Oral Tech AI Pty Ltd (ACN 638 265 648) seeks to provide users (“You”) of its Technology with information about oral health and a platform to facilitate any services that may be required from a Dentist or other Registered Health Professional (“the Services”). The Services are constantly evolving and new services may be offered from time to time.
We comply with the Privacy Act 1988 (Cth) (“Privacy Act”) and the applicable Australian Privacy Principles under that Act in Australia. We take the protection of your Personal Information seriously and we have put measures in place to maintain the integrity of your Personal Information and provide full transparency and accountability of our conduct.
- “Technology” means any application, website (including but not limited to Smilo.ai) or other technology operated by us, including the Smilo.ai Application, Smilo web based widget, social media and other communication forums.
- “we”, “us” and “our” means Oral Tech AI Pty Ltd ACN 638 265 648 and any associated entities of that company, and each of them severally, and their related bodies corporate, associates and affiliates (Associates).
To access the Services, you must be at least 18 years old or, where the legal jurisdiction in which you are based prescribed a higher age, at least that age.
What is Personal Information?
Sensitive Information also includes Health Information and information to be used for biometric identification.
What types of Personal Information do we collect?
Examples of Personal Information we may collect include names, dates of birth, their source of inquiry, contact details (e.g. telephone number, email address and home/postal address), health aids and services required, body height and weight, languages spoken and financial details for payment for services. We also collect survey information which includes, but is not limited to, details of general health, oral health, symptoms, recent treatment and any future treatment you believe you may require
Names and contact details may also be collected from industry related contacts. By using our Technology, you consent to us collecting Personal Information, Health Information and Sensitive Information including photographic, videographic, radiographic and other images, and written information about your oral and general health and circumstances.
How do we collect Personal Information?
Personal Information may be collected using our Technology or other means. We have broadly outlined (below) our methods of collection and the Personal Information, Health Information and Sensitive Information which may be obtained from using our Technology.
General User Data
If you interact with our Technology, our technology service provider may record certain information about your visit, which may include but is not limited to:
- IP address;
- login details;
- geographic location domain name;
- internet service provider;
- the date and time of the visit;
- any information or documentation downloaded; the length of the session;
- the pages accessed;
- viewing and interaction activity, including but not limited to views, bounces, clicks, replies, forwards, opt outs and links;
- the website that referred you to our Technology or other source of inquiry; your purchase history through the Technology;
- the type and version of the browser used by you;
- the operating system and platform used by you; and
- other technology on the devices you use to access the Technology.,
Technical and Personal Data
If you register for an account with us we collect identifying Personal Information, including:
- Email address; Physical address; Phone number; Gender; Occupation;
- Date of birth and Age; Cultural background;
- Preferred language and other languages spoken; Emergency or next-of-kin details;
- Payment details for user fees (where applicable);
- Information about your private health insurance, including membership number; Your Medicare number and details;
- Your health care card, seniors card and DVA card number and details (if applicable); Your feedback, comments and conversations.
To fully interact with the Technology we will request that you disclose to us Personal Information, including Health Information and Sensitive Information, including:
- Demographic data and comments that you enter into a contact form – to understand your needs and provide you with information and/or services provided by the Technology;
- any data uploaded by you, including but not limited to:
- photographic, videographic, radiographic and other images of your teeth, gums, lips, tongue and other anatomy inside your mouth (oral and perioral structures)
- information you disclose to us about oral health issues you are experiencing and general health issues which may contribute to your oral health (including your body height and weight, allergies, medications taken, investigation results and symptoms) (“Images”); and
- responses to surveys, which may include such information as details of general health, oral health, symptoms, recent treatment and any future treatment you believe you may require.
When you use the Technology, we may collect images of you via:
- you manually uploading them;
- the camera or camera roll on the device via which you use the Technology (if you have granted us permission to access your camera or camera roll); or
- your social media account (if you choose to connect your social media account to your Smilo.ai account or the Technology).
We obtain only the specific images selected by you for use with the Technology even if you grant us access to your whole photo album.
Please note that while we do not require or request any metadata to be attached to images provided by you, metadata (including, for example, geotags) may be associated these images by default.
Third-Party Access Data
If we offer the functionality, and if you choose to login to the Technology, or download it, via a third-party platform or social media network (for example, but not limited to, Facebook, Google, Twitter, the Apple App Store and Google Play Store), or otherwise connect your account on the third-party platform or network to the Technology, we may collect information from that platform or network. The information we collect may include, but is not limited to, your social media alias, your name and, depending on your settings for the third- party platform or network, a list of your friends or connections (though we do not use, store or disclose this information). Our collection and processing of the information we obtain from social media platforms is governed by the requirements these social media platforms impose on us in their relevant terms and conditions (including their own privacy policies).
Oral Health Forum Data
The Technology includes the Oral Health Forum where users may ask general oral health questions or describe their own symptoms and receive answers from the administrators of the Technology or associated Dental Health Practitioners. Any posts uploaded by an individual user, and the answers to those posts from the administrators, will be displayed on the Technology for other users to see, including the name of the user and their profile picture if they have chosen to upload one to their profile.
