In this document
CompliDent, LLC, doing business as CompliDent (“CompliDent,” “we,” “us,” or “our”), provides software and related services that help dental practices and other organizations manage compliance activities. This Privacy Policy explains how we collect, use, disclose, retain, and protect Personal Information when you visit our website, create or administer an account, use our software platform or related services, communicate with us, or otherwise interact with CompliDent (collectively, the “Services”).
This Privacy Policy is a notice of our privacy practices. It is not a contract requiring you to waive privacy rights, and it is not a HIPAA Notice of Privacy Practices. A dental practice or other covered entity remains responsible for its own HIPAA Notice of Privacy Practices and for responding to individuals’ HIPAA rights requests.
This Privacy Policy should be read together with our Terms of Service, Acceptable Use Policy, Cookie Policy, Data Processing Addendum (“DPA”), and any other agreement that applies to your use of the Services. This Privacy Policy describes our privacy practices; binding restrictions on customer use of the Services, including restrictions on Protected Health Information (“PHI”) and other Prohibited Health Data, are set forth in the Terms of Service and Acceptable Use Policy. The Services are not designed or offered for the storage or processing of PHI or other Prohibited Health Data, and customers are prohibited from submitting such information to the Services as described below.
1. Scope and Our Privacy Roles
CompliDent may act in different legal roles depending on the information and the relationship involved:
- For website visitor, prospect, account-registration, billing, security, and direct business-relationship information, CompliDent generally determines why and how the information is processed and acts as a “controller,” “business,” or similar responsible party under applicable privacy laws.
- For information that a customer submits to or generates through the Services on behalf of its organization (“Customer Data”), CompliDent generally processes that information on the customer’s documented instructions and acts as a “processor,” “service provider,” or “contractor,” as applicable. The customer generally controls the purposes and means of processing that Customer Data. Customer Data does not include account administration data, security logs, diagnostic information, service telemetry, or usage information that CompliDent generates or collects through operation of the Services for its own security, operational, analytics, and service-improvement purposes as described in this Privacy Policy.
- The Services are offered on the express condition that customers will not submit or use them to create, receive, maintain, or transmit Prohibited Health Data, including PHI. In particular, customers may not use the Services to create, receive, maintain, or transmit PHI on behalf of a HIPAA covered entity or business associate. CompliDent does not offer the standard Services as a HIPAA business-associate service and does not enter into a Business Associate Agreement (“BAA”) for the standard Services. Whether HIPAA or business-associate obligations apply in a particular circumstance is determined by applicable law and the actual facts, not solely by contractual labels.
When we process Customer Data solely on behalf of a customer, requests concerning that Customer Data should ordinarily be directed to the customer that controls the information. We will assist customers with legally required privacy requests as provided by our agreements and applicable law.
2. Key Definitions
“Personal Information” or “Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable person or household, as defined by applicable law. It generally does not include information that has been lawfully deidentified or aggregated so that it cannot reasonably be linked to a person.
“Sensitive Personal Information” or “Sensitive Data” means information treated as sensitive under applicable law, which may include account credentials, certain financial information, precise geolocation, biometric or genetic information, information revealing certain protected characteristics, and certain health information.
“PHI” means “Protected Health Information” as defined by the Health Insurance Portability and Accountability Act of 1996, as amended by HITECH, and the regulations at 45 C.F.R. Parts 160 and 164 (“HIPAA”). PHI is included within Prohibited Health Data and may not be submitted to or stored in the Services.
“Prohibited Health Data” means: (a) PHI; (b) any information that identifies, is reasonably capable of being associated with, or could reasonably be linked to an individual and that reveals, describes, or relates to the individual’s past, present, or future physical or mental health, dental condition, diagnosis, treatment, care, prescription, procedure, health-care services, insurance, or payment for health care; (c) “consumer health data,” “consumer health information,” or substantially similar information regulated under applicable state privacy or health-data law; and (d) other identifiable patient information. Prohibited Health Data does not include information that has been properly de-identified before transmission so that it is no longer identifiable or reasonably linkable to an individual under applicable law, including information derived from PHI that has been de-identified in accordance with 45 C.F.R. § 164.514.
