Legal
Data Processing & Security
Last updated: July 2026
This page explains how we handle the personal information that flows through the platform on your behalf. It complements our Privacy Policy (which covers visitors to this marketing site). Grovique is an independent service operated by its founding team as freelancers, based in Ahmedabad, India, serving Australian dental clinics. All clinic and patient data is hosted in Australia (AWS, Sydney — ap-southeast-2). We are not an incorporated company and never display a placeholder ABN or company number.
Roles: you control, we process
For your patients’ personal information, your clinic is the controller and Grovique is the processor: we handle that information only to provide the service and only on your instructions. We do not use your patients’ information for our own marketing or sell it — ever.
Where your data lives
Clinic and patient data — leads, messages, reviews content and your site’s structured content — is stored in Australia (AWS, Sydney, ap-southeast-2), in line with the Privacy Act 1988 and the Australian Privacy Principles. Public website assets may be delivered through a global CDN for speed, but the source data stays in Australia.
Security measures
- Encryption in transit (TLS) and at rest.
- Row-level access controls so one clinic can never see another’s data.
- Least-privilege access for our team, and no standing access to your live data beyond what support requires.
- Backups and monitoring, with a documented process for restoring service.
AI and your data
The AI chatbot answers operational questions (hours, parking, health funds) and captures enquiries. It is never sent clinical records and never gives clinical advice. Only the minimum needed to answer a website visitor’s question is processed.
Service providers
We use a small number of reputable providers to run the service — cloud hosting and database, SMS and email delivery, and error monitoring, plus an AI provider for the chatbot’s operational (non-clinical) answers. Each is bound by agreement to protect your data and use it only to provide their part of the service, and none are permitted to use it for their own purposes. A full, current list is available on request.
Data breaches
If a data breach likely to cause serious harm occurs, we will act quickly to contain it and notify you and, where required, the OAIC, in line with the Notifiable Data Breaches scheme.
A signed agreement
If your practice needs a signed data-processing agreement, email hello@grovique.com and we’ll provide one.
Questions? Email hello@grovique.com. We usually reply within one business day.
