Privacy Policy
Alvero Dental Systems Inc. ("Alvero", "we", "us", "our") operates the Alvero platform — a multi-tenant practice operating system for dental practices. This Privacy Policy describes how we collect, use, disclose, and protect information when you interact with our website, sales process, and platform.
1. Who this policy covers
- Practice owners and staff who use Alvero as a customer-facing operator.
- Patients whose information is processed by their dental practice through Alvero (the practice — not Alvero — is the Custodian / Covered Entity; Alvero acts as a Service Provider / Business Associate / Information Manager under applicable law).
- Website visitors browsing alvero.dental.
2. What we collect
- Account information: name, email, phone, practice name and address, role, login credentials.
- Practice operational data: appointment records, financial summaries, staff scheduling, recall queues, and any data you connect via your practice management system (e.g. Dentrix).
- Protected Health Information (PHI / PHIPA-regulated data): only as necessary to provide the contracted service, processed under a Data Processing Agreement and/or Information Manager Agreement.
- Telemetry: logs, error reports, feature-usage events — anonymized wherever possible.
- Website analytics: standard first-party analytics. We do not sell this data.
3. How we use it
- Provide and operate the Alvero platform under your service agreement.
- Deliver agent-generated insights, briefings, and workflows to your authorized users.
- Maintain audit logs required by HIPAA, PHIPA, and equivalent Canadian provincial law.
- Improve the platform — including model evaluation — using data that has been de-identified or aggregated, unless your contract specifies otherwise.
- Communicate with you about your account, billing, security incidents, and material product changes.
4. How we protect it
- Tenant-isolated infrastructure with row-level security.
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access control with full audit trail.
- Human approval on every outbound PHI event in Messenger workflows.
- Background-checked staff with least-privilege access to production data.
- Annual third-party security review (next: Q4 2026).
5. Who we share with
- Sub-processors strictly necessary to operate the service. Current sub-processor list available on request.
- You and your authorized users — within your tenant boundary.
- Regulators and law enforcement — only where legally required.
- We do not sell personal information. Ever.
6. Your rights
You have the right to access, correct, or request deletion of your personal information. Patients whose PHI is processed through Alvero should contact their dental practice (the Custodian); Alvero will support the practice in honouring those requests.
7. Retention
Account data is retained while your contract is active and for the period specified in your service agreement after termination (typically 90 days for active export, then secure deletion). PHI retention is governed by your practice's regulatory obligations.
8. International data
Alvero is operated from Canada. By default, all customer data is processed and stored in Canadian data centres. Cross-border processing, if any, is disclosed in your Data Processing Agreement.
9. Contact
- Privacy questions: [email protected]
- Security incidents: [email protected]
- General contact: [email protected]
- Mailing address: Alvero Dental Systems Inc., Kelowna, British Columbia, Canada
10. Changes to this policy
We will post material changes here and notify active customers by email at least 30 days before the changes take effect.