Skip to main content

Privacy Policy

What personal information we collect when you use our Services, how we use it, and what rights you have over it.

Effective Date: 14 August 2026

Your Social Smile LTD, a company existing under the laws of ADGM (English Common Law), with its principal place of business at 14-123-41, Level 14, WeWork Hub71 Al Khatem Tower, Abu Dhabi Global Market Square, Al Maryah Island, Abu Dhabi, UAE, company registration number 000010273 ("YSS", "we", "us").

This Privacy Notice explains what personal information we collect when you use our Services, how we use it, and what rights you have over it.

1. Scope and Services

This Privacy Notice applies to the following services, where they link to or reference this Notice:

"YSS Visualisation Tool" means the AI-powered smile simulation feature that allows end users to upload or capture a photo and preview how dental or cosmetic treatments (such as veneers, braces, or lip fillers) might look. The YSS Visualisation Tool may be embedded within dental clinic websites and applications via the YSS Platform or may be made available directly by YSS.

"YSS Platform" means the cloud-based software platform operated by YSS that dental clinics use to configure, deploy, and manage the YSS Visualisation Tool, including clinic-facing dashboards, booking integration, analytics, and administrative functions.

"Website" means yoursocialsmile.com and any of its subdomains, including app.yoursocialsmile.com, clinic.yoursocialsmile.com, api.yoursocialsmile.com, and any other subdomain we may create.

"API" means any application programming interface provided by YSS through which third-party systems or developers interact with the YSS Platform or YSS Visualisation Tool.

"Services" means, collectively, the YSS Visualisation Tool, the YSS Platform, the Website, and the API, together with any other digital product or feature operated by YSS that links to or references this Privacy Notice.

Different parts of the Services involve different data flows and legal roles. The sections below explain which rules apply to each scenario.

2. Our Role Depending on the Context

YSS may act as a controller, processor, service provider, or contractor depending on how the Services are used and the agreements in place with the clinic or customer. Where HIPAA applies, YSS acts as a Business Associate only when it creates, receives, maintains, or transmits Protected Health Information on behalf of a HIPAA-covered clinic under a Business Associate Agreement.

ScenarioData processedYSS roleClinic/customer role
1. YSS Visualisation Tool embedded on a clinic website or appEnd-user photo, generated visualisation, consent records, technical logs, related metadataProcessor/service provider for data processed on the clinic's instructions. Where the clinic is a HIPAA covered entity and the data is Protected Health Information, YSS acts as the clinic's Business Associate under a BAA. YSS may act as controller for limited operational, security, compliance, consent-record purposes where permitted by law.The clinic is responsible for the patient relationship and clinic-directed processing. Where applicable, the clinic determines the purposes and means of that processing and is responsible for its own HIPAA Notice of Privacy Practices and patient-facing obligations.
2. YSS Visualisation Tool made available directly by YSS, including demosPhoto, generated visualisation, consent records, technical logsYSS is responsible for the direct interaction with the end user and determines the purposes and means of that processing, where applicable.Not applicable unless a clinic is involved.
3. Optional AI model improvement/trainingPhoto, generated output, training-related metadata, and derived anonymized or aggregated dataYSS is responsible for this separate optional purpose and determines the purposes and means of the processing, unless a written agreement states otherwise. For clinic-directed deployments, AI training will occur only where permitted by the applicable clinic agreement and lawful consent or authorization flow.May be independent controller or not involved, depending on the deployment and consent flow.
4. YSS Platform / clinic dashboardClinic staff account data, configuration data, audit logs, support communications, operational recordsYSS is responsible for clinic staff account administration, security, billing, support, and platform operations; YSS acts as processor/service provider for patient data processed on behalf of a clinic.The clinic is responsible for clinic operations and the patient relationship.
5. Website, newsletter, demo requests, and marketingContact details, form submissions, cookies, device data, marketing preferencesYSS is responsible for Website, newsletter, demo request, and marketing processing and determines the purposes and means of that processing, where applicable.Not applicable.
6. API and integrationsAPI credentials, request metadata, integration logs, and data transmitted through the APIDepends on the integration. YSS is generally processor/service provider for customer-directed data and is responsible for account, security, and operational data where YSS determines the purposes and means of processing. HIPAA Business Associate status applies only where the integration involves PHI for a HIPAA-covered clinic under a BAA.The clinic/customer is responsible for data it submits through the integration and for any end-user or patient-facing obligations.

