Legal
Privacy Policy
Effective September 23, 2026
Dentappl, LLC (“Dentappl,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the personal information entrusted to us.
This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you access or use Dentappl’s websites, mobile and desktop applications, patient services, provider-search and appointment services, clinic-management software, professional tools, and related products and services that link to this Privacy Policy (collectively, the “Services”).
It also explains the privacy choices and rights that may be available to you.
This Privacy Policy applies to patients, visitors, dental professionals, clinic personnel, and other individuals whose Personal Data is processed by Dentappl, except where a different privacy notice expressly applies.
Certain information Dentappl processes on behalf of healthcare providers may constitute Protected Health Information (“PHI”) under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”). The treatment of PHI is described separately below.
By using the Services, you acknowledge the practices described in this Privacy Policy.
1. Definitions
For purposes of this Privacy Policy:
“Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household.
“Sensitive Personal Data” means Personal Data treated as sensitive under applicable law, which may include health information, insurance information, precise geolocation, financial account information, certain government identifiers, and other protected categories.
“PHI” means Protected Health Information regulated by HIPAA.
“Consumer Health Data” means health-related Personal Data protected under applicable state consumer health privacy laws, to the extent such laws apply.
“Patient” means an individual using Dentappl to search for dental professionals, communicate with a clinic, schedule or manage appointments, complete forms, manage insurance information or payments, or otherwise interact with patient-facing Services.
“Professional User” means a dentist, dental professional, clinic owner, administrator, employee, contractor, or other individual using Dentappl on behalf of a dental practice or other organization.
2. HIPAA and Protected Health Information
Dentappl provides technology services to dental practices and healthcare professionals.
In certain circumstances, Dentappl may process identifiable health information on behalf of a dental practice or other healthcare provider that is a “Covered Entity” under HIPAA. When Dentappl performs such services and qualifies as a “Business Associate” under HIPAA, applicable PHI is governed by HIPAA and the applicable Business Associate Agreement (“BAA”) between Dentappl and the healthcare provider.
Examples may include information Dentappl processes on behalf of a clinic in connection with:
- patient records;
- clinical documentation;
- treatment information;
- appointment administration;
- patient forms;
- insurance eligibility;
- benefits information;
- billing;
- insurance claims;
- payment administration;
- communications relating to patient care; and
- other healthcare operations performed on behalf of a clinic.
When Dentappl acts as a Business Associate, the healthcare provider generally controls the applicable patient relationship and determines the permitted purposes for which Dentappl processes PHI.
Patients should review the applicable healthcare provider’s Notice of Privacy Practices for information about how that provider uses and discloses PHI and how patients may exercise HIPAA rights relating to that PHI.
Dentappl may assist providers in responding to requests involving PHI as required by the applicable BAA and law.
Information that is not PHI
Not all health-related information processed by Dentappl is PHI.
For example, information may not be PHI when Dentappl collects it directly from an individual in Dentappl’s own capacity rather than on behalf of a HIPAA Covered Entity.
Depending on the circumstances, such information may instead be protected by this Privacy Policy, state consumer health privacy laws, general consumer privacy laws, or other applicable requirements.
3. Personal Data we collect
The information we collect depends on how you interact with Dentappl and which Services you use.
3.1 Account and identity information
We may collect information such as:
- first and last name;
- email address;
- telephone number;
- mailing address;
- account identifiers;
- username;
- authentication information;
- account role;
- communication preferences; and
- information used to verify your identity or account.
We do not need to receive your password in readable form when authentication systems store credentials using appropriate cryptographic protection.
3.2 Patient profile and demographic information
When relevant to the Services, we may collect:
- date of birth;
- age;
- gender or sex information;
- address;
- preferred language;
- emergency contact information;
- dependent or family-member information; and
- other demographic information you choose or are required to provide.
3.3 Appointment and provider-search information
We may collect information about:
- dental professionals or clinics you search for or view;
- locations or geographic areas you search;
- appointment dates and times;
- appointment requests;
- appointment status;
- appointment type;
- reason for visit;
- provider preferences;
- cancellations or rescheduling;
- previous or upcoming appointments; and
- your interactions with provider profiles and search results.
Some of this information may constitute health information or PHI depending on the context in which Dentappl processes it.
