Legal
Privacy Policy
How Ambergrin collects, uses, and protects your clinic's data.
Overview
Ambergrin ("we", "us", "our") provides cloud-based practice management software for dental clinics in India. This Privacy Policy explains what information we collect when you use ambergrin.com, how we use it, and the choices you have.
Each clinic receives an isolated workspace at yourclinic.ambergrin.com. Operational patient and billing data is processed and stored in India within your tenant database; this policy covers both platform-level account data and data processed within your workspace.
Information we collect
Account & signup
- Clinic name, workspace subdomain, and practice owner details
- Email address and password (stored using industry-standard hashing)
- Verification codes sent during onboarding
Clinic operations data
- Patient records, appointments, treatment notes, and billing entered by your team
- Staff accounts and activity within your workspace
- Usage logs required to operate, secure, and improve the service
Automatically collected
- Device type, browser, IP address, and approximate location
- Pages visited, actions taken, and error reports
How we use your information
- Provision and maintain your clinic workspace
- Authenticate users and send transactional emails (e.g. OTP verification)
- Provide customer support and respond to inquiries
- Monitor performance, prevent fraud, and enforce our Terms of Service
- Comply with applicable law and lawful requests
We do not sell your personal or patient data to third parties.
Data storage & security
Ambergrin is built in India. Clinic data — including patient records, appointments, clinical notes, billing, and imaging metadata — is processed and stored on infrastructure located in India. We do not route your operational data through overseas data centres.
Each tenant workspace is stored in strict isolation with its own database, separate from every other clinic on the platform. Data is encrypted in transit (TLS), protected by role-based access controls, and sensitive record access is logged. While no system is perfectly secure, we follow reasonable industry practices to protect your information.
We do not sell your personal or patient data to third parties.
Data portability
Your clinic owns the data you enter. Patient Desk supports export as branded PDF, Ambergrin JSON, and CSV so you can access and move your records at any time — including if you decide to switch to another system. Upon account closure, we provide a reasonable window to export your data before deletion, as described in our Terms of Service.
Data retention
We retain account and workspace data for as long as your subscription is active. If you close your account, we will delete or anonymise data within a reasonable period, except where retention is required by law or for legitimate business purposes (e.g. billing records).
Your rights
Depending on applicable law, you may request access to, correction of, or deletion of personal data we hold about you or your clinic. Contact us at [email protected] and we will respond within a reasonable timeframe.