If a clinic provides its own privacy notice or consent language for the YSS Visualisation Tool, that clinic notice may apply in addition to this Notice.

3. Information We Collect

3.1 YSS Visualisation Tool

Facial photos and generated visualisations. When you use the YSS Visualisation Tool, you upload or capture a photo of your face. The photo is transmitted over an encrypted connection to our servers and, where disclosed in the Third Parties and Subprocessors section, to service providers or subprocessors solely to provide, secure, and support the Services. It is processed using AI to generate your smile preview.

Biometric, health or sensitive personal data. Processing your facial photo may involve analysis of facial geometry and may constitute processing of biometric data or sensitive personal information under applicable laws, including GDPR/UK GDPR, BIPA, CUBI, and certain US state privacy laws. Depending on the context, photos, generated visualisations, appointment references, and related clinic-provided information may also constitute health information, including Protected Health Information under HIPAA or data concerning health under GDPR/UK GDPR. We do not use this data to identify you and do not use it to infer health conditions, ethnicity, or other sensitive characteristics beyond what is necessary to generate the visualisation.

Consent records. We collect and retain records of the consents you provide, which may include timestamp, session or user ID, consent text version, IP address, user-agent, and whether the optional AI training checkbox was selected.

Usage and technical data. We collect session identifiers, feature selections, device type, browser type and version, operating system, pages or screens visited, session duration, feature interaction logs, activation times, latency, error rates, and similar technical information. This data is used to operate, secure, analyze, and improve the Services.

Information provided by your clinic. Your clinic may provide limited information to set up your access or manage the service, such as your name, appointment reference, or booking-related information. We process this information on behalf of your clinic and in accordance with applicable data processing terms and the clinic's own privacy notice.

3.2 YSS Platform, Website, API, and communications

  • Clinic staff and account data, such as name, work email address, role, login credentials, organization details, dashboard settings, and support communications.
  • Website and marketing data, such as name, email address, company, message content, newsletter preferences, demo request information, and related communications.
  • API and integration data, such as API credentials, request metadata, endpoint usage, error logs, authentication logs, and integration configuration data.
  • Cookies and similar technologies, as described in the Cookies section below.

4. How We Use Information

We use personal information to:

  • provide the YSS Visualisation Tool and generate the visualisation requested by the end user;
  • operate, secure, troubleshoot, maintain, and improve the YSS Platform, Website, API, and related Services;
  • administer clinic accounts, integrations, dashboards, support, billing, and contractual relationships;
  • maintain consent records and comply with applicable legal, regulatory, security, and audit requirements;
  • send service communications, including security alerts, account notifications, operational messages, and changes to applicable terms or notices;
  • send marketing communications where you have opted in or where otherwise permitted by applicable law. You may unsubscribe at any time;
  • improve and train our AI models only where you have separately provided optional explicit consent.

We do not sell facial photos or biometric data. We do not share facial photos or biometric data for cross-context behavioral advertising. We do not use facial photos for marketing.

5. Automated Processing and AI Model Training

The YSS Visualisation Tool uses AI to generate a visual simulation of dental or cosmetic treatment options based on your photo. The visualisation is for illustrative purposes only. It is not a clinical assessment, dental diagnosis, medical advice, or guarantee of treatment outcomes. YSS does not provide dental or medical advice through the Services.

The visualisation process does not involve automated decision-making that produces legal or similarly significant effects on you.

Optional AI model improvement/training is a separate purpose. We will use your photo for AI model improvement or training only if you provide a separate opt-in consent. This consent is not required to use the visualisation service and may be withdrawn independently at any time by contacting privacy@yoursocialsmile.com. For clinic-directed deployments, AI training will occur only where permitted by the applicable clinic agreement, privacy law, and, where relevant, HIPAA authorization or de-identification requirements.

When you consent to AI model improvement/training, photos used for that purpose may be retained for up to 3 years from your last interaction with us, or until the training purpose is fulfilled, whichever occurs first. Original photo files will be deleted upon expiry or earlier valid withdrawal request, unless we are legally required to retain them. Anonymized or aggregated data derived from training may be retained where it cannot reasonably be linked to an identified or identifiable person. We will stop future use of your data for training after withdrawal; however, it may not always be technically possible to remove the influence of data from models that were already trained before withdrawal.

