Privacy Policy
Last updated: September 2026
CuspFlow, operated by Keplify LLC, a Delaware limited liability company ("Keplify", "CuspFlow", "we", "us" or "our"), provides cloud dental practice management software to dental clinics in Asia, South America and Africa. This Privacy Policy explains what information we collect, how we use, share and protect it, and the choices available to clinics and their patients. It forms part of our Terms of Service.
1. Our role: controller and processor
We handle personal information in two capacities:
- As a processor (or operator) for the clinic data your staff enter, including patient records. The clinic decides what is collected and why and is the controller, responsible party or data fiduciary under its local law; we process that data on the clinic's behalf and instructions to provide the Service. Patients who want to access, correct or delete their records should contact their clinic.
- As a controller for the limited data we collect to run our business, such as the account and billing details of the clinic staff who sign up, and usage and security logs.
2. Information we collect
- Account data: name, email address, password (stored only as a secure hash), clinic name, country, phone and role of the staff who register and use the Service.
- Patient and clinical data entered by clinic staff, which may include patient names, contact details, date of birth, medical and dental history, allergies and medications, treatment plans and clinical notes, images and X-rays, appointments, lab cases, and consent or intake forms.
- Billing data: subscription plan, seat and storage usage, invoices, and payment details processed by our payment processor. We do not store full card numbers.
- Communications data: patient reminders and confirmations sent over WhatsApp and email on the clinic's behalf, and messages you send us for support.
- Usage and technical data: log data, device and browser information, IP address, and actions taken in the Service, used for security, troubleshooting and improvement.
3. How we collect it
We collect information directly from clinic staff when they register and use the Service, from data your staff enter about patients and operations, automatically through use of the Service (logs and cookies), and from our service providers (for example a payment or delivery status from the payment or messaging provider). Where a patient books through an optional online booking page, we collect the contact and appointment details they submit, on behalf of the clinic.
4. How we use information
We use information to:
- Provide, operate and maintain the Service and its features.
- Authenticate users, enforce roles, permissions and device limits, and keep the Service and its data secure.
- Process subscriptions, payments and invoices.
- Send transactional messages the clinic configures, such as appointment reminders, confirmations and receipts, and to provide support.
- Monitor, troubleshoot, analyze and improve the Service and develop new features.
- Comply with law and enforce our Terms.
We do not sell or rent personal information, we do not share patient data with third parties for their own marketing, and we do not use patient data to train third-party advertising or profiling systems.
5. Lawful basis
For account and business data we act as controller and rely on the performance of our contract with the clinic, our legitimate interest in running and securing the Service, and compliance with law. For patient data we act on the clinic's documented instructions; the clinic is responsible for having a valid lawful basis and any required consent under the law that applies to it before entering patient data into the Service.
6. Service providers and sharing
We rely on a small number of trusted providers (sub-processors) to run CuspFlow. They process data only on our instructions, under confidentiality and data-protection obligations, and solely to deliver their part of the Service:
- Supabase: cloud database, authentication and file storage that host the Service and Clinic Data.
- Cloudflare: hosting and content delivery for our websites and application.
- Stripe: subscription billing and payment processing.
- Resend: delivery of transactional emails such as reminders, receipts and confirmations.
- WhatsApp Business Platform (Meta): delivery of patient reminders and messages the clinic chooses to send over WhatsApp.
We may also disclose information if required by law or valid legal process, to protect the rights, safety and security of clinics, patients, the public or CuspFlow, or in connection with a merger, acquisition or sale of assets, in which case we will require the recipient to honor this Policy. See our current list of sub-processors, which we update as our providers change.
7. Where data is stored and processed
Clinic Data is hosted on cloud infrastructure operated by our providers, and may be stored and processed in data centers located outside the clinic's own country. Where data is transferred across borders, we rely on our providers' contractual and technical safeguards to protect it. Clinics remain responsible for any data-localization or cross-border transfer requirements that apply to them under their local law.
8. Security
We use reasonable technical and organizational measures to protect information, including encryption in transit (TLS) and at rest, per-clinic isolation enforced by row-level security so access to any clinic's data requires credentials scoped to that clinic, role-based and per-user permissions the clinic controls, a limit on the number of active devices per login, and access logging. No method of transmission or storage is completely secure, and clinics are responsible for safeguarding their own credentials and devices. If we become aware of a security incident affecting personal information, we will notify affected clinics without undue delay and as required by law.
9. Data retention and deletion
Clinic Data is retained for the duration of the subscription. If a subscription lapses or is cancelled, the clinic enters a 60-day view-only window during which all records remain readable and can be exported in full. If the subscription is not reactivated within that window, the Clinic Data is permanently deleted from active systems, and backup copies are overwritten in the ordinary backup cycle.
Individual records that clinic staff delete inside the Service (for example a patient, appointment or catalogue item) are removed from active use immediately and kept recoverable for 30 days, after which they move to archival storage and are eventually erased in line with the record-keeping requirements that apply in the clinic's country. We retain limited account and billing records for as long as needed to meet our own legal, tax and accounting obligations.
10. Your rights and choices
Clinics can access, correct, export and delete the data they hold in CuspFlow directly within the Service, and can request account closure at any time. Patients who wish to exercise rights over their records (such as access, correction or deletion) should contact their clinic, which controls that data and can act on the request using the tools we provide; we will support clinics in responding. Where your local law grants additional rights, such as the right to object to or restrict processing or to lodge a complaint with a data-protection authority, those rights continue to apply.
11. Patient and minor data
Dental records often include minors and sensitive health information. Clinics are responsible for collecting any consent required under their local law before entering such data and for handling it lawfully. CuspFlow provides the security, access controls, export and deletion tools that help clinics meet those obligations. We do not knowingly collect data directly from patients except through features a clinic enables, such as online booking or digital forms.
12. Cookies and local storage
We use only the cookies and browser storage needed to keep users signed in, maintain security, and remember basic preferences. We do not use third-party advertising cookies or cross-site tracking.
13. Marketing and automated decisions
We may send clinic staff service and product updates related to their account; you can opt out of non-essential messages. We do not make decisions producing legal or similarly significant effects about patients through solely automated processing.
14. Local data protection laws
CuspFlow is designed for clinics in Asia, South America and Africa, and our handling of personal information is intended to support clinics in meeting the data-protection laws that apply to them, such as POPIA in South Africa, the NDPA in Nigeria, the Data Protection Act in Kenya, the LGPD in Brazil, and the DPDP Act in India, among others. The clinic remains the party responsible to its patients and regulators for lawful processing.
15. Changes to this Policy
We may update this Policy from time to time. When we make material changes we will update the date above and, where appropriate, notify clinics through the Service. Your continued use after a change takes effect constitutes acceptance of the updated Policy.
16. Contact
For privacy questions or requests, contact us at privacy@cuspflow.co. Patients should contact their clinic in the first instance for questions about their own records.