3. Categories of Personal Information We Collect
Depending on how you interact with the Services, we may collect the following categories of Personal Information. We collect only information that is reasonably necessary for disclosed business or service purposes, subject to applicable law.
| Category | Examples / Sources | Purposes / Retention |
|---|---|---|
| Identifiers and contact information | Name; business or practice name; job title or role; mailing address; email address; telephone number; user ID; account identifier; IP address. Sources: Directly from you; your employer or organization; authorized administrators; automatically from your device. | Provide and administer the Services; communicate with you; authenticate users; customer support; security; legal compliance. Retention: For the life of the account or business relationship and thereafter as reasonably necessary for legal, security, dispute, and recordkeeping purposes. |
| Account and authentication information | Username; password hash or authentication credential; multi-factor authentication information; account status; login history. Sources: Directly from you; authentication providers; automatically from the Services. | Create and secure accounts; prevent unauthorized access; investigate fraud, abuse, or security incidents. Retention: For the account lifecycle and for a reasonable security period after account closure, subject to applicable law and backup cycles. |
| Commercial, billing, and transaction information | Subscription plan; billing contact; invoices; payment status; transaction identifiers; purchase and renewal history. Payment card or bank information may be collected and processed by third-party payment processors. Sources: Directly from you; your organization; payment processors. | Process subscriptions and payments; accounting; fraud prevention; customer support; tax and legal compliance. Retention: For the relationship and as required or permitted for accounting, tax, fraud, dispute, and legal purposes. |
| Professional and organizational information | Practice or office location; employee or workforce names; job roles; permissions; organizational affiliations; vendor information. Sources: You; your organization; authorized administrators; Customer Data. | Configure the Services; manage roles and permissions; support compliance workflows; provide reports and records requested by customers. Retention: Generally according to the customer relationship, customer instructions, applicable agreement, and deletion schedule. |
| Customer content and compliance data | Risk assessments; compliance records; policies; training records; vendor records; audit logs; task data; notes; evidence; uploaded documents; other permitted business-compliance information submitted to the Services. Prohibited Health Data, including PHI, is prohibited and is not permitted Customer Data. Sources: You; your organization; users you authorize; permitted integrations you enable. | Provide the Services; generate requested compliance outputs; maintain records; support collaboration, auditing, and customer-directed workflows. Retention: According to customer instructions and applicable agreements, subject to legal obligations and backup cycles. Prohibited Health Data will be restricted and addressed in accordance with Section 6, including secure return or destruction as appropriate and permitted by applicable law. |
| Device, internet, and usage information | Browser type; device type; operating system; IP address; timestamps; pages or features used; referring pages; session information; log files; crash and diagnostic data; cookie or similar identifiers. Sources: Automatically from browsers, devices, logs, cookies, and similar technologies. | Operate, secure, troubleshoot, measure, and improve the Services; prevent abuse; understand feature usage. Retention: For periods reasonably necessary for operations, analytics, security, and legal purposes, after which data is deleted, aggregated, or deidentified where appropriate. |
| Communications and support information | Support tickets; emails; messages; survey responses; call or meeting notes; feedback; other communications. Sources: Directly from you; your organization; our support systems. | Respond to inquiries; provide support; improve the Services; maintain records of requests; protect legal rights. Retention: For as long as reasonably necessary to resolve the matter, maintain business records, improve support, and address legal or security needs. |
| Marketing and preference information | Communication preferences; subscription choices; event or demo requests; marketing engagement information. Sources: Directly from you; our communications systems; cookies or similar technologies where permitted. | Send requested information; manage preferences; measure business communications; market the Services where permitted by law. Retention: Until you opt out or the information is no longer needed, while retaining limited suppression records as necessary to honor opt-out requests. |
| Sensitive information, if lawfully provided | Account credentials; certain financial information handled by payment processors; other non-health information legally defined as sensitive and permitted by the Services. Prohibited Health Data, including PHI, is expressly prohibited. Sources: You; your organization; authorized users; service providers acting on our behalf. | Only for purposes reasonably necessary to provide, secure, support, or comply with the Services and applicable agreements, or as otherwise permitted by law or valid consent. Retention: Only for as long as reasonably necessary for the applicable permitted purpose, subject to legal, contractual, and security requirements. |
4. Sources of Personal Information
We may collect Personal Information from the following sources:
- Directly from you, such as when you create an account, request a demo, contact support, complete forms, upload documents, or communicate with us.
