Privacy Policy
How Rooted handles the information involved in running the Service — the information about your account, the practice information we process on your behalf, and the operational information we generate to keep Rooted secure.
This policy is written in plain language and organized so you can find what matters to you. It distinguishes between information about your account, practice information we process on your behalf, and operational information we generate to run and secure the Service. Use the list on this page to jump to any section.
1. About this Privacy Policy
This Privacy Policy explains how Rooted Node Inc. (“Rooted,” “we,” “us,” or “our”) handles information in connection with our public website, the Rooted account, the Rooted Node software, and the Rooted / Rooted Intelligence service (together, the “Service”). It is written in plain language so that the people who rely on Rooted can understand how their information is treated.
Rooted provides business intelligence and related functionality to dental practices. It works alongside a practice’s existing systems and does not replace a practice-management system. Because Rooted serves practices that hold sensitive information, we have written this policy to support our operations under applicable Canadian federal and provincial privacy laws, including health-information regimes such as Ontario’s Personal Health Information Protection Act (PHIPA) where applicable, and to support future operation in the United States, including HIPAA-regulated relationships where applicable.
2. The information we handle
It helps to think about the information we handle in three distinct categories, because we treat each of them differently.
a. Customer and account information
This is information about our customers and the people who set up and use a Rooted account. It may include:
- Identity and contact details — such as name, email address, and mobile number.
- Practice information — such as the practice’s name, location, and the management software it uses.
- Authorized people — the individuals a customer designates to use Rooted and the roles or permissions assigned to them.
- Authentication and security information — credentials, security factors, and related records used to protect access to the account.
- Subscription and account information — plan, billing status, and related account records.
- Communications with Rooted — messages, requests, and support correspondence you send to us.
b. Practice information processed for customers
To do its work, Rooted may process information made available from a dental practice’s systems. This can include personal information and personal health information (sometimes called protected health information), such as patient, provider, scheduling, production, and collections information and the relationships among them.
We process this practice information on behalf of, and under the instructions of, the customer, under the applicable customer agreement and applicable law. Rooted does not treat this category as its own information to use for its own independent purposes.
c. Rooted operational information
This is information we generate or observe in the course of operating and securing the Service. It may include:
- Website interactions and basic usage information.
- Security, access, and audit records.
- Rooted Node, device, and service telemetry and diagnostics.
- Messaging metadata and delivery information for communications we send on a customer’s behalf.
- Consent, opt-in, and opt-out evidence.
- Support information and service diagnostics.
3. How we obtain information
We obtain information in a few straightforward ways:
- Directly from you — when you contact us, create or configure an account, or communicate with us.
- From the customer’s authorized systems — practice information is made available to Rooted through the connection a customer authorizes between Rooted and the practice’s systems.
- Automatically — operational information such as telemetry, security records, and website usage is generated as you and the Service interact.
- From service providers — for example, providers that help us deliver messages, process payments, or secure the Service.
4. Why we process information
We process information for the following purposes:
- To provide, maintain, and improve the Service and its features.
- To understand a practice’s business and produce the intelligence, reports, and artifacts a customer asks for.
- To authenticate users and protect accounts and the Service.
- To send and deliver communications a customer authorizes, and to manage consent and preferences.
- To provide support and respond to requests.
- To monitor, secure, and troubleshoot the Service, and to maintain audit records.
- To manage subscriptions, billing, and our business operations.
- To comply with applicable law and enforce our agreements.
We process practice information (category b) only for the purpose of providing the Service to the customer and as instructed under the applicable customer agreement and applicable law.
5. Operation and security of Rooted
Operating the Service securely is itself a purpose for which we handle information. We use operational information to keep the Service running reliably, to detect and investigate security events, to maintain audit trails of what was asked, done, and delivered, and to diagnose and resolve problems.
6. Account authentication
We use authentication and security information to verify identity and to control access to Rooted accounts. This includes credentials and additional security factors, along with records of sign-in and access events used to protect the account. You are responsible for keeping your credentials confidential and for the activity of the people you authorize.
