Privacy Policy

Last Updated: March 3, 2026

This Privacy Policy describes how Dobbe-AI ("we", "us", or "our") collects, uses, and discloses your personal information in connection with our website(s) at https://dobbe.ai, and our dental AI detection and analysis services (collectively, the "Services").

By using our Services, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree, please discontinue use of the Service immediately.

1. Information We Collect

We may collect the following categories of personal information:

  • Identifiers: Your first and last name, account username, password, and IP address.
  • Professional and Contact Information: Your professional title or position, business address, email address, and phone number.
  • Payment Information: If you make a payment, we may collect information such as your name and payment card details (number, expiration date, CVV code). This is typically handled by a secure third-party payment processor.
  • Device and Usage Information: We may collect information about the device and browser you use to access our Services, including device type, browser type, operating system, and your browsing activity (which pages you visit, in what order, and for how long).
  • Dental and Health Information: To provide our core Services, we process information provided to us by dental professionals. This may include dental images (such as X-rays), patient charts, and related clinical notes necessary for AI detection and analysis.
  • Patient Intake Forms: If you submit a patient intake form directly through the Dobbe-AI platform, we collect and store the personal and medical information you provide — such as your name, date of birth, symptoms, allergies, and dental history. This data is securely stored and used to generate your Patient Summary for the clinic that requested the form.

You are not required to provide all personal information identified in this policy to use our Services, but certain features may not be available if you do not provide certain information.

1.1. Patient Information: Storage vs. AI Processing (Important Distinction)

Dobbe AI's platform separates patient identity management from AI analysis to protect patient privacy:

  1. Data Stored Securely in Clinic's Account:
    • Patient metadata including: name, date of birth, age, gender, contact information (phone, email, address), medical history, clinical notes, and treatment records.
    • This information is securely stored in encrypted form within our dedicated database for clinics on the Dobbe AI platform.
    • It is used for patient record management, appointment scheduling, care coordination, and generating patient summaries.
  2. Data Transmitted to AI Inference Services:
    • Dental radiographs (X-ray images) in de-identified form.
    • Technical imaging parameters (such as modality type, exposure settings, image dimensions).
    • Clinical context codes (such as tooth numbers, finding types, procedure codes) needed for AI analysis and reporting.
  3. What is NOT Sent to AI Services:
    • Patient names, dates of birth, contact information, addresses, government ID numbers, or insurance details are not transmitted to Dobbe AI's AI inference services.
    • The AI analysis engine is not aware of patient identity or personal details.

This separation ensures patient privacy while enabling accurate AI-assisted radiographic analysis.Direct patient identifiers are only accessed by the treating clinic's authorized staff through the secure clinic portal.

1.2. Dobbe AI Scribing Chrome Extension (Microphone Audio)

Dobbe AI provides a Chrome browser extension (the “Dobbe AI Scribing Extension”) that allows authorized clinicians to capture and transcribe clinical consultations using real-time audio recording.

Purpose of the Extension

The Extension is designed to assist dental professionals with AI-generated clinical notes and scribing by converting spoken interactions into structured text.

The Extension is an optional tool; clinicians may choose when to activate it during a consultation.

Microphone Permissions and Recording Controls

  • When a user installs and first opens the Extension, the browser will prompt the user to grant microphone access.
  • The Extension does not record audio by default. Recording begins only when the user explicitly clicks “Start Recording” within the Extension interface.
  • While recording is active, audio from the user’s microphone is captured and transmitted to Dobbe AI’s secure services for transcription.
  • When the user clicks “Stop Recording” or closes the Extension, microphone capture stops immediately and the Extension no longer has access to microphone audio.

Authentication and JWT Tokens

  • Access to the Extension is limited to authenticated Dobbe AI users.
  • The Extension uses a short-lived JSON Web Token (JWT) issued after login to securely associate recordings with the correct clinic account and user.
  • The JWT is used only for authentication and authorization of API requests and is not used for tracking across third-party websites.

