Privacy Policy
DentalRobot Privacy Policy
EffectiveDate: June 21, 2026. Version: 1.01
DentalRobot,Inc. (“DentalRobot,” “we,” “us,” or “our”) is committed to protecting the privacy, confidentiality, security, and integrity of the information entrusted to us. This Privacy Policy explains, in general terms, how DentalRobot handles information when providing our AI-powered healthcare automation services to dental practices, dental service organizations (DSOs), healthcare providers, and other authorized customers (“Customers”), and how we handle information collected through our websites. In providing its services, DentalRobot acts primarily as a service provider, data processor, and HIPAA Business Associate on behalf of its Customers, and processes information in accordance with Customer instructions and applicable law. The specific, binding terms governing that processing are set out in theagreements between DentalRobot and each Customer, including the Master Service Agreement, Data Processing Agreement, and HIPAA Business Associate Agreement (together, the “Customer Agreements”). Where this Policy and a CustomerAgreement conflict, the Customer Agreement controls.
This Policy applies to information DentalRobot processes in connection with its services and its websites. DentalRobot’s services are directed to Customers located in the United States.
DentalRobot provides AI-powered healthcare workflow automation, including insurance verification, eligibility and benefits verification, Voice AI and payer communications, claims status, and revenue cycle automation, group plan management, prior authorization, document understanding and OCR, practice management system (PMS) integrations, and custom AI agents and workflow automation.
Customer Ownership of Data
All Customer Data, including patient data and Protected Health Information (“PHI”),remains the sole property of the Customer. DentalRobot: Does not acquire ownership rights over Customer Data; Processes Customer Data solely to provide the contracted services, under Customer instructions and applicable law; DentalRobot does not sell Customer Data and does not share Customer Data for cross-context behavioral advertising; Does not “share” Customer Data; Does not use, retain, or disclose Customer Data for any purpose other than performing the services, except as permitted or required by law.
Roles of the Parties
The Customer is the covered entity, controller, and/or business. DentalRobot is the Business Associate, data processor, and/or service provider acting on the Customer’s behalf. For the website and marketing data described in Section 13, DentalRobot acts as an independent controller or business.
Protected Health Information (HIPAA)
DentalRobot processes PHI as a HIPAA Business Associate and enters into a Business Associate Agreement with each Customer for which it processes PHI before processing begins. We implement the administrative, physical, and technical safeguards required by the HIPAA Security Rule, apply the minimum necessary standard, and use and disclose PHI only as permitted by the applicable BAA and the HIPAA Privacy Rule. Detailed HIPAA obligations are set out in the DPA/BAA.
Information We Process
Depending on the services used, DentalRobot may process: Patient information, Provider information: NPI numbers; tax IDs; provider credentials; office locations. Operational data: workflow instructions; portal credentials; configuration settings; PMSintegration data. We do not knowingly collect personal information directly from children.
Data Minimization, Retention, and Deletion
DentalRobot is designed around data minimization and limited retention. Customer Data and PHI are generally processed transiently during workflow execution and used onlyto perform the authorized service. Processing artifacts are deleted followingcompletion of processing in accordance with the retention periods set out inthe applicable DPA/BAA. DentalRobot does not permanently retain PHI for its own purposes. Upon termination of services, and subject to legal and contractual obligations, DentalRobot will return or securely delete Customer Data and PHI at the Customer’s election, as specified in the DPA/BAA. Customers may request exportor deletion at any time, subject to legal or contractual obligations.
Artificial Intelligence and Automated Processing
DentalRobot uses AI technologies, including AI agents, machine learning, natural language processing, OCR, Voice AI, and document understanding, solely to perform Customer-authorized workflows. DentalRobot does not use AI to make independent clinical decisions, and does not use automated processing to make decisions producing legal or similarly significant effects about an individual without Customer involvement. The Customer retains decision-making authority.