- From your employer, dental practice, organization, or another user authorized to administer your account or submit information through the Services.
- Automatically from your browser, device, and use of the Services, including through logs, cookies, local storage, and similar technologies.
- From service providers and business partners that support payments, authentication, hosting, communications, analytics, security, or other operational functions.
- From integrations or third-party services that you or your organization choose to connect to the Services.
- From public or professional sources when reasonably necessary for business development, fraud prevention, security, or verification, and where permitted by law.
5. How We Use Personal Information
We may use Personal Information for the following business and service purposes:
- Provide, operate, maintain, configure, and improve the Services.
- Create and administer accounts, organizations, roles, permissions, subscriptions, and billing.
- Process payments and maintain transaction, accounting, tax, and business records.
- Provide customer support, respond to requests, troubleshoot problems, and communicate about the Services.
- Generate customer-requested assessments, reports, task lists, audit trails, and other compliance-management outputs.
- Secure the Services, authenticate users, monitor for misuse, detect and prevent fraud, investigate incidents, and protect the rights, property, and safety of CompliDent, our customers, users, and others.
- Analyze performance and usage, improve functionality, conduct quality assurance, and develop new features using service telemetry, diagnostic and usage information, feedback, and lawfully aggregated or deidentified information. We use identifiable Customer Data for product improvement only to the extent necessary to provide or support the Services or as otherwise authorized by the applicable customer agreement or documented customer instructions; we do not use identifiable Customer Data for unrelated product development.
- Send service-related notices and, where permitted, marketing communications. You may opt out of marketing communications at any time, but you may still receive transactional or service communications.
- Comply with applicable law, court orders, lawful process, regulatory requirements, contractual obligations, and enforce our agreements and policies.
- Carry out a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar corporate transaction, subject to applicable privacy and confidentiality requirements.
We will not materially change the purpose for which Personal Information was collected in a manner that is incompatible with the original disclosed purpose unless we provide any notice and obtain any consent required by applicable law.
6. Customer Data and Prohibition on PHI and Other Health Data
The Services are designed for business and compliance-management activities. They are not an electronic health record, patient-management system, clinical record repository, imaging system, claims platform, patient portal, clinical communications platform, consumer-health-data repository, or other service intended to receive or maintain PHI or other identifiable patient or consumer health information.
This prohibition applies to every feature and input surface of the Services, including assessments, tasks, notes, comments, filenames, evidence uploads, policy documents, training records, vendor records, screenshots, links, integrations, support requests, emails to CompliDent, and other communications. Without limitation, customers must not submit:
- patient charts, clinical notes, treatment plans, diagnoses, prescriptions, medical or dental histories, identifiable appointment or procedure information, or other identifiable patient health information;
- dental radiographs, photographs, scans, intraoral images, laboratory records, or other clinical images or files that identify or can reasonably be linked to a patient or consumer;
- insurance claims, explanations of benefits, billing or payment information, member or subscriber identifiers, or other health-care payment or insurance records that constitute PHI or other Prohibited Health Data;
- patient or consumer names, dates of birth, addresses, telephone numbers, email addresses, medical-record numbers, account numbers, or other identifiers when combined with health, dental, treatment, care, insurance, or payment information in a manner that constitutes PHI or other Prohibited Health Data; or
- any other information that constitutes PHI under HIPAA, consumer health data or consumer health information under applicable state law, or other identifiable patient or health information included within the definition of Prohibited Health Data.
If a document, screenshot, record, or other evidence is useful for a compliance workflow but contains or is derived from Prohibited Health Data, the customer must de-identify it before transmission to CompliDent. If the information is derived from PHI, de-identification must satisfy 45 C.F.R. § 164.514, including the Safe Harbor or Expert Determination method as applicable. Merely removing a patient’s name or a small number of direct identifiers is not sufficient unless the resulting information satisfies the applicable de-identification standard. For other Prohibited Health Data, the customer must de-identify the information in accordance with applicable law so that it is no longer identifiable or reasonably linkable to an individual. Customers are solely responsible for reviewing content before submission and confirming that the material is permitted Customer Data.