4. Health and dental information
Depending on the Services you use, Dentappl may process health or dental information such as:
- dental history;
- medical history;
- health conditions;
- allergies;
- medications;
- treatment information;
- procedures;
- diagnoses;
- clinical notes;
- dental charts;
- treatment plans;
- radiographs, photographs, or other clinical images;
- forms and questionnaires;
- consent forms;
- documents uploaded by patients or clinics;
- provider communications; and
- other information relevant to dental or healthcare services.
When Dentappl processes this information as a Business Associate of a healthcare provider, it is handled in accordance with HIPAA and the applicable BAA.
5. Insurance, benefits, billing, and claims information
The Services may process information necessary to support insurance and payment workflows, including:
- insurance company;
- insurance plan;
- member or subscriber ID;
- group number;
- payer identifiers;
- subscriber information;
- relationship to subscriber;
- coverage information;
- eligibility information;
- benefit information;
- deductible information;
- annual maximum information;
- coordination-of-benefits information;
- claims;
- claim status;
- procedure and diagnosis codes;
- supporting claim documentation;
- estimated insurance payments;
- actual insurance payments;
- patient responsibility;
- adjustments;
- refunds; and
- billing history.
This information may come from you, a healthcare provider, an insurer, a clearinghouse, or another service involved in processing eligibility or claims.
Insurance eligibility and benefit information may change and is not a guarantee of payment or coverage.
6. Payment and transaction information
Dentappl may facilitate payments for dental services or Dentappl products and subscriptions.
Payment transactions may be processed by third-party payment processors.
Depending on the payment workflow, Dentappl may receive information such as:
- billing name;
- billing address;
- transaction amount;
- payment status;
- transaction identifiers;
- payment method type;
- last four digits of a payment card;
- refunds;
- adjustments; and
- payment processor tokens or references.
Dentappl does not need to store full payment-card numbers when payment information is collected directly by an authorized payment processor.
Payment processors process payment information according to their own legal and privacy obligations.
7. Professional and clinic information
For Professional Users, we may collect information including:
- name;
- professional title;
- dental or professional specialty;
- professional license information;
- National Provider Identifier or similar identifiers;
- clinic affiliations;
- clinic address;
- professional telephone numbers and email addresses;
- biography;
- education and credentials;
- languages;
- services offered;
- photographs;
- schedule and availability;
- employment or staff role;
- account permissions;
- billing and subscription information;
- administrative activity; and
- other information associated with use of professional Services.
Certain provider and clinic information may be displayed publicly through Dentappl provider or clinic profiles.
8. Communications
We may process communications sent through or relating to the Services, including:
- emails;
- support requests;
- chat or messaging communications;
- SMS or MMS messages;
- appointment communications;
- push notifications;
- communications between patients and clinics;
- billing communications;
- insurance communications;
- security notifications; and
- account-status, account-deletion, and account-recovery notices.
We may retain appropriate records of communications for customer support, security, compliance, dispute resolution, and service operation.
Professional Users are responsible for ensuring that communications they initiate through Dentappl comply with applicable law and patient-consent requirements.
9. Device, technical, and usage information
When you access the Services, we may automatically receive certain information about your device and use of the Services, such as:
- IP address;
- browser type;
- device type;
- operating system;
- application version;
- device identifiers;
- language;
- referring page;
- pages or screens viewed;
- dates and times of access;
- interactions with features;
- errors and diagnostic information;
- approximate location derived from IP address;
- login activity;
- authentication activity; and
- security and audit logs.
We use this information to operate, secure, troubleshoot, maintain, and improve the Services.
10. Location information
Certain features may use location information to help you find nearby dental professionals or clinics, display map results, or provide location-related functionality.
Depending on your device settings, this information may include:
- ZIP code;
- city;
- address;
- approximate location; or
- device location where you have granted the applicable permission.
You can control device-level location permissions through your device or browser settings.
Dentappl does not use precise location information to infer sensitive characteristics unrelated to providing the Services.
11. Sources of Personal Data
We may obtain Personal Data from the following sources.
Directly from you
For example, when you:
- create an account;
- complete your profile;
- search for a provider;
- request or manage an appointment;
- complete a patient form;
- provide insurance information;
- communicate with a clinic;
- make a payment;
- submit a review;
- contact customer support; or
- otherwise provide information through the Services.