6. Legal Bases for Processing Where GDPR Applies

Processing activityLegal basisSpecial category basis, where relevant
Direct visualisation processing by YSS, including upload and processing of facial photoConsent, article 6(1)(a) GDPRExplicit consent, article 9(2)(a) GDPR, where biometric data, data concerning health, or other sensitive data is processed
Clinic-directed visualisation processingWhere YSS acts as processor, the clinic determines the applicable legal basis. YSS processes data on the clinic's instructions under applicable data processing terms.Determined by the clinic where the clinic is controller, including any special-category basis for health or biometric data
Optional AI model improvement/trainingConsent, article 6(1)(a) GDPRExplicit consent, article 9(2)(a) GDPR, where biometric data, data concerning health, or other sensitive data is processed
Platform account administration, clinic staff access, API access, billing, and supportPerformance of contract, article 6(1)(b) GDPR, and/or legitimate interests, article 6(1)(f) GDPRNot applicable
Security, fraud prevention, troubleshooting, audit logs, and service integrityLegitimate interests, article 6(1)(f) GDPR, and/or legal obligation, article 6(1)(c) GDPRNot applicable
Marketing communicationsConsent, article 6(1)(a) GDPR, or legitimate interests where permitted by applicable lawNot applicable
Analytics cookies and similar non-essential technologiesConsent where required by applicable ePrivacy/cookie lawsNot applicable

Providing a facial photo is optional. If you do not provide a photo or do not consent to visualisation processing, we cannot generate a visualisation for you. Refusing optional AI training consent does not affect access to the visualisation service.

7. US State Privacy Laws

Depending on your state of residence and the deployment context, you may have rights under state privacy laws. We design our consent mechanism for facial photo and biometric processing to obtain opt-in consent before collection. Where biometric privacy laws apply, including the Illinois Biometric Information Privacy Act and the Texas Capture or Use of Biometric Identifier Act, we provide the following disclosures:

  • We collect and process facial geometry data derived from your photo to generate your smile visualisation and, only where you separately opt in, to improve and train our AI models.
  • We do not sell, lease, trade, or otherwise profit from your biometric data.
  • We do not disclose biometric data to third parties for their own purposes. We may use service providers and subprocessors solely to provide, secure, and support the Services, under contractual obligations.
  • For standard visualisation processing, facial photos and generated visualisations are stored for a maximum of 30 days and then automatically deleted, unless earlier deletion is requested or a legal obligation requires retention.
  • For optional AI training, photos may be retained for the separate period described in the AI Model Training section.
  • We use security measures designed to protect biometric data in storage and transit.

8. California Notice and California Rights

If you are a California resident, the following California-specific disclosures apply. The categories below describe personal information we may have collected, disclosed for a business purpose, or retained within the last 12 months, depending on how you used the Services.

CategoryExamplesSourcesPurposesDisclosure
IdentifiersName, email address, IP address, session ID, user ID, account credentialsYou, your clinic, device/browserProvide Services, accounts, support, security, consent records, communicationsDisclosed to service providers where needed. Not sold or shared for cross-context behavioral advertising.
Biometric information / sensitive personal informationFacial photo and facial geometry data derived from the photoYou or your clinic-directed interaction with the ToolGenerate visualisation; optional AI training only with separate consentDisclosed to service providers/subprocessors only to provide and secure the Services. Not sold or shared.
Internet or network activityDevice data, browser data, pages/screens visited, feature interactions, logs, cookie dataDevice/browser and analytics toolsOperate, secure, analyze, and improve ServicesDisclosed to service providers. Analytics cookies used only where permitted/consented. Not sold or shared for cross-context behavioral advertising.
Commercial or business informationClinic account information, subscription/support records, demo requestsYou, clinic/customer, YSS systemsAdminister customer relationship, support, billing, and contractsDisclosed to service providers. Not sold or shared.
InferencesLimited service analytics and aggregated usage patternsYSS systemsImprove reliability, performance, and user experienceDisclosed to service providers where needed. Not sold or shared.

