Terms of Service
Last Updated: March 3, 2026
Please carefully read these Terms of Service ("Terms"). These Terms govern your use of the services provided by Dobbe-AI ("Dobbe-AI," "we," "our," and "us") through https://dobbe.ai (the "Services"). By using the Services, including viewing or accessing content on our website, you agree to be bound by these Terms. If you don’t agree, you may not use the Services.
Additional terms may apply to Dobbe-AI’s paid products and services, as outlined in a signed order form or another agreement between you and Dobbe-AI ("Additional Services"). These supplemental terms will override these Terms in case of any conflict. If you don’t agree with the supplemental terms, you may not use the Additional Services.
FOR NON-EMERGENCY USE ONLY
DO NOT USE THE SERVICES FOR EMERGENCY CARE. IF YOU NEED EMERGENCY HELP, CALL YOUR LOCAL EMERGENCY NUMBER OR GO TO THE NEAREST EMERGENCY ROOM. THE SERVICES ARE NOT DESIGNED FOR TIME-SENSITIVE OR EMERGENCY COMMUNICATIONS.
The Services do not establish a patient relationship with Dobbe-AI, nor should they replace professional medical advice. Always consult with a healthcare provider for medical concerns.
We may update, modify, or discontinue the Services or these Terms at any time. It’s your responsibility to review them regularly. By continuing to use the Services, you accept any changes.
1. Registration
To use our Services, you may need to create an account and provide your email address and phone number. By doing so, you agree to receive communications from Dobbe-AI, including emails, SMS messages, and voice calls, related to your account and use of the Services. You also agree to receive all agreements, notices, disclosures, and other communications in electronic form, which satisfies any legal requirements for written communication.
Please Note: Communications via email or text may not be secure. By sending personal or confidential information through these methods, or by agreeing to receive communications through them, you acknowledge and accept any associated risks.
If you are a dental clinic, hospital, or healthcare provider ("Practice"), you agree and acknowledge that:
A. Data Fiduciary Status:
- You are the Data Fiduciary under the Digital Personal Data Protection Act (DPDP), India, the Data Controller under GDPR (if applicable), or the Covered Entity under HIPAA (if applicable).
- Dobbe AI functions as a Data Processor (DPDP/GDPR) or Business Associate (HIPAA) and processes patient data solely on your instructions and in accordance with applicable data processing agreements.
B. Patient Consent Responsibility:
- You are solely responsible for obtaining, documenting, and maintaining valid, explicit, and informed consent from your patients before uploading or processing any patient data through Dobbe AI Services.
Consent Must Clearly Cover:
- Use of artificial intelligence tools to analyze patient dental radiographs and clinical data.
- Storage of patient data on Dobbe AI's secure cloud platform.
- Generation of AI-assisted reports, treatment plans, and clinical decision support outputs.
- Optional: Use of de-identified patient data to improve AI models (this should be presented as a separate, optional consent).
Acceptable Consent Methods:
- Written patient intake form with dedicated AI consent section and patient signature.
- Digital consent form with electronic signature via your practice management system or patient portal.
- Inclusion of AI data use in your Notice of Privacy Practices (HIPAA, US) or Privacy Notice (GDPR, EU).
- Verbal consent documented in the patient's clinical record (for voice recording and ambient AI transcription).
Documentation Requirements:
- You must maintain an audit trail showing:
- Date and method of consent
- Scope of consent (clinical use vs. optional model training)
- Patient signature or documented acknowledgment
- This documentation must be made available to regulatory authorities upon request and to Dobbe AI if needed to respond to patient data subject rights requests.
C. Authorization and Compliance:
- You confirm that you are authorized by your organization to use Dobbe AI Services with patient data and to enter into data processing agreements on behalf of your organization.
- You agree to comply with all applicable data protection, privacy, and healthcare laws, including but not limited to DPDP Act (India), GDPR (EU/UK), HIPAA (US), and professional standards (dental boards, medical councils).
D. Dobbe AI's Role:
- Dobbe AI processes patient data solely as instructed by you and in accordance with this Agreement and any executed Data Processing Agreement (DPA), Business Associate Agreement (BAA), or DPDP Data Processor Agreement.
- Dobbe AI does not directly interact with patients, does not provide medical advice, and does not establish a patient-provider relationship.
E. Support and Resources:
- Dobbe AI will provide sample patient consent language, templates, and guidance to assist you in obtaining proper consent. Contact legal@dobbe.ai to request these resources.
