Skip to content
dentalxpand.io
  • Home
  • Services
  • Features
  • Resources
  • Blog
  • About
  • Contact
Log in Book a demo
Log in Book a demo

Privacy, healthcare data, and trust

Privacy Policy

How DentalXpand collects, uses, discloses, and protects information across our website, dental operations platform, integrations, and AI-assisted workflows.

Effective
July 17, 2026
Last updated
July 17, 2026
Applies to
Website and DentalXpand Service
i

Important healthcare privacy distinction

This Policy is not a dental practice Notice of Privacy Practices and is not a substitute for a Business Associate Agreement. When DentalXpand processes protected health information for a customer, the applicable Business Associate Agreement, Data Processing Addendum, Order Form, and customer instructions govern that processing and control if they conflict with this Policy.

01

Customer-controlled data

Customers control the patient, provider, workforce, and business data they place in the Service.

02

No advertising sale

We do not use Service Data for cross-context behavioral advertising or sell it to data brokers.

03

Human review for AI

AI output is assistive. Healthcare, employment, payment, and credentialing decisions require qualified human review.

04

Rights and choices

Individuals may have access, correction, deletion, restriction, portability, objection, and appeal rights.

On this page

  1. Scope and roles
  2. Key definitions
  3. Information we collect
  4. Sources of information
  5. How we use information
  6. Legal bases
  7. PHI and healthcare data
  8. Google user data
  9. AI-assisted features
  10. Workforce monitoring
  11. How information is disclosed
  12. Cookies and local storage
  13. Retention and deletion
  14. Security
  15. International transfers
  16. Your rights and choices
  17. U.S. state disclosures
  18. EEA, UK, and Swiss rights
  19. Children
  20. Changes and contact

DentalXpand provides business software for dental organizations, dental service organizations, billing and credentialing teams, providers, and their authorized workforce. This Policy explains our practices when DentalXpand determines why and how information is processed, and when we process information for a customer under that customer's instructions.

01

Scope and privacy roles

This Policy applies to xpand.dental and other DentalXpand websites that link to it, the hosted and desktop DentalXpand applications, related support and implementation services, and the integrations and features described here (collectively, the "Service"). It does not govern a third-party website, payer portal, clearinghouse, practice-management system, or service that publishes its own privacy notice.

When DentalXpand acts as a controller or business

DentalXpand generally determines the purposes and means of processing for website visits, sales and demo inquiries, account administration, billing, security, product operations, support communications, and our own business records. In those contexts, references to "we," "us," and "DentalXpand" mean the DentalXpand provider identified in the applicable Order Form, invoice, or contracting document.

When DentalXpand acts for a customer

A subscribing dental practice, DSO, billing company, employer, or other organization (the "Customer") generally determines why Customer Content is entered into the Service, who may access it, which modules and integrations are enabled, and how long it should be retained. For that data, DentalXpand acts as a processor, service provider, contractor, or business associate as applicable. Requests about Customer Content should normally be directed first to the Customer that controls the workspace.

Order of precedence

If an Order Form, Data Processing Addendum (DPA), Business Associate Agreement (BAA), or other signed agreement addresses a topic differently, that signed agreement controls for the covered Customer and data.

02

Key definitions

Personal Information
Information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household.
Customer Content
Information, records, files, messages, prompts, images, and other material submitted to or generated in a Customer workspace.
Service Data
Customer Content plus account, configuration, usage, support, audit, and operational data processed to provide and secure the Service.
PHI
Protected health information regulated by HIPAA when created, received, maintained, or transmitted by a covered entity or business associate in a regulated context.
Authorized User
An employee, contractor, provider, administrator, or other person whom a Customer authorizes to use its workspace.
Deidentified Data
Data that does not identify an individual and cannot reasonably be used to identify one under the standard applicable to that data.
03

Information we collect and process

The information processed depends on the modules, integrations, permissions, and deployment selected by a Customer. A workspace may use only a subset of the categories below.

