Legal
Privacy Policy
Effective 2026-07-13
Effective date: July 13, 2026 | Last updated: July 13, 2026
This Privacy Policy explains how Dentist Owners LLC ("Dentist Owners," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information when you visit dentistowners.com or use our onboarding and deal-room platform (together, the "Platform"). It also describes the privacy rights available to residents of California, Oregon, and other U.S. states, and how to exercise them.
Dentist Owners LLC is organized under, and this Policy is governed by and construed in accordance with, the laws of the State of Oregon, without regard to its conflict-of-laws rules and to the extent not preempted by applicable federal or other state privacy law that grants you greater rights.
1. Who we are and how to reach us
Dentist Owners LLC is the business responsible for (the "business" and "controller" of) the personal information described in this Policy. Because we operate online, our designated method for privacy questions and requests is email:
- Email: info@dentistowners.com
- Attention: Privacy — Dentist Owners LLC
If you are an authorized advisor (accountant, attorney, lender, co-owner, or, where applicable, an ESOP trustee) invited to the Platform by a practice owner, this Policy also applies to your use of the Platform.
2. Scope of this Policy — and what it does NOT cover
This Policy is a consumer-facing website and Platform privacy notice. It does not govern:
- Protected health information (PHI) or patient records. The Platform is for business records only. Any PHI, patient data, or limited data set that may be exchanged during diligence in a deal room is governed by the Mutual Non-Disclosure Agreement (NDA) and its data-handling protocol between the parties, and by a Business Associate Agreement (BAA) where one is required under HIPAA — not by this consumer Policy. Do not upload PHI to the Platform; see Section 4.
- The signed deal-room agreements. The definitive agreements you may sign in connection with a transaction — including the NDA, the Letter of Intent, the Participation/Contribution Agreement, the Contribution & Purchase Agreement, and the Subscription & Accredited-Investor Agreement — contain their own confidentiality and data-use terms, which control over this Policy as to the information exchanged under them.
Where we act as a service provider or processor for a customer's own data, our written Data Processing Addendum (DPA) governs that processing and, in the event of a conflict as to that data, controls over this Policy (see Section 8).
3. Notice at collection — categories of personal information
This section is our "notice at collection" under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), Cal. Civ. Code Sections 1798.100 and 1798.130, the Oregon Consumer Privacy Act (OCPA), and comparable disclosures under other state privacy laws. In the preceding 12 months we collect or may collect the following categories, each for the business and commercial purposes described in Section 6 and retained per the criteria in Section 11:
- Identifiers — name, email address, phone number, account username, and IP address.
- Account & security data — password (stored only as a salted, one-way hash), two-factor authentication (2FA) settings, and login/session records. *(Account log-in credentials are treated as sensitive personal information; see Section 5.)*
- Professional or employment-related information — your role, dental license/credential details you provide, and your relationship to a practice or entity.
- Practice, business, and commercial information — practice and ownership details, financial statements, operational and diligence documents, valuations, and other business records you choose to upload. These are records about a practice or entity; to the extent they contain information about an identifiable individual, we treat that information as personal information.
- Internet or network activity — log data, pages accessed, actions taken on the Platform, browser and device type, and basic analytics.
- Coarse geolocation — an approximate location derived from your IP address for security and fraud-prevention purposes (not precise GPS location).
- Inferences — limited inferences drawn from the above solely to operate, secure, and improve the Platform (we do not build advertising or behavioral profiles; see Section 12).
Categories we do NOT intentionally collect. We do not intentionally collect government identifiers (such as Social Security, driver's license, or passport numbers), financial-account numbers together with access codes, precise geolocation, biometric or genetic data, health information, or personal information revealing racial or ethnic origin, religious beliefs, union membership, sexual orientation, or the contents of your private communications. If you upload documents containing such information, please redact it first.
Sources of this information: directly from you; automatically from your device and use of the Platform; and from people you authorize to act for you (for example, a co-owner or advisor who invites you or uploads on your behalf).
Categories of third parties and recipients to whom information may be disclosed for a business purpose are listed in Section 6.
We do not collect information for the purpose of selling it or sharing it for cross-context behavioral advertising. See Section 7.
4. What we never collect — no PHI, no patient records
We collect business records only. We do not want, and we ask you not to upload, patient records, treatment information, or any other protected health information (PHI). The Platform screens for and quarantines suspected PHI. If PHI must be exchanged for diligence, it is handled outside this Policy under the NDA's data-handling protocol (limited data set / de-identified data, staged disclosure) and a BAA where required (see Section 2).
