Customer-controlled data
Customers control the patient, provider, workforce, and business data they place in the Service.
Privacy, healthcare data, and trust
How DentalXpand collects, uses, discloses, and protects information across our website, dental operations platform, integrations, and AI-assisted workflows.
This Policy is not a dental practice Notice of Privacy Practices and is not a substitute for a Business Associate Agreement. When DentalXpand processes protected health information for a customer, the applicable Business Associate Agreement, Data Processing Addendum, Order Form, and customer instructions govern that processing and control if they conflict with this Policy.
Customers control the patient, provider, workforce, and business data they place in the Service.
We do not use Service Data for cross-context behavioral advertising or sell it to data brokers.
AI output is assistive. Healthcare, employment, payment, and credentialing decisions require qualified human review.
Individuals may have access, correction, deletion, restriction, portability, objection, and appeal rights.
DentalXpand provides business software for dental organizations, dental service organizations, billing and credentialing teams, providers, and their authorized workforce. This Policy explains our practices when DentalXpand determines why and how information is processed, and when we process information for a customer under that customer's instructions.
This Policy applies to xpand.dental and other DentalXpand websites that link to it, the hosted and desktop DentalXpand applications, related support and implementation services, and the integrations and features described here (collectively, the "Service"). It does not govern a third-party website, payer portal, clearinghouse, practice-management system, or service that publishes its own privacy notice.
DentalXpand generally determines the purposes and means of processing for website visits, sales and demo inquiries, account administration, billing, security, product operations, support communications, and our own business records. In those contexts, references to "we," "us," and "DentalXpand" mean the DentalXpand provider identified in the applicable Order Form, invoice, or contracting document.
A subscribing dental practice, DSO, billing company, employer, or other organization (the "Customer") generally determines why Customer Content is entered into the Service, who may access it, which modules and integrations are enabled, and how long it should be retained. For that data, DentalXpand acts as a processor, service provider, contractor, or business associate as applicable. Requests about Customer Content should normally be directed first to the Customer that controls the workspace.
If an Order Form, Data Processing Addendum (DPA), Business Associate Agreement (BAA), or other signed agreement addresses a topic differently, that signed agreement controls for the covered Customer and data.
The information processed depends on the modules, integrations, permissions, and deployment selected by a Customer. A workspace may use only a subset of the categories below.
| Category | Examples | Primary context |
|---|---|---|
| Website and inquiry data | Name, business email, phone, organization, inquiry type, message, demo request, support request, and privacy acknowledgement. | Contact forms, email, phone, and sales conversations. |
| Account and organization data | Name, work email, role, permissions, organization, practice, team, subscription, branding, settings, authentication records, and last login. | Account setup, access control, tenant administration, and billing. |
| Patient and insurance data | Patient or subscriber name, date of birth, member and group identifiers, relationship, payer, coverage, benefits, treatment history, claims, dates of service, EOB or ERA content, and verification results. | Eligibility, VOB, claims, AR, billing, and Auto Verify workflows. |
| Provider and credentialing data | Identity and contact details, NPI, tax identifiers, licenses, DEA and Medicaid identifiers, CAQH information, education, work history, malpractice and disclosure information, addresses, signatures, government IDs, banking details, documents, packet status, and payer submissions. | Provider management, credentialing, enrollment, and practice administration. |
| Workforce and HR data | Employee profile, contact and emergency details, date of birth, department, compensation, attendance, shifts, tasks, time entries, leave, loans, expenses, notices, agreements, complaints, recruitment evaluations, and applicant details. | HR, team, attendance, finance, recruitment, and support workflows. |
| Communications and collaboration | Chats, comments, email addresses, email content, call notes, meeting details, participant status, voice notes, attachments, screen shares, recordings when enabled, support tickets, and notifications. | Messages, meetings, Gmail outreach, calendar, support, and collaboration. |
| Business and financial operations | Revenue, expenses, invoices, payment status, client agreements, BAA records, task performance, reports, leads, business contact details, and outreach history. | Finance, reporting, agreements, marketing, lead generation, and CRM. |
| Files and workspace content | Uploaded documents, PDFs, images, spreadsheets, receipts, resumes, credentialing documents, agreements, generated reports, form data, and metadata. | Data vault, documents, credentialing, billing, HR, and reports. |
| Device, usage, and audit data | IP address, user agent, device identifier and label, operating system, app version, online status, access time, feature activity, error logs, support-session reason, security events, and audit records. | Authentication, presence, support, troubleshooting, fraud prevention, and security. |
| AI interaction data | Prompts, recent conversation context, selected workspace context, uploaded images or documents, extracted text, model output, feedback, and sanitized review-queue records where enabled. | Xpand AI, document extraction, workflow assistance, and reviewed learning features. |
If website comments are enabled, WordPress may collect the comment, display name, email address, optional website, IP address, user agent, moderation status, and a cookie preference. To display an avatar, an email-derived hash and browser request may be sent to the Gravatar service operated by Automattic. Public comments and profile links are visible to other visitors after approval.
