top of page

PRIVACY POLICY – STEVE CLINICAL SUPPORT

AlignerService.com

Last updated: March 2026

 

──────────────────────────────────────────

 

 

1. WHO WE ARE

 

Steve Clinical Support is a clinical decision support service operated by:

 

Hatt Consulting GmbH

Bernerstrasse 11

5400 Baden

Switzerland

 

Contact: TPS@AlignerService.com

Phone: +41 78 268 00 78

 

For data protection inquiries, contact: TPS@AlignerService.com

 

 

2. WHAT THIS POLICY COVERS

 

This policy describes how we collect, use, store and protect data when you use the Steve Clinical Support service at alignerservice.com/clinical-support-chat. For cookies and general website usage, please see our Cookie & Privacy Policy at alignerservice.com/cookie-privatlivspolitik.

 

 

3. WHAT DATA WE COLLECT

 

When you submit a case to Steve, we collect:

 

- Your name and email address (to deliver the case analysis)

- Aligner system and case number (to contextualise the analysis)

- Clinical details you provide (patient goals, treatment objectives, specific questions)

- Screenshots you upload from your aligner software (movement charts, occlusal views, lateral views)

- Follow-up questions and any additional images you share in the chat

 

We do NOT collect or store:

- Patient names, dates of birth, or identification numbers

- Clinical photographs showing identifiable patient features

- Health insurance or payment information related to patients

 

You are responsible for ensuring that uploaded images do not contain patient identifiers. The consent statement at submission confirms this.

 

 

4. HOW WE USE YOUR DATA

 

Your data is used for:

 

a) Clinical analysis: Your case data and screenshots are analysed by our AI system to provide clinical decision support for clear aligner treatment planning.

 

b) Quality assurance: Our clinical team reviews cases to verify the accuracy of AI-generated assessments. Reviewed cases may be stored in our verified case database to improve future analysis quality.

 

c) Communication: Your email address is used to send case-related notifications.

 

d) Service improvement: Anonymised, aggregated data may be used to improve our clinical protocols and AI accuracy.

 

Your data is NEVER used for:

- Marketing or advertising purposes

- Sale or transfer to third parties for their own purposes

- Training of general AI models (see Section 5)

 

 

5. AI PROCESSING AND THIRD-PARTY SERVICES

 

Steve uses artificial intelligence to analyse clinical data. This involves the following service providers:

 

a) Anthropic (Claude AI)

Purpose: Clinical analysis of case data and uploaded screenshots

Data shared: Case details and images submitted through the service

Location: API processing (US-based servers)

Safeguards: Data Processing Agreement in place. Anthropic does not train its models on data submitted via API. Data is not retained by Anthropic after processing.

 

b) Cloudflare (Workers, R2 Storage, AI Search)

Purpose: Application hosting, data storage, and knowledge base search

Data stored: All case data, images, and analysis results

Location: EU region (data residency configured for EU)

Safeguards: AES-256 encryption at rest. TLS encryption in transit.

 

c) Wix

Purpose: Website hosting and user interface

Data passing through: Case submissions are proxied through Wix backend functions

Data stored on Wix: No clinical data is permanently stored on Wix servers

Location: EU and US

 

d) Resend

Purpose: Transactional email delivery (internal team notifications)

Data shared: Case ID, triage classification, email addresses

Location: US

Safeguards: TLS encryption. Emails contain no clinical images.

 

 

6. DATA STORAGE AND RETENTION

 

All clinical data (case records, images, analysis results) is stored in Cloudflare R2 with EU data residency.

 

Retention periods:

- Active cases (pending review): Stored until reviewed and either saved to verified database or deleted by our clinical team. Target: within 7 days.

- Verified cases (approved for knowledge base): Stored indefinitely as part of our clinical knowledge base. These contain only the clinical parameters and approved analysis — not your personal contact details.

- Feedback and analytics data: Deleted automatically after 180 days.

- Chat session data: Automatically expires when the Durable Object session is evicted (typically within 30 days of inactivity).

 

Your email address and name are stored only in the active case record and are not carried over to the verified case database.

 

 

7. DATA SECURITY

 

We implement the following security measures:

 

- All data in transit is encrypted using TLS 1.2+

- All data at rest is encrypted using AES-256 (Cloudflare standard)

- API access requires authentication tokens stored in encrypted secret managers

- Access to the case approval system is restricted to authorised clinical team members

- CORS restrictions limit API access to alignerservice.com only

- Images are compressed client-side before transmission

- No clinical data is stored in browser local storage or cookies

 

 

8. YOUR RIGHTS

 

Under the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP), you have the right to:

 

a) Access: Request a copy of all personal data we hold about you.

b) Rectification: Request correction of inaccurate data.

c) Erasure: Request deletion of your data. We will delete all case records, images, and analysis results associated with your email address.

d) Restriction: Request that we limit how we process your data.

e) Portability: Request your data in a structured, machine-readable format.

f) Objection: Object to processing of your data for specific purposes.

 

To exercise any of these rights, contact: TPS@AlignerService.com

 

We will respond to your request within 30 days.

 

 

9. IMPORTANT LIMITATIONS

 

Steve is a Clinical Decision Support (CDS) tool. It does NOT:

- Replace the treating clinician's professional judgment

- Provide medical diagnoses or prescriptions

- Approve or reject treatment plans

- Guarantee clinical outcomes

 

All clinical decisions remain the sole responsibility of the treating dentist. Steve's analyses are advisory only.

 

 

10. CHANGES TO THIS POLICY

 

We may update this policy from time to time. Material changes will be communicated via the service interface. The "last updated" date at the top indicates the most recent revision.

 

 

11. SUPERVISORY AUTHORITY

 

If you believe your data protection rights have been violated, you have the right to lodge a complaint with:

 

- Swiss Federal Data Protection and Information Commissioner (FDPIC): www.edoeb.admin.ch

- Or the relevant data protection authority in your country of residence within the EU/EEA.

 

 

──────────────────────────────────────────

Hatt Consulting GmbH

Bernerstrasse 11, 5400 Baden, Switzerland

TPS@AlignerService.com

bottom of page