top of page

Privacy Policy

Last Updated: February 22, 2026

​

This Privacy Policy explains how Evolving Smiles Dental and Wellness Studio (“we,” “our,” “us”), a dental clinic located at 1st Floor, 18 Anniah Reddy Layout, Ramamurthy Nagar Main Road, Banaswadi, Bangalore 560043, collects, uses, stores, and protects your personal data. This policy applies to information collected through our website (www.evolvingsmiles.com), our social media pages, appointment booking systems, and in-clinic visits.

We comply with the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable rules notified thereunder.

1. Information We Collect

1.1 Information You Provide

  • Name, age, gender, phone number, email address

  • Dental and medical history, treatment records, X-rays, prescriptions

  • Payment and billing information

  • Appointment preferences and scheduling details

  • Feedback, reviews, and communications with us

1.2 Information Collected Automatically

  • When you visit our website: IP address, browser type, device information, pages visited, and time spent

  • Cookies and similar tracking technologies (see Section 6)

1.3 Information from Advertising Platforms

  • When you interact with our ads on Facebook, Instagram, or Google, those platforms may share limited information with us such as your ad interaction data, demographic category, and location (city-level). This is governed by the respective platform’s privacy policies.

2. How We Use Your Information

We process your personal data only for specific, clearly defined purposes:

  • To provide dental treatment, consultations, and follow-up care

  • To schedule and manage appointments

  • To process payments and issue receipts

  • To send appointment reminders via SMS, WhatsApp, or email

  • To run advertisements on Facebook, Instagram, and Google and measure their effectiveness

  • To create Custom Audiences and Lookalike Audiences on Meta platforms and Google Ads for reaching relevant audiences (using hashed, non-identifiable data)

  • To respond to your enquiries and feedback

  • To comply with legal and regulatory obligations

  • To improve our services and website experience

3. Legal Basis for Processing

Under the DPDPA 2023, we process your data based on:

  • Your consent, obtained at the time of registration, appointment booking, or website interaction

  • For healthcare services: legitimate use under Section 7 of the DPDPA for medical emergencies and provision of health services

  • Legal obligations under applicable healthcare regulations

You may withdraw your consent at any time by contacting us (see Section 10). Withdrawal will not affect the lawfulness of processing carried out before withdrawal. Please note that withdrawing consent for processing essential to dental treatment may limit our ability to provide certain services.

4. Sharing of Information

We do not sell your personal data. We may share your information with:

  • Dental laboratories, specialists, or referral clinics as necessary for your treatment

  • Payment processors for completing transactions

  • Meta Platforms (Facebook/Instagram) and Google for advertising purposes. Data shared with these platforms is hashed and anonymised. These platforms act as independent data fiduciaries and their processing is governed by their own privacy policies.

  • Government or regulatory authorities when required by law

  • Cloud service providers for secure storage of clinic records

5. Advertising and Remarketing

We use the following advertising tools:

5.1 Meta Pixel (Facebook/Instagram)

Our website may use the Meta Pixel, which collects data about your website visits to help us show relevant ads on Facebook and Instagram. This may include pages visited and actions taken (such as booking an appointment). Meta processes this data as an independent data fiduciary.

5.2 Google Ads and Google Analytics

We use Google Ads conversion tracking and may use Google Analytics to understand website traffic and ad performance. Google may use cookies to serve ads based on your prior visits to our website.

5.3 Your Choices

  • You can opt out of personalised ads on Facebook via your Facebook Ad Settings

  • You can opt out of Google personalised ads at adssettings.google.com

  • You can disable cookies through your browser settings (see Section 6)

6. Cookies

Our website uses cookies for:

  • Essential functions: website navigation, appointment booking

  • Analytics: understanding how visitors use our site

  • Advertising: enabling Meta Pixel and Google Ads tracking

On your first visit, we display a cookie consent banner. You may accept or reject non-essential cookies. You can also manage cookies through your browser settings at any time.

7. Data Retention

  • Medical and treatment records: retained as required under applicable healthcare regulations (minimum 3 years under the Clinical Establishments Act, or as prescribed by state rules)

  • Billing and payment records: retained for the period required under tax and financial regulations

  • Website and advertising data: retained for up to 24 months, unless you request earlier deletion

  • Contact information for marketing: retained until you unsubscribe or withdraw consent

8. Data Security

We implement reasonable security measures to protect your personal data, including:

  • Encryption of data in transit and at rest

  • Access controls limiting data access to authorised staff

  • Secure storage of physical records in the clinic

  • Regular review of security practices

In the event of a data breach, we will notify the Data Protection Board of India and affected individuals as required under the DPDPA.

9. Your Rights Under the DPDPA

As a data principal, you have the right to:

  • Access: Request a summary of your personal data and how it is being processed

  • Correction and Erasure: Request correction of inaccurate data or deletion of your data (subject to legal retention requirements)

  • Grievance Redressal: Raise a complaint with our Grievance Officer (see below)

  • Nomination: Nominate another person to exercise your rights in case of your death or incapacity

To exercise any of these rights, contact our Grievance Officer using the details in Section 10.

10. Grievance Officer / Contact

For any questions, concerns, or requests regarding this Privacy Policy or your personal data:

Grievance Officer: Dr. Sajni, Founder

Email: sajni.dr@gmail.com

Phone: +91 99863 66633 / +91 99725 52127

Address: 1st Floor, 18 Anniah Reddy Layout, Ramamurthy Nagar Main Road, Banaswadi, Bangalore 560043

We will respond to your request within 30 days.

If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India.

11. Children’s Data

If a patient is under 18 years of age, we require verifiable consent from a parent or legal guardian before collecting or processing their personal data, in accordance with Section 9 of the DPDPA.

12. Third-Party Links

Our website or social media pages may contain links to third-party websites. We are not responsible for the privacy practices of those websites. We encourage you to read their privacy policies before providing any personal information.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on our website with the updated date. We encourage you to review this page periodically.

14. Governing Law

This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 and rules notified thereunder, and the Information Technology Act, 2000.

 

​

bottom of page