Covers MaxDent website, desktop software, MaxDent Mobile, licensing and trial activation, customer accounts, support, payment processing, advertising/analytics, affiliate/referral activity, and supported Google/Meta/Apple developer integrations and app-store distribution, Enterprise/multi-branch connectivity, and third-party or replacement network-connectivity providers.
| Item | Details |
|---|---|
| Operator | MaxDentSystem ("MaxDent", "we", "us") |
| Website | www.maxdentsystem.com |
| Privacy / Support contact | maxdentsystem@gmail.com |
| WhatsApp / phone | +20 103 730 6914 |
| Address | Taqseem el Shorta - 1st of Kafr El-Shiekh, Egypt |
| Effective date | 18 September 2026 |
| Policy version | 1.3 |
Quick Privacy Summary
- MaxDent is a dental-clinic management software platform. Clinics control the patient and clinical records they enter into MaxDent and are responsible for the lawful collection and use of those records.
- In ordinary local desktop operation, the clinic database is hosted on the clinic-controlled server/environment. MaxDentSystem does not routinely receive the clinic’s full clinical database as part of normal local use.
- MaxDent Mobile uses secure pairing, device binding, scoped sessions, role-based access, and application-layer encrypted relay transport for clinical/authentication payloads. The Android app blocks cleartext network traffic.
- Any future iOS/iPadOS release is covered by this policy. Its permissions, App Store privacy disclosures, SDK privacy manifests and any tracking-consent requirements will be matched to the actual released build.
- Some branch or device connectivity may use secure relay infrastructure or an independent connectivity provider, which may process limited technical metadata necessary to operate the connection.
- The Android camera permission is used for QR pairing/scanning. QR camera images are not designed to be uploaded or saved by MaxDent Mobile.
- Electronic payment credentials are handled by independent payment processors. MaxDent may receive transaction status, amount, reference, billing/contact information, and any receipt evidence voluntarily submitted for manual payment review.
- Website advertising/analytics tools may use cookies, pixels, browser/device identifiers, and conversion events where enabled and where consent is legally required. Patient clinical/health data is not sent to advertising platforms for targeting.
- We do not sell personal or sensitive data. Data is shared only as necessary to provide the service, with service providers, on user/customer instruction, for security/fraud prevention, or when legally required.
- Users may request access, correction, deletion, restriction or other applicable privacy rights. Patients should normally direct requests about clinic-held patient records to the clinic that controls those records.
1. Who We Are and Scope of This Policy
This Privacy Policy explains how MaxDentSystem, operating the MaxDent product family and www.maxdentsystem.com, handles personal data and other information in connection with the MaxDent website, desktop software, MaxDent Mobile, licensing and activation services, free trials, customer accounts, technical support, payment processing, advertising and analytics, affiliate/referral activities, and supported developer-platform integrations.
This policy applies to visitors, prospective customers, customers, clinic users, affiliates/marketers, and other individuals who interact directly with MaxDentSystem. It also explains the limited role MaxDentSystem may play when processing patient or clinic data on behalf of a clinic.
MaxDent is a software provider and is not a healthcare provider, medical practitioner, insurer, or payment institution. Clinical decisions, treatment, professional confidentiality, lawful patient notices/consents, and the accuracy of records remain the responsibility of the clinic and its authorized healthcare professionals.
2. Roles: Clinic Data Controller vs. MaxDent Service Provider
For patient records, medical histories, diagnoses, treatment plans, appointments, financial balances, clinical notes, and other clinic-entered records, the clinic/customer generally determines why and how the data is processed. The clinic is therefore normally the primary data controller (or equivalent role under applicable law).
MaxDentSystem acts as a software/service provider and, where it processes clinic data on the clinic’s documented instructions, may act as a processor/service provider. Patients should normally contact the clinic directly to exercise rights relating to their patient record. MaxDentSystem may assist the clinic where technically necessary and legally appropriate.
