Privacy Policy
Privacy Policy
Mobile Application, Website, Clinics and Digital Services
AVMSmiles is a brand operated by Flexismile Private Limited, the legal entity responsible for the collection, processing, storage, use and protection of Personal Data under this Policy.
Effective Date / Last Updated: 20 May 2026
Prepared for: App Store, Google Play, website, mobile application, clinics and digital healthcare privacy disclosures.
AVMSmiles (“Company”, “we”, “our”, or “us”) is committed to safeguarding the privacy, confidentiality, and security of personal data entrusted to us by patients, users, and stakeholders. As a provider of dental healthcare services, we recognize that certain categories of information, particularly health-related data, are inherently sensitive in nature and require enhanced standards of protection.
This Privacy Policy (“Policy”) outlines the manner in which AVMSmiles collects, processes, stores, uses, discloses, and protects personal data in the course of providing its services, including but not limited to clinical care, appointment management, patient engagement, digital interactions, and marketing communications.
By accessing our website, submitting information, booking an appointment, or otherwise engaging with our services through any online or offline channel, you acknowledge that you have read, understood, and agreed to the terms of this Policy, and you consent to the collection and processing of your personal data in accordance with applicable laws.
This Policy is intended to ensure transparency, accountability, and compliance with the prevailing legal, regulatory, and ethical standards governing data protection, healthcare confidentiality, telecommunications, advertising practices, and consumer rights in India.
Data Fiduciary Identity and Contact Details
For the purposes of applicable data protection laws, including the Digital Personal Data Protection Act, 2023, the entity responsible for determining the purpose and means of processing Personal Data (“Data Fiduciary”) in relation to AVMSmiles services is as follows:
- Legal Entity Name: Flexismile Private Limited
- Registered Office Address: No. 5, Amrut Elegance, Nehru Road, Vile Parle (East), Mumbai, Maharashtra, India – 400057
- Operational / Corporate Office: Same as Registered Office Address
- Official Email: info@flexismile.in
- Contact Number: +91 9920221016
All matters relating to the collection, processing, storage, use, and protection of Personal Data shall be governed by this Privacy Policy and applicable laws in force.
1. Legal Framework and Governing Laws
This Privacy Policy has been formulated in accordance with, and shall be governed by, the applicable laws, regulations, and guidelines in force within the Republic of India, including but not limited to the following:
- The Digital Personal Data Protection Act, 2023, governing the lawful processing of digital personal data, including requirements relating to consent, purpose limitation, data principal rights, and data fiduciary obligations;
- The Information Technology Act, 2000, along with applicable rules thereunder, including provisions relating to electronic records, data security practices, and protection of sensitive personal data or information;
- The Consumer Protection Act, 2019, ensuring transparency, fairness, and protection of consumer rights in relation to data usage, disclosures, and service practices;
- The regulations, directions, and guidelines issued by the Telecom Regulatory Authority of India (TRAI), including but not limited to Distributed Ledger Technology (DLT) framework and Do Not Disturb (DND/DNC) norms governing commercial communications via SMS, calls, and other telecommunication channels;
- Ethical standards, professional conduct requirements, and confidentiality obligations prescribed by the National Medical Commission, including those applicable to healthcare practitioners handling patient data;
- Advertising and communication guidelines issued by the Advertising Standards Council of India (ASCI), particularly in relation to healthcare advertising, patient testimonials, and responsible use of data in promotional activities;
- Applicable directions, circulars, and regulatory frameworks issued by the Reserve Bank of India (RBI), to the extent that they relate to payment processing, financial transactions, and protection of payment-related data, where such services are facilitated by or through AVMSmiles.
In the event of any conflict between this Policy and applicable law, the provisions of the applicable law shall prevail.
2. Nature of Data Collected
In the course of providing dental healthcare services and associated patient engagement activities, AVMSmiles may collect and process various categories of personal data. Such data is collected through online platforms, clinic interactions, communication channels, and integrated third-party systems, strictly in accordance with applicable laws and for legitimate business and clinical purposes.
The categories of data collected are as follows:
2.1 Patient and Healthcare Data (Sensitive Personal Data)
AVMSmiles may collect and process health-related information that qualifies as sensitive personal data, including but not limited to:
- Medical and dental history provided by the patient;
- Diagnostic records, prescriptions, radiographic images (including X-rays), and other clinical documentation;
- Treatment plans, case notes, consultation records, and progress reports prepared by healthcare professionals.
Such data is essential for the provision of accurate diagnosis, treatment planning, and continuity of care. AVMSmiles acknowledges that healthcare data is of a highly sensitive nature and, accordingly, ensures that such data is handled with the highest degree of confidentiality, integrity, and security. Access to such data is strictly restricted to authorized medical professionals and personnel on a need-to-know basis and is governed by applicable legal, regulatory, and ethical standards.
2.2 CRM and Lead Management Data
AVMSmiles may collect and maintain personal data of prospective and existing patients for the purposes of lead management and service facilitation, including:
- Name, contact number, and email address;
- Residential location, city, or pincode;
- Source of enquiry or lead generation, including advertisements, website forms, referrals, or third-party platforms;
- Stated treatment interests or service preferences.
Such data is stored and processed within Customer Relationship Management (CRM) systems and associated platforms for purposes including, but not limited to:
- Lead identification, tracking, and qualification;
- Appointment scheduling and conversion management;
- Follow-up communication and patient engagement;
- Internal analytics and service optimization.
All such processing is carried out in accordance with applicable data protection laws and with appropriate safeguards.
2.3 Tracking and Behavioral Data
In order to enhance user experience and improve service delivery, AVMSmiles may collect certain technical and behavioral data through its digital platforms, including:
- Website usage data such as page visits, clicks, navigation patterns, and scrolling behavior;
- Campaign attribution data, including interaction with advertisements and referral sources;
- Data collected through cookies, tracking pixels, and similar technologies, including but not limited to Meta Pixel, Google Tags, and other analytics tools.
Such data is utilized for legitimate business purposes, including:
- Performance analysis of marketing campaigns;
- Retargeting and remarketing activities, subject to applicable consent requirements;
- Optimization of user journeys and conversion funnels;
- Enhancement of website functionality and user experience.
Where applicable, such tracking is conducted in accordance with user consent and applicable regulatory requirements.
