Privacy Policy

Privacy Policy

AI Dental Assistant Software – Data Privacy Notice

Last Updated

May 15, 2026

Effective Date

May 15, 2026

1

Overview

This Privacy Policy describes the policies and procedures of DentraxAI ("DentraxAI", "we", "us", or "our") on the collection, use, and disclosure of your information when you use the DentraxAI website, AI dental assistant, AI voice receptionist, dental practice automation software, and related services (collectively, the "Service"). It also explains your data privacy rights and how applicable laws — including the California Consumer Privacy Act (CCPA/CPRA), the UK General Data Protection Regulation (UK GDPR), the EU GDPR, and the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) — protect you.

We use your Personal Data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

2

Interpretation and Definitions

Interpretation

Words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or plural form.

Definitions

For the purposes of this Privacy Policy:

Account means a unique account created for you to access our Service or parts of our Service.

Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest, or other securities entitled to vote for election of directors or other managing authority.

Business for the purpose of CCPA/CPRA, refers to the Company as the legal entity that collects Consumers' personal information and determines the purposes and means of the processing of Consumers' personal information.

CCPA and/or CPRA refers to the California Consumer Privacy Act (the "CCPA") as amended by the California Privacy Rights Act of 2020 (the "CPRA").

Company (referred to as either "the Company", "DentraxAI", "We", "Us", or "Our" in this Privacy Policy) refers to DentraxAI, located at [ADDRESS].

Consumer for the purpose of the CCPA/CPRA, means a natural person who is a California resident.

Cookies are small files that are placed on your computer, mobile device, or any other device by a website, containing the details of your browsing history on that website among its many uses.

Country refers collectively to the United States of America (with California as the primary jurisdiction), Canada, and the United Kingdom for users located in those regions.

Data Subject for the purpose of the UK GDPR and EU GDPR, means any living individual who is using our Service and is the subject of Personal Data.

Dental Practice means the dental clinic, dental office, or other healthcare provider entity that subscribes to or uses the Service.

Device means any device that can access the Service such as a computer, a cell phone, a digital tablet, or VoIP-enabled hardware.

Do Not Track (DNT) is a concept that has been promoted by US regulatory authorities, in particular the U.S. Federal Trade Commission (FTC), for the Internet industry to develop and implement a mechanism for allowing internet users to control the tracking of their online activities across websites.

Patient Data means information generated through the Service that relates to a patient of a Dental Practice, including names, contact details, appointment information, voice recordings, transcripts, and any related communications. The Dental Practice is the data controller for Patient Data; DentraxAI acts as a data processor.

PIPEDA refers to the Personal Information Protection and Electronic Documents Act (Canada) and applicable provincial privacy legislation.

Personal Data (or "Personal Information") is any information that relates to an identified or identifiable individual. For the purposes of the CCPA/CPRA, Personal Data means any information that identifies, relates to, describes, or is capable of being associated with, or could reasonably be linked, directly or indirectly, with you. We use "Personal Data" and "Personal Information" interchangeably unless a law uses a specific term.

Service refers to the DentraxAI website, AI dental receptionist, AI voice assistant, dental practice automation tools, integrations, and any related software or features.

Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by DentraxAI to facilitate the Service, to provide the Service on behalf of DentraxAI, to perform services related to the Service, or to assist DentraxAI in analyzing how the Service is used.

UK GDPR refers to the United Kingdom General Data Protection Regulation as retained in UK law, read together with the Data Protection Act 2018.

Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

Website refers to DentraxAI, accessible from https://dentist-ai-website.vercel.app/.

You means the individual accessing or using the Service, or the dental practice, company, or other legal entity on behalf of which such individual is accessing or using the Service.

3

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you. Personally identifiable information may include, but is not limited to:

  • Email address
  • First name and last name
  • Phone number
  • Dental practice name and role/title
  • Address, state, province, ZIP/postal code, city, country
  • Billing information (processed by our payment processor; full card details are not stored by DentraxAI)
  • Voice recordings and call transcripts generated by the AI dental assistant (processed on behalf of the Dental Practice)
  • Account credentials and any information you choose to share when contacting support

Usage Data

Usage Data is collected automatically when using the Service. Usage Data may include information such as your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.

When you access the Service by or through a mobile device, we may collect certain information automatically, including the type of mobile device you use, your mobile device's unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers, and other diagnostic data.

