Privacy Policy
Effective 6/2/2026 · Last updated 6/14/2026
For dental practices, dentists, providers, specialists, and authorized dental office staff
This Privacy Policy explains how DDSALLY LLC ("DDSALLY," "we," "us," or "our") collects, uses, discloses, retains, and protects information when visitors, dental practices, dentists, providers, specialists, and authorized dental office staff use the DDSALLY website, platform, and related services (collectively, the "Service").
DDSALLY is designed as a clinician-to-clinician dental referral, secure communication, and record-sharing platform. The Service is intended for dental professionals, dental practices, specialists, and authorized dental office staff. The Service is not a patient portal and is not intended for direct use by patients or the general public.
1. Scope and Relationship to HIPAA
This Policy applies to website visitors, practice administrators, dentists, dental providers, specialists, and authorized staff members who create or use DDSALLY accounts. It describes DDSALLY’s practices for account information, practice information, billing information, support information, website information, technical information, and usage information.
Patient information, including Protected Health Information ("PHI"), is handled differently. When DDSALLY receives, creates, maintains, transmits, or stores PHI on behalf of a dental practice, DDSALLY acts as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended ("HIPAA"). In that role, DDSALLY processes PHI according to the applicable Business Associate Agreement ("BAA"), HIPAA, the dental practice’s instructions through the Service, and applicable law.
Each dental practice remains responsible for its own patient Notice of Privacy Practices, patient consents and authorizations, dental record obligations, professional obligations, and patient-facing privacy responsibilities.
If this Policy conflicts with an executed BAA regarding PHI, the BAA controls with respect to PHI.
2. Patient Communication Limitation
DDSALLY may allow a dental practice or authorized provider to send secure messages, records, referral updates, instructions, imaging, attachments, or other patient-facing communications to a patient at the direction of the dental practice or authorized provider. In that situation, DDSALLY processes the information according to the applicable BAA, the practice’s instructions, HIPAA, and applicable law.
DDSALLY does not allow patients to use the Service to send messages to offices, upload files, submit medical or dental information, provide histories, send images, request care, or otherwise communicate back to dental practices through DDSALLY unless DDSALLY separately enables that functionality in writing and implements appropriate privacy, security, consent, authorization, workflow, and compliance controls.
Dental practices and authorized users are responsible for verifying patient identity and contact information before sending patient-directed communications through the Service. This includes verifying, as appropriate, the patient’s email address, phone number, recipient identity, delivery method, and the accuracy of any PHI or records being transmitted.
DDSALLY is not responsible for incorrect patient contact information, incorrect recipient selection, inaccurate PHI submitted by a practice, unauthorized disclosure caused by a practice or user error, or misuse of patient-directed messaging by a practice or its authorized users, except to the extent required by applicable law or the applicable BAA.
If DDSALLY inadvertently receives patient-submitted medical, dental, clinical, imaging, diagnostic, or other PHI outside an approved workflow, DDSALLY may notify the relevant practice and handle the information according to the applicable BAA, HIPAA, and DDSALLY’s privacy and security procedures.
3. Information We Collect
Account Information
Name, email address, phone number, login credentials, role, practice affiliation, authentication settings, account status, and related profile information.
Practice Information
Practice name, practice address, phone number, specialty, provider information, NPI, license or credential information, administrator details, referral preferences, onboarding information, and practice configuration settings.
Billing Information
Billing contact, billing address, subscription plan, invoice history, transaction history, payment status, and payment metadata. Payment cards are processed by Stripe or another payment processor. DDSALLY does not store full payment card numbers on its own servers. DDSALLY does not intentionally submit PHI to payment processors.
Clinical and Operational Content
Referral information, secure messages, patient-directed messages, attachments, images, DICOM files, PDFs, notes, referral status updates, workflow information, and related content submitted through the Service by practices or authorized users. Some of this content may contain PHI and is governed by the applicable BAA.
Support and Communications
Information provided when contacting DDSALLY support, security, privacy, legal, billing, or administrative teams.