2.4 Communication Data
AVMSmiles may collect and maintain records of communications between the Company and the Data Principal, including:
- Call recordings for quality assurance, training, and dispute resolution purposes;
- Messages exchanged via WhatsApp or other messaging platforms;
- SMS and email communications;
- Telecalling interaction logs, including call outcomes and engagement details.
Such communication data is collected and processed for purposes including service delivery, patient support, compliance monitoring, and internal quality improvement.
2.5 Financial and Transaction Data
Where applicable, AVMSmiles may facilitate the collection of financial and transactional information in relation to services rendered, including:
- Payment details processed through authorized and secure third-party payment gateways;
- Information related to financing options, including Equated Monthly Installments (EMI) or third-party credit facilities, where availed by the patient.
AVMSmiles does not store sensitive financial credentials such as full card numbers, CVV, or UPI authentication details on its systems. All such data is processed and secured by compliant payment service providers in accordance with applicable regulatory standards, including those prescribed by the Reserve Bank of India.
2.6 Mobile App Permissions, Device Data, and User Uploaded Content
AVMSmiles may collect and process certain information through its mobile application depending on the features used by the user and permissions granted on the device. Such data may include:
- Account and profile information such as name, mobile number, email address, age, gender, patient ID, clinic preference, appointment history, and treatment interest;
- Camera access, where required, to capture dental images, prescriptions, reports, identity documents, treatment-related photos, or other records uploaded by the user;
- Photo gallery, media library, and file/document access, where required, to allow users to upload existing medical records, prescriptions, X-rays, invoices, reports, claim documents, or other treatment-related documents;
- Microphone access, where required, for voice support, teleconsultation, video consultation, audio interaction, or recording of audio with user consent;
- Location data, including approximate or precise location where permitted by the user, to identify nearby AVMSmiles clinics, display clinic distance, assist with directions, recommend city-based clinic options, or improve service availability;
- Device information such as device model, operating system, browser/app version, IP address, device identifiers, language settings, and network information;
- App activity and usage data such as screens visited, clicks, appointment booking journey, form submissions, feature usage, session duration, and in-app interactions;
- Crash logs, diagnostics, and performance data for detecting bugs, improving app stability, troubleshooting errors, and enhancing user experience;
- Advertising identifiers, device identifiers, or similar technical identifiers, where applicable and subject to platform consent requirements, for campaign attribution, analytics, remarketing, fraud prevention, and service optimization;
- Push notification tokens for sending appointment reminders, treatment updates, service alerts, follow-up reminders, promotional communication where consented, and important account or clinic-related notifications;
- Calendar access, where enabled by the user, to add appointment reminders to the user's device calendar;
- Contact access, where specifically enabled by the user, for referral, family appointment booking, or invite-related features;
- Phone or calling permission, where applicable, to allow users to directly call AVMSmiles clinics, support teams, or appointment desks from within the app;
- SMS or OTP-related access, where applicable, only for authentication, verification, or auto-reading OTPs with user permission and in accordance with applicable platform rules.
AVMSmiles collects such data only where necessary for app functionality, patient support, appointment booking, clinic discovery, medical record upload, communication, analytics, security, service improvement, or consent-based marketing. Users may allow, deny, or revoke permissions through their device settings. Denial or withdrawal of certain permissions may limit specific app features, such as uploading documents, finding nearby clinics, receiving reminders, or accessing teleconsultation features.
3. Purpose of Processing
AVMSmiles processes Personal Data, including Sensitive Personal Data, strictly for lawful, specific, and legitimate purposes in accordance with applicable data protection laws. All processing activities are undertaken in a manner that is proportionate, necessary, and limited to the purposes for which such data has been collected, and are supported by valid legal bases, including consent and statutory obligations.
The purposes for which Personal Data may be processed include, but are not limited to, the following:
3.1 Clinical Purposes
Personal Data, particularly health-related information, is processed for the provision of dental healthcare services, including:
- Conducting diagnosis, evaluation, and treatment of patients;
- Developing and implementing individualized treatment plans;
- Maintaining accurate and complete medical and dental records;
- Ensuring continuity of care across consultations, procedures, and follow-ups.
Such processing is essential for delivering safe, effective, and evidence-based clinical care and is carried out in compliance with applicable medical and ethical standards.
3.2 Operational Purposes
Personal Data may be processed for administrative and operational functions necessary for the efficient delivery of services, including:
- Appointment scheduling, confirmation, and reminders;
- Patient journey management, including coordination between clinics, practitioners, and support staff;
- Handling patient queries, feedback, and support requests;
- Internal record-keeping, reporting, and service optimization.
Such processing enables AVMSmiles to provide a seamless and efficient patient experience.
3.3 Marketing and Communication Purposes (Consent-Based)
Subject to the explicit or deemed consent of the Data Principal and in compliance with applicable communication and advertising regulations, Personal Data may be processed for marketing and engagement activities, including:
- Sending promotional offers, service updates, and health-related information;
- Issuing reminders for appointments, follow-ups, and preventive care;
- Conducting awareness campaigns related to dental health and wellness;
- Delivering personalized advertisements, including retargeting and remarketing campaigns, based on user interactions and preferences.
All such communications are carried out in accordance with applicable consent requirements, including regulations governing telecommunication and digital marketing practices, and Data Principals are provided with mechanisms to opt out of such communications at any time.
3.4 Compliance and Legal Obligations
Personal Data may be processed to comply with applicable legal, regulatory, and statutory requirements, including:
- Maintenance of records as required under healthcare, taxation, and other applicable laws;
- Compliance with audit, inspection, and reporting obligations;
- Responding to lawful requests from governmental or regulatory authorities;
- Establishing, exercising, or defending legal claims.
Such processing is undertaken strictly to the extent necessary to meet legal and regulatory obligations.
3.5 Mobile App Functionality and Permission-Based Purposes
Personal Data and device permission-based data collected through the AVMSmiles mobile application may be processed for the following purposes:
- Creating and managing user accounts and patient profiles;
- Booking, confirming, rescheduling, or cancelling appointments;
- Identifying nearby clinics and enabling location-based clinic recommendations;
- Uploading, storing, and reviewing dental records, prescriptions, reports, X-rays, invoices, and treatment-related documents;
- Enabling teleconsultation, voice support, video consultation, or patient support interactions, where applicable;
- Sending push notifications for appointment reminders, treatment updates, follow-ups, payment updates, service alerts, and consent-based promotional communication;
- Improving app functionality, user experience, app security, service quality, and operational efficiency;
- Conducting analytics, attribution, campaign performance measurement, remarketing, and service optimization, subject to applicable consent requirements;
- Detecting, preventing, and resolving technical issues, crashes, fraud, misuse, unauthorized access, or security incidents.
