Privacy Policy

Introduction.

AlineCloud OÜ (“AlineCloud,” “we,” “our,” or “us”) is committed to protecting the privacy of our users, including dental clinics, dentists, orthodontists, and clinic staff (“you,” “your,” or “Users”). This Privacy Policy explains how we collect, use, store, and protect Personal Data when you use our B2B orthodontic treatment planning platform (“Platform”) and any related websites, communication tools, or services (collectively, the “Services”). By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, you must discontinue using the Services. This Privacy Policy is prepared in accordance with:

  • EU General Data Protection Regulation (GDPR)
  • Estonian Data Protection Act
  • Applicable international privacy standards

Platform Description.

AlineCloud is a B2B orthodontic treatment planning platform where dentists and orthodontists upload patient photos, scans, and clinical information to request digital aligner treatment plans. The workflow includes:

  1. upload of patient files,
  2. creation of the digital orthodontic plan,
  3. revision requests, and
  4. delivery and storage of final plans.

The Platform is used exclusively by dental clinics, dentists, orthodontists, and authorized clinic staff. AlineCloud is currently intended to operate as a non-medical device software platform under EU regulations.

1. Information We Collect.

AlineCloud processes Personal Data strictly for the purpose of delivering B2B digital aligner planning services. We collect data in three primary ways:

1.1. Information Clinics Provide Directly.

  1. You may provide personal information to us when you:
    1. Create a clinic account
    2. Upload patient cases (photos/scan files)
    3. Request or modify treatment plans
    4. Communicate with our orthodontists
    5. Contact support
    6. Make payments
    7. Update account or billing information
  2. AlineCloud does not obtain patient consent. Clinics are solely responsible for ensuring lawful collection and uploading of patient data.
  3. AlineCloud does not collect information directly from patients and never communicates with them.
  4. Clinic profile information, dentist identification details, payment details, billing contacts, and limited usage data necessary for service optimization.

Role of Clinics as Data Controllers
Clinic profile information, dentist identification details, payment details, billing contacts, and limited usage data necessary for service optimization.

1.2. Patient Information Uploaded by Clinics.

  1. Clinics may upload:
    1. Patient photos
    2. 3D intraoral scans (STL/OBJ files)
    3. X-rays and other diagnostic files
    4. Dental notes
    5. Treatment instructions and comments
  2. This data may qualify as special category health data under GDPR.
  3. All patient data is uploaded manually by Clinics; AlineCloud does not automatically collect any patient-related information.

1.3. Information Collected Automatically.

  1. Device information (IP address, browser type, OS)
  2. Log data (timestamps, error logs, login activity)
  3. Usage data (pages visited, actions taken, features used)
  4. General location (approximate IP-based region)
        This data is used to improve platform performance, security, and user experience.

1.4. Information from Third Parties.

We may receive necessary data from:

  1. Stripe (payment confirmations)
  2. Email services (delivery status)
  3. Hosting/security providers
  4. Analytics tools (once implemented; no PHI shared)

No patient data is obtained through third parties.

2. How We Use Your Information.

We use Personal Data only for lawful purposes under GDPR Art. 6, primarily for:

2.1. Providing and Improving Services.

  1. Processing orthodontic treatment planning requests.
  2. Enabling uploads, revisions, and plan deliveries.
  3. Managing clinic accounts and user access.
  4. Ensuring accurate storage and retrieval of case files.
  5. Providing free case evaluations.
  6. Maintaining platform functionality.

2.2. To Provide Customer Support.

  1. Responding to technical or account-related inquiries.
  2. Communicating regarding case modifications or deadlines.
  3. Troubleshooting and issue resolution.

2.3. Platform Security.

  1. Preventing unauthorized access.
  2. Monitoring suspicious activity.
  3. Verifying account authentication.
  4. Maintaining audit logs.

2.4. Payments and Billing.

  1. Processing financial transactions via Stripe.
  2. Managing billing records and legal compliance.
  3. Sending receipts and order confirmations.

2.5. Analytics and Optimization.

(Used once tools are finalized and implemented)

  1. Understanding platform usage.
  2. Improving workflows and performance.
  3. Aggregated insights for product improvement.

No identifiable patient data is used for analytics.

2.6. To Ensure Security and Prevent Fraud.

  1. Detect and prevent fraudulent or unauthorized transactions.
  2. Safeguard against misuse, cyberattacks, and security breaches.
  3. Verify account access and log-in attempts to prevent identity theft.
  4. Monitor for suspicious activity and protect against spam or abuse.
  5. Maintain the security and integrity of our systems.

2.7. Legal and Regulatory Compliance.

  1. Fulfilling GDPR obligations.
  2. Responding to lawful requests from authorities.
  3. Maintaining mandatory business and financial records.