We use Personal Information and Service Data as reasonably necessary to:
We do not use PHI or Google user data for advertising. We do not use Customer Content to make unrelated determinations about an individual's eligibility for credit, employment, insurance, housing, or healthcare.
Where a law requires a legal basis, DentalXpand relies on one or more of the following, depending on context:
For Customer Content, the Customer determines the applicable lawful basis and is responsible for notices, authorizations, consents, and other legal conditions required for collection and use.
DentalXpand can process healthcare data in eligibility, VOB, claim, billing, AR, document, communication, and AI-assisted workflows. When that information is PHI and DentalXpand acts as a business associate, we process it under an executed BAA and applicable Customer instructions. The BAA defines permitted uses and disclosures, safeguards, incident reporting, subcontractor obligations, return or destruction, and assistance with individual rights.
Do not place patient names, dates of birth, member IDs, claim details, clinical information, or other PHI in the public contact form, blog comments, or ordinary sales email. Authorized Customers should use approved support and Service channels.
DentalXpand is not the dental provider, payer, or plan that determines patient care or benefits. Patients seeking access, amendment, restriction, or an accounting for PHI should contact the dental practice, plan, or other covered entity responsible for their record. We will assist that Customer as required by the BAA and applicable law.
A Customer may not submit PHI until the parties have executed any BAA required for the intended use. Customer administrators must configure permissions, integrations, exports, and retention consistent with minimum-necessary access and their own privacy obligations.
When an Authorized User chooses to connect a Google account, DentalXpand requests the account identity and the scopes needed for enabled user-facing features. The current integration can request basic account identity, permission to send email through Gmail, and permission to create, read, update, and delete events on the user's primary Google Calendar. The precise scopes appear on Google's authorization screen.
DentalXpand's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide or improve prominent, user-facing connection features. We do not sell it, use it for advertising, transfer it to data brokers, use it to determine creditworthiness, or permit human reading except with the user's affirmative agreement for specific data, for security or support where permitted, to comply with law, or in aggregated form for lawful internal operations.
An Authorized User can disconnect through the Service where available and can revoke DentalXpand access in Google Account security settings. Revocation prevents new Google API access but may not automatically delete outreach, calendar, audit, or business records already created in the Customer workspace. The Customer may request deletion subject to legal and contractual retention requirements.
Xpand AI and document-assistance features may process prompts, recent conversation history, selected employee, provider, verification, practice, or operational context, and text extracted from images or documents. Depending on Customer configuration, processing may occur through a Customer-selected local model endpoint or a remote model provider. Customer administrators are responsible for selecting an authorized deployment and ensuring the applicable contract and BAA permit the data sent to it.
AI output can be incomplete, outdated, or incorrect. It is intended to assist qualified users, not replace professional judgment. DentalXpand does not intend AI features to independently make decisions that produce legal or similarly significant effects. Users must verify eligibility, coverage, claim, coding, payment, credentialing, employment, financial, and patient-related output before acting on it.
If a Customer enables continuous-learning or review-queue features, the Service may create a sanitized record of a prompt, context, answer, rating, user role, and operational metadata for human review. Automated masking is designed to remove obvious identifiers such as email addresses, phone numbers, Social Security numbers, dates of birth, member or claim identifiers, names, dates, and long IDs, and raw attachments are not intended to enter that learning queue. Masking is not guaranteed to identify every sensitive detail.
