Skip to content
Treat

Treat

Privacy Policy

Last updated

Treat Technologies LLC, doing business as Treat ("Treat," "we," "us"), provides practice-management, communications, payments, and related software to healthcare practices. This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have. It applies to alltreat.io and our related websites (the "Website"), and to our software and services (the "Services").

This policy speaks to three different people, and your rights depend on which one you are:

  • Practices and their Users — the dental and medical practices that subscribe to the Services, and their staff who use them.
  • Patients — people whose information a Practice manages using the Services. If you are a patient, Treat handles your information on behalf of your healthcare provider, and Section 3 explains what that means for you.
  • Visitors — people who browse the Website, request a demo, or contact us.

Protected health information. Where a Practice is a Covered Entity under HIPAA, information that identifies a patient and relates to their health, care, or payment for care is Protected Health Information ("PHI"). We process PHI only as the Practice's Business Associate, under our Business Associate Agreement and the Practice's instructions. Where this Privacy Policy and the Business Associate Agreement differ as to PHI, the Business Associate Agreement controls.

1. Information We Collect

1.1 From Practices and Users. Account and contact details (name, work e-mail, phone, role, practice name and address); billing information (billing contact, payment method details held by our payment processor, tax identifiers); credentials and security data (login events, IP address, device and browser); the content Users create in the Services (messages, notes, templates, configurations, uploads); and communications with us (support tickets, calls, which may be recorded with notice).

1.2 About Patients, on behalf of Practices. Information a Practice enters, uploads, or synchronizes from its practice-management system, and information patients provide through Practice-branded tools we host (online booking, forms, kiosk check-in, patient portal, text-to-pay, telehealth). This may include name, date of birth, contact details, appointment and treatment information, insurance and eligibility information, payment and balance information, and the content of communications with the Practice, including texts, call recordings, voicemails, and transcripts. The Practice decides what is collected and why.

1.3 From Visitors. Information you give us when you request a demo, sign up, download something, or contact us (name, e-mail, phone, practice name, message); and technical information collected automatically (IP address, device and browser type, pages viewed, referring page, and interactions with our e-mails), as Section 6 describes.

1.4 From third parties. Business contact data from data providers and referral partners; information from the practice-management, scheduling, telephony, payment, insurance, and advertising platforms a Practice connects to the Services; and public information about a practice.

2. How We Use Information

We use information about Practices, Users, and Visitors to: provide, operate, secure, and support the Services; set up and administer accounts and billing; communicate about the Services, including service notices, security alerts, and support; respond to inquiries and demo requests; understand how the Services and Website are used and improve them; detect, prevent, and investigate fraud, abuse, and security incidents; comply with law and enforce our agreements; and, for Visitors and Practice contacts, send marketing communications you can opt out of at any time.

We use patient information only to provide the Services to the Practice and as our Business Associate Agreement permits. We do not use patient information to market to patients, and we do not sell it.

3. If You Are a Patient

Treat is a service provider to your healthcare practice. Your practice decides what information is collected, how it is used, and who may see it. When you receive a text, call, or e-mail through the Services, it comes from your practice, and your practice is responsible for having your permission to contact you. When you pay through a link or complete a form we host, the information goes to your practice.

To access, correct, or delete your information, to ask who has seen it, to change how your practice contacts you, or to ask about your practice's privacy practices, contact your practice directly. Your practice's Notice of Privacy Practices describes your rights under HIPAA. If you contact us, we will forward your request to your practice. To stop text messages from a practice, reply STOP to any message.

4. How We Share Information

We share information only as follows:

  • With your Practice. Information about patients and Users is available to the Practice that controls the account.
  • Service providers and subprocessors. Companies that help us deliver the Services, under written contracts that restrict their use of the information to providing services to us: cloud hosting and database services, telecommunications carriers, payment processors and financing partners, insurance clearinghouses, e-mail and print-mail delivery, AI model and transcription providers, a sales CRM and e-signature service for practice agreements, analytics, and customer support tools. Our current list of subprocessors that may handle Practice data is at https://www.alltreat.io/legal/subprocessors. Subprocessors that handle PHI are bound by Business Associate Agreements.
  • At the Practice's direction. Third-party systems a Practice connects to the Services, such as its practice-management system, e-mail, calendars, review platforms, advertising accounts, and webhook endpoints. The Practice controls these connections.
  • Legal and safety. When required by law, subpoena, or court order; to protect the rights, property, or safety of Treat, our customers, patients, or the public; or to investigate fraud or security incidents. Where law permits, we notify the affected Practice.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Privacy Policy and, for PHI, the Business Associate Agreement.
  • Aggregated or de-identified information. Information that no longer identifies a person or a practice, which we may use and share for any purpose, including benchmarks and research.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not send patient information to advertising platforms.