Patient Data Processed on Behalf of Dental Practices

When a Dental Practice uses DentraxAI to manage patient calls, appointment scheduling, or communications, the Service processes Patient Data on behalf of the Dental Practice. The Dental Practice acts as the data controller (or, in the U.S., the HIPAA-regulated entity) and DentraxAI acts as a processor (or business associate, where applicable). DentraxAI processes Patient Data only to provide the Service in accordance with the agreement with the Dental Practice and applicable law.

Tracking Technologies and Cookies

We use Cookies and similar tracking technologies to track activity on our Service and store certain information. Tracking technologies we use include beacons, tags, and scripts to collect and track information and to improve and analyze our Service.

  • Cookies or Browser Cookies. A cookie is a small file placed on your Device. You can instruct your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if you do not accept Cookies, you may not be able to use some parts of our Service.
  • Web Beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit DentraxAI, for example, to count users who have visited those pages or opened an email and for other related website statistics.

Cookies can be "Persistent" or "Session" Cookies. Persistent Cookies remain on your personal computer or mobile device when you go offline, while Session Cookies are deleted as soon as you close your web browser.

Where required by law (including in the UK, EU, and certain Canadian provinces), we use non-essential cookies (such as analytics, advertising, and remarketing cookies) only with your consent. You can withdraw or change your consent at any time using our cookie preferences tool (if available) or through your browser/device settings. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.

We use both Session and Persistent Cookies for the purposes set out below:

Necessary / Essential Cookies

Type: Session Cookies | Administered by: Us

Purpose: These Cookies are essential to provide you with services available through the Website and to enable you to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts.

Cookie Notice Acceptance Cookies

Type: Persistent Cookies | Administered by: Us

Purpose: These Cookies identify if users have accepted the use of cookies on the Website.

Functionality Cookies

Type: Persistent Cookies | Administered by: Us

Purpose: These Cookies allow us to remember choices you make when you use the Website, such as remembering your login details or language preference.

Tracking and Performance Cookies

Type: Persistent Cookies | Administered by: Third Parties

Purpose: These Cookies are used to track information about traffic to the Website and how users use the Website. The information gathered via these Cookies may directly or indirectly identify you as an individual visitor.

Targeting and Advertising Cookies

Type: Persistent Cookies | Administered by: Third Parties

Purpose: These Cookies track your browsing habits to enable us to show advertising that is more likely to be of interest to you.

4

Use of Your Personal Data

DentraxAI may use Personal Data for the following purposes:

  • To provide and maintain our Service, including monitoring usage.
  • To manage your Account and registration as a user of the Service.
  • For the performance of a contract: the development, compliance, and undertaking of any contract you have entered into with us, including your Subscription.
  • To contact you by email, telephone calls, SMS, or other equivalent forms of electronic communication regarding updates, security notices, or informative communications related to the Service.
  • To provide you with news, special offers, and general information about other goods, services, and events that we offer that are similar to those that you have already purchased or inquired about, unless you have opted out.
  • To manage your requests and respond to your inquiries.
  • For business transfers: to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets.
  • For analytics, identifying usage trends, evaluating the effectiveness of our promotional campaigns, and improving the Service and your experience.
  • To train and improve our AI models, using anonymized or aggregated data only, and never using identifiable Patient Data for training without the express agreement of the Dental Practice.

We may share your Personal Data in the following situations:

  • With Service Providers — to monitor and analyze the use of our Service, to support telephony and AI infrastructure, to process payments, and to contact you.
  • For business transfers — in connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business.
  • With Affiliates — who are required to honor this Privacy Policy.
  • With business partners — to offer you certain products, services, or promotions.
  • With other users — if our Service offers public areas, any information shared there may be viewed publicly.
  • With your consent — for any other purpose disclosed at the time of collection.
5

Retention of Your Personal Data

DentraxAI will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.

Where possible, we apply shorter retention periods and/or reduce identifiability by deleting, aggregating, or anonymizing data. The retention periods below are maximum periods ("up to") and we may delete or anonymize data sooner when it is no longer needed.

Account Information

  • User Accounts: duration of your account relationship plus up to 24 months after account closure.

Customer Support Data

  • Support tickets and correspondence: up to 24 months from the date of ticket closure.
  • Chat transcripts: up to 24 months for quality assurance and staff training purposes.