Apple Vision Framework Data
For users of Apple devices, the Technology uses the Apple Vision Framework each time you choose to take an image from the camera of your smart device. While the Technology allows you to store and share your image, the Technology does not collect, store or share any Vision Framework data during this process.
However, to ensure the continued improvement and reliability of the Technology, we use the Apple Vision Framework to collect information from the debug log, including:
- Application Programming Interface (API) requests, responses, date, time & errors; Technology screen name while the screen is open;
- Technology user activity and tap actions;
- Smart device information, including but not limited to device manufacturer, model, Operating System type and version, time zone, device unique key and IP address); and User information such as first name, last name, email address and profile picture.
Dental Health Practitioner Data
We collect a range of information from dental health practitioners registered with our Services, which may include:
- services offered; fees charged; practice name; practice address; phone number; email address;
- health profession and specialty/sub-specialty; gender;
- academic qualifications;
- experience and specialisation summary; and languages spoken.
How do we use Personal Information?
We use Personal Information, Health Information and Sensitive Information for the Services which include:
- providing oral and dental health information tailored to the user who provides that information;
- referrals to dental health practitioners and other services for the user who provides that information; and
- to build the capacity of the Technology to better recognize oral and dental health issues experienced by users of the Technology in general (“Oral Health Data”).
We may also hold and use Personal Information for other purposes including:
- to contact you about your use of the Technology; providing you with oral health awareness information;
- sending you newsletters, publications, communications and advertising material (including third party publications, communications and advertising material). You can choose to stop receiving these communications at any time by:
- clicking on the “Unsubscribe” link on email correspondence;
- emailing firstname.lastname@example.org;
- to promote and drive engagement with our products and services, including the use of targeted online advertising;
- to send push notifications to your device, however, you may enable or disable notifications at any time on your device;
- to report to health professionals and their practices about the use and functionality of our services, including associated financial benefits;
- for data analytics to help us improve our service and products and the user experience, including by monitoring aggregate metrics such as total number of visitors, traffic, and demographic patterns;
- for payment processing and debt collection; and
- for other purposes that are notified to you at the time we collect your information, which you give your consent to, or which are authorised or required by law.
- responding to enquiries or providing/referring you to a relevant product or service provider as requested by you (including to remind you of an upcoming appointment, to confirm a booking, or to request feedback or participate in a survey or questionnaire); compiling and analysing statistics and/or case studies (where you have consented to the latter instance);
- administration, business planning, research and development and other internal management functions;
- surveys and customer feedback; complying with our legal obligations; audit; and
- other purposes for which it was collected.
Disclosure of Personal Information
Health Information and Sensitive Information is collected and used for the purpose of providing the Services. To facilitate the Services and offer other services to you from time to time, it may be necessary for disclosure of your Personal Health and Sensitive Information to our technology partners for the purpose of technology development; disclosure to our dental and other health professional partners for the purpose clinical professional development; and disclosure to entities which will provide you with health services to ensure the most appropriate services are offered to you. We will require those individuals or entities to agree that they will only use that information strictly for the purpose for which it has been disclosed to them.
In the course of our business, we may disclose Personal Information to:
- third parties where you have requested information, goods or services from them (e.g. Dental Health Practitioners when you opt for the Technology to refer you to them) and others from time to time;
- our Associates (as defined above);
- external organisations that are our agents, suppliers, service providers or contractors;
- advertisers for marketing material;
- our shareholders;
- third party IT and software suppliers where they are bound by confidentiality obligations;
- third parties purchasing, licencing or subscribing to use the Technology;
- third party providers of research services, payment processing service, data processing services and entities that support the security of the Technology and block suspicious behaviour;
- our professional advisers, such as accountants, lawyers, auditors and insurers where they are bound by confidentiality obligations;
- any other person notified to you at the time we collect your Personal Information, who you give your consent to, or to whom we are authorised or required by law to make such disclosure; and
- if required or authorised by law, regulatory bodies, government agencies and authorities, tribunals, law enforcement bodies and courts.
You should be aware that we may disclose your Personal Information through the sale, distribution, subscription or licencing of our Technology to outside entities, including those located overseas. However, we will only ever disclose your demographic data in an aggregated and deidentified manner (e.g. we may disclose a summary of all of our users by gender, aged group and locations).
You should also be aware that your Oral Health Data may become part of the Technology to increase the effectiveness of the Technology. Therefore, we may disclose your Oral Health Data through the sale, distribution, subscription or licencing of the Technology to third parties.
Where your Oral Health Data becomes part of the Technology and includes images of you, we will make reasonable efforts to crop, blur, distort or otherwise de-identify any parts of the images which identify you as a person and which are not required for recognising dental and oral health issues. Images in this form may be visible to other users of the Technology, including members of the general public.
Where your Oral Health Data becomes part of the Technology and includes information about your oral or general health issues and responses to surveys, this will only be disclosed after it has been aggregated and deidentified..
