Privacy
Privacy information
How ConphiDent handles public enquiries and clinic workspace information.
Public website information
When you request a demonstration, ConphiDent stores the contact and clinic information you provide so the team can respond to your enquiry. Do not submit patient health information through the demo form.
Clinic application data
Each clinic workspace is account-controlled and access is limited by staff role. Clinics remain responsible for entering accurate data, obtaining required patient permissions, and using the platform in accordance with applicable law and their agreement with ConphiDent.
WhatsApp communications
Clinic staff must send WhatsApp messages only to confirmed numbers and with appropriate consent. A recipient may reply STOP, UNSUBSCRIBE, or an equivalent request to stop non-essential WhatsApp communications; they can reply START to opt in again.
Service providers
ConphiDent uses a small number of service providers, which process information only on our instructions and only in order to run the platform. The application and its runtime logs are hosted by Vercel. Clinic records, WhatsApp conversations and encrypted credentials are held in a managed PostgreSQL database provided by Supabase. Both run in the Mumbai (India) region, and each vendor may access that infrastructure remotely from the United States in order to support it. Resend delivers transactional email such as password resets and laboratory notices. Where a clinic uses WhatsApp, Meta Platforms Ireland Limited and its affiliates operate the WhatsApp Business Platform that carries those messages: a patient’s WhatsApp number and the content of every message sent or received through it are transmitted to and processed by Meta, on Meta’s own infrastructure and under Meta’s terms, in order to deliver them. Message templates a clinic uses are submitted to Meta for review before they may be sent. ConphiDent does not send clinical records, billing documents or imaging to Meta; documents are shared as expiring links that open inside ConphiDent after the recipient is authenticated.
What we record about consent
For every patient WhatsApp number a clinic messages, ConphiDent keeps a consent ledger: what was consented to, when, how it was obtained, and every later change including a withdrawal. A patient who replies STOP is recorded as withdrawn and is excluded from further automated messages until they reply START. This record exists so a clinic can show, for any individual message, the basis on which it was sent.
Automated replies and AI processing
Where a clinic switches on the automated WhatsApp assistant, the patient’s message, the recent messages in that conversation, and that patient’s own upcoming appointment dates, times and treatment names are sent to OpenAI in the United States so that a reply can be generated. The patient’s WhatsApp phone number and the clinic’s Meta credentials are never sent, though the conversation history does include whatever the patient has typed, which may include their name. Staff can set any conversation to human replies or pause it, and nothing from that conversation is then sent to OpenAI.
Retention and deletion requests
We retain information only for as long as needed to operate the service, meet legal obligations, resolve disputes, and enforce agreements. A clinic or individual may request access, correction, or deletion by following our data deletion process. Requests are reviewed after identity and authority are verified.
Product previews
Public product screenshots use sanitized, fictional demonstration data and are not real patient records.
Contact
For privacy questions, email contact@conphident.live with the subject “Privacy request”.
Last updated: 3 September 2026.
