PRIVACY POLICY

Effective Date: March 21, 2026 | Last Updated: March 21, 2026

Introduction

PracticeNova AI LLC ("PracticeNova AI," "we," "us," or "our") provides an AI-powered growth and marketing automation platform designed exclusively for independent dental and medical practices (the "Platform"). We are committed to protecting the privacy of both the practices we serve and, indirectly, the patients those practices serve.

This Privacy Policy describes how we collect, use, and protect information when you visit our website at practicenova.ai (the "Site") or use our Platform and services (collectively, the "Services"). This policy applies to practice owners, administrators, and authorized users who access the Platform.

This Privacy Policy does not apply to Protected Health Information (PHI) processed on behalf of our practice clients under a Business Associate Agreement (BAA), which is governed separately by that agreement and applicable HIPAA regulations.

1. Information We Collect

A. Information You Provide Directly

When you interact with our Site or Services, we may collect:

  • Contact and account information: name, email address, phone number, practice name, and role
  • Billing and payment information (processed securely through third-party payment processors — we do not store payment card data on our servers)
  • Practice information provided during onboarding: specialty, location, marketing goals, and existing vendor relationships
  • Communications: messages, support requests, and feedback submitted to us

B. Information Collected Automatically

We use cookies and similar technologies to collect:

  • Log data: IP address, browser type, pages visited, time spent, and referring URLs
  • Device information: operating system, browser version, and screen resolution
  • Usage data: feature interactions, session activity, and platform engagement patterns

You may control cookie preferences through your browser settings. Note that disabling certain cookies may affect Platform functionality.

C. Practice Management System (PMS) Data

When you connect your practice management system to our Platform, we access de-identified, aggregate data only — including appointment volume by procedure type, production trends, and capacity metrics. We do not access, store, or use individually identifiable patient records or Protected Health Information for any marketing, analytics, or optimization purposes. All PMS connectivity is governed by a signed Business Associate Agreement.

2. How We Use Your Information

We use information we collect to:

  • Provide, operate, and improve the Platform and Services
  • Onboard your practice and configure AI-powered campaigns on your behalf
  • Generate marketing recommendations, performance reports, and attribution analysis
  • Communicate with you about your account, campaigns, and service updates
  • Respond to support requests and inquiries
  • Ensure platform security and prevent fraud or unauthorized access
  • Comply with applicable legal obligations
  • Improve our AI models and platform capabilities using aggregated, anonymized data that does not identify individual patients or practices

We do not sell your personal information to third parties. We do not use patient data from your PMS for advertising targeting, profiling, or any purpose beyond providing the Services.

3. HIPAA Compliance and Business Associate Agreement

PracticeNova AI operates as a HIPAA Business Associate with respect to any Protected Health Information (PHI) that may be encountered in connection with our Services. We execute a Business Associate Agreement (BAA) with each practice client prior to accessing any practice management system data.

Our platform is designed so that marketing optimization and campaign execution rely on de-identified, aggregate data only — meaning individual patient records are not used or exposed in our marketing workflows. However, to the extent any PHI is encountered in connection with our Services, we adhere strictly to HIPAA Security Rule and Privacy Rule requirements, including:

  • Implementing administrative, physical, and technical safeguards to protect PHI
  • Limiting access to PHI to personnel who require it to perform authorized functions
  • Reporting any breach of unsecured PHI in accordance with HIPAA breach notification requirements
  • Not using or disclosing PHI except as permitted by the BAA and applicable law

4. How We Share Your Information

We do not sell your information. We may share information with:

Service Providers: Third-party vendors who support our operations, including cloud hosting providers, analytics services, payment processors, email platforms, and customer support tools. All subprocessors are bound by confidentiality obligations consistent with this policy.

AI Model Providers: We use third-party AI infrastructure providers including OpenAI, Google, Anthropic, and others to power our platform capabilities. Content processed through these providers is subject to their applicable data use policies. We do not transmit individually identifiable patient data to AI model providers.

Legal and Regulatory Requirements: We may disclose information when required by law, subpoena, court order, or government request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice prior to such transfer.

5. AI Model Disclosures

Our Platform uses artificial intelligence models to generate campaign recommendations, SEO content, attribution analysis, and growth strategies. Specifically:

  • AI models used: OpenAI GPT-4 and related models, Google Gemini, Anthropic Claude, and others as appropriate for specific tasks
  • Data shared with AI providers: Practice-level inputs, campaign parameters, and anonymized performance data. We do not share patient records or PHI with AI model providers.
  • Human review: All AI-generated content and campaign recommendations are reviewed by our team before going live. Nothing is published to your practice's marketing channels without human oversight.
  • Accuracy: AI-generated content is not guaranteed to be accurate, complete, or appropriate for all contexts. You are responsible for reviewing and approving all content before it reaches patients or the public.

6. Data Security

We implement industry-standard physical, technical, and organizational safeguards to protect your information, including:

  • Encryption in transit (TLS) and at rest for sensitive data
  • Role-based access controls limiting data access to authorized personnel
  • Regular security reviews and vulnerability assessments
  • Secure cloud infrastructure with SOC 2-compliant hosting providers

No method of electronic storage or internet transmission is 100% secure. We will notify you in accordance with applicable law in the event of a breach affecting your information.

7. Data Retention

We retain your information for as long as necessary to provide the Services and fulfill the purposes described in this policy, or as required by applicable law. Upon termination of your account, we will delete or anonymize your data within a reasonable period, except where retention is required for legal, tax, or compliance purposes.

8. Your Privacy Rights

Depending on your jurisdiction, you may have rights to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Request deletion of your information (subject to legal retention requirements)
  • Opt out of marketing communications at any time

California Residents: Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), you have additional rights including the right to know what personal information is collected, the right to delete, and the right to opt out of sale (we do not sell personal information). To exercise these rights, contact us at hello@practicenova.ai.

To submit a privacy request, contact us at hello@practicenova.ai. We will respond within the timeframe required by applicable law.

9. Children's Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided personal information to us, please contact us immediately at hello@practicenova.ai.

10. Changes to This Policy

We may update this Privacy Policy periodically. For material changes, we will provide at least 30 days' notice by posting an updated policy on our Site and notifying active users by email. Your continued use of the Services after the effective date of an updated policy constitutes acceptance of the changes.

11. Contact Us

PracticeNova AI LLC

2380 Salvio St. Ste 303 Concord, CA 94520

hello@practicenova.ai