4. Consent Architecture
AVMSmiles adopts a structured and layered consent framework to ensure that the collection and processing of Personal Data, including Sensitive Personal Data, is conducted in a lawful, fair, and transparent manner. All consent obtained is in accordance with applicable data protection laws and is designed to be free, specific, informed, unambiguous, and capable of being withdrawn by the Data Principal at any time.
The categories of consent obtained by AVMSmiles are as follows:
4.1 Explicit Consent
Explicit consent is obtained from the Data Principal at the point of initial data collection through various channels, including but not limited to:
- Submission of lead generation forms on websites or landing pages;
- Online enquiries or appointment booking interfaces;
- Physical or digital registration at AVMSmiles clinics;
- Any other direct interaction where Personal Data is voluntarily provided.
By submitting such information, the Data Principal expressly consents to the collection, use, storage, and processing of their Personal Data for the purposes specified in this Policy.
4.2 Communication Consent
The Data Principal, upon providing their contact details, expressly authorizes AVMSmiles to communicate with them through various channels, including:
- Voice calls;
- Short Message Service (SMS);
- Messaging platforms, including but not limited to WhatsApp;
- Electronic mail (email).
Such communication may include service-related information, appointment confirmations, reminders, and, where permitted, promotional content. All communications are carried out in compliance with applicable telecommunication and data protection regulations, and the Data Principal is provided with appropriate mechanisms to opt out of such communications.
4.3 Medical Consent
Separate and specific consent is obtained from patients in relation to the collection, use, and processing of health-related information, including:
- Consent for medical examination, diagnosis, and treatment;
- Consent for creation, storage, and maintenance of medical and dental records;
- Consent for use of clinical data for continuity of care and internal clinical purposes.
Such consent is obtained in accordance with applicable medical, ethical, and legal standards, and is documented in a manner consistent with professional healthcare practices.
4.4 Marketing Consent
Where Personal Data is used for promotional or marketing purposes, including the dissemination of offers, advertisements, and awareness campaigns, AVMSmiles ensures that:
- Appropriate consent is obtained prior to initiating such communication;
- The nature and purpose of such communication is clearly disclosed to the Data Principal;
- Data Principals are provided with clear and accessible options to opt out or withdraw consent for such communications at any time.
All marketing activities are conducted in compliance with applicable laws, including those governing electronic communications and advertising standards.
4.5 Nature and Validity of Consent
All consent obtained by AVMSmiles adheres to the following principles:
- Free: Consent is provided voluntarily without coercion or undue influence;
- Informed: The Data Principal is adequately informed about the nature and purpose of data processing;
- Specific: Consent is obtained for clearly defined purposes and is not bundled indiscriminately;
- Unambiguous: Consent is indicated through clear affirmative action;
- Withdrawable: The Data Principal retains the right to withdraw consent at any time, subject to applicable legal and operational constraints.
Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.
4.6 Mobile App Permission Consent
Where the AVMSmiles mobile application requests access to device features such as camera, photo gallery, file storage, microphone, location, contacts, calendar, phone, SMS, notifications, or advertising identifiers, such access shall be based on user permission, platform-level consent, or other lawful basis as applicable.
Users may grant, deny, or revoke such permissions at any time through their mobile device settings. AVMSmiles shall not access restricted device permissions unless the user has enabled such access, except where permitted by applicable law or platform functionality. Withdrawal of device permissions may affect the availability or performance of certain app features.
5. TRAI and DNC Compliance
AVMSmiles ensures that all telecommunication and electronic communication practices are conducted in strict compliance with the regulations, directions, and guidelines issued by the Telecom Regulatory Authority of India (TRAI), including but not limited to the Distributed Ledger Technology (DLT) framework and Do Not Disturb (DND) / Do Not Call (DNC) regulations governing commercial communications.
5.1 Compliance with DLT Framework
All SMS communications initiated by or on behalf of AVMSmiles are routed through telecom operators and platforms that are registered under the TRAI-mandated Distributed Ledger Technology (DLT) system.
In this regard:
- All sender IDs, message templates, and communication headers are duly registered and approved in accordance with applicable DLT requirements;
- Messages are transmitted only through authorized and compliant telecommunication channels;
- Records of communication templates and delivery logs are maintained for audit and regulatory purposes.
5.2 Categorization of Messages
In accordance with TRAI guidelines, AVMSmiles classifies all outbound communications into the following categories:
- Transactional Communications: These include messages that are essential for the provision of services, such as appointment confirmations, reminders, follow-up notifications, and other service-related updates.
- Promotional Communications: These include messages relating to offers, discounts, marketing campaigns, awareness initiatives, and other promotional content intended to inform or engage users.
Such categorization ensures that communications are sent in compliance with applicable consent and regulatory requirements.
5.3 Do Not Disturb (DND) / Do Not Call (DNC) Compliance
AVMSmiles maintains strict adherence to DND/DNC regulations as prescribed by TRAI. In particular:
- Data Principals who have registered their contact numbers under the National Do Not Disturb (NDND) registry shall not receive unsolicited promotional communications via SMS or voice calls;
- Promotional communications shall be restricted to users who have provided valid consent and are not registered under DND, or where such communication is otherwise permitted under applicable regulations;
- Users registered under DND shall receive only transactional or service-related communications that are necessary for the fulfillment of services requested by them.
5.4 Opt-Out and Preference Management
AVMSmiles provides mechanisms for users to manage their communication preferences, including the ability to opt out of promotional communications at any time. Upon receipt of such opt-out requests:
- The user's preferences shall be updated within a reasonable timeframe;
- Further promotional communications shall be discontinued in accordance with applicable regulations.
5.5 Compliance Responsibility
AVMSmiles undertakes to regularly review its communication practices and ensure ongoing compliance with TRAI regulations. Any violation or deviation identified shall be addressed promptly through corrective measures, including system updates, process modifications, and staff training.
