Privacy Policy
Patient Education

Privacy Policy

03_Privacy_Policy


AMII Platform Privacy Policy

Operated by [AMII LEGAL ENTITY NAME]

DRAFT FOR LEGAL AND SECURITY REVIEW

Effective date: July 23, 2026. Replace all bracketed fields before publication.

1. Scope

This Privacy Policy explains how [AMII LEGAL ENTITY NAME] (“AMII,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects information when individuals use AMII Platform, related mobile applications, websites, portals, and services (collectively, the “Services”).

Developer and privacy contact: [PRIVACY EMAIL]

Business address: [BUSINESS POSTAL ADDRESS]

Public website: [PUBLIC WEBSITE DOMAIN]

2. Information We Collect

Account and Contact Information

We may collect names, email addresses, phone numbers, login information, role information, profile images, account identifiers, membership or customer numbers, and home, personal, work, or mailing addresses.

Dental, Health, and Clinical Information

We may collect dental service requests, treatment categories, tooth numbers or oral areas, patient charts, clinical notes, chart logs, treatment plans, treatment status, surgery information, follow-up information, appointment history, reservation history, patient lifecycle information, provider observations, and other information supplied by patients or authorized dental professionals.

Insurance and Identification Information

We may collect insurance provider details, policy and group numbers, member IDs, subscriber information, expiration dates, no-insurance selections, identification document details, issuing jurisdiction, document numbers, names on documents, validity information, and front and back images of insurance or identification documents.

Reservations, Offers, Promotions, and Communications

We collect reservation requests, appointment dates, availability selections, provider responses, rejection reasons, proposed times, offers, promotion decisions, notification activity, education activity, and communications necessary to operate the Services.

Feedback and User Content

We collect ratings, written feedback, uploaded images, notes, support requests, and other content users submit. A rating may be automatically recorded as five stars when a completed visit remains unrated for seven days, as described in the App. An automatic rating contains no fabricated written review and may be replaced by the patient.

Technical, Security, and Usage Information

Depending on the production configuration, we may collect IP address, browser type, device type, operating system, app version, session and authentication events, crash reports, performance information, audit logs, security events, and feature interactions. Final App Store and Google Play disclosures must reflect the production build and integrated service providers.

3. How We Collect Information

• Directly from patients, dentists, AMII personnel, and authorized account users.

• From Microsoft Entra ID or another approved identity provider when a user signs in.

• From a dentist or dental practice participating in a patient-requested workflow.

• Automatically from the App, browser, servers, security controls, and approved service providers.

• From lawful administrative, compliance, audit, or support processes.

4. How We Use Information

• Create, authenticate, secure, and manage accounts.

• Provide role-based access to patient, dentist, operations, and administrative functions.

• Process reservations, appointment requests, provider responses, scheduling, check-in, checkout, treatment, and follow-up.

• Allow authorized dentists to review insurance and identification documents and maintain patient charts and clinical logs.

• Provide offers, promotions, education, notifications, service messages, and requested communications.

• Process ratings and feedback and improve service quality.

• Prevent fraud, protect the Services, investigate misuse, troubleshoot errors, and maintain audit history.

• Comply with legal, regulatory, professional, contractual, and record-retention obligations.

We do not use health, treatment, clinical, insurance, or identification information for behavioral advertising, unrelated marketing, cross-app tracking, or sale to data brokers.

5. How We Disclose Information

Dentists and Dental Providers

We disclose information to a dentist or dental practice when necessary to process a patient-requested reservation, review documents, coordinate treatment or follow-up, maintain a patient chart, or provide other requested dental services. Participating providers may have independent legal and professional obligations concerning patient records.

AMII Personnel

Authorized AMII Operations, administrative, support, security, and compliance personnel may access information according to role-based permissions and job responsibilities.

Service Providers and Subprocessors

We use contracted vendors to provide authentication, hosting, database, storage, communications, app distribution, security, support, and related operational services. These vendors may process information only for authorized purposes and are expected to provide appropriate confidentiality and security protections. The current list is published in the AMII Subprocessor List.