Technical Data
IP address, device identifiers, browser type, operating system, pages viewed, referring pages, timestamps, session data, approximate location inferred from IP address, and similar technical information.
Usage Data
Login events, feature usage, workflow actions, settings changes, referral status actions, patient-directed send events, administrative actions, account configuration activity, and other interactions with the Service.
Security and Audit Logs
Authentication events, access attempts, content access, downloads, uploads, administrative changes, user invitations, message transmission events, security alerts, system events, and other records needed for security monitoring, compliance, HIPAA audit support, and investigation of suspicious activity.
Cookies and Similar Technologies
Session cookies, preference cookies, security cookies, analytics technologies, local storage, and similar technologies as described in this Policy.
Third-Party Information
Information from public or professional registries when used to verify licensing or professional eligibility; information from payment processors regarding transaction status and billing metadata; and information from service providers that help DDSALLY operate, secure, support, or improve the Service.
4. How We Use Information
DDSALLY may use information to:
- Provide, operate, maintain, secure, and improve the Service.
- Create and administer accounts for practices, dentists, providers, specialists, and authorized staff.
- Authenticate users, enforce multi-factor authentication, and secure accounts.
- Process subscriptions, billing, invoices, and payment-related communications.
- Enable referral coordination, secure file exchange, clinical messaging, patient-directed message delivery, workflow management, and audit logging.
- Send transactional communications such as verification codes, password resets, security alerts, billing notices, service announcements, administrative notices, and support responses.
- Detect, prevent, investigate, and respond to security incidents, fraud, abuse, unauthorized access, or policy violations.
- Comply with legal, regulatory, contractual, tax, accounting, professional, and HIPAA-related obligations.
- Analyze usage trends, improve performance, develop features, troubleshoot issues, and create aggregated, anonymized, or de-identified information for internal analytics and product improvement.
- Send marketing, educational, or product updates where permitted by law and subject to applicable opt-out rights.
DDSALLY does not use PHI for marketing except as expressly permitted by HIPAA, the applicable BAA, the relevant dental practice’s lawful instructions, and applicable law.
DDSALLY does not sell PHI.
5. How We Share Information
With Authorized Practices and Users
The Service is collaborative. Referral content, messages, patient-directed communications, attachments, and related workflow information may be visible to authorized users at the sending practice, receiving practice, and other authorized practices selected within the referral workflow. Practice administrators may view user activity, access history, and audit information associated with their practice account.
With Patients at a Practice’s Direction
DDSALLY may transmit secure messages, records, images, instructions, referral updates, or other information to a patient only when directed by a practice or authorized provider. The sending practice is responsible for determining whether the communication is appropriate, whether the recipient information is accurate, and whether any required patient consent, authorization, acknowledgment, or other legal basis has been obtained.
With Service Providers and Subprocessors
DDSALLY may share information with service providers and subprocessors that help host, secure, support, analyze, bill for, or operate the Service. DDSALLY requires service providers and subprocessors to protect information through appropriate contractual, technical, and organizational safeguards. Where a service provider or subprocessor creates, receives, maintains, or transmits PHI on DDSALLY’s behalf, DDSALLY will require appropriate HIPAA protections, including a BAA where required.
DDSALLY maintains a list of subprocessors that may process PHI or materially support the Service. DDSALLY makes that list available through the Service, on a designated webpage, during onboarding, or upon reasonable request to privacy@ddsally.com.
Cloud Infrastructure
DDSALLY may use AWS or similar cloud infrastructure providers for hosting, storage, databases, logging, encryption, identity services, email delivery, backup, and related infrastructure. DDSALLY processes PHI only through services and configurations intended to support HIPAA compliance, including HIPAA-eligible services where required and applicable BAA coverage.
Payment Processors
Stripe or another payment processor may process payment and billing information. DDSALLY does not intentionally provide PHI to payment processors, and users should not include PHI in billing fields, invoice notes, payment metadata, or payment communications.