6. WhatsApp and Telephony Compliance
AVMSmiles ensures that all communications conducted through messaging platforms and telephony channels are carried out in compliance with applicable data protection laws, telecommunication regulations, and industry best practices. Such communications are governed by principles of consent, transparency, purpose limitation, and user control.
6.1 WhatsApp Communication (via Official APIs)
AVMSmiles utilizes authorized and compliant messaging infrastructure, including official WhatsApp Business APIs, for the purpose of engaging with users and patients.
In this regard:
- Messages are sent only to individuals who have provided prior consent or have initiated communication through approved channels;
- All outbound communications are conducted using pre-approved templates, in accordance with platform policies and applicable regulations;
- Communications may include appointment confirmations, reminders, service updates, and, where permitted, promotional messages;
- Users are provided with clear and accessible mechanisms to opt out or discontinue receiving such communications at any time.
AVMSmiles ensures that all WhatsApp communications are aligned with applicable platform guidelines, data protection requirements, and user consent preferences.
6.2 Calling and Telecalling Practices
AVMSmiles undertakes telephonic communication in a responsible and compliant manner, ensuring that calls are made only under lawful and consent-based conditions.
In particular:
- Calls are initiated only to individuals who have provided valid consent to be contacted or who are existing patients with an established service relationship;
- Telecalling activities are conducted strictly for purposes such as appointment scheduling, follow-ups, patient support, and, where permitted, service-related communication;
- Promotional calling is carried out only in accordance with applicable consent and regulatory requirements.
6.3 Call Recording and Monitoring
AVMSmiles may record telephonic conversations for legitimate business purposes, including but not limited to:
- Training and capacity building of personnel;
- Quality assurance and service improvement;
- Monitoring compliance with internal policies and regulatory requirements;
- Resolution of disputes and verification of communication.
Such recordings are maintained securely and access is restricted to authorized personnel on a need-to-know basis.
6.4 User Rights and Opt-Out Mechanism
Data Principals retain the right to:
- Withdraw consent for telephonic or messaging communication;
- Request cessation of non-essential or promotional communication;
- Exercise control over communication preferences at any time.
Upon receipt of such requests, AVMSmiles shall take reasonable steps to update communication preferences and ensure compliance within a reasonable timeframe.
7. CRM and Third-Party Data Sharing
AVMSmiles may engage third-party service providers and technology platforms to facilitate the efficient delivery of its services, including patient management, communication, marketing, and payment processing. In the course of such engagements, limited Personal Data may be shared with such third parties strictly on a need-to-know and purpose-limited basis.
All such data sharing is carried out in compliance with applicable laws and subject to appropriate contractual, technical, and organizational safeguards.
7.1 Categories of Third-Party Recipients
Personal Data may be shared with the following categories of third-party service providers:
- Customer Relationship Management (CRM) Platforms: For the purpose of lead management, patient data organization, appointment tracking, and service coordination;
- Communication Service Providers: Including platforms facilitating communication via WhatsApp, SMS, email, and voice calls, for sending transactional and, where permitted, promotional communications;
- Marketing and Analytics Platforms: Including digital advertising and analytics platforms (such as Meta, Google, and similar providers) for campaign execution, performance measurement, and user engagement, subject to applicable consent requirements;
- Payment Processing Partners: Authorized payment gateways and financial service providers for the processing of payments, refunds, and related financial transactions.
- Mobile App, Analytics, and Diagnostic Service Providers: AVMSmiles may use third-party mobile app service providers, analytics tools, cloud service providers, crash reporting tools, app performance monitoring tools, advertising platforms, and attribution partners, including but not limited to Google, Firebase, Meta, Google Ads, analytics SDKs, cloud hosting providers, and similar technology partners. Such providers may process limited data such as device information, app activity, crash logs, diagnostics, advertising identifiers, campaign attribution data, and user interaction data for app performance, analytics, troubleshooting, security, marketing attribution, and service improvement, subject to applicable consent requirements and contractual safeguards.
7.2 Purpose Limitation and Data Minimization
Personal Data shared with third parties shall be limited to the minimum information necessary to fulfill the specific purpose for which such sharing is undertaken. Third parties are not authorized to process Personal Data for any purpose other than that expressly permitted by AVMSmiles.
7.3 No Sale of Personal Data
AVMSmiles does not sell, rent, lease, or otherwise commercially exploit Personal Data of Data Principals to any third party.
All Personal Data collected is used strictly for the purposes outlined in this Privacy Policy, including service delivery, patient care, communication, and permitted marketing activities, and is shared only with authorized service providers under controlled and compliant conditions.
7.4 Restrictions on Use of Data
All third-party service providers are expressly prohibited from:
- Selling, leasing, or otherwise commercializing Personal Data received from AVMSmiles;
- Using such data for their own independent purposes or for the benefit of any other entity;
- Retaining Personal Data beyond the period necessary for the provision of contracted services;
- Engaging in any activity that may result in misuse, unauthorized disclosure, or breach of Personal Data.
7.5 Contractual Safeguards and Compliance Requirements
AVMSmiles ensures that all third-party engagements are governed by legally binding agreements that include, but are not limited to:
- Confidentiality obligations to protect Personal Data from unauthorized access or disclosure;
- Data protection clauses requiring compliance with applicable data protection laws and standards;
- Security requirements mandating implementation of appropriate technical and organizational safeguards;
- Obligations to notify AVMSmiles of any data breach, incident, or unauthorized access;
- Provisions governing data return or deletion upon termination of services.
7.6 Due Diligence and Oversight
AVMSmiles undertakes reasonable due diligence prior to onboarding third-party service providers and periodically reviews their compliance with applicable data protection and security standards. Appropriate oversight mechanisms are implemented to ensure that such third parties adhere to the terms of engagement and applicable regulatory requirements.
7.7 Cross-Border Data Transfer
In the course of providing services, AVMSmiles may engage third-party service providers whose systems or infrastructure may be located outside the territorial boundaries of India.
Accordingly:
- Personal Data may be transferred to, stored in, or processed in jurisdictions outside India, where such transfer is necessary for the provision of services, including but not limited to communication platforms, analytics tools, and marketing services;
- AVMSmiles shall ensure that such cross-border data transfers are conducted in compliance with applicable laws and are subject to appropriate safeguards, including contractual obligations, data protection standards, and security measures;
- All reasonable steps shall be taken to ensure that such third parties provide a level of data protection that is comparable to applicable legal requirements in India.
