Medilust
Back to site IT

Privacy Policy

Last updated: March 31, 2026

1. Data Controller

Medilust S.r.l.
Registered office: Piazzetta Ado Furlan 4, 33170 Pordenone (PN), Italy
VAT: IT01999240938
Email: privacy@medilust.com
Certified email (PEC): medilustsrl@pec.it

2. What we do

Medilust develops and provides "Mami AI", a digital platform for dental practices that includes appointment management, patient communication via WhatsApp Business, AI-powered voice telephony, and administrative practice management.

3. Data we collect

In the course of providing the Mami AI service, we process the following categories of data:

  • Client dental practice data: company name, VAT number, contact details, platform login credentials, billing data.
  • Practice patient data: first name, last name, phone number, email address, appointment-related data, consents given. This data is processed by Medilust as a Data Processor on behalf of the dental practice (the Data Controller).
  • Platform usage data: access logs, interface interactions, device technical data.
  • WhatsApp communication data: phone numbers, content of messages sent and received via Meta's WhatsApp Business API, message delivery status.

4. Legal basis for processing

  • Performance of a contract: processing necessary to deliver the Mami AI service to client practices.
  • Consent: for sending marketing communications and for processing patients' health data (managed by the dental practice as Controller).
  • Legal obligation: for tax and regulatory compliance.
  • Legitimate interest: for platform security and service improvement.

5. Data sharing with third parties

Data may be shared with the following service providers (Sub-processors):

  • Meta Platforms, Inc. — for sending and receiving messages via the WhatsApp Business API
  • Telnyx, Inc. — for voice telephony and SMS services
  • Anthropic, PBC / Google LLC — for artificial intelligence services
  • Amazon Web Services / Hetzner — for hosting and data storage
  • Resend — for sending transactional emails

Data is not sold to third parties.

6. Transfers outside the EU

Some of our providers are based in the United States. Transfers take place on the basis of the Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the EU-US Data Privacy Framework.

7. Data retention

  • Client practice data is retained for the entire duration of the contract and for the 10 years following its termination, as required by Italian tax law.
  • Patient data is retained according to the instructions of the dental practice acting as Data Controller.
  • WhatsApp messaging logs are retained for a maximum of 24 months.

8. Your rights

Under EU Regulation 2016/679 (GDPR), you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure of your data
  • Restrict processing
  • Object to processing
  • Request data portability
  • Withdraw consent at any time

To exercise your rights, write to: privacy@medilust.com

9. Security

We adopt appropriate technical and organizational measures to protect personal data, including:

  • AES-256 encryption for sensitive data at rest
  • TLS encryption for data in transit
  • Data access limited to authorized personnel
  • Daily backups and disaster recovery procedures

10. Cookies

The medilust.com website uses only technical cookies necessary for its operation. We do not use profiling or marketing cookies.

11. Changes

We reserve the right to update this policy. Any changes will be published on this page with an updated date.

12. Supervisory authority

You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) (www.garanteprivacy.it).

Contact LinkedIn Privacy Terms Data deletion

© 2026 Medilust S.r.l. · VAT IT01999240938 · Piazzetta Ado Furlan 4, 33170 Pordenone (PN), Italy