5. Sensitive personal information — limited use
The only sensitive personal information we intentionally process is your account log-in credentials and 2FA information, which we use solely to authenticate you and secure your account. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for any purpose other than those permitted under Cal. Civ. Code Section 1798.121 and comparable state law (such as providing the service, ensuring security and integrity, and preventing fraud). We therefore do not offer a separate "Limit the Use of My Sensitive Personal Information" control, because we already limit that use by default. We do not sell or share sensitive personal information.
6. How we use and disclose information
How we use it (business and commercial purposes)
- To provide, operate, maintain, and secure the Platform;
- To create and authenticate your account and enforce 2FA;
- To facilitate diligence and the secure exchange of documents with a doctor-owned group's review team, at your direction;
- To communicate with you about your account, agreements, and requests;
- To detect, investigate, and prevent security incidents, fraud, and unauthorized activity;
- To comply with legal, tax, and accounting obligations; and
- To establish, exercise, or defend legal claims, and to protect the rights, property, and safety of users, the public, and Dentist Owners.
Who we disclose it to (categories of recipients)
- Service providers / processors who host and support the Platform under written confidentiality and data-protection obligations — for example, our cloud-infrastructure provider and our transactional email provider. These providers are contractually restricted to processing personal information only on our documented instructions to provide the service, and may not sell it or use it for their own purposes. A current list of our subprocessors is available on request at info@dentistowners.com.
- The group's review team, only for the specific documents you submit for review, and only under a signed confidentiality agreement.
- Professional advisors and authorities — our attorneys, auditors, and, when required by law or valid legal process, courts, regulators, or law-enforcement authorities.
- Successors — a party to a merger, acquisition, financing, or sale of assets involving Dentist Owners, subject to this Policy or a policy at least as protective.
7. We do not sell or share your personal information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA, the OCPA, and comparable state laws. We have not sold or shared personal information, and we have not sold or shared the sensitive personal information of any consumer, in the preceding 12 months. Because we do not sell or share, there is no "Do Not Sell or Share My Personal Information" transaction to opt out of; you may still submit a request confirming this under Section 10. We do not offer financial incentives or price or service differences in exchange for the collection, sale, or retention of personal information.
8. Our role — controller, service provider, and processor
Depending on the context, Dentist Owners acts as a business / controller for information you provide to create and manage your account and use the Platform. When we process documents and diligence materials at the direction of a practice owner or a review team, we act as a service provider / processor and handle that information only to provide the Platform, under contract and our DPA, and not for our own commercial purposes. We do not retain, use, or disclose that information outside the direct business relationship or for any purpose other than the services specified, except as permitted by applicable law.
9. Your privacy rights
Subject to verification and to exceptions permitted by law, and depending on your state of residence, you may have the right to:
- Know / access the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of recipients;
- Delete personal information we have collected from you;
- Correct inaccurate personal information;
- Data portability — receive a copy of certain information in a portable, machine-readable format;
- Opt out of any sale or sharing of personal information, and of targeted advertising (note: we do not sell, share, or conduct targeted advertising — see Section 7);
- Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects (note: we do not conduct such profiling — see Section 12);
- Limit the use of sensitive personal information (note: we already limit this by default — see Section 5); and
- Non-discrimination — you will not receive discriminatory or retaliatory treatment for exercising any of these rights.
Oregon residents (OCPA). In addition to the rights above, Oregon residents may request a list of the specific third parties — not merely the categories — to which we have disclosed personal data, to the extent required by ORS 646A.574. Oregon residents also have the rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of sale, targeted advertising, and profiling as described above.
Other states. Residents of California, Virginia, Colorado, Connecticut, Texas, Utah, and other states with comprehensive consumer privacy laws (and additional states as those laws take effect) have analogous rights under their respective statutes. The specific rights available to you, and any exemptions, are determined by the law of your state of residence.
We describe these as rights available under applicable law. This Policy does not state, and you should not infer, any specific amount of statutory or other monetary damages; the availability and scope of any private remedy (including the limited private right of action for certain unencrypted-and-unredacted data breaches) is governed by the applicable statute and by counsel's advice, not by this Policy.
10. How to exercise your rights (DSAR process)
To submit a data-subject or consumer request, email info@dentistowners.com with the subject line "Privacy Request" and tell us which right you want to exercise.
- Verification. To protect your information, we will verify your identity before acting — typically by confirming control of the account email and, for sensitive requests, additional account information. We will not disclose personal information in response to an unverified request.
- Authorized agents. You may use an authorized agent to submit a request; we may require the agent to provide proof of authorization and may require you to verify your own identity directly, to the extent permitted by applicable law.
- Timing. We will confirm receipt within 10 business days and respond substantively within 45 days. If we reasonably need more time, we may extend once by an additional 45 days and will tell you why within the initial period.