AI Training Restrictions
DentalRobot does not use Customer Data or PHI to train, fine-tune, or improve any artificial intelligence model, whether publicly available, third-party, orinternal, except as expressly authorized in writing by the Customer. We do not use Customer Data to develop, train, or improve products or services offered to other customers or the public. Where internal testing or quality assurance requires it, we use synthetic or de-identified data and do not re-identify it. Full details are in the DPA/BAA.
Voice AI and Communications
DentalRobot may use Voice AI to communicate with insurance carriers and other authorized parties on a Customer’s behalf. Calls are not recorded as a default practice; temporary transcripts may be generated solely to perform the workflow and are not retained after processing completes. Human review may occur solely for quality assurance and troubleshooting. We conduct these communications in a manner designed to comply with applicable call-monitoring, recording, andconsent laws.
Security, Human Access, and Subprocessors
DentalRobot maintains a documented information security program with administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of Customer Data, including encryption in transit and at rest, role-based and least-privilege access, multi-factor authentication, logging and monitoring, vulnerability management, and incident response. Our program is designed to meet HIPAA requirements. Authorized personnel access Customer Data only as necessary to support, troubleshoot, maintain, and quality-assure the services, under confidentiality obligations and least-privilege controls. DentalRobot may engage trusted subprocessors(such as cloud hosting and infrastructure providers) under written agreements no less protective than this Policy and the DPA/BAA, including a BAA with any subprocessor that handles PHI. A current list of subprocessors is available to Customers on request or as part of their MLA. DentalRobot may use authorized personnel located in the United States, Mexico, and Nicaragua. In all cases,HIPAA obligations, confidentiality requirements, and equivalent safeguards continue to apply.
Website, Cookies, and Marketing Data
DentalRobot's public websites may use cookies, analytics technologies, pixels, session management technologies, and customer relationship management ("CRM") tools to improve website functionality, understand website usage, enhance user experience, and communicate with prospective and existing customers. These technologies may collect information such as: Browser, type and version; Device type and operating system; IP address and approximate geographic location; Pages viewed and links clicked; Referring websites and search terms; Session information and website interactions; Marketing preferences and form submissions. DentalRobot may use third-party analytics and marketing tools, including customer relationship management platforms, website analytics providers, and similar technologies, to help operate and improve its websites and services. These providers process information pursuant to contractual confidentiality and data protection obligations. Information collected through DentalRobot's public websites, including cookies, analytics technologies, contact forms, and marketing communications, is generally not Protected Health Information (PHI). DentalRobot processes such information as an independent controller or business in accordance with this Privacy Policy and applicable law. Users may manage cookie preferences through their browser settings. Disabling certain cookies may affect the availability or functionality of portions of the website. DentalRobot does not sell personal information, Customer Data, or Protected Health Information and does not share Customer Data for cross-context behavioral advertising.
Your Privacy Rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict or object to processing, obtain a portable copy of, and opt out ofcertain processing of their personal information, with additional protections for sensitive information such as health data. BecauseDentalRobot processes most personal information on behalf of Customers, individuals should ordinarily direct rights requests to the relevant Customer(the covered entity or controller); DentalRobot will assist the Customer as required by the DPA/BAA and law. For website data that DentalRobot controls,you may contact us using Section 16. We respond to verifiable requests within the timeframes required by law and do not discriminate against individuals for exercising their rights.
Complaints
You may contact DentalRobot or the relevant Customer with privacy concerns. You also have the right to file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, or with your applicable data protection authority. We do not retaliate against anyone for filing a complaint
Changes and Contact
We may update this Policy periodically; updated versions will be posted with a revised “Last Updated” date, and material changes will be communicated asrequired by law or the Customer Agreements. DentalRobot,Inc. Privacy Inquiries:
info@dentalrobot.ai. 8400 NW 33rd St Suite 310, Doral, FL 33122. This Privacy Policy is provided for transparency regarding DentalRobot's privacy practices. It is complemented by, and subordinate to, the applicable CustomerAgreements, including the Master License Agreement, applicable Order Forms, andthe DentalRobot Data Processing and Business Associate Addendum (DPA/BAA). In the event of any inconsistency, the Customer Agreements shall control.