Privacy Policy

Our privacy policy and how we handle your data

Molario is built for dental hygiene practices. We know you trust us with sensitive patient and practice data, and we take that responsibility seriously. This policy explains what we collect, why, and how we keep it safe.

1. Who we are

Molario is operated by Bitcodia s.r.o., a company registered in the Czech Republic. When we say "Molario," "we," or "us" in this policy, we mean Bitcodia s.r.o. as the data controller.

2. What we collect

Account information

When you create an account, we collect your name, email address, and practice details. If you invite team members, we collect their names and email addresses too.

Patient records

Your practice stores patient data in Molario — names, contact details, medical history, treatment notes, and documents. You are the data controller for your patients' data. We process it on your behalf.

Billing information

Payment processing is handled by Stripe. We do not store full credit card numbers. We keep billing records such as invoice history and subscription status.

Usage data

We do not currently collect usage analytics. Molario ships no analytics client, so the pages you visit and the features you use are not recorded or sent anywhere. If we introduce anonymous usage measurement, this section will describe what it collects before it is switched on.

Cookies

We use essential cookies to keep you signed in and remember your preferences. We do not use advertising cookies. See our Cookie Policy for details.

3. How we use your data

  • Running your practice: Appointments, patient records, billing, and team management — the core of what Molario does.
  • Improving the product: Feedback you send us and support conversations. We do not currently collect usage analytics — see section 2.
  • Communicating with you: Account notifications, security alerts, and product updates. No marketing emails unless you opt in.
  • Keeping things secure: Monitoring for suspicious activity and preventing unauthorized access.

4. Who we share data with

We do not sell your data. We share it only with trusted service providers who help us run Molario. For each one, this is what it receives and why:

  • Stripe — payment processing. Receives your billing contact details and payment information. We never see or store full card numbers.
  • Resend — transactional email (appointment confirmations, password resets). Receives the recipient's email address and the content of the message.
  • Convex — database infrastructure. Stores the practice and patient data you enter into Molario.
  • Vercel — application hosting. Processes request metadata such as IP address and browser type in the course of serving the application.
  • Twilio — SMS delivery and inbound replies. Receives the recipient's phone number and the text of the message, including any patient name or appointment detail your practice chooses to include. This covers appointment reminders and confirmations, opt-out handling, marketing SMS where your practice runs a campaign, and one-off messages a staff member sends to an individual customer.
  • Cloudflare Turnstile — bot protection on forms reachable without signing in: sign-in and sign-up, public booking and lead-capture forms, password-reset requests, job applications and documentation feedback. Receives the visitor's IP address and browser signals in order to tell a person from an automated script. It does not receive the contents of the form.
  • Inngest — background job orchestration (reminders, exports, scheduled clean-up). Receives job messages that reference records by identifier, together with the data a given job needs in order to run.
  • OpenAI — the AI assistant and website chatbot features. Receives the text you or a website visitor send to the assistant, along with the document or knowledge-base content used to answer. It is processed only to generate that response.

Each provider is bound by data processing agreements and processes data only as needed to provide their service.

5. Where your data is stored

Your data is stored on servers in the European Union and the United States. Where data is transferred outside the EU, appropriate safeguards are in place (Standard Contractual Clauses or equivalent).

6. How we protect your data

  • Encryption in transit (TLS) and at rest
  • Role-based access control within your practice
  • Multi-factor authentication support
  • Regular security monitoring and audits
  • Automatic backups

7. How long we keep your data

We keep your account data for as long as your account is active. Patient records are retained according to your practice's settings and applicable healthcare record-keeping regulations. When you delete your account, we remove your data within 30 days, except where legal obligations require us to retain it.

8. Your rights

Under GDPR and applicable Czech law, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data (right to be forgotten)
  • Export your data in a portable format
  • Restrict or object to certain processing
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at privacy@molario.com.

9. Your patients' rights

As the data controller for your patients, you are responsible for handling their data requests (access, correction, deletion). Molario provides tools to help you export and delete patient data. If a patient contacts us directly, we will refer them to your practice.

10. Children's data

Dental practices may treat minors. Patient records for children are managed by the practice under the responsibility of the parent or guardian and the practice itself. Molario does not knowingly collect data from children outside of a practice's patient records.

11. Changes to this policy

We may update this policy from time to time. When we do, we will update the date at the top and notify you by email for significant changes. Continued use of Molario after changes means you accept the updated policy.

12. Contact us

Questions about this policy or how we handle your data? Reach out:

You also have the right to file a complaint with the Czech Office for Personal Data Protection (UOOU) or your local supervisory authority.