Privacy Policy
Last updated 20 September 2026
Your clinic decides what happens to its patients’ records. We hold them, protect them, and log every time one is opened. We never sell them and never train AI on them.
1. Who is responsible for what
Jordan’s Personal Data Protection Law No. 24 of 2023 splits responsibility between the "controller", who decides why data is held, and the "processor", who handles it on the controller’s instructions. SmileyWay is both, in different places, and it matters which:
- For patient records — histories, notes, treatment plans, images, appointments, invoices — the clinic is the controller and SmileyWay is only the processor. The clinic decides what is collected and why; we act on its instructions. If you are a patient and want a record corrected or erased, ask your clinic first: they hold that decision, not us.
- For clinic and staff accounts — the name, email and phone of the people who sign in, billing records, support tickets — SmileyWay is the controller.
2. What we hold
Account information, for everyone who signs in:
- Name, email address, phone number, role, and a one-way hash of your password (we never store the password itself and cannot read it).
- Language and display preferences, and whether two-factor authentication is on.
Clinical information, entered by a clinic about its patients:
- Identity and contact details, date of birth, medical history, allergies and medications.
- Clinical notes, treatment plans, tooth charts, uploaded images and documents.
- Appointments, attendance, and payments recorded at the clinic.
Technical and usage information, created by using the system:
- An access log entry every time a patient record is opened — who, what, when, and the IP address.
- Support tickets you send us, including any screenshot you choose to attach.
- Messages exchanged between a patient and clinic staff inside the app.
3. Why we hold it, and on what basis
Account data: to give you an account, authenticate you, bill your clinic and answer your support requests. The basis is the contract between us.
Clinical data: to provide the service the clinic has asked for. The clinic’s own basis for holding it — patient consent, a legal duty to keep dental records, or care itself — is the clinic’s to establish and to explain to its patients.
Access logs: to protect patients. Being able to show who opened a record is a safety requirement, and we keep those entries even when other data is deleted.
Reminders and notices: to send the appointment reminders and subscription notices you have asked for. A patient can turn appointment reminders off at any time from their account.
4. What we never do
We do not sell personal data. We do not share it with advertisers. We do not use patient records to train machine learning models, ours or anyone else’s. We do not read your clinical notes except where you ask us to look at something to fix a fault, and that access is logged like any other.
5. Who else touches the data
Running the service means other companies process some data on our behalf. Each is bound to use it only for what we ask. The current list:
- Railway — hosts the application servers and the database where clinical records are stored.
- Google (Firebase) — authentication, in-app messages, and push notifications to your device.
- Google (Gmail) — delivery of emails we send you, such as reminders and receipts.
- Green API — delivery of WhatsApp messages, where a clinic has enabled them. The message content passes through this provider.
We update this list when it changes. Clinics are given notice of a new sub-processor before it starts handling their data — see the Data Processing Addendum.
6. Where the data is held
SmileyWay runs on cloud infrastructure that may be located outside Jordan. That makes it a cross-border transfer under the Personal Data Protection Law, and the law places conditions on transfers of sensitive data — which health records are.
We are being direct about this because it is the part of our setup a clinic’s own compliance review should look at hardest. If you need your patients’ records to stay inside Jordan, talk to us before you sign up rather than after.
7. How long we keep it
Clinical records stay for as long as the clinic’s account is open, and for thirty days after it closes so the clinic can export them. We then delete them.
Account data is kept while the account is open and for up to twelve months afterwards, for billing and dispute records.
Access log entries are kept for at least seven years. They are a safety record and are not deleted on request.
8. How we protect it
The specific measures, so you can judge them rather than take our word for it:
- All traffic between your browser and our servers is encrypted in transit (HTTPS).
- Passwords are stored as bcrypt hashes, never in a readable form.
- Every request to our API is authenticated with a signed token that expires.
- Access is scoped by role and by clinic: a practitioner at one clinic cannot read another clinic’s patients, and a receptionist does not see clinical notes.
- Every patient-record view is written to an access log, including views by our own staff.
- Two-factor authentication is available on every account and we recommend it for practitioners.
No system is perfectly secure. If we ever discover a breach affecting your data we will notify the regulator and the affected clinic without undue delay, and tell you what happened, what was affected, and what we are doing about it.
9. Your rights
Under the Personal Data Protection Law you may ask to:
- Know what data is held about you and get a copy of it.
- Have inaccurate data corrected.
- Have data erased, where there is no legal or clinical reason to keep it.
- Withdraw consent you previously gave, without affecting what was done before you withdrew it.
- Object to a particular use of your data.
- Complain to the competent authority in Jordan if you are not satisfied with our answer.
For patient records, send the request to your clinic — they are the controller and the decision is theirs. For anything else, write to privacy@smiley-way.com and we will respond within thirty days.
10. Children
Dental practices treat children, so SmileyWay holds records about people under 18. Those records are entered by the clinic under the consent of a parent or guardian, which it is the clinic’s responsibility to obtain and record. A child does not get their own patient login; their guardian manages the account.
11. Cookies and local storage
We do not use advertising or tracking cookies, and there are no third-party analytics trackers on the site.
The app stores a few things in your browser so it works: your sign-in token, your language and theme choice, and small interface preferences. Clearing your browser data signs you out and removes them.
12. Changes to this policy
We will post any change here and update the date at the top. If a change materially affects how we handle your data, we will give notice in the app or by email before it takes effect.
13. Contact
Data protection questions and rights requests: privacy@smiley-way.com. Anything else: support@smiley-way.com.
This page is provided for information. It is not legal advice and it does not create a lawyer–client relationship. If you need advice about your own obligations, speak to a lawyer qualified in Jordan.