DentaZon Marketplace

Data Protection Policy

Effective From: April 20, 2026

1. Purpose

Dentazon recognizes that its digital dental ecosystem may involve personal, professional, commercial, educational, and health-related information. This Data Protection Policy establishes the principles Dentazon applies to protect such information throughout its lifecycle. It complements the Dentazon Privacy Policy and describes our organizational approach to responsible data governance, security, confidentiality, access, artificial intelligence, retention, disclosure, and incident management.

2. Policy Objectives

Dentazon aims to:
  • protect the confidentiality, integrity, and availability of information;
  • reduce unauthorized collection and use of personal information;
  • give additional protection to health and other sensitive information;
  • maintain appropriate cybersecurity safeguards;
  • limit access to information according to legitimate business or professional need;
  • protect patient confidentiality;
  • responsibly manage information used by AI systems;
  • maintain reasonable retention and deletion practices;
  • appropriately manage third-party processors and vendors;
  • respond appropriately to security incidents; and
  • operate consistently with applicable Pakistani law and recognized data-protection principles.

3. Applicable Framework

Dentazon operates in Pakistan and seeks to comply with legal and regulatory requirements applicable to its operations, including, as relevant:
  • the Prevention of Electronic Crimes Act, 2016, as amended;
  • the Electronic Transactions Ordinance, 2002;
  • the Pakistan Medical and Dental Council Act, 2022;
  • applicable PM&DC regulations and professional ethical requirements;
  • applicable consumer-protection legislation;
  • applicable competition and deceptive-marketing requirements; and
  • other laws, regulations, court orders, or regulatory obligations that apply to particular Dentazon Services.
Where additional privacy or data-protection legislation becomes applicable, this Policy may be updated accordingly.

4. Data Protection Principles

Dentazon seeks to apply the following principles.

Lawful and Fair Handling

Information should be collected and used for legitimate and appropriate purposes and should not be handled in a misleading or unfair manner.

Transparency

Individuals should be provided understandable information about how their information is used.

Purpose Limitation

Information collected for one purpose should not be used for an unrelated incompatible purpose without an appropriate basis.

Data Minimization

Dentazon should collect only information reasonably required for the intended Service.

Accuracy

Reasonable measures should be taken to keep material personal and professional information accurate and current.

Storage Limitation

Information should not be retained indefinitely without a valid operational, professional, legal, security, or recordkeeping reason.

Confidentiality and Security

Appropriate measures should be implemented to protect information from unauthorized access, disclosure, destruction, or alteration.

Accountability

Personnel and service providers handling Dentazon information should be subject to appropriate responsibilities, controls, and oversight.

5. Information Classification

Dentazon may classify information according to its sensitivity and risk.

Public Information

Information intentionally made available to the public, such as general website content and authorized public professional profiles.

Internal Information

Operational information not intended for unrestricted public disclosure.

Confidential Information

Information requiring restricted access, including internal business information, account information, transaction information, vendor records, and non-public communications.

Sensitive and Health Information

Information requiring heightened protection, including:
  • dental history;
  • symptoms;
  • medical information;
  • dental photographs;
  • X-rays or radiographic images;
  • diagnostic information;
  • patient communications;
  • treatment information;
  • identification documentation;
  • private chatbot conversations containing health information; and
  • other information whose unauthorized disclosure could create significant privacy, professional, financial, or safety risk.
Access controls and security requirements should be proportionate to the classification of the information.

6. Collection Controls

Before collecting personal information, Dentazon should consider:
  • why the information is required;
  • whether less information would be sufficient;
  • who needs access;
  • how long the information is likely to be required;
  • whether the individual has received appropriate notice;
  • whether consent is appropriate;
  • whether third parties will receive the information; and
  • whether the information involves heightened health or privacy risks.
Forms and workflows should avoid unnecessary collection of sensitive information.

7. Patient and Health Information

Health information must receive enhanced protection. Dentazon personnel should not access a patient's health information merely because technical access is available. Access should be based on legitimate functions such as:
  • facilitating the requested appointment;
  • supporting the patient;
  • resolving technical issues;
  • authorized clinical workflows;
  • security investigations;
  • legal requirements; or
  • other specifically authorized functions.
Health information must not be casually disclosed internally or externally.

8. Professional Confidentiality

Dentists and other healthcare professionals using Dentazon remain responsible for applicable professional confidentiality requirements. Dentists should not upload identifiable patient information unless:
  • it is necessary for a legitimate professional purpose;
  • appropriate authorization or consent exists where required;
  • disclosure is compatible with professional obligations; and
  • appropriate platform functionality is being used.
Clinical personnel must exercise particular care when using patient cases for education, research, AI evaluation, or professional discussion. Where practical and appropriate, information should be de-identified.

