VoxDenta - Terms of Service & Privacy Policy

    Are you a patient? Read the plain-English version — with read-aloud and larger-text options.

    TERMS OF SERVICE

    Effective Date: 30 July 2025

    1. ACCEPTANCE OF TERMS

    By accessing or using VoxDenta ("Service"), you ("User," "Dentist," or "Practice") agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, do not use the Service.

    2. DESCRIPTION OF SERVICE

    Applied Health Science Pty Ltd (ABN 50 665 812 797) trading as "VoxDenta" provides AIDA (AI Dental Assistant), an artificial intelligence-powered tool designed to assist dental professionals with administrative tasks, patient communication, and practice management. The Service is intended for use by licensed dental professionals only.

    3. USER RESPONSIBILITIES

    3.1 Professional Licensing

    • You represent that you are a licensed dental professional in good standing
    • You are responsible for ensuring your use complies with all applicable laws and professional standards

    3.2 Appropriate Use

    • The Service is for administrative and communication assistance only
    • You shall not use the Service for clinical diagnosis or treatment decisions
    • You remain solely responsible for all patient care decisions
    • You are responsible for reviewing, editing and adopting every draft note before it is relied on or entered into the patient record. VoxDenta does not sign off notes.

    3.3 Data Accuracy

    • You are responsible for the accuracy of information provided to the Service
    • You must verify any output or recommendations from the Service before acting upon them

    4. DATA OWNERSHIP AND CONTROL

    4.1 Your Data Ownership

    • You retain complete ownership of all data, conversations, and information processed through the Service
    • We claim no ownership rights to your data or patient information

    4.2 Data Deletion Rights

    • You may request deletion of any or all data at any time
    • Upon request, we will permanently delete your data within 30 days
    • You may export your data before deletion upon request

    4.3 Retention

    • We do not automatically delete your data after a fixed period. Records are kept until you delete them, so that you can meet your own record-keeping obligations (dental records generally must be kept for at least seven years, and longer for patients who were minors).
    • Raw audio segments captured during upload are deleted automatically seven days after the appointment.
    • If we introduce automatic or inactivity-based deletion in future, we will give you at least 30 days' notice before it takes effect.

    5. LIMITATIONS OF LIABILITY

    5.1 Disclaimer of Warranties

    THE SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.

    5.2 Limitation of Liability

    • WE SHALL NOT BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, OR CONSEQUENTIAL DAMAGES
    • OUR TOTAL LIABILITY SHALL NOT EXCEED THE AMOUNT PAID BY YOU FOR THE SERVICE
    • WE SPECIFICALLY DISCLAIM LIABILITY FOR ANY MEDICAL OR CLINICAL DECISIONS MADE USING THE SERVICE

    5.3 AI Limitations

    • The Service uses artificial intelligence which may produce inaccurate or inappropriate responses
    • You acknowledge AI systems are not infallible and agree to use professional judgment
    • We do not guarantee the accuracy, completeness, or reliability of AI-generated content

    6. INDEMNIFICATION

    You agree to indemnify and hold harmless the Company from any claims, damages, or expenses arising from your use of the Service or violation of these Terms.

    7. TERMINATION

    Either party may terminate this agreement at any time. Upon termination, your access will cease but data deletion rights remain available for 90 days.

    8. GOVERNING LAW

    These Terms are governed by NSW law, without regard to conflict of law principles.

    PRIVACY POLICY

    Last Updated: 27/08/2026

    1. Security by Design

    Applied Health Science Pty Ltd (ABN 50 665 812 797) trading as "VoxDenta" ("VoxDenta," "we," "us," or "our") provides AIDA (AI Dental Assistant), an AI-powered dental scribe application.

    Strong Encryption & Tier-1 Vendor Compliance

    VoxDenta protects your data through strong encryption and infrastructure providers that publish SOC 2 and ISO 27001 certification. Data is encrypted at rest using AES-256 and in transit using TLS 1.2+ across our entire infrastructure. Our transcription and clinical-intelligence providers necessarily process content in unencrypted form in order to perform their function; their use of that content is governed by the terms described under Authorized Sub-Processors.