Healthcare providers and clinics
A clinic may provide or create information through Dentappl while managing appointments, records, treatment, insurance, billing, claims, communications, or other practice functions.
Insurance companies, payers, and clearinghouses
We may receive information needed to verify eligibility, obtain benefit information, submit or manage claims, or support related administrative services.
Payment processors and financial-service providers
We may receive transaction status and related payment information necessary to operate payment and billing features.
Service providers and integrations
We may receive information from vendors and systems used to support identity verification, communications, hosting, security, mapping, analytics, practice-management integrations, and other functionality.
Public and professional sources
For provider profiles or professional verification, we may obtain information from publicly available professional sources, licensing information, clinic websites, or other lawful sources.
12. How we use Personal Data
We may use Personal Data to:
Provide the Services
Including to:
- create and manage accounts;
- authenticate users;
- enable provider search;
- display provider and clinic profiles;
- schedule and manage appointments;
- communicate appointment information;
- support clinic workflows;
- maintain patient information;
- process forms;
- support insurance verification;
- submit and manage claims;
- support billing and payments;
- provide customer support;
- operate subscriptions; and
- provide other requested functionality.
Communicate with you
We may send:
- account communications;
- account-deletion confirmations, reminders, cancellations, and completion notices;
- appointment confirmations;
- appointment reminders;
- form requests;
- insurance-related communications;
- billing and payment notices;
- security notices;
- service announcements;
- customer-support communications; and
- other transactional or operational messages.
Marketing communications are subject to applicable consent and opt-out requirements.
Secure and protect the Services
We may use information to:
- authenticate accounts;
- prevent unauthorized access;
- detect fraud;
- investigate suspicious activity;
- prevent abuse;
- enforce access controls;
- maintain audit logs;
- investigate security incidents; and
- protect patients, clinics, Dentappl, and others.
Maintain and improve Dentappl
We may use appropriate information to:
- diagnose technical problems;
- measure system performance;
- develop new functionality;
- improve user experience;
- conduct internal analytics;
- understand how features are used;
- test and improve software; and
- maintain service quality.
When possible and appropriate, we use aggregated or de-identified information for these purposes.
Comply with legal obligations
We may process information to:
- comply with applicable law;
- comply with HIPAA obligations where applicable;
- respond to valid legal process;
- enforce agreements;
- establish or defend legal claims;
- investigate fraud or unlawful conduct;
- meet accounting and tax requirements; and
- satisfy regulatory obligations.
13. Advertising and use of health information
Dentappl recognizes that health, dental, appointment, and insurance information is particularly sensitive.
Dentappl does not sell PHI.
Dentappl does not use or disclose PHI for cross-context behavioral advertising.
Dentappl also does not use clinical records, appointment reasons, treatment information, insurance information, claims information, or other sensitive health information to target third-party behavioral advertising to patients.
We may use limited analytics technologies to understand how public-facing portions of the Services operate and how users find Dentappl.
Dentappl seeks to configure analytics and marketing technologies so that PHI and sensitive patient information are not transmitted through advertising or marketing tracking technologies.
Advertising or analytics technologies should not be deployed in authenticated clinical areas, patient records, insurance forms, claim workflows, or other areas containing PHI unless their use has been reviewed and determined to comply with applicable privacy and healthcare requirements.
14. Cookies and similar technologies
Dentappl may use cookies and similar technologies on websites and web applications.
These may include:
Essential technologies
Necessary to:
- authenticate users;
- maintain sessions;
- prevent fraud;
- provide security;
- remember privacy selections; and
- operate requested functionality.
Functional technologies
Used to remember settings such as:
- language;
- display preferences;
- previously selected options; and
- other user preferences.
Analytics technologies
Used to understand:
- website traffic;
- feature usage;
- application performance;
- errors; and
- general user interaction with the Services.
Where required by applicable law, non-essential cookies or similar technologies will be subject to appropriate consent or privacy controls.
You may also control certain cookies through your browser settings.
Blocking essential cookies may prevent portions of the Services from functioning correctly.
15. Sale and sharing of Personal Data
Dentappl does not sell Personal Data for monetary consideration.
