Privacy Policy
Last Updated: March 20, 2026 | Effective Date: March 20, 2026
Introduction
This Privacy Policy explains how MyDigitalAgency1 — by Svibor 2 d.o.o. ("we," "us," or "our"), the company behind the DentiAI platform and website at https://denti-ai.chat, collects, uses, stores, and protects your personal information when you visit our website or use our AI-powered dental e-assistant services.
We are committed to protecting your privacy and to complying with all applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Union and European Economic Area, and the Health Insurance Portability and Accountability Act (HIPAA) for our dental practice clients and their patients in the United States.
By using our website or services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please discontinue use of our services.
DentiAI acts as a Business Associate under HIPAA when providing AI chat and automation services to covered dental entities. We enter into a Business Associate Agreement (BAA) with all dental practice clients prior to processing any Protected Health Information (PHI). We do not use or disclose PHI except as permitted by the BAA and applicable law.
Who We Are
The data controller responsible for your personal data is:
We operate the DentiAI platform — an AI-powered dental e-assistant that provides 24/7 chat support, automated appointment booking, patient communication, and related digital marketing services to dental practices primarily in the United States.
Data We Collect
We collect different types of data depending on how you interact with our website and services. The categories of data we collect include:
3.1 Data You Provide Directly
3.2 Data Collected Automatically
3.3 Patient Data (PHI) — Dental Practice Clients Only
When DentiAI is deployed on a dental practice's website, the AI assistant may interact with patients and collect information such as appointment requests, dental concerns, and contact details. This information may constitute Protected Health Information (PHI) under HIPAA. Such data is:
How We Use Your Data
We use the personal data we collect for the following purposes:
| Purpose | Legal Basis (GDPR) | Data Used |
|---|---|---|
| Providing and managing our services | Contract performance | Contact info, business info |
| Processing free trial and order requests | Contract performance | Contact info, payment info |
| Responding to inquiries and support requests | Legitimate interest | Contact info, communication data |
| Sending service-related communications | Contract performance | Email, phone |
| Sending marketing communications (with consent) | Consent | Email address |
| Improving our website and services | Legitimate interest | Usage data, technical data |
| Complying with legal obligations | Legal obligation | All applicable data |
| Fraud prevention and security | Legitimate interest | Technical data, usage data |
We will never use your data for purposes incompatible with those listed above without first obtaining your explicit consent.
HIPAA Compliance
DentiAI is designed to support dental practices in maintaining their HIPAA compliance obligations. As a Business Associate under 45 CFR § 160.103, we implement the following safeguards:
5.1 Administrative Safeguards
5.2 Physical Safeguards
5.3 Technical Safeguards
All dental practices using DentiAI services that involve PHI must execute a Business Associate Agreement before going live. The BAA defines the permitted uses and disclosures of PHI, our obligations to safeguard PHI, and breach notification procedures. To request a BAA, contact us at info@denti-ai.chat.
5.4 Breach Notification
In the event of a breach of unsecured PHI, we will notify the affected dental practice (Covered Entity) without unreasonable delay and no later than 60 days following discovery of the breach, as required by the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414). The notification will include the information required by 45 CFR § 164.410.
GDPR — Your Rights (EU/EEA Users)
As a company registered in Slovenia, European Union, we are subject to the General Data Protection Regulation (GDPR). If you are located in the EU or EEA, you have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Right of Access | You may request a copy of the personal data we hold about you. |
| Right to Rectification | You may request correction of inaccurate or incomplete personal data. |
| Right to Erasure | You may request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations. |
| Right to Restriction | You may request that we restrict processing of your data in certain circumstances. |
| Right to Data Portability | You may request your data in a structured, machine-readable format for transfer to another controller. |
| Right to Object | You may object to processing based on legitimate interests or for direct marketing purposes. |
| Right to Withdraw Consent | Where processing is based on consent, you may withdraw it at any time without affecting prior processing. |
| Right to Lodge a Complaint | You may lodge a complaint with the Slovenian Information Commissioner (IP RS) or your local supervisory authority. |
To exercise any of these rights, please contact us at info@denti-ai.chat. We will respond to your request within 30 days. In complex cases, we may extend this period by a further 60 days, with prior notice.
