Privacy Policy

Effective date: [EFFECTIVE DATE] · Last updated: [DATE]

This Privacy Policy explains how Nodi ("Nodi", "we", "us") handles information when a dental practice uses the Nodi application and related services (the "Service"). Nodi provides analytics, recall, and patient-messaging tools to dental practices using their practice-management data.

1. Our role

The dental practice that uses Nodi is the custodian of its patients' health information and controls that information. When Nodi processes patient health information, it does so on the practice's behalf and under its instructions — as an "Information Manager" within the meaning of Alberta's Health Information Act (HIA), under a written agreement with the practice. Nodi does not use patient health information for its own purposes.

2. Information we handle

3. How we use information

We use information solely to provide, secure, support, and improve the Service for the practice — for example, to compute analytics, generate recall worklists, send patient outreach the practice initiates, and maintain audit and security logs. We do not sell personal or health information, and we do not use it for advertising.

4. Data location

Patient health information is stored and processed in Canada (Microsoft Azure, Canada region). We do not move health information outside Canada without an assessed, documented basis.

5. Service providers (sub-processors)

We use vetted service providers to run the Service, each under agreements that limit their use of information:

6. Security

We protect information with encryption in transit (TLS) and at rest, role-based access control, multi-factor authentication for staff accounts, per-practice data isolation, audit logging of access to health information, and network and secret-management controls. No system is perfectly secure, but we work to safeguard information using measures appropriate to its sensitivity.

7. Retention

We retain information for as long as the practice uses the Service, and afterward only as needed to meet legal, audit, or contractual obligations, per our agreement with the practice. On offboarding, the practice's data is returned or securely deleted as directed.

8. Your privacy rights

Because the practice is the custodian of its patients' health information, requests from patients to access or correct their health information are directed to and handled by their dental practice. Nodi supports practices in fulfilling those requests. For personal information Nodi holds directly (e.g. staff accounts), contact us using the details below.

9. Breach notification

If a privacy breach involving health information occurs, we will notify the affected practice promptly and cooperate with its obligations, including notification to Alberta's Office of the Information and Privacy Commissioner (OIPC) and affected individuals where required.

10. Changes

We may update this policy; material changes will be communicated to practices. The effective date above reflects the current version.

11. Contact

Questions or requests: privacy@nodi.ca
[NODI LEGAL ENTITY NAME], [BUSINESS ADDRESS], Alberta, Canada.