2.8. Legal Basis for Processing.

  1. For clinic and staff data: Processing is based on Art. 6(1)(b) (performance of contract), Art. 6(1)(f) (legitimate interest), and Art. 6(1)(c) (legal obligation).
  2. For patient data: Clinics are the Data Controllers and determine the lawful basis, including obtaining explicit patient consent where required. AlineCloud processes patient data under Art. 28 as a Data Processor and under Art. 9(2)(h) when acting under the clinic’s responsibility.

3. How We Share Your Information.

AlineCloud does not sell or rent Personal Data. We only share data where necessary

3.1. Service Providers.

We may share limited data with trusted third parties:

  1. AWS Europe: secure cloud storage of encrypted patient files.
  2. Stripe: payment processing.
  3. Email delivery systems: communication notifications.
  4. Analytics tools (TBD): anonymized usage insights.

All subcontractors engaged for data processing are bound by written Data Processing Agreements (DPAs) compliant with GDPR Art. 28, ensuring confidentiality, security, and restricted processing. A GDPR Article 28 Data Processing Agreement forms an integral part of our contractual documentation with all clinic partners.

3.2. Professional Advisors.

  1. Lawyers.
  2. Compliance consultants.
  3. Accountants/auditors.

Shared only when strictly necessary.

3.3. For Legal and Regulatory Compliance.

We may disclose your personal information if we believe it is reasonably necessary to:

  1. Comply with EU/Estonian laws.
  2. Respond to court orders or lawful requests.
  3. Protect our rights, Users, or the public.

3.4. During Business Transfers.

In the event of a merger, sale, acquisition, or restructuring, Personal Data may be transferred, subject to GDPR safeguards.

3.5. Aggregated and De-identified Information.

We may share anonymized data for analytics or research that cannot identify clinics or patients.

4. Intellectual Property Rights.

  1. The Clinic owns all rights to its patient files and the final treatment plans generated through the Platform.
  2. AlineCloud retains all intellectual property rights to the Platform software, algorithms, design tools, and related technology.
  3. Clinics may export and download treatment plans at any time.

5. Commercial and Operational Model.

  1. Pricing Model: AlineCloud operates on a per-case pricing basis with no subscription plans.
  2. Free Trial: Not offered.
  3. Free Case Evaluation: Always available.
  4. Refunds: Provided only in limited circumstances, accessed on case-by-case basis.
  5. Discounts: May be provided based on case volume.
  6. Minimum Contract Duration: None.
  7. Cancellation: Clinics may stop using the Platform at any time without penalty.

6. Cookies and Tracking Technologies.

  1. AlineCloud uses essential cookies for login, security, and core functionality.
  2. We maintain records of cookie consent decisions for compliance with GDPR and the Estonian Data Protection Act.
  3. Check our Cookie Policy for more information [Insert link].

7. Data Security.

AlineCloud implements stringent security measures appropriate to the sensitivity of the data processed.

7.1. Technical Measures.

  1. Encryption in transit (TLS/HTTPS)
  2. Encrypted storage on AWS Europe
  3. Regular vulnerability scanning
  4. Secure development practices
  5. Access control lists (ACLs)

7.2. Organisational Measures.

  1. Role-based access control
  2. Audit logs and activity monitoring
  3. Restricted employee access
  4. Mandatory confidentiality obligations
  5. Data protection training

7.3. User Responsibilities.

Users must:

  1. secure login credentials
  2. maintain professional use only
  3. upload only lawful and consented patient data
  4. comply with local medical and legal requirements

Clinics and dentists are solely responsible for obtaining patient consent, ensuring accurate diagnosis, complying with local medical regulations, and approving all final treatment plans before use.

7.4. No Absolute Security Guarantee.

While we take industry-standard measures, no system is entirely immune from risks.

8. Data Retention.

We keep your personal information only for as long as it is reasonably necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by Estonian law and EU regulations.

8.1. Patient Data.

  1. Patient data is stored until the clinic deletes it from the Platform or requests deletion. AlineCloud does not retain patient files independently once a clinic has deleted them or requested erasure.
  2. AlineCloud deletes patient files upon the Clinic’s written request and provides written confirmation once deletion is completed.

8.2. Clinic Account Data.

  1. Retained as long as the Clinic account remains active
  2. Limited retention thereafter for legal/tax purposes

8.3. Billing and Financial Records.

Stored for the legally required period under Estonian accounting law (typically 7 years)

8.4. Logs and Audit Trails.

Retained for reasonable security and operational periods

8.5. Secure Disposal.

Data is securely deleted or anonymised once retention periods expire.

9. International Data Transfers.

All primary data hosting occurs within the European Union (AWS Europe).

9.1. Transfers outside the EU.

  1. AlineCloud stores all patient and clinic data exclusively within the European Union (AWS Europe).
  2. Limited data (such as payment information processed by Stripe) may involve transfers outside the EU, always protected by GDPR-approved safeguards.
  3. No patient health data is transferred outside the EU or shared with analytics or marketing providers.

9.2. Safeguards.

We ensure:

  1. adequate contractual commitments.
  2. secure processing environments.
  3. GDPR-aligned privacy protections.