If you discover that Prohibited Health Data was submitted to the Services, you must promptly remove it if you are able to do so and notify CompliDent at getcomplident@gmail.com without including PHI, patient-identifying information, or other Prohibited Health Data in the notice. The Terms of Service and Acceptable Use Policy govern the customer’s binding obligations concerning prohibited submissions and authorize CompliDent, subject to applicable law, to restrict access to, quarantine, securely return, or securely delete or destroy Prohibited Health Data submitted in violation of those agreements.
Upon becoming aware that Prohibited Health Data has been submitted to or is being maintained through the Services, CompliDent will promptly take reasonable steps to restrict further access to or processing of the information, investigate and document the submission, and securely return or destroy the information as appropriate and permitted by applicable law and the applicable customer agreement. CompliDent will not intentionally use or disclose Prohibited Health Data except as reasonably necessary to identify, locate, contain, secure, investigate, document, return, or destroy the prohibited information; respond to a security incident; protect legal rights; or comply with applicable law. An accidental or unauthorized submission does not authorize continued storage or processing of Prohibited Health Data, amend the parties’ agreements, or create a right to use the Services for such information. Nothing in this Privacy Policy limits any obligation that applicable law may impose based on information CompliDent actually receives or maintains.
7. How We Disclose Personal Information
We may disclose Personal Information to the following categories of recipients, only for the purposes described in this Privacy Policy or otherwise permitted by law:
- Service providers, processors, and contractors. These may include providers of cloud infrastructure, database services, communications, authentication, payment processing, customer support, analytics, monitoring, backup, security, and professional services. We require service providers that process Personal Information on our behalf to be subject to contractual restrictions and protections appropriate to the services and applicable law.
- Your organization and authorized users. Account administrators and authorized users within your organization may be able to access information associated with your organization, including user activity, roles, tasks, records, and Customer Data, according to the permissions configured by the organization.
- Professional advisers. We may disclose information to lawyers, accountants, auditors, insurers, consultants, and similar advisers where reasonably necessary and subject to appropriate duties of confidentiality.
- Government authorities and legal recipients. We may disclose information when we reasonably believe disclosure is required by law, valid legal process, or a lawful governmental request, or when reasonably necessary to protect legal rights, investigate fraud or security issues, enforce agreements, or protect safety. Where legally permitted and appropriate, we may seek to narrow or challenge requests that are overbroad or unlawful.
- Corporate transaction parties. Information may be disclosed or transferred in connection with due diligence or a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and confidentiality protections.
- At your direction or with consent. We may disclose information when you or your organization directs us to do so, enables an integration, or otherwise provides legally valid consent.
We may use and disclose information that has been lawfully deidentified or aggregated and that cannot reasonably be linked to an identified person, subject to applicable law and contractual restrictions.
8. Sale, Sharing, Targeted Advertising, and Profiling
As of the Effective Date, CompliDent does not sell Personal Information for monetary or other valuable consideration as “sale” is defined by applicable comprehensive state privacy laws, and we do not share Personal Information for cross-context behavioral advertising or process Personal Information for targeted advertising as those terms are defined by applicable law.
We do not use Customer Data for cross-context behavioral advertising or targeted advertising, and we do not use Customer Data submitted for compliance workflows to build advertising profiles about individuals. Prohibited Health Data, including PHI, is prohibited from the Services and therefore must not be submitted for any purpose, including advertising or marketing.
If our practices change so that an opt-out right applies, we will update this Privacy Policy and provide legally required opt-out methods. Where applicable to our processing, we will recognize valid opt-out preference signals, such as Global Privacy Control (“GPC”), as required by law.
We do not currently use Personal Information to make automated decisions that produce legal or similarly significant effects concerning consumers. If that changes, we will provide any notices, explanations, access rights, or opt-out rights required by applicable law.
