Privacy Policy
1. Who we are and what this covers
PerceptaDent operates PerceptaDent Passport, a service that lets dental clinics issue a portable “implant passport” — a record of a dental implant and its post-operative radiograph — that the patient can later claim, view, share with other providers, and delete.
This policy covers two groups:
- Clinicians and clinics — the account holders who use the platform to create passports.
- Patients — the individuals whose implant and health information is recorded in a passport.
For clinics in the United States, PerceptaDent acts as a Business Associate under HIPAA and processes Protected Health Information (PHI) on the clinic’s behalf under a Business Associate Agreement (BAA), executed with each clinic directly. The clinic remains the Covered Entity responsible for obtaining patient consent.
2. Information we collect
Clinician / clinic account data: full name, email, a securely hashed password, country, and clinic details (name, city, contact email).
Patient data (treated as PHI for US clinics):
- Identifying details: name, phone, email, date of birth, country, an external reference, and free-text clinical notes entered by the clinic
- Implant records: manufacturer, system/model, dimensions, lot/reference number, and tooth position
- Post-operative radiograph (X-ray) images uploaded by the clinic
Technical data: a single HTTP-only authentication cookie to keep you signed in (no advertising or third-party tracking cookies), and basic server logs used for security and reliability.
3. How we use information
- Provide the service: create, issue, claim, view, share, export, and delete passports, and generate claim codes and wallet cards
- Authenticate clinicians and secure accounts
- Communicate about your account and service-related matters (e.g., deletion confirmations)
- Improve our AI-assisted implant identification — using only implant records and radiographs (no patient name, email, or other identifiers)
- Maintain security, prevent abuse, and comply with legal obligations
We do not sell personal information, and we do not use patient data for advertising.
4. De-identified data and the private beta
As permitted by the BAA and by 45 CFR § 164.514, we may de-identify information in the platform so that it no longer identifies, and cannot reasonably be used to identify, any individual. During the private beta, use of de-identified implant records and radiographs — including to operate, develop, and improve our products and services, such as our AI-assisted implant identification (see §3 above) — is authorized under a Business Associate Agreement (BAA) executed directly with each participating clinic, rather than through in-app per-patient consent toggles. Free-text clinical notes are not used for this purpose. We maintain de-identified data in de-identified form, do not attempt to re-identify it, maintain technical safeguards and business processes preventing re-identification, and require anyone to whom we provide it to do the same. The clinic remains responsible for obtaining any patient consent required under applicable law. Clinicians separately accept these Terms and this Privacy Policy before using the platform, and are re-prompted when a new version is published.
5. How we share information
- Service providers (subprocessors) acting on our instructions — including a cloud storage provider (file/image storage) and an email-delivery provider (patient email) — each covered under our Microsoft Business Associate Agreement. See our subprocessor list for the specific providers currently in use.
- The patient and authorized providers, when a patient claims or shares a passport using a claim code.
- Authorities or other parties where required by law, or to protect rights, safety, and the integrity of the service.
We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.
6. HIPAA (U.S. clinics)
When serving Covered Entities in the United States, PerceptaDent:
- Acts as a Business Associate and processes PHI only as permitted by the BAA and this policy
- Applies administrative, physical, and technical safeguards to PHI
- Limits uses and disclosures of PHI to those necessary to provide the service
- Will notify the relevant Covered Entity of any breach of unsecured PHI without unreasonable delay, as required by the HIPAA Breach Notification Rule
Patients should direct requests about their PHI (access, amendment, accounting of disclosures) to their issuing clinic, which can coordinate with us.
7. California privacy rights (CCPA/CPRA)
California residents have the right to know, access, correct, and delete their personal information, and to opt out of its sale or sharing. We do not sell or share personal information, so no opt-out is required. We will not discriminate against you for exercising these rights, and you may use an authorized agent.
To exercise these rights, contact support@perceptadent.com. Medical information governed by HIPAA or California’s Confidentiality of Medical Information Act (CMIA) may be exempt from certain CCPA obligations and is handled under the HIPAA/CMIA frameworks above.
Categories collected: identifiers (name, email), professional information (license number), medical/health information (implant records, radiographs, clinical notes), and internet/network activity (authentication cookie, server logs).
8. Data retention and deletion
- Passports and associated files are retained for the life of the record unless deletion is requested. A patient may request deletion at any time; we permanently remove the passport and its files within 30 days and confirm by email.
- Account data is retained while the account is active and for a reasonable period afterward as required for legal, security, and audit purposes.
9. Security
We protect information using encryption in transit, hashed passwords, scoped access controls, and de-identification of any data used for model improvement. No system is perfectly secure, but we work to protect information consistent with HIPAA safeguards and industry practice.
10. International data transfers
PerceptaDent’s infrastructure is operated in the cloud and information may be processed in the United States. Where information is transferred across borders, we take steps to ensure it remains protected consistent with this policy.
11. Children's privacy
The platform is intended for use by dental professionals, not directly by children. Passports may describe care provided to minors; in those cases the issuing clinic is responsible for obtaining any required parental or guardian consent before creating a passport.
12. Your choices and how to exercise rights
To access, correct, or delete information, or to ask a privacy question, contact support@perceptadent.com. Patients can also request deletion directly from their passport view. We respond within the timeframes required by applicable law.
13. Changes to this policy
We may update this policy as our practices evolve. Material changes are published with a new version, and clinicians are prompted to review and accept the updated terms before continuing to use the platform.
14. Contact
PerceptaDent — Privacy
Email: support@perceptadent.com