements.
← Back to Tony OS