How Chairside Protects Your Data
Your patients' data security is at the heart of everything we do. This article walks you through how Chairside keeps your data safe - and how to talk to your patients about it with confidence.
Table of contents
- Where your data is stored
- How your data is protected
- What happens to consultation audio
- How Chairside uses AI
- Independent certification
- Data retention and deletion
- Talking to your patients about it
- Where to go for more
Where your data is stored
Everything Chairside stores - patient records, dental imaging, photos, audio, transcripts, chat messages, system logs and backups - is stored in Australia, in Google Cloud's Sydney region.
Some processing happens outside Australia. The main cases are:
-
AI processing. Our own dental imaging AI runs on Google Cloud computing capacity in the United States, and Google's transcription and language models process requests through Google's United States and global endpoints. In both cases the content is held in memory only for as long as the request takes, is not retained afterwards, and is never used to train any AI model. This is governed by the Google Cloud Data Processing Addendum.
-
Signing in. Your account details for signing in - your email address, your practice and your role - are handled by an authentication provider in the United States. No clinical or patient information is held there.
-
Product analytics. Information about how Chairside is used is processed by an analytics provider in the United States.
Backups are encrypted at rest, access-controlled, and monitored.
What happens to consultation audio
When you record a consult with Transcribe:
-
The audio is transcribed, then deleted. By default, Chairside removes the audio file as soon as transcription finishes. It is not kept.
-
The session stays. The transcript, and the notes, letters and Care Packs generated from it, remain in your account until someone deletes them.
-
One setting changes this. If your practice turns on **Retain audio recordings** (Account > Practice > Advanced), the original audio is kept instead of deleted, and is not removed automatically. It exists so our support team can investigate a transcription problem for you. Leave it off unless support has asked you to switch it on - and if you do switch it on, check that your patient consent wording still describes what happens accurately.
How your data is protected
- Encryption. Your data is encrypted both at rest and in transit.
- Access controls. Multi-factor authentication protects all administrative access to our systems. For your practice's own users, multi-factor authentication is available and can be made mandatory on request.
- Logging. Security and audit logs are kept for 12 months and cannot be altered or deleted. Application logs are kept for 90 days.
- Practice system integrations. Where Chairside integrates with your practice management system, the connection is one-way only - data flows from your PMS into Chairside, and Chairside never writes back.
How Chairside uses AI
Chairside uses a combination of CoTreat's own dental imaging AI and Google's Gemini and speech-to-text models, both running on Google Cloud under the Google Cloud Data Processing Addendum.
Identifiable patient data is never used to train AI models - not by CoTreat, and not by Google. Only aggregated, de-identified data, with facial imagery and other identifiers removed, is ever used to improve the product, and only where our agreements with practices permit it. If you would prefer your practice's de-identified data not to be used this way, email privacy@cotreat.com.au and we will exclude it.
Chairside provides decision-support, not decisions. The clinician always retains oversight and the final say.
Independent certification
CoTreat is ISO 27001:2022 certified, certified in March 2026, with continuous automated compliance monitoring in place. We also commission independent penetration testing each year, most recently in April 2026.
Google Cloud, our infrastructure provider, separately holds its own certifications - including ISO 27001, ISO 27017, ISO 27018, and SOC 1, 2, and 3. These are Google's certifications, covering the infrastructure Chairside runs on, rather than certifications held by CoTreat directly.
We also run a supplier risk-management process to assess the security of the vendors we rely on. For the full list of sub-processors, what each one is used for and where it runs - including Google Cloud, WorkOS (sign-in) and PostHog (product analytics) - see our Trust Centre
Data retention and deletion
Your practice owns your Customer Data - the patient and clinical information you put into Chairside. CoTreat owns the platform itself.Health records legislation generally requires health information to be kept for at least 7 years after a patient's last service, and for information collected from a child, until they turn 25. The exact period depends on the State or Territory your practice operates in, and meeting it is your practice's obligation. We keep your information for as long as it is required or authorised under law, and no longer.
You can request a copy of your data at any time during your subscription, or within 30 days after it ends. We provide it in a commonly used format within a reasonable period.
If you request deletion, your data is securely destroyed or permanently de-identified, subject to those statutory retention requirements. Backups roll off automatically after roughly 14-30 days, and once that window passes the deleted records are gone from our backups too. Security and audit logs, which record system events rather than clinical content, run on their own retention cycle.
Talking to your patients about it
If a patient asks about Chairside, here's a simple way to explain it:
- Why you're using Chairside. It helps your dental team focus on you during your visit, instead of splitting their attention with note-taking.
- Is it safe and secure? Yes, your data is encrypted, access-controlled, and never used to train AI models without being de-identified first.
- Is it independently certified? Yes, CoTreat is ISO 27001:2022 certified, and our infrastructure provider, Google Cloud, holds its own independent certifications too.
- Where is data stored? In Australia, on Google Cloud's Sydney region.
- Does it ever leave Australia? Some AI processing steps happen outside Australia using secure cloud AI services. The content is processed in memory only, isn't kept by those providers, and isn't used to train their models.
Getting a patient's consent to use Chairside during their appointment - and explaining what that means - is part of your practice's own consent process, not something Chairside handles for you.
Where to go for more
-
Our Privacy Policy sets out how we handle personal information, including exactly where data is stored and processed (sections 4.6 and 4.7).
-
Our Terms and Conditions cover security, data storage, export and deletion (clauses 39 to 46).
-
Our Trust Centre has our certifications and the full sub-processor list.
For privacy questions, contact privacy@cotreat.com.au. For security or general support questions, contact help@cotreat.com.au.