1A. Data Processing Agreements and Regulatory Compliance
As Dobbe AI processes patient health information on behalf of healthcare providers, appropriate data processing agreements are required to ensure compliance with applicable data protection laws.
Business Associate Agreement (BAA) – United States (HIPAA):
If you are a dental clinic, practice, or DSO in the United States and you are a HIPAA-covered entity or business associate, you must execute a HIPAA Business Associate Agreement (BAA) with Dobbe AI before transmitting any Protected Health Information (PHI) through the Services.
The BAA will:
- Define Dobbe AI's obligations as a Business Associate under HIPAA Privacy, Security, and Breach Notification Rules.
- Commit Dobbe AI to implement appropriate administrative, physical, and technical safeguards to protect PHI.
- Outline breach notification, incident response, and audit support procedures.
- Limit Dobbe AI's use and disclosure of PHI to purposes authorized by you.
Data Processing Agreement (DPA) – European Union / United Kingdom (GDPR):
If you are a dental clinic or healthcare provider in the European Union, United Kingdom, or European Economic Area, you must execute a GDPR-compliant Data Processing Agreement (DPA) with Dobbe AI before transmitting any personal data through the Services.
The DPA will:
- Incorporate Standard Contractual Clauses (SCCs) approved by the European Commission for lawful international data transfers.
- Define Dobbe AI as the Data Processor and your organization as the Data Controller.
- Commit to GDPR principles including purpose limitation, data minimization, security, and confidentiality.
- Support data subject rights (access, rectification, erasure, portability) and provide audit rights.
- Disclose subprocessors (e.g., cloud hosting providers) and commit to notify you of subprocessor changes.
DPDP Data Processor Agreement – India (DPDP Act, 2023):
If you are a dental clinic or healthcare provider in India, you must execute a written Data Processor Agreement under the Digital Personal Data Protection Act, 2023, with Dobbe AI before transmitting any personal data through the Services.
The agreement will:
- Clarify Dobbe AI's role and obligations as a Data Processor.
- Commit to processing personal data only as instructed by you (the Data Fiduciary).
- Implement technical and organizational security measures to protect personal data.
- Support your obligations to respond to data principal (patient) requests under DPDP.
- Provide audit and compliance support as required under DPDP.
2. Privacy and Your Personal Information
Dobbe-AI’s current Privacy Policy may be found at https://dobbe.ai/privacy-policy and is hereby expressly incorporated into these Terms by reference. The Privacy Policy discloses Dobbe-AI’s practices regarding the collection, use, and disclosure of your personal information. By agreeing to these Terms, you are also agreeing to the terms of Dobbe-AI’s Privacy Policy. For inquiries regarding the Privacy Policy, please contact compliance@dobbe.ai.
Dobbe-AI acts solely as a Data Processor on behalf of Practices. The Practice remains responsible for addressing all data access, correction, and erasure requests from patients. Dobbe-AI will support such requests if formally routed by the Practice to compliance@dobbe.ai.
3. Rules and Conduct
As a condition of using the Services, you agree not to use them for any unlawful purpose or in violation of these Terms or any applicable law, rule, or regulation. Specifically, you will not:
- Take any action that imposes an unreasonable load on Dobbe-AI’s or its providers’ infrastructure.
- Interfere with or disrupt the functioning of the Services.
- Attempt to bypass security measures on the Services.
- Send spam, auto-responses, or mass emails via the Services.
- Use automated tools to scrape or crawl the Services.
- Reverse-engineer, decompile, or attempt to access the source code of the Services.
- Modify, translate, or create derivative works based on any part of the Services.
- Copy, rent, lease, distribute, or transfer any rights granted to you under these Terms.
4. Third-Party Sites and Materials
The Services may let you access content or link to websites from third parties (“Third-Party Materials”). When you access these, you do so at your own risk. Dobbe-AI does not control these materials and is not responsible for their accuracy, reliability, or legality.
DOBBE-AI DISCLAIMS ALL RESPONSIBILITY FOR INFORMATION COLLECTED OR USED BY THIRD-PARTY PROVIDERS. YOU AGREE THAT DOBBE-AI IS NOT LIABLE FOR ANY DAMAGES OR LOSS RESULTING FROM YOUR USE OF THIRD-PARTY MATERIALS.
5. Content and Intellectual Property
All content and materials provided through the Services (“Content”) are owned exclusively by Dobbe-AI. You must follow all copyright notices and restrictions. You are not allowed to sell, license, copy, or create derivative works from the Services or Content without consent from the owner.
