Plain-English summary. If you are a patient calling a dental practice that uses this service, your call is answered by an automated system acting for that practice. What you say is used to book, reschedule or triage your call, and to create a record the practice can see. The practice — not us — decides how long that record is kept and who at the practice sees it. We do not sell anything about you to anyone, ever, and we do not use your call to train AI models.
The service is operated by [[FULL LEGAL NAME]], trading as AI Dental Reception, of [[REGISTERED ADDRESS]]. Contact: privacy@receptionistai.health.
When a dental practice uses this service, the practice is the controller of patient information and we are its processor. Under US health privacy law the equivalent terms are covered entity and Business Associate. We handle patient information only on the practice's documented instructions.
On HIPAA, honestly. There is no such thing as being "HIPAA certified", and we do not claim to be. What is true and verifiable is this: the service is designed to operate as a Business Associate, and we will execute a Business Associate Agreement with any practice before real patient calls reach the system. Some of our subprocessors listed in section 6 have executed BAAs with us and some have not yet; the table states which. A practice should not route live patient calls to the service until every subprocessor in that chain is covered. We would rather lose the sale than mislead you on this point.
| Category | Examples | Why |
|---|---|---|
| Caller identity | Name, phone number, date of birth where the practice asks for it | To identify an existing patient and attach the booking to the right record |
| Call content | Audio, and a written transcript of what was said | To carry out the request, and so the practice can review what happened |
| Reason for calling | Symptoms described, appointment type requested | To triage urgency and book the correct appointment length |
| Triage records | Which warning signs were detected and what the caller was told | Safety. These are kept as a permanent audit record — see section 4 |
| Practice information | Hours, services, staff names, calendar availability | To answer accurately. This is not patient information |
| Website visitors | Page requests and approximate location, from server logs | Security and basic traffic counts. The site sets no advertising or analytics cookies |
Some of what a caller says will be health information. That is unavoidable in a dental context — the reason for the call is usually clinical. It is treated accordingly.
The service can record calls and can produce written transcripts. Whether recording is switched on is controlled by the practice.
Practices must decide this before going live. Consent to record a phone call is governed by state law, and states differ: some require only one party to consent, others require all parties. This is a legal question specific to where your practice operates, and we are not able to answer it for you. Where recording is enabled, the system can play a spoken disclosure at the start of the call. We recommend it everywhere and require it where all-party consent applies.
Where the system identifies a potential emergency, it writes a permanent audit entry — what the caller said, which warning signs were detected, what they were told, and when. These entries are not deleted on request, because their purpose is to evidence that a caller in danger was told to seek care. This is a deliberate exception to the deletion rights in section 8, and it exists to protect callers and practices alike.
| What | Kept for |
|---|---|
| Call transcripts and recordings | [[RETENTION PERIOD — a 90-day default purge is implemented; confirm the number with counsel and state it here]] |
| Appointment and patient records | For as long as the practice remains a client, then returned or deleted at the practice's direction |
| Emergency triage audit entries | Retained permanently — see section 4 |
| Website server logs | Short-term, for security purposes only |
We use the following subprocessors. Each receives only what it needs to perform its function.
| Subprocessor | Function | BAA status |
|---|---|---|
| [[VOICE PLATFORM]] | Telephony and speech processing | [[STATUS — update the day it is signed]] |
| [[LLM PROVIDER]] | Understanding and generating the conversation | [[STATUS]] |
| [[SMS PROVIDER]] | Appointment confirmations and reminders | [[STATUS]] |
| [[HOSTING PROVIDER]] | Running the application | [[STATUS]] |
| [[DATABASE PROVIDER]] | Storing appointment and call records | [[STATUS]] |
Our infrastructure is located in [[REGION]]. The service is operated from [[OPERATING COUNTRY]], which means personal information may be accessed from outside the country where the practice and its patients are located. Where that transfer requires a safeguard, we rely on [[MECHANISM — for example standard contractual clauses]]. A practice that requires all processing and access to remain within a single jurisdiction should tell us before signing, because that is a configuration decision and not always possible.
No system is perfectly secure. If a breach affects a practice's patient information we will notify that practice without undue delay and within the timeframe our agreement with them requires.
Patients should contact their dental practice, not us. The practice holds the relationship and the record, and it decides these requests; we act on its instruction. If you contact us directly we will pass your request to the practice and tell you we have done so.
Depending on where you live, those rights may include access to a copy, correction, deletion, restriction, portability, and objection to certain processing — and the right to complain to a regulator. Exercising them will not cause you to be treated differently. The one exception is the emergency triage audit record described in section 4.
Dental practices treat children, so the service will handle information about minors when a parent or guardian calls to arrange care. It is not directed at children and does not knowingly collect information directly from a child.
Material changes will be notified to practices in advance of taking effect. The date at the top of this page always reflects the current version.
Privacy questions: privacy@receptionistai.health
Security reports and BAA requests: security@receptionistai.health
Postal: [[REGISTERED ADDRESS]]