7. Rooted Node and service telemetry
Rooted Node and the Service generate telemetry and diagnostics — such as operational status, performance, and error information — that we use to confirm the Service is installed and running correctly, to maintain reliability and security, and to improve the Service. We aim to limit telemetry to what we need for these operational purposes.
8. SMS, RCS, and other communications
Rooted can send communications, including by SMS, RCS, email, and similar channels, to the people a customer authorizes. To do this, we handle messaging metadata, delivery information, and consent, opt-in, and opt-out evidence. Recipients can opt out of non-essential messages using the method described in the message or by contacting us or the practice. Message and data rates may apply depending on the recipient’s carrier and plan.
9. Authorized users
A customer decides who may use Rooted and what each person is permitted to ask about and receive. We handle information about authorized users to administer access, apply per-person permissions, and maintain an audit trail. Customers are responsible for keeping their list of authorized users accurate and for promptly removing people who should no longer have access.
10. Service providers and subprocessors
We use trusted service providers to help us deliver the Service — for example, to host infrastructure, deliver messages, process payments, and support security and operations. These providers may handle information only to perform services for Rooted, under agreements that require appropriate confidentiality and protection, and they are not permitted to use it for their own purposes. We remain accountable for information handled on our behalf.
11. Disclosures required by law
We may disclose information where we are required or permitted to do so by applicable law, such as to comply with a valid legal process, to protect the rights, safety, and security of people, the public, or Rooted, or to enforce our agreements. Where we may lawfully do so, and consistent with any applicable customer agreement, we will limit such disclosure to what is required.
12. Safeguards and security
We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, or disclosure. These include encryption of information in transit and at rest, least-privilege access, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; we work to protect information using measures appropriate to its sensitivity.
13. Retention and deletion
We retain information for as long as needed to provide the Service, for the purposes described in this policy, and as required to meet legal, regulatory, security, and record-keeping obligations. Retention and deletion of practice information are handled in accordance with the applicable customer agreement and applicable law. When information is no longer required, we take steps to delete it or render it no longer attributable.
14. Access, correction, and privacy rights
Depending on your location and role, and subject to applicable law, you may have rights to access, correct, or update certain personal information, to withdraw consent where applicable, or to make a privacy complaint. For customer and account information, you can contact us using the details below.
For practice information that Rooted processes on behalf of a customer, requests are generally directed to and handled through the customer (for example, the practice), because the customer determines how that information is used. We will assist our customers in responding to such requests as set out in the applicable customer agreement and applicable law.
15. Cookies and website analytics
Our public website may use cookies and similar technologies to operate the site, remember preferences, and understand how the site is used so we can improve it. You can usually control cookies through your browser settings; disabling some cookies may affect how parts of the site work.
16. Children’s information
The Service is intended for use by dental practices and their authorized personnel, not by children, and our website is directed to businesses rather than to children. We do not knowingly collect personal information directly from children through the website. Practice information processed for a customer may relate to patients of any age; that information is handled as described in the “practice information” category and under the applicable customer agreement and applicable law.
17. International and cross-border considerations
Rooted operates in Canada and may operate in the United States. Depending on the service providers and infrastructure involved, information may be processed or stored in more than one jurisdiction, and it may be subject to the laws of the jurisdictions where it is processed. Where we transfer information across borders, we take steps intended to protect it consistent with this policy and applicable law. This policy does not create a specific data-residency guarantee beyond what Rooted has actually established with a customer.
18. What we do not do
To be clear about our commitments:
- We do not sell customer personal information or Practice health information for advertising purposes.
- We do not use customer Practice information to train shared or general-purpose models as part of the Rooted product model.
- We do not repurpose one customer’s practice information to serve another customer.
We use practice information to provide the Service to the customer it belongs to, and for no unrelated purpose.
19. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, provide additional notice. Your continued use of the Service after an update takes effect means you are subject to the updated policy.
20. How to contact us
If you have a privacy question, request, or concern, you can reach us at privacy@rootednode.ai. Please include enough detail for us to understand and respond to your request. If you are asking about practice information held for a specific practice, we may direct you to that practice, which determines how its information is used.