Privacy Policy
What we collect, why, who sees it, how long we keep it, and what you can ask us to do about it. Written for the United States, where every practice we serve operates.
Last updated 09/20/2026
1.Two kinds of information, and why the difference matters
Almost everything confusing about privacy in a product like this comes from treating all of it as one pile. It is two.
The first is what callers tell your receptionist: a name, a date of birth, an insurance carrier, a reason for calling, and the recording and transcript of the conversation itself. That is protected health information. It belongs to your practice, not to us. We hold it as your business associate under HIPAA, we act only on your instructions, and the Business Associate Agreement we sign with you — not this page — is the document that governs it.
The second is ordinary business information: the name and work email of the person who signs up, who on your team logs in and when, what you configure, what you are billed, and what a visitor does on our marketing site. That is not protected health information and HIPAA does not reach it. State privacy law does, and this page is mostly about that half.
We keep the two apart in the product as well as on paper. Patient-identifying data and vendor credentials sit under separate encryption keys, and a practice's records are scoped to that practice at the database layer rather than by a filter somebody could forget to write.
2.Who we are in each of these
Under HIPAA, your practice is the covered entity and we are your business associate. Patients exercise their HIPAA rights — access, amendment, an accounting of disclosures — through you, because you hold the designated record set and we do not. If a patient contacts us directly, we tell them that and point them to you.
Under state privacy laws, you are the controller (some statutes say business) and we are the processor (or service provider). We process what you have configured us to process, for you, and for nothing else of our own.
For the business information described above, where you are a Dentelo customer rather than a patient, we are the controller of your own account and billing data and answer for it directly.
3.What we collect
From the person who signs up and the colleagues they invite: name, work email, phone number, role, password (stored only as a hash), the timezone your browser reports, and a dated record that you accepted these documents, including the version, the time, your IP address and your browser's user agent. That last one exists so that if the agreement is ever disputed we can say precisely what was shown and when, rather than asserting it.
From callers to your practice line: the calling number, the number dialled, call audio, a transcript, and whatever the caller volunteers — name, date of birth, insurance carrier, reason for the visit. Protected health information, handled under the BAA.
From your practice management system, where you connect one: appointment slots, providers, operatories and the patient records needed to match a caller to a chart and write an appointment back. We read what the integration you enabled permits and no more.
Operational data: timing, duration, outcome, latency and error diagnostics. We use this to keep the service working and to show you what happened on each call.
From our marketing site: standard server logs and first-party analytics. We do not run third-party advertising trackers on it, so there is no cross-site profile of you being assembled here.
4.Calls are recorded, and every caller is told so before they are
Two things are said at the start of every call, before any audio reaches the model: that the caller is speaking with an automated assistant, and that the call is recorded. They are spoken by the telephone network itself, as fixed text, on every call, in every state.
That is deliberate and it is not configurable. Roughly a dozen states require every party to a call to consent to its recording, and several more are unsettled enough that careful operators treat them the same way. Rather than keep a map of which caller is in which state and get it wrong once, the notice plays for everyone. It is also why the disclosure is not an instruction in the model's prompt: a model can be talked out of saying something, and a legal obligation is not a matter of persuasion.
A caller who objects to being recorded should be transferred to a person. Your escalation settings control how that happens.
5.What we do with it
Answer your calls, look up availability, book appointments into your practice management system, take messages, send the SMS you have configured, and show you a record of all of it in your dashboard.
Keep the service running and secure: diagnosing faults, preventing fraud and abuse, and meeting our own legal obligations.
Improve the service within the bounds of the BAA — which means aggregate and de-identified operational measurements, not listening to your patients' calls for product ideas.
6.What we do not do
We do not sell personal information, and we do not share it for cross-context behavioural advertising. Under the California statutes those two words have specific meanings and this sentence is meant in those meanings, not loosely: no disclosure of personal information to a third party for monetary or other valuable consideration, and no disclosure for targeted advertising. There is therefore no “Do Not Sell or Share My Personal Information” mechanism to offer you, because there is nothing to opt out of.
We do not use protected health information to train general-purpose models, ours or anyone else's. All model traffic runs through an enterprise endpoint covered by a Business Associate Agreement; the consumer API is not used anywhere in the product and a test fails the build if it appears.
We do not compute or store voiceprints. Nothing in the system derives a biometric identifier from a caller's voice, which is a design constraint rather than a setting — Illinois, Texas and Washington each regulate that separately and Illinois attaches a private right of action to it.
