← Legal

● Legal

Privacy Policy

Last updated 1 September 2026

Introduction and Scope

This Privacy Policy describes how SanctifAI Dental Inc. dba Dental Maverick AI (“Company”, “we”, “us”, “our”) collects, uses, and discloses your information when you use our Service. We are committed to protecting your privacy through compliance with applicable federal and state data protection laws. This Policy applies to our marketing website at dentalmaverick.ai, our application at app.dentalmaverick.ai, and any other website or application we operate that links to this Policy.

For general account management, marketing and website operation, Company acts as an independent business or data controller. When processing Protected Health Information (“PHI”) as defined by the Health Insurance Portability and Accountability Act (HIPAA), on behalf of our Customers (Covered Entities), Company acts strictly as a Data Processor and Business Associate. This processing is governed exclusively by the Business Associate Agreement (“BAA”) entered into with our Customers, which legally supersedes this Policy. To the extent any data processed through our Service falls outside the definition of HIPAA PHI but is protected as Consumer Health Data or Sensitive Personal Information under state law, such data is governed by the applicable Data Processing Agreements (DPAs) and security protocols established with our Customers.

Legal Basis for Processing

We process Personal Data under the following valid legal bases:

Types of Data We Collect

While using our Service, we may collect the following data:

Sources of Data

We obtain the data described above from the following sources:

Purposes of Processing (How We Use Your Data)

We process your Personal Data for the following purposes:

AI and Automated Decision-Making

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this privacy policy, comply with applicable legal, tax, or reporting requirements, or to resolve disputes. Company enforces a strict deletion and return protocol for PHI upon termination of the Service within the timeframe established by the applicable BAA, except if legally required to retain (such as insurance records). Usage data used for internal analysis will be retained for shorter periods, except when used to strengthen the security or improve the functionality of our technology infrastructure.

Transfer of Your Personal Data

By accessing or using our technological infrastructure, you acknowledge and agree that your Personal Data may be transferred to, stored in, and processed in United States (where our servers and cloud infrastructure are primarily located) and other countries where our personnel, Service Providers or corporate affiliates are located (who works as hosting, payment, analytics partners and others), ensuring the security of your data.

Sharing and Disclosure of Data

We do not sell your personal data. We only share information in the following strictly defined scenarios:

Patient Rights Routing (HIPAA)

If we or one of our sub-processors receives a data privacy request (such as access, amendment, or deletion) directly from a patient, we will immediately notify the Data Controller (Covered Entity). We will not respond directly to the patient’s request unless expressly authorized in writing by the Data Controller, providing reasonable assistance to them to fulfill the request.

Security and Data Protection

Security of your personal data is a priority for our Company; therefore, we implement acceptable security measures through a multi-layered security framework. This framework includes industry-standard encryption, and access to confidential information is strictly controlled through Multi-Factor Authentication (MFA) and the Principle of Least Privilege (PoLP). Although we have these acceptable security measures, while we maintain a comprehensive internal Information Security Policy (ISP), and conduct periodic vulnerability assessments, no method of electronic transmission or storage is 100% secure. Consequently, in the event of a data breach or compromise of security, our Information Security Policy (ISP) establishes protocols for notifying the relevant authorities and affected users in accordance with applicable legal requirements.

All Company personnel with access to PHI undergo mandatory training in data protection and HIPAA compliance and are subject to disciplinary action for privacy violations. In the event of a security breach involving PHI, Company notifies the respective Data Controller (Covered Entity) within the timeframes established in the BAA.

Children's Privacy and Age Limits

Our Service is designed for professional dental care providers and business entities and we do not direct our Services to, nor do we permit individuals under the age of 18 to create accounts or directly interact with our platform. If we discover that a user under the age of 18 has created an account through our Service, we will immediately delete that information from our servers.

As a Business Associate, Company may process PHI of minors (pediatric patients) uploaded to the platform by our Customers. Such processing is strictly conducted under the instructions of the Data Controller (Covered Entity). Covered Entity is solely and exclusively responsible for obtaining and documenting the legally required consent from the minor's parent, legal guardian, or authorized Personal Representative in full compliance with HIPAA and any other applicable laws prior to submitting any pediatric data.

Your Rights

Email privacy@dentalmaverick.ai to request a copy of your data, correct it, or delete it. We respond within 30 days.

Changes to this Privacy Policy

We may update our Privacy Policy periodically to reflect changes in our practices, technology, or legal obligations. When changes are made, we will notify you after the "Last Updated" date at the top of this policy is published, and the updated policy will be effective from the date published on this page. We retain prior versions of this Policy and will make any previous version available on request to privacy@dentalmaverick.ai.

In the case of material changes (those that significantly affect your rights or how we handle your data), we will provide you with more prominent notice, which may include an email notification or a notification on the Platform dashboard, before the change takes effect. We encourage you to review this policy periodically.

Notwithstanding any changes made to this general Privacy Policy, Company guarantees that no update, modification, or revision to this document will ever supersede, diminish, or materially alter the strict privacy and security obligations regarding PHI established in any active BAA signed with a Covered Entity. Any changes affecting the processing of PHI must be mutually agreed upon in writing through an amendment to the respective BAA.

Contact Us

SanctifAI Dental Inc. dba Dental Maverick AI

7415 Southwest Pkwy, Bldg 6 suite 500-710, Austin TX 78735, USA

privacy@dentalmaverick.ai

Light