CategoryExamplesPrimary context
Website and inquiry dataName, business email, phone, organization, inquiry type, message, demo request, support request, and privacy acknowledgement.Contact forms, email, phone, and sales conversations.
Account and organization dataName, work email, role, permissions, organization, practice, team, subscription, branding, settings, authentication records, and last login.Account setup, access control, tenant administration, and billing.
Patient and insurance dataPatient or subscriber name, date of birth, member and group identifiers, relationship, payer, coverage, benefits, treatment history, claims, dates of service, EOB or ERA content, and verification results.Eligibility, VOB, claims, AR, billing, and Auto Verify workflows.
Provider and credentialing dataIdentity and contact details, NPI, tax identifiers, licenses, DEA and Medicaid identifiers, CAQH information, education, work history, malpractice and disclosure information, addresses, signatures, government IDs, banking details, documents, packet status, and payer submissions.Provider management, credentialing, enrollment, and practice administration.
Workforce and HR dataEmployee profile, contact and emergency details, date of birth, department, compensation, attendance, shifts, tasks, time entries, leave, loans, expenses, notices, agreements, complaints, recruitment evaluations, and applicant details.HR, team, attendance, finance, recruitment, and support workflows.
Communications and collaborationChats, comments, email addresses, email content, call notes, meeting details, participant status, voice notes, attachments, screen shares, recordings when enabled, support tickets, and notifications.Messages, meetings, Gmail outreach, calendar, support, and collaboration.
Business and financial operationsRevenue, expenses, invoices, payment status, client agreements, BAA records, task performance, reports, leads, business contact details, and outreach history.Finance, reporting, agreements, marketing, lead generation, and CRM.
Files and workspace contentUploaded documents, PDFs, images, spreadsheets, receipts, resumes, credentialing documents, agreements, generated reports, form data, and metadata.Data vault, documents, credentialing, billing, HR, and reports.
Device, usage, and audit dataIP address, user agent, device identifier and label, operating system, app version, online status, access time, feature activity, error logs, support-session reason, security events, and audit records.Authentication, presence, support, troubleshooting, fraud prevention, and security.
AI interaction dataPrompts, recent conversation context, selected workspace context, uploaded images or documents, extracted text, model output, feedback, and sanitized review-queue records where enabled.Xpand AI, document extraction, workflow assistance, and reviewed learning features.

WordPress comments and avatars

If website comments are enabled, WordPress may collect the comment, display name, email address, optional website, IP address, user agent, moderation status, and a cookie preference. To display an avatar, an email-derived hash and browser request may be sent to the Gravatar service operated by Automattic. Public comments and profile links are visible to other visitors after approval.

04

Sources of information

  • Directly from you, such as when you contact us, create an account, submit a form, upload a file, connect an integration, or communicate with support.
  • From Customers and Authorized Users, such as when an administrator creates a user, a practice submits patient or provider data, or a manager configures workforce features.
  • From connected services, including Google, payer and clearinghouse services, practice-management or Guardian systems, communications services, and other integrations selected by a Customer.
  • From payers, providers, and business counterparties, including eligibility, claim, enrollment, credentialing, and remittance responses.
  • From public or licensed business sources, such as business websites, professional directories, map listings, search results, and job or lead sources used by Customer-directed prospecting tools.
  • Automatically from devices and use, including logs, browser storage, presence, security events, and optional time-tracking evidence.
05

How we use information

We use Personal Information and Service Data as reasonably necessary to:

  • provide, configure, maintain, support, and improve the Service and Customer-requested workflows;
  • authenticate users, enforce permissions, separate tenant data, and administer organizations, practices, roles, and subscriptions;
  • perform eligibility, claim, payment, AR, credentialing, provider, HR, finance, collaboration, reporting, and document functions requested by a Customer;
  • send emails, create calendar events, deliver notifications, and support meetings or calls at an Authorized User's direction;
  • generate reports, populate forms, organize documents, calculate operational metrics, and assist with workflow follow-up;
  • provide AI-assisted answers, extraction, summaries, drafting, and workspace context where the feature is enabled;
  • respond to inquiries, provide support, troubleshoot incidents, and conduct time-limited, reason-documented support access;
  • detect misuse, investigate security events, preserve audit trails, enforce agreements, and comply with law;
  • manage our business, including billing, accounting, product planning, service communications, and legal claims; and
  • create aggregate or deidentified insights that do not identify an individual, subject to applicable contracts and law.