Dentappl does not sell PHI, clinical information, dental information, insurance information, claims information, or other patient health information.
Dentappl does not share such sensitive patient information with third parties for cross-context behavioral advertising.
If Dentappl changes its practices in the future in a manner that constitutes a “sale,” “sharing,” or targeted advertising under applicable privacy law, Dentappl will provide legally required disclosures and privacy choices before engaging in those practices.
16. How we disclose Personal Data
We may disclose Personal Data to the following categories of recipients when reasonably necessary for the purposes described in this Privacy Policy.
Healthcare providers and clinics
When you choose to interact with, schedule with, or receive services from a participating provider or clinic.
Authorized clinic personnel
Patient information may be made available to Professional Users authorized by the applicable clinic and their assigned permissions.
Insurance companies and payers
To:
- verify eligibility;
- obtain benefits;
- submit claims;
- obtain claim status;
- coordinate benefits; and
- support insurance-related workflows requested by the patient or clinic.
Claims clearinghouses and healthcare transaction providers
To facilitate healthcare administrative transactions.
Payment processors
To process payments, refunds, subscriptions, and other transactions.
Communications providers
To deliver:
- email;
- SMS;
- telephone communications;
- push notifications; and
- related service communications.
Hosting, infrastructure, and technology providers
To operate, secure, store, maintain, and support the Services.
Where PHI is involved, Dentappl requires applicable service providers to handle PHI in accordance with HIPAA requirements, including through Business Associate Agreements where required.
Security and fraud-prevention providers
To detect, investigate, and prevent unauthorized access, fraud, cybersecurity threats, and abuse.
Mapping and location providers
To provide map, address, geocoding, and location functionality requested by users.
Analytics providers
To understand and improve the performance and use of Dentappl, subject to the restrictions described in this Privacy Policy regarding health information and PHI.
Parties you authorize
We may disclose information to a third party when you request, direct, or authorize us to do so.
17. Legal disclosures
Dentappl may disclose Personal Data when we reasonably believe disclosure is necessary to:
- comply with applicable law or regulation;
- comply with a valid subpoena, court order, warrant, or other lawful process;
- respond to governmental or regulatory requests;
- investigate suspected fraud or illegal activity;
- enforce our agreements;
- protect the rights, safety, or security of Dentappl, users, patients, clinics, or others; or
- establish, exercise, or defend legal claims.
When PHI is involved, disclosures are also subject to applicable HIPAA requirements and the relevant BAA.
18. Business transfers
If Dentappl is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction, Personal Data may be disclosed or transferred as part of that transaction where permitted by law.
Any successor entity receiving Personal Data remains subject to applicable legal obligations regarding that information.
Additional consent or notice will be provided where legally required.
19. De-identified and aggregated information
Dentappl may create aggregated or de-identified information that is not reasonably capable of identifying an individual.
We may use such information for purposes including:
- service analytics;
- product development;
- security;
- operational planning;
- performance measurement;
- quality improvement; and
- business analysis.
Where required by applicable law, Dentappl will maintain de-identified information in de-identified form and will not attempt to re-identify it except where permitted by law for purposes such as validating the effectiveness of de-identification processes.
De-identification of PHI will be performed in accordance with applicable HIPAA requirements where HIPAA applies.
20. Data retention
Dentappl retains Personal Data for only as long as reasonably necessary for the purposes for which it was collected or as required or permitted by law.
Retention periods may depend on factors including:
- the type and sensitivity of information;
- the purpose for which it was collected;
- whether an account remains active, is pending deletion, or has been closed;
- the relationship between Dentappl and the applicable clinic;
- legal or contractual obligations;
- healthcare record-retention requirements;
- insurance and claims requirements;
- payment and accounting requirements;
- security and fraud-prevention needs;
- dispute-resolution needs; and
- applicable statutes of limitations.
Certain data may be retained after an account is closed where necessary to meet legal, healthcare, security, financial, contractual, audit, or record-integrity requirements. Closing or deleting a Dentappl sign-in account does not alter a healthcare provider’s independent obligation or right to retain its patient records.
Information contained in backups may remain for a limited period until backups are overwritten or securely removed through ordinary backup processes.
Dentappl may retain de-identified or aggregated information when legally permitted.
