info
This is a starter template tailored for a commission-tracking app used by contractor dentists. Replace the bracketed placeholders with your specifics, and have qualified legal counsel review it before publishing or pointing app stores at it.
Privacy Policy
Effective date: [EFFECTIVE DATE]
1. Overview
This Privacy Policy describes how [YOUR ORG NAME] ("we", "us", or "our") collects, uses, and protects information when you use the ChairTime DDS mobile application and any associated backend services (collectively, the "Service"). The Service is intended for use by licensed dental professionals — including contractor dentists, associate dentists, and other commission-paid practitioners — who need to track their own production and commission across one or more clinics.
By using the Service you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information we collect
We collect only what is necessary to log your jobs, calculate your commission, and keep your records secure.
- Account information — your name, email, professional title, and authentication credentials.
- Contracted clinics & commission rates — the practices you work at and the contract terms you have configured (commission percentages, pay periods, deductions).
- Job logs — the procedures, production amounts, and clinical notes you enter or dictate, including any patient identifiers you choose to record.
- Voice recordings — audio captured when you use dictation features in the Service.
- Device & diagnostic data — device model, OS version, app version, locale, crash logs, and non-identifying performance metrics.
- Usage data — anonymized signals such as feature interactions and screen views, used to improve the Service.
3. How we use your information
- To provide, maintain, and improve the Service.
- To transcribe voice recordings into structured job entries when you invoke dictation.
- To calculate commission estimates and pay-period totals based on the contracts you configure.
- To synchronize content across your devices, where you have enabled sync.
- To respond to support requests and communicate important Service notices.
- To detect, prevent, and address technical issues, fraud, and abuse.
4. Protected Health Information (PHI) and HIPAA
ChairTime DDS is designed primarily to track your work — production, commission, and pay-period totals. However, the job-log feature lets you attach clinical notes and patient identifiers to individual entries, which may constitute Protected Health Information (PHI) under the U.S. Health Insurance Portability and Accountability Act of 1996 ("HIPAA").
We treat any PHI you enter with elevated controls:
- PHI is stored in an encrypted local database on your device.
- Audit logging records access to PHI within the application.
- Network transmission of PHI is restricted to channels that we cover under a Business Associate Agreement.
You are responsible for using the Service consistent with your obligations to your patients and the clinics you contract with. If your use of the Service requires a Business Associate Agreement (BAA), please contact [CONTACT EMAIL] to request one before processing PHI through the Service.
5. Voice recordings
Voice recordings are captured locally on your device when you actively engage the dictation feature. Recordings may be transmitted to our transcription provider for the sole purpose of generating a structured job entry, and are deleted from transcription infrastructure after the entry has been returned and confirmed.
We do not use your voice recordings, transcripts, job logs, or commission data to train external machine-learning models. You may delete recordings and transcripts at any time from within the Service.
6. How we share information
We do not sell your personal information, your commission data, or any PHI you enter. We share information only in the following limited circumstances:
- With service providers (hosting, transcription, crash reporting) who process information on our behalf under written agreements that include confidentiality, security, and — where PHI is involved — Business Associate obligations.
- To comply with applicable law, lawful requests, or legal process.
- To protect the rights, property, or safety of [YOUR ORG NAME], our users, or the public.
- In connection with a merger, acquisition, or sale of assets, with notice to affected users.
We never share your contract terms, commission rates, or earnings totals with the clinics you work at.
7. Data retention and deletion
You control your job logs, voice recordings, and contract data. You can delete individual entries or your entire account from within the Service. After account deletion, we retain residual backups for up to [RETENTION WINDOW] days for disaster recovery, after which they are purged.
De-identified, aggregated metrics (e.g., total jobs processed in a month across the user base) may be retained indefinitely for product analytics, since they cannot be linked back to you, your patients, or your earnings.
8. Security
We protect your information using a combination of technical and organizational measures:
- TLS encryption in transit between the Service and our backend.
- Encryption at rest for the on-device database that holds job logs and contract data.
- Optional biometric and PIN screen-lock to protect the Service when your device is unattended.
- Multi-factor authentication for accounts that opt in.
- Internal audit logging for access to PHI within the HIPAA-aware mode.
No system can be guaranteed 100% secure. You are responsible for keeping your device, OS, and credentials up to date.
9. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete the personal information we hold about you. To exercise these rights, contact [CONTACT EMAIL].
Where the Service is used to record information about your patients, those patients' rights are exercised through the clinic that holds the underlying patient record, not through us directly.
10. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at [CONTACT EMAIL] and we will take appropriate steps to delete it.
11. International users
The Service is operated from [JURISDICTION]. If you access the Service from another country, you understand that your information may be processed in [JURISDICTION] and other countries where our service providers operate, which may have different data-protection laws than your country.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version here and revise the "Effective date" above. Material changes will be communicated through the Service or by email. Your continued use of the Service after the updated policy takes effect constitutes acceptance of the changes.
13. Contact
Questions about this policy or our privacy practices?
[YOUR ORG NAME]
[MAILING ADDRESS]
[CONTACT EMAIL]
arrow_back
Back to chairtime.app