California residents may have the right to know/access, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and not be discriminated against for exercising privacy rights. We do not sell personal information and do not share personal information for cross-context behavioral advertising. We use sensitive personal information only for the purposes described in this Notice, including providing the requested visualisation, optional AI training where separately consented to, security, compliance, and service operations.

To exercise California rights, contact privacy@yoursocialsmile.com. We will verify your request and respond within 45 days, unless an extension is permitted by law. You may designate an authorized agent to submit a request on your behalf.

9. HIPAA and Health Information

Not every clinic or use of the Services is subject to HIPAA. Where a clinic is a HIPAA covered entity and YSS creates, receives, maintains, or transmits Protected Health Information on behalf of that clinic, YSS acts as the clinic's Business Associate and processes such information only as permitted by a Business Associate Agreement with the clinic and applicable HIPAA requirements. Your clinic's HIPAA Notice of Privacy Practices, not this Notice, governs your HIPAA rights with respect to Protected Health Information held by the clinic.

The Services are not designed to process records subject to 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records) unless YSS expressly agrees to do so in writing. Clinics must not submit such records to the Services without such written agreement.

10. Data Retention and Deletion

Data categoryRetention period
Facial photos and generated visualisations for standard visualisation processingMaximum of 30 days, then automatically deleted, unless earlier deletion is requested or a legal obligation requires retention.
Photos used for optional AI model improvement/trainingUp to 3 years from your last interaction with us, or until the training purpose is fulfilled, whichever occurs first, unless earlier deletion is required after withdrawal or a legal obligation requires retention.
Consent recordsAt least 3 years, or longer where required to establish, exercise, or defend legal claims or comply with applicable law.
Account and clinic contact informationFor the duration of the account or business relationship, plus any period required by law or needed for legitimate business records, then deleted or anonymized.
Usage, analytics, and log dataMaximum of 12 months in identifiable form, unless a longer period is required for security, legal, audit, or contractual reasons. May be retained longer in aggregated or de-identified form.
API request metadataMaximum of 90 days, unless a longer period is required for security, troubleshooting, legal, audit, or contractual reasons.
Clinic portal audit logs12 months, or longer where required by law, security needs, contract, or Business Associate Agreement.
Marketing subscription dataUntil you unsubscribe or we no longer need the data for the purpose collected, subject to legal recordkeeping requirements.

11. Data Security

  • Photos are transmitted via encrypted connections.
  • Files are stored in private, access-controlled cloud storage environments, including Amazon S3, with public access disabled.
  • Access to stored files is provided only via time-limited API links, currently configured with a 15-minute expiry.
  • Access to systems is restricted on a need-to-know basis.
  • We use administrative, technical, and organizational measures designed to protect personal information, including testing and assessment of security measures.
  • Where HIPAA applies, we maintain safeguards and contractual controls designed to support our obligations as a Business Associate.

In the event of a personal data breach, where we act as processor, service provider, or Business Associate, we will notify the affected clinic or customer in accordance with our contractual and statutory obligations. Where we act as controller and the breach creates a risk to rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach where required by law and notify affected individuals where required.

12. Your Rights

Depending on where you live and how you use the Services, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal information, withdraw consent, appeal certain decisions, or opt out of certain processing. If GDPR/UK GDPR applies, you may also have the right to lodge a complaint with your national data protection authority.

To exercise rights, contact privacy@yoursocialsmile.com. Where YSS acts as processor, service provider, or Business Associate for a clinic, we may refer your request to the clinic or assist the clinic in responding.

13. International Transfers

Your data may be transferred to and stored on servers located outside your country or region, including in the United States. Where GDPR/UK GDPR or similar laws require transfer safeguards, we use appropriate mechanisms such as Standard Contractual Clauses, data processing agreements, and supplementary measures where appropriate.

14. Third Parties and Subprocessors

We use third-party service providers and subprocessors to deliver and support the Services. They process data only for specified purposes and under contractual obligations, except where a provider acts as an independent controller as disclosed or required by law.

Cloud infrastructure: Amazon Web Services (AWS), including the US-East-1 region, for storage of photos and generated results in private, access-controlled S3 buckets. We may expand to additional regions or providers, including Google Cloud Platform, as our infrastructure develops. Where HIPAA applies, use of infrastructure providers must be covered by appropriate contractual arrangements, including BAAs where required.

