Patient data, under the law where your clinic practises.
MolarPlus serves dental clinics in India, the United States, Europe and South Africa. Each statement below sets out how MolarPlus handles patient data under the data protection law of that region, provision by provision.
Operated by Upclick Labs (OPC) Pvt. Ltd. · Last reviewed September 2026
How MolarPlus processes the personal data of patients and clinic staff under India’s Digital Personal Data Protection Act.
How MolarPlus safeguards protected health information for dental practices in the United States.
How MolarPlus processes health data for dental practices in the European Union and the United Kingdom.
How MolarPlus processes personal information for dental practices in South Africa.
One set of safeguards, whichever law applies.
Clinic and patient records are stored on Amazon Web Services in the Asia Pacific (Mumbai) region, India. The same controls protect every clinic, and each regional statement maps them to the provisions of its law.
- Encryption at rest
- Patient and clinic records are held in a managed PostgreSQL database on Amazon RDS, encrypted at rest with AES-256. The storage volumes of the application servers are encrypted in the same way.
- Encryption in transit
- Every connection between a browser or the MolarPlus mobile app and the MolarPlus service is encrypted with TLS.
- Network isolation
- The production database accepts no connections from the public internet. It can be reached only from the MolarPlus application servers.
- Role-based access
- The clinic owner decides, section by section, what each staff member can see and do. Staff are given access to the information their work requires and nothing more.
- Authentication
- Every user signs in with an individual account. Passwords are stored only as bcrypt hashes, sign-in and sign-up are verified with one-time codes, and repeated attempts are rate limited.
- Audit trail
- Actions taken within a clinic account are recorded in an activity log, which the clinic owner can review and export.
- Private document links
- Documents, prescriptions and reports are kept in private object storage and are opened only through signed links that expire shortly after they are issued.
- Backups and recovery
- The database is backed up automatically every day, with point-in-time recovery available across a rolling seven-day window.
- Portability
- A clinic owner can download a complete archive of the clinic’s data at any time and export patient records as a spreadsheet, without contacting MolarPlus.
Every provider that handles clinic data.
MolarPlus uses the following service providers to deliver the service. Some process data outside India, including in the United States. Under their commercial terms, Anthropic and OpenAI do not use data submitted through their APIs to train their models. MolarPlus will update this register before engaging a new provider that handles patient data.
What MolarPlus secures, and what the clinic decides.
MolarPlus is responsible for the security of the service: the infrastructure, the application and the safeguards described on this page.
The clinic is responsible for how it uses the service: obtaining patient consent, deciding which staff may see what, keeping sign-in details private, and keeping records for the period its professional regulator requires.