Artemis Ortho App Privacy Policy
Effective date: May 15, 2026 · Last updated: June 30, 2026
1. Scope of this policy
This Privacy Policy describes how Artemis Ortho App (the "Application", "Platform", or "Service"), operated by Artemis Technologies LLC ("we", "us", or "the Operator"), collects, uses, stores, and protects information. The Application is a multi-tenant practice-management and analytics platform provided to orthodontic and dental practices ("Customer Practices" or "Practices") and used by each Practice's authorized workforce to run that practice. It is not a patient-facing service and is not used to deliver care directly to patients.
Each Customer Practice is an independent Covered Entity under HIPAA. We act as a Business Associate to each Practice under a signed Business Associate Agreement (BAA), and we process patient information only on the Practice's behalf and on its documented instructions. For information specific to patient-facing services at a particular practice, see that practice's own Notice of Privacy Practices and public privacy policy.
2. Information we process
On behalf of Customer Practices, the Application processes the following categories of information:
- Patient demographics, clinical records, treatment plans, scheduling, and financial records imported from each Practice's Cloud 9 Ortho instance and other connected sources
- Communication logs (SMS, email, call notes) associated with patient outreach
- Workforce account information (name, email, role, permissions, authentication metadata, session and audit logs)
- Operational metrics derived from the data sources above (KPIs, funnel counts, AR aging, chair utilization)
- Marketing and acquisition data (lead sources, ad spend, review counts) from connected providers
Patient data processed by the Application includes electronic protected health information (ePHI) as defined under HIPAA, 45 CFR Parts 160 and 164. Each Practice's data is logically isolated from every other Practice's data; the Operator does not use one Practice's data for the benefit of another.
3. How we use information
We use the information above solely to provide the Application to Customer Practices and on their behalf, including:
- Supporting each Practice's treatment, payment, and healthcare operations as permitted under HIPAA, 45 CFR § 164.506
- Internal reporting and clinical-quality review within a Practice
- Scheduling, recall, and patient communication coordinated by a Practice's staff
- Workforce management, including access control, training, and audit-log review
- Operating, securing, maintaining, and improving the Application, and providing support to Customer Practices
- Compliance with legal, regulatory, and contractual obligations, including the BAA
The Operator does not sell, rent, or share ePHI with third parties, does not use ePHI for the Operator's own marketing or advertising, and does not perform automated decision-making that produces legal or similarly significant effects on patients.
4. HIPAA roles and patient rights
Each Customer Practice is the Covered Entity under HIPAA and the Operator is its Business Associate. Patient rights regarding ePHI — including the right to access, amend, request restrictions, request confidential communication, and receive an accounting of disclosures — are administered by the Practice and described in the Practice's Notice of Privacy Practices, available from the Practice. The Operator supports each Practice in fulfilling these obligations through the Application. This Privacy Policy supplements, but does not replace, each Practice's Notice of Privacy Practices.
5. Social media platform integrations
Artemis Ortho App can integrate with a Practice's own social media accounts (TikTok, Meta — Facebook and Instagram, and YouTube) so the Practice's marketing team can view post performance, audience metrics, and content history inside the dashboard. These integrations connect the Practice's own brand accounts; no patient data is sent to any social platform, and no third-party user data is collected. Patients are not asked to log in or to share their own social media accounts with the Application.
TikTok Login Kit and Content Posting API. The Application uses TikTok OAuth for the Practice's brand account. The exact scopes requested and how each is used are listed below. The Application does not use TikTok's Display API and does not read the connected account's follower counts, post metrics, or video list.
| TikTok scope | Data obtained | How Artemis Ortho App uses it |
|---|---|---|
user.info.basic | Open ID, display name, avatar, account type | Identifies which TikTok account is connected, so Practice staff confirm the correct publishing target before posting. |
video.publish | A video file the Practice created in the dashboard's Social Planner, plus its caption and privacy setting | Directly posts the Practice's own video to its own connected TikTok account when a Practice user explicitly chooses to publish from the Social Planner. |
video.upload | A video file the Practice created in the dashboard's Social Planner | Uploads the Practice's own video to its own connected TikTok account's inbox/drafts ("Send to TikTok drafts") when a Practice user explicitly chooses to, so they can finish posting from the TikTok app. TikTok bundles this scope with video.publish in the Content Posting API. |
Read access (profile and video metadata) is fetched read-only via the official TikTok APIs and stored only to the extent needed to render the dashboard. Posting is performed solely via TikTok's Content Posting API, only with content the Practice itself created and scheduled in the Social Planner, and only to the Practice's own connected TikTok account — the Application never posts to any other account, never posts without an explicit Practice action, and never transmits TikTok data to third parties. All TikTok data and tokens are purged when the Practice disconnects the integration. Meta and YouTube integrations follow the same pattern using their respective Graph API and Data API endpoints.
