1. Introduction
ZoellioDental is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when using our cloud-based dental practice management platform. We comply with HIPAA (Health Insurance Portability and Accountability Act), GDPR (General Data Protection Regulation), CCPA (California Consumer Privacy Act), and state-specific healthcare privacy laws.
2. Information We Collect
We collect practice information (name, address, phone, billing), professional user information (credentials, login data, activity logs), patient information (demographics, medical history, treatment plans, prescriptions, imaging, insurance), technical information (browser, IP address, device info), and communication records (emails, chat, support tickets).
3. How We Use Your Information
We use information to provide Service features, ensure compliance with healthcare regulations, improve Service functionality, conduct research on de-identified data, manage accounts and billing, send service updates, and manage subscriptions. We do not use data for marketing without your opt-in consent.
4. Data Sharing and Disclosure
We do NOT sell patient data. We share information only with service providers under data processing agreements, insurance companies for claims (with authorization), pharmacy partners for prescriptions, and legal authorities when required by law. We do not allow data brokers to access patient records.
5. Data Retention
Active account data is retained while your account is active. Patient records are retained per healthcare record retention requirements (typically 6 years minimum). Financial records are retained for 7 years for tax compliance. Upon termination, patient data is retained for the legal period then securely deleted. Audit logs are retained for 1 year.
6. Your Rights (GDPR, CCPA)
You have rights to: access your data in portable format (30 days), correct inaccurate data, request deletion (subject to retention requirements), restrict processing, receive data portability, object to marketing communications, and avoid automated decision-making. Submit requests to privacy@zoelliodental.com with identity verification.
7. Cookies and Tracking Technologies
We use essential cookies (required for functionality), analytics cookies (understand usage), and optional marketing cookies (require consent). You can disable non-essential cookies in browser settings. We use Google Analytics for de-identified aggregate metrics only.
8. Data Security
We implement AES-256 encryption at rest, TLS 1.3 in transit, role-based access controls, multi-factor authentication, regular security assessments, SOC 2 Type II compliance, intrusion detection, and automatic backup testing. You are responsible for password confidentiality and reporting suspicious activity.
9. International Data Transfers
Data is primarily stored in US data centers with optional EU data residency for GDPR compliance. We rely on Standard Contractual Clauses for GDPR-regulated data transfers. We maintain regular assessment of transfer mechanisms and regulatory requirements.
10. Contact Us
For privacy questions: ZoellioDental Privacy Department, privacy@zoelliodental.com. Response time: 30 days for verified requests. For GDPR-related inquiries (EU users), please contact your data protection representative. For CCPA-related inquiries (California users), please use the contact form above.