1. Introduction
PatientArc is operated by PatientArc, Inc.. We help dental practices manage front-office workflows — schedule protection, recall, patient communication, insurance preparation, and claim follow-up. This policy explains what we collect, how we use it, and the choices available to practices and the people who work in them.
PatientArc supports administrative dental workflows across the patient journey. It does not provide clinical advice, diagnose patients, submit claims autonomously, guarantee insurance coverage, or send patient-facing messages without staff approval. PatientArc does not diagnose patients, prescribe treatment, or replace clinical judgment. AI features assist with administrative drafting, summarization, and prioritization only.
This policy is informational and does not constitute legal advice. Practices remain responsible for their own legal, regulatory, and patient-consent obligations.
2. Data we collect
We collect the following categories of data:
- Account data — name, email, password credentials, role, and authentication identifiers for users who sign in to PatientArc.
- Practice data — practice name, location details a practice chooses to enter, business contact information, and configuration settings.
- User profile data — display name, role at the practice, communication preferences, and signed-in session metadata.
- Patient workflow data entered by users — records, notes, and identifiers that practice staff enter or import in order to run their workflows.
- Schedule and import data — appointments, cancellations, openings, and structured imports uploaded by practice staff.
- Recall lists — patient names and contact details flagged for recall, hygiene, and overdue follow-up.
- Patient communication content — message drafts, sent messages, and message history relating to appointment confirmations, recall, and follow-ups.
- Insurance and admin task data — verification notes, eligibility details staff record, and task status.
- Claim preparation data — pre-submission details and follow-up notes practice staff create or upload.
- Support, contact, and sales form data — the name, email, practice name, role, message, and metadata you submit through https://patientarc.site forms.
- Usage and device data — pages viewed, features used, error reports, IP address, browser, and operating system, used to operate and improve the service.
- Cookie and analytics data — see Section 7.
- Billing and payment data — if billing is enabled, billing contact information and payment metadata returned by the payment processor. We do not store full payment card numbers.
3. Patient and practice content
Patient and practice content entered into PatientArc is processed on behalf of the dental practice that controls the account. Practices are responsible for having the legal rights and patient permissions necessary to upload, store, and process that content.
Practices remain the data controller for patient information they enter. PatientArc, Inc. acts as a service provider that processes that information to deliver the workflows the practice has configured.
4. AI feature usage
PatientArc uses AI to assist with administrative workflows such as scheduling, recall, messaging drafts, and insurance follow-ups. Patient data is never used to train third-party foundation models.
- AI may draft, summarize, classify, or prioritize operational content (for example, suggesting recall messages or grouping insurance tasks).
- AI does not diagnose patients or make clinical recommendations. AI outputs are administrative.
- AI outputs should be reviewed by qualified staff before being acted upon.
- Patient-facing messages generated with AI assistance require staff approval where the workflow exposes that approval step.
- Sensitive information should be handled with the same caution practices apply to other administrative systems. Avoid entering content that is not necessary for the workflow.
5. How we use data
We use the data described above to:
- provide, operate, and secure the service;
- authenticate users and protect accounts;
- organize schedule, recall, messaging, insurance, and claim workflows that practices have configured;
- generate AI-assisted drafts, summaries, and prioritization for staff review;
- send transactional emails (for example, account notifications, password resets, and confirmations of requests submitted through our forms);
- respond to and manage support and sales requests;
- monitor reliability and improve the product;
- comply with legal, regulatory, and contractual obligations.
6. Third-party services
PatientArc relies on a small number of service categories to operate. The specific vendors used depend on what is configured for a given deployment:
- Authentication, database, and storage — a managed backend platform is used for authentication, database, and file storage where configured.
- Email sending — a transactional email provider is used to send transactional and (where users have opted in) marketing emails when an email provider is configured.
- AI feature providers — model providers reached through a managed AI drafting service are used for AI-assisted drafting, summarization, and prioritization where AI features are enabled.