8. Tracking and Advertising Ethics
AVMSmiles undertakes all tracking, analytics, and advertising activities in compliance with applicable laws, data protection principles, and the guidelines issued by the Advertising Standards Council of India (ASCI). The Company is committed to ensuring that all advertising practices are transparent, ethical, and do not compromise the privacy or rights of individuals.
8.1 Ethical Advertising Practices
In the course of promoting its services, AVMSmiles adheres to the following principles:
- All advertisements, promotional materials, and communications shall be truthful, accurate, and not misleading in any manner;
- No false claims, exaggerated representations, or unsubstantiated guarantees shall be made in relation to dental treatments or outcomes;
- Personal Data, including patient information, shall not be used in advertising without obtaining prior, explicit, and informed consent from the concerned individual;
- Patient testimonials, images, or case studies, where used, shall comply with applicable legal and ethical requirements, including appropriate disclosures and safeguards to protect identity where necessary.
8.2 Use of Tracking Technologies
AVMSmiles may employ cookies, tracking pixels, and similar technologies to collect data relating to user interactions with its digital platforms. Such technologies may include, but are not limited to:
- Website analytics tools;
- Advertising tracking tools such as Meta Pixel, Google Tags, or equivalent technologies;
- Session tracking and behavioral analysis tools.
The use of such technologies is intended to enhance user experience, improve service delivery, and enable effective communication with users.
8.3 Mobile App Analytics, SDKs, and Advertising Identifiers
The AVMSmiles mobile application may use mobile analytics tools, software development kits, advertising identifiers, attribution tools, and similar technologies to understand app usage, measure campaign performance, improve user experience, detect errors, and deliver relevant advertisements.
Such tools may collect information such as device identifiers, advertising IDs, app activity, session data, clicks, screens viewed, crash logs, referral source, campaign source, and interaction history. Where required by applicable law or platform policy, AVMSmiles obtains user consent before using such identifiers for tracking, personalized advertising, or cross-app/cross-site attribution.
No sensitive health-related information is knowingly used for targeted advertising without explicit consent.
8.4 Retargeting and Behavioral Advertising
AVMSmiles may engage in retargeting or remarketing activities to display relevant advertisements to users based on their interaction with the Company's website or digital platforms.
In this regard:
- Retargeting is carried out using aggregated, pseudonymized, or anonymized data to the extent feasible;
- No sensitive personal data, including health-related information, is knowingly used for targeted advertising without explicit consent;
- Such activities are conducted in compliance with applicable data protection and advertising regulations.
8.5 Transparency and User Disclosure
AVMSmiles ensures transparency in its advertising and tracking practices. Users are hereby informed that:
- They may see advertisements relating to AVMSmiles services on third-party platforms based on their prior interactions with the Company's website or digital channels;
- Such advertisements may be influenced by browsing behavior, engagement history, or interaction with marketing campaigns;
- Users may manage or restrict tracking preferences through browser settings or platform-specific controls, where available.
8.6 User Rights and Control
Users retain the right to:
- Control or disable cookies through browser settings;
- Opt out of certain forms of targeted advertising through platform-specific mechanisms;
- Withdraw consent for marketing communications, in accordance with this Policy.
9. Medical and Dental Ethics Compliance
AVMSmiles is committed to upholding the highest standards of professional ethics, patient confidentiality, and data protection in accordance with the ethical guidelines and professional conduct standards prescribed by the National Medical Commission and other applicable regulatory bodies governing healthcare practices in India.
9.1 Patient Confidentiality
AVMSmiles recognizes patient confidentiality as a fundamental obligation in the provision of healthcare services. Accordingly:
- All patient-related information, including medical and dental records, diagnostic data, and consultation details, is treated as strictly confidential;
- Access to such information is restricted to authorized healthcare professionals and personnel on a need-to-know basis;
- Appropriate technical and organizational safeguards are implemented to prevent unauthorized access, disclosure, or misuse of patient data.
9.2 Restrictions on Public Disclosure
AVMSmiles shall not disclose, publish, or otherwise make available any patient-related data in the public domain without obtaining prior, explicit, and informed consent from the concerned individual.
In particular:
- No patient data, including personal identifiers, clinical information, or treatment details, shall be used for promotional, educational, or any other external purpose without consent;
- Any disclosure of patient-related information shall be limited to the extent necessary and in compliance with applicable legal and ethical standards.
9.3 Use of Clinical Cases, Images, and Testimonials
Where clinical cases, images, testimonials, or treatment outcomes are used for educational, promotional, or informational purposes, AVMSmiles ensures that:
- Prior written consent is obtained from the patient in a clear and documented manner;
- The purpose, scope, and nature of such use are adequately disclosed to the patient at the time of obtaining consent;
- Reasonable measures are taken to protect the identity of the patient, including anonymization or masking of identifiable features, where appropriate;
- Such usage complies with applicable legal, ethical, and professional guidelines governing healthcare communication and advertising.
9.4 Ethical Handling of Patient Data
All personnel associated with AVMSmiles, including doctors, clinical staff, and administrative teams, are required to:
- Adhere to established standards of medical and dental ethics;
- Maintain strict confidentiality of patient information at all times;
- Avoid any unauthorized use or disclosure of patient data;
- Handle patient data with due care, integrity, and professional responsibility.
10. Consumer Protection Compliance
AVMSmiles is committed to ensuring fairness, transparency, and accountability in all aspects of its data handling practices, in accordance with the provisions of the Consumer Protection Act, 2019 and related guidelines governing consumer rights and protection.
10.1 Transparency in Data Usage
AVMSmiles ensures that all Personal Data collected from Data Principals is handled in a transparent manner. In particular:
- The nature, purpose, and scope of data collection and processing are clearly communicated to users at the time of data collection;
- Users are informed about how their data will be used, including for service delivery, communication, and, where applicable, marketing purposes;
- No material information relating to data usage is concealed or misrepresented.
