Privacy Policy
This explains how usdpr. (US Dental Patient Recovery) collects, uses, and protects information when you visit our site, reply to our outreach, or become a client. Patient data we handle on behalf of a dental practice is governed by that practice's privacy notice and our signed Business Associate Agreement — not this policy.
Information we gather, and from whom.
From dental practices
Practice name, owner name, address, office phone and email, billing contact. Under a signed BAA, we receive the patient list exports the practice sends us (name, phone, email, last visit date).
From patients of our client practices
Only what the practice shares under the BAA. We do not sell, rent, or share this data with anyone except the subprocessors listed below. Replies from patients come into our operator console and into the weekly report.
From website visitors
Standard server request data (IP, user agent, pages viewed), kept briefly. If you email us or book a call, we keep the exchange to honor any opt-out.
Only for what you hired us to do.
- Run reactivation outreach (text, email, phone) for your practice
- Send weekly reports on outreach volume, responses, and bookings
- Bill the practice, comply with our BAA, respond to legal requests
- Contact dental practice owners about our service — opt out anytime (section 07)
We never use patient data to train models, build audience segments, target ads, or cross-reference with other practices. Every reply you see in your report is a reply sent to your practice.
Core commitmentTCPA compliant. STOP honored. Carrier registered.
Patient texts only go out after the practice confirms the patient's consent, per the Telephone Consumer Protection Act (TCPA) and our A2P 10DLC campaign registration. Every text includes the practice name and "Reply STOP to opt out." STOP is honored immediately and permanently. Texts are rate-limited: max 1 per day, 3 per week, per patient.
If you get outreach from us as a practice owner, reply STOP and we won't text you again.
Who else handles the data.
We only share data with services we need to run ours, under written agreements that require HIPAA compliance where patient data is involved:
- Twilio
- SMS delivery, 10DLC carrier registration, phone number hosting. HIPAA-eligible with BAA.
- Resend
- Transactional + outreach email delivery. DPA in place; no patient clinical detail in message bodies.
- Anthropic
- Reply-intent classification and draft suggestions. Zero-data-retention tier; inputs are not used for training.
- Stripe
- Card tokenization and subscription billing. PCI-DSS Level 1; we never see card numbers.
- HelloSign
- BAA + Service Agreement e-signing. Signed documents stored encrypted, retained for audit.
- Fly.io
- Application hosting on encrypted volumes, US-only regions, with IAM-scoped keys.
We do not sell data. We do not share data for cross-site advertising. We do not enroll patient data in any analytics, remarketing, or audience tool.
Built to the HIPAA Security Rule.
Data at rest on encrypted volumes. Data in transit uses TLS 1.2+. Access is role-based with least-privilege defaults. Every send, reply, and booking is logged with an immutable audit trail. Soft-delete semantics mean no record disappears in a hurry. We have a written incident-response plan tested quarterly. We don't store payment card data — payments go through a PCI-DSS Level 1 processor.
Patient data lives as long as the BAA does.
At the end of the engagement we return or destroy the data per the BAA. Our own business records (invoices, prospect emails) we keep up to seven years for tax and contractual purposes, unless you ask us to delete them.
Opt out anytime.
- Email: reply "REMOVE" to any of our messages — removed within 10 business days
- Text: reply "STOP" to any of our texts — immediate and permanent
- Patient rights: if you're a patient of one of our client practices, contact that practice directly
- Data export: active clients can download their full data (patients, messages, replies, bookings) any time from the dashboard
We don't collect from minors directly.
Practices may share minor-patient contact data under the BAA using the parental consent mechanisms they control. We don't collect data from children directly.
Florida law. Orange County venue.
We operate under Florida law. Any dispute is resolved in Orange County, Florida courts. Nothing here limits rights you have under HIPAA, the Florida Information Protection Act of 2014, or other applicable law.
When we update, we date the change.
We update this policy from time to time. The "Last updated" date at the top reflects any change. We email active clients when something material changes, with a plain-English summary of what's different.
Questions or complaints.
usdpr. — US Dental Patient Recovery
Orlando, FL
colin@usdentalpatientrecovery.com