- Analytics and cookie tools — privacy-aware analytics and cookie management tooling may be used where configured, only after the visitor has opted in.
We only describe categories that are actually wired into the product. Vendors that are not configured for a given workspace are not in the data path for that workspace.
8. Marketing communications
Marketing communications from PatientArc are opt-in:
- Signing up for PatientArc does not automatically subscribe you to marketing emails.
- Submitting a contact, sales, or support form does not automatically subscribe you to marketing emails. Those forms generate a transactional confirmation only.
- Marketing consent is explicit and unchecked by default. You choose which categories (newsletter, product updates, educational guides) you want to receive.
- Unsubscribing is available without logging in via the link included in every marketing email.
- Email preferences can be managed without logging in via a secure, time-limited link sent to your email address.
Transactional emails (for example, password resets and security notices) are separate from marketing preferences and will continue while your account is active.
9. Data retention
PII is retained for 7 years per HIPAA-aligned recordkeeping guidelines. System logs are retained for 30 days.
Retention windows apply to production data in PatientArc. On a verified deletion request, we remove data from active systems and schedule deletion from backups in line with our backup rotation, subject to applicable legal and audit obligations.
10. Security
PatientArc applies the following technical and organizational controls to protect practice and patient workflow data:
- Encryption — AES-256 for data at rest; TLS 1.3 in transit.
- Access — MFA is required for all users. SAML 2.0 SSO is available for enterprise clients.
- Data residency — production data is hosted in AWS US-East-1.
- Subprocessors — AWS (hosting and storage), Twilio (SMS and voice delivery), and Stripe (billing).
Authority boundary. PatientArc organizes front-desk work, prepares drafts, flags missing next steps, and groups patient journey tasks for staff review across recall, communication, benefits, and claim prep. It does not diagnose patients, replace clinical judgment, guarantee insurance coverage, submit claims automatically, send patient-facing messages without staff approval, or decide care, billing, or treatment actions on its own.
Escalation. Conflicting patient data triggers a Review Required flag and notifies the Practice Manager by push notification.
PatientArc is not a HIPAA-certified product. HIPAA is referenced only in the context of the recordkeeping guidelines that inform our data retention windows and patient-data handling practices. If you need documentation about a specific control, contact privacy@patientarc.site.
No system can guarantee absolute security. Practices should follow good security practices on their own devices, browsers, and accounts.
11. Your rights
Depending on the laws that apply to you and your practice, you may be able to:
- request access to personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your account and associated data;
- request an export of personal data in a portable format;
- change your email and marketing preferences at any time.
Patient data is generally controlled by the practice. Patient rights requests should be directed to the practice that entered the data. We support practices in fulfilling those requests.
To exercise your rights, contact privacy@patientarc.site. We may need to verify your identity before acting on a request.
12. Children
PatientArc is built for dental practices and the business users who staff them. It is not directed to children, and we do not knowingly create accounts for children. Patient information about minors that a practice enters is handled under the practice's clinical and legal obligations to those patients and their guardians.
13. International use
PatientArc is provided from the jurisdiction set out in our terms (the State of Arizona, United States). If you access PatientArc from a different country, you understand that your information may be processed in jurisdictions whose laws differ from your own.
We do not claim coverage under regulatory frameworks we have not implemented. Practices subject to specific regional requirements should confirm that PatientArc fits their obligations before entering regulated data.
14. Changes to this policy
We may update this policy as the product evolves or as legal requirements change. The current version is always posted at patientarc.site/privacy with the "Last updated" date at the top of this page. Material changes will be communicated through the product or by email to account owners where appropriate.
15. Contact
Get in touch on the right channel for the topic. We monitor each inbox separately so requests reach the right team faster.
Privacy and data requests
privacy@patientarc.siteCookie questions
privacy@patientarc.siteGeneral product support
support@patientarc.site
Operated by PatientArc, Inc..
Contact