Privacy Policy
Last updated: January 2026
This Privacy Policy explains how Sinan Software Solutions (“we”, “us”) collects, uses, stores, and protects information in connection with the Sinan application (the “Service”).
This Policy applies to two categories of data: (A) Account/Business Data — information about you and your practice as our customer; and (B) Customer Data — the data you input into the Service, including patient information, which you control as described in our Terms and Conditions.
For Customer Data, we act as a data processor/service provider on your behalf. You (the practice) act as the data controller responsible for your patients’ information and for obtaining any necessary consents.
1. INFORMATION WE COLLECT
1.1 Account & Licensing Information
- Practice/business name, contact name, email, phone number
- Activation key(s), license status, device identifiers used for activation/seat management
- Billing information (processed via [payment processor], not stored directly by us unless stated otherwise)
1.2 Customer Data (entered by you into the Service)
- Patient names, contact details, appointment history
- Treatment notes, billing/insurance information entered by staff
- Any other data your practice chooses to record in the Service
1.3 Technical & Usage Information
- Application version, operating system, crash reports, error logs
- Update-check requests (app name, current version, platform)
- Basic usage analytics, if enabled (e.g., feature usage counts), [state clearly if you do or do not collect this — recommend being conservative and opt-in for a healthcare-adjacent app]
2. HOW WE USE INFORMATION
We use the information described above to:
- Provide, operate, and maintain the Service
- Verify license activation and prevent unauthorized use
- Process software updates and deliver update notifications
- Provide customer support
- Improve the Service (using aggregated/anonymized data where possible)
- Comply with legal obligations
- Communicate important service notices (e.g., security updates, changes to these policies)
We do NOT sell Customer Data or Account Data to third parties.
We do NOT use patient data entered into the Service for advertising purposes.
3. WHERE DATA IS STORED
The Service is offered in two editions. The applicable edition determines how your Customer Data is stored:
3.1 Local Edition
In the Local Edition, all Customer Data (including patient records, appointments, and billing information) is stored solely on your local device(s). We do not receive, transmit, or store your Customer Data on our servers or any third-party infrastructure in this edition.
3.2 Synced Edition
In the Synced Edition, Customer Data is stored locally on your device(s) and also synchronized to cloud infrastructure operated via our service provider, Supabase, to enable multi-device access and backup. In this edition, we act as a data processor with respect to your Customer Data, as described in Section 5.
3.3 Both Editions — License and Update Data
Regardless of edition, the Service periodically communicates with our servers over the internet for two limited purposes: (a) license activation and validation (transmitting your activation key, device identifier, and app version); and (b) checking for and downloading software updates. This communication does not include any Customer Data (e.g., no patient information is transmitted for license checks or updates), regardless of which edition you use.
4. THIRD-PARTY SUBPROCESSORS
We use the following categories of third-party service providers to operate the Service:
- Supabase (database, authentication, file storage) — [region]
- [Payment processor, if applicable]
- [Error/crash reporting tool, if applicable]
These providers process data solely on our behalf and under contractual confidentiality and security obligations.
5. DATA RETENTION
- We retain Account Data for as long as your account/license is active, and for a reasonable period afterward for legal, billing, and dispute-resolution purposes.
- Customer Data is retained for as long as you continue using the Service. Upon termination, we retain Customer Data for [X days/months] to allow for export, after which it is deleted or anonymized, unless a longer retention period is required by law or agreed with you in writing.
6. DATA SECURITY
We implement reasonable administrative, technical, and physical safeguards designed to protect information from unauthorized access, alteration, disclosure, or destruction, including:
- Encryption of data in transit (TLS)
- [Encryption at rest, if applicable]
- Access controls limiting internal access to Customer Data
- Cryptographic signature verification for software updates
No system is completely secure. In the event of a data breach affecting your data, we will notify you without undue delay and in accordance with applicable law.
7. YOUR RIGHTS
Depending on your jurisdiction, you (or, with respect to patient data, your practice acting on behalf of patients) may have rights including:
- Access to personal data we hold
- Correction of inaccurate data
- Deletion of data (“right to be forgotten”), subject to legal retention requirements
- Data portability / export
- Objection to or restriction of certain processing
Requests can be made by contacting mouayad.alhamwi.ma@gmail.com. We will respond within the timeframe required by applicable law.
8. INTERNATIONAL DATA TRANSFERS
If data is transferred across borders (e.g., to cloud infrastructure located outside your country), we take steps to ensure appropriate safeguards are in place, such as [Standard Contractual Clauses / equivalent mechanisms], consistent with applicable law.
9. CHILDREN’S DATA
The Service is intended for use by dental practice staff and is not directed at children. Patient records may include minors’ data entered by the practice; such data is treated as Customer Data under the controller/processor relationship described above, and the practice is responsible for appropriate consent (e.g., parental/guardian consent) as required by applicable law.
10. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will notify you of material changes via the application or email, and indicate the “Last updated” date above. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
11. CONTACT US
Questions or requests regarding this Privacy Policy or your data can be directed to:
Damascus, Syria