6. Subprocessors and third-party service providers
The Application is built on the following subprocessors. Every subprocessor with access to ePHI operates under a signed Business Associate Agreement (BAA) with the Operator.
| Provider | Purpose | BAA status |
|---|---|---|
| Google Cloud Platform | Application hosting, database | BAA on file |
| Anthropic | AI assistant (Artemis) | BAA on file |
| Cloud 9 Ortho | Practice management source-of-truth | BAA on file |
7. Security safeguards
The Application operates under the HIPAA Security Rule, with administrative, physical, and technical safeguards including role-based access control, TLS 1.2+ encryption in transit, AES-256 encryption at rest, multi-factor authentication, PHI audit logging, automatic session timeout, annual security risk assessments, and an incident-response procedure aligned with 45 CFR § 164.404.
8. Data retention and deletion
Data is retained in accordance with HIPAA (minimum 6 years for audit logs), each Practice's documented instructions, and applicable state dental-board record-retention requirements (which vary by state — for example, many states require records to be kept for several years after last patient contact, and longer for minors). Application data derived from Cloud 9 is refreshed on a rolling basis; upon termination of a Practice's subscription or its Cloud 9 integration, locally cached copies of that Practice's data will be deleted or returned within 30 days, except as required by law or the BAA.
9. California privacy rights (CCPA / CPRA)
The Application processes medical information that is exempt from the California Consumer Privacy Act and the California Privacy Rights Act to the extent it is governed by HIPAA and the Confidentiality of Medical Information Act (CMIA). For non-exempt categories of personal information, California residents may request to know, delete, or correct their personal information, and may opt out of the sale or sharing of personal information. Neither the Operator nor, to the Operator's knowledge, the Customer Practices sell or share personal information.
To exercise these rights, contact the Operator's Privacy Officer at the address below, or contact the relevant Customer Practice directly.
10. Children's privacy
The Application is used by Practice workforce only and is not directed to children. Patient records for minors are processed on behalf of a Practice as part of providing orthodontic care, with the involvement of a parent or legal guardian as required by applicable law.
11. Google API Services and Limited Use
Artemis Ortho App can connect to a Practice's own Google accounts so the Practice can see its marketing and operations data inside the dashboard. The Application requests only the minimum Google OAuth scopes its live features use; a Practice user authorizes the connection and can revoke it at any time from their Google Account or by disconnecting the integration in the dashboard. No patient data is sent to Google through these integrations, and no third-party (non-Practice) user data is collected.
| Google scope | Data obtained | How Artemis Ortho App uses it |
|---|---|---|
adwords | The Practice's own Google Ads campaign, cost, and conversion metrics | Shows ad spend and lead-source ROI on the Growth dashboard. |
analytics.readonly | The Practice's own Google Analytics traffic and acquisition data (read-only) | Renders website-traffic and channel KPIs on the Growth dashboard. |
business.manage | The Practice's own Google Business Profile listing, reviews, and insights | Surfaces local-listing performance and inbound reviews, and lets the Practice reply to its own reviews. |
webmasters.readonly | The Practice's own Search Console search-performance data (read-only) | Powers the SEO local-ranking and search-query views. |
blogger | The Practice's own Blogger blog posts | Publishes Practice-authored SEO blog content the Practice creates in the dashboard. |
calendar.readonly | The Practice's own Google Calendar events (read-only) | Displays the Practice's booking/availability calendar inside the dashboard. |
drive.readonly | Files the Practice explicitly selects from its own Google Drive (read-only) | Imports Practice-chosen marketing assets (e.g. doctor photos) into the dashboard; the Application reads only files the Practice picks and never the whole Drive. |
youtube.upload, youtube.readonly | The Practice's own YouTube channel and videos | Lists the Practice's channel and publishes Practice-created videos as Shorts when a Practice user explicitly chooses to from the Social Planner. |
Limited Use. Artemis Ortho App's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained through Google APIs is used only to provide and improve the user-facing features described above; is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition; is not used for advertising; and is not used by, or transferred to, humans except with the Practice's explicit consent, to comply with applicable law, or for security purposes (e.g. investigating abuse).
12. Text messaging (SMS) and mobile opt-in
A Customer Practice may send text messages to patients and their responsible parties through the Application. Messages are transactional and relate to care with that Practice — appointment confirmations and reminders, treatment updates, and account or billing notifications. Message frequency varies. Message and data rates may apply. Reply STOP to any message to opt out, or HELP for help.
A mobile number is enrolled only after the patient or responsible party actively opts in: by ticking the unchecked SMS consent box on the Practice's online booking form, by answering Yes to the text-message consent question on the new-patient intake forms, or by signing the same consent on the Practice's paper intake forms in the office. Consent is never a condition of treatment, and the wording shown at the moment of opt-in is stored with a timestamp as a record of that consent. Replying STOP or UNSUBSCRIBE suppresses the number immediately; replying START resumes messages.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All of the information-sharing categories described elsewhere in this policy exclude text-messaging originator opt-in data and consent; that information is not shared with any third party. Mobile numbers and consent records are disclosed only to the messaging carriers and the telecommunications subprocessor strictly necessary to transmit the Practice's own messages, and only for that purpose.
13. Changes to this policy
The Operator may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notice to affected Customer Practices.
14. Contact
Artemis Technologies LLC
Attn: James Seay, Privacy Officer
346 Redland Rd NW, Atlanta, GA 30309
Phone: +1 (855) 964-4793
Email: Info@artemisorthoapp.com
© 2026 Artemis Ortho App. All rights reserved.