9. AI and RAG Data Governance

Dentazon may use Retrieval-Augmented Generation and other AI technologies. AI systems require additional controls because user prompts may contain health, identity, or other sensitive information. Dentazon's AI governance should include:
  • clearly identifying AI-generated interactions;
  • limiting unnecessary sensitive-data collection;
  • restricting access to private chat logs;
  • applying appropriate security controls;
  • evaluating AI performance and known limitations;
  • maintaining human escalation where professional intervention is appropriate;
  • preventing AI outputs from being represented as guaranteed medical diagnoses;
  • appropriately controlling information sources used for retrieval;
  • monitoring for harmful, misleading, or unsafe outputs; and
  • reviewing material changes to high-impact AI functionality.

10. AI Training Data

Private patient information and identifiable health information require special controls before being used for AI model training, fine-tuning, testing, or evaluation. Dentazon should use appropriately de-identified, synthetic, licensed, public, or specifically authorized information wherever reasonably possible. Identifiable private health information or identifiable private chatbot conversations should not be placed into general-purpose model training datasets without appropriate authority, safeguards, and, where required, explicit informed consent. Operational use of a user's information within a RAG conversation to respond to that user's request is distinct from permanently incorporating that information into model training.

11. Human Oversight

AI is intended to assist rather than improperly replace professional clinical judgment. Where an AI output could materially affect healthcare decisions, appropriate human professional review should be available or recommended. Clinical diagnosis and treatment decisions remain the responsibility of appropriately qualified professionals.

12. Access Control

Access to Dentazon systems and data should follow the principle of least privilege. Where technically appropriate, controls may include:
  • unique user accounts;
  • role-based permissions;
  • strong passwords;
  • multifactor authentication for privileged accounts;
  • controlled administrator access;
  • session management;
  • access logging;
  • periodic access review; and
  • prompt removal of access when an individual no longer requires it.
Shared administrator accounts should be avoided wherever reasonably practical.

13. Encryption and Transmission

Dentazon should use appropriate protections for information in transit and, where appropriate, at rest. Sensitive information should not be transmitted through insecure methods where a secure authorized alternative is available. Security controls should be reviewed as technologies and risks evolve.

14. Passwords and Authentication Information

Passwords should be stored using appropriate secure password-hashing practices rather than reversible plaintext storage. Passwords, authentication tokens, private keys, API credentials, and similar secrets should receive restricted access and appropriate technical protection. Users must not be asked to provide account passwords through the AI chatbot.

15. Logging and Monitoring

Dentazon may maintain technical and security logs for purposes including:
  • cybersecurity;
  • troubleshooting;
  • fraud prevention;
  • service reliability;
  • incident investigation; and
  • compliance.
Logging should avoid unnecessary duplication of sensitive patient information. Access to sensitive logs should be restricted.

16. Third-Party Service Providers

Third-party processors may support services including:
  • cloud hosting;
  • AI;
  • databases;
  • communications;
  • email;
  • payment processing;
  • analytics;
  • storage;
  • backups;
  • cybersecurity;
  • appointment systems; and
  • customer support.
Before providing sensitive information to an important third-party processor, Dentazon should consider, where appropriate:
  • the nature of data involved;
  • the provider's security measures;
  • confidentiality obligations;
  • access controls;
  • data location;
  • subcontractors;
  • incident-notification obligations;
  • retention and deletion arrangements; and
  • contractual protections.
Providers should receive only the data reasonably required to perform their role.

17. Dentists, Clinics and Vendors as Third Parties

Dentazon may need to provide data to independent dentists, clinics, laboratories, vendors, and other platform participants. Information-sharing should be limited to the relevant purpose. Examples include:
  • providing booking details to a selected dentist;
  • providing order delivery information to a marketplace seller;
  • providing relevant information to an authorized laboratory; or
  • sharing course registration information with an authorized educator.
Platform participants must not use received information for unrelated purposes.

18. International and Cross-Border Processing

Where Dentazon uses international technology or cloud providers, information may be processed outside Pakistan. Before transferring particularly sensitive information across borders, Dentazon should consider:
  • the necessity of the transfer;
  • contractual protections;
  • access restrictions;
  • encryption;
  • the recipient's security arrangements; and
  • applicable Pakistani legal requirements.
The use of an offshore technology provider should not remove Dentazon's responsibility to apply appropriate safeguards to information under its control.

19. Data Retention

Each significant category of information should be retained according to its legitimate purpose. Retention decisions may consider:
  • patient and professional requirements;
  • appointment administration;
  • transaction history;
  • financial and tax obligations;
  • contractual obligations;
  • dispute limitation periods;
  • cybersecurity;
  • fraud prevention;
  • educational records;
  • regulatory obligations; and
  • backup cycles.
Data should be securely deleted, anonymized, or disposed of when retention is no longer reasonably necessary.

20. Backups

Backups may be maintained to support business continuity, security recovery, and system integrity. Backup access should be restricted. Expired information contained in backup systems may remain until it is removed through the normal backup-rotation process, provided it is not restored or used for unrelated purposes.