21. Patient account deletion
Dentappl provides eligible patients with mechanisms to request deletion of their Dentappl sign-in account and applicable account-level Personal Data. A deletion request may be initiated through available account functionality or by contacting Dentappl.
14-day deletion period
Unless a different period is required by law or necessary for security, fraud-prevention, legal, or operational reasons, an eligible patient-account deletion request is scheduled for completion 14 days after the request is submitted.
During this waiting period:
- the account generally remains available for normal use;
- Dentappl may display the scheduled deletion date within the account;
- Dentappl will send an account-deletion notice to the email address associated with the account and may send additional reminder notices before deletion; and
- the patient may cancel the deletion request at any time before the scheduled deletion is completed.
Dentappl may require identity or account verification before accepting, cancelling, or completing a deletion request. Dentappl may also pause, decline, or cancel a deletion request where necessary to protect account security, investigate fraud or abuse, comply with law, preserve records subject to legal hold, or resolve an account that has active professional or clinic-administration access.
What is removed from Dentappl
After the waiting period expires and the deletion request is eligible for completion, Dentappl will remove or disable the patient’s Dentappl sign-in access and delete or disassociate account-level information that Dentappl independently controls where no retention requirement applies. Depending on the Services used, this may include authentication identifiers, active sessions or tokens, device or push-notification registrations, account notification preferences, personal marketplace preferences, and family or dependent access relationships.
Some limited information may be retained where reasonably necessary to document the deletion request, protect security, prevent fraud, comply with legal obligations, resolve disputes, or maintain required audit records.
Clinic and healthcare records are not deleted with the Dentappl account
Deleting a Dentappl account does not delete dental or medical records maintained by or on behalf of a healthcare provider merely because those records were accessible through the deleted account.
A healthcare provider may be legally or professionally required to retain information such as:
- patient demographics and identifiers maintained as part of the clinic chart;
- clinical records;
- consent documentation;
- treatment records;
- appointment history;
- insurance and eligibility information;
- claims and claim documentation;
- billing information;
- payment and refund records;
- communications relating to care;
- audit records; and
- other information maintained as part of the provider’s healthcare or business records.
Dentappl may therefore retain or continue processing such information on behalf of the healthcare provider when necessary to satisfy the provider’s legal, professional, or contractual obligations or Dentappl’s obligations as a Business Associate. The healthcare provider remains responsible for responding to requests concerning its own clinical or healthcare records, including requests for access, amendment, restriction, or other rights that apply to those records.
Similarly, information may remain with insurers, payment processors, clearinghouses, communications providers, or other third parties according to their own legal obligations and retention policies.
Where Dentappl controls information independently and no retention exception applies, Dentappl will process valid deletion requests as required by applicable law.
22. Your health-information rights
When information is PHI maintained by or on behalf of a healthcare provider, HIPAA may provide rights relating to:
- access to PHI;
- copies of PHI;
- amendment of PHI;
- accounting of certain disclosures;
- restrictions on certain uses or disclosures;
- confidential communications; and
- complaints regarding privacy practices.
Because the applicable healthcare provider generally controls these records, you should normally exercise HIPAA rights through that provider.
Dentappl will assist healthcare-provider customers with such requests when required by HIPAA and the applicable BAA.
23. U.S. state privacy rights
Depending on where you live and which privacy laws apply to Dentappl, you may have rights concerning Personal Data that Dentappl controls independently.
These rights may include the right to:
- confirm whether Dentappl processes your Personal Data;
- access Personal Data;
- obtain a copy of Personal Data;
- learn the categories of Personal Data collected;
- learn the categories of sources from which Personal Data was obtained;
- learn the purposes for which Personal Data is processed;
- learn the categories of recipients to whom information is disclosed;
- correct inaccurate Personal Data;
- delete certain Personal Data;
- obtain portable Personal Data;
- withdraw consent where processing is based on consent;
- opt out of sale of Personal Data;
- opt out of sharing or processing for targeted advertising;
- limit certain uses or disclosures of Sensitive Personal Data;
- opt out of qualifying profiling or automated decision-making activities;
- appeal certain decisions regarding a privacy request; and
- exercise privacy rights without unlawful discrimination.
These rights are subject to applicable legal definitions, exceptions, and verification requirements.