What Audio We Collect and Send to AI Services

  • During an active recording session, we collect the audio stream from the user’s microphone (for example, a conversation between a clinician and a patient).
  • For transcription, this audio is sent to our AI transcription services (LLM / speech-to-text API) without any direct patient identifiers attached as metadata (such as patient name, date of birth, MRN, contact information, or clinic ID).
  • The AI transcription service receives only the audio content and a random or internal technical identifier needed to return the transcript to our systems; it does not receive information identifying which patient, which doctor, or which clinic the audio relates to.

Audio Storage and Security

  • Audio files generated via the Extension are encrypted and stored in Dobbe AI’s secure environment hosted on Google Cloud Platform (GCP).
  • Audio at rest is protected using strong encryption (such as AES-256 or equivalent), and all transfers between the Extension, Dobbe AI services, and GCP occur over encrypted channels (such as HTTPS/TLS).
  • Access to stored audio is strictly limited to authorized personnel and systems that require it to provide the scribing service, troubleshoot issues, or comply with legal obligations.
  • Audio is retained only for as long as necessary for:
    • Generating and validating the transcript;
    • Supporting the clinic’s documentation needs; and
    • Meeting applicable medical-record and regulatory retention requirements.
  • Clinics may request deletion or anonymization of specific recordings in accordance with our data subject rights and deletion procedures described elsewhere in this Privacy Policy.

2. Health Information (Protected Health Information)

Dobbe AI primarily provides services to dental clinics, dental support organizations (DSOs), and related healthcare businesses ("Practices"). These Practices may provide us with their patients' data, or patients may submit data directly via intake forms. This may include Protected Health Information (PHI) as defined under HIPAA, personal health data under DPDP, or special category data under GDPR.

  1. Dobbe AI's Role for Patient Health Data:
    • Dobbe AI acts as a Data Processor (under DPDP/GDPR terminology) or Business Associate (under HIPAA terminology) when processing patient health data.
    • The dental clinic or Practice acts as the Data Fiduciary (DPDP), Data Controller (GDPR), or Covered Entity (HIPAA).
    • Dobbe AI stores patient health data in encrypted form and makes it available only to the Practice that owns the patient relationship.
    • We do not use patient health data for our own purposes beyond providing AI-assisted services on behalf of the Practice.
  2. Dobbe AI's Independent Role:
    • Dobbe AI acts as an independent Data Fiduciary (DPDP) or Data Controller (GDPR) for:
      • Clinician and practice staff account information
      • Website visitor data and analytics
      • Business operations data (billing, support tickets, usage logs)

2A. Clinic Responsibility for Patient Consent

Dental clinics and healthcare providers using Dobbe AI services are responsible for obtaining and documenting explicit patient consent before uploading or processing patient data through the Dobbe AI platform.

Patient Consent Must Clearly Cover:

  • AI Analysis: Use of artificial intelligence tools to analyze the patient's dental radiographs and clinical data to assist in diagnosis and treatment planning.
  • Cloud Storage: Storage of dental images and clinical information on Dobbe AI's secure cloud platform for the duration of the patient-clinic relationship and as required by applicable law.
  • Clinical Decision Support: Generation of AI-assisted detection overlays, reports, treatment plans, and dental charts, with the understanding that the treating dentist remains fully responsible for all clinical decisions.
  • De-identification and Model Improvement (Optional): Use of de-identified patient data (with direct identifiers removed) to train and improve AI models. This should be presented as an optional consent that patients may decline without affecting their care.

Audit Trail Requirements:

Clinics must maintain documentation that patient consent was obtained, including:

  • Date of consent
  • Method of consent (written form, digital signature, verbal with documentation)
  • Scope of consent (clinical use vs. optional model training)
  • Patient signature or documented acknowledgment

This documentation must be made available upon request for regulatory audits or patient data subject access requests. Dobbe AI will support clinics in responding to such requests by providing relevant system logs and data processing records.

