Legal
Privacy Policy
Last Updated: April 14, 2026
1. Who We Are
OrthoAscend ("we," "us," "our") is a digital strategy and technology company serving orthodontic practices. We operate the OrthoAscend website (orthoascend.io) and build products including OrthoAngel (practice intelligence and patient engagement platform, with new capabilities added over time) and Orderli (inventory management for orthodontic practices).
This Privacy Policy describes how we collect, use, and protect your personal information when you interact with our website, products, and services.
2. Information We Collect
Website Visitors
When you visit orthoascend.io, we may collect:
- Basic analytics data (pages viewed, referral source, session duration) via Google Analytics and PostHog
- Information you provide through our contact form (practice name, location, email, areas of interest)
- Cookies and similar technologies for site functionality and analytics
OrthoAngel — Practice Intelligence Platform
When orthodontic practices use OrthoAngel, we may process the following categories of data, including but not limited to:
- Patient information — Names, phone numbers, opt-in/opt-out status, and consent history
- Communication data — SMS message content, timestamps, phone call transcripts and metadata
- Appointment data — Scheduling information, clinical notes, and staff-authored observations
- Website data — Patient browsing behavior on the practice website (anonymous until identity-stitched at booking)
- Documents — Patient forms, insurance information, and uploaded files
- AI-generated insights — Consult briefings, message classifications, and engagement analytics produced by our platform
Important: OrthoAngel processes patient data on behalf of the orthodontic practice. The practice is the data controller; OrthoAscend acts as a data processor.
Orderli — Inventory Management
When practices use Orderli, we may process:
- Practice account information (practice name, contact details, authorized users)
- Inventory and supply data entered by practice staff
- Order history and vendor information
3. How We Use Your Information
We use collected information to:
- Provide and improve our website, products, and services
- Respond to inquiries submitted through our contact form
- Send appointment confirmations, reminders, and care coordination messages (OrthoAngel)
- Manage inventory data and facilitate ordering workflows (Orderli)
- Analyze site usage to improve user experience
- Comply with legal obligations
We do NOT use patient information for marketing, advertising, or promotional purposes. We do NOT sell, rent, or share personal information with third parties for their marketing purposes.
4. Artificial Intelligence & Automated Processing
OrthoAscend may use artificial intelligence (AI) and machine learning technologies to enhance our products and services. These capabilities may include, but are not limited to, generating consult briefings, classifying messages, analyzing engagement patterns, and producing data-driven insights for practice staff.
When AI is used to process data:
- All AI processing occurs server-side within our secured GCP infrastructure
- Third-party AI providers (such as OpenAI) are contractually prohibited from using your data for model training
- No protected health information (PHI) is stored by AI providers beyond transient API processing
- AI-generated outputs are tools for practice staff — they do not replace professional clinical judgment
As AI capabilities evolve, this section applies to all current and future AI-powered features across our products.
5. Third-Party Service Providers
We use the following third-party services to operate our platform. This list reflects our current providers and may be updated as our platform evolves. A current list of service providers is available upon request.
- Twilio — SMS message delivery for OrthoAngel (Twilio Privacy Policy)
- OpenAI — AI-powered consult intelligence and message classification (OpenAI Privacy Policy)
- RingCentral — Phone call integration and transcription (RingCentral Privacy Policy)
- NexHealth — PMS data synchronization and appointment management (NexHealth Privacy Policy)
- Mapbox — Geographic data visualization (Mapbox Privacy Policy)
- Google Analytics — Website analytics (Google Privacy Policy)
- PostHog — Product analytics (PostHog Privacy Policy)
- Google Cloud Platform — Infrastructure and data hosting
These providers process data solely on our behalf and in accordance with our instructions.
6. SMS Messaging Privacy
This section applies specifically to the OrthoAngel SMS messaging service operated on behalf of orthodontic practices.
- Phone numbers and message history are stored securely and used only for appointment scheduling and care coordination purposes
- We do not sell, share, or use patient phone numbers or message data for marketing
- You may opt out of SMS messages at any time by replying STOP
- Reply HELP to any message for assistance
- Message and data rates may apply — check with your mobile carrier for details
7. Data Retention
We retain personal information for as long as necessary to provide our services and comply with applicable legal and regulatory requirements. If you opt out of SMS messaging, we retain your opt-out status to ensure we do not send you future messages.
8. Data Security
We use industry-standard security measures to protect your personal information, including:
- Encrypted data storage (AES-256 at rest) and secure transmission protocols (TLS 1.2+)
- Infrastructure hosted on Google Cloud Platform, which maintains SOC 2 Type II, ISO 27001, and HITRUST certifications
- Secrets management via GCP Secret Manager — API keys and credentials are never stored in application code
- Multi-tenant data isolation — each practice's data is logically separated; no patient data is shared across practices
- Role-based access control (RBAC) with Google SSO authentication
- Automated CI/CD pipeline via GitHub Actions with workload identity federation (no static GCP credentials)
For practices handling protected health information (PHI), we execute Business Associate Agreements (BAAs) in compliance with HIPAA requirements.
9. Your Rights
You may:
- Opt out of SMS messages at any time by replying STOP
- Request information about the data we have collected
- Request deletion of your personal information
- Contact us with privacy questions or concerns
10. Children's Privacy
Our services are not directed to individuals under 13. We do not knowingly collect personal information from children under 13 years of age.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted at this URL with an updated effective date.
12. Contact Us
For privacy questions or concerns, please contact us at:
- Email: benjamin@orthoascend.io
- Website: orthoascend.io