5. Artificial Intelligence

Some features of the Services use artificial intelligence, including transcription and summarization of calls, assistants that answer questions about a Practice's data, translation, and drafting tools. We use information in these features only to provide them to the Practice. We contract with our AI providers on terms that prohibit them from training their models on our customers' data. We do not use identifiable PHI to train general-purpose AI models. We may use de-identified information to evaluate and improve the Services. Our AI Features Terms describe these features in more detail.

6. Cookies and Similar Technologies

6.1 On the Services. The Services use cookies and similar technologies that are necessary to sign you in, keep you signed in, remember your preferences, and secure your session. We do not run third-party advertising trackers or session-replay tools inside the Services.

6.2 On the Website. The Website does not currently use third-party analytics or advertising cookies. Our hosting provider records standard server logs (IP address, browser type, pages requested) to operate and secure the Website, and our signup forms use a bot-protection service that evaluates browser signals. If we add analytics or advertising technologies to the Website, we will update this section and, where required, ask for your consent. You can control cookies through your browser settings.

6.3 Do Not Track and opt-out signals. We honor the Global Privacy Control signal as a request to opt out of any sale or sharing of personal information for the browser sending it. We do not respond to Do Not Track signals, for which there is no common standard.

6.4 E-mail. Our marketing e-mails may include technologies that tell us whether an e-mail was opened or a link clicked. You can unsubscribe using the link in any marketing e-mail.

7. Security

We use administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, and disclosure, including encryption in transit, encryption of data at rest by our hosting providers, access controls, logging, and workforce confidentiality obligations. No system is perfectly secure, and we cannot guarantee the security of information. Practices are responsible for the security of their own devices, networks, credentials, and configuration of the Services. Report a security concern to legal@alltreat.io.

8. Retention

We keep information for as long as needed for the purposes described in this policy: for the life of a Practice's account and for a period afterward to allow export, meet legal and regulatory obligations, resolve disputes, and enforce our agreements. Patient information is retained and returned or destroyed as our Business Associate Agreement and the Practice's instructions provide. Audit and security logs are retained as law requires. De-identified and aggregated information may be retained indefinitely.

9. Children

The Website and the Services are for adults. We do not knowingly collect information directly from anyone under 18 as a User or Visitor. Practices may manage information about minor patients; that information is controlled by the Practice and governed by HIPAA and the Business Associate Agreement. If you believe a child has provided us information directly, contact us at legal@alltreat.io.

10. Your Privacy Rights

10.1 Practice Users and Visitors. Depending on where you live, you may have the right to know what personal information we hold about you, to access it, to correct it, to delete it, to obtain a portable copy, to opt out of targeted advertising or any sale of personal information, and to not be discriminated against for exercising these rights. Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have these rights under those laws.

To exercise a right, e-mail legal@alltreat.io or write to the address in Section 13. We will verify your identity, which may require you to confirm information we hold about you. An authorized agent may submit a request with your written permission. We will respond within forty-five (45) days, extendable once by forty-five (45) days where permitted, and we will not charge for a request unless it is excessive or repetitive. If we deny a request, you may appeal by replying to our response; we will explain the outcome and, where required, how to contact your state attorney general.

10.2 Patients. If you are a patient, your practice, not Treat, is the business that decides how your information is used, and your rights under HIPAA and state law are exercised through your practice. Please direct requests to your practice. We will forward requests we receive.

10.3 California. For California residents, the categories of personal information we have collected in the last twelve months, the sources, our purposes, and the categories of recipients are described in Sections 1, 2, and 4. In the terms of the California Consumer Privacy Act, those categories may include identifiers; customer records; commercial information; internet or network activity; geolocation (approximate, from IP address); audio and electronic information (call recordings and transcripts, where a Practice enables recording); professional information; and inferences. Information a Practice provides about patients is processed on the Practice's behalf as a service provider. We have not sold or shared personal information in the preceding twelve months and do not use or disclose sensitive personal information except as permitted to provide the Services. California residents may also request, once a year, information about disclosures to third parties for their direct marketing; we make no such disclosures.

10.4 Marketing choices. You can unsubscribe from marketing e-mail using the link in any message, and from marketing texts by replying STOP. You will still receive service and account notices.

11. International Users

Treat operates in the United States and the Services are intended for practices in the United States. Information is stored and processed in the United States and may be subject to U.S. law, including lawful requests by U.S. authorities. If you access the Website from outside the United States, you consent to the transfer of your information to the United States.

12. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the new version with a new "Last updated" date and, for material changes affecting Practices, provide notice by e-mail or in the Services. Your continued use after a change takes effect is acceptance of it.

13. Contact Us

Privacy questions and requests: legal@alltreat.io

Security concerns: legal@alltreat.io

Mail: Treat Technologies LLC, Attn: Privacy, 1657 N State St, Lehi, UT 84043

General inquiries: hello@alltreat.io