3. How We Use Your Personal Information

We collect and use personal information for the following purposes:

  • Providing, maintaining, and improving our Services.
  • Analyzing usage of our Services to maintain and improve them, including the training and refinement of our AI detection and analysis models.
  • Managing our relationship with you, including responding to your inquiries, requests, and feedback.
  • Processing transactions and managing your account.
  • Detecting security incidents and protecting against malicious, fraudulent, or illegal activity.
  • Complying with legal and regulatory obligations and responding to lawful requests for information from the government or pursuant to valid legal process.
  • Generating and updating the Patient Summary for a given clinic based on the intake form submitted by the patient.
  • Sending you promotional materials or other marketing communications, where you have consented to receive them.

3A. AI-Assisted Analysis and Model Training

Nature of AI Services: Dobbe AI provides artificial intelligence-assisted radiographic analysis and clinical decision support tools to licensed dental professionals. These tools are designed to assist, not replace, the clinical judgment of the treating dentist.

AI Limitations and Clinical Responsibility:

  • AI outputs may contain false positives (incorrectly flagging normal findings as abnormal) or false negatives (missing actual pathology).
  • All AI-generated detections, reports, treatment plans, and recommendations are suggestions only and must be independently reviewed and verified by a licensed dental professional before use in patient care.
  • The treating dentist remains solely responsible for all clinical decisions, diagnoses, treatment planning, and patient communications.
  • AI outputs do not constitute a medical diagnosis or treatment prescription.

AI Model Training and Improvement: Dobbe AI uses dental radiographs and associated clinical data to train, test, and refine its AI detection models. This training is essential to improve the accuracy, reliability, and scope of our AI capabilities.

  • Data Used for Training: Only de-identified radiographs and clinical context (with direct patient identifiers such as name, date of birth, and contact information removed or not used).
  • Purpose: To improve detection accuracy, add new pathology categories, reduce false positives/negatives, and validate model performance across diverse patient populations.
  • Opt-Out Option: Patients and clinics may request exclusion of their data from future AI model training by contacting privacy@dobbe.ai. Exclusion does not affect the clinic's ability to use Dobbe AI services for patient care.

Once de-identified data has been incorporated into a trained AI model, it may not be technically feasible to remove it from that specific model version. However, we will ensure the data is not used in future training cycles and will document the limitation in compliance with GDPR and DPDP requirements.

4. How We Disclose Your Personal Information

We do not sell or rent your personal information. We may share personal information with the following third parties for the purposes described above:

  • Service Providers: With vendors and partners who help us provide, maintain, and improve our Services, such as IT and hosting providers, web analytics providers, and payment processors. We require these providers to protect the confidentiality and security of your information.
  • Professional Advisors: With our legal, tax, risk, and compliance advisors, as necessary.
  • Legal and Law Enforcement: With government bodies, law enforcement agencies, or other third parties to comply with a subpoena, court order, or other lawful request, or to protect our rights and property.
  • Business Transactions: In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be shared with counterparties and transferred to a successor entity.

4A. De-identification and Anonymization Standards

Dobbe AI uses two levels of data protection for secondary uses (AI model training, analytics, research):

De-identified Data:

  • Definition: Personal data from which direct identifiers have been removed or masked, but the data may still be re-identifiable when combined with other information or through technical means.
  • Direct Identifiers Removed:
    • Patient name
    • Date of birth
    • Phone number
    • Email address
    • Physical address
    • Government ID numbers
    • Insurance policy numbers
    • Account numbers
  • Indirect Identifiers May Remain:
    • Clinic location (city/state)
    • Approximate age range
    • Gender
    • Tooth number
    • Finding type
    • Imaging modality
    • Date ranges (year/month only)
  • Use: Internal analytics, quality assurance, and preliminary model testing within secure Dobbe AI systems.
  • Legal Status: Still subject to GDPR, DPDP, and HIPAA protections as it may be re-identifiable.