Error Monitoring, Analytics, and Performance Tools
DDSALLY configures error monitoring, analytics, logging, and performance tools to avoid, minimize, scrub, aggregate, de-identify, or otherwise protect PHI as appropriate. Users should not enter PHI into free-text support, billing, or technical fields unless the field is specifically intended for clinical or referral content within the secure Service.
Legal and Safety Disclosures
DDSALLY may disclose information when reasonably necessary to comply with law, regulation, legal process, subpoena, court order, governmental request, professional obligation, or contractual obligation; protect the rights, safety, or property of DDSALLY, practices, users, patients, or others; detect or prevent fraud, abuse, security incidents, or unauthorized access; or enforce DDSALLY’s Terms of Service, BAA, or other agreements.
Business Transfers
If DDSALLY is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to applicable law, BAA obligations, confidentiality protections, and appropriate safeguards.
No Sale or Cross-Context Behavioral Advertising
DDSALLY does not sell personal information as “sale” is commonly defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”). DDSALLY does not share personal information for cross-context behavioral advertising. DDSALLY does not sell PHI.
6. HIPAA and Patient Information
DDSALLY may receive, create, maintain, transmit, or store PHI for dental practices. In that role, DDSALLY is a Business Associate, and the dental practice is generally the Covered Entity or the entity responsible for the patient relationship.
DDSALLY will use and disclose PHI only as permitted by the applicable BAA, HIPAA, the practice’s lawful instructions through the Service, and applicable law.
Dental practices are responsible for ensuring they have the legal right to submit patient information to the Service and to send patient-facing communications through the Service. This includes responsibility for any patient authorization, consent, acknowledgment, notice, or legal basis required by HIPAA, state privacy laws, dental practice laws, professional obligations, or payer requirements.
Patients who have privacy-rights requests involving PHI should generally contact the dental practice that provided, received, or controls the patient’s information. DDSALLY may direct patient requests to the relevant practice unless DDSALLY is required by law or the applicable BAA to respond directly.
7. Data Retention
DDSALLY retains information for as long as necessary to provide the Service, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, support security, maintain audit logs, and meet clinical, referral, contractual, tax, accounting, professional, and HIPAA-related obligations.
Clinical referral content, patient-directed messages, attachments, imaging, DICOM files, PDFs, notes, referral communications, and related clinical or operational communications may be retained as part of the sending or receiving practice’s clinical, referral, or designated record set for the longer of HIPAA retention requirements, applicable state dental record retention laws, payer or professional requirements, contractual obligations, and special rules for minors.
Audit logs are retained for at least six years or longer if required by law, contract, security needs, litigation hold, investigation needs, or HIPAA-related obligations.
Billing and accounting records are retained as required by tax, accounting, and business laws.
Closed-account personal identifiers may be deleted, anonymized, or restricted upon request where legally permissible. However, deletion will not compromise required clinical records, referral records, audit logs, security evidence, backup systems, legal holds, or records retained on behalf of another practice.
Backup copies may persist for a limited period according to DDSALLY’s backup and disaster recovery procedures, unless longer retention is required by law, contract, security, or compliance obligations.
8. Security
DDSALLY implements administrative, technical, and physical safeguards designed to protect information, including safeguards aligned with the HIPAA Security Rule. These safeguards may include encryption in transit and at rest, role-based access controls, unique user accounts, multi-factor authentication, audit logs, vulnerability management, secure backup and recovery controls, least-privilege access, vendor risk management, workforce access controls, and incident response procedures.
DDSALLY maintains policies and procedures intended to prevent, detect, respond to, and mitigate unauthorized access, inappropriate disclosure, loss, misuse, or alteration of information.
No system can be guaranteed completely secure. Users and practices must maintain strong passwords, protect credentials, use multi-factor authentication where required or available, promptly remove access for departing staff, assign appropriate user roles, verify recipient information before sending PHI, avoid uploading unnecessary PHI, and notify DDSALLY immediately of suspected unauthorized access or security incidents at security@ddsally.com.
DDSALLY’s obligations regarding HIPAA security incidents, breaches, reporting, mitigation, and cooperation are governed by the applicable BAA and applicable law.
