1. Who this policy covers
This policy applies to General Future Guide (“Future Guide”, “we”), Commercial Registration 1508999, health licence 1508999, registered in Bousher, Muscat Governorate, Sultanate of Oman.
It covers everyone who uses futureguide.services: dentists and clinics who open an account, visitors who contact us, and — indirectly — the patients whose imaging a dentist uploads.
2. What we collect
From the dentist: name, clinic or centre name, country, email address, WhatsApp number, and — optionally — a professional licence number. If you write to us in the chat window or on WhatsApp, what you type is collected too — section 5c says what happens to it.
- Patient imaging: CBCT scans (DICOM/ZIP) and intraoral scans (STL/PLY) that the dentist uploads with a case.
- Case data: patient name, age, gender, relevant medical history, number of implants, implant system, surgical kit and required guide type.
- Clinical notes written by the dentist about the case.
- Transaction data: amount, method, exchange-office reference and receipt image where payment is made manually.
- Technical data: IP address, browser type and pages visited, used only to keep the service secure and working.
- Which link brought you: if you arrive from a campaign link, the campaign name it carries is kept for the length of your visit and attached to your message if — and only if — you send one, so we know which channel to keep. It is not a tracker, it is not shared, and a visit with no message leaves nothing.
3. Why we collect it
Patient imaging is collected for one purpose only: to produce the consultative report and, where ordered, the surgical guide file that the dentist requested. We do not use it to build products, train models, or make decisions about any individual patient.
Account and transaction data are collected to operate the account, issue invoices, and meet our record-keeping obligations.
4. The dentist’s responsibility
The treating dentist decides what patient data to send us and why. In data-protection terms the dentist is the controller of that patient’s data and Future Guide acts as a processor on the dentist’s instructions.
Before uploading, every dentist must confirm in the submission form that the patient has consented to their imaging being shared for planning. We rely on that confirmation and do not contact patients ourselves.
5. Who can see the data
A case’s details and files can be opened only by the dentist who sent it and by the members of our team who hold administrator accounts — each by signing in. Every download of a file is recorded with the name of the person who made it.
No case data is sold, rented, or shared with advertisers under any circumstances.
5b. Third-party services this website uses
One service outside our control may receive your IP address when you use this site: the office map on the contact page is served by Google Maps, and it is only contacted after you press “Show the map” — it does not load on its own. Until v3.37 the typefaces were also requested from Google Fonts on every page load; they are now served from this domain, and no request leaves it for them.
Measurement. If you accept it, this site loads Google Analytics and the Meta pixel to count which pages are read and which links are used. Neither is loaded, and no cookie for either is written, until you press Accept on the bar at the foot of the page; declining is one click and is what closing the bar means. You can change that decision at any time from the link in the footer.
What those two receive is a page address, the language you are reading in, and that a link of a certain kind was used — a WhatsApp button, a catalogue, the sign-up page. What they never receive, on any event: patient imaging, case numbers, file names, or the contents of any field you type into. We do not send them your e-mail address or your phone number, and we have switched off Google’s cross-device advertising signals.
The fonts were moved to our own domain in v3.37, which this section promised would be done at deployment. The map is the one that remains, and it can go the same way: a static image in place of the embed. Measurement is off entirely until an account is connected — with no account configured, no bar is shown and no tag exists to load.
5c. Chat and WhatsApp
This site is adding a chat window, and a WhatsApp number answered through the WhatsApp Business Platform, which Meta operates. They are being switched on in stages, and this section was published before any of it, because the section above promises that order for measurement and the same rule applies here. The chat is being brought into service now — the parts that hold a conversation are in place and the window opens to readers shortly. The WhatsApp number is not in service yet. The date each begins operating is recorded here.
What is collected. What you type, the name and contact detail you choose to give, the page you started from, and the time. Nothing else is read from your device.
Where it goes. The conversation is held on our own infrastructure. When it is passed to a person to answer, a copy of it is written to Notion, which we use as our customer-records system; a conversation the assistant handles by itself is not copied there. Notion is a processor acting on our instructions and can see what is written there. A WhatsApp conversation additionally passes through Meta, which operates that platform and can see the message and the number it came from — as it can for any WhatsApp message.
Do not type patient information into either channel. Not a name, not an age, not a case or file number, not imaging. The assistant is built to stop and warn you when it detects one, and that message is not stored. This is not a formality: a chat window and WhatsApp are not appropriate channels for patient data. A case goes through the case form, where it is handled under the rest of this policy.
What the assistant will and will not do. It answers questions about the service — what we do, the delivery times, the subscription, how to submit a case. It does not answer clinical questions and does not give an opinion on a case; it says so and passes you to a consultant. And we will never ask you for a password or a login code — not in chat, not on WhatsApp, not anywhere.
