1. Introduction
IntelliDent provides software for dental practices in Australia: AI voice and chat receptionist agents, appointment booking and reminders, patient communication tools, and related practice administration features (the “Service”). The Service is operated by [LEGAL ENTITY NAME] (ABN [ABN]) (“IntelliDent”, “we”, “us”).
This policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It describes what the Service actually does today. Where something depends on how a practice configures the Service, we say so.
IntelliDent is an administrative tool. It does not diagnose conditions, give clinical advice, recommend treatment, or replace a dentist or other health professional.
2. Scope and roles
This policy applies to personal information about:
- visitors to our website, including people who use our contact form or website chat;
- our customers (dental practices) and the staff who use the Service;
- patients and other people who call, message, or are contacted by a practice through the Service; and
- people at dental practices we contact about our Service.
Practices and IntelliDent
When a practice uses the Service, it decides what patient information to collect and why. The practice remains responsible for its own obligations to its patients under privacy and health records laws, including giving patients collection notices, obtaining any consent that is required, responding to patients’ access and correction requests, and keeping health records for the periods the law requires. Each practice should have its own privacy policy.
We handle patient information to provide the Service to the practice, under our agreement with the practice and this policy. We are responsible for how we handle the information we hold, including keeping it secure and using it only as described here. Using IntelliDent does not transfer a practice’s legal responsibilities to us.
3. Information we collect
Customer and user information
- Practice and account details: practice name, locations, staff names, email addresses, phone numbers, and user roles.
- Login information: passwords (stored as salted hashes, never in plain text) or, if you use Google sign-in, your name, email address, and Google profile identifier.
- Billing information: billing contact details and transaction records. Payments are processed by Stripe; we do not receive full card numbers.
- Practice configuration: opening hours, services and prices, practitioner names, knowledge base documents and website content you add, AI agent instructions, and credentials for integrations you connect.
Information about people who contact a practice
- Caller and recipient phone numbers, and the time and duration of calls.
- Recordings of calls handled by the AI agent, and transcripts of what was said.
- Chat and message content sent through a practice’s chat widget, SMS, email, or WhatsApp.
- Details used to identify a caller and manage appointments, such as name, date of birth, email address, and appointment history.
- The type of request the AI identified (for example, booking or rescheduling).
4. Patient and health information
Health information is sensitive information under the Privacy Act. The Service handles it in two main ways:
- Patient records. Practices can store patient details in the Service, including name, date of birth, gender, contact details, address, emergency contact, appointment history, notes, and, if the practice chooses to record them, medical history, allergies, medications, medical alerts, and insurance details. Practices can import patient lists from spreadsheets.
- Conversations. Callers often mention health matters, such as a toothache or the reason for a visit. That appears in call recordings, transcripts, and chat messages.
We handle this information only to provide the Service to the practice, as described in this policy.
5. How we collect information
- Directly from you, when you register, use the Service, contact us, or chat on our website.
- From practices, when they enter, import, or sync information about their patients and staff.
- From callers and message senders, through the practice’s AI agents.
- From services a practice connects, such as calendars and CRMs.
- From Google, if you sign in with Google, and from Stripe for billing.
- Automatically, from your browser or device, such as IP address and cookies needed to run the site (see section 14).
- For our own sales activity, from publicly available business sources, such as dental practice contact details published online.
6. How we use information
- To provide the Service: answering calls and messages, booking, rescheduling and cancelling appointments, sending reminders, and escalating to practice staff.
- To let practice staff review call history, recordings, transcripts, and conversations.
- To manage accounts, provide support, and bill for the Service.
- To operate, secure, and troubleshoot the Service, including monitoring usage such as call counts, response times, and AI token usage.
- To prevent spam, fraud, and misuse.
- To comply with the law and enforce our agreements.
- To contact people at dental practices about IntelliDent. You can opt out at any time (section 16).
We do not sell personal information.
7. AI and automated processing
AI agents generate replies using large language models from OpenAI or Anthropic, chosen by the practice for each agent. To produce a reply, we send the provider the conversation so far, the agent’s instructions, relevant practice information and knowledge base content and, where a caller has been identified, context such as their name and upcoming appointments. We also use OpenAI to classify what a caller is asking for and to index knowledge base content for search, and, where a practice turns on patient search, patient records.
Agents can book, reschedule, and cancel appointments within the permissions the practice sets. They are instructed not to diagnose, give clinical advice, or recommend treatment, and to direct life-threatening emergencies to 000. AI output can be wrong; practices should review their agents’ configuration and the bookings they make.
AI model training
We do not use customer data or patient information to train or fine-tune AI models. The one exception is a feature a customer must request themselves: a customer on an eligible plan can upload its own training file to create a custom model for its own agents. That file is sent to OpenAI for that purpose. We automatically remove some identifiers from it first, but that removal is pattern-based and will not catch everything, so customers should not include patient information in training files.
AI provider data handling
AI providers process the information we send under their own terms, which may allow them to retain it for a limited period, for example for abuse monitoring. We do not claim that providers retain no data. If a practice supplies its own AI API key, the provider processes that agent’s conversations under the practice’s own account and terms.
8. Voice calls, recordings, and transcripts
- Recording and transcription. Calls answered or made by an IntelliDent AI voice agent, including appointment reminder calls, are recorded and transcribed.
- Caller notice. At the start of each of these calls, the caller hears that they are speaking with an AI assistant and that the call is recorded and transcribed. Practices can reword the notice, but the Service keeps the recording notice and adds an AI notice if the wording leaves it out.
- Where recordings are kept. Twilio records the call. We copy the recording to our storage on AWS in Australia. A copy may also remain with Twilio.