The clinic is responsible for ensuring that it has a valid legal basis for collecting, entering, storing, using, disclosing, and retaining patient information and for assigning appropriate user permissions inside MaxDent.
3. Information We May Collect or Process
| Item | Details |
|---|---|
| Website & contact data | Name, email, phone/WhatsApp number, country, language, message content, inquiry details, form submissions, and communications. |
| Trial, licensing & activation data | Email, phone, country, product/edition, subscription/trial status, license identifiers, activation request data, installation/device identifiers and technical attributes reasonably necessary for licensing, security, anti-abuse and support. |
| Customer/account data | Account email, authentication/verification information, clinic name, user name, role, permissions, subscription status and related account settings. |
| Payment & billing data | Plan/edition, amount, currency, transaction status/reference, billing/contact information and, for manual payment methods, receipt or proof-of-payment information voluntarily submitted. Full card credentials are handled by independent payment processors where electronic card payment is used. |
| Support data | Support tickets, messages, diagnostic logs, screenshots or files that the customer voluntarily provides, and technical environment information needed to resolve an issue. |
| Advertising & analytics data | Cookie identifiers, browser/device information, IP address, page visits, campaign/referral parameters, conversion events and similar measurement data where advertising/analytics technologies are enabled. |
| Affiliate/referral data | Affiliate identity/contact details, referral code, attribution records, order/commission information, verification data and payout details required to operate the program. |
| Clinic/patient data | Patient identity/contact information, appointments, medical history, allergies, alerts, diagnoses, treatment plans, clinical notes, financial records, laboratory workflow and other records entered by authorized clinic users. This category is controlled primarily by the clinic. |
| Mobile security data | Clinic ID, device UID, device number, pairing credentials, transport public-key metadata, scoped access/refresh session tokens, user name, device platform/name, security/audit events and encrypted relay envelopes. |
4. MaxDent Desktop and Local Clinic Data
MaxDent is designed for clinic-controlled operation. In ordinary local deployment, the primary clinic database is stored and operated on the clinic’s server/environment and accessed by clinic-authorized users according to roles and permissions.
MaxDentSystem does not routinely collect or centrally host the clinic’s complete clinical database merely because the clinic uses the desktop software. A clinic may choose to create local backups or synchronize backup files through third-party cloud storage under the clinic’s own account and configuration. Those third-party storage providers have their own privacy and security terms.
If a clinic voluntarily sends a backup, diagnostic file, screenshot, log, or other record to MaxDent support, MaxDentSystem will use it only for the requested support/security purpose and will seek to minimize unnecessary exposure of patient information.
5. MaxDent Mobile: Security and Data Flow
MaxDent Mobile is an authenticated companion application for authorized clinic users. It does not create a separate patient-facing account and is designed to access clinic information according to the user’s existing MaxDent account, permissions, clinic pairing and device authorization.
The current Android application requests Internet access and camera access for QR pairing/scanning. It does not require broad photo/media storage, contacts, microphone, or location permissions for its core functionality. The application blocks cleartext network traffic and mixed-content access.
On Android, device pairing credentials are protected using Android Keystore-backed AES-GCM encryption. The MaxDent password is not stored as a reusable credential in the secure pairing store. Session access/refresh tokens are maintained for the active session rather than stored as a plaintext password.
Clinical and authentication payloads sent through the MaxDent Mobile relay are application-layer encrypted end-to-end between the mobile client and the clinic connector using ephemeral X25519 key agreement, HKDF-SHA-256 key derivation, and AES-256-GCM authenticated encryption. This is in addition to transport-layer HTTPS where applicable.
The relay/control-plane layer is designed to receive an opaque encrypted envelope together with limited routing/cryptographic metadata (for example clinic ID, request ID, key ID, ephemeral public key, nonce and ciphertext). It is not provided with the private cryptographic keys required to decrypt the clinical/authentication payload itself. Decryption occurs at the authorized clinic connector and on the authorized mobile client.
