DATA & SECURITY
Your patients’ data is sacred
We handle patients’ medical data, so security is not a feature — it is the foundation. What follows is implemented, not promised.
You will not find certification logos on this page, nor uptime percentages. You will find exactly what we do and how it is checked — because those are the only things you can verify before trusting us with your patients.
Per-clinic isolation, enforced by the database
Isolation does not rest on the application behaving well: it is enforced inside the database itself, by a separate, non-privileged role that has no right to bypass the fence.
If that fence were ever missing, the system refuses to start. And on every build an isolation test suite runs that deliberately tries to break it.
Encryption
Every sensitive secret — provider, telephony and AI keys — is stored encrypted, with a separate key per domain. User passwords are stored only as a cryptographic hash, and secrets are not sent to the browser.
Where the data lives
The system runs with a European provider, in a French region; the encrypted backups are kept in a second European region, in the Netherlands. We are precise rather than convenient about the two places that are not absolute: email leaves from our provider’s European region, but that provider keeps our account metadata outside the EU; and the language-model step may run outside the EU, under processing agreements with no retention and no training. Speech recognition runs in a European region.
A sub-processor register, by name
Who they are, what they see, where they are. You get it before you sign and we notify you before it changes — you do not discover it afterwards.
Access logging
Every access to a patient record is logged. The policy is IDs-only: we record who touched which record, not what it said — and that is enforced by an automated check on every change.
Multi-factor authentication
Security keys and passkeys, an authenticator app, codes by email — with “remember this device for 30 days” so it does not become a burden for the front desk.
3-2-1 backups
Encrypted backups every four hours, plus a second independent copy off the infrastructure that stays unreadable even if the whole server is breached. And — most importantly — a quarterly restore drill: a backup is not trustworthy until it has been tried.
A failure has to be visible
Messages carry delivery status, money reconciles, and monitoring fires when something did not happen — not only when something broke.
No public telephony port
The phone system exposes no port to the internet, and recording of inbound calls starts after the greeting that tells the caller.
Who is who, under the GDPR
You are the controller of your patients’ data; we are the processor and act only on your instructions.
The Article 28 data-processing agreement is signed before the first patient record goes in — not afterwards, and not with a tick on a form.
Deletion and the ten-year duty
The law requires you to keep the clinical record for ten years. Odontia respects that instead of promising something that is not permitted: when you “delete” a patient, the record leaves every screen, list and message immediately, and is deleted for good when the retention duty expires.
When the relationship ends, your clinic’s data is either handed back to you as a full export or deleted — you choose, and the data-processing agreement sets out how. Backups expire on their own cycle.
And the artificial intelligence
It never writes to the record or the calendar on its own: it drafts, and a person confirms with one tap — with every confirmation logged.
Everything it writes is marked as such, on screen and in the data. AI runs with your own key and a monthly cost ceiling in euros.
The audio and transcript of calls stay on our own infrastructure in Europe, with a European speech-recognition provider — not an American speech service. Only the language-model step (Claude Sonnet 5) runs under a no-retention, no-training agreement, and it is named in the sub-processor register.
The data-processing agreement and the named sub-processor register are available on request — and you read them before you say yes.
Join the list