10.2 Prohibition of Unfair or Deceptive Practices
AVMSmiles undertakes that:
- No unfair, misleading, or deceptive practices shall be employed in relation to the collection, use, or disclosure of Personal Data;
- Personal Data shall not be collected or processed through misrepresentation, coercion, or lack of adequate disclosure;
- Users shall not be subjected to any undisclosed data practices that may adversely affect their rights or interests.
10.3 Clear Opt-Out and User Control Mechanisms
AVMSmiles provides Data Principals with clear, accessible, and effective mechanisms to exercise control over their Personal Data, including:
- The ability to opt out of promotional communications at any time through designated channels;
- The option to withdraw consent for specific categories of data processing, subject to applicable legal and operational limitations;
- Access to communication preference management tools, where available.
All opt-out and withdrawal requests are processed within a reasonable timeframe and in accordance with applicable legal requirements.
10.4 Grievance Redressal and Consumer Rights
In line with consumer protection principles, AVMSmiles ensures that:
- Users have access to appropriate grievance redressal mechanisms for addressing concerns relating to data usage or privacy;
- Complaints are acknowledged and resolved in a fair, timely, and transparent manner;
- Consumer rights, including the right to be informed and the right to seek redressal, are respected and upheld at all times.
11. Data Security Measures
AVMSmiles implements appropriate technical and organizational measures to safeguard Personal Data, including Sensitive Personal Data, against unauthorized access, disclosure, alteration, or destruction. Such measures are designed to ensure a level of security appropriate to the nature of the data being processed and the associated risks.
The Company adopts industry-standard practices and continuously reviews and enhances its security framework to maintain the confidentiality, integrity, and availability of Personal Data.
11.1 Access Control Mechanisms
Access to Personal Data is strictly restricted to authorized personnel on a need-to-know basis. AVMSmiles implements role-based access control systems to ensure that:
- Individuals are granted access only to the data necessary for the performance of their designated roles and responsibilities;
- Access rights are periodically reviewed and updated to reflect changes in roles or employment status;
- Unauthorized access or misuse of data is prevented through appropriate authentication and authorization protocols.
11.2 Data Encryption and Protection
Where applicable, AVMSmiles employs encryption and related security measures to protect Personal Data during storage and transmission. Such measures are intended to:
- Prevent unauthorized interception or access to data;
- Ensure the secure handling of sensitive information, including healthcare-related data;
- Maintain data integrity during processing and transfer.
11.3 Secure Infrastructure
Personal Data is stored and processed on secure servers and systems that incorporate appropriate safeguards, including:
- Firewalls and network security controls;
- Secure hosting environments and infrastructure protections;
- Monitoring mechanisms to detect and respond to potential security threats.
11.4 Audit and Monitoring Controls
AVMSmiles maintains audit logs and monitoring systems to track access to and use of Personal Data. Such controls enable the Company to:
- Monitor data access and processing activities;
- Detect unauthorized access, anomalies, or suspicious behavior;
- Support internal audits, compliance reviews, and incident investigations.
11.5 Continuous Improvement
AVMSmiles undertakes periodic review and assessment of its data security practices to ensure alignment with evolving legal requirements, technological advancements, and industry standards. Necessary updates and improvements are implemented to address emerging risks and enhance overall data protection.
12. Data Retention Policy
AVMSmiles retains Personal Data, including Sensitive Personal Data, only for as long as is necessary to fulfill the purposes for which such data was collected, or as required under applicable laws, regulations, and professional standards. Data retention practices are designed to ensure compliance with legal obligations while minimizing unnecessary storage of personal information.
12.1 Retention for Medical and Legal Purposes
Personal Data, particularly health-related information, may be retained for such periods as are required to:
- Maintain accurate medical and dental records in accordance with applicable healthcare regulations and professional standards;
- Comply with statutory requirements, including those relating to medical record retention, taxation, and audit obligations;
- Support legal proceedings, dispute resolution, or the establishment, exercise, or defense of legal claims.
12.2 Retention for Service Continuity
Personal Data may be retained to ensure continuity and quality of services, including:
- Facilitating follow-up consultations, ongoing treatment, and future care requirements;
- Maintaining patient history for improved diagnosis and treatment outcomes;
- Supporting internal operations, analytics, and service improvement initiatives.
12.3 Retention Based on Consent and Deletion Requests
Personal Data shall be retained until:
- The Data Principal withdraws consent or submits a request for deletion; or
- The purpose for which the data was collected has been fulfilled, and no legal or regulatory requirement mandates further retention.
Upon receipt of a valid deletion request, AVMSmiles shall take reasonable steps to delete or anonymize the Personal Data, subject to applicable legal, regulatory, and operational constraints.
12.4 Data Minimization and Periodic Review
AVMSmiles undertakes periodic review of retained data to ensure that:
- Personal Data is not retained longer than necessary;
- Redundant, outdated, or irrelevant data is securely deleted or anonymized;
- Retention practices remain aligned with applicable legal requirements and business needs.
13. Rights of Data Principals (DPDP Compliance)
In accordance with the provisions of the Digital Personal Data Protection Act, 2023 and other applicable laws, individuals whose Personal Data is processed by AVMSmiles (“Data Principals”) are entitled to exercise certain rights in relation to their Personal Data.
AVMSmiles is committed to facilitating the exercise of such rights in a transparent, timely, and lawful manner, subject to applicable legal and operational limitations.
13.1 Right to Access Personal Data
Data Principals have the right to request access to their Personal Data processed by AVMSmiles. Upon receiving a valid request, AVMSmiles shall, in accordance with applicable law:
- Provide a summary of Personal Data being processed;
- Disclose the nature of processing activities undertaken;
- Provide information regarding third parties, if any, with whom such data has been shared.
13.2 Right to Correction and Updating
Data Principals have the right to request correction, completion, or updating of their Personal Data where such data is inaccurate, incomplete, or outdated.
AVMSmiles shall take reasonable steps to:
- Verify the authenticity of the request;
- Update or rectify the relevant data within a reasonable timeframe;
- Ensure that corrected data is reflected across relevant systems, where applicable.
13.3 Right to Erasure (Deletion of Data)
Data Principals have the right to request the deletion of their Personal Data where:
- The data is no longer necessary for the purpose for which it was collected;
- Consent for processing has been withdrawn;
- Processing is no longer lawful or required.
AVMSmiles shall process such requests in accordance with applicable laws, provided that retention of such data is not required for legal, regulatory, or legitimate business purposes.