The camera is used to scan a MaxDent pairing QR code. The app is designed not to upload or save QR camera images. The QR content/pairing data itself may be processed to establish the secure clinic-device relationship.
5A. Apple / iOS and iPadOS Distribution
If MaxDent Mobile is released for iOS, iPadOS, macOS, visionOS, watchOS, or another Apple platform, this Privacy Policy will apply to that released build in addition to the privacy information presented through Apple and App Store Connect. Platform-specific disclosures will be kept consistent with the actual behavior of the released application and its included SDKs.
An Apple-platform build will request only permissions reasonably required for enabled features. For example, camera access may be used for QR pairing. Access to photos/media, contacts, microphone, precise location, health frameworks, Bluetooth, or other sensitive capabilities will not be treated as part of the service unless the released feature actually needs them, the user is informed, and any required platform permission or consent is obtained.
Credentials, tokens and device-binding material on Apple platforms will be protected using platform-appropriate secure storage and access controls available to the released build. Where the MaxDent Mobile secure-relay architecture is used, the same principle applies: clinical and authentication payloads are intended to remain encrypted between the authorized mobile client and the clinic connector, while relay infrastructure handles encrypted envelopes and limited routing/security metadata rather than clear clinical content.
Apple may independently process App Store account, device, distribution, purchase/subscription, diagnostics, crash, security and analytics information under Apple’s own terms and privacy practices. MaxDentSystem receives only the categories made available to developers or intentionally supplied by the user and uses them for distribution, support, security, entitlement, analytics, accounting or legal purposes as applicable.
If a future Apple build uses data for tracking across apps or websites owned by other companies, MaxDentSystem will request any permission required by Apple’s App Tracking Transparency framework and applicable law before such tracking. Patient clinical/health data will not be used for cross-company advertising tracking or audience targeting.
For App Store submission, MaxDentSystem will maintain the required privacy policy link and App Privacy disclosures, and will review privacy manifests and third-party SDK disclosures required for the released build. If Apple privacy requirements change, MaxDentSystem may update the platform disclosures and this policy as needed without expanding data use beyond what is lawfully disclosed.
6. Website, Cookies, Analytics and Advertising
The MaxDent website may use essential cookies or local storage required for security, language, session continuity and core functionality. Where enabled, analytics and advertising technologies may also use cookies, pixels, browser/device identifiers, referral parameters and similar signals to measure traffic, campaign performance, conversions and the effectiveness of MaxDent marketing.
The MaxDent website currently uses Google Analytics 4 to measure traffic, acquisition sources and overall website performance, and Microsoft Clarity to understand general page interaction such as clicks, scrolling, heatmaps and session recordings. Clarity is not enabled on administration, authenticated portal or checkout pages, and these tools are not used to send patient clinical/health records.
Where required by law, non-essential advertising/analytics technologies are activated only after an appropriate consent choice. Users may withdraw or change consent through the available consent controls, browser/device settings, and relevant advertising-platform settings.
Third-party advertising vendors, including Google and Meta where their tools are enabled, may receive website/app interaction or conversion information according to their own terms and the user’s applicable consent choices. MaxDentSystem does not provide patient clinical/health records to these advertising platforms for ad targeting.
If remarketing or audience features are used, third-party vendors may use cookies or device identifiers to show MaxDent advertisements based on prior visits or interactions. Users can control or opt out of personalized advertising through the applicable platform ad-preference settings and device/browser controls.
7. Payment Processing
Electronic payments may be processed by independent payment service providers. MaxDentSystem does not intentionally store full payment-card numbers, CVV security codes, or online-banking credentials when those credentials are entered directly into the payment provider’s secure payment interface.
MaxDentSystem may receive and retain information necessary to complete and evidence the commercial transaction, such as customer/contact details, plan/edition, amount, currency, transaction identifier, payment status, fraud/security signals and invoice/accounting information.