Usage Data

  • Website analytics data (cookies, IP addresses, device identifiers): up to 24 months from collection.
  • Server logs: up to 24 months for security monitoring and troubleshooting.

Marketing Data

  • Advertising identifiers and profiles: up to 24 months from last interaction or until you opt out, whichever comes first.

Financial and Transaction Data

  • Payment information: full card details are not stored on our servers; they are processed by our payment service providers. We retain transaction records (invoices, purchase history, amounts) for up to 10 years to comply with tax laws and financial regulations.
  • Billing and invoice records: up to 10 years to meet accounting and tax compliance requirements.

Patient Data

Patient Data is retained for the period required by the contract with the Dental Practice and by applicable healthcare laws (including HIPAA in the United States, UK GDPR and NHS retention guidance in the United Kingdom, and PIPEDA and applicable provincial health privacy laws in Canada). Upon termination of the Dental Practice's Subscription, DentraxAI will return or securely delete Patient Data in accordance with the applicable data processing agreement.

We may retain Personal Data beyond the periods above where: (i) we are required by law to do so; (ii) data is necessary to establish, exercise, or defend legal claims; (iii) you have asked us to retain specific information; or (iv) data exists in backup systems scheduled for routine deletion.

6

Transfer of Your Personal Data

Your information, including Personal Data, is processed at DentraxAI's operating offices and in any other places where the parties involved in the processing are located. This means that this information may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction.

Where required by applicable law, we will ensure that international transfers of your Personal Data are subject to appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office and the European Commission, the UK International Data Transfer Addendum, and equivalent measures under Canadian privacy law. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.

7

Delete Your Personal Data

You have the right to delete or request that we assist in deleting the Personal Data that we have collected about you.

Our Service may give you the ability to delete certain information about you from within the Service. You may update, amend, or delete your information at any time by signing into your Account, if you have one, and visiting the account settings section.

You may also contact us at Info@DentraxAI.com to request access to, correct, or delete any Personal Data that you have provided. Please note, however, that we may need to retain certain information when we have a legal obligation or lawful basis to do so.

8

Disclosure of Your Personal Data

Business Transactions

If DentraxAI is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.

Law Enforcement

Under certain circumstances, DentraxAI may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency in the United States, Canada, or the United Kingdom).

Other Legal Requirements

DentraxAI may disclose your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of DentraxAI
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users of the Service or the public
  • Protect against legal liability
9

Security of Your Personal Data

The security of your Personal Data is important to us. We implement commercially reasonable administrative, technical, and physical safeguards designed to protect Personal Data, including encryption in transit (TLS), encryption at rest where appropriate, access controls, audit logging, and vendor security reviews. However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. While we strive to use commercially reasonable means to protect your Personal Data, we cannot guarantee its absolute security.

10

Detailed Information on the Processing of Your Personal Data

The Service Providers we use may have access to your Personal Data. These third-party vendors collect, store, use, process, and transfer information about your activity on our Service in accordance with their Privacy Policies.

Analytics

We may use third-party Service Providers to monitor and analyze the use of our Service.

Google Analytics

Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. You can opt out of having your activity made available to Google Analytics by installing the Google Analytics opt-out browser add-on. For more information on the privacy practices of Google, please visit: https://policies.google.com/privacy

Advertising

Google AdSense & DoubleClick Cookie

Google, as a third-party vendor, uses cookies to serve ads on our Service. You may opt out of the use of the DoubleClick Cookie for interest-based advertising by visiting: http://www.google.com/ads/preferences/

Payments

We may provide paid products and/or services within the Service. We use third-party services for payment processing. We will not store or collect your payment card details. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council.

Stripe

Their Privacy Policy can be viewed at https://stripe.com/privacy

11

CCPA/CPRA Privacy Notice (California Privacy Rights)

This section supplements the information contained in our Privacy Policy and applies solely to all visitors, users, and others who reside in the State of California.

Categories of Personal Information Collected

We collect information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or Device. The following is a list of categories of personal information that we may collect from California residents within the last twelve (12) months:

Category A: Identifiers Real name, alias, postal address, unique personal identifier, online identifier, IP address, email address, account name. Collected: Yes.