⚠️ Note: The Slovenian supervisory authority is the Information Commissioner of the Republic of Slovenia (IP RS), Dunajska cesta 22, 1000 Ljubljana, Slovenia. Website: www.ip-rs.si
Data Sharing & Disclosure
We do not sell, rent, or trade your personal data to third parties. We share your data only in the following limited circumstances:
Key Subprocessors
| Provider | Purpose | Location |
|---|---|---|
| Cloud Hosting Provider | Infrastructure & data storage | USA / EU |
| Payment Processor | Secure payment handling | USA |
| Email Service Provider | Transactional & marketing emails | USA / EU |
| Analytics Provider | Website usage analytics (anonymized) | EU |
| AI/LLM Provider | AI chat processing (no PHI without BAA) | USA |
A full list of current subprocessors is available upon request at info@denti-ai.chat.
Data Security
We implement industry-standard technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security measures include:
⚠️ While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but commit to promptly notifying affected users in the event of a data breach as required by applicable law.
Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience and analyze website traffic. A cookie is a small text file stored on your device by your browser.
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential Cookies | Required for the website to function (e.g., session management, security). Cannot be disabled. | Session |
| Analytics Cookies | Collect anonymized data about how visitors use our website (e.g., pages visited, time on site). Used to improve our services. | Up to 2 years |
| Preference Cookies | Remember your settings and preferences (e.g., language, region) for a better experience. | Up to 1 year |
| Marketing Cookies | Used to deliver relevant advertisements and track campaign effectiveness. Only set with your consent. | Up to 90 days |
You can control and manage cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website. For EU/EEA users, we obtain your consent before setting non-essential cookies in accordance with the GDPR and the ePrivacy Directive.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our general retention periods are:
| Data Category | Retention Period | Basis |
|---|---|---|
| Contact form submissions | 3 years from submission | Legitimate interest |
| Customer account data | Duration of contract + 5 years | Legal obligation |
| Billing & payment records | 7 years | Legal obligation (tax law) |
| Website analytics data | 26 months (anonymized) | Legitimate interest |
| Marketing consent records | Until consent withdrawn + 3 years | Legal obligation |
| PHI (dental patient data) | Per BAA terms / applicable state law | HIPAA / contract |
| Security & audit logs | 1 year | Security / legal obligation |
When data is no longer required, we securely delete or anonymize it in accordance with our data disposal procedures.
Third-Party Services & Links
Our website and services may contain links to third-party websites, social media platforms, or integrate with third-party services (such as Facebook Messenger, Instagram, Google, or SMS providers). This Privacy Policy applies only to our website and services. We are not responsible for the privacy practices of third-party websites or services.
We encourage you to review the privacy policies of any third-party services you interact with. When our AI assistant integrates with platforms such as Facebook Messenger or Instagram DMs, those interactions are also subject to the respective platform's privacy policies (Meta Privacy Policy, etc.).
For international data transfers outside the EU/EEA (e.g., to US-based service providers), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or we rely on providers certified under equivalent frameworks.
Children's Privacy
Our services are intended for dental practice owners, managers, and adult patients. We do not knowingly collect personal data from children under the age of 13 (or under 16 in the EU/EEA, where applicable). If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at info@denti-ai.chat and we will promptly delete such information.
Dental practices using DentiAI are responsible for ensuring that their use of our services complies with applicable laws regarding the collection of data from minors, including COPPA (Children's Online Privacy Protection Act) in the United States.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
Your continued use of our website or services after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. We encourage you to review this page periodically to stay informed about how we protect your information.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Team:
For HIPAA-related inquiries, BAA requests, or to report a potential privacy incident, please email info@denti-ai.chat with the subject line "HIPAA Privacy Request". We take all privacy concerns seriously and will respond promptly.