Watch Algoricum work a live practice in two minutes · See it live →
Legal

Privacy Policy

Last updated: [ add date ]
Draft for review. This document describes how Algoricum intends to handle information. It is a working draft pending review by legal counsel and is not yet a binding agreement. Do not rely on it until a final version is published.

Algoricum (“Algoricum,” “we,” “us”) provides front-desk automation for dental and medical practices. This policy explains what information we collect, how we use it, and the choices available to practices and to the patients they serve.

Two kinds of relationship. When a practice uses Algoricum, the practice is the covered entity and Algoricum acts as its business associate under HIPAA. We process protected health information (PHI) only to provide the service, and only as permitted by the Business Associate Agreement (BAA) between us and the practice. This policy is subordinate to that BAA wherever the two touch the same subject.

Information we collect

From the practice

Generated by using the service

How we use information

We do not sell personal information or PHI. We do not use PHI to build or train models outside of what is needed to provide the service to that practice, and only as the BAA permits.

Service providers we share with

We use a small set of vetted providers to run the service. Where they process PHI on our behalf, they do so under their own business associate or data-processing terms.

ProviderPurpose
SupabaseApplication database and authentication
StripeSubscription and usage billing
TwilioText messaging and telephony
MailgunEmail delivery
VapiVoice calling, where enabled

This list may change as the service evolves; the current list will be kept accurate in the published version.

How we protect information

Data retention

We keep practice data for as long as the practice's account is active and as needed to provide the service. Note that our audit and event records are append-only by design, which supports accountability but means some records are retained rather than deleted. When an account is closed, outreach is switched off and the account is retired; specific retention and deletion terms are governed by the BAA and the final version of this policy.

Patients’ choices

Patients can opt out of messages at any time by replying STOP to a text, and that request is honored immediately across the service. Because Algoricum acts on behalf of the practice, patients who want to access, correct, or delete their records should contact their practice, which controls that data. We support practices in fulfilling those requests.

Practices’ responsibilities

Practices are responsible for having the right to share the patient data they connect, for obtaining any consent required to contact their patients, and for using the service in line with the Terms of Service and applicable law.

Changes to this policy

We will update this policy as the service changes and will revise the date at the top. Material changes will be communicated to practices.

Contact

Questions about this policy or your data can be sent to privacy@algoricum.com.