Privacy Policy
This Privacy Policy explains how PracticeSteady™ ("we," "us") collects, uses, and protects information across our marketing website and the platform we operate for dental practices ("Services"). It is written for two audiences: practices that subscribe to PracticeSteady, and visitors to our or our customers' websites.
1. Information we collect
- Practice / account information: name, email, phone, practice details, billing information, and the content you provide during onboarding.
- Website visitor information: basic analytics, device/browser data, and messages submitted through forms or the website assistant.
- Patient booking information: details a patient submits to book or ask a question (name, contact, requested time). For our customers' practices, this may include limited health-related context.
2. How we use information
To provide and operate the Services, build and run practice websites and booking, send appointment and account communications, process payments, improve the Services, provide support, and meet legal obligations. We do not sell personal information.
3. Protected Health Information (HIPAA)
When a practice uses PracticeSteady, PracticeSteady acts as a Business Associate and the practice is the Covered Entity under HIPAA. Any protected health information ("PHI") is processed only to provide the Services and is governed by a Business Associate Agreement (BAA) between PracticeSteady and the practice.
By design, patient booking, recall, and membership data are handled on HIPAA-eligible, BAA-covered infrastructure that is kept separate from the public marketing layer. The public marketing website does not store PHI. We use subprocessors only under terms consistent with HIPAA where PHI is involved.
4. How information is shared
We share information with service providers (subprocessors) that help us run the Services — for example, cloud hosting, payment processing, messaging (email/SMS), and AI providers — under contracts that limit their use of the information. We may disclose information if required by law or to protect rights and safety. We do not sell personal information.
5. Data security and retention
We use administrative, technical, and physical safeguards appropriate to the data involved, and keep clinical/patient data separated from marketing data. We retain information for as long as needed to provide the Services and meet legal, accounting, and compliance obligations.
6. Your choices and rights
Depending on your location, you may have rights to access, correct, or delete your personal information, or to opt out of certain processing. Patients should direct requests about their records to the dental practice (the Covered Entity). To make a request to PracticeSteady, contact us below.
7. Cookies and analytics
Our marketing site may use cookies and basic analytics to understand usage and improve the experience. You can control cookies through your browser settings.
8. Children's privacy
The Services are intended for dental practices and adult patients/guardians. We do not knowingly collect personal information directly from children through the marketing site.
9. Changes and contact
We may update this Policy; material changes will be posted here with a new "last updated" date. Questions or requests: hello@practicesteady.com.