13.4 Right to Withdraw Consent
Where processing of Personal Data is based on consent, Data Principals have the right to withdraw such consent at any time.
Upon withdrawal of consent:
- AVMSmiles shall cease processing of Personal Data for the purposes for which consent was withdrawn, unless otherwise required or permitted by law;
- The Data Principal shall be informed of any consequences of such withdrawal, including potential limitations in service delivery.
13.5 Manner of Exercising Rights
Data Principals may exercise the above rights by submitting a request through the designated contact channels provided in this Policy. AVMSmiles shall:
- Acknowledge such requests within a reasonable timeframe;
- Take appropriate action in accordance with applicable legal requirements;
- Provide responses or resolutions within timelines prescribed under applicable laws.
13.6 Account Deletion and App Data Deletion
Users of the AVMSmiles mobile application may request deletion of their app account and associated Personal Data by contacting AVMSmiles through the designated grievance or support channels mentioned in this Policy.
Upon receiving a valid account or data deletion request, AVMSmiles shall take reasonable steps to delete or anonymize the user's Personal Data, subject to applicable legal, medical, regulatory, tax, audit, dispute-resolution, and operational retention requirements. Certain medical, dental, transaction, or legal records may be retained where required under applicable laws or professional standards.
Where full deletion is not legally or operationally possible, AVMSmiles shall inform the user of the reason for continued retention, wherever required under applicable law.
13.7 Limitations and Exceptions
The exercise of the above rights may be subject to certain limitations where:
- Retention of data is required under applicable laws or regulations;
- Processing is necessary for the establishment, exercise, or defense of legal claims;
- Disclosure may adversely affect the rights of other individuals or entities.
14. Children's Privacy
AVMSmiles does not knowingly collect, process, or store Personal Data of individuals below the age of eighteen (18) years without obtaining prior consent from a parent or lawful guardian.
Where such data is collected inadvertently, AVMSmiles shall take reasonable steps to delete such data or obtain appropriate parental or guardian consent, in accordance with applicable laws.
15. Opt-Out and Withdrawal of Consent
AVMSmiles respects the right of Data Principals to control the manner in which their Personal Data is used, particularly in relation to communications and marketing activities. Accordingly, mechanisms are provided to enable users to withdraw consent and opt out of non-essential communications at any time.
15.1 Opt-Out of Communications
Data Principals may opt out of receiving promotional or non-essential communications through the following methods:
- By replying with the keyword “STOP” or any other designated opt-out instruction to SMS or messaging platform communications, including WhatsApp;
- By utilizing the “unsubscribe” link or option provided in email communications;
- By submitting a request through designated customer support channels.
15.2 Push Notifications and App Permission Controls
Users may manage push notifications and app permissions through their mobile device settings. Users may disable notifications, location access, camera access, microphone access, photo/gallery access, file access, or other device permissions at any time.
Disabling such permissions may affect certain app features, including appointment reminders, nearby clinic discovery, document uploads, teleconsultation, support interactions, or other app-based services.
15.3 Effect of Opt-Out
Upon receipt of a valid opt-out request:
- AVMSmiles shall take reasonable steps to update the user's communication preferences within a reasonable timeframe;
- Promotional and marketing communications shall be discontinued in accordance with applicable laws and regulations;
- Transactional or service-related communications, including appointment reminders, treatment updates, and essential notifications, may continue to be sent where necessary for the fulfillment of services.
15.4 Withdrawal of Consent
Where the processing of Personal Data is based on consent, Data Principals have the right to withdraw such consent, either wholly or partially, at any time.
Upon withdrawal of consent:
- AVMSmiles shall cease processing Personal Data for the purposes to which such withdrawal applies, unless such processing is required or permitted under applicable law;
- The Data Principal shall be informed, where applicable, of any consequences of such withdrawal, including limitations in accessing certain services.
15.5 Processing of Requests
All opt-out and withdrawal requests shall be:
- Acknowledged and processed within a reasonable timeframe;
- Implemented in accordance with applicable legal and regulatory requirements;
- Recorded and maintained for compliance and audit purposes.
16. Payment and Financial Data Ethics
AVMSmiles ensures that all financial transactions and related data handling practices are conducted in a secure, transparent, and compliant manner, in accordance with applicable laws, regulations, and standards issued by the Reserve Bank of India (RBI) and other relevant regulatory authorities.
16.1 Secure Payment Processing
All payments made in connection with AVMSmiles services are processed through authorized and secure third-party payment gateways. In this regard:
- Payment transactions are facilitated using industry-standard security protocols and encryption mechanisms;
- AVMSmiles does not directly process or store sensitive payment information on its own systems;
- Payment service providers engaged by AVMSmiles are required to comply with applicable regulatory and security standards.
16.2 Non-Retention of Sensitive Payment Credentials
AVMSmiles does not collect, store, or retain sensitive financial credentials, including but not limited to:
- Full debit or credit card numbers;
- Card verification values (CVV) or personal identification numbers (PIN);
- UPI authentication details or credentials.
Such information is processed exclusively by compliant payment service providers in accordance with applicable laws and industry standards.
16.3 Compliance by Financial and EMI Partners
Where AVMSmiles facilitates payment through financing options, including Equated Monthly Installments (EMI) or third-party credit arrangements:
- Such services are provided by duly authorized financial institutions or partners;
- All financial partners are required to comply with applicable regulatory requirements, including those prescribed by the Reserve Bank of India and other competent authorities;
- AVMSmiles does not exercise control over the independent processing of financial data by such partners, and users are advised to review the privacy policies of such third parties where applicable.
16.4 Data Security and Responsibility
AVMSmiles undertakes reasonable measures to ensure that:
- Financial transaction data shared with third-party providers is limited to the extent necessary for processing payments;
- Appropriate safeguards are in place to prevent unauthorized access, misuse, or disclosure of financial information;
- Any financial data handled directly by AVMSmiles (such as transaction references or payment confirmations) is stored securely and accessed only by authorized personnel.
17. Breach and Incident Management
AVMSmiles is committed to maintaining robust incident response mechanisms to identify, investigate, and mitigate any actual or suspected data breaches or security incidents involving Personal Data, including Sensitive Personal Data. Appropriate procedures are established to ensure timely action, regulatory compliance, and minimization of potential impact.