Category B: Customer Records (Cal. Civ. Code § 1798.80(e)) Name, address, telephone number, financial information (processed by Stripe). Collected: Yes.

Category C: Protected classification characteristics Age, race, color, ancestry, national origin, citizenship, religion. Collected: No.

Category D: Commercial information Records of products or services purchased, obtained, or considered. Collected: Yes.

Category E: Biometric information Fingerprints, faceprints, voiceprints. Collected: Voice recordings may be processed on behalf of Dental Practices; DentraxAI does not use them to extract biometric identifiers.

Category F: Internet or other similar network activity Browsing history, search history, interaction with the Service. Collected: Yes.

Category G: Geolocation data Approximate or precise physical location. Collected: No (only inferred from IP address at country level).

Category H: Sensory data Audio, electronic, visual information. Collected: Voice/audio data processed on behalf of Dental Practices only.

Category I: Professional or employment-related information Current or past job history. Collected: Limited to job title/role at sign-up.

Category J: Non-public education information Education records under FERPA. Collected: No.

Category K: Inferences Profiles reflecting preferences, characteristics, behavior. Collected: Limited inferences for product analytics.

Category L: Sensitive personal information Government IDs, financial details, precise geolocation, race, religion, biometric, health, sexual orientation. Collected: Health-related information may be processed solely on behalf of Dental Practices and is subject to HIPAA, not CCPA, where applicable.

Under CCPA/CPRA, Personal Information does not include publicly available information from government records, deidentified or aggregated consumer information, or information excluded from the CCPA/CPRA's scope, such as health or medical information covered by HIPAA and the California Confidentiality of Medical Information Act (CMIA).

Sources of Personal Information

  • Directly from you (e.g., forms you complete or purchases on our Service).
  • Indirectly from you (e.g., observing your activity on our Service).
  • Automatically from you (e.g., cookies set on your Device).
  • From Service Providers (e.g., analytics, advertising, payment processing).

Use of Personal Information

We may use or disclose personal information we collect for "business purposes" or "commercial purposes" (as defined under the CCPA/CPRA), including operating the Service, providing support, fulfilling your requests, responding to law enforcement requests, internal administration and auditing, and detecting security incidents.

Sale or Sharing of Personal Information

DentraxAI does not "sell" or "share" information as most people would commonly understand these terms — we do not disclose your Personal Information in direct exchange for money. However, the use of certain third-party advertising and analytics technologies may be considered "sharing" or "sale" under the CCPA/CPRA. The categories that may be considered sold or shared include Identifiers (A), Customer Records (B), Commercial Information (D), and Internet/Network Activity (F).

Sale of Personal Information of Minors Under 16

We do not sell the Personal Information of consumers we actually know are less than 16 years of age, unless we receive affirmative authorization from the parent or guardian.

Your Rights under the CCPA/CPRA

California residents have the following rights:

  • Right to notice — be notified of categories of Personal Information collected and the purposes for use.
  • Right to know / access — request disclosure of information about our collection, use, sale, and sharing of personal information.
  • Right to opt out of sale or sharing — direct us not to sell or share your personal information.
  • Right to correct — correct inaccurate personal information.
  • Right to limit use and disclosure of sensitive personal information.
  • Right to delete — request deletion of your Personal Information, subject to legal exceptions.
  • Right not to be discriminated against for exercising your rights.

Exercising Your CCPA/CPRA Rights

To exercise any of your rights under the CCPA/CPRA, you can contact us at Info@DentraxAI.com. We will disclose and deliver the required information free of charge within 45 days of receiving your verifiable request (extendable once by an additional 45 days with prior notice). Disclosures will cover the 12-month period preceding the request.

12

UK GDPR and EU GDPR Rights (United Kingdom and European Economic Area Residents)

Legal Basis for Processing

If you are located in the United Kingdom or the European Economic Area, we rely on the following legal bases under UK GDPR / EU GDPR to process your Personal Data:

  • Performance of a contract — to provide the Service and fulfill our agreement with you.
  • Legitimate interests — to operate and improve the Service, secure our systems, and communicate with you.
  • Consent — for non-essential cookies, marketing communications, and certain other processing, where required.
  • Legal obligation — to comply with applicable law (including tax, accounting, and consumer protection laws).