Legal, Safety, and Business Requirements

We may disclose information when required by law, court order, subpoena, professional obligation, regulatory request, or when reasonably necessary to protect patients, users, providers, AMII, or the public. We may transfer information in connection with a merger, acquisition, financing, reorganization, or sale, subject to applicable privacy obligations.

6. Health and Sensitive Information

Dental, clinical, insurance, identification, and related information is sensitive. We limit access according to role, workflow, and legitimate need. We do not sell this information or use it for third-party advertising. Where healthcare privacy laws, including HIPAA or state medical-record laws, apply, AMII and participating providers will address their respective obligations through appropriate policies, agreements, and safeguards.

7. Data Security

We use administrative, technical, and organizational safeguards designed to protect information, including role-based authorization, authentication controls, audit history, secure development practices, and encryption in transit. Production claims concerning encryption at rest, backup protection, monitoring, vulnerability management, and incident response must match the final hosting environment.

No system can guarantee absolute security. Users should protect account credentials and promptly report suspected unauthorized access.

8. Retention

We retain information only as long as reasonably necessary for the purposes described in this Policy, including account operation, dental care coordination, legal compliance, fraud prevention, dispute resolution, audit, security, backup, and provider record-retention requirements.

Account and nonclinical profile data will be deleted or de-identified after a valid deletion request, subject to a reasonable processing period and backup cycle. Clinical, treatment, reservation, insurance, identification, billing, audit, or legal records may be retained when required by law, professional rules, provider obligations, fraud-prevention needs, or legal claims. Access to retained information will be limited and the data will be deleted or de-identified when the retention basis ends.

9. Account and Data Deletion

Users may initiate account deletion within the App and through the public deletion resource at [PUBLIC ACCOUNT-DELETION URL]. A deletion request will be authenticated before processing. AMII will delete or de-identify associated information except information that must be retained for lawful healthcare, insurance, security, fraud-prevention, audit, tax, contractual, or legal reasons.

The production App must make deletion readily discoverable and must not treat account suspension or deactivation as a substitute for deletion.

10. User Choices and Rights

• Access and update profile information.

• Upload, replace, or manage insurance and identification documents where the workflow permits.

• Control optional profile images, feedback, marketing preferences, and notification settings.

• Request access, correction, deletion, restriction, or a copy of information where applicable law provides those rights.

• Withdraw consent for optional processing, without affecting processing already lawfully completed.

Privacy requests may be submitted to [PRIVACY EMAIL]. We may verify identity before acting on a request.

11. Communications and Marketing

We may send service-related messages about accounts, reservations, treatment, follow-up, documents, security, and policy changes. Optional promotional communications may be sent using contact information, membership status, service area, or user-selected preferences. Clinical notes, treatment records, insurance documents, identification documents, and other sensitive health data will not be used for behavioral advertising or unrelated marketing.

12. Device Permissions

The App may request camera or photo access when a user chooses to upload a profile image, insurance card, or identification document. The App should request permissions only when needed and provide alternatives where practical. Precise device location, contacts, microphone, health sensors, HealthKit, and Health Connect are not part of the current core functionality unless expressly added and disclosed in a future version.

13. Children and Minors

The Services are not intended for independent use by children under 13. Where services are provided for a minor, a parent, guardian, or legally authorized person should create or manage the account and provide required permissions. AMII and participating providers may apply additional age, consent, and record requirements.

14. International Processing

Information may be processed in the United States and other locations where AMII or its approved service providers operate. We will use appropriate safeguards where required by applicable law.

15. Changes to This Policy

We may update this Policy to reflect changes in the Services, law, technology, or data practices. We will post the revised effective date and provide additional notice when required.

16. Contact

Privacy inquiries: [PRIVACY EMAIL]

Support: [SUPPORT EMAIL]

Mail: [BUSINESS POSTAL ADDRESS]

  1. Public account deletion: [PUBLIC ACCOUNT-DELETION URL]
Privacy Policy body 2
Click Here(CTA)
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.