21. Data Subject Requests

Dentazon should maintain a reasonable mechanism for individuals to request:
  • access;
  • correction;
  • updating;
  • deletion where appropriate;
  • withdrawal of consent where applicable; or
  • clarification regarding information use.
Before fulfilling a request, Dentazon may verify the requester's identity. Requests may be limited where necessary because of:
  • professional healthcare record obligations;
  • legal requirements;
  • fraud prevention;
  • security;
  • rights of another person;
  • pending disputes; or
  • another legitimate and lawful requirement.

22. Employee and Contractor Responsibilities

Anyone granted access to confidential Dentazon information should:
  • use it only for authorized purposes;
  • protect passwords and authentication credentials;
  • avoid unauthorized copying;
  • avoid sending sensitive information to personal accounts;
  • avoid unauthorized storage devices or cloud accounts;
  • report suspicious activity;
  • maintain confidentiality;
  • follow applicable security procedures; and
  • promptly report suspected data incidents.
Confidentiality obligations should continue where appropriate after the relationship with Dentazon ends.

23. Security Incident Management

A data or cybersecurity incident may include:
  • unauthorized account access;
  • compromised credentials;
  • malware;
  • ransomware;
  • loss of a device containing information;
  • accidental disclosure;
  • unauthorized database access;
  • unauthorized extraction;
  • inappropriate internal access; or
  • compromise of an important service provider.
Suspected incidents should be reported promptly to the designated Dentazon technical or management contact.

24. Incident Response

Dentazon should maintain a reasonable process to:
  1. identify and report the incident;
  2. contain the immediate threat;
  3. preserve relevant evidence and logs;
  4. investigate the nature and scope of the incident;
  5. identify affected information and individuals;
  6. remediate vulnerabilities;
  7. determine relevant legal, professional, contractual, and notification requirements;
  8. communicate with affected parties or authorities where appropriate; and
  9. document lessons learned and corrective actions.
Incidents involving sensitive health information should receive heightened priority.

25. Vendor Security Incidents

Service-provider agreements should, where appropriate, require the provider to notify Dentazon promptly of a security incident involving Dentazon information and cooperate with investigation and remediation.

26. Secure Development

Systems handling sensitive data should be developed and maintained using appropriate secure-development practices. Depending upon risk, these may include:
  • code review;
  • dependency management;
  • patching;
  • access control testing;
  • vulnerability scanning;
  • secure configuration;
  • secrets management;
  • testing of APIs;
  • backup testing; and
  • security review before significant production changes.

27. AI and Software Change Management

Material changes to AI models, retrieval sources, prompts, integrations, or handling of health information should be assessed for potential effects on:
  • privacy;
  • confidentiality;
  • clinical safety;
  • cybersecurity;
  • accuracy;
  • fairness;
  • data retention; and
  • user transparency.

28. Data Protection by Design

Dentazon should consider privacy and security during the design of new Services rather than only after deployment. High-risk features should consider:
  • data minimization;
  • access permissions;
  • user notice;
  • consent mechanisms;
  • security;
  • deletion capability;
  • auditability;
  • human oversight; and
  • potential misuse.

29. Children and Student Data

Services directed toward students or individuals who may be minors require particular care. Where appropriate, Dentazon should:
  • limit information collected;
  • obtain authorization from a parent or guardian where required;
  • avoid unnecessary profiling;
  • avoid unnecessary collection of health data; and
  • provide age-appropriate information.

30. Marketing and Data Protection

Information collected for healthcare support should not automatically be treated as marketing data. Marketing communications should use appropriate contact information and respect available consent and opt-out mechanisms. Sensitive health information should not be used for unrelated targeted marketing without appropriate authorization.

31. Analytics

Dentazon may use analytics to understand system performance and user behaviour. Where reasonably possible, analytics should avoid unnecessarily exposing identifiable health information. Aggregated or de-identified data should be preferred for statistical and product-improvement analysis where practical.

32. Research

Dentazon may support dental or technology research. Research involving identifiable patient information should be subject to appropriate authorization, confidentiality safeguards, ethical review where applicable, and relevant professional requirements. Where appropriate, research datasets should be anonymized or de-identified.

33. Data Quality

Dentazon should maintain reasonable procedures for correcting materially inaccurate account, professional, appointment, transaction, or other records. Professional users are responsible for keeping their public qualifications and registration information current.

34. Policy Violations

Unauthorized disclosure, misuse, extraction, alteration, destruction, or access to Dentazon information may result in:
  • restriction of Platform access;
  • termination of account or contractual relationship;
  • disciplinary action where applicable;
  • reporting to a relevant regulator or professional body; or
  • legal action where appropriate.
Unauthorized access or interference with electronic systems may also constitute an offence under applicable Pakistani cybercrime legislation.

35. Review of this Policy

Dentazon should review this Policy periodically and following significant changes to:
  • applicable law;
  • regulatory requirements;
  • healthcare operations;
  • AI systems;
  • infrastructure;
  • security risks; or
  • data-processing activities.

36. Contact

Questions, privacy concerns, security reports, or data-protection requests may be directed to: Dentazon Email: dentazonpk@gmail.com Phone: +92 321 4305057 Pakistan Dentazon should designate an appropriate internal person or function responsible for coordinating privacy and data-protection requests.