Privacy Policy

Last updated: September 16, 2026

1. Introduction

This Privacy Policy describes how Limitless Royalty LLC — a limited liability company formed in the State of Florida, United States, which operates the 3yadtk platform ("Company," "we," "us") — collects, uses, shares, and protects personal information when you use the 3yadtk platform, websites, applications, and services ("Service").

By using the Service, you agree to the terms of this Privacy Policy.

2. Information We Collect

2.1 User-provided information: Name, email address, phone number, onboarding data (clinic name, country, specialty), and payment information (processed by Stripe, not stored by us).

2.2 Patient data: Collected by the subscribing clinic (the data controller) and controlled by the clinic/doctor. We act as data processor under our Data Processing Agreement (DPA).

2.3 Usage data: IP addresses, browser type and requested paths, from server logs. The Google Ads tag measures visits to our public pages only; it does not run inside the clinic system or the patient portal.

2.4 Device data: Device type, operating system, device identifiers for PWA support.

3. How We Use Your Data

  • Providing, operating, and improving the Service
  • Managing your subscription and billing
  • Responding to support requests
  • Sending essential service notifications
  • Complying with legal and regulatory requirements
  • Preventing fraud and ensuring platform security

We will never use patient data for marketing purposes at any time.

4. Where Your Data Is Stored

By default, patient data for every clinic — including clinics in Saudi Arabia and the United Arab Emirates — is stored on our hosting provider’s infrastructure in Europe. It is not stored inside Saudi Arabia or inside the UAE unless you have separately arranged in-region hosting with us in writing (see below).

In-region hosting is available on request, as a paid add-on. If your clinic is required to keep patient data inside a particular country, contact us at privacy@3yadtk.com. In-region hosting is not included in the standard subscription, is priced separately, depends on a suitable hosting region being available for your country, and only takes effect once it is agreed in writing and provisioned for your clinic. Until then, the default above applies.

What this means for you. Every country we serve has its own personal data protection law — PDPL in Saudi Arabia, FDPL in the UAE, and the equivalent in each of the other twelve (the DPA lists the authority and the statute for each). All of them place obligations on your clinic as the controller of your patients’ data, including in relation to transfers outside the country. Because our default hosting is outside all of them, using the platform on the standard subscription involves a cross-border transfer of patient data. You are responsible for assessing whether that is permitted for your clinic and for obtaining any consent or approval your regulator requires. We will provide the information you need for that assessment on request — and we would rather you asked before signing up than discovered it afterwards.

Where we are, as distinct from where the data is. The hosting is in Europe; the company operating it is formed in the United States, and our personnel access the hosted data from there in order to run and support the Service. A clinic assessing a transfer therefore has two destinations to consider, not one: the European hosting region, and the United States. We say so plainly, because a policy that names only the hosting country leaves out the half a regulator usually asks about.

What we do regardless of where data sits: patient data is encrypted at rest and in transit, access is restricted and logged, and we do not use it for marketing or sell it. Those protections are described in section 6 and apply in every region.

5. Third-Party Data Sharing

We work with trusted service providers to operate the platform:

  • Stripe: Payment processing (no access to patient data)
  • Resend: Transactional email, including appointment reminders
  • Google (Gemini): The in-app assistant. It receives the text of the question and the results of the tools it runs; by default it is not sent a patient's name, phone, email, national ID or date of birth — only their MRN. The assistant is off unless the deployment is given keys for it.
  • Railway: Platform hosting, databases, and file storage
  • Sentry: Error tracking (no patient data included)
  • Google Ads: Advertising measurement, on our public pages only. It does not load inside the clinic system or the patient portal, so no patient data and no patient page address reaches it.
  • The push service in the patient's own browser — Google, Apple or Mozilla depending on their device: device notifications pass through it encrypted, and it cannot read their contents.

We use no SMS or WhatsApp provider today, because neither channel is enabled and neither sends anything. If that changes, this list is updated before the first message goes out.

We never sell your data to third parties.

6. Your Rights

Under whichever data protection law applies to you — PDPL in Saudi Arabia, FDPL in the UAE, the equivalent in each other country we serve, and GDPR where it reaches you — you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request data deletion (subject to legal retention requirements)
  • Object to data processing
  • Export your data in a machine-readable format (data portability)

To exercise any of these rights, contact us at: privacy@3yadtk.com

7. Data Retention

We retain account data for the duration of an active subscription plus up to 90 days after cancellation. Patient data retention is controlled by the subscribing clinic. Dental patient records in UAE clinics are retained for 25 years per NABIDH requirements.

8. Security

We use TLS 1.3 encryption for data in transit and AES-256 for data at rest. Access is controlled via multi-factor authentication and least-privilege policies. All patient data access events are logged to an immutable audit trail.

9. Cookies

We use essential cookies for session management and authentication, one functional cookie that remembers your language, and the Google Ads tag on our public pages to measure advertising. It does not load inside the clinic system or the patient portal. Until you accept the banner, consent stays denied and no advertising cookie is set. The detail is in the cookie policy.

10. Breach Notification

In the event of a data breach affecting your personal data, we will notify you within 72 hours of discovery. We commit to that window for every customer in every country we serve alike; where your own country’s law sets a shorter one, the shorter one applies.

For subscribing clinics: notifying a supervisory authority is the controller’s duty — yours — and the deadline differs by country. We will give you, without delay and in writing, everything you need in order to make it: what happened, when, which data and which patients are affected, and what we have done about it. Where a regulator accepts or requires notification from a processor as well, we will make it — but do not rely on that to discharge your own obligation.

11. How to Reach Us About Data

The operator is Limitless Royalty LLC, formed in the State of Florida, United States. We are not established in any of the countries we serve — Saudi Arabia and the United Arab Emirates included — and we do not have an office, branch or registered company in any of them. The platform is operated remotely from the United States. There is one contact point for every data protection question, and it is the same one in every country we serve:

Email (all data protection inquiries)

privacy@3yadtk.com

We will respond to all valid requests within 30 days.

If your regulator requires a locally appointed representative or data protection officer for a provider that is not established in your country, tell us and we will discuss what is possible — but we will not claim to have one where we do not.