Privacy
Privacy Policy
Last updated: July 20, 2026
Morph builds and operates DentBot, a service assistant that runs on WhatsApp and helps dental clinics answer, book, reschedule and confirm appointments. This Policy explains what personal data we process, why, whom we share it with and what your rights are, in line with Brazil's General Data Protection Law (Law 13,709/2018, the "LGPD").
When a clinic hires DentBot, the clinic is the data controller of its patients' data and Morph acts as the data processor, handling data only under the clinic's instructions and as described here. For data of visitors to this site or people who contact us, Morph is the controller.
1. Data we process
We only process the data needed to serve patients and organize appointments. In the DentBot flow, this includes:
- Patient registration: full name, tax ID (CPF), email and date of birth, provided within the conversation.
- Phone number (WhatsApp): identifies the patient and links each conversation to their service history.
- Message content: text and voice notes sent over WhatsApp, including transcriptions of the audio.
- Appointment data: procedure, chosen dentist, date, time and status (booked, confirmed, cancelled, rescheduled or no response).
- Minimal technical records: message identifiers and timestamps, used to avoid duplicate processing and for audit purposes.
2. Why we use it
- Identify the patient and continue the service.
- Book, reschedule and cancel appointments in each dentist's calendar.
- Send reminders the day before and request attendance confirmation before the appointment.
- Transcribe voice notes to understand and respond to the request.
- Detect possible urgent situations and direct the patient to the clinic's contact.
- Answer frequently asked questions about the clinic and its services.
3. Legal bases
Processing relies on the performance of a contract and preliminary steps taken at the data subject's request (the requested booking) and on the legitimate interest of providing the service; where applicable, on the data subject's consent.
Any health data provided by the patient is processed solely to enable the booking and communication with the clinic, with the care the LGPD requires for sensitive personal data.
4. Artificial intelligence and audio
DentBot uses language models to interpret messages and transcribe voice notes sent by the patient. Scheduling decisions - whether a slot is free and which time to offer - are made by deterministic logic, never left to the AI model.
We do not use patients' conversations to train artificial intelligence models.
5. Who we share it with
To operate DentBot, we rely on providers acting as sub-processors, only to the extent necessary to run the service:
- Meta (WhatsApp Business Platform) - sending and receiving messages.
- Google (Gemini) - transcribing audio and supporting message interpretation.
- Google (Calendar) - recording appointments in each dentist's calendar.
- A cloud infrastructure provider - hosting the application and database.
- The contracting clinic - which follows its patients' conversations and bookings.
6. How long we keep it
We keep data for as long as necessary for the purposes above and for the clinic's legal obligations. Closed conversations and messages follow a retention policy and are discarded periodically, as are system execution logs, which are pruned automatically.
We do not sell or trade personal data.
7. Your rights (LGPD)
As a data subject, you may at any time request:
- Confirmation that processing exists and access to your data.
- Correction of incomplete, inaccurate or outdated data.
- Anonymization, blocking or deletion of unnecessary or non-compliant data.
- Portability and information about whom we share your data with.
- Withdrawal of consent, where processing is based on it.
8. Deleting your data
Patients can request deletion of their data directly in the WhatsApp conversation. On confirming the request, we remove the patient's data and the related calendar events. Requests can also be made through the contact channels below. As the clinic is the controller, some requests may be forwarded to it.
9. Security
We apply technical and organizational measures to protect data, including:
- Database access through an application user with the least privilege required.
- Secrets and tokens stored in environment variables, never in the code.
- Signature validation of messages received from Meta.
- Logical separation of data by clinic and by dentist.
10. Minors
Service for minors must be conducted by a legal guardian. When we process minors' data, we do so in the best interest of the data subject, in line with the LGPD.
11. Contact and Data Protection Officer
For questions about this Policy or to exercise your rights, contact us at [email protected]. The Data Protection Officer (DPO) is designated together with the controlling clinic.
12. Changes
We may update this Policy from time to time. The date at the top shows the latest revision; significant changes will be communicated through appropriate channels.