Only approved records may be promoted to retrieval knowledge or model-improvement material for the authorized environment. Customers must not enable reviewed learning for PHI or other restricted data unless the applicable agreement, BAA, configuration, and law expressly permit it. DentalXpand does not use Google user data for generalized AI model training.
Customers may enable task timers, attendance, device presence, and desktop work-diary features for their workforce. Depending on configuration and the user's device, those features can process:
The tracking interface is intended to display that tracking is active. Customer administrators and other users with permission may review these records. DentalXpand supplies the tool, but the Customer is the party that decides whether and how to monitor its workforce.
Before enabling monitoring, each Customer must determine whether it is lawful, provide clear advance notice, obtain any required consent, limit collection to legitimate business purposes, avoid capturing unrelated or privileged material, define retention, and honor employment, labor, wiretap, biometric, and privacy rights in every applicable jurisdiction.
We disclose information only as described below, as directed by a Customer, or with appropriate authorization:
DentalXpand does not sell Personal Information or Service Data to data brokers and does not share it for cross-context behavioral advertising. We do not use PHI, credentialing records, workforce monitoring data, or Google user data for targeted advertising. If our practices materially change, we will update this Policy and provide any notice or choice required by law.
The website and Service use cookies, local storage, session storage, and related technology to keep sessions active, secure accounts, remember preferences, and support requested features. Depending on use, stored items can include authentication tokens, user and tenant context, device ID, theme and layout preferences, pinned navigation, view modes, task timers, notification state, scraper job history, recent AI conversation history, and recent workflow or search drafts.
WordPress may set essential login, security, and comment-preference cookies. Browser requests for embedded or connected third-party services are governed by those services' notices. The current DentalXpand marketing theme does not include third-party behavioral advertising pixels. If non-essential analytics or advertising technology is introduced, we will update disclosures and provide consent controls where required.
Browser storage remains on the user's device until it expires, is removed by the Service, or is cleared by the user. Because local workflow drafts may contain sensitive information, users should secure their device, use approved profiles, log out when finished, and avoid shared or public computers.
We retain information only for as long as reasonably necessary for the purpose described, the Customer's instructions and configuration, our agreements, backup and security cycles, dispute resolution, and legal obligations. Actual periods depend on the module and deployment.
| Record | General retention approach |
|---|---|
| Website inquiries and comments | For the time needed to respond, maintain business records, moderate content, prevent abuse, and meet legal obligations. |
| Accounts and subscriptions | For the account term and a reasonable period afterward for billing, audit, security, reactivation, and legal records. |
| Customer Content and PHI | According to the Customer agreement, BAA, workspace configuration, Customer deletion instructions, and applicable record-retention law. |
| Auto Verify audit records | Designed for a short operational audit window, commonly configured around 10 days, unless a Customer setting, contract, incident hold, or law requires otherwise. |
| Time-tracking records and screenshots | Customer configurable. The application includes a default database purge target around 40 days, but deployment settings, storage cleanup, backups, legal holds, or Customer policy may change actual retention. |
| Google connections and records | Connection credentials until disconnection, revocation, or deletion; outreach, calendar, and audit records according to Customer and legal business-record needs. |
| Security and audit logs | For a period proportionate to security investigation, compliance, support, dispute, and legal requirements. |
Deletion from active systems may not immediately remove information from encrypted backups, immutable logs, recipient systems, payer or clearinghouse systems, or Customer-directed exports. Residual copies are isolated from ordinary use and age out under applicable cycles unless preservation is legally required. Deidentified data may be retained where it can no longer reasonably identify an individual.
DentalXpand uses administrative, technical, and organizational measures designed to protect information in light of its sensitivity and the Service's risk profile. Depending on deployment, these measures include authenticated access, role and permission controls, tenant and practice scoping, row-level and storage policies, protected integration credentials, audit logging, time-limited support sessions, backups, transport security, monitoring, and incident response procedures.
No system, transmission, or storage method is completely secure. Customers and users are responsible for strong credentials, secure devices, appropriate permissions, prompt removal of departed users, safe exports, authorized integrations, and reporting suspected misuse. Do not share passwords, API keys, CAQH credentials, OAuth grants, or authentication tokens.
If we confirm an incident affecting information for which notice is legally or contractually required, we will notify the appropriate Customer or affected party as required by the applicable agreement and law. Customers remain responsible for their own regulatory notices unless the BAA or another agreement assigns a specific notice obligation to DentalXpand.
