Artemis Ortho App logo

Artemis Ortho App Terms of Service

Effective date: May 15, 2026  ·  Last updated: July 31, 2026

1. About this application

Artemis Ortho App (the "Application", "Platform", "Service", or "Artemis Ortho App") is a multi-tenant practice-management and analytics platform operated by Artemis Technologies LLC ("we", "us", or "the Operator") and provided to orthodontic and dental practices ("Customer Practices" or "Practices").

The Application consolidates clinical, financial, scheduling, marketing, and social-media performance data into a single dashboard so each Practice's workforce can manage day-to-day operations, monitor key performance indicators, and coordinate patient communication. Access is provisioned by each Customer Practice for its authorized workforce; no self-registration is offered to the public.


2. Who may use this application

Access is restricted to the authorized workforce of a Customer Practice and to contractors who are bound by appropriate confidentiality and HIPAA obligations. The Application is not available to the public, to patients, or to any third party not authorized by a Customer Practice. All accounts are provisioned by the relevant Practice's administrators.

If you have received access in error, cease use immediately and contact Info@artemisorthoapp.com.


3. Data accessed through Cloud 9 Ortho

On each Practice's behalf and on its instructions, the Application integrates with that Practice's Cloud 9 Ortho instance via its developer API and reads patient demographics, clinical records, scheduling data, financial records, and communication logs. This data is used solely to provide the Application to that Practice. It is not shared with, sold to, or transmitted to any third party except as required to deliver the Application's services under a signed Business Associate Agreement (BAA), or as required by law.


4. Social media platform integrations (TikTok, Meta, YouTube)

Artemis Ortho App can connect to a Practice's own brand accounts on TikTok, Meta (Facebook and Instagram), and YouTube. These integrations are used to show the Practice's social-media performance inside the dashboard and, where the Practice chooses, to publish content the Practice created in the dashboard to its own connected accounts. No patient information is transmitted to any social platform, and the Application does not collect data from any third-party user of those platforms. Patients do not log in to the Application and are not asked to connect their own social media accounts.

TikTok Login Kit and Content Posting API. The Application requests the following TikTok scopes against the Practice's brand TikTok account, each strictly limited to the use described. The Application does not use TikTok's Display API and does not read the connected account's follower counts, post metrics, or video list:

  • user.info.basic — open ID, display name, avatar, account type. Used to confirm which TikTok account is connected, so Practice staff verify the publishing target before posting.
  • video.publish — directly posts a video the Practice created in the Social Planner to the Practice's own connected TikTok account, only when a Practice user explicitly chooses to publish.
  • video.upload — uploads a video the Practice created in the Social Planner to the Practice's own connected TikTok account's inbox/drafts ("Send to TikTok drafts"), so the Practice can finish posting from the TikTok app. TikTok bundles this scope with video.publish in the Content Posting API.

The Application posts only content the Practice itself created and scheduled in the dashboard, only to the Practice's own connected TikTok account, and only on an explicit Practice action; it never posts to any other account, never sends direct messages, and never accesses data about TikTok users other than the connected Practice account. Tokens are stored encrypted server-side and revoked when the integration is disconnected from the dashboard.


5. HIPAA compliance

Data accessed by this Application includes electronic protected health information (ePHI) as defined under HIPAA, 45 CFR Parts 160 and 164. Each Customer Practice is a Covered Entity under HIPAA, and the Operator acts as its Business Associate under a signed Business Associate Agreement. The Application operates under the HIPAA Security Rule and Privacy Rule, with role-based access control, TLS 1.2+ encryption in transit, AES-256 encryption at rest, PHI audit logging, and annual security risk assessments. All subprocessors that handle ePHI have executed Business Associate Agreements.


6. Subprocessors and third-party service providers

ProviderPurposeBAA status
Google Cloud PlatformApplication hosting, databaseBAA on file
AnthropicAI assistant (Artemis)BAA on file

7. Data retention and deletion

Data is retained in accordance with HIPAA requirements (minimum 6 years for audit logs), each Practice's documented instructions, and applicable state dental-board record-retention requirements (which vary by state). Upon termination of a Practice's subscription or its Cloud 9 integration, locally cached copies of that Practice's Cloud 9 data will be deleted or returned within 30 days, except as required by law or the BAA.


8. Security incident notification

In the event of a security incident involving a Practice's data, the Operator will notify the affected Practice without unreasonable delay and consistent with the BAA, and will follow HIPAA breach notification procedures (§164.404) and applicable state law. Where required by an integration agreement (for example, with Cloud 9), the Operator will provide the corresponding notice within the applicable timeframe.


9. Prohibited uses

The following are prohibited for all users:

  • Accessing or transmitting ePHI for any purpose beyond legitimate practice operations
  • Sharing login credentials with any other person
  • Accessing data beyond what your assigned role permits, or attempting to access another Practice's data
  • Bulk-exporting patient records without authorization from the relevant Practice
  • Circumventing or disabling any security control

Violations may constitute a violation of HIPAA, the Computer Fraud and Abuse Act (18 U.S.C. § 1030), or other applicable law.


10. Availability and changes

The Application is provided to Customer Practices under their subscription agreement and without any uptime guarantee except as expressly stated in that agreement. The Operator may modify, suspend, or discontinue the Application as permitted by the subscription agreement. These Terms may be updated from time to time; continued use after an update constitutes acceptance of the revised Terms.


11. Limitation of liability

To the maximum extent permitted by law, the Operator's liability for any claim arising out of or related to the Application is limited as set out in the applicable subscription agreement, and the Operator is not liable for indirect, incidental, consequential, or punitive damages of any kind. Nothing in these Terms limits either party's obligations under the BAA.


12. Governing law

These Terms are governed by the laws of the State of Georgia, without regard to conflict-of-law principles. Disputes shall be resolved in the state or federal courts located in Fulton County, Georgia, except where a Customer Practice's subscription agreement specifies otherwise.


13. Text messages to patients (SMS)

The Application sends text messages to patients on a Practice's behalf — appointment reminders and confirmations, scheduling and rescheduling notifications, treatment updates, and account or billing notifications. It does not send marketing or promotional text messages.

Opting in is voluntary. A mobile number is enrolled only after the patient or responsible party actively opts in: by ticking the SMS consent box — unchecked by default — on the Practice's online booking form, by answering Yes to the text-message consent question on the new-patient intake forms, or by signing the same consent on the Practice's paper intake forms in the office. Providing a phone number, booking an appointment, submitting a form, or accepting these Terms does not by itself opt anyone in.

Consent to receive text messages is never a condition of booking an appointment, of purchase, of creating an account, of completing any transaction, or of receiving treatment. A patient who declines receives exactly the same care and is contacted by phone and email instead.

Message frequency varies with appointment activity. Message and data rates may apply. Reply STOP or UNSUBSCRIBE at any time to stop messages, START to resume, or HELP for help — or call the Practice. The wording shown at the moment of opt-in is stored with a timestamp as the record of that consent. No mobile information or opt-in consent is shared with third parties or affiliates for marketing or promotional purposes.


14. Contact

Artemis Technologies LLC

Attn: James Seay

346 Redland Rd NW, Atlanta, GA 30309

Phone: +1 (855) 964-4793

Email: Info@artemisorthoapp.com