In this document
This Cookie Policy explains how CompliDent, LLC, doing business as CompliDent ("CompliDent," "we," "us," or "our"), uses cookies and similar technologies when you visit our website, access or use our software platform, or otherwise interact with our online Services.
This Cookie Policy supplements our Privacy Policy and should be read together with the Privacy Policy, Terms of Service, Acceptable Use Policy, Data Processing Addendum, and any other agreement applicable to your use of the Services.
No PHI or Prohibited Health Data. The Services are not designed or offered to receive, maintain, store, or process Protected Health Information ("PHI") or other Prohibited Health Data. Cookies and similar technologies are not intended to collect such information, and customers must not use the Services in a manner that causes such information to be transmitted through URLs, query strings, integrations, support requests, or other technical fields.
1. What Are Cookies and Similar Technologies?
Cookies are small data files or identifiers stored on or associated with a browser or device. They can help a website recognize a browser or device, maintain a session, remember preferences, support security, and understand how online services are used.
We may also use technologies that perform similar functions, including:
- Local storage and session storage. Browser-based storage used to maintain session state, preferences, or application functionality.
- Pixels or web beacons. Small code elements that may record whether a page or communication was viewed or an action occurred.
- Software development kits (SDKs). Code libraries used in applications to support functionality, diagnostics, security, or analytics.
- Device or session identifiers. Identifiers used to recognize a browser, device, application session, or authenticated user session.
- Authentication tokens. Technical credentials or tokens used to maintain secure account sessions and authorized access.
- Server logs and similar records. Technical records generated by servers, infrastructure, security tools, or applications when the Services are accessed or used.
2. Why We Use These Technologies
We may use cookies and similar technologies to:
- authenticate users and maintain secure sessions;
- prevent fraud, abuse, unauthorized access, and other security threats;
- operate core website and application functionality;
- remember settings, preferences, and choices;
- route traffic, balance loads, maintain availability, and support technical performance;
- diagnose errors, crashes, failed requests, and other technical issues;
- understand feature usage and general engagement with the Services;
- measure and improve performance, usability, and functionality; and
- comply with legal, security, and recordkeeping obligations where applicable.
We do not use Customer Data submitted for compliance workflows to build advertising profiles, and we do not use cookies or similar technologies to sell Personal Information, share Personal Information for cross-context behavioral advertising, or conduct targeted advertising as those terms are defined by applicable comprehensive state privacy laws.
3. Categories of Cookies and Similar Technologies
| Category | Purpose | Who May Set It | Typical Duration | Choice / Consent |
|---|---|---|---|---|
| Strictly Necessary | Authentication, security, session management, fraud prevention, load balancing, account access, and core functionality. | CompliDent and service providers supporting hosting, authentication, infrastructure, security, or essential operations. | Session-based or limited persistent periods reasonably necessary for security and core operation. Some authentication or security identifiers may persist beyond a single session. | Generally required for the Services to function and not disabled through a non-essential-cookie preference control. |
| Functional | Remembering user choices, settings, preferences, and requested functionality. | CompliDent and service providers supporting requested functionality. | Session-based or persistent until the relevant preference expires, is reset, or is no longer needed. | Where required by applicable law, used only after required consent. Disabling may reduce functionality. |
| Analytics / Performance | Understanding usage, diagnosing performance, measuring feature engagement, improving usability, and identifying technical issues. | CompliDent and analytics, monitoring, or infrastructure providers acting for operational or analytics purposes. | Provider- and configuration-specific. Where applicable, the live consent or preference interface will identify available controls and may provide more specific duration information. | Where applicable law requires prior consent, these technologies are not used until consent is obtained. You may later withdraw consent through available controls. |
CompliDent does not currently maintain a separate advertising-cookie category because, as stated in the Privacy Policy, we do not currently sell Personal Information, share Personal Information for cross-context behavioral advertising, or process Personal Information for targeted advertising. If those practices change, we will update our notices and provide any consent or opt-out mechanisms required by law before using technologies for those purposes.
4. Information These Technologies May Collect
Depending on the technology and how you use the Services, technical information may include:
- IP address and general location inferred from IP address;
- browser type, browser version, device type, and operating system;
- device, session, cookie, or similar identifiers;
- authentication status and session information;
- pages, screens, or features accessed and timestamps associated with use;
- referring or previous page information where provided by the browser;
- preferences and settings stored in the browser or application;
- error messages, crash information, diagnostic data, and performance measurements; and
- general interaction events used to understand and improve the Services.
We do not intentionally configure analytics or similar technologies to collect the contents of Customer Data fields, uploaded compliance documents, or Prohibited Health Data. Customers remain responsible for ensuring that they do not place Prohibited Health Data in URLs, query strings, filenames, integration parameters, support links, or other fields likely to be included in technical logs or telemetry.
5. PHI and Other Prohibited Health Data
PHI and other Prohibited Health Data are prohibited throughout the Services under the Terms of Service and Acceptable Use Policy. This prohibition also applies to information that could be exposed through cookies, technical logs, referrer information, URLs, query parameters, or similar technologies.
Customers and Authorized Users must not:
- place patient names, medical-record numbers, diagnoses, treatment details, dental information, insurance information, or other Prohibited Health Data in URLs or query strings;
- configure integrations or links so that Prohibited Health Data is passed to CompliDent through technical parameters or tracking events;
- send Prohibited Health Data in support URLs, screenshots, filenames, or other diagnostic materials; or
- attempt to use browser storage, cookies, local storage, or similar mechanisms to store Prohibited Health Data within the Services.