Where a customer uses a manual or fallback payment method, the customer may voluntarily submit a transfer reference, receipt image, bank-transfer evidence or other proof of payment. Such material is used for payment verification, accounting, fraud prevention and dispute handling and is not used for advertising.
Payment providers operate under their own privacy notices and security controls. MaxDentSystem selects and integrates providers for legitimate commercial purposes but does not control every aspect of an independent provider’s systems.
8. Licensing, Free Trials, Device Binding and Anti-Abuse
MaxDent may process installation/device identifiers, license identifiers, activation requests, trial status, subscription status, product edition and related security signals to issue, validate, revoke, transfer, renew or troubleshoot licenses and to prevent abuse, duplicate activation, fraud or unauthorized use.
Device identifiers used by MaxDent are intended for software licensing, security and account/device management rather than advertising. They are not sold or shared with advertising platforms for behavioral targeting.
When a customer requests a license transfer to another device, MaxDent may retain an audit record of the request, approval, revocation of the old device and issuance of the new license as reasonably necessary for security and contractual records.
9. Technical Support and Diagnostics
Support communications may include account information, technical logs, screenshots, error messages, version information, device/environment details and files that a customer voluntarily shares to diagnose a problem.
Customers should avoid sending patient records unless genuinely necessary for the support request. Where patient information is required, the clinic remains responsible for having authority to disclose it, and MaxDentSystem will limit use to the requested support/security purpose.
MaxDentSystem personnel are not granted routine access to clinic clinical records merely because support is available. Any access or material voluntarily provided for support should be limited to authorized personnel on a need-to-know basis.
10. Affiliate, Referral and Marketing Programs
If MaxDent operates an affiliate, referral, publisher or marketplace-partner program, MaxDent may process participant identity/contact information, referral codes, attribution records, sales/commission amounts, verification information and payout details.
Affiliates or referrers should not receive unnecessary customer personal information. They may receive only the order/commission information reasonably required to attribute a sale and manage commission status. Patient clinical data is never shared with affiliates for marketing.
Self-purchase, fraud, abuse and commission eligibility may be assessed using reasonable anti-fraud indicators such as contact details, payment reference and device/account signals, subject to applicable law.
10A. Marketing Email Unsubscribe / Opt-Out
Marketing emails from MaxDent can be stopped at any time. Use the Unsubscribe link included in a marketing email where available, or email contact@maxdentsystem.com with the subject “Unsubscribe” and the email address you want removed from marketing communications.
An unsubscribe request applies to promotional and marketing messages. MaxDent may still send strictly necessary transactional, security, licensing, OTP, purchase, service or support messages when required to provide the service or protect the account.
11. Google, Meta and Apple Developer Platform Data
If MaxDent uses Google or Meta APIs, authentication, developer tools or platform services, MaxDentSystem requests only the permissions/scopes reasonably required for the user-facing feature being provided.
Data obtained from Google or Meta developer APIs is used only for the purposes disclosed to the user, to provide or improve the requested user-facing feature, for security, or where legally required. It is not sold to data brokers or used to build unrelated advertising profiles.
Where platform rules impose additional restrictions (including Google API Services limited-use requirements or Meta platform data-use requirements), MaxDentSystem intends to follow those restrictions and to update this policy and in-product disclosures before materially expanding use of platform-derived data.
Users may revoke connected-platform permissions through the relevant Google or Meta account controls. MaxDentSystem will delete or disconnect platform-derived data when required by the user, the platform rules, or applicable law, subject to lawful retention obligations.
12. Why We Process Information (Purposes and Legal Bases)
Depending on the context and applicable law, MaxDentSystem processes personal data to perform a contract or requested service, take steps requested before entering a contract, comply with legal/accounting obligations, protect legitimate security and business interests, prevent fraud/abuse, provide support, improve service reliability, or based on consent where consent is required.
For patient/health data entered by a clinic, the clinic is responsible for identifying and documenting the lawful basis and any healthcare-specific authorization required for that processing. MaxDentSystem processes such data only as necessary to provide the software/service on the clinic’s instructions or where law requires otherwise.
