Legal

Privacy Policy

Last updated September 6, 2026

Pronto Plus reads the numbers already inside your practice and turns them into a plain-language report and a short list of authorized automations. That only works if you can trust how we handle the information involved — the practice’s business data, your account details and, most importantly, your patients’ information.

This policy sets out what we collect, why, where it lives, who we share it with and the rights you and your patients have. It should be read together with our Terms of Service.

1.Who this policy covers

This Privacy Policy explains how Pronto Plus LLC (“Pronto Plus”, “we”, “us”) collects, uses, discloses and safeguards information when you visit our website, create an account, or use the Pronto Plus service — the Business IQ report, the dashboard and the curated automation library (together, the “Service”).

Pronto Plus is built for orthodontic and specialized dental practices and is used by the practice’s owners and staff. It is an internal office-intelligence tool: it is not a patient-facing application, and patients do not create Pronto Plus accounts.

We are a Canadian service. This policy is written to meet the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where they apply to a practice, provincial private-sector and health-information privacy laws (for example Ontario’s PHIPA, Alberta’s HIA and British Columbia’s PIPA). If you use the Service from outside Canada, Canadian law still governs how we handle your information unless your agreement with us says otherwise.

To confirmThe registered address of Pronto Plus LLC is to be inserted here before this policy is relied on by customers.

2.The practice is the custodian; Pronto Plus is a service provider

Patient information that reaches Pronto Plus does so because a practice connected its practice-management system, accounting system or other business tools and asked us to read from them. For that information the practice remains the custodian (or “health information custodian”, “trustee” or “organization” under the applicable statute) and decides why and how it is used. Pronto Plus acts as the practice’s service provider (an “agent” or “information manager” in some provinces) and processes that information only on the practice’s instructions and only to provide the Service.

If you are a patient of a practice that uses Pronto Plus, please direct any privacy request — access, correction, questions about a message you received — to your practice. We will help the practice respond.

For account holders (the practice’s owners and staff), Pronto Plus LLC is the organization responsible for the account and usage information described below.

3.Information we collect

We collect three kinds of information.

  • Account information. Your name, work email address, practice name, practice type (orthodontics or specialized dental), role in the practice (Owner, Office Manager, Front Desk, Pronto Ops) and authentication credentials. Passwords are stored only as salted hashes by our authentication provider; we never see them.
  • Practice data from connected systems. With your authorization we read from systems the practice already uses: accounting (QuickBooks Online); practice-management systems through read-only bridges; claims and eligibility (DentalXChange); advertising and analytics accounts (Google Ads, Meta Ads, GA4); and the practice calendar. This can include financial ledgers, accounts-receivable balances, production by provider, appointment and recall records, insurance and benefit information, and — where a practice enables an outreach automation — the patient contact details and consent flags needed to send an authorized message.
  • Usage and technical information. Sign-in events, the pages and features you use, actions you take (for example turning an automation to Automate or authorizing a collections sequence), browser type, approximate location derived from IP address, and diagnostic logs. Every action taken in the Service by a person or an agent is written to an append-only audit trail that the practice can review.

4.How we treat patient information

The Service is designed around data minimization. In practice this means:

  • Connectors to practice-management systems are read-only in the current release.
  • Patients appear as initials, not names, in dashboards, reports, agent summaries and the activity feed.
  • Text messages sent by automations are templated and never contain a patient’s name, diagnosis, treatment details or dollar amounts. Outreach honours quiet hours and opt-outs.
  • Where a step is assisted by a language model, identifiers are reduced to initials before any content is sent, every such step has a deterministic (non-AI) fallback, and no patient information is used to train models.
  • The sandbox demo uses entirely synthetic data. It contains no real patients and no personal health information.
  • Nothing is sent to a patient unless someone in the practice launched it with one click or switched the relevant automation to Automate, which records a standing authorization.

5.How we use information

  • To provide, operate and secure the Service, including generating Business IQ reports and running the automations a practice has authorized.
  • To authenticate users, enforce role-based access and maintain the audit trail.
  • To provide support and respond to your requests.
  • To bill for paid plans and communicate about your account, service changes and security notices.
  • To improve the Service using information that has been aggregated or de-identified so it no longer identifies a practice or a patient.
  • To comply with law, enforce our terms and protect the rights, safety and property of practices, patients and Pronto Plus.

We do not sell personal information, we do not use practice or patient information for advertising, and we do not use it for any purpose that is not compatible with providing the Service without first obtaining the practice’s consent.