If CompliDent becomes aware that Prohibited Health Data was submitted or exposed through the Services, CompliDent will address it in accordance with the Terms of Service, Acceptable Use Policy, Privacy Policy, and applicable law, including reasonable steps to restrict further access or processing and securely return or destroy the information as appropriate.
6. Third-Party Service Providers
We may use third-party service providers to support hosting, infrastructure, authentication, payment processing, communications, customer support, analytics, monitoring, security, fraud prevention, and related operational functions. Some of these providers may set or access cookies or similar technologies when providing services to CompliDent.
Where a provider processes Personal Information on our behalf, we require contractual protections appropriate to the provider's role and applicable law. Our current service providers and subprocessors may be identified in our Subprocessor List or other service documentation.
Independent third-party websites or services linked from CompliDent may use their own cookies or tracking technologies under their own privacy notices. CompliDent does not control the cookies or privacy practices of independent third parties.
7. Your Cookie Choices
Depending on your location and the technologies in use, you may control cookies and similar technologies in several ways:
- Cookie or preference controls. Where we provide a cookie banner, consent manager, or preference center, you may use it to accept, reject, or change available non-essential-cookie choices.
- Browser settings. Most browsers allow you to delete stored cookies, block cookies, restrict third-party cookies, or receive notices when cookies are set.
- Device or application settings. Mobile operating systems and applications may provide privacy, tracking, or identifier controls.
- Withdrawal of consent. Where processing is based on consent, you may withdraw that consent through available controls without affecting processing that occurred lawfully before withdrawal.
Blocking or deleting strictly necessary cookies may prevent you from signing in, maintaining a secure session, saving settings, or using important portions of the Services.
8. Do Not Track and Cross-Site Tracking
Some browsers provide a "Do Not Track" ("DNT") signal. Because there is no uniform industry standard for interpreting DNT signals, the CompliDent website does not currently respond to DNT signals.
CompliDent does not currently sell Personal Information or share it for cross-context behavioral advertising, and we do not authorize third parties to collect Personal Information through the Services over time and across unaffiliated websites for their own cross-site behavioral advertising.
Third-party service providers may collect device or usage information through the Services to provide analytics, security, monitoring, infrastructure, or other operational services to CompliDent, subject to contractual restrictions and applicable law.
9. Global Privacy Control and Other Opt-Out Preference Signals
Where applicable law requires recognition of an opt-out preference signal, including Global Privacy Control ("GPC"), CompliDent will recognize the signal as required by law.
Because CompliDent does not currently sell Personal Information or share it for cross-context behavioral advertising, there is presently no sale or cross-context behavioral advertising activity for a GPC signal to opt out of. If our practices change, we will update this Cookie Policy and the Privacy Policy and implement legally required opt-out mechanisms before engaging in such processing.
10. Consent and International Users
Where applicable law requires consent before placing or accessing non-essential cookies or similar technologies, CompliDent will request the required consent before using those technologies.
Where consent is the legal basis for analytics or functional technologies, you may withdraw consent at any time through available controls. Strictly necessary technologies may be used without consent where permitted by applicable law because they are required to provide, secure, or administer requested Services.
11. Retention
Cookie and similar-technology retention depends on the technology, its purpose, and how it is configured. Session technologies generally expire when the browser session ends. Persistent technologies remain until their configured expiration, until they are deleted or reset, or until they are no longer needed.
Where a cookie or consent-management interface identifies a specific cookie or similar technology, the duration shown in that interface controls for that implementation. Server logs, security records, and analytics records derived from online activity may be retained separately from the cookie itself in accordance with the retention criteria described in the Privacy Policy.
We seek to retain technical information only for periods reasonably necessary for operations, analytics, security, troubleshooting, legal obligations, and related legitimate purposes, after which it may be deleted, aggregated, or de-identified as appropriate.
12. Children
The Services are designed for business use by adults and are not directed to children. We do not knowingly use cookies or similar technologies to collect Personal Information directly from children under 13 for behavioral advertising or other child-directed purposes. Additional information regarding children's privacy is provided in the Privacy Policy.
13. Relationship to the Privacy Policy
The Privacy Policy provides additional information about the categories of Personal Information CompliDent collects, the purposes for which it is used, categories of recipients, retention, privacy rights, security, and international processing.
If this Cookie Policy and the Privacy Policy appear inconsistent regarding CompliDent's privacy practices, the Privacy Policy controls. Nothing in this Cookie Policy authorizes conduct prohibited by the Terms of Service, Acceptable Use Policy, or Data Processing Addendum, including the submission or processing of Prohibited Health Data.
14. Changes to This Cookie Policy
We may update this Cookie Policy from time to time to reflect changes in the Services, technologies we use, legal requirements, or our privacy practices. We will post the updated version and revise the Last Updated date. Where required by law, we will provide additional notice or obtain consent before materially changing how non-essential technologies are used.
15. Contact Us
If you have questions about this Cookie Policy or our use of cookies and similar technologies, contact:
CompliDent, LLC
Attn: Privacy
Email: getcomplident@gmail.com
Website: https://www.getcomplident.com
If you believe PHI or other Prohibited Health Data was submitted or exposed through the Services, email getcomplident@gmail.com with the subject line "Prohibited Health Data Removal Request." Do not include PHI, patient-identifying information, or other Prohibited Health Data in the message.