Privacy Policy
Who we are
DLabFlow is a management system for dental laboratories, operated by Ahmed Nabil ("DLabFlow", "we"), Cairo, Egypt. Contact: support@dlabflow.space.
Each dental laboratory that creates a lab on DLabFlow (the "Lab") runs its own private workspace at lab-name.dlabflow.space. The Lab decides what information it enters about its team, its clinics and the dental cases it produces. For that information the Lab is the data controller and DLabFlow is the processor that stores and processes it on the Lab's behalf. This policy explains what we store, why, and what your rights are.
What we collect
| Data | Where it comes from | Why |
|---|---|---|
| Lab account โ lab name, owner's name, email, username, password (stored only as a salted hash) | Entered when the Lab is created | To create and secure the Lab's workspace and to contact the owner about the service |
| Team and clinic accounts โ name, username, role, email, phone, specialty, optional salary field, clinic name, doctor name, address | Entered by the Lab owner or by the clinic | So team members and clinic doctors can sign in and work on the Lab's cases |
| Case and production data โ patient name or reference, tooth numbers, shade, prescription, photos, 3D scan files, notes, workflow history, quality checks, invoices, quotes, payments, inventory | Entered or uploaded by the Lab and its clinics | This is the core service: tracking dental work from request to delivery and billing |
| Attendance โ check-in / check-out times; whether the device was on the Lab's own network (the Lab's public internet address, which the Lab chooses to save) | Generated when team members use the app at the lab | Only when the Lab enables attendance |
| Clinic location โ an address pin | Only if a clinic chooses "share my location" | So the Lab knows where to deliver |
| Technical logs โ IP address, browser/app version, time of requests | Automatic, kept for a short period | Security, rate-limiting of sign-in attempts, troubleshooting |
We do not use advertising or analytics trackers, and we do not sell or rent data to anyone.
Phone permissions (iPhone app)
- Camera โ to scan case QR codes and labels, and to take case photos you choose to attach. Scanning happens on the device; nothing is uploaded unless you attach it.
- Microphone โ only when you record a voice note on a case.
- Photo library โ only when you choose a photo to attach.
- Location โ only when a clinic taps "share my location" to save its address.
The app stores the name of the lab you opened on your phone so it opens straight into it next time. Nothing else is stored on the phone beyond what the browser engine caches to show the app.
AI features
DLabFlow includes assistive features (daily briefing, case intake from a prescription photo, message drafts, quality hints). By default these run on rules inside DLabFlow and no data leaves our servers. A Lab may choose to connect its own AI provider key in Settings; from then on the specific case text or image being analysed is sent to that provider under the provider's terms. The Lab can disconnect the key at any time.
Where data is stored and how it is protected
- Servers hosted by DigitalOcean in Frankfurt, Germany (European Union). Each Lab has its own separate database and file store.
- All traffic is encrypted (HTTPS). Passwords are stored as salted hashes; two-factor authentication is available to every account; sign-in attempts are rate-limited.
- Automatic daily backups are kept for 14 days so a Lab can recover from mistakes.
- Access to the servers is limited to the DLabFlow operator for maintenance and support.
Patient information
Dental cases may contain a patient's name and clinical details. The Lab and its clinics are responsible for having the right to record this information and for entering only what is needed for the work. DLabFlow never contacts patients and never uses patient information for any purpose other than delivering the service to the Lab. DLabFlow is a lab management tool, not a medical device, and gives no clinical advice.
How long we keep data
For as long as the Lab's workspace is active. When a Lab asks us to close its workspace, its database and files are deleted within 30 days, after which they only remain in rolling backups for up to 14 more days. Technical logs are kept for up to 30 days.
Your rights and choices
- Access and correction โ team and clinic users can see and edit their own profile; the Lab owner manages all accounts and data.
- Delete your account โ any user can delete their own account inside the app (menu โ My login โ Delete my account). Deletion removes your name, contact details and sign-in immediately; production records the Lab needs to keep (for example an invoice you issued) stay, without your personal details.
- Close a Lab / export data โ the Lab owner can request a full export or closure of the workspace by emailing support@dlabflow.space.
- Questions or complaints โ write to us at the same address; we answer within a few working days.
Children
DLabFlow is a professional tool for dental laboratories and clinics. It is not directed at children and we do not knowingly create accounts for anyone under 18.
Changes
If we change this policy we will update the date at the top and, for significant changes, notify Lab owners by email.