9. Cookies and Tracking Technologies
DDSALLY may use cookies, local storage, and similar technologies to maintain authenticated sessions, remember preferences, improve performance, detect fraud, secure the Service, understand usage, and support administrative functions.
Essential cookies are required for the Service to function. Non-essential analytics or marketing cookies, if used, will be implemented in accordance with applicable law and consent requirements.
Users can control cookies through browser settings. Disabling essential cookies may prevent the Service from working properly.
DDSALLY honors legally required opt-out preference signals, such as Global Privacy Control, where applicable.
DDSALLY does not knowingly use tracking technologies to collect PHI for advertising or cross-context behavioral advertising.
10. Your Privacy Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of certain personal information.
California residents may have additional rights under the CCPA/CPRA, including the right to know the categories of personal information collected, the categories of sources, the business or commercial purposes for collection, the categories of third parties to whom information is disclosed, the categories of information disclosed, applicable retention practices, and the right to request access, correction, deletion, or portability of certain personal information.
DDSALLY may collect the following categories of personal information, depending on how you use the Service:
- Identifiers, such as name, email address, phone number, account credentials, IP address, and practice affiliation.
- Professional or employment-related information, such as role, specialty, license information, NPI, practice affiliation, and administrator status.
- Commercial information, such as subscription plan, billing contact, invoice history, and transaction metadata.
- Internet or electronic network activity information, such as login events, device information, pages viewed, workflow activity, and usage data.
- Geolocation information, limited to approximate location inferred from IP address.
- Sensitive personal information, such as login credentials and account security information. DDSALLY does not use sensitive personal information to infer characteristics.
- Clinical or health-related information submitted by practices or authorized users, which may include PHI and is governed by the applicable BAA.
DDSALLY uses these categories of information for the purposes described in this Policy, including providing the Service, securing accounts, supporting referral workflows, processing billing, complying with legal obligations, preventing fraud or misuse, supporting audit logs, and improving the Service.
DDSALLY does not sell personal information. DDSALLY does not share personal information for cross-context behavioral advertising. DDSALLY does not sell PHI.
To exercise privacy rights, contact privacy@ddsally.com from the email address associated with your account. DDSALLY may need to verify your identity, role, and authority before fulfilling a request.
Requests involving PHI may need to be directed to the relevant dental practice, because the dental practice is generally responsible for patient rights under HIPAA and applicable state privacy laws.
DDSALLY will not discriminate against individuals for exercising privacy rights protected by applicable law.
11. International Users
DDSALLY is designed for use in the United States and stores information in the United States unless otherwise stated.
If you access the Service from outside the United States, you understand that information may be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
DDSALLY does not currently represent that the Service is designed for use outside the United States or for compliance with non-U.S. healthcare privacy laws unless separately agreed in writing.
12. Children’s Privacy
The Service is not intended for use by children or by anyone under 18. DDSALLY does not knowingly collect personal information directly from children through account registration.
Patient information about minors may be processed only when submitted by authorized dental professionals and is governed by the applicable BAA, HIPAA, state dental record laws, professional obligations, and the relevant practice’s patient-facing privacy obligations.
13. Changes to This Policy
DDSALLY may update this Policy from time to time. Material changes will be posted on the website or communicated to practice administrators or users by email, in-product notice, or other appropriate method where required.
For changes materially affecting PHI, patient-directed messaging, subprocessors, security practices, data sharing, or privacy rights, DDSALLY will provide notice as required by applicable law, the applicable BAA, and DDSALLY’s agreements with practices.
Continued use of the Service after the effective date of a revised Policy means the revised Policy applies going forward, except where additional notice, consent, amendment, or agreement is required by law or contract.
14. Contact
Privacy Officer: privacy@ddsally.com
Security: security@ddsally.com
Support: support@ddsally.com
Legal: legal@ddsally.com
Mailing Address:
DDSALLY LLC
1601 N. Sepulveda Blvd., #398
Manhattan Beach, CA 90266
USA
