Effective date: 22 September 2026. Version: 1.0.
Answerdent is an AI telephone receptionist for dental practices. This policy explains what information we collect, how we use it, who we share it with, and the choices you have. It is written for two audiences: the dental practices that are our customers, and the patients and callers whose calls our service answers.
If you are a patient, please read section 2 first. Your dentist, not Answerdent, decides how your health information is used, and your dentist's own Notice of Privacy Practices governs it.
Who we are. Answerdent, doing business as Answerdent, Sofia, Bulgaria. Contact: privacy@answerdent.com.
1. Two roles, two kinds of information
Patient and call information. When a practice uses Answerdent, our service answers the practice's phone line, talks to callers, and reads and writes appointment and patient information in the practice's practice management system. That information is Protected Health Information under the US Health Insurance Portability and Accountability Act (HIPAA). We handle it only on behalf of the practice, as its business associate, under a Business Associate Agreement with each practice. We do not own it, we do not sell it, and we do not use it for our own purposes beyond running the service.
Practice account and website information. Information about the practice itself and the people who run it (names, email addresses, phone numbers, login details, billing details, settings) and information from visitors to answerdent.com. For this information we are the controller and this policy applies directly.
2. Information from calls (patients and callers)
When you call a practice that uses Answerdent, the call is answered by an automated receptionist. During the call we may collect:
- The number you are calling from and the number you called.
- What is said on the call: the audio of the conversation and a written transcript of it.
- Information you give the receptionist to identify you or to book: your name, phone number, date of birth, email address, the type of appointment you want, and the times you prefer.
- Appointment records the receptionist creates, moves or cancels in the practice's scheduling system, and the existing appointment and patient records it reads to help you.
- Messages you ask the receptionist to pass to the practice, including any call-back number you give.
- A short automatic summary of the call.
Automated receptionist. The receptionist is an AI system, not a person. The practice is responsible for telling callers this where the law requires it; our standard greeting can be set by the practice to say so.
Recording. Calls are recorded and transcribed so that the receptionist can work, so that the practice can review what was said, and so that we can fix problems. The practice is responsible for any recording notice required in its state. We recommend that every practice keeps the recording notice in the receptionist's greeting.
How we use it. Only to provide the service to the practice: to identify you, to book, move or cancel your appointment, to answer your questions from information the practice has given us, to take a message, and to show the practice a record of the call. We do not use call content or patient information to train artificial-intelligence models, and we do not allow our vendors to.
Where it goes. Appointment and patient records are written into the practice's own practice management system through NexHealth. Transcripts, summaries and messages are stored in Answerdent's database and shown to the practice in its dashboard. See section 5 for the vendors involved.
Your rights. Because your dentist controls your health information, requests to see, correct, or get an accounting of your information go to your dentist. If you contact us directly we will forward your request to the practice within five business days and tell you we have done so.
3. Information from practices (our customers)
When a practice signs up and uses Answerdent we collect:
- Account details: practice name, address, the EHR or practice management system used, the contact's name, email address and mobile number, and a password (stored only as a one-way hash).
- Settings the practice enters: appointment types and lengths, dentists and what they do, office hours, greeting, receptionist name and voice, and answers to common caller questions such as address, parking, insurance accepted and what to do in an emergency.
- Billing details, when billing starts, handled by our payment processor; we will not store full card numbers.
- Usage and technical logs: pages visited in the dashboard, actions taken, IP address, browser type, timestamps, and error logs.
- Email we exchange with the practice for support.
How we use it. To create and run the account, to configure and operate the receptionist for the practice, to bill, to provide support, to send service emails (verification, password reset, notice of a new message, changes to terms), to secure the service, and to understand how the service is used in aggregate.
Marketing. We may email practices about Answerdent features. Every such email has an unsubscribe link. We do not sell or rent practice contact information.
4. Information from website visitors
answerdent.com collects only what a web server ordinarily collects: IP address, browser type, pages requested and timestamps, kept in server logs for security and troubleshooting. The site uses a session cookie for logged-in users and no advertising or third-party analytics cookies. If you email us, we keep the email to reply and for our records.