13. When We Share Information
MaxDentSystem does not sell personal or sensitive user data. Information may be shared only in limited circumstances: with infrastructure/security providers, payment processors, communications/support providers, cloud/storage providers selected or enabled by the customer, analytics/advertising providers where enabled and legally permitted, professional advisers, or other service providers that help deliver MaxDent.
Information may also be disclosed when a customer or user instructs us to do so, when necessary to investigate abuse/security incidents, to protect rights or safety, to comply with a valid legal obligation or governmental request, or as part of a merger, acquisition, restructuring or sale of business/assets subject to appropriate notice and safeguards.
Service providers should receive only information reasonably necessary for their function and are expected to handle it under contractual, legal or platform obligations appropriate to the context.
14. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this policy, to provide the service, maintain security/audit history, resolve disputes, enforce agreements, prevent fraud, and comply with accounting, tax, legal or regulatory requirements.
Clinic clinical data in local MaxDent deployments remains under the clinic’s retention and backup policies. MaxDentSystem does not set the clinic’s legal medical-record retention period.
Encrypted mobile relay data is designed to be transient for request/response routing. Operational/security metadata and logs may be retained for a limited period reasonably necessary for service reliability, abuse prevention and incident investigation; logs should not intentionally contain plaintext patient clinical payloads.
Payment, invoice, license and security records may be retained beyond active use where required for legal/accounting, fraud prevention, contractual evidence or dispute purposes. Advertising/analytics data is retained according to the applicable provider settings, consent status and configured retention periods.
15. Deletion, Access, Correction and Other Privacy Rights
Depending on applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, withdrawal of consent, portability, or information about how their personal data is processed.
For MaxDent website/customer/account data, a request may be submitted to maxdentsystem@gmail.com with the subject “Privacy / Data Request”. We may need to verify identity and authority before acting on a request.
For patient records held by a clinic, the patient should normally contact that clinic. The clinic controls the patient record and is responsible for responding under applicable healthcare/privacy law. MaxDentSystem may assist the clinic with technical deletion/export functionality where applicable.
Mobile device pairing can be revoked by an authorized clinic administrator. Unpairing/revocation is designed to invalidate the device’s clinic access and remove local pairing credentials as part of the app’s security workflow.
Some information may lawfully be retained despite a deletion request, for example transaction/accounting records, security/fraud records, legal claims, or other information that law requires or permits us to keep. Where retention is required, use will be limited to the applicable retention purpose.
16. Security Measures
MaxDentSystem uses technical and organizational safeguards appropriate to the nature of the data and service, including access controls, authentication, role-based permissions, audit/security logging, secure software-signing/release practices, encrypted network transport, device binding, secure pairing and encrypted mobile credential storage.
For MaxDent Mobile, additional application-layer cryptography is used for relay payloads so that the relay layer handles ciphertext rather than plaintext clinical/authentication content. The Android application blocks cleartext traffic and restricts file/content access in its embedded local interface.
Customers also have security responsibilities, including protecting administrator accounts and passwords, maintaining the clinic server and operating system, restricting physical/network access, keeping backups, applying updates, configuring cloud-storage permissions correctly, and promptly revoking access for former staff or lost devices.
No security method is perfect. MaxDentSystem cannot guarantee absolute protection against every attack, malware infection, compromised customer device, stolen credential, misconfiguration, third-party breach, force majeure event or unlawful action outside reasonable control.
17. International Processing and Third-Party Services
Website, payment, communications, cloud, analytics, advertising or platform providers may process limited personal data in countries other than the individual’s country. Where required, MaxDentSystem will seek to use appropriate contractual, technical or legal safeguards for such transfers.
When a clinic independently chooses a cloud backup provider, messaging provider, device platform or other third-party service, the clinic is also responsible for reviewing that provider’s privacy terms, access controls, location of processing and suitability for the clinic’s legal obligations.