Analytics: Google Analytics, for understanding how the Services are used and improving them. These tools may collect IP addresses, device data, and usage data, but they must not receive facial photos, generated visualisations, Protected Health Information, patient identifiers, appointment references, photo IDs, or URL parameters that reveal such information unless this Notice is updated and a valid legal basis is obtained.

Email and communications: Intuit Mailchimp, used to send marketing communications to individuals who have opted in via the Website or other Services. Data shared with Mailchimp is limited to the subscriber's name, email address, and related marketing preference information.

CRM and support: We do not currently use a third-party CRM or support platform. If we engage such a provider in the future, we will update this Notice and our subprocessor list as required.

A current list of subprocessors is available upon request at privacy@yoursocialsmile.com. We do not share facial photos or biometric data with third parties for their own marketing, advertising, or independent commercial purposes, except as required by law.

15. Children and Minors

The Services are not directed to children under 13. We do not knowingly collect personal information, including facial photos, from children under 13 without verifiable parental consent. If you are under 13, do not use the YSS Visualisation Tool unless your parent or legal guardian has provided consent through an approved process.

For users in the EU/EEA or UK, the applicable digital consent age may be 16 or a lower age set by local law. Where an end user is below the applicable threshold, use is permitted only with consent given or authorized by a parent or legal guardian. Clinics are responsible for obtaining any patient, parent, or guardian consents required for clinic-directed use of the Services. If we become aware that we hold personal information of a child below the applicable threshold without proper consent, we will delete it without undue delay. To report a concern, contact privacy@yoursocialsmile.com.

16. Cookies and Similar Technologies

The Services may use cookies, SDKs, pixels, local storage, and similar technologies. We do not use cookies for advertising or cross-site behavioral advertising. Where required by law, we request your consent before placing non-essential cookies.

  • Essential cookies: required for the Services to function, such as session management, security, authentication, and consent storage. These are always active and do not require consent.
  • Analytics cookies: used to understand how the Services are used and to improve performance and stability. These may be provided by third-party services such as Google Analytics. Analytics cookies are optional and require consent where required by law.
  • Functional cookies: used to remember preferences such as language, region, or consent choices. These are optional where required by law.
  • Subdomain-specific cookies: different subdomains of yoursocialsmile.com may set cookies specific to that subdomain, such as clinic portal session cookies or API authentication tokens.

You may manage cookie preferences through our cookie banner, preference center where available, browser settings, or by contacting privacy@yoursocialsmile.com. Withdrawing consent for analytics or functional cookies will not affect the core functionality of the Services. If we add new non-essential cookie categories or third-party analytics tools, we will update this Notice and obtain renewed consent where required before those cookies are set.

17. Marketing Communications

If you opt in to receive marketing communications from us, such as through a newsletter signup, contact form, or demo request, we will process your name, email address, and related preference information for that purpose. The GDPR legal basis is consent, unless another legal basis is permitted by applicable law. You may unsubscribe at any time using the link in each marketing email or by contacting privacy@yoursocialsmile.com. Opting out of marketing does not affect service communications necessary to deliver or secure the Services.

18. Changes to This Notice

We may update this notice when our practices change. Material changes will be communicated via the YSS Visualisation Tool interface or through your clinic. The effective date at the top reflects the current version. Prior versions are available upon request.

19. Contact

Your Social Smile LTD, 14-123-41, Level 14, WeWork Hub71 Al Khatem Tower, Abu Dhabi Global Market Square, Al Maryah Island, Abu Dhabi, UAE. privacy@yoursocialsmile.com

EU/UK Representative: Shuaib Khaderi, 14-123-41, Level 14, WeWork Hub71 Al Khatem Tower, Abu Dhabi Global Market Square, Al Maryah Island, Abu Dhabi, UAE. privacy@yoursocialsmile.com

Data Protection Officer: for questions or concerns about our data protection practices, please contact our Data Protection Officer at privacy@yoursocialsmile.com.

The latest in teeth and tech directly to your inbox

Sign up to our newsletter for the latest news, insights, and trends from experts in the tech and cosmetic dental space.