NOTE: You acknowledge that by requesting that we provide you with the Services you are agreeing that we may disclosure your information in accordance with the terms above.
We may disclose your Personal Information overseas but this will only be done in the manner described under Disclosure of Personal Information section above.
Dental Health Practitioner Information Sharing
If you consent within the Technology and request us to do so, we will share your Personal Information stored on the Technology to your Dental Health Practitioner if they are also a user of the Technology.
We will only share your Personal Information in this manner with your request and consent but in requesting us to do this you acknowledge that your Dental Health Practitioner will then be able to collect and hold your Personal Information on their systems which are subject to different privacy policies and security systems to that used in the Technology.
You consent to us using your Personal Information to send direct marketing material in relation to our products or services, Associatesʼ products or services, or the products or services of third parties.
You also consent to us disclosing your Personal Information to Associates, our partners, co‑publishers, our sponsors and other third parties, in order to facilitate direct marketing by those parties.
If you do not wish to receive marketing information from us, you may at any time opt-out of receipt of further marketing communications by contacting our Privacy Officer (contact details below). If direct marketing is by email, you may also use the unsubscribe function.
You may contact our Privacy Officer if you do not wish us to disclose your Personal Information to third parties for direct marketing purposes.
Cookies and Other Technologies
Cookies and other technologies may be used by us or by third parties when you visit the Technology. In some cases, we may collect Personal Information from cookies.
We may also collect anonymous data (which is not Personal Information) about performance and errors that occur while you use the Technology.
The information collected from cookies and other technologies is used solely for our internal purposes in managing the Technology and improving its functionality and reliability, as well as to assist us to better target advertising, report statistics, analyse trends, administer our services, diagnose any errors so that we can provide you with the best service.
Government related identifiers
We do not use any government related identifiers, such as driverʼs licence or Medicare numbers. We will not use or disclose any government related identifiers other than in accordance with the Privacy Act, or as otherwise required or authorised by law.
Storage of Personal Information
We take reasonable steps to protect Personal Information that we hold from:
- misuse, interference and loss; and
- unauthorized access, modification or disclosure.
Personal Information of a user is only ever stored on servers in the country of residence as advised by the user to us. Although we work to ensure our security systems align with industry best standard, there is always risk associated with the transmission of information via the internet.
You acknowledge that we cannot guarantee the security of any data transmission, and as such all data transmissions are entirely at your risk. Once we have received your Personal Information, we will take reasonable steps to use procedures and security features to try to prevent unauthorized access, modification or disclosure.
Data Rights and Retention
We endeavour to ensure that all Personal Information we hold is accurate, complete and up- to-date, however, we rely on the accuracy of the Personal Information provided by you or third parties authorised by you. To assist us with this, you should contact us if any of your Personal Information changes, or if you believe that the Personal Information we have is not accurate or complete.
If we no longer require Personal Information that we hold (including when we are no longer required by law to keep records relating to you), we will take such steps as are reasonable in the circumstances to destroy the information or ensure that it is de-identified.
Access and correction
You can ask us for access to your Personal Information or for us to correct or update your Personal Information by sending a written request to our Privacy Officer at the address below. We do not impose any charges for requests for access, correction or updates but may charge a small fee for providing printed information.
Before correcting or providing access to Personal Information, we will require your identity to be confirmed. While the Privacy Act provides you the option of not identifying yourself or of using a pseudonym, we must confirm your identity before we provide you with access or the ability to correct your Personal Information in order to maintain its security and integrity.
Requests for access or correction may be refused upon the grounds contained in the Privacy Act. Further, in some circumstances, we may not be able to comply with a request that you make in respect of your Personal Information. Reasons for this may include, but are not limited to, a legal requirement for us to retain certain Personal Information. If we refuse to provide access, or to correct Personal Information, we will provide you with reasons for the refusal.
If we do agree to your request for the deletion or de-identification of your Personal Information, we will delete or de-identify that Personal Information but assume that you would prefer us to keep a note of your email address on a confidential register of individuals who do not wish to be contacted to avoid sending you marketing and other information in future. If you would prefer us not to do this, you may direct us not to keep this information at any time but will need to acknowledge that we may market to you if you disclose, or consent to the disclosure of, your Personal Information to us in a separate and future manner.
Privacy related complaints should be directed to our Privacy Officer in writing at the email or postal address shown below. No charge will be imposed for making a complaint, or for dealing with the complaint. Once a complaint has been lodged, our Privacy Officer will acknowledge its receipt to you as soon as possible and we will endeavour to respond to your complaint as soon as possible.
We will do our best to ensure that our investigation is completed, and a decision on your complaint is communicated to you, within 30 days of our receipt of the written complaint. We will inform you if we need more time
If we are not able to resolve your complaint to your satisfaction you may also contact the Australian Information Commissioner on the following details:
Office of the Australian Information Commissioner GPO Box 5218 SYDNEY NSW 2001 Telephone: 1300 363 992 Website: www.oaic.gov.au
Changes to this policy