6.When we share information

We share information only with service providers that help us deliver the Service, with the systems you choose to connect, or when the law requires it. We do not share it with anyone else. Our current categories of service providers are:

  • Database, authentication and file storage — Supabase, hosted in the Canada (Central) region.
  • Application hosting and delivery — the cloud platform that serves the website and application.
  • Messaging — Twilio for SMS and voice, and Resend for email, used only for the outbound actions a practice authorizes and for account notices.
  • Systems you connect — Intuit (QuickBooks Online), your practice-management bridge provider, DentalXChange, Google and Meta. Data flows to and from these systems under the authorization you grant, and their own privacy terms govern their handling of it.
To confirmA maintained sub-processor list with entity names, processing locations and links to each provider’s data-protection terms should be published (or made available on request) and referenced from this section.

7.Data residency and cross-border transfers

Practice and account data is stored in Canada (Supabase, ca-central-1). Some of our service providers — in particular messaging, email and content-delivery infrastructure — process information in the United States or other countries in the course of delivering a message or serving the application. Information processed outside Canada may be accessible to the courts, law enforcement and national-security authorities of that jurisdiction under its laws.

Where information leaves Canada we use contractual and technical safeguards intended to provide a comparable level of protection, as PIPEDA requires. Practices in provinces with public-body or health-sector residency requirements should confirm that this arrangement is acceptable before enabling outreach automations.

8.How we protect information

  • Encryption in transit (TLS) and at rest for databases, backups and file storage.
  • Row-level security so that each practice can only ever read and write its own records, enforced in the database rather than only in application code.
  • Role-based access within a practice (Owner, Office Manager, Front Desk, Pronto Ops) so each person sees only what their role needs.
  • An append-only audit log of every human and agent action, and a kill switch that pauses all automations immediately.
  • Least-privilege, credentialed access for our own staff, limited to what is needed to operate and support the Service.
  • Connector credentials and OAuth tokens stored in an encrypted secrets vault, never in application code or logs.

No system is perfectly secure. If we become aware of a breach of security safeguards involving information under our control we will notify the affected practice without undue delay, provide the information it needs to meet its own notification obligations, and where PIPEDA or provincial law requires it, report the breach to the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner and keep the records the law requires.

9.How long we keep information

We keep account information for as long as your account is active. We keep practice data for as long as the practice’s subscription is active and the connector that supplies it remains authorized. When a practice ends its subscription or asks us to, we delete or de-identify its practice data within 30 days, except that audit-trail records and billing records may be retained for the period required by law, and residual copies may persist in encrypted backups for up to 90 days before they are overwritten.

Disconnecting a connector stops new data from being read immediately. Sandbox demo state is kept only in your browser tab and is discarded when the tab closes.

10.Your rights and choices

Under PIPEDA and provincial privacy laws you have the right to access the personal information we hold about you, to ask us to correct it, to withdraw consent (subject to legal or contractual restrictions and reasonable notice) and to ask how your information has been used and to whom it has been disclosed. Account holders can update most account details in Settings; for anything else, contact us using the details below. We respond within 30 days as PIPEDA requires, and will tell you if we need longer and why.

If you are not satisfied with our response you may complain to the Office of the Privacy Commissioner of Canada or to the privacy commissioner in your province.

Patients: because your practice is the custodian of your health information, please contact the practice directly. We will support the practice in responding to you.

11.Cookies and similar technologies

The Service uses only the cookies and browser storage strictly necessary to keep you signed in and to remember choices you make in the application (for example the role you are viewing as). The sandbox demo keeps its state in your browser’s session storage and sets one short-lived cookie that only records that you are viewing the demo; it holds no identifier and expires within a few hours. We do not use advertising cookies or third-party tracking pixels on the website or in the application.

12.Children

The Service is for use by practices and their staff. We do not knowingly collect personal information directly from anyone under 18. Information about minor patients may be included in practice data that a practice connects; that information is handled under the practice’s custodianship as described above.

13.Changes to this policy

We may update this policy from time to time. When we do we will change the “last updated” date above and, for material changes, notify account holders by email or in the application before the change takes effect. Continued use of the Service after a change takes effect means you accept the updated policy.

14.Contact us

Privacy questions, access or correction requests, and complaints should be addressed to the Privacy Officer of Pronto Plus LLC. Please include the practice name and your role so we can verify the request.

To confirmPrivacy Officer name, mailing address and a monitored privacy email address are to be inserted here. Until then, use the contact channel provided during your onboarding.

Questions about this document? Contact us using the details in the contact section above. You can also read our Terms of Service.