9. Cookies and Similar Technologies
We and our service providers may use cookies, local storage, pixels, software development kits, log files, and similar technologies to operate and secure the Services, remember preferences, maintain sessions, understand usage, troubleshoot, and measure performance.
We may use the following categories of technologies:
- Strictly necessary technologies, which support authentication, security, session management, fraud prevention, and core functionality.
- Functional technologies, which remember settings and preferences and support requested features.
- Analytics technologies, which help us understand how the Services are used and improve performance and functionality, where permitted by law.
Where applicable law requires consent before placing or accessing non-essential technologies, we will request that consent before using those technologies. You may also manage cookies through your browser settings and any consent controls we make available. Disabling certain cookies may affect functionality. Additional details, including cookie-specific retention periods where applicable, are provided in our Cookie Policy.
Do Not Track and cross-site tracking. Some browsers offer a “Do Not Track” (“DNT”) setting. Because there is no uniform industry standard for interpreting DNT signals, our website does not currently respond to DNT signals. As stated in Section 8, CompliDent does not sell Personal Information or share it for cross-context behavioral advertising, and we do not authorize third parties to collect Personal Information through the Services over time and across unaffiliated websites for their own cross-site behavioral advertising. Third-party service providers may collect device or usage information through the Services to provide analytics, security, or other operational services to CompliDent, subject to contractual restrictions and applicable law. We recognize legally required opt-out preference signals, including Global Privacy Control (“GPC”), as described in Section 8.
10. Communications and Marketing Choices
We may send administrative, security, billing, product, and other service-related communications that are necessary to manage your account or provide the Services. These communications are not marketing messages and may continue even if you opt out of promotional communications.
Where permitted by law, we may send marketing communications about CompliDent. You can opt out by using the unsubscribe mechanism in the message or by contacting us. We may retain limited suppression information to ensure that we honor your opt-out request.
11. Data Retention and Deletion
We retain Personal Information only for as long as reasonably necessary and proportionate for the purposes described in this Privacy Policy, taking into account the nature and sensitivity of the information, the purposes for which it is processed, customer instructions, contractual commitments, legal and regulatory requirements, security needs, statutes of limitation, and backup or disaster-recovery cycles.
Retention is generally determined as follows:
- Account and relationship data: for the duration of the account or business relationship and for a reasonable period afterward for security, support, legal, tax, dispute, and recordkeeping purposes.
- Billing and transaction records: for periods required or permitted by accounting, tax, anti-fraud, contractual, and other applicable legal obligations.
- Customer Data: according to customer instructions, the applicable agreement, our deletion processes, backup cycles, and legal obligations. Prohibited Health Data identified in the Services will be restricted and addressed under Section 6, including secure return or destruction as appropriate and permitted by applicable law and the applicable customer agreement.
- Security and technical logs: for periods reasonably necessary to investigate incidents, maintain system integrity, detect abuse, support operations, and meet legal obligations.
- Support and communications: for as long as reasonably necessary to address the request, maintain business records, improve support, and protect legal rights.
- Marketing preferences: until changed or withdrawn, with limited suppression data retained as necessary to honor opt-outs.
When retention is no longer reasonably necessary, we will delete, deidentify, or aggregate the information as appropriate, subject to technical limitations, backup cycles, legal holds, and applicable law. Information in backups may remain until overwritten or securely deleted in the ordinary backup cycle, but it will remain protected while retained.
12. Information Security
We maintain administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of information appropriate to the nature, volume, and sensitivity of the information and the risks presented by the processing. Depending on the system and information involved, safeguards may include access controls, authentication controls, role-based permissions, encryption in transit, encryption at rest where applicable, audit logging, monitoring, secure cloud infrastructure, vulnerability management, backup and recovery measures, vendor oversight, workforce security measures, and incident-response procedures.
Our security measures are designed to protect the Personal Information and permitted Customer Data processed through the Services. They do not mean that the Services are approved, certified, or offered for storing or processing PHI or other Prohibited Health Data. Customers must not rely on the Services as a HIPAA-compliant repository, transmission system, consumer-health-data repository, or patient-data platform.
You are responsible for maintaining the confidentiality of your account credentials, using security features made available to you, and promptly notifying us if you suspect unauthorized access to your account.