- Transcripts. Transcripts are stored with call details (phone numbers, time, duration) and linked to a patient record when the caller’s phone number matches one.
- Identifier removal. Before a caller’s words are sent to the AI model or stored, we automatically try to remove payment card numbers and security codes, Medicare numbers, health fund membership numbers, tax file numbers, and bank details. This is pattern-based and can miss or over-remove information. Names, phone numbers, dates of birth, and appointment details are kept, because practices need them.
- Access. Authorised users of the practice’s account can view call history, transcripts, and recordings.
- Deletion. Practice administrators can delete a call’s recording and transcript from the dashboard.
Laws on recording calls differ between states and territories. Each practice is responsible for making sure its use of call recording is lawful and that its patients are properly informed (section 13). Calls made by IntelliDent’s own sales team are also recorded, and the other party is told at the start of the call.
9. How we share information, and overseas disclosure
We disclose personal information to:
- the practice the information belongs to, and the users it authorises;
- our service providers, listed on our Subprocessors page, who process information for us to provide the Service;
- services a practice chooses to connect, such as its calendar or CRM;
- our professional advisers, under confidentiality obligations;
- a buyer or successor, if our business is sold or restructured, subject to confidentiality; and
- government bodies or others where the law requires or permits it.
Overseas disclosure
Our database and file storage, including call recordings and transcripts, are hosted on AWS in Australia. However, some providers process information outside Australia, mainly in the United States:
- Twilio (calls, recordings, SMS, WhatsApp) — United States;
- Google speech services used through Twilio during calls — outside Australia;
- OpenAI and Anthropic (AI replies, classification, and search indexing) — United States;
- Stripe (billing) and Google (reCAPTCHA and sign-in) — United States and other countries.
Before disclosing personal information to an overseas recipient, we take reasonable steps to make sure the recipient handles it consistently with the APPs, including by using providers whose terms restrict how they use the information. The Subprocessors page is kept up to date.
10. Data security
We take reasonable steps to protect personal information, including:
- encrypting information in transit using HTTPS/TLS;
- storing data on AWS database and storage services that encrypt data at rest;
- hashing passwords;
- separating each practice’s data by organisation, with role-based permissions for practice users;
- checking that telephony webhooks genuinely come from Twilio;
- keeping credentials in a secrets manager rather than in code; and
- automated code, dependency, and secret scanning in our development process.
No system is completely secure, and we cannot guarantee that information will never be accessed without authorisation. If we experience a data breach that is likely to cause serious harm, we will follow the Notifiable Data Breaches scheme, including notifying affected practices, individuals, and the Office of the Australian Information Commissioner where required.
11. Retention
- We keep account, practice, and patient information, call recordings, transcripts, and conversation records while the practice’s account is active. The Service does not currently delete these automatically after a fixed period.
- Practices decide how long to keep patient information, and are responsible for meeting health record retention requirements. Practice administrators can delete individual call recordings and transcripts.
- When an account ends, we handle customer data as set out in our Terms of Service.
- We keep billing records for as long as tax and accounting laws require.
- Deleted information may remain in backups, logs, or our providers’ systems for a period before it is overwritten or removed in the ordinary course.
12. Access, correction, and deletion
You can ask for access to, or correction of, personal information we hold about you by emailing [email protected]. We may need to verify your identity. We aim to respond within 30 days. If we refuse a request, we will explain why, unless it would be unreasonable to do so.
If you are a patient of a practice, please contact the practice first. It controls your patient record and can access, correct, or delete it. If you contact us, we will refer your request to the practice and help it respond.
Practices can correct patient details in the dashboard. Deleting a patient in the dashboard hides the record from normal use but keeps the underlying record, and it does not delete that patient’s call recordings or transcripts. To have information erased completely, contact us.
13. Practice responsibilities
Practices using the Service are responsible for:
- having a lawful basis, and any required consent, to collect and use patient information in the Service;
- telling patients in their own privacy policy and collection notices that they use IntelliDent, including AI call handling, call recording, and overseas processing;
- making sure call recording is lawful in each state or territory where they operate;
- deciding who in the practice can access information, and keeping login details secure;
- checking the accuracy of the information and instructions they give their AI agents;
- handling patients’ access, correction, and complaint requests about patient records; and
- meeting their own record-keeping and data breach obligations.
14. Cookies and similar technologies
Our website and dashboard use:
- cookies that keep you signed in and keep the dashboard secure;
- a cookie that identifies your browser to the live demo so we can limit how often it is used; and
- Google reCAPTCHA on forms, which uses cookies and device information to detect spam.
We do not currently use analytics or advertising cookies. The live voice demo on our website uses your browser’s built-in speech recognition, which your browser provider may process.
15. Children
The Service is for businesses, and its users must be adults. Practices may hold information about patients who are children, which we handle for the practice in the same way as other patient information.
16. Direct marketing
We may contact people at dental practices about IntelliDent using business contact details. Every marketing email includes a way to unsubscribe, and you can ask us to stop at any time by emailing [email protected]. We do not use patient information for our own marketing.
17. Privacy questions and complaints
If you have a question or complaint about how we handle personal information, email [email protected] with details. We will acknowledge your complaint, look into it, and aim to respond in writing within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992.
18. Contact us
- [LEGAL ENTITY NAME] (ABN [ABN]), trading as IntelliDent
- Address: [REGISTERED ADDRESS]
- Email: [email protected]
19. Changes to this policy
We will update this policy when our practices change. The date at the top shows when it was last revised. If we make a material change, we will tell customers by email or in the Service before it takes effect.