Our trademarks, logos, and any other marks used by Dobbe-AI are trademarks or registered trademarks of Dobbe-AI. Your use of the Services does not grant you any rights to reproduce or use our marks or any third-party marks.
7. Termination
Dobbe-AI may terminate your access to all or any part of the Services at any time, with or without cause or notice. Upon termination, all licenses and rights granted to you by these Terms will immediately terminate. All provisions of these Terms which by their nature should survive termination shall survive.
8. Warranties and Disclaimers
TO THE FULLEST EXTENT PERMITTED BY LAW, THE SERVICES AND CONTENT ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT ANY WARRANTIES, EXPRESS OR IMPLIED. Dobbe-AI makes no guarantees that: (a) the Services will be accurate, secure, or always available; (b) any defects or errors will be fixed; (c) content or software is free from viruses; or (d) the Services will meet your needs. Your use of the Services is entirely at your own risk.
9. Indemnification
You agree to indemnify, defend, and hold harmless Dobbe-AI, its affiliates, and their employees from any liabilities, claims, or expenses (including reasonable attorneys' fees) arising from your use or misuse of the Services or your breach of these Terms.
10. Limitation of Liability
A. Cap on Liability:
To the maximum extent permitted by law, Dobbe AI's aggregate liability for all claims arising out of or related to these Terms or your use of the Services (whether in contract, tort, negligence, strict liability, or otherwise) shall not exceed the greater of:
- The total amount paid by you (or your organization) to Dobbe AI in the 12 months immediately preceding the event giving rise to the claim; or
- Ten Thousand U.S. Dollars (USD $10,000).
B. Exclusions from Liability Cap:
The above limitation of liability does not apply to:
- Death or Personal Injury: Liability for death or personal injury caused by Dobbe AI's negligence or willful misconduct.
- Data Breaches: Liability for unauthorized access, disclosure, or loss of patient Protected Health Information (PHI) or personal data caused by Dobbe AI's failure to implement required security safeguards under HIPAA, GDPR, or DPDP.
- Breach of Confidentiality: Liability for Dobbe AI's breach of confidentiality obligations under data processing agreements (BAA, DPA, DPDP agreements).
- Regulatory Fines and Penalties: Liability for fines, penalties, or enforcement actions imposed on you by regulatory authorities (HIPAA OCR, GDPR supervisory authorities, Data Protection Board of India) resulting directly from Dobbe AI's non-compliance with data protection laws.
- Indemnification Obligations: Your indemnification obligations under Section 9 are not subject to this liability cap.
- Fraud or Willful Misconduct: Liability for Dobbe AI's fraud, intentional misconduct, or gross negligence.
- Non-Waivable Rights: Any liability that cannot be limited or excluded by law under applicable consumer protection, data protection, or healthcare regulations.
C. Disclaimer of Consequential Damages:
To the maximum extent permitted by law, Dobbe AI shall not be liable for any:
- Indirect, incidental, special, exemplary, punitive, or consequential damages.
- Loss of profits, revenue, business opportunities, goodwill, or reputation.
- Cost of substitute services.
- Loss of data or use of services (except where caused by breach of data protection obligations as described in Exclusion B.2 above).
This limitation applies even if Dobbe AI has been advised of the possibility of such damages.
D. Statute of Limitations:
Any claim arising out of or related to these Terms or the Services must be filed within one (1) year from the date the cause of action arose, except where a longer limitation period is required by applicable law. Claims not filed within this period are permanently barred.
E. Essential Basis of the Bargain:
You acknowledge that the fees charged by Dobbe AI reflect the allocation of risk set forth in these Terms and that Dobbe AI would not enter into this Agreement without these limitations on liability.
11. Governing Law and Dispute Resolution
A. Governing Law:
These Terms and your use of the Services are governed by and construed in accordance with the laws of India, without regard to conflict of law principles, except where mandatory laws of your jurisdiction require application of local law.
B. Dispute Resolution for Commercial Disputes:
For any dispute, claim, or controversy arising out of or relating to these Terms or the Services between Dobbe AI and a Practice/clinic/organization ("Commercial Dispute"), the parties agree to the following dispute resolution process:
Step 1 – Informal Negotiation:
The parties will first attempt to resolve the dispute through good-faith informal negotiation. Either party may initiate negotiations by sending written notice to the other party describing the dispute and proposed resolution. The parties will negotiate for 30 days from the notice date.
