What it does The five partsHow it runs One connected dayPricing From INR 999 a monthSign in Your clinic workspacePrivacy policy  Terms of service  Refunds and cancellation  Start your free trial
OROwork

Privacy policy

Last updated 14 September 2026

OROwork is used by dental clinics to run their practice, which means we hold information about the clinic, its staff and its patients. This page says what we hold, why we hold it, and what you can ask us to do with it.

Who this is about

There are two kinds of people in this policy, and they are treated differently.

  • A clinic and its staff are our customers. They sign up, they choose a plan, and they decide what goes into their workspace.
  • A patient of that clinic is not our customer. Their records belong to the clinic, and the clinic decides what is stored and for how long. We hold that information on the clinic’s behalf and act on the clinic’s instructions.

If you are a patient and you want your records changed or removed, ask your clinic first. They can do it themselves, and they know which record is yours. If they need our help they can write to us.

What we collect

From a clinic and its staff:

  • Name, email address and password, so an account can exist and be signed into.
  • The clinic’s own details: name, address, phone, and GST registration if it has one, because these appear on invoices.
  • Which plan the clinic is on and its billing history.

Entered by the clinic, about its patients:

  • Contact details: name, phone number, email and address.
  • Appointment history and what each visit was for.
  • Clinical information the clinic chooses to record: notes, treatment plans, prescriptions, consent forms, medical alerts and allergies.
  • Invoices, payments and receipts.
  • Messages sent to the patient and any replies received, where the clinic uses WhatsApp messaging.

Collected automatically when the software is used:

  • Sign-in times and the device and browser used, to keep accounts secure.
  • A record of changes made inside a workspace, with who made them and when.
  • Error reports when something goes wrong, so it can be fixed.

We do not buy personal data from anybody, and we do not run advertising or tracking networks on the product.

Why we hold it

  • To provide the software the clinic is paying for.
  • To take payment for a subscription and issue an invoice for it.
  • To keep accounts secure and to investigate misuse.
  • To answer a support request.
  • To meet a legal or tax obligation that applies to us.

We do not sell personal information. We do not use patient records to train models or for any purpose other than running the clinic’s own workspace.

Who else sees it

Only the services we need to run OROwork, and only the part each one needs:

  • Our hosting and database provider, which stores the data.
  • Our payment provider, which handles subscription payments. Card details are entered on their page and never reach our servers.
  • Our email provider, for sign-in emails, invitations and billing notices.
  • WhatsApp, operated by Meta, where a clinic has connected its own WhatsApp number to send patient messages. Only the message and the recipient number go to them.

We will also disclose information if the law requires it. If that happens and we are allowed to tell the clinic, we will.

Where it is stored, and for how long

Data is stored on servers operated by our hosting provider. While a subscription is active we keep the clinic’s data so the clinic can use it.

  • If a subscription lapses, the workspace becomes read-only. Nothing is deleted for non-payment: we keep the data for 3 months in case the subscription resumes or an export is asked for, then delete it.
  • If a clinic asks us to delete its workspace, we delete it and it cannot be recovered afterwards.
  • Some records are kept longer where the law requires it, for example invoices and tax records.
  • Backups are kept for a limited period and then overwritten, so deleted data can persist in a backup for a short time after deletion.

How it is protected

  • Each clinic is a separate tenant. One clinic cannot read another clinic’s records.
  • Access inside a clinic is decided by role, so not everyone sees everything.
  • Passwords are stored hashed and can never be read back, by us or anybody else.
  • Two-factor sign-in is available and we recommend it for owners.
  • Traffic is encrypted in transit.

No system is perfect. If we discover a breach that affects a clinic’s data, we will tell that clinic what happened, what was affected and what we are doing about it.

What you can ask for

A clinic can ask us at any time to:

  • Give it a copy of its data.
  • Correct something that is wrong.
  • Delete its workspace.
  • Explain what we hold and why.

Write to connect@orowork.in and we will respond within 30 days. We may need to confirm who you are before acting on a request, particularly a deletion.

Children

OROwork is for clinic staff and is not intended for anyone under 18 to sign up. A clinic may of course hold records for patients who are children; those are the clinic’s records, entered by the clinic under its own obligations.

Changes to this policy

If we change something that matters, we will update the date at the top of this page and email the account owner of every active clinic before it takes effect.

Contact

Privacy questions and requests: connect@orowork.in
Anything else: connect@orowork.in

Read these alongside our privacy policy, terms of service and refunds and cancellation policy. Questions about any of them go to connect@orowork.in.

Start your free trial