Effective · 2026-04-18 Last updated · 2026-04-18 Version · 1.0 12 min read · Terms →
Privacy

Privacy Policy

This explains how usdpr. (US Dental Patient Recovery) collects, uses, and protects information when you visit our site, reply to our outreach, or become a client. Patient data we handle on behalf of a dental practice is governed by that practice's privacy notice and our signed Business Associate Agreement — not this policy.

TL;DR We don't sell data. We don't share for ads. Patient data sits behind a signed BAA with encrypted storage, TCPA-compliant rate limits, and instant STOP honoring. Opt out any time.
01What we collect

Information we gather, and from whom.

From dental practices

Practice name, owner name, address, office phone and email, billing contact. Under a signed BAA, we receive the patient list exports the practice sends us (name, phone, email, last visit date).

From patients of our client practices

Only what the practice shares under the BAA. We do not sell, rent, or share this data with anyone except the subprocessors listed below. Replies from patients come into our operator console and into the weekly report.

From website visitors

Standard server request data (IP, user agent, pages viewed), kept briefly. If you email us or book a call, we keep the exchange to honor any opt-out.

02How we use it

Only for what you hired us to do.

  • Run reactivation outreach (text, email, phone) for your practice
  • Send weekly reports on outreach volume, responses, and bookings
  • Bill the practice, comply with our BAA, respond to legal requests
  • Contact dental practice owners about our service — opt out anytime (section 07)

We never use patient data to train models, build audience segments, target ads, or cross-reference with other practices. Every reply you see in your report is a reply sent to your practice.

Core commitment
03Text messages and consent

TCPA compliant. STOP honored. Carrier registered.

Patient texts only go out after the practice confirms the patient's consent, per the Telephone Consumer Protection Act (TCPA) and our A2P 10DLC campaign registration. Every text includes the practice name and "Reply STOP to opt out." STOP is honored immediately and permanently. Texts are rate-limited: max 1 per day, 3 per week, per patient.

If you get outreach from us as a practice owner, reply STOP and we won't text you again.

04Subprocessors

Who else handles the data.

We only share data with services we need to run ours, under written agreements that require HIPAA compliance where patient data is involved:

Twilio
SMS delivery, 10DLC carrier registration, phone number hosting. HIPAA-eligible with BAA.
Resend
Transactional + outreach email delivery. DPA in place; no patient clinical detail in message bodies.
Anthropic
Reply-intent classification and draft suggestions. Zero-data-retention tier; inputs are not used for training.
Stripe
Card tokenization and subscription billing. PCI-DSS Level 1; we never see card numbers.
HelloSign
BAA + Service Agreement e-signing. Signed documents stored encrypted, retained for audit.
Fly.io
Application hosting on encrypted volumes, US-only regions, with IAM-scoped keys.

We do not sell data. We do not share data for cross-site advertising. We do not enroll patient data in any analytics, remarketing, or audience tool.

05Security

Built to the HIPAA Security Rule.

Data at rest on encrypted volumes. Data in transit uses TLS 1.2+. Access is role-based with least-privilege defaults. Every send, reply, and booking is logged with an immutable audit trail. Soft-delete semantics mean no record disappears in a hurry. We have a written incident-response plan tested quarterly. We don't store payment card data — payments go through a PCI-DSS Level 1 processor.

Our full security page →

06Retention

Patient data lives as long as the BAA does.

At the end of the engagement we return or destroy the data per the BAA. Our own business records (invoices, prospect emails) we keep up to seven years for tax and contractual purposes, unless you ask us to delete them.

07Your choices

Opt out anytime.

  • Email: reply "REMOVE" to any of our messages — removed within 10 business days
  • Text: reply "STOP" to any of our texts — immediate and permanent
  • Patient rights: if you're a patient of one of our client practices, contact that practice directly
  • Data export: active clients can download their full data (patients, messages, replies, bookings) any time from the dashboard
08Children

We don't collect from minors directly.

Practices may share minor-patient contact data under the BAA using the parental consent mechanisms they control. We don't collect data from children directly.

09Jurisdiction

Florida law. Orange County venue.

We operate under Florida law. Any dispute is resolved in Orange County, Florida courts. Nothing here limits rights you have under HIPAA, the Florida Information Protection Act of 2014, or other applicable law.

10Changes

When we update, we date the change.

We update this policy from time to time. The "Last updated" date at the top reflects any change. We email active clients when something material changes, with a plain-English summary of what's different.

11Contact

Questions or complaints.

usdpr. — US Dental Patient Recovery
Orlando, FL
colin@usdentalpatientrecovery.com

About this document. This policy is a living document reviewed by Florida healthcare counsel before any client data moves. It is not a substitute for independent legal advice for your practice. If you spot something unclear, email us — we'll fix it.