    We operate in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Our business is located in Western Australia (WA 6015).

    Accessibility: A plain-English, patient-facing version of this policy is available at Privacy for patients, with a built-in read-aloud option, larger text and a high-contrast mode. If you need this policy in another format, please contact us.

    2. Australian Data Sovereignty

    Persistent Patient Records are hosted exclusively in Australia (Sydney Region).

    Your clinical notes, audio recordings, transcripts, and user accounts are stored within Australian jurisdiction in Google Cloud's australia-southeast1 (Sydney) region. Some processing occurs outside Australia — see Authorized Sub-Processors below.

    3. Our Role

    The Practitioner (You)

    You are the Data Controller. You maintain ownership of patient records and are responsible for obtaining patient consent.

    VoxDenta

    We are the Data Processor. We provide the interface to process audio and draft clinical notes for the practitioner's review. The practitioner reviews, edits and adopts every note; VoxDenta does not approve, sign off, or enter notes into the patient record.

    4. Information We Collect

    4.1 Account Information (Practitioner Data)

    • Name and email
    • Billing data and technical logs (IP address, device type)

    4.2 Consultation Data (Patient Data)

    • Audio Recordings: Voice recordings of the consultation
    • Transcripts & Notes: Text-based outputs generated by AI
    "No Patient ID" Architecture

    VoxDenta is designed to minimize risk. We do not require you to input, nor do we structure, Patient Names or Patient IDs within our database fields. However, the content of the audio/transcript will inevitably contain health information and potentially patient identifiers spoken during the session.

    4.3 Audio Data Lifecycle

    VoxDenta retains audio recordings as source records for verification, quality assurance, and medico-legal protection. Our audio data handling practices include:

    • Retention Period: Recordings, transcripts and notes are retained until you delete them. We do not currently apply automatic time-based deletion.
    • Storage Location: All recordings, transcripts and notes are stored in Australian data centres (Google Cloud australia-southeast1, Sydney) with encryption at rest. Processing by our speech-to-text and clinical-intelligence providers occurs outside Australia — see Authorized Sub-Processors.
    • Access Control: Within the application, audio recordings are accessible only to the account holder who was signed in at the time of recording. A small number of authorised VoxDenta engineers can access production systems where necessary to operate and support the service, under access controls and audit logging
    • Encryption: Audio data is encrypted at rest using industry-standard AES-256 encryption
    Audio Deletion

    Audio recordings will be permanently deleted under the following circumstances:

    • Your request: When you delete a session it is removed from the application immediately and permanently erased 30 days later. Deletion requests made to us are actioned within 30 days.
    • Raw upload segments: The individual audio segments uploaded during recording are deleted automatically seven days after the appointment. The combined recording is retained until you delete it.
    • No automatic expiry: We do not currently delete recordings automatically after a fixed retention period or after account inactivity. If that changes we will give at least 30 days' notice.

    5. Authorized Sub-Processors

    To provide high-quality transcription and clinical intelligence, VoxDenta transmits data to authorized sub-processors. Each is configured with strict security controls:

    Sub-ProcessorPurposeLocationSecurity Configuration
    Google Cloud Storage & FirestoreStorage of recordings, transcripts and notesSydney, AustraliaAES-256 encryption at rest, TLS 1.2+ in transit. Tenant-scoped access controls.
    Google Cloud Vertex AIClinical IntelligenceUnited States (Google Cloud global endpoint)Commercial API Terms. Encrypted in transit and at rest. Google's commercial terms prohibit using customer data to train foundation models. Requests are served from Google Cloud's global endpoint and are processed outside Australia, including in the United States.
    ElevenLabsSpeech-to-TextUSA (Transient)Encrypted in transit (TLS 1.2+). Audio is sent to ElevenLabs in two ways: after the appointment, via a time-limited link to the stored recording; and during the appointment, streamed live from the browser for approximately the first 30 seconds. ElevenLabs states that it maintains SOC 2 Type II certification. Use of the data is governed by ElevenLabs' published API terms.
    Temporal CloudOrchestrationManaged service (region not disclosed here)Identifiers only. Temporal schedules the processing steps. It receives session and account identifiers only — recordings, transcripts and notes are not sent to it and are not stored in workflow payloads. Transmitted over TLS 1.2+.
    StripeSubscription billingUnited States / AustraliaPractitioner name, email and billing details. No patient data. Card details are handled by Stripe and never reach VoxDenta.
    Firebase Authentication (Google)Practitioner sign-inUnited StatesEmail address and authentication credentials. No patient data.
    ZuploAPI gateway that authenticates and routes requestsGlobal edge networkSees request metadata and authentication tokens in transit. Recordings and notes pass through in transit only and are not stored by the gateway.