17.1 Identification and Internal Investigation
In the event of a suspected or confirmed data breach or security incident:
- AVMSmiles shall initiate an immediate internal investigation to assess the nature, scope, and impact of the incident;
- Relevant systems, logs, and access records shall be reviewed to determine the cause and extent of the breach;
- Appropriate containment measures shall be implemented to prevent further unauthorized access or data loss.
17.2 Notification and Regulatory Compliance
Where required under applicable laws and regulations:
- AVMSmiles shall notify the relevant regulatory authorities and affected Data Principals within the timelines prescribed by law;
- Where required under applicable law or where such breach is likely to impact the rights or interests of Data Principals, AVMSmiles shall inform affected individuals through appropriate communication channels, including but not limited to email, SMS, or messaging platforms such as WhatsApp, providing relevant details of the breach and recommended actions, if any;
- Such notification shall include material details of the breach, including the nature of the data affected, potential risks, and recommended mitigation steps for affected individuals;
- All notifications shall be made in accordance with applicable legal, regulatory, and contractual obligations.
17.3 Corrective and Remedial Measures
Following identification of a data breach or incident, AVMSmiles shall undertake appropriate corrective actions, including:
- Rectification of vulnerabilities or system weaknesses that contributed to the incident;
- Strengthening of security controls, policies, and procedures;
- Implementation of additional safeguards to prevent recurrence;
- Training and awareness measures for personnel, where necessary.
17.4 Documentation and Review
All data breach incidents shall be documented and maintained for audit and compliance purposes. AVMSmiles shall:
- Maintain records of the incident, investigation findings, and actions taken;
- Conduct periodic reviews to improve incident response processes;
- Ensure continuous enhancement of its data protection and security framework.
18. Grievance Redressal Mechanism
In accordance with applicable laws and regulations, including data protection and consumer protection requirements, AVMSmiles has established a formal grievance redressal mechanism to address concerns, complaints, or queries relating to the collection, processing, use, or protection of Personal Data.
18.1 Appointment of Grievance Officer
AVMSmiles has designated a Grievance Officer responsible for overseeing and addressing all privacy-related concerns and ensuring compliance with applicable legal obligations.
The details of the Grievance Officer are as follows:
- Name: Gaurav Kudalkar
- Email: gaurav.kudalkar@avmsmiles.com
- Contact Number: +91 9920221016
18.2 Scope of Grievance Redressal
Data Principals may contact the Grievance Officer for matters including, but not limited to:
- Concerns relating to the collection or use of Personal Data;
- Requests for access, correction, or deletion of Personal Data;
- Complaints regarding unauthorized use, disclosure, or breach of data;
- Issues relating to communication preferences, consent withdrawal, or opt-out requests.
18.3 Resolution Timeline
Upon receipt of a grievance:
- AVMSmiles shall acknowledge the complaint within a reasonable timeframe;
- The grievance shall be reviewed and addressed in a fair, transparent, and timely manner;
- Reasonable efforts shall be made to resolve the matter within the timelines prescribed under applicable laws.
18.4 Escalation and Compliance
Where required, grievances may be escalated internally or addressed in accordance with applicable regulatory frameworks. AVMSmiles undertakes to ensure that all grievances are handled with due diligence, confidentiality, and in compliance with legal and ethical standards.
19. Limitation of Liability
AVMSmiles undertakes reasonable measures to ensure the protection and security of Personal Data in accordance with applicable laws and industry standards. However, to the fullest extent permitted under applicable law, the Company shall not be held liable for any loss, damage, or unauthorized access to Personal Data arising from circumstances beyond its reasonable control.
19.1 Third-Party Services and Failures
AVMSmiles may engage third-party service providers, including but not limited to technology platforms, communication providers, payment gateways, and analytics tools, for the purpose of delivering its services.
In this regard:
- AVMSmiles shall not be liable for any acts, omissions, failures, or deficiencies on the part of such third-party service providers;
- Any disruption, delay, or data-related incident arising from the systems, infrastructure, or services of such third parties shall be governed by the respective policies and terms of such providers;
- Users are encouraged to review the privacy policies and terms of use of such third-party services where applicable.
19.2 Events Beyond Reasonable Control
AVMSmiles shall not be held liable for any failure or delay in the performance of its obligations under this Policy where such failure or delay is attributable to events beyond its reasonable control, including but not limited to:
- Natural disasters, acts of God, or unforeseen environmental events;
- Cyberattacks, system failures, or unauthorized access despite implementation of reasonable security measures;
- Government actions, legal restrictions, or regulatory changes;
- Disruptions in telecommunication networks, internet services, or power supply.
19.3 Reasonable Security Standard
AVMSmiles maintains that it implements reasonable security practices and procedures in line with applicable legal and industry standards. However:
- No method of transmission over the internet or electronic storage is completely secure;
- AVMSmiles does not guarantee absolute or uninterrupted security of Personal Data.
19.4 Limitation to the Extent Permitted by Law
Nothing contained in this section shall limit or exclude liability where such limitation or exclusion is not permissible under applicable law.
20. Policy Updates
AVMSmiles reserves the right to review, modify, or update this Privacy Policy from time to time in order to reflect changes in applicable laws, regulations, business practices, technological advancements, or operational requirements.
20.1 Right to Modify
The Company may amend this Policy at its sole discretion, without prior notice, to ensure continued compliance with legal and regulatory obligations or to enhance data protection practices.
20.2 Notification of Changes
Any material changes to this Policy shall be communicated through appropriate channels, which may include:
- Publication of the updated Policy on the official website of AVMSmiles;
- Notification through email or other communication channels, where required or deemed appropriate.
The “Effective Date” or “Last Updated” date at the beginning of this Policy shall indicate the date on which the revised version becomes applicable.
20.3 Continued Use
By continuing to access or use the services of AVMSmiles after any updates to this Policy, the Data Principal shall be deemed to have accepted the revised terms of the Privacy Policy.
20.4 Periodic Review
Users are encouraged to review this Policy periodically to remain informed about how their Personal Data is being collected, used, and protected.
Grievance Officer — AVMSmiles (Flexismile Private Limited)
Gaurav Kudalkar
Email: gaurav.kudalkar@avmsmiles.com
Phone: +91 9920221016
Effective Date / Last Updated: 20 May 2026