Some information processed by Dentappl on behalf of healthcare providers may be exempt from certain state privacy laws or may need to be addressed through the healthcare provider rather than Dentappl directly.
24. California privacy information
California residents may have rights under the California Consumer Privacy Act, as amended (“CCPA”), where the CCPA applies.
Categories of information
During the preceding twelve months, depending on your relationship with Dentappl, we may have collected categories of information such as:
| CategoryExamples | |
|---|---|
| Identifiers | Name, email, phone number, address, account ID, IP address |
| Customer records | Contact information, account information, payment-related information |
| Protected or demographic characteristics | Age, date of birth, gender information where provided |
| Commercial information | Transactions, subscriptions, payment history |
| Internet or network activity | Device information, interactions with Dentappl, logs |
| Geolocation information | Approximate location, address or device location where enabled |
| Professional information | Provider credentials, clinic role, professional information |
| Sensitive Personal Information | Health, insurance, account authentication and certain financial information |
| Inferences | Preferences or information derived to provide or improve Services |
Dentappl collects these categories for the purposes described in this Privacy Policy.
Dentappl may disclose these categories to service providers, healthcare providers, insurers, payment providers, and other recipients described in this Privacy Policy.
Sale and sharing
Dentappl does not sell Personal Data for monetary consideration.
Dentappl does not sell or share PHI or sensitive health information for cross-context behavioral advertising.
California consumer rights
Where applicable, California consumers may request:
- access to information;
- disclosure of categories and specific pieces of Personal Data;
- correction;
- deletion;
- information regarding disclosures;
- opt-out of sale or sharing;
- limitation of certain uses of Sensitive Personal Information; and
- non-discriminatory treatment when exercising privacy rights.
25. Sensitive Personal Data
Dentappl processes Sensitive Personal Data only for purposes reasonably necessary to provide, secure, and operate the Services or for other purposes permitted by law.
Depending on your interaction with Dentappl, Sensitive Personal Data may include:
- health information;
- dental information;
- insurance information;
- certain financial information;
- account authentication credentials;
- precise geolocation if enabled;
- information concerning minors; and
- other information classified as sensitive by applicable law.
We do not process Sensitive Personal Data for the purpose of making unrelated inferences about an individual.
We do not sell Sensitive Personal Data.
26. Consumer health data
Health-related information that is not governed by HIPAA may nevertheless be protected under state consumer health privacy laws.
Where such laws apply, Dentappl will process applicable Consumer Health Data in accordance with those requirements, including applicable requirements concerning:
- transparency;
- collection;
- consent;
- disclosure;
- security;
- access;
- deletion;
- withdrawal of consent; and
- authorization for certain transfers or sales.
Dentappl may provide a separate Consumer Health Data Privacy Policy where required by applicable law.
27. Exercising your privacy rights
You may exercise applicable privacy rights by contacting Dentappl at:
Where available, certain requests may also be made through account settings or other privacy controls within the Services.
Please describe your request with enough detail for us to identify the information and right involved.
Dentappl may need to verify your identity before completing certain privacy requests.
Verification may involve information associated with your account and will be proportionate to the nature and sensitivity of the request.
We will use information provided for verification only as reasonably necessary to verify and process the request.
If Dentappl cannot verify a request, we may be unable to provide or delete certain information.
Authorized agents
Where permitted by applicable law, you may authorize another person to submit a privacy request on your behalf.
Dentappl may request evidence that the agent is authorized to act for you and may verify your identity directly.
Appeals
If applicable state law provides a right to appeal our decision concerning a privacy request, you may submit an appeal to:
Please identify the original privacy request and explain the basis for your appeal.
28. Global Privacy Control and opt-out signals
Where applicable law requires recognition of browser-based opt-out preference signals, Dentappl will process qualifying signals, such as Global Privacy Control, in accordance with applicable law.
Because Dentappl does not sell PHI or use sensitive health information for targeted advertising, such signals do not affect Dentappl’s processing of information that is necessary to provide requested healthcare or administrative Services.
29. Communications and marketing choices
Transactional communications may be necessary to operate the Services and may include:
- appointment confirmations, changes, cancellations, and reminders;
- security notifications;
- billing notices;
- account notices;
- account-deletion confirmations, reminders, cancellation notices, and completion notices;
- form requests;
- service notifications; and
- insurance-related communications.
