LEGAL

Privacy Policy

Last Updated: March 20, 2026  |  Effective Date: March 20, 2026

HIPAA Compliant
GDPR Compliant
SSL Encrypted
No PHI Stored Without Consent
1

Introduction

This Privacy Policy explains how MyDigitalAgency1 — by Svibor 2 d.o.o. ("we," "us," or "our"), the company behind the DentiAI platform and website at https://denti-ai.chat, collects, uses, stores, and protects your personal information when you visit our website or use our AI-powered dental e-assistant services.

We are committed to protecting your privacy and to complying with all applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Union and European Economic Area, and the Health Insurance Portability and Accountability Act (HIPAA) for our dental practice clients and their patients in the United States.

By using our website or services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please discontinue use of our services.

HIPAA Notice

DentiAI acts as a Business Associate under HIPAA when providing AI chat and automation services to covered dental entities. We enter into a Business Associate Agreement (BAA) with all dental practice clients prior to processing any Protected Health Information (PHI). We do not use or disclose PHI except as permitted by the BAA and applicable law.

2

Who We Are

The data controller responsible for your personal data is:

Company Name
MyDigitalAgency1
by Svibor 2 d.o.o.
Location
Slovenia, Europe
Website
https://denti-ai.chat
Privacy Contact
info@denti-ai.chat

We operate the DentiAI platform — an AI-powered dental e-assistant that provides 24/7 chat support, automated appointment booking, patient communication, and related digital marketing services to dental practices primarily in the United States.

3

Data We Collect

We collect different types of data depending on how you interact with our website and services. The categories of data we collect include:

3.1 Data You Provide Directly

Contact information: Name, email address, phone number, WhatsApp number, and dental clinic name — collected when you submit a contact form, sign up for a free trial, or request information.
Business information: Dental practice name, website URL, location, and service preferences — collected during onboarding and account setup.
Communication data: Messages, inquiries, and correspondence you send to us via contact forms, email, or chat.
Payment information: Billing details processed securely through our payment processor. We do not store full credit card numbers on our servers.

3.2 Data Collected Automatically

Technical data: IP address, browser type, device type, operating system, referring URLs, and pages visited — collected automatically when you access our website.
Usage data: Pages viewed, links clicked, time spent on pages, and interaction patterns — collected via analytics tools to improve our services.
Cookie data: Session cookies, preference cookies, and analytics cookies — see Section 9 for details.

3.3 Patient Data (PHI) — Dental Practice Clients Only

Protected Health Information (PHI)

When DentiAI is deployed on a dental practice's website, the AI assistant may interact with patients and collect information such as appointment requests, dental concerns, and contact details. This information may constitute Protected Health Information (PHI) under HIPAA. Such data is:

Processed only under a signed Business Associate Agreement (BAA) with the dental practice
Transmitted and stored using AES-256 encryption at rest and TLS 1.2+ in transit
Never sold, rented, or shared with third parties for marketing purposes
Accessible only to authorized personnel and the dental practice that owns the data
Retained only for the period specified in the BAA or as required by applicable law
4

How We Use Your Data

We use the personal data we collect for the following purposes:

PurposeLegal Basis (GDPR)Data Used
Providing and managing our servicesContract performanceContact info, business info
Processing free trial and order requestsContract performanceContact info, payment info
Responding to inquiries and support requestsLegitimate interestContact info, communication data
Sending service-related communicationsContract performanceEmail, phone
Sending marketing communications (with consent)ConsentEmail address
Improving our website and servicesLegitimate interestUsage data, technical data
Complying with legal obligationsLegal obligationAll applicable data
Fraud prevention and securityLegitimate interestTechnical data, usage data

We will never use your data for purposes incompatible with those listed above without first obtaining your explicit consent.

5

HIPAA Compliance

DentiAI is designed to support dental practices in maintaining their HIPAA compliance obligations. As a Business Associate under 45 CFR § 160.103, we implement the following safeguards:

5.1 Administrative Safeguards

Designated Privacy and Security Officer responsible for HIPAA compliance oversight
Workforce training on HIPAA Privacy and Security Rules
Access controls limiting PHI access to authorized personnel only
Incident response procedures for potential PHI breaches
Business Associate Agreements (BAA) executed with all covered dental entity clients

5.2 Physical Safeguards

PHI is stored on secure cloud infrastructure with physical access controls
Workstation and device security policies for all personnel accessing PHI
Media disposal procedures ensuring PHI is permanently destroyed when no longer needed

5.3 Technical Safeguards

Encryption: AES-256 encryption for data at rest; TLS 1.2+ for data in transit
Access controls: Role-based access with multi-factor authentication (MFA)
Audit logs: Comprehensive logging of all access to PHI with timestamps
Automatic logoff: Sessions automatically terminate after periods of inactivity
Integrity controls: Mechanisms to detect unauthorized alteration or destruction of PHI
Business Associate Agreement (BAA)

All dental practices using DentiAI services that involve PHI must execute a Business Associate Agreement before going live. The BAA defines the permitted uses and disclosures of PHI, our obligations to safeguard PHI, and breach notification procedures. To request a BAA, contact us at info@denti-ai.chat.

5.4 Breach Notification

In the event of a breach of unsecured PHI, we will notify the affected dental practice (Covered Entity) without unreasonable delay and no later than 60 days following discovery of the breach, as required by the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414). The notification will include the information required by 45 CFR § 164.410.