Anonymized Data:

  • Definition: Personal data that has been irreversibly processed such that it can no longer be linked back to an identifiable individual by any reasonably available means, in accordance with GDPR Recital 26 and DPDP standards.
  • Anonymization Techniques Applied:
    • Removal of all direct and indirect identifiers (including clinic affiliation and precise dates)
    • Aggregation and generalization (e.g., age ranges instead of exact age)
    • Data perturbation and noise injection where applicable
    • Unlinking patient records from radiographs
  • Re-identification Risk Assessment: Regular risk assessments are conducted to ensure anonymized data cannot be re-identified using reasonably available techniques or datasets.
  • Use: Only truly anonymized data (per GDPR Recital 26 standard) is used for AI model training, algorithm improvement, and research publications.
  • Legal Status: Anonymized data falls outside the scope of GDPR, DPDP, and HIPAA because it does not relate to an identifiable individual. However, Dobbe AI maintains strict controls to ensure anonymization integrity.

Verification and Compliance:

Upon request, Dobbe AI will provide evidence that data used for specific purposes meets the appropriate de-identification or anonymization standard. Patients and clinics concerned about re-identification risk may request exclusion from model training data by contacting privacy@dobbe.ai.

5. Cookies and Tracking Technologies

Dobbe AI uses cookies and similar tracking technologies to operate our website, understand user preferences, and improve your experience. A cookie is a small text file stored on your device by your web browser.

Types of Cookies We Use:

  • Strictly Necessary Cookies:

    Required for website functionality, security, and authentication. These cannot be disabled as they are essential for the Services to work.

    • Examples: Session management, login authentication, security tokens, load balancing
  • Analytical / Performance Cookies:

    Help us understand how visitors use our website by collecting anonymous information about pages visited, time spent, and navigation patterns.

    • Examples: Google Analytics, usage statistics, error tracking
    • Legal Basis: Consent (opt-in via cookie banner) and legitimate interest for aggregated analytics
  • Functional Cookies:

    Remember your preferences and settings to provide a more personalized experience.

    • Examples: Language preference, display settings, saved filters
    • Legal Basis: Consent (opt-in via cookie banner)
  • Marketing / Advertising Cookies:

    Used to deliver relevant advertisements and measure campaign effectiveness. We do not currently use third-party advertising cookies but may do so in the future with your consent.

    • Legal Basis: Explicit consent (opt-in via cookie banner)

Browser Controls:

You can manage or disable cookies through your web browser’s settings. However, disabling certain cookies may prevent you from using some features of the Services.

For instructions on managing cookies:

  • Chrome: Settings > Privacy and Security > Cookies and other site data
  • Firefox: Settings > Privacy & Security > Cookies and Site Data
  • Safari: Preferences > Privacy > Manage Website Data
  • Edge: Settings > Privacy, Search, and Services > Cookies and Site Permissions

Do-Not-Track Signals:

Some browsers support "Do Not Track" (DNT) signals. At this time, there is no universal standard for how websites should respond to DNT signals. Dobbe AI does not currently respond to automated DNT browser signals. However, you can control tracking through our cookie consent banner and browser settings.

Third-Party Services:

We may use third-party services such as Google Analytics, which may set their own cookies. These services are subject to their own privacy policies:

6. User Content and Clinic Responsibilities

As a user of Dobbe AI Services, you are responsible for all content, data, and materials you upload, submit, or transmit through the Services ("User Content"), including but not limited to:

  • Patient dental radiographs and clinical images
  • Patient intake forms and medical history
  • Clinical notes, diagnoses, and treatment plans
  • Practice information and account details

You represent and warrant that:

  • You have obtained all necessary patient consents, authorizations, and legal rights to upload and process User Content through Dobbe AI Services.
  • User Content does not violate any applicable laws, professional standards, or third-party rights (including patient privacy, confidentiality, and intellectual property rights).
  • You are authorized by your organization (clinic, practice, DSO) to use Dobbe AI Services with patient data.

