Are you a patient? Read the plain-English version — with read-aloud and larger-text options.
Effective Date: 30 July 2025
By accessing or using VoxDenta ("Service"), you ("User," "Dentist," or "Practice") agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, do not use the Service.
Applied Health Science Pty Ltd (ABN 50 665 812 797) trading as "VoxDenta" provides AIDA (AI Dental Assistant), an artificial intelligence-powered tool designed to assist dental professionals with administrative tasks, patient communication, and practice management. The Service is intended for use by licensed dental professionals only.
THE SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.
You agree to indemnify and hold harmless the Company from any claims, damages, or expenses arising from your use of the Service or violation of these Terms.
Either party may terminate this agreement at any time. Upon termination, your access will cease but data deletion rights remain available for 90 days.
These Terms are governed by NSW law, without regard to conflict of law principles.
Last Updated: 27/08/2026
Applied Health Science Pty Ltd (ABN 50 665 812 797) trading as "VoxDenta" ("VoxDenta," "we," "us," or "our") provides AIDA (AI Dental Assistant), an AI-powered dental scribe application.
VoxDenta protects your data through strong encryption and infrastructure providers that publish SOC 2 and ISO 27001 certification. Data is encrypted at rest using AES-256 and in transit using TLS 1.2+ across our entire infrastructure. Our transcription and clinical-intelligence providers necessarily process content in unencrypted form in order to perform their function; their use of that content is governed by the terms described under Authorized Sub-Processors.
We operate in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Our business is located in Western Australia (WA 6015).
Accessibility: A plain-English, patient-facing version of this policy is available at Privacy for patients, with a built-in read-aloud option, larger text and a high-contrast mode. If you need this policy in another format, please contact us.
Persistent Patient Records are hosted exclusively in Australia (Sydney Region).
Your clinical notes, audio recordings, transcripts, and user accounts are stored within Australian jurisdiction in Google Cloud's australia-southeast1 (Sydney) region. Some processing occurs outside Australia — see Authorized Sub-Processors below.
You are the Data Controller. You maintain ownership of patient records and are responsible for obtaining patient consent.
We are the Data Processor. We provide the interface to process audio and draft clinical notes for the practitioner's review. The practitioner reviews, edits and adopts every note; VoxDenta does not approve, sign off, or enter notes into the patient record.
VoxDenta is designed to minimize risk. We do not require you to input, nor do we structure, Patient Names or Patient IDs within our database fields. However, the content of the audio/transcript will inevitably contain health information and potentially patient identifiers spoken during the session.
VoxDenta retains audio recordings as source records for verification, quality assurance, and medico-legal protection. Our audio data handling practices include:
Audio recordings will be permanently deleted under the following circumstances:
To provide high-quality transcription and clinical intelligence, VoxDenta transmits data to authorized sub-processors. Each is configured with strict security controls:
| Sub-Processor | Purpose | Location | Security Configuration |
|---|---|---|---|
| Google Cloud Storage & Firestore | Storage of recordings, transcripts and notes | Sydney, Australia | AES-256 encryption at rest, TLS 1.2+ in transit. Tenant-scoped access controls. |
| Google Cloud Vertex AI | Clinical Intelligence | United States (Google Cloud global endpoint) | Commercial API Terms. Encrypted in transit and at rest. Google's commercial terms prohibit using customer data to train foundation models. Requests are served from Google Cloud's global endpoint and are processed outside Australia, including in the United States. |
| ElevenLabs | Speech-to-Text | USA (Transient) | Encrypted in transit (TLS 1.2+). Audio is sent to ElevenLabs in two ways: after the appointment, via a time-limited link to the stored recording; and during the appointment, streamed live from the browser for approximately the first 30 seconds. ElevenLabs states that it maintains SOC 2 Type II certification. Use of the data is governed by ElevenLabs' published API terms. |
| Temporal Cloud | Orchestration | Managed service (region not disclosed here) | Identifiers only. Temporal schedules the processing steps. It receives session and account identifiers only — recordings, transcripts and notes are not sent to it and are not stored in workflow payloads. Transmitted over TLS 1.2+. |
| Stripe | Subscription billing | United States / Australia | Practitioner name, email and billing details. No patient data. Card details are handled by Stripe and never reach VoxDenta. |
| Firebase Authentication (Google) | Practitioner sign-in | United States | Email address and authentication credentials. No patient data. |
| Zuplo | API gateway that authenticates and routes requests | Global edge network | Sees request metadata and authentication tokens in transit. Recordings and notes pass through in transit only and are not stored by the gateway. |
Our sub-processors maintain industry-recognized security certifications:
The transcript displayed in the application is filtered to clinically relevant content; non-clinical conversation is replaced with [redacted] in that view. This is a display filter, not de-identification — clinical content, including identifying details relevant to care, is retained verbatim. The unfiltered transcript is retained and is the version used to draft notes, so that the clinical record remains complete and reviewable for medico-legal purposes.
VoxDenta is not itself SOC 2 or ISO 27001 certified. We are a small team and we apply the following controls to protect data while it is in our control:
AES-256
TLS 1.2+
Internal MFA
Sub-processors are chosen from vendors publishing SOC 2 or ISO 27001 certification
While we implement industry-standard security measures, no system is 100% secure. We cannot guarantee absolute security but commit to maintaining reasonable and appropriate safeguards.
We maintain a data breach response plan in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of an eligible data breach likely to result in serious harm, we will notify the affected practice and the Office of the Australian Information Commissioner as soon as practicable, and will support the practice in notifying affected individuals where required.
You warrant that you have obtained express consent from patients to record their voice and have disclosed that third-party AI processors will handle their data.
For questions about this Privacy Policy or to exercise your privacy rights:
Applied Health Science Pty Ltd
ABN: 50 665 812 797
Trading as: VoxDenta
Location: Western Australia 6015
Email: privacy@voxdenta.com
We take privacy concerns seriously and will investigate all complaints promptly and confidentially. If you have a privacy complaint:
If you are unsatisfied with our response to your privacy concern, you may contact the Office of the Australian Information Commissioner (OAIC):
Last Updated: 27/08/2026