Step 2 – Binding Arbitration:
If the dispute is not resolved through informal negotiation, either party may submit the dispute to binding arbitration administered by:
- For Indian Practices: The Indian Council of Arbitration or another mutually agreed arbitration body, seated in New Delhi, India, conducted in English, in accordance with the Arbitration and Conciliation Act, 1996.
- For US Practices: The American Arbitration Association (AAA) under its Commercial Arbitration Rules, seated in [specify city, e.g., New York, NY, USA], conducted in English.
- For EU/UK Practices: The London Court of International Arbitration (LCIA) or another mutually agreed arbitration body, seated in London, UK, conducted in English.
The arbitration will be conducted by a single arbitrator mutually agreed upon by the parties, or appointed in accordance with the applicable arbitration rules. The arbitrator's decision will be final and binding, and judgment may be entered in any court of competent jurisdiction.
Arbitration Fees: Each party will bear its own legal costs and fees. Arbitration filing fees and arbitrator costs will be split equally unless the arbitrator determines otherwise based on the merits.
C. Exceptions to Arbitration:
Notwithstanding the above, the following disputes are not subject to arbitration and may be brought directly in the courts specified below:
- Regulatory Complaints: Complaints, investigations, or enforcement actions by government regulatory authorities (e.g., HIPAA Office for Civil Rights, GDPR supervisory authorities, Data Protection Board of India, professional licensing boards) may proceed without arbitration.
- Data Protection Disputes (GDPR/DPDP): Disputes concerning data subject rights, data protection compliance, or GDPR/DPDP violations may be escalated directly to the relevant Data Protection Authority and are not subject to mandatory arbitration where such arbitration would waive non-waivable rights.
- Injunctive Relief: Either party may seek temporary or preliminary injunctive relief in a court of competent jurisdiction to prevent irreparable harm, pending arbitration.
- Small Claims: Either party may bring a claim in small claims court if it qualifies under the applicable small claims court rules and the claim is within the court's jurisdiction.
D. Exclusive Jurisdiction (for Non-Arbitrable Disputes):
For disputes not subject to arbitration under Section 11.C above, the parties consent to the exclusive jurisdiction and venue of:
- For Indian Practices: The courts located in New Delhi, India.
- For US Practices: The courts located in the state where the Practice is located, or [specify federal district if applicable].
- For EU/UK Practices: The courts located in the country where the Practice is located, as required by GDPR.
E. Jury Trial Waiver:
To the extent permitted by law, each party waives any right to a jury trial for any dispute arising out of or related to these Terms. This waiver applies to both arbitration and court proceedings.
F. Class Action Waiver:
You agree that any arbitration or court proceeding will be conducted on an individual basis only, and not as a class action, collective action, or representative action. You waive any right to participate in a class action lawsuit or class-wide arbitration against Dobbe AI.
G. Severability:
If any provision of this dispute resolution section is found to be unenforceable or invalid, that provision will be severed, and the remainder of the section will remain in full force and effect. If the class action waiver is found unenforceable, the arbitration agreement will be void, and the dispute will proceed in court.
12. Digital Millennium Copyright Act (DMCA) Policy
If you believe that your rights have been violated, please provide a notification containing the information required by the DMCA to legal@dobbe.ai.
13. Patient Intake Forms and Health Information
Dobbe-AI enables dental clinics to collect patient intake information through secure online forms. When you submit such a form, you agree to the following:
- Purpose of Collection: Intake information, such as your personal details, medical history, symptoms, and past dental procedures, is collected to streamline your care and populate your patient summary.
- Storage and Access: This data is stored in encrypted form on the Dobbe-AI platform and is used to generate and update a Patient Summary accessible only by the clinic that requested the intake.
- Data Usage Scope: Dobbe-AI does not access or use this data for any purpose other than enabling the clinic to deliver and manage your care. We do not sell or share your intake form data with any third party.
- Security: Data is encrypted both in transit and at rest, with strict access controls ensuring clinic-level isolation.
- No Doctor-Patient Relationship with Dobbe-AI: Submitting this form does not create a patient–provider relationship with Dobbe-AI. We serve only as the technology platform for your clinic.
- Consent: By submitting the form, you provide explicit consent for Dobbe-AI to store and process your data on behalf of the clinic.