13. Security Incidents and Breach Notification
If we become aware of a security incident involving Personal Information, we will investigate, contain, remediate, document, and provide notices as required by applicable law. If an incident involves Prohibited Health Data that was submitted in violation of the Terms of Service, Acceptable Use Policy, or this Privacy Policy, we will take the response steps described in Section 6 and any additional steps required by applicable law. We will not intentionally retain, use, or disclose such information beyond what is reasonably necessary for containment, investigation, documentation, secure return or destruction, incident response, protection of legal rights, or legal compliance.
14. U.S. Privacy Rights
Depending on your state of residence, the nature of the information, our role, and applicable legal exemptions, you may have some or all of the following rights regarding Personal Information for which CompliDent acts as the controller or business:
- Confirm whether we process your Personal Information and access it.
- Correct inaccurate Personal Information.
- Delete Personal Information, subject to applicable exceptions.
- Obtain a portable copy of certain Personal Information.
- Opt out of the sale of Personal Information, targeted advertising, or certain profiling, where applicable.
- Limit certain uses or disclosures of Sensitive Personal Information, or withdraw consent to certain sensitive-data processing, where applicable.
- Obtain information about categories of Personal Information, sources, purposes, and disclosures, and in some states obtain information about specific third parties to which Personal Information was disclosed, where applicable.
- Appeal a denial of a privacy-rights request, where applicable.
- Not be discriminated against for exercising a legally protected privacy right.
Certain rights do not apply to all information. For example, state privacy laws may contain exemptions for information governed by other federal or state laws, employment-related information, or business-to-business information. Prohibited Health Data, including PHI, is prohibited from the Services and is not an intended category of information processed under this Privacy Policy.
How to submit a request
To exercise an applicable privacy right, email getcomplident@gmail.com with the subject line “Privacy Request” and describe the right you wish to exercise. You do not need to create a new account solely to make a request. If you already have an account, we may use account-based verification where appropriate.
We may request information reasonably necessary to authenticate your identity and authority. We will use verification information only for verification, security, fraud prevention, and legal compliance. If we cannot reasonably verify a request, we may be unable to fulfill it.
We will respond within the period required by applicable law and will provide extensions, explanations, or appeal instructions where required. Requests are generally processed without charge, although applicable law may permit a reasonable fee or denial for manifestly unfounded, excessive, or repetitive requests.
Authorized agents
Where permitted by law, you may use an authorized agent to submit a request. We may require proof of the agent’s authority and may also require you to verify your identity or directly confirm that you authorized the request, except where applicable law provides otherwise.
Appeals
If we deny a request and applicable law gives you a right to appeal, you may appeal by emailing getcomplident@gmail.com with the subject line “Privacy Appeal” and identifying the request you are appealing. We will respond to the appeal within the time required by applicable law. If an appeal is denied, we will provide information about how to contact the appropriate state regulator or attorney general when required by law.
15. Additional Notice for California Residents
This section supplements the rest of this Privacy Policy for California residents. It applies only to the extent CompliDent is subject to the California Consumer Privacy Act (“CCPA”), as amended, with respect to the relevant Personal Information.
In the preceding 12 months, depending on your interaction with the Services, we may have collected the following CCPA categories of Personal Information: identifiers; categories of personal information described in California Civil Code section 1798.80(e); commercial information; internet or other electronic network activity; professional or employment-related information; inferences derived from information described in this Privacy Policy; and Sensitive Personal Information such as account credentials and certain financial information processed for billing. Prohibited Health Data, including PHI and identifiable patient or consumer health information, is not an intended category of Personal Information collected through the Services and may not be submitted.
The sources, business or commercial purposes, categories of recipients, and retention criteria for these categories are described in Sections 3 through 11 above. Categories of recipients may include service providers and contractors, your organization and authorized users, professional advisers, government or legal recipients, transaction parties, and recipients you direct or authorize.
CompliDent does not, as of the Effective Date, sell Personal Information or share Personal Information for cross-context behavioral advertising. We do not knowingly sell or share the Personal Information of consumers under 16 years of age. We use and disclose Sensitive Personal Information only for purposes reasonably necessary and proportionate to provide, secure, administer, and support the Services, comply with law, or as otherwise permitted by the CCPA or valid consent; we do not use Sensitive Personal Information to infer characteristics about consumers for unrelated purposes.