6

GDPR — Your Rights (EU/EEA Users)

As a company registered in Slovenia, European Union, we are subject to the General Data Protection Regulation (GDPR). If you are located in the EU or EEA, you have the following rights regarding your personal data:

RightDescription
Right of AccessYou may request a copy of the personal data we hold about you.
Right to RectificationYou may request correction of inaccurate or incomplete personal data.
Right to ErasureYou may request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
Right to RestrictionYou may request that we restrict processing of your data in certain circumstances.
Right to Data PortabilityYou may request your data in a structured, machine-readable format for transfer to another controller.
Right to ObjectYou may object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw ConsentWhere processing is based on consent, you may withdraw it at any time without affecting prior processing.
Right to Lodge a ComplaintYou may lodge a complaint with the Slovenian Information Commissioner (IP RS) or your local supervisory authority.

To exercise any of these rights, please contact us at info@denti-ai.chat. We will respond to your request within 30 days. In complex cases, we may extend this period by a further 60 days, with prior notice.

⚠️ Note: The Slovenian supervisory authority is the Information Commissioner of the Republic of Slovenia (IP RS), Dunajska cesta 22, 1000 Ljubljana, Slovenia. Website: www.ip-rs.si

7

Data Sharing & Disclosure

We do not sell, rent, or trade your personal data to third parties. We share your data only in the following limited circumstances:

Service Providers (Subprocessors): We engage trusted third-party providers for hosting, analytics, email delivery, payment processing, and customer support. All subprocessors are bound by data processing agreements and may only process data as instructed by us.
Dental Practice Clients: When you interact with a DentiAI-powered chat on a dental practice's website, relevant conversation data is shared with that dental practice as the data controller for patient communications.
Legal Requirements: We may disclose data when required by law, court order, or governmental authority, or to protect our legal rights and interests.
Business Transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected users in advance.

Key Subprocessors

ProviderPurposeLocation
Cloud Hosting ProviderInfrastructure & data storageUSA / EU
Payment ProcessorSecure payment handlingUSA
Email Service ProviderTransactional & marketing emailsUSA / EU
Analytics ProviderWebsite usage analytics (anonymized)EU
AI/LLM ProviderAI chat processing (no PHI without BAA)USA

A full list of current subprocessors is available upon request at info@denti-ai.chat.

8

Data Security

We implement industry-standard technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security measures include:

Encryption: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS). Data stored on our servers is encrypted at rest using AES-256.
Access Controls: Strict role-based access controls ensure that only authorized personnel can access personal data. Multi-factor authentication (MFA) is required for all system access.
Regular Security Audits: We conduct regular vulnerability assessments and penetration testing to identify and address security weaknesses.
Incident Response: We maintain a documented incident response plan for security breaches, including procedures for containment, investigation, and notification.
Secure Development: Our software development follows secure coding practices, including code reviews and security testing before deployment.

⚠️ While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but commit to promptly notifying affected users in the event of a data breach as required by applicable law.

9

Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience and analyze website traffic. A cookie is a small text file stored on your device by your browser.

Cookie TypePurposeDuration
Essential CookiesRequired for the website to function (e.g., session management, security). Cannot be disabled.Session
Analytics CookiesCollect anonymized data about how visitors use our website (e.g., pages visited, time on site). Used to improve our services.Up to 2 years
Preference CookiesRemember your settings and preferences (e.g., language, region) for a better experience.Up to 1 year
Marketing CookiesUsed to deliver relevant advertisements and track campaign effectiveness. Only set with your consent.Up to 90 days

You can control and manage cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website. For EU/EEA users, we obtain your consent before setting non-essential cookies in accordance with the GDPR and the ePrivacy Directive.

10

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our general retention periods are:

Data CategoryRetention PeriodBasis
Contact form submissions3 years from submissionLegitimate interest
Customer account dataDuration of contract + 5 yearsLegal obligation
Billing & payment records7 yearsLegal obligation (tax law)
Website analytics data26 months (anonymized)Legitimate interest
Marketing consent recordsUntil consent withdrawn + 3 yearsLegal obligation
PHI (dental patient data)Per BAA terms / applicable state lawHIPAA / contract
Security & audit logs1 yearSecurity / legal obligation

When data is no longer required, we securely delete or anonymize it in accordance with our data disposal procedures.

11

Third-Party Services & Links

Our website and services may contain links to third-party websites, social media platforms, or integrate with third-party services (such as Facebook Messenger, Instagram, Google, or SMS providers). This Privacy Policy applies only to our website and services. We are not responsible for the privacy practices of third-party websites or services.

We encourage you to review the privacy policies of any third-party services you interact with. When our AI assistant integrates with platforms such as Facebook Messenger or Instagram DMs, those interactions are also subject to the respective platform's privacy policies (Meta Privacy Policy, etc.).

For international data transfers outside the EU/EEA (e.g., to US-based service providers), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or we rely on providers certified under equivalent frameworks.

12

Children's Privacy

Our services are intended for dental practice owners, managers, and adult patients. We do not knowingly collect personal data from children under the age of 13 (or under 16 in the EU/EEA, where applicable). If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at info@denti-ai.chat and we will promptly delete such information.

Dental practices using DentiAI are responsible for ensuring that their use of our services complies with applicable laws regarding the collection of data from minors, including COPPA (Children's Online Privacy Protection Act) in the United States.

13

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

Update the "Last Updated" date at the top of this page
Post the revised policy on this page with reasonable notice before the changes take effect
Notify registered users and dental practice clients by email for significant changes

Your continued use of our website or services after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. We encourage you to review this page periodically to stay informed about how we protect your information.

14

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Team:

Company
MyDigitalAgency1
by Svibor 2 d.o.o.
Slovenia, Europe
Email
info@denti-ai.chat
We respond within 5 business days
Website
https://denti-ai.chat
Contact Page
denti-ai.chat/contact/

For HIPAA-related inquiries, BAA requests, or to report a potential privacy incident, please email info@denti-ai.chat with the subject line "HIPAA Privacy Request". We take all privacy concerns seriously and will respond promptly.