We do not use PHI or Google user data for advertising. We do not use Customer Content to make unrelated determinations about an individual's eligibility for credit, employment, insurance, housing, or healthcare.

06

Legal bases for processing

Where a law requires a legal basis, DentalXpand relies on one or more of the following, depending on context:

  • Contract, to provide the Service, administer accounts, process payments, and fulfill Customer instructions.
  • Legitimate interests, to secure and improve the Service, communicate with business contacts, prevent fraud, support Customers, and operate our business, after considering affected rights.
  • Consent, where you choose an optional integration, marketing communication, cookie, recording, or other activity for which consent is required. Consent may be withdrawn prospectively.
  • Legal obligation, to keep required records, respond to lawful process, protect rights, and satisfy privacy, tax, accounting, security, or regulatory duties.
  • Vital interests or public interest, only where applicable and legally permitted.

For Customer Content, the Customer determines the applicable lawful basis and is responsible for notices, authorizations, consents, and other legal conditions required for collection and use.

07

Protected health information and healthcare data

DentalXpand can process healthcare data in eligibility, VOB, claim, billing, AR, document, communication, and AI-assisted workflows. When that information is PHI and DentalXpand acts as a business associate, we process it under an executed BAA and applicable Customer instructions. The BAA defines permitted uses and disclosures, safeguards, incident reporting, subcontractor obligations, return or destruction, and assistance with individual rights.

Do not send PHI through the public website

Do not place patient names, dates of birth, member IDs, claim details, clinical information, or other PHI in the public contact form, blog comments, or ordinary sales email. Authorized Customers should use approved support and Service channels.

DentalXpand is not the dental provider, payer, or plan that determines patient care or benefits. Patients seeking access, amendment, restriction, or an accounting for PHI should contact the dental practice, plan, or other covered entity responsible for their record. We will assist that Customer as required by the BAA and applicable law.

A Customer may not submit PHI until the parties have executed any BAA required for the intended use. Customer administrators must configure permissions, integrations, exports, and retention consistent with minimum-necessary access and their own privacy obligations.

08

Google user data and connected accounts

When an Authorized User chooses to connect a Google account, DentalXpand requests the account identity and the scopes needed for enabled user-facing features. The current integration can request basic account identity, permission to send email through Gmail, and permission to create, read, update, and delete events on the user's primary Google Calendar. The precise scopes appear on Google's authorization screen.

How Google data is used and stored

  • Account email, granted scopes, connection status, and token expiration are used to display and manage connection status.
  • OAuth access and refresh credentials are stored in protected, encrypted form where the integration is configured.
  • Email recipient, subject, body, status, provider message identifiers, and related outreach records may be stored in the Customer workspace to provide message history and auditing.
  • Calendar title, attendees, time, timezone, description, Google event identifiers, links, and meeting details may be stored to create and synchronize Customer-requested events.

Google API Limited Use

DentalXpand's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide or improve prominent, user-facing connection features. We do not sell it, use it for advertising, transfer it to data brokers, use it to determine creditworthiness, or permit human reading except with the user's affirmative agreement for specific data, for security or support where permitted, to comply with law, or in aggregated form for lawful internal operations.

Disconnecting Google

An Authorized User can disconnect through the Service where available and can revoke DentalXpand access in Google Account security settings. Revocation prevents new Google API access but may not automatically delete outreach, calendar, audit, or business records already created in the Customer workspace. The Customer may request deletion subject to legal and contractual retention requirements.

09

AI-assisted features and automated processing

Xpand AI and document-assistance features may process prompts, recent conversation history, selected employee, provider, verification, practice, or operational context, and text extracted from images or documents. Depending on Customer configuration, processing may occur through a Customer-selected local model endpoint or a remote model provider. Customer administrators are responsible for selecting an authorized deployment and ensuring the applicable contract and BAA permit the data sent to it.