DentalXpand, Customers, Authorized Users, and service providers may operate in different countries. As a result, information can be processed outside the country where it was collected, including in the United States and other locations selected by the Customer's deployment or integrations. Those countries may have different privacy laws.
Where legally required, we use an approved transfer mechanism, such as adequacy decisions, standard contractual clauses, contractual safeguards, or another lawful basis. Customers are responsible for ensuring that their own uploads, exports, remote workforce access, and third-party integrations comply with applicable localization and cross-border transfer restrictions.
Depending on where you live and the context, you may have the right to request access, confirmation, correction, deletion, restriction, objection, portability, withdrawal of consent, an appeal, or information about recipients and processing. You may also have the right not to be discriminated against for exercising a privacy right.
If your information was submitted by your employer, dental practice, provider, plan, or another Customer, contact that organization first. DentalXpand will route or assist with a verified request as required by our contract and law, but we may not be authorized to act independently of the Customer.
For information DentalXpand controls, email contact@xpand.dental with the subject "Privacy Request." Describe the right you wish to exercise and the context in which you interacted with us. We may verify identity and authority, request additional information, deny or limit a request where an exception applies, and retain a record of the request. Authorized agents must provide proof of authority, and we may still verify the individual directly where permitted.
Residents of states with comprehensive privacy laws may have rights to know or access categories and specific pieces of Personal Information, correct inaccuracies, delete information, obtain a portable copy, opt out of certain sale, sharing, targeted advertising, or profiling, limit certain uses of sensitive information, appeal a decision, and receive equal service and pricing.
The categories collected and disclosed for business purposes are described in Sections 3 and 11. DentalXpand does not sell Personal Information, does not share it for cross-context behavioral advertising, and does not use it for targeted advertising. We use sensitive information only for the Service, security, legal, and other permitted business purposes described in this Policy, not to infer unrelated characteristics.
Some state privacy laws exempt PHI, medical information, employment data, business-to-business data, or information processed solely for a Customer. Whether an exemption applies depends on the record and relationship. We will respond to verified requests as required by applicable law and explain any material denial and available appeal process.
If applicable data protection law in the European Economic Area, United Kingdom, or Switzerland governs our processing, you may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent without affecting prior lawful processing. You may also lodge a complaint with your local supervisory authority.
Section 6 describes our legal bases. We do not intend to subject individuals to a decision based solely on automated processing that produces legal or similarly significant effects. If that changes in a specific Customer workflow, the responsible controller must provide the required notice, lawful basis, safeguards, and opportunity for human intervention.
Where DentalXpand is a processor, the Customer is the controller and should receive the request. Where DentalXpand is the controller, use the contact details below. If a representative or data protection contact is legally required for a particular offering, that contact will be identified in the applicable DPA or regional notice.
The website and Service are business products and are not directed to children under 13. Authorized User accounts are intended for adults acting in a professional capacity. We do not knowingly invite children under 13 to create accounts or submit Personal Information directly through the public website.
A dental Customer may submit patient records concerning a minor when legally permitted and necessary for care, billing, eligibility, or related operations. DentalXpand processes those records as Customer Content under the Customer's instructions, applicable agreement, BAA, and healthcare privacy law. A parent or guardian seeking rights concerning such a record should contact the responsible dental practice or covered entity.
If you believe a child submitted information directly to DentalXpand outside an authorized Customer healthcare workflow, contact us so we can investigate and take appropriate action.
We may update this Policy to reflect changes in the Service, law, integrations, or business practices. We will revise the "Last updated" date and provide additional notice through the website, Service, email, or contractual channel where a change is material or consent is required. Continued use after an effective update is subject to applicable law and agreement terms.
Contact us with privacy questions, rights requests, complaints, or concerns about how this Policy applies. Do not include PHI, passwords, API keys, financial account numbers, or other sensitive records in ordinary email.
DentalXpand
The exact contracting provider and formal notice address are identified in the applicable Order Form, invoice, or contracting document.
This Policy is designed to describe the current DentalXpand product and website. It should be reviewed together with the executed Customer agreement, BAA, DPA, security documentation, and deployment configuration.