● Legal
Privacy Policy
Last updated 1 September 2026
Introduction and Scope
This Privacy Policy describes how SanctifAI Dental Inc. dba Dental Maverick AI (“Company”, “we”, “us”, “our”) collects, uses, and discloses your information when you use our Service. We are committed to protecting your privacy through compliance with applicable federal and state data protection laws. This Policy applies to our marketing website at dentalmaverick.ai, our application at app.dentalmaverick.ai, and any other website or application we operate that links to this Policy.
For general account management, marketing and website operation, Company acts as an independent business or data controller. When processing Protected Health Information (“PHI”) as defined by the Health Insurance Portability and Accountability Act (HIPAA), on behalf of our Customers (Covered Entities), Company acts strictly as a Data Processor and Business Associate. This processing is governed exclusively by the Business Associate Agreement (“BAA”) entered into with our Customers, which legally supersedes this Policy. To the extent any data processed through our Service falls outside the definition of HIPAA PHI but is protected as Consumer Health Data or Sensitive Personal Information under state law, such data is governed by the applicable Data Processing Agreements (DPAs) and security protocols established with our Customers.
Legal Basis for Processing
We process Personal Data under the following valid legal bases:
- Consent: When you have given us clear and explicit consent or permission for a specific purpose. Any processing of PHI by Company is strictly conditioned upon the Data Controller (Covered Entity) having obtained any patient consent or authorization required by applicable law.
- Performance of a Contract: When processing is necessary for the execution of our Service you requested, manage your account, fulfill our Terms of Service, or Agreements with you.
- Legitimate Interests: When it is necessary for our business interests, such as ensuring our tech infrastructure and platform security, preventing fraud, and improving our Artificial Intelligence (“AI”) assisted processes, provided these interests do not override your privacy rights. For the avoidance of doubt, "legitimate interest" described here does not apply as a legal basis for the processing of PHI. Company acts strictly as a Data Processor and Business Associate, and claims no ownership rights or legitimate interests regarding PHI, processing such data exclusively in accordance with the documented instructions of the Data Controller.
- Legal Obligation: When we must comply with the law.
Types of Data We Collect
While using our Service, we may collect the following data:
- Identity or Personal Data: First and last name, email address, phone number.
- Business Data: Prospect name, operational data and competitive financial information.
- Usage Data: IP address, browser type, browser version, device identifiers, device telemetry and other diagnostic data (pages of our Service you visit, time and date of your visit, time spent on those pages, and others collected automatically when using our Service as well as, information that your browser sends to our Service through any device). Much of this Usage Data is collected automatically through cookies and similar tracking technologies used by us and our analytics providers; how these work and how to control them is described in our Cookies and Tracking Technologies Policy.
- Protected Health Information (PHI): Individually identifiable health information provided by our Customers, the Data Controller (Covered Entity), which may include dental treatment information, insurance data and patient demographic data. We collect and process this data strictly under the conditions and requests of the Data Controller, and always supported by prior and explicit consent obtained from the patient by the Data Controller (Covered Entity) as required by applicable law.
Sources of Data
We obtain the data described above from the following sources:
- Directly from you: Information you provide when you create an account, complete a contact or waitlist form, request a demonstration, or communicate with our team.
- Automatically from your device: Usage Data collected through cookies, server logs, and similar technologies when you visit our website or use the Service.
- From our Customers (Covered Entities): PHI and Customer information transmitted to us by the Data Controller, including data retrieved from the Customer's systems under the Customer's authorization and credentials.
- From third parties: Dental provider identification data from public registries maintained by United States federal authorities, and insurance eligibility, claim status, and remittance data received from dental insurance carriers and clearinghouses in the course of providing the Service.
Purposes of Processing (How We Use Your Data)
We process your Personal Data for the following purposes:
- Provision of Service and Maintenance: To provide access to the Company Platform, manage your account registration, and ensure the technical functionality of our Service.
- Contractual Obligations: To fulfill purchase agreements, process payments through payment entities, and manage the relationship between us and our Customers.
- Critical Communications: To send security updates, administrative alerts, and technical notices via email or push notifications.
- Administrator Support: Company only handles and responds to inquiries, requests, and technical comments from administrators and authorized users of our Customers (Covered Entities) who act as Data Controller. As a Business Associate, Company does not provide direct patient support or communications. Any patient privacy communication or request received directly from us will be immediately forwarded to the appropriate Data Controller in strict compliance with HIPAA regulations.
- Platform Optimization: To analyze usage trends, evaluate the effectiveness of our Service, and improve the user experience. Company uses solely de-identified or aggregated data for these optimization purposes.
- Marketing (Optional): To send news, product updates, and offers relating to our Service. You may opt out at any time by emailing privacy@dentalmaverick.ai. Opting out of marketing does not affect the Critical Communications described above, which are necessary to operate your account.
AI and Automated Decision-Making
- Human Oversight: We implement processes and protocols to ensure that high-risk AI outcomes are validated and verified by human oversight.
- No Profiling or Automated Decision Making: We do not use personal data to make fully automated decisions or create fully automated profiles that produce legal effects without the explicit consent provided by the patient and obtained by the Data Controller (Covered Entity). AI models are used exclusively for improving the processing of dental insurance related processes.