You agree that:

  • Dobbe AI may use User Content solely to provide the Services and as described in the Privacy Policy and any executed Data Processing Agreement.
  • You retain all ownership rights in User Content, subject to the limited license granted to Dobbe AI to provide the Services.
  • You are solely responsible for the accuracy, quality, legality, and appropriateness of User Content.

Dobbe AI reserves the right (but has no obligation) to monitor, review, or remove User Content that violates these Terms, applicable law, professional standards, or that poses a security or legal risk.

7. Use of the Dobbe AI Scribing Chrome Extension

Description of the Extension

Dobbe AI may provide a Chrome browser extension (the “Dobbe AI Scribing Extension”) that enables authorized users to capture microphone audio during clinical encounters and generate AI-assisted transcripts, notes, and summaries (“Scribed Content”).

Activation and Microphone Permissions

The Extension operates only after installation and authentication with a valid Dobbe AI account.

When the Extension is first used, the browser will request permission to access the user’s microphone. By granting this permission, you authorize the Extension to capture audio only while a recording session is actively in progress.

Recording starts when the user clicks the “Start Recording” button and stops when the user clicks “Stop Recording” or closes the Extension. Dobbe AI does not continuously listen in the background and does not record audio outside of an active session.

Clinic Responsibility for Consent and Recording

  • Obtaining all legally required patient and participant consents for audio recording and AI-based scribing.
  • Informing patients that conversations may be recorded and transcribed using third-party technology providers acting on your behalf.
  • Ensuring that your use of the Extension complies with HIPAA, DPDP, GDPR, and any applicable state or local privacy or recording laws.

Disclaimers for AI-Generated Scribed Content

Scribed Content generated from audio recordings is provided as clinical decision support and documentation assistance only and does not constitute medical advice or a final clinical record.

The treating clinician remains solely responsible for reviewing, editing, and approving all notes, transcripts, and documentation before they are added to the patient’s chart or relied upon for diagnosis, treatment, billing, or regulatory reporting.

Dobbe AI does not guarantee that transcripts or generated notes will be error-free, and the Practice is responsible for verifying accuracy and completeness.

8. Children's Privacy

Our Services are not directed at or intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 16, please contact us.

9. Your Rights and Choices

You have certain choices regarding the personal information you provide to us.

  • Marketing Communications: If you no longer wish to receive marketing communications from us, you can opt out at any time by following the unsubscribe instructions in the communication itself.
  • Accessing and Correcting Your Information: You may be able to review and update your account information by logging into your account. You can also contact us to request access to or correction of your personal information.

Depending on your jurisdiction, you may have additional rights, such as the right to request deletion of your data or to object to certain processing. To exercise these rights, please contact us using the information below.

10. Data Subject Rights and How to Exercise Them

Under the DPDP Act (India), GDPR (EU/UK), and applicable data protection laws, you have the following rights regarding your personal data. To exercise any of these rights, submit a request to compliance@dobbe.ai with the required information.

Right to Access (Data Portability):

You may request a copy of your personal data held by Dobbe AI, including:

  • Dental radiographs and clinical records
  • Patient intake form submissions
  • Visit and treatment history
  • Account information (for clinicians)

How to Request:

  • Email compliance@dobbe.ai with:
    • Full name and date of birth
    • Clinic name (if applicable)
    • Date range of visits or records requested
    • Preferred format (PDF, DICOM, CSV)

Patient vs. Clinician Routing:

  • Patients: Requests may be routed through your dental clinic (Data Fiduciary) for verification or submitted directly to Dobbe AI. Data will be provided within 30 calendar days.
  • Clinicians: You may access your professional and account information directly through the Dobbe AI portal or by contacting compliance@dobbe.ai.

Right to Correction (Rectification):

You may request correction of inaccurate or incomplete personal data.