Outputs require human review

AI output can be incomplete, outdated, or incorrect. It is intended to assist qualified users, not replace professional judgment. DentalXpand does not intend AI features to independently make decisions that produce legal or similarly significant effects. Users must verify eligibility, coverage, claim, coding, payment, credentialing, employment, financial, and patient-related output before acting on it.

Reviewed learning features

If a Customer enables continuous-learning or review-queue features, the Service may create a sanitized record of a prompt, context, answer, rating, user role, and operational metadata for human review. Automated masking is designed to remove obvious identifiers such as email addresses, phone numbers, Social Security numbers, dates of birth, member or claim identifiers, names, dates, and long IDs, and raw attachments are not intended to enter that learning queue. Masking is not guaranteed to identify every sensitive detail.

Only approved records may be promoted to retrieval knowledge or model-improvement material for the authorized environment. Customers must not enable reviewed learning for PHI or other restricted data unless the applicable agreement, BAA, configuration, and law expressly permit it. DentalXpand does not use Google user data for generalized AI model training.

10

Time tracking, screenshots, and workforce monitoring

Customers may enable task timers, attendance, device presence, and desktop work-diary features for their workforce. Depending on configuration and the user's device, those features can process:

  • tracker start, pause, resume, and stop times, active and idle duration, task, and activity percentage;
  • periodic desktop screenshots while a user has actively started tracking in the desktop application;
  • active application, window title, and active URL where supported;
  • persistent device identifier, device label, platform, online status, and recent presence; and
  • attendance, shift, hours, overtime, payroll-related calculations, and manager review records.

The tracking interface is intended to display that tracking is active. Customer administrators and other users with permission may review these records. DentalXpand supplies the tool, but the Customer is the party that decides whether and how to monitor its workforce.

Customer notice and consent responsibility

Before enabling monitoring, each Customer must determine whether it is lawful, provide clear advance notice, obtain any required consent, limit collection to legitimate business purposes, avoid capturing unrelated or privileged material, define retention, and honor employment, labor, wiretap, biometric, and privacy rights in every applicable jurisdiction.

11

How we disclose information

We disclose information only as described below, as directed by a Customer, or with appropriate authorization:

  • Within a Customer workspace. Customer administrators, managers, assigned team members, providers, and other Authorized Users may access information according to permissions and workflow assignments.
  • Infrastructure and service providers. Hosting, database, authentication, storage, email, push, communications, meeting, security, error-monitoring, support, and other vendors may process data to provide contracted services to us.
  • Healthcare and operational integrations. At Customer direction, data may be transmitted to payers, clearinghouses, eligibility or claim services, credentialing portals, practice systems, communications providers, and other selected integrations.
  • AI providers. Prompts and selected context may be sent to the configured local or remote model provider when an Authorized User invokes the feature, subject to Customer settings and applicable agreements.
  • Customer-directed recipients. The Service may send emails, calendar invitations, documents, reports, claim or credentialing submissions, and exports to recipients selected by an Authorized User.
  • Professional advisers and authorities. We may disclose information to auditors, insurers, legal counsel, law enforcement, regulators, courts, or other parties where reasonably necessary to comply with law, protect rights or safety, investigate wrongdoing, or establish legal claims.
  • Business transactions. Information may be disclosed in connection with financing, diligence, reorganization, merger, acquisition, or sale, subject to confidentiality, applicable law, and any consent required for Google user data or PHI.

No sale or cross-context behavioral advertising

DentalXpand does not sell Personal Information or Service Data to data brokers and does not share it for cross-context behavioral advertising. We do not use PHI, credentialing records, workforce monitoring data, or Google user data for targeted advertising. If our practices materially change, we will update this Policy and provide any notice or choice required by law.

12

Cookies, browser storage, and similar technology

The website and Service use cookies, local storage, session storage, and related technology to keep sessions active, secure accounts, remember preferences, and support requested features. Depending on use, stored items can include authentication tokens, user and tenant context, device ID, theme and layout preferences, pinned navigation, view modes, task timers, notification state, scraper job history, recent AI conversation history, and recent workflow or search drafts.

