Draft template — not legal advice. This document must be reviewed, customized, and finalized by qualified legal counsel before it is published or relied upon.

Privacy Policy

Last updated: June 9, 2026

DentalX (the “Service”) is operated by VstreamX (“we”, “us”). This Privacy Policy explains what information we collect, how we use and protect it, and your choices. It applies to the DentalX websites and applications. [Insert the legal entity name, address, and jurisdiction.]

1. Who this applies to

Our direct customers are dental clinics and their staff (“Clinics”). Clinics enter information about their patients into the Service. That patient information is Protected Health Information (PHI), and for it we act as a Business Associateof the Clinic — we process it only on the Clinic’s behalf and under a Business Associate Agreement (BAA). Patients should direct privacy requests to their Clinic.

2. Information we collect

  • Account & contact data — name, email, phone, role, and clinic details.
  • Clinic configuration — settings, staff, plan and entitlements.
  • Billing data — handled by our payment processor (Stripe); we do not store full card numbers.
  • Customer Data, including PHI — patient records, appointments, treatments, clinical notes, images, and documents that Clinics enter.
  • Usage & device data — log data, IP address, browser/device info, and error reports, used to operate and secure the Service.

3. How we use information

  • To provide, maintain, and secure the Service and support our customers.
  • To process subscriptions and payments.
  • To detect, prevent, and respond to security incidents and abuse.
  • To improve the Service using aggregated or de-identified data.
  • To comply with legal obligations.

We do not sell personal information, and we do not use PHI for advertising.

4. PHI and HIPAA

We process PHI only as permitted by the BAA and the Clinic’s instructions. PHI is encrypted in transit and at rest. AI-assisted features transmit clinical content to AI providers only where a BAA with that provider is in place; until then those features are disabled.

5. Service providers (sub-processors)

We share information with vendors that help us run the Service, under appropriate contracts:

  • Google Cloud / Firebase — hosting, database, storage, and authentication.
  • AI providers (e.g., OpenAI, Google) — only for AI features, only under a BAA.
  • Stripe — payment processing.
  • Email / messaging providers — transactional notifications and reminders.

6. Security

We use encryption, access controls, multi-factor authentication for staff, audit logging, and least- privilege practices. No method of transmission or storage is 100% secure, but we work to protect your information and to meet our obligations under applicable law and the BAA.

7. Data retention and deletion

We retain Customer Data for as long as the account is active and as required by law or the Clinic’s retention settings. Clinics can export their data at any time. On cancellation, data is handled under our offboarding process and the BAA (return or destruction of PHI). [Confirm retention periods with counsel.]

8. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, or port personal information. Patients exercise these rights through their Clinic; Clinic staff may contact us using the details below.

9. Cookies

We use strictly necessary cookies/local storage for authentication and core functionality. [Add a cookie notice/consent if required in your markets.]

10. International transfers & children

Data may be processed in regions where we or our providers operate. [Add transfer mechanisms if you serve the EU/UK.] The Service is not directed to children, and patient data is entered by Clinics in the course of providing care.

11. Changes

We may update this Policy; material changes will be posted here with a new “Last updated” date.

12. Contact

Questions about this Policy: [privacy@your-domain] · [mailing address].