10.Your Privacy Rights under GDPR.

10.1.Users have the following rights:

  1. Access to data we hold.
  2. Rectification of inaccurate data.
  3. Erasure (“right to be forgotten”).
  4. Restriction of processing.
  5. Data portability.
  6. Objection to processing.
  7. Withdraw consent where applicable.

10.2.Exercising Your Rights.

  1. Email us at: [Insert] with the subject line "Privacy Rights Request".
  2. Address: Estonian virtual office address [Insert]
  3. We may request identity verification for security purposes.

10.3.Response Times.

We respond within 30 days, extendable for complex cases as permitted under GDPR.

11.Changes to This Privacy Policy.

We may update this Policy to reflect:

  1. legal changes.
  2. operational adjustments.
  3. new features.
  4. updated security practices.

Material changes will be communicated via:

  1. Platform notice.
  2. email (for registered Clinics).

11.1.Your Responsibility to Review

  1. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of the Site after changes are posted will signify your acceptance of the revised Policy.
  2. Material changes that affect how we process personal data will be communicated directly through a Platform notification or email prior to taking effect. Material changes include updates relating to data categories, processing purposes, retention periods, or third-party sharing.
  3. AlineCloud will not retroactively reduce your privacy rights or expand data processing without providing notice where legally required.

12.Complaints and Contact Information.

12.1.How to Contact Us.

If you have any questions, concerns, or complaints about this Privacy Policy or how we handle your personal information, please contact us:

  • AlineCloud OÜ
  • Registered Address: [Insert]
  • Country: Estonia
  • Email: [Insert]
  • Business Hours: [Insert]

12.2.Complaint Resolution Process.

We take all privacy concerns seriously and will:

  1. Acknowledge receipt of your complaint within 5 business days.
  2. Investigate your complaint thoroughly and fairly.
  3. Provide you with a response within 30 days (or notify you if more time is needed).
  4. Work with you to resolve the issue to your satisfaction where possible.

This complaint process applies specifically to privacy and data protection matters. General service or technical issues should be directed to our support team.

12.3.Your Right to Escalate Complaints.

You may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or with any supervisory authority in the European Economic Area where you live or work, as permitted by GDPR Article 77.

You also have the right to seek judicial remedy under GDPR Article 79 if you believe your data protection rights have been violated.

12.4.Patient Related Complaints.

For complaints or rights requests concerning patient data, the Clinic acts as the Data Controller and is responsible for responding directly to the patient.

AlineCloud acts solely as a Data Processor and will assist the Clinic in fulfilling its GDPR obligations where required.

12.5.No Retaliation.

AlineCloud will not retaliate against you, limit your access to the Services, or reduce service quality because you submitted a privacy complaint or exercised your GDPR rights. All complaints are handled confidentially and professionally.

13.Governing Law and Dispute Resolution.

13.1.Governing Law.

This Privacy Policy, and any dispute or claim arising out of or in connection with it, shall be governed by and interpreted in accordance with the laws of Estonia, without regard to its conflict-of-law principles.

13.2.Dispute Resolution.

  1. Good Faith Resolution. Before initiating any formal proceedings, the parties agree to first attempt to resolve the dispute in good faith. You may contact us with any concerns at:
    • AlineCloud OÜ
    • Email: [Insert]
    • Registered Address: [Insert Estonian virtual office address]
    • We will make reasonable efforts to resolve the issue through informal negotiation within 30 days of receiving your notice.
  2. Jurisdiction and Venue. If a dispute cannot be resolved informally, it shall be submitted to the exclusive jurisdiction of the Harju County Court (Harju Maakohus) in Tallinn, Estonia, unless otherwise required by mandatory EU or GDPR supervisory authority procedures. Clinics located outside Estonia agree that Estonian courts will have jurisdiction, and waive any objection to venue or forum non conveniens.
  3. EU Regulatory Complaints (Data Protection). Nothing in this section limits your right to:
    • Lodge a complaint with the Estonian Data Protection Inspectorate (AKI), or
    • Any other supervisory authority in the EEA where you live or work (GDPR Art. 77), or
    • Seek judicial remedy under GDPR Art. 79

    This section applies only to contractual disputes, not GDPR rights

  4. Injunctive Relief. Nothing in this section prevents either party from seeking urgent injunctive or equitable relief in a competent court when necessary to protect data security, intellectual property, or confidential information.

14.Contact Information.

If you have any questions, requests, or concerns regarding this Privacy Policy or how AlineCloud processes personal data, you may contact us using the details below:

  • AlineCloud OÜ
  • Registered Address: [Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 5 ]
  • Country of Incorporation: Estonia (EU)
  • Email: [info@alinecloud.co]
  • Business Hours: Monday–Friday, [09:00–17:00 EET/EEST]

For privacy-specific matters, please include:

Subject Line: “Privacy Inquiry” or “GDPR Rights Request”