    Sub-Processor Security Certifications

    Our sub-processors maintain industry-recognized security certifications:

    Google Cloud
    SOC 2 Type IIISO 27001
    ElevenLabs
    SOC 2 Type IIGDPR
    Temporal Cloud
    SOC 2 Type II
    Transcript Filtering

    The transcript displayed in the application is filtered to clinically relevant content; non-clinical conversation is replaced with [redacted] in that view. This is a display filter, not de-identification — clinical content, including identifying details relevant to care, is retained verbatim. The unfiltered transcript is retained and is the version used to draft notes, so that the clinical record remains complete and reviewable for medico-legal purposes.

    Data Training Policy
    • Intelligence (Google): Google's commercial terms prohibit training their foundation models on your clinical data.
    • Speech-to-Text (ElevenLabs): Use of audio is governed by ElevenLabs' published API terms. We do not have a negotiated enterprise agreement with zero-retention terms at this time.
    • VoxDenta: We do not use your recordings, transcripts or notes to train our own models.

    6. Security Standards

    VoxDenta is not itself SOC 2 or ISO 27001 certified. We are a small team and we apply the following controls to protect data while it is in our control:

    Encryption at Rest

    AES-256

    Encryption in Transit

    TLS 1.2+

    Strict Access Control

    Internal MFA

    Vendor Vetting

    Sub-processors are chosen from vendors publishing SOC 2 or ISO 27001 certification

    While we implement industry-standard security measures, no system is 100% secure. We cannot guarantee absolute security but commit to maintaining reasonable and appropriate safeguards.

    7. Data Breach Notification

    We maintain a data breach response plan in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of an eligible data breach likely to result in serious harm, we will notify the affected practice and the Office of the Australian Information Commissioner as soon as practicable, and will support the practice in notifying affected individuals where required.

    8. Practitioner Obligations (Consent)

    You warrant that you have obtained express consent from patients to record their voice and have disclosed that third-party AI processors will handle their data.

    9. Contact Us

    For questions about this Privacy Policy or to exercise your privacy rights:

    Applied Health Science Pty Ltd

    ABN: 50 665 812 797

    Trading as: VoxDenta

    Location: Western Australia 6015

    Email: privacy@voxdenta.com

    Privacy Complaints

    We take privacy concerns seriously and will investigate all complaints promptly and confidentially. If you have a privacy complaint:

    • Contact us at privacy@voxdenta.com with details of your concern
    • We will acknowledge your complaint within 5 business days
    • We will provide a full response within 30 days
    External Complaints

    If you are unsatisfied with our response to your privacy concern, you may contact the Office of the Australian Information Commissioner (OAIC):

    • Phone: 1300 363 992
    • Website: oaic.gov.au
    • Email: enquiries@oaic.gov.au

    Last Updated: 27/08/2026

    VoxDenta

    AI Voice Assistant for Dental Documentation, enhancing clinical workflows and patient care.

    © 2026 Applied Health Science Pty Ltd trading as VoxDenta. All rights reserved.

    Applied Health Science Pty Ltd | ABN 50 665 812 797 | Western Australia 6015

    Security & Compliance: We utilise Google Cloud's ISO/IEC 27001 compliant managed cloud infrastructure. All data is encrypted at rest and in transit via industry best practices utilising AES256 encryption. As per the Privacy Act, all data is stored in Google Cloud's Australian data centres.