How long it is kept. A conversation is kept while it is open and for as long as the record is useful in supporting you. The final period is with our legal adviser, together with the periods in section 7.
Open point for legal review: the retention period for chat and WhatsApp records, and whether naming Notion and Meta as processors requires a specific agreement or disclosure in the markets served.
5d. Voice assistant
This site offers a voice assistant: a call in which you speak to an automated assistant instead of typing. This section was published before it was switched on, because the section above promises that order and the same rule applies here. The voice assistant is in service, as a trial, from 20 September 2026. If the trial ends, that is recorded here.
What is collected. What you say is turned into text and answered, and both the question and the answer are written into the chat thread beside it — the same record section 5c describes, kept the same way. The microphone opens only after you press Talk and your browser asks you and you allow it, and it closes when you press End or leave the page. No recording of your voice is kept.
Where it goes. The turning of speech into text is done by your own browser, and most browsers do that on their makers’ servers rather than on your device — Google for Chrome, Apple for Safari. That is between you and your browser; we neither receive the audio nor choose who handles it, and you can see and change it in your browser’s own settings. The spoken reply is produced by your device and goes nowhere.
What answers you. The same assistant that answers in writing, from the same text published on this site. There is no AI model in this feature — nothing is generated, invented or paraphrased: a question is matched to an answer somebody here wrote and reviewed, and that answer is read aloud. It is why the spoken answer and the written one in the thread are word for word the same.
Do not say patient information during a call. Not a name, not an age, not a case or file number. What you say passes through the same filter as what you type, and the assistant stops and warns you — but speech cannot be withdrawn once spoken, which is a further reason this is not a channel for patient data. A case is submitted through the case portal, not through a call.
What the assistant will and will not do. It answers questions about the service — what we do, the delivery times, the subscription, how to submit a case. It does not answer clinical questions and does not give an opinion on a case; it says so and passes you to a consultant. It is an automated voice, not a person and not medical advice. It will never ask you for a password or a login code.
How long it is kept. The written thread is kept as section 5c describes. The audio is not kept at all.
Open point for legal review: whether the browser’s own speech service needs naming as a processor when we neither receive the audio nor choose the provider, and whether Iraq or Oman require express consent before a spoken exchange begins.
6. Where the data is stored
A case sent through this site — its details and the files the dentist uploads, and the report and guide we return — is stored with Cloudflare, which hosts this site: the case details in its database (D1) and the files in a private storage bucket (R2), encrypted in transit and at rest. The bucket has no public address. A file can be downloaded only by the dentist who sent the case and by our own team, after signing in, and every download is recorded with who made it.
The emails this site sends — sign-in codes, account activation, “your case is ready”, a new message on a case, and the reminder before a subscription ends — go out through Resend, which receives the recipient’s address and the message. No email carries patient details or case content: they say only that there is something to read, and where.
The hosting region has not been finalised. If any market we serve requires patient data to remain inside its borders, we will host that market’s data accordingly and state it here.
Open point for legal review: whether Iraq, Oman or any GCC market imposes a data-residency requirement on medical imaging.
7. How long we keep it
Everything relating to a case — the imaging the dentist uploaded and the report and guide we produced — is deleted 24 hours after delivery. Patient imaging does not remain on our servers beyond that window, and the dentist can no longer retrieve anything from the site once it closes.
At the same moment the patient’s name, age, gender, medical history, the dentist’s notes and the messages exchanged about the case are erased. A case that is started but never sent is deleted, with any files already uploaded, within 24 hours.
The administrative records that hold no imaging — the case number, its dates and the subscription status — are kept for a period that has not yet been set and is pending legal advice.
Open point for legal review: how long the administrative record of a case should be kept.
8. Anonymised images
We may use images from a case for education and marketing only if the dentist ticked the optional consent when submitting it, and only after every identifier — patient name, reference number, date of birth and scanner metadata — has been removed.
This consent is optional, separate from the mandatory patient-consent confirmation, and can be withdrawn by contacting us.
9. Access, correction and deletion
A dentist can ask us at any time for a copy of the data held about their account or a specific case, ask for it to be corrected, or ask for a case to be deleted before the 24-hour window ends.
Where a patient asks their dentist to have imaging deleted, the dentist should contact us and we will act on that instruction. Requests go to [email protected].
10. Security
Accounts are activated only after manual review. There is no password: each sign-in uses a six-digit code sent to the e-mail address on the account, valid for ten minutes and for one use, so there is no password to guess, reuse or leak. We will never ask you for that code. Uploads and downloads run over encrypted connections.
No system is perfect. If a breach affects your data we will tell you and the relevant authority without delay.
11. Contact
Questions about this policy: [email protected] or WhatsApp +964 774 764 4134, daily 08:00–22:00. We reply within 24 hours.