RodinWorks is a cloud platform for dental professionals, operated by Pac-Dent, Inc. ("Pac-Dent," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our websites or use the RodinWorks web application, AI design applications, and related services (together, the "Services").
The Services are intended for dentists, dental practices, dental laboratories, and their authorized staff. They are not directed to consumers or to individuals under 18. If you are a patient whose information was uploaded by your dental provider, please see "Patient Data and HIPAA" below.
Information We Collect
We collect the following categories of information:
- Account information
- Your name, email address, practice or organization name, and password when you register. Passwords are stored only in hashed form. If you sign in with Google or Microsoft, we receive your name, email address, and an account identifier from that provider; we do not receive your password for that provider.
- Billing information
- Your subscription plan, RodinCash balance, purchase and transaction history, and billing address. Card payments are processed by our payment processor, Stripe. We do not store full card numbers; we receive limited details such as card brand, last four digits, and expiration date.
- Clinical content and Patient Data
- Files and information you upload or create in the Services, such as intraoral scans and 3D models (for example, STL, OBJ, and PLY files), photographs, patient names or identifiers, case details, measurements, and the designs and files the Services generate for you.
- Information from connected services
- If you connect a third-party intraoral scanner cloud or other integration, we receive the cases, scans, and related information you choose to import from that service.
- AI assistant conversations
- Messages you send to AI features of the Services and the responses generated.
- Communications
- Information you provide when you contact support or otherwise correspond with us.
- Usage and device information
- IP address, browser and device type, time zone, pages and features used, and log data about requests to our servers, collected automatically when you use the Services.
- Referral information
- If you joined RodinWorks through an invitation from an authorized dealer or sales representative, the invitation code and the dealer or representative it belongs to.
Cookies and Similar Technologies
We use cookies, browser local storage, and similar technologies that are necessary to operate the Services, such as keeping you signed in, protecting your account, and remembering preferences like language and theme. We do not currently use third-party advertising cookies or cross-site tracking technologies. You can block or delete cookies through your browser settings, but parts of the Services may not work without them.
If you use Google or Microsoft sign-in, those providers' scripts load on our sign-in page and may collect information under their own privacy policies. Other than that, we do not allow third parties to collect information about your online activities over time and across different websites through the Services.
Some browsers send "Do Not Track" signals. Because there is no common industry standard for these signals, the Services do not respond to them. Where applicable law requires, we treat Global Privacy Control (GPC) signals as a valid request to opt out of the sale or sharing of personal information. We do not sell or share personal information in any case.
How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Services, including generating AI-assisted dental designs and 3D models at your request;
- Create and manage your account, authenticate you, and provide customer support;
- Process subscriptions, RodinCash purchases, case charges, and refunds;
- Send service communications, such as verification codes, password resets, receipts, and notices about your account or subscription;
- Monitor, secure, and troubleshoot the Services, and detect and prevent fraud and abuse;
- Understand how the Services are used and improve them;
- Comply with legal obligations and enforce our Terms of Service.
We use Patient Data only to provide the Services to you and as otherwise permitted by our business associate obligations described below. We do not sell Patient Data and do not use it for marketing.
Patient Data and HIPAA
When a dental practice or other covered entity uses the Services to process protected health information ("PHI"), we act as that customer's business associate under the Health Insurance Portability and Accountability Act ("HIPAA"). We handle PHI in accordance with HIPAA and our Business Associate Agreement ("BAA") with the customer. Where this Privacy Policy and a BAA conflict with respect to PHI, the BAA controls. Customers may request a BAA by contacting us at the address below.
We may de-identify Patient Data in accordance with HIPAA. De-identified data is no longer PHI and may be used to operate and improve the Services, including to develop and improve our AI features. Removing a patient's name alone does not de-identify a scan; we de-identify only by the methods HIPAA recognizes.
If you are a patient and want to access, correct, or delete your information, please contact your dental provider, who controls your records. We will assist your provider in responding to your request.
Data Retention
We retain information for as long as your account is active and as needed to provide the Services. After your account is closed, we retain information for as long as necessary to comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements, and we then delete or de-identify it. PHI is retained and returned or destroyed as provided in the applicable BAA.
Security
We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit, access controls, and signed, time-limited links for file downloads. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your password confidential and for controlling access to your account. Please notify us promptly if you believe your account has been compromised. Do not attach patient files to ordinary support emails unless we direct you to a secure channel.
Your Choices and Rights
- Account information: you can review and update most account information in your account settings.
- Access, correction, and deletion: you can ask us to provide, correct, or delete personal information we hold about you by contacting us. We may need to verify your identity and may retain information as permitted by law.
- Service emails: we send transactional messages related to your account; these cannot be turned off while your account is active.
Residents of California and certain other U.S. states may have additional rights under applicable state privacy laws, including the right to know what personal information we collect, use, and disclose; to request deletion or correction; and not to be discriminated against for exercising these rights. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use sensitive personal information for purposes that would require an opt-out. To exercise your rights, contact us at the email below. You may use an authorized agent, subject to verification. We will not discriminate against you for exercising your rights.
Where Information Is Processed
The Services are operated in the United States, and your information is stored in the United States. Some of our service providers may process information in other countries. Where they do, we require appropriate safeguards for that information.
Children
The Services are not directed to children, and we do not knowingly collect personal information directly from children under 13. Information about pediatric patients is provided by their dental providers and is handled as Patient Data under this Privacy Policy and the applicable BAA.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and change the effective date above. If we make material changes, we will notify you by email or through the Services before the changes take effect.
Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact Pac-Dent, Inc. at:
Pac-Dent, Inc. (RodinWorks)670 Endeavor Circle, Brea, CA 92821, USAsupport@rodinworks.com