Как Dental Education, Inc. d/b/a Intake.Dental собирает, использует и защищает информацию.
This Privacy Policy explains how Dental Education, Inc. d/b/a Intake.Dental ("we", "our", or "the Service") collects, uses, and protects information. By using the Service you agree to the terms below.
We want to be explicit about what we do not do with your data:
Practice name, address, and contact information, along with billing details, subdomain preferences, and staff user accounts.
Patient demographics, contact information, and medical/dental history submitted through intake forms, plus insurance information, electronic signatures, and appointment data.
Browser type and version, and IP addresses for service improvement and security monitoring.
All patient data is encrypted using AES-256-GCM with our proprietary dual-layer Glyph encryption (included on every account) and stored on our HIPAA-compliant infrastructure.
Data resides on Amazon Web Services (AWS) for HIPAA-compliant storage and computing, plus Supabase for database services. Both providers operate under their own executed BAAs with Intake.Dental.
Services include AWS, Supabase, Stripe, our PMS integration partner, insurance verification APIs, Daily.co (video), and DeepL (form translation). Each is bound by either a BAA or an equivalent data processing agreement where required.
We do not store credit card information. Stripe's privacy policy governs their handling of payment information.
Practices on the Service may send text messages to their patients through the platform for appointment confirmations, reminders, and schedule-change notifications; notifications when an earlier appointment opening becomes available for patients on the practice’s waitlist; links to complete intake and registration forms; one-time verification codes; and replies to conversations a patient initiates. Patients provide their mobile number and consent to receive these messages directly to their dental practice — when booking an appointment, on the practice’s intake or registration forms, or in person at the office.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are never sold or shared with any third party.
Message frequency varies based on your appointments and requests. Message and data rates may apply. Patients can opt out of text messages at any time by replying STOP to any message, and can reply HELP for assistance. Opt-outs are honored immediately across the platform.
Dental Education, Inc. executes a Business Associate Agreement (BAA) with every registered practice at no additional cost.
Implementations include AES-256-GCM encryption, TLS 1.3, HIPAA-compliant AWS infrastructure, protection against common web attacks, and isolated per-practice data environments.
Practices can access and export all their patient data at any time and can request deletion in compliance with applicable retention requirements.
We will notify affected practices within 72 hours of the discovery of a security incident affecting PHI.
Minor patient information is handled in accordance with HIPAA, applicable state laws, and the practice's own policies.
Patient data is stored on servers located in the United States.
The "Last Updated" date will reflect any changes to this policy. Continued use of the Services after notification constitutes acceptance of the updated terms.
Questions about this policy? Email support@intake.dental.