How to Request:

  • Clinicians: Update your professional or practice information directly in the Dobbe AI platform.
  • Patients: Submit a request including:
    • Full name, date of birth, and clinic name
    • Specific data to be corrected
    • Supporting documentation (if applicable)

Dobbe AI will coordinate with the clinic to verify and implement corrections within 30 calendar days.

Right to Erasure (Right to be Forgotten):

  • Deletion of personal identifiers within 30 days
  • Deletion of radiographs and clinical records (subject to legal retention requirements)
  • Limitation for anonymized training data: If irreversibly anonymized and incorporated into a trained model, removal from that version may not be technically feasible. However, Dobbe AI commits to exclusion from future training cycles.

Right to Restrict Processing:

  • You contest the accuracy of data (restricted during verification).
  • Processing is unlawful but restriction is preferred over deletion.
  • Dobbe AI no longer needs the data but you require it for legal claims.
  • You have objected to processing and verification is ongoing.

To request restriction, email compliance@dobbe.ai with the reason and applicable circumstances.

Right to Object:

You may object to processing based on legitimate interests (e.g., analytics or marketing). Processing will cease unless compelling legitimate grounds override your interests.

Right to Withdraw Consent:

If processing is based on consent, you may withdraw consent at any time by emailing compliance@dobbe.ai. Withdrawal does not affect prior lawful processing.

Response Timeline and Process:

  • Acknowledgment: Within 3 business days
  • Response: Within 30 calendar days
  • Extensions: Up to an additional 30 days if complex
  • Denials: Explanation provided with appeal rights

Appeals and Complaints: If you are not satisfied with Dobbe AI's response to your data subject rights request, you may contact our Grievance Officer at grievance@dobbe.ai for internal review.

11. Data Retention Policy

We retain personal and health data only as long as it is required by the associated clinic for patient care continuity, regulatory compliance, and internal historical analysis.

Patient Intake Forms: Intake form data submitted directly by patients is retained securely and encrypted, and is accessible only by the associated clinic. The clinic (as Data Fiduciary/Controller) controls when patient intake data should be deleted. Dobbe AI does not automatically delete intake form data after a fixed period; instead, retention is aligned with the associated clinic's policy and applicable legal requirements. Dobbe AI will delete or anonymize intake form data upon written request from the clinic.

12. Lawful Basis for Processing Personal Data

Dobbe AI processes personal data under different legal bases depending on the category of data:

  1. Patient Health Data (Dental Images, Clinical Records)
    • Dobbe AI's Role: Data Processor
    • Data Fiduciary: The dental clinic/healthcare provider
    • Legal Basis: Explicit written consent obtained and documented by the treating clinic before uploading patient data to Dobbe AI
    • Purpose: To provide AI-assisted radiographic analysis, clinical decision support, dental charting, and related services to the clinic
  2. Clinician and Practice Staff Data (Account Information)
    • Dobbe AI's Role: Data Fiduciary
    • Legal Basis: Consent (for account creation and service use) and Legitimate use (for service delivery, support, billing, security, fraud prevention, and regulatory compliance)
    • Purpose: To manage accounts, provide technical support, process payments, ensure security, and comply with applicable laws
  3. Website Visitor and Device Data (Analytics, Cookies)
    • Dobbe AI's Role: Data Fiduciary
    • Legal Basis: Consent (for non-essential cookies via cookie banner) and Legitimate use (for essential website functionality, security, and analytics)
    • Purpose: To operate and improve the website, analyze usage patterns, prevent fraud, and ensure cybersecurity

All data processing complies with the purpose limitation, data minimization, and transparency principles under the DPDP Act(2023).

13. Consent Statement

Dobbe AI does not rely on deemed consent for any data processing activities.

14. Grievance Redressal Mechanism

If you have a privacy-related complaint, you may contact our designated Grievance Officer at: Email: grievance@dobbe.ai

We acknowledge all grievances within 24 hours and aim to resolve them within 7 business days.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this policy. We encourage you to review this policy periodically to stay informed about how we are protecting your information. For material changes, we may provide additional notice, such as a message on our website or via email.

