04_Data_Usage_Collection_and_Sharing
AMII Platform — Data Usage, Collection & Sharing Policy
Detailed operational data-handling notice
DRAFT FOR REVIEW
Effective date: July 23, 2026. This policy is designed to accompany, not replace, the AMII Privacy Policy.
1. Principles
• Collect only information reasonably necessary for a defined App, care-coordination, security, legal, or user-requested purpose.
• Use sensitive information only for the purpose disclosed at collection or another legally permitted purpose.
• Limit access by role, workflow, and legitimate need.
• Do not sell personal information or health information.
• Do not use health, treatment, clinical, insurance, or identification data for behavioral advertising or cross-app tracking.
• Provide users with clear controls, correction options, and deletion mechanisms.
2. Authentication and Account Management
We collect account identifiers, name, email, phone, role, profile information, login events, and authentication tokens to create accounts, sign users in, apply role-based permissions, protect the Services, and recover or manage accounts.
Microsoft Entra ID may process identifiers and authentication information for Microsoft sign-in. AMII Operations users may be assigned roles based on approved organizational identity information.
3. Profiles and Addresses
Patients and dentists may provide profile images, personal addresses, work addresses, city, state, ZIP code, and contact information. We use these data for account personalization, provider-service areas, reservation coordination, communication, and operational support.
4. Booking, Reservations, and Availability
We collect selected address, treatment category, requested dates and times, availability selections, provider responses, deadlines, statuses, rejection reasons, proposed times, notes, and reservation history. We use them to submit requests, connect users to providers, schedule appointments, manage provider availability, confirm visits, and maintain audit history.
A selected or assigned dentist receives the information needed to review and act on a reservation. Other dentists are not permitted to access that dentist’s reservations, charts, treatments, offers, availability, or feedback.
5. Insurance and Identification Documents
Patients may upload front and back images and structured information for insurance and identification documents. The App may reuse an existing unexpired document and skip unnecessary upload steps. Dentists may view the exact documents attached to a reservation, including expired or invalid documents, when necessary to review or reject the request.
These documents are not used for advertising. Access is limited to authorized patient, dentist, operations, security, support, or compliance workflows.
6. Patient Charts, Chart Logs, and Treatments
Authorized dentists may create and view patient charts, reservation-linked chart logs, selected tooth numbers or oral areas, treatment categories, clinical notes, observations, treatment records, surgery status, and follow-up information. The App enforces current-dentist ownership and workflow sequencing.
Chart and treatment data are used for care coordination, documentation, checkout, follow-up, audit, and patient communication. They are not used for unrelated marketing or advertising.
7. Offers and Promotions
We collect offer assignment, acceptance, rejection, redemption, reservation, and usage history. Promotions may be based on general service area, membership, campaign rules, or user-selected preferences. Sensitive clinical notes, insurance images, identification images, and detailed treatment records should not be used to create advertising profiles.
8. Feedback and Ratings
Patients may submit a rating from zero to five in half-star increments and may provide up to 250 characters of written feedback. Ratings below five require at least 50 characters. If a completed visit remains unrated for seven days, the system may create an automatic five-star rating with no fabricated text. The patient may replace the automatic rating.
The treating dentist may view feedback associated with that dentist’s completed visits. Authorized AMII personnel may use aggregated or moderated feedback for quality, support, compliance, and reporting.
9. Notifications, Education, and Communications
We use account, reservation, treatment, offer, lifecycle, and document status to deliver service-related notifications and relevant educational content. Optional marketing communications require an appropriate legal basis and user choice. Sensitive health information will not be disclosed in insecure message previews or used for unrelated marketing.
10. Technical and Diagnostic Data
Servers and approved service providers may process IP address, device and browser details, app version, timestamps, errors, crash data, performance information, security events, and audit logs. These data are used to operate, secure, troubleshoot, and improve the Services. Any analytics or diagnostics SDK must be inventoried and reflected in App Store and Google Play disclosures.
11. Sharing Categories
Selected Dentists and Dental Practices
We share information necessary to deliver a patient-requested reservation, treatment, document review, follow-up, chart, or care-coordination workflow.
AMII Operations and Administrators
Authorized personnel process information for support, scheduling, provider coordination, offers, promotions, security, audit, compliance, and platform administration.
Subprocessors
Approved vendors may process information for authentication, hosting, storage, database, communications, app distribution, security, or support. They may not use AMII information for their own unrelated advertising or data-broker purposes.
Legal and Safety Disclosures
We may disclose information when legally required or reasonably necessary to protect users, providers, AMII, or the public.
12. Data Not Collected by Default
• Precise GPS location, unless a future version expressly requests and discloses it.
• Phone contacts or address book.
• Microphone or audio recordings.
• Advertising identifiers for cross-app tracking.
• HealthKit or Health Connect data.
• Payment-card or bank-account information, unless a separately disclosed payment feature is added.
13. Retention and Deletion
Retention depends on the type of record and the applicable purpose. Account and nonclinical data are deleted or de-identified after a verified deletion request, subject to processing and backup cycles. Healthcare, clinical, reservation, insurance, identification, security, audit, fraud, and legal records may be retained when required by law, provider obligations, contracts, or legal claims.
Users may request deletion in the App and at [PUBLIC ACCOUNT-DELETION URL]. The public and in-app processes must be operational before store submission.
14. Security and Access Controls
• Microsoft Identity and approved authentication controls.
• Role-based authorization for Patient, Dentist, AMII Operations, and Admin users.
• Current-dentist ownership enforcement.
• HTTPS/TLS for production data transmission.
• Audit and status-history records for sensitive workflows.
• Least-privilege administrative access.
• Secure retention, backup, monitoring, and incident-response controls appropriate to the final hosting environment.
15. Contact
Questions about data collection, use, sharing, or deletion may be sent to [PRIVACY EMAIL].