- Strict Prohibition on Training Algorithms with PHI: Company and its authorized subcontractors are strictly prohibited from using PHI to train, improve, adjust, or compare their own AI algorithms and models, as well as any public or third-party artificial intelligence models. The PHI is used exclusively to process dental insurance related processes for a specific patient according to the instructions of the Covered Entity.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this privacy policy, comply with applicable legal, tax, or reporting requirements, or to resolve disputes. Company enforces a strict deletion and return protocol for PHI upon termination of the Service within the timeframe established by the applicable BAA, except if legally required to retain (such as insurance records). Usage data used for internal analysis will be retained for shorter periods, except when used to strengthen the security or improve the functionality of our technology infrastructure.
Transfer of Your Personal Data
By accessing or using our technological infrastructure, you acknowledge and agree that your Personal Data may be transferred to, stored in, and processed in United States (where our servers and cloud infrastructure are primarily located) and other countries where our personnel, Service Providers or corporate affiliates are located (who works as hosting, payment, analytics partners and others), ensuring the security of your data.
- PHI Transfers: In the event that PHI is transferred to or processed by us, our personnel, or our authorized sub-processors (including those located outside the United States), such processing is strictly governed by downstream Business Associate Agreements and applicable Data Protection Agreements. These legally binding agreements mandate that us or our sub-processors implement and maintain the exact same, or stricter, administrative, physical, and technical safeguards as required by HIPAA, ensuring that PHI remains fully protected under U.S. federal healthcare standards regardless of its processing location.
Sharing and Disclosure of Data
We do not sell your personal data. We only share information in the following strictly defined scenarios:
- Service Providers: Cloud infrastructure providers, communication tools, payment processors, and analytics tools process general account, billing, personal, business and usage data on our behalf under strict confidentiality agreements. For avoidance of doubt, PHI is strictly segregated and is never shared with payment processors, marketing platforms, or general analytics tools.
- Authorized Sub-processors for PHI: We only share PHI with specialized, authorized sub-processors. These entities are strictly bound by downstream BAAs ensuring they implement the exact same or stricter HIPAA compliance and security measures that we guarantee to our Covered Entities.
- Business Transfers and Corporate Affiliates: In the event of a merger, acquisition, sale of assets, or sharing with corporate affiliates, the receiving or acquiring entity will be required to uphold this Privacy Policy.
- Legal Mandates: When required by competent authorities, to comply with court orders, valid requests from law enforcement, or applicable legal requirements. If a legal request or subpoena specifically involves PHI, Company will promptly notify the respective Data Controller (Covered Entity) before any disclosure is made. This allows Covered Entity to seek a protective order or respond directly to the authority, unless the Company is explicitly prohibited by law from providing such prior notice.
Patient Rights Routing (HIPAA)
If we or one of our sub-processors receives a data privacy request (such as access, amendment, or deletion) directly from a patient, we will immediately notify the Data Controller (Covered Entity). We will not respond directly to the patient’s request unless expressly authorized in writing by the Data Controller, providing reasonable assistance to them to fulfill the request.
Security and Data Protection
Security of your personal data is a priority for our Company; therefore, we implement acceptable security measures through a multi-layered security framework. This framework includes industry-standard encryption, and access to confidential information is strictly controlled through Multi-Factor Authentication (MFA) and the Principle of Least Privilege (PoLP). Although we have these acceptable security measures, while we maintain a comprehensive internal Information Security Policy (ISP), and conduct periodic vulnerability assessments, no method of electronic transmission or storage is 100% secure. Consequently, in the event of a data breach or compromise of security, our Information Security Policy (ISP) establishes protocols for notifying the relevant authorities and affected users in accordance with applicable legal requirements.
All Company personnel with access to PHI undergo mandatory training in data protection and HIPAA compliance and are subject to disciplinary action for privacy violations. In the event of a security breach involving PHI, Company notifies the respective Data Controller (Covered Entity) within the timeframes established in the BAA.
Children's Privacy and Age Limits
Our Service is designed for professional dental care providers and business entities and we do not direct our Services to, nor do we permit individuals under the age of 18 to create accounts or directly interact with our platform. If we discover that a user under the age of 18 has created an account through our Service, we will immediately delete that information from our servers.
As a Business Associate, Company may process PHI of minors (pediatric patients) uploaded to the platform by our Customers. Such processing is strictly conducted under the instructions of the Data Controller (Covered Entity). Covered Entity is solely and exclusively responsible for obtaining and documenting the legally required consent from the minor's parent, legal guardian, or authorized Personal Representative in full compliance with HIPAA and any other applicable laws prior to submitting any pediatric data.
Your Rights
Email privacy@dentalmaverick.ai to request a copy of your data, correct it, or delete it. We respond within 30 days.
Changes to this Privacy Policy
We may update our Privacy Policy periodically to reflect changes in our practices, technology, or legal obligations. When changes are made, we will notify you after the "Last Updated" date at the top of this policy is published, and the updated policy will be effective from the date published on this page. We retain prior versions of this Policy and will make any previous version available on request to privacy@dentalmaverick.ai.
In the case of material changes (those that significantly affect your rights or how we handle your data), we will provide you with more prominent notice, which may include an email notification or a notification on the Platform dashboard, before the change takes effect. We encourage you to review this policy periodically.
Notwithstanding any changes made to this general Privacy Policy, Company guarantees that no update, modification, or revision to this document will ever supersede, diminish, or materially alter the strict privacy and security obligations regarding PHI established in any active BAA signed with a Covered Entity. Any changes affecting the processing of PHI must be mutually agreed upon in writing through an amendment to the respective BAA.
Contact Us
SanctifAI Dental Inc. dba Dental Maverick AI
7415 Southwest Pkwy, Bldg 6 suite 500-710, Austin TX 78735, USA