Your Rights

Subject to applicable law, you have the right to:

  • Access your Personal Data and obtain a copy of it.
  • Rectify inaccurate or incomplete Personal Data.
  • Erase your Personal Data ("right to be forgotten"), subject to legal exceptions.
  • Restrict the processing of your Personal Data.
  • Object to processing based on legitimate interests, including direct marketing.
  • Data portability — receive your Personal Data in a structured, commonly used, machine-readable format.
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
  • Lodge a complaint with a supervisory authority — for UK residents, the UK Information Commissioner's Office (ICO) at https://ico.org.uk. For EU residents, your local Data Protection Authority.

International Data Transfers

Where Personal Data is transferred outside the United Kingdom or European Economic Area, we rely on appropriate safeguards including Standard Contractual Clauses, the UK International Data Transfer Addendum, or adequacy decisions where applicable.

13

Canadian Privacy Rights (PIPEDA)

If you are a resident of Canada, your Personal Information is also protected by the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Quebec's Law 25, Alberta's PIPA, and British Columbia's PIPA.

Your Rights

  • Right to access your Personal Information held by DentraxAI.
  • Right to correct inaccurate Personal Information.
  • Right to withdraw consent for processing, subject to legal or contractual restrictions.
  • Right to file a complaint with the Office of the Privacy Commissioner of Canada (https://www.priv.gc.ca) or your provincial privacy regulator.

Consent

DentraxAI seeks meaningful consent for the collection, use, and disclosure of Personal Information in accordance with PIPEDA. Where Quebec residents are concerned, additional rights apply under Law 25, including the right to data portability and the right to be informed of automated decision-making.

14

HIPAA and Healthcare Privacy (Dental Practice Customers)

DentraxAI's AI dental assistant may process information that is considered Protected Health Information (PHI) under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Where DentraxAI processes PHI on behalf of a covered Dental Practice, DentraxAI acts as a Business Associate and will enter into a Business Associate Agreement (BAA) with the Dental Practice. DentraxAI will use and disclose PHI only as permitted by the BAA and applicable law.

Comparable processor agreements apply for UK and Canadian Dental Practice customers under UK GDPR (Article 28 processor agreements) and PIPEDA/Law 25 (service provider agreements).

15

"Do Not Track" Policy as Required by CalOPPA

Our Service does not respond to Do Not Track signals. However, some third-party websites do keep track of your browsing activities. If you are visiting such websites, you can set your preferences in your web browser to inform websites that you do not want to be tracked.

16

California Shine the Light Law

Under California Civil Code Section 1798 (California's Shine the Light law), California residents with an established business relationship with us can request information once a year about sharing their Personal Data with third parties for the third parties' direct marketing purposes. To make such a request, please contact us at Info@DentraxAI.com.

17

California Privacy Rights for Minor Users (Section 22581)

California Business and Professions Code Section 22581 allows California residents under 18 who are registered users of online sites, services, or applications to request and obtain removal of content or information they have publicly posted. To request removal, please contact us with the email address associated with your Account.

18

Children’s Privacy

The Service is intended for use by adult professionals operating Dental Practices and is not directed to children under 13. DentraxAI does not knowingly collect personal information from children under 13. If you are a parent or guardian and you become aware that your child has provided us with personal information, please contact us at Info@DentraxAI.com and we will take steps to remove that information.

In the United Kingdom and European Union, the age of digital consent may be 13–16 depending on the jurisdiction; in Canada, parental consent rules apply under PIPEDA and Law 25 where applicable. DentraxAI does not knowingly collect data from minors below those thresholds.

20

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this Privacy Policy. For material changes, we will provide reasonable prior notice, such as via email and/or a prominent notice on our Service, before the change takes effect.

You are advised to review this Privacy Policy periodically for any changes. Changes are effective when they are posted on this page.

21

Contact Us

If you have any questions about this Privacy Policy, you can contact us:

  • By email: Info@DentraxAI.com
  • By visiting our website: https://dentist-ai-website.vercel.app/
  • By mail: DentraxAI, [ADDRESS]

Data Protection Inquiries: If you are a resident of the United Kingdom, European Union, or Canada and have a data protection inquiry, please write to Info@DentraxAI.com with the subject line "Data Protection Request".

© 2026 DentraxAI. All rights reserved. AI Dental Assistant • Dental Practice Privacy • Voice AI for Dentists • HIPAA-aware • UK GDPR & PIPEDA compliant.