14. Entire Agreement and Order of Precedence
A. Entire Agreement:
These Terms of Service, together with the Privacy Policy available at https://dobbe.ai/privacy-policy, and any executed agreements listed below, constitute the entire agreement between you and Dobbe AI regarding your use of the Services and supersede all prior or contemporaneous understandings, agreements, representations, and warranties, whether written or oral.
B. Related Agreements:
The following agreements, if executed, supplement and modify these Terms:
- Order Form or Service Agreement: Specifies pricing, service levels, and commercial terms for paid services.
- Business Associate Agreement (BAA): Governs HIPAA-related PHI processing obligations (US practices).
- Data Processing Agreement (DPA): Governs GDPR-related personal data processing obligations (EU/UK practices).
- DPDP Data Processor Agreement: Governs DPDP Act personal data processing obligations (India practices).
C. Order of Precedence:
In the event of any conflict or inconsistency between these documents, the order of precedence is as follows (highest to lowest):
- Business Associate Agreement (BAA) or Data Processing Agreement (DPA) or DPDP Data Processor Agreement (whichever is applicable) – for data protection, privacy, and security matters.
- Signed Order Form or Service Agreement – for commercial terms, pricing, service levels, and deliverables.
- These Terms of Service – for general use, access, conduct, intellectual property, warranties, and liability.
- Privacy Policy – for data collection, use, and disclosure practices not covered by BAA/DPA/DPDP agreements.
D. Modifications and Amendments:
No modification, amendment, or waiver of these Terms is effective unless:
- It is in writing and signed by an authorized representative of Dobbe AI; or
- It is posted on the Dobbe AI website as an updated version of these Terms with a new "Last Updated" date.
Dobbe AI reserves the right to update these Terms at any time. Continued use of the Services after changes are posted constitutes acceptance of the modified Terms. For material changes, Dobbe AI will provide notice via email or prominent website notice at least 30 days before the changes take effect.
E. No Oral Modifications:
Any oral statements, representations, or agreements made by Dobbe AI employees, agents, or representatives are not binding unless confirmed in a signed written agreement.
15. Audit and Compliance Support
A. Compliance Documentation:
Upon reasonable written request, Dobbe AI will provide Practices with documentation necessary to demonstrate compliance with applicable data protection, privacy, and healthcare laws, including:
- HIPAA: Security risk assessments, breach notification logs, access logs, and evidence of HIPAA Security Rule safeguards.
- GDPR: Data processing records, subprocessor lists, data protection impact assessments (DPIAs), evidence of Standard Contractual Clauses (SCCs) compliance.
- DPDP: Data processing activity records, security measures documentation, data breach incident reports.
B. Audit Rights:
Practices (or their authorized third-party auditors) have the right to audit Dobbe AI's compliance with data protection and security obligations as follows:
- Frequency: No more than once per year, unless required by regulatory authority, breach incident, or reasonable suspicion of non-compliance.
- Notice: Practices must provide 30 days' advance written notice specifying the scope and objectives of the audit.
- Scope: Audits may include review of policies, procedures, security controls, access logs, and data processing activities relevant to the Practice's data.
- Confidentiality: Auditors must sign a confidentiality agreement before conducting the audit.
- Costs: Practice is responsible for its own audit costs unless the audit reveals material non-compliance by Dobbe AI, in which case Dobbe AI will reimburse reasonable audit costs.
C. Regulatory Inspections:
Dobbe AI will cooperate with government regulatory inspections and investigations related to data protection, privacy, and healthcare compliance, to the extent legally permitted and required. Dobbe AI will:
- Notify the affected Practice promptly upon receiving a regulatory investigation notice or subpoena related to the Practice's data.
- Provide requested documentation and records to regulatory authorities as required by law.
- Coordinate with the Practice's legal counsel to protect attorney-client privilege and confidential information where applicable.
D. Response Timeline:
Dobbe AI will respond to compliance documentation requests and audit inquiries within 15 business days of receipt, or within a shorter timeframe if required by regulatory authority or urgent compliance matter.
E. Continuous Monitoring:
Dobbe AI maintains continuous monitoring and logging systems to track:
- Access to patient data and Protected Health Information (PHI).
- Data processing activities and AI model inference requests.
- Security incidents, unauthorized access attempts, and anomalies.
- Data subject rights requests and responses.
These logs are retained for a minimum of 6 years (or longer as required by applicable law) and are available to Practices and regulatory authorities upon request.
16. Contact Us
You may contact us at:
Dobbe-AIEmail: compliance@dobbe.ai
Mailing Address:
12/A, BA Block Janakpuri
New Delhi 110058
India
