Launch Offer — up to 62% off, flat--:--:--Claim now
Legal · India

DPDPA Compliance

AmritSmile is designed to help dental practices comply with India's Digital Personal Data Protection Act, 2023 — from consent management to breach notification.

DPDPA 2023 aligned
Our commitments

What DPDPA compliance means at AmritSmile

Lawful processing

AmritSmile processes personal data only for the purposes for which it was collected and only on the basis of valid consent or legitimate use as defined in the DPDPA.

Data Fiduciary support

We help dental practices (who are Data Fiduciaries) meet their DPDPA obligations — providing consent management tools, data-subject request workflows, and breach notification procedures.

Purpose limitation

Personal data is not used for any purpose beyond delivering the AmritSmile service. We do not sell, licence or share personal data with advertisers or data brokers.

Data minimisation

We collect only the data necessary to provide the service. Fields marked optional are genuinely optional and not required for core functionality.

Rights fulfilment

We provide tools for data principals (patients) to access, correct and erase their data, and for Data Fiduciaries (clinics) to facilitate these requests within statutory timelines.

Cross-border restrictions

All patient data is stored and processed in India (AWS ap-south-1). We do not transfer personal data outside India without assessing government-notified country adequacy.

Common questions

DPDPA FAQs

Who is the Data Fiduciary under DPDPA for patient data?

The dental practice (clinic) is the Data Fiduciary. AmritSmile acts as a Data Processor, processing data only as instructed by the clinic and in accordance with our Data Processing Agreement.

How does AmritSmile help clinics obtain patient consent?

AmritSmile provides a consent capture flow during patient registration. Consent is recorded with a timestamp and can be withdrawn by the patient at any time. Clinics can generate consent reports on demand.

What happens when a patient requests data erasure?

The clinic receives the request in the AmritSmile dashboard and can process it within 30 days. AmritSmile will permanently delete the data from all backups within 90 days of the clinic's confirmation.

Does AmritSmile appoint a Data Protection Officer (DPO)?

Yes. Our DPO can be contacted at privacy@amritsmile.in. The DPO is responsible for overseeing our DPDPA compliance programme and responding to regulatory enquiries.

How does AmritSmile handle data breaches?

In the event of a personal data breach, AmritSmile will notify affected clinics within 72 hours of becoming aware of the breach. We will provide details of the data affected, likely consequences, and measures taken.

Is a Data Processing Agreement (DPA) available?

Yes. A signed DPA is available to all clinic customers on the Professional and Enterprise plans. Email legal@amritsmile.in to request a copy.

Need a Data Processing Agreement?

A signed DPA is available for all Professional and Enterprise customers. Contact our legal team to receive a copy.