5. Who we share information with
We share information only with the vendors we need to run the service, each bound by contract to protect it. Before we handle patient information for a practice, each vendor that will handle that information is bound by a Business Associate Agreement with us.
| Vendor | What they do | What they receive |
|---|---|---|
| NexHealth, Inc. | Connects Answerdent to the practice's practice management system | Patient and appointment records read from and written to the practice's system |
| ElevenLabs, Inc. | Runs the conversational voice AI that speaks with callers | Call audio and the conversation, processed in real time; configured to retain nothing after the call |
| Twilio, Inc. | Telephone carrier for the receptionist's phone number | Call audio and phone numbers in transit; call metadata |
| Railway Corp. | Hosts the Answerdent application and database | All information stored by Answerdent, encrypted |
| Resend, Inc. | Sends our service emails | Practice account emails and email content. Our emails do not contain patient information. |
| Cloudflare, Inc. | Domain, DNS and web traffic protection | Web request metadata |
We also disclose information when required by law, such as a subpoena or court order, and where necessary to protect the rights, safety or property of Answerdent, our customers or the public. If Answerdent is acquired or merges, information may transfer to the successor, which will be bound by this policy, and we will notify practices.
We will give practices at least thirty days' notice by email before adding a vendor that handles patient information.
6. How long we keep information
- Call transcripts, summaries, recordings and messages: ninety (90) days from the call, after which they are deleted automatically. The practice's dashboard therefore shows the last ninety days of call history. Messages the practice has not yet marked as done are kept until they are marked done, then deleted on the same schedule. When an account is closed, everything is deleted within thirty days, unless the practice asks us to return it first or the law requires us to keep it longer.
- Appointment and patient records in the practice's system: these belong to the practice and stay in its practice management system. We keep a log of the bookings, changes and cancellations the receptionist made, so the dashboard can show counts, for the same ninety days.
- Practice account information: for the life of the account and up to seven years afterwards for tax, accounting and legal purposes.
- Server and security logs: up to twelve months.
7. How we protect information
Information is encrypted in transit (TLS) and at rest. Access to systems that hold patient information is limited to the people and services that need it, with individual credentials and access logging. Passwords are stored as one-way hashes. Our vendors that handle patient information are bound by Business Associate Agreements and are chosen for their own security programs. We maintain an incident response plan and will notify affected practices of a breach of unsecured patient information without unreasonable delay, and in any case within ten business days of discovery, so that the practice can meet its own obligations. No system is perfectly secure and we cannot guarantee against every loss.
8. Cookies and tracking
We use one strictly necessary cookie to keep a practice user logged in. We do not use advertising cookies, cross-site tracking, session replay tools or third-party analytics. Your browser can block or delete cookies; the dashboard will not work without the login cookie.
9. Children
The service is for dental practices and the people who call them. Callers may be booking for a child; that information is handled as patient information under section 2 on behalf of the practice. We do not knowingly collect information directly from children under 13 online.
10. Where information is stored
Answerdent stores and processes information in the United States. Our service is offered to practices in the United States. If we offer the service elsewhere in future, this policy will be updated with the applicable rules.
11. Your choices and rights
Practices can view and change their account and settings in the dashboard, export their call history on request, and close the account at any time from the dashboard or by email. Closing the account triggers the deletion schedule in section 6.
Patients exercise their rights through their dental practice, as explained in section 2.
California residents. If the California Consumer Privacy Act applies, you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and not to be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioural advertising. Patient information handled under HIPAA on behalf of a practice is exempt from the CCPA and requests about it go to the practice. To exercise these rights, email privacy@answerdent.com; we will verify your identity by confirming the email on your account.
Other states. Residents of other US states with privacy laws have similar rights and can use the same contact.
12. Changes to this policy
We may update this policy. For material changes we will email practices at least thirty days before the change takes effect and show the new effective date at the top. Continued use of the service after that date is acceptance of the updated policy.
13. Contact
Email privacy@answerdent.com or write to Answerdent, Sofia, Bulgaria. Practices with a question about their Business Associate Agreement can use the same address.