16. Data Processing Agreements and Regulatory Compliance

Dobbe AI recognizes its role as a Data Processor (DPDP/GDPR) or Business Associate (HIPAA) when handling patient health information on behalf of dental clinics and healthcare providers. To formalize this relationship and ensure regulatory compliance, Dobbe AI will execute appropriate data processing agreements based on the clinic's jurisdiction and applicable law.

Business Associate Agreement (BAA) – United States (HIPAA):

For dental clinics, practices, and DSOs in the United States that are HIPAA-covered entities or business associates, Dobbe AI will sign a HIPAA Business Associate Agreement (BAA) that:

  • Defines Dobbe AI's obligations as a Business Associate under HIPAA Privacy, Security, and Breach Notification Rules.
  • Commits Dobbe AI to implement appropriate safeguards to protect Protected Health Information (PHI).
  • Outlines incident response, breach notification, and audit support procedures.
  • Limits use and disclosure of PHI to purposes authorized by the clinic.

Data Processing Agreement (DPA) – European Union / United Kingdom (GDPR):

For dental clinics and healthcare providers in the European Union, United Kingdom, and European Economic Area, Dobbe AI will provide a GDPR-compliant Data Processing Agreement (DPA) that:

  • Incorporates Standard Contractual Clauses (SCCs) approved by the European Commission for international data transfers.
  • Defines Dobbe AI as the Data Processor and the clinic as the Data Controller.
  • Commits to data protection principles including purpose limitation, data minimization, security, and confidentiality.
  • Supports data subject rights (access, rectification, erasure, portability) and provides audit rights.
  • Discloses subprocessors (e.g., cloud hosting providers) and commits to notify the clinic of subprocessor changes.

DPDP Data Processor Agreement – India (DPDP Act, 2023):

For dental clinics and healthcare providers in India, Dobbe AI will provide a written Data Processor Agreement under the Digital Personal Data Protection Act, 2023, that:

  • Clarifies Dobbe AI's role and obligations as a Data Processor.
  • Commits to processing personal data only as instructed by the clinic (Data Fiduciary).
  • Implements technical and organizational security measures to protect personal data.
  • Supports the clinic's obligations to respond to data principal (patient) requests.
  • Provides audit and compliance support as required under DPDP.

How to Request Agreements:

Clinics must request and sign the applicable agreement(s) before transmitting patient data to Dobbe AI. To request a BAA, DPA, or DPDP agreement, contact:

  • Email: legal@dobbe.ai
  • Subject Line: "Request for [BAA/DPA/DPDP Agreement] – [Clinic Name]"

Dobbe AI will provide the agreement within 5 business days of request and work with the clinic to execute it promptly.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us using the appropriate email address below:

General Privacy Inquiries:

  • Email: privacy@dobbe.ai
  • Purpose: Questions about data collection, use, and protection practices

Data Subject Rights Requests (Access, Correction, Erasure):

  • Email: compliance@dobbe.ai
  • Purpose: Submit requests to access, correct, delete, or restrict use of your personal data
  • Expected Response Time: Acknowledgment within 3 business days, resolution within 30 calendar days

Grievance Officer (DPDP Act Compliance):

  • Email: grievance@dobbe.ai
  • Purpose: Formal privacy-related complaints and grievances
  • Expected Response Time: Acknowledgment within 24 hours, resolution within 7 business days

Legal and Contract Inquiries (BAA/DPA/DPDP Agreements):

  • Email: legal@dobbe.ai
  • Purpose: Request Business Associate Agreements, Data Processing Agreements, or contractual terms

Technical Support:

  • Email: support@dobbe.ai
  • Purpose: Technical assistance with Dobbe AI platform usage

General Information:

Dobbe-AI
Mailing Address:
12/A, BA Block Janakpuri
New Delhi 110058
India