WordPress may set essential login, security, and comment-preference cookies. Browser requests for embedded or connected third-party services are governed by those services' notices. The current DentalXpand marketing theme does not include third-party behavioral advertising pixels. If non-essential analytics or advertising technology is introduced, we will update disclosures and provide consent controls where required.

Browser storage remains on the user's device until it expires, is removed by the Service, or is cleared by the user. Because local workflow drafts may contain sensitive information, users should secure their device, use approved profiles, log out when finished, and avoid shared or public computers.

13

Retention and deletion

We retain information only for as long as reasonably necessary for the purpose described, the Customer's instructions and configuration, our agreements, backup and security cycles, dispute resolution, and legal obligations. Actual periods depend on the module and deployment.

RecordGeneral retention approach
Website inquiries and commentsFor the time needed to respond, maintain business records, moderate content, prevent abuse, and meet legal obligations.
Accounts and subscriptionsFor the account term and a reasonable period afterward for billing, audit, security, reactivation, and legal records.
Customer Content and PHIAccording to the Customer agreement, BAA, workspace configuration, Customer deletion instructions, and applicable record-retention law.
Auto Verify audit recordsDesigned for a short operational audit window, commonly configured around 10 days, unless a Customer setting, contract, incident hold, or law requires otherwise.
Time-tracking records and screenshotsCustomer configurable. The application includes a default database purge target around 40 days, but deployment settings, storage cleanup, backups, legal holds, or Customer policy may change actual retention.
Google connections and recordsConnection credentials until disconnection, revocation, or deletion; outreach, calendar, and audit records according to Customer and legal business-record needs.
Security and audit logsFor a period proportionate to security investigation, compliance, support, dispute, and legal requirements.

Deletion from active systems may not immediately remove information from encrypted backups, immutable logs, recipient systems, payer or clearinghouse systems, or Customer-directed exports. Residual copies are isolated from ordinary use and age out under applicable cycles unless preservation is legally required. Deidentified data may be retained where it can no longer reasonably identify an individual.

14

Security and incident response

DentalXpand uses administrative, technical, and organizational measures designed to protect information in light of its sensitivity and the Service's risk profile. Depending on deployment, these measures include authenticated access, role and permission controls, tenant and practice scoping, row-level and storage policies, protected integration credentials, audit logging, time-limited support sessions, backups, transport security, monitoring, and incident response procedures.

No system, transmission, or storage method is completely secure. Customers and users are responsible for strong credentials, secure devices, appropriate permissions, prompt removal of departed users, safe exports, authorized integrations, and reporting suspected misuse. Do not share passwords, API keys, CAQH credentials, OAuth grants, or authentication tokens.

If we confirm an incident affecting information for which notice is legally or contractually required, we will notify the appropriate Customer or affected party as required by the applicable agreement and law. Customers remain responsible for their own regulatory notices unless the BAA or another agreement assigns a specific notice obligation to DentalXpand.

15

International data transfers

DentalXpand, Customers, Authorized Users, and service providers may operate in different countries. As a result, information can be processed outside the country where it was collected, including in the United States and other locations selected by the Customer's deployment or integrations. Those countries may have different privacy laws.

Where legally required, we use an approved transfer mechanism, such as adequacy decisions, standard contractual clauses, contractual safeguards, or another lawful basis. Customers are responsible for ensuring that their own uploads, exports, remote workforce access, and third-party integrations comply with applicable localization and cross-border transfer restrictions.

16

Your privacy rights and choices

Depending on where you live and the context, you may have the right to request access, confirmation, correction, deletion, restriction, objection, portability, withdrawal of consent, an appeal, or information about recipients and processing. You may also have the right not to be discriminated against for exercising a privacy right.

Customer-controlled records

If your information was submitted by your employer, dental practice, provider, plan, or another Customer, contact that organization first. DentalXpand will route or assist with a verified request as required by our contract and law, but we may not be authorized to act independently of the Customer.

Requests to DentalXpand

For information DentalXpand controls, email contact@xpand.dental with the subject "Privacy Request." Describe the right you wish to exercise and the context in which you interacted with us. We may verify identity and authority, request additional information, deny or limit a request where an exception applies, and retain a record of the request. Authorized agents must provide proof of authority, and we may still verify the individual directly where permitted.