17A. Enterprise / Multi-Branch Connectivity and Third-Party Network Providers
Some Enterprise or Mobile functions may use secure relay infrastructure or another independent connectivity method. MaxDentSystem may change or reconfigure the connectivity method when reasonably required for security, reliability, legal, technical or compatibility reasons.
The clinic/customer remains responsible for deciding which branches, administrators and users are authorized to access patient or clinic data across branches, for configuring and reviewing those permissions, and for ensuring that any inter-branch disclosure, transfer or access has an appropriate legal basis and complies with professional confidentiality and applicable privacy/health-data obligations.
The connectivity layer may process limited device and network metadata needed to operate the service, such as device identifiers, IP addresses, public cryptographic keys, connection timestamps and status information. MaxDent is designed to protect application data in transit using its approved security mechanisms.
MaxDentSystem does not intentionally provide patient clinical content to a connectivity provider for advertising, profiling or unrelated commercial purposes. Clinical confidentiality nevertheless also depends on the clinic’s endpoint security, credentials, user permissions, device security, local configuration and the continued proper operation of the relevant connectivity technology.
Third-party plans, pricing, commercial-use eligibility, feature limits, APIs, security requirements, terms and availability may change independently of MaxDentSystem. A change by such a provider does not expand MaxDentSystem’s collection or use of clinic data and does not create a promise that the same provider, free tier or technical route will remain available indefinitely.
If a provider change affects Enterprise connectivity, MaxDentSystem may reasonably migrate to another provider or architecture, require a compliant third-party account/plan, modify configuration, temporarily suspend affected connectivity for security or migration, or make other proportionate technical changes. Any third-party fees not expressly included in the customer’s MaxDent order may be the customer’s responsibility, subject to applicable law and the applicable commercial agreement.
An outage, provider suspension, provider policy change, internet failure or migration event is not by itself a disclosure of clinical content or a security incident attributable to MaxDentSystem. If MaxDentSystem becomes aware of an actual security incident affecting data under its control, the incident-response provisions of this Privacy Policy continue to apply.
18. Children and Minor Patients
MaxDent services are intended for dental professionals, clinics, authorized staff, business customers and adult account holders, not for children to independently create consumer accounts or use the service as a child-directed application.
Clinics may lawfully maintain records relating to minor patients as part of dental care. The clinic—not MaxDentSystem—must determine the appropriate parental/guardian authorization, healthcare legal basis, retention period and disclosure obligations for those records.
19. Security Incidents and Breach Response
If MaxDentSystem becomes aware of a security incident affecting personal data under its control, it will investigate, contain and remediate the incident as appropriate and provide notifications to affected customers, individuals or regulators where applicable law requires.
For incidents originating within a clinic-controlled server, device, network, backup destination or user account, the clinic remains responsible for its own incident response obligations, while MaxDentSystem may provide technical assistance within the scope of support.
20. Changes to This Policy
We may update this Privacy Policy when MaxDent features, legal requirements, security architecture, payment/advertising tools, or platform integrations change. The updated policy will show a revised effective date.
If a material change significantly expands how personal or sensitive data is collected, used or shared, we will provide additional notice or obtain consent where required before applying the new use.
21. Contact and Complaints
Privacy questions, requests and complaints may be sent to: maxdentsystem@gmail.com. Please include enough information to identify the relevant account/relationship and the nature of the request, but do not send unnecessary patient health information by ordinary email.
MaxDentSystem • www.maxdentsystem.com • WhatsApp/Phone: +20 103 730 6914 • Taqseem el Shorta - 1st of Kafr El-Shiekh, Egypt.
Nothing in this policy limits mandatory privacy rights granted by applicable law. Where local data-protection or healthcare rules impose stronger obligations, those mandatory rules apply.
For platform submission, this policy should also be published as a stable, publicly accessible web page on the MaxDent domain and linked from the app and relevant platform/store settings. Actual app/site practices, Data Safety answers, consent notices, and platform declarations must remain consistent with this policy.
