1. Purpose of this document
This document briefly explains how SmileCrop approaches patient photographs and which responsibilities remain with the orthodontic practice or other healthcare facility.
2. Local processing
SmileCrop is designed as a desktop application. Photographs inserted into the Application are normally processed locally on the User's device. Normal use of the Application does not require uploading patient photographs to the Provider's servers. Internet connection is used only for license activation, occasional subscription validation, updates, and payment-related processes.
Choosing a synced folder, network share or cloud backup can transmit files through services configured by your practice. A QR code or filename containing a patient's name remains personal data; replacing a name with an internal number does not automatically anonymise a photograph.
3. Role of the Provider
If the Provider does not have access to patient photographs, the Provider generally does not act as a processor of those patient data. However, the Provider may be a controller or processor of other data, such as customer, license, payment, or technical support data; see the Privacy Policy.
Do not send patient photographs or other patient data through ordinary email. Use sample images without real patient data for support. If resolving an issue exceptionally requires access to real data, roles, a legal basis, a secure transfer method and retention must be agreed in advance; processing on behalf of the practice also requires an Article 28 GDPR agreement. Sending an attachment does not replace that agreement.
4. Role of the Customer
The Customer, typically an orthodontic practice or healthcare facility, is responsible for the lawfulness of processing patient photographs, their security, maintaining documentation, informing patients, and setting internal processes according to the GDPR and regulations relating to medical documentation.
5. Recommended practice
- Store original photographs and outputs securely and back them up regularly.
- Restrict access to the device and folders only to authorized persons.
- Do not send patient photographs by email without a proper reason and security measures.
- Use anonymized, own, or sample photographs for technical support.
- Verify automatically created outputs before storing them in documentation or sharing them with other persons.
- Ensure that the use of QR codes or patient names complies with the clinic's internal rules and personal data protection.
6. No diagnostic function
SmileCrop does not perform diagnosis, medical analysis, treatment evaluation, or clinical decision-making. The Application only technically processes photographs for the purposes of organization and documentation. The Application is not a medical device within the meaning of applicable legal regulations.