We do not mix practices. One practice's data is never used to answer another practice's calls.
7.Who else sees it
Our subprocessors, which are listed on our Trust page, and each of which has signed a Business Associate Agreement with us where it could receive protected health information. We give 30 days' notice before adding one, which gives you time to object.
Our own staff, only where they need it to run the service or to answer a support request you have raised, and every such access is written to your audit log with who, what, when and why.
Where we are legally compelled. We will tell you before we disclose anything unless we are prohibited from telling you, and we will narrow the request where there are grounds to.
All processing takes place in the United States.
8.How long we keep it
Call recordings and transcripts are kept for the window your practice chooses, from 30 days to seven years. The default is 12 months. Audio is the highest-risk thing we hold and the least often needed, so it can be set to expire sooner than the transcript.
When a window closes, the purge runs automatically and writes its own deletion to your audit log — the deletion is itself an audited event, so the record of what was removed survives the removal.
Account, billing and acceptance records outlive the subscription, because they are what we would need to answer a tax authority or a dispute about what was agreed.
You can ask for earlier deletion at any time.
9.How it is protected
Encryption in transit and at rest; patient-identifying data and vendor credentials under separate keyrings, each rotatable without downtime; role-based access inside your practice, so a read-only team member cannot reach what an owner can.
Vendor credentials — your practice management system, your carrier — are write-only through our API. Once saved they cannot be read back out, by you or by us, which means an account compromise does not hand over the keys to your PMS.
The audit log is append-only. It has no update path and no per-row delete; only the retention job removes entries, and it audits its own removals.
10.Your rights, and which law gives them to you
If you are a patient of a practice we serve, your rights in your health information come from HIPAA and you exercise them with the practice. Ask them; they will ask us, and we will answer them promptly.
If you are a resident of a state with a comprehensive privacy law — California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Rhode Island, Indiana, Kentucky and a growing list behind them — you generally have the right to know what we hold about you, to get a copy, to correct it, to delete it, and not to be discriminated against for asking.
How those laws interact with HIPAA is not uniform, and the difference is worth stating plainly. California carves out the protected health information itself but still covers everything else a HIPAA-regulated business holds, so your account and website data are in scope there. Virginia, Texas and several others exempt the regulated entity as a whole. We do not use the broader exemption as a reason to refuse a request we could honour: if you ask us about data we hold that is not protected health information, we will answer.
To exercise any of this, email privacy@dentelo.ai from the address you want us to look up, or write to us at the postal address below. We will verify that the request is really yours before acting on it — for a deletion request that verification is the only thing standing between your data and somebody impersonating you. We respond within 45 days and will tell you if we need the extension the statutes allow. An authorised agent may act for you with written permission.
If we refuse, we will say why, and you may appeal by replying to our decision. We answer appeals within 45 days and, where the statute requires it, we will give you the contact details for your state Attorney General if you remain unsatisfied.
11.Text messages
Messages we send on your behalf go out under your practice's sender registration and only to numbers that have consented to receive them. Every outbound path in the product runs through a single consent check; there is deliberately no second way to send that could skip it.
STOP stops them and HELP returns your practice's contact details, on every campaign, because carriers require it and because a reminder somebody cannot stop is a complaint waiting to happen.
Message and data rates may apply. Consent to receive messages is never a condition of treatment.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. The categories above that name who we share information with exclude text messaging opt-in data and consent.
The full terms for text messages — what is sent, how often, and how to stop — are in our SMS Terms at /legal/sms-terms.
12.Children
Our website and dashboard are for dental practices and are not directed at children, and we do not knowingly collect personal information from a child through them.
Practices treat minors, so calls about a child are ordinary and expected. That information is protected health information belonging to the practice, handled under the BAA and under the practice's own policies on parental access.
13.If something goes wrong
We will tell you about any breach of unsecured protected health information without unreasonable delay and in no case later than 30 days after we discover it, with what we know at the time: who is affected, what was involved, and what we are doing. The notice to affected individuals is the practice's to make as the covered entity, and we will give you what you need to make it.
Where state breach-notification law applies to information that is not protected health information, we comply with it in every state where affected people live.
14.Changes, and how to reach us
When we change this page we change the date at the top. For a change that materially affects your rights we will email the account owner rather than rely on you noticing, and where the law requires fresh consent we will ask for it rather than assume it.
Privacy questions, requests and appeals: privacy@dentelo.ai. Security reports: security@dentelo.ai. Anything else: support@dentelo.ai.