You may not be able to opt out of communications that are strictly necessary to secure or operate your account, complete an account-deletion request, or provide Services you request.
For eligible patient accounts, appointment text-message updates may be enabled for the verified sign-in telephone number when that functionality is available, subject to applicable law and carrier requirements. You can turn off appointment text updates through the notification settings available in your Dentappl account. Where supported, SMS recipients may also reply STOP to unsubscribe from applicable text messages and HELP for assistance. Message and data rates may apply.
Turning off appointment text messages does not prevent Dentappl from sending necessary email, in-app, security, legal, or account-status notices.
You may opt out of promotional email communications using the unsubscribe mechanism contained in the communication. Marketing communications that require separate consent will be sent only in accordance with applicable consent requirements.
Certain clinic communications are controlled by the clinic rather than Dentappl. Clinics remain responsible for obtaining any consent or authorization required for communications they initiate.
30. Data security
Dentappl maintains administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, acquisition, loss, misuse, alteration, or disclosure.
Depending on the system and information involved, safeguards may include:
- encryption;
- secure transmission;
- identity and authentication controls;
- role-based access controls;
- logging and monitoring;
- restricted administrative access;
- system and application security controls;
- backup protections;
- vulnerability management;
- incident-response procedures;
- workforce access restrictions; and
- vendor-security requirements.
Access to patient information should be limited according to professional role and legitimate need.
No information system or method of electronic transmission can be guaranteed to be completely secure.
If Dentappl discovers a security incident involving Personal Data, we will investigate and provide legally required notifications when applicable.
Where PHI is involved, Dentappl will follow applicable HIPAA requirements and BAA obligations concerning security incidents and breaches.
31. Children and dependent patients
Dental practices commonly provide services to minors.
Parents, legal guardians, or other legally authorized individuals may provide information about a minor or manage certain aspects of a minor’s care through Dentappl where permitted by law.
Healthcare providers may also maintain information about minor patients through the professional Services.
Such information may be subject to HIPAA, state healthcare laws, parental-consent requirements, and other legal protections.
Children should not create independent consumer accounts unless the applicable Dentappl Service expressly permits it and applicable consent requirements have been satisfied.
If we learn that Personal Data from a child has been collected in circumstances where legally required consent was not obtained, we will take appropriate action consistent with applicable law.
32. Third-party services and links
Dentappl may provide links to or integrations with third-party services.
Those third parties may independently collect or process information according to their own privacy policies and legal obligations.
Examples may include:
- payment processors;
- mapping providers;
- insurance services;
- practice-management systems;
- authentication providers; and
- external websites.
Dentappl is not responsible for the independent privacy practices of third parties when those parties process information outside Dentappl’s instructions or control.
We encourage you to review applicable third-party privacy policies.
33. Professional customers and their workforce
When Dentappl receives Personal Data concerning a clinic’s employees, contractors, or other workforce members in connection with providing professional Services, Dentappl may process that information on behalf of the clinic.
The clinic is responsible for:
- determining authorized users;
- assigning appropriate permissions;
- maintaining accurate workforce information;
- removing access when no longer appropriate; and
- providing privacy notices required to its workforce.
Professional Users should not access patient information unless they are authorized to do so.
34. International access
Dentappl is operated from the United States and is primarily intended to provide Services in the United States.
If you access Dentappl from another jurisdiction, information may be transferred to and processed in the United States.
Where legally required for international transfers, Dentappl will use appropriate safeguards.
35. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to:
- our Services;
- technology;
- data practices;
- legal requirements; or
- business operations.
When we make changes, we will revise the Effective Date at the top of this Privacy Policy.
If changes are material, we may provide additional notice through the Services, by email, through an application notification, or through another appropriate method.
Where consent is legally required for a new processing activity, we will obtain that consent rather than relying solely on an updated Privacy Policy.
36. Contact us
For questions, privacy requests, or concerns regarding this Privacy Policy or Dentappl’s privacy practices, contact:
Dentappl, LLC
15442 Ventura Blvd, Ste 101
Sherman Oaks, California
United States
Email: info@dentappl.com
For privacy-related correspondence, please include “Privacy Request” in the subject line where appropriate.