Other choices

  • Use the unsubscribe method in a marketing email or contact us to stop promotional messages. Service and security messages may still be sent.
  • Disconnect optional integrations and revoke third-party access through the relevant provider.
  • Manage browser cookies and storage through browser settings, recognizing that essential features may stop working.
  • Ask the Customer administrator about workspace permissions, monitoring, retention, exports, and account deletion.
17

U.S. state privacy disclosures

Residents of states with comprehensive privacy laws may have rights to know or access categories and specific pieces of Personal Information, correct inaccuracies, delete information, obtain a portable copy, opt out of certain sale, sharing, targeted advertising, or profiling, limit certain uses of sensitive information, appeal a decision, and receive equal service and pricing.

The categories collected and disclosed for business purposes are described in Sections 3 and 11. DentalXpand does not sell Personal Information, does not share it for cross-context behavioral advertising, and does not use it for targeted advertising. We use sensitive information only for the Service, security, legal, and other permitted business purposes described in this Policy, not to infer unrelated characteristics.

Some state privacy laws exempt PHI, medical information, employment data, business-to-business data, or information processed solely for a Customer. Whether an exemption applies depends on the record and relationship. We will respond to verified requests as required by applicable law and explain any material denial and available appeal process.

18

EEA, United Kingdom, and Swiss disclosures

If applicable data protection law in the European Economic Area, United Kingdom, or Switzerland governs our processing, you may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent without affecting prior lawful processing. You may also lodge a complaint with your local supervisory authority.

Section 6 describes our legal bases. We do not intend to subject individuals to a decision based solely on automated processing that produces legal or similarly significant effects. If that changes in a specific Customer workflow, the responsible controller must provide the required notice, lawful basis, safeguards, and opportunity for human intervention.

Where DentalXpand is a processor, the Customer is the controller and should receive the request. Where DentalXpand is the controller, use the contact details below. If a representative or data protection contact is legally required for a particular offering, that contact will be identified in the applicable DPA or regional notice.

19

Children's privacy

The website and Service are business products and are not directed to children under 13. Authorized User accounts are intended for adults acting in a professional capacity. We do not knowingly invite children under 13 to create accounts or submit Personal Information directly through the public website.

A dental Customer may submit patient records concerning a minor when legally permitted and necessary for care, billing, eligibility, or related operations. DentalXpand processes those records as Customer Content under the Customer's instructions, applicable agreement, BAA, and healthcare privacy law. A parent or guardian seeking rights concerning such a record should contact the responsible dental practice or covered entity.

If you believe a child submitted information directly to DentalXpand outside an authorized Customer healthcare workflow, contact us so we can investigate and take appropriate action.

20

Policy changes and contact

Changes to this Policy

We may update this Policy to reflect changes in the Service, law, integrations, or business practices. We will revise the "Last updated" date and provide additional notice through the website, Service, email, or contractual channel where a change is material or consent is required. Continued use after an effective update is subject to applicable law and agreement terms.

Contact DentalXpand

Contact us with privacy questions, rights requests, complaints, or concerns about how this Policy applies. Do not include PHI, passwords, API keys, financial account numbers, or other sensitive records in ordinary email.

Privacy and support contacts

DentalXpand
The exact contracting provider and formal notice address are identified in the applicable Order Form, invoice, or contracting document.

contact@xpand.dental support@xpand.dental 732 944 0318 Terms and Conditions

This Policy is designed to describe the current DentalXpand product and website. It should be reviewed together with the executed Customer agreement, BAA, DPA, security documentation, and deployment configuration.

A clearer way to run dental operations

Bring revenue, credentialing, and team workflows together.

Book a demo
dentalxpand.io

Dental RCM, billing, credentialing, and growth operations in one connected workspace.

Platform

  • Services
  • Features
  • Application login

Company

  • About
  • Resources
  • Blog
  • Contact
  • contact@xpand.dental
  • support@xpand.dental
  • 732 944 0318

Legal

  • Privacy Policy
  • Terms and Conditions

© 2026 DentalXpand. All rights reserved.

Built for modern dental organizations.