If the CCPA applies, California residents may have the right to know/access, delete, correct, opt out of sale or sharing, limit certain uses and disclosures of Sensitive Personal Information, use an authorized agent, and be free from discriminatory treatment for exercising CCPA rights. Requests may be submitted using the methods in Section 14.
CompliDent does not currently offer a financial incentive or price or service difference in exchange for the collection, sale, or sharing of Personal Information. If we introduce such a program, we will provide the legally required notice and consent mechanisms before applying it.
16. Additional Information for EEA, United Kingdom, and Switzerland
If the GDPR, UK GDPR, Swiss data-protection law, or similar law applies to our processing of your Personal Data, this section supplements the rest of this Privacy Policy. CompliDent’s role as controller or processor depends on the context described in Section 1.
Where CompliDent acts as a controller, our legal bases for processing may include:
- Performance of a contract or steps requested before entering into a contract, such as creating and administering an account or providing requested Services.
- Legitimate interests, such as securing and improving the Services, communicating with business users, preventing fraud, maintaining records, and protecting legal rights, provided those interests are not overridden by applicable privacy rights.
- Compliance with legal obligations.
- Consent, where required, such as for certain non-essential cookies or marketing activities. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
Where these laws apply, you may have rights to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, and you may have the right to lodge a complaint with a competent supervisory authority. Where CompliDent acts only as a processor, please direct your request to the customer that controls the Personal Data.
Personal Data may be transferred to and processed in the United States and other countries where our service providers operate. Where required, we use an applicable lawful transfer mechanism, such as an adequacy decision, approved standard contractual clauses, a UK addendum or other legally recognized safeguard. We will provide additional information about applicable transfer safeguards upon request where required by law.
17. Children’s Privacy
The Services are designed for business use by adults and are not directed to children. We do not knowingly collect Personal Information directly from children under 13 through the public-facing Services. We also do not intend to offer accounts directly to individuals under 18. If we learn that we collected Personal Information from a child in a manner prohibited by law, we will take appropriate steps to delete or otherwise address the information. If you are a parent or guardian and believe a child under 13 has provided Personal Information directly to CompliDent, contact us at getcomplident@gmail.com. We will investigate and, if appropriate, delete the information as required by applicable law.
Customers must not submit Prohibited Health Data or other identifiable patient information concerning minors to the Services. If we learn that such information about a child was submitted in a manner prohibited by this Privacy Policy, the Terms of Service, the Acceptable Use Policy, or applicable law, we will address it in accordance with Section 6 and take any additional action required by applicable law.
18. Third-Party Services and Integrations
The Services may link to or integrate with third-party websites, applications, payment processors, identity providers, or other services. When a third party independently determines how it uses Personal Information, its own privacy notice and terms govern that processing. CompliDent is not responsible for the privacy practices of independent third parties. Customers should review the privacy and security terms of any integration they enable.
19. Corporate Changes and Data Transfers
If CompliDent is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, Personal Information may be reviewed, disclosed, or transferred as part of that transaction. We will continue to protect Personal Information consistent with applicable law and will provide notice if required before Personal Information becomes subject to materially different privacy practices.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, privacy practices, legal requirements, or other circumstances. We will post the updated version and revise the “Last Updated” date. If a change is material, we will provide additional notice when required by law. Where applicable law requires consent before we use previously collected Personal Information for a materially different purpose, we will obtain that consent before doing so.
21. Contact Us
If you have questions about this Privacy Policy, our privacy practices, or a privacy-rights request, contact:
CompliDent, LLC Attn: Privacy Email: getcomplident@gmail.com Website: https://www.getcomplident.com
If you discover that PHI or other Prohibited Health Data has been submitted to the Services, contact CompliDent promptly at getcomplident@gmail.com with the subject line “Prohibited Health Data Removal Request.” Do not include PHI, patient-identifying information, or other Prohibited Health Data in the email. We may request non-prohibited information reasonably necessary to locate and address the content.