- Appeals. If we decline your request and your state provides an appeal right, our response will explain how to appeal; if your appeal is denied, we will, where required, tell you how to contact your state Attorney General.
- No fee. We do not charge a fee to process or respond to a verifiable request unless it is excessive, repetitive, or manifestly unfounded, as permitted by applicable law.
11. Data retention and deletion
We keep personal information only for as long as necessary for the purposes described in this Policy, then delete or de-identify it. Retention is determined by these criteria:
- Account information — for the life of your account, then deleted or de-identified within a reasonable period after account closure, unless a longer period is required by law.
- Uploaded business documents and diligence materials — for the duration of the review relationship and any resulting agreement, then deleted or returned per the applicable agreement.
- Security, audit, and log records — retained for a limited period appropriate to security and legal-defense needs.
- Records we must keep — information required for legal, tax, accounting, securities-compliance, or dispute-resolution purposes is retained for the period required by the applicable obligation or limitations period, then deleted.
You may request deletion of your account and associated documents under Section 10, subject to records we are permitted or required to retain.
12. Automated decision-making and profiling
We do not use personal information to make decisions that produce legal or similarly significant effects about you through solely automated processing, and we do not engage in profiling for behavioral advertising. The limited inferences described in Section 3 are used only to operate, secure, and improve the Platform. If we ever introduce such processing, we will update this Policy and provide any opt-out or other rights required by applicable law before doing so.
13. De-identified and aggregate information
Where we de-identify or aggregate information so that it no longer reasonably identifies you, we will maintain and use it only in de-identified or aggregate form, will not attempt to re-identify it except as permitted by law to test our de-identification, and will contractually require recipients to do the same, consistent with Cal. Civ. Code Section 1798.140 and comparable state law.
14. How we protect information
We maintain an information-security program with administrative, technical, and physical safeguards aligned with and modeled on recognized frameworks such as SOC 2 and ISO/IEC 27001. We do not, by this statement, represent that we currently hold any specific certification or attestation. Our controls include:
- Encryption in transit using TLS 1.2 or higher;
- Encryption at rest using AES-256 envelope encryption for stored documents;
- Multi-factor authentication (MFA/2FA) required before any document surface is available;
- Role-based access control (RBAC) scoping access to the people you assign;
- Immutable, tamper-evident, hash-chained audit logs recording every document access, which you can review; and
- Ongoing monitoring, least-privilege administration, and periodic review of our safeguards.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
15. Data breach notification
If we confirm a breach of security affecting your unencrypted and unredacted personal information, we will notify affected users and any applicable regulators without undue delay and consistent with the timelines required by applicable law. As a matter of policy, we target notification without undue delay and, where feasible, within 72 hours after we confirm a reportable breach — a self-imposed commitment, not a concession that any single statutory deadline applies. Our notice will describe, to the extent known, what happened, the categories of information involved, and the steps we are taking and you can take.
16. Cookies, analytics, and tracking
We use strictly necessary cookies to keep you signed in and to secure the Platform, and limited, privacy-respecting analytics to understand and improve usage. We do not use third-party advertising cookies and we do not track you across other websites for advertising.
"Do Not Track" and Global Privacy Control (GPC). Because we do not sell or share personal information or engage in cross-context behavioral advertising, browser "Do Not Track" signals do not change our practices. Where required by law, we honor a recognized opt-out preference signal such as GPC as a valid opt-out of sale/sharing — consistent with the fact that we do not sell or share.
17. International data transfers
The Platform is operated from, and personal information is processed and stored in, the United States. If you access the Platform from outside the United States, you understand that your information will be transferred to and processed in the United States. Where personal information subject to EU/UK data-protection law is transferred, such transfers are made under an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses (SCCs) and the UK Addendum, consistent with our Data Processing Addendum (DPA).
18. Children
The Platform is intended only for professionals and their advisors and is not directed to children. We do not knowingly collect personal information from anyone under 18, and specifically not from children under 13 (or under 16 where applicable). If we learn that we have collected such information, we will delete it.
19. Third-party links
The Platform and dentistowners.com may link to third-party businesses and websites (for example, other companies in the Dentist Owners network). Their privacy practices are governed by their own policies, and we are not responsible for them.
20. Changes to this Policy
We may update this Policy from time to time. Material changes take effect when we post the updated Policy with a new effective date, and, where required by law, we will provide additional notice. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy, to the extent permitted by applicable law.
21. Severability and interpretation
If any provision of this Policy is held to be invalid or unenforceable, that provision will be limited or severed to the minimum extent necessary, and the remaining provisions will remain in full force and effect, in each case to the extent enforceable under applicable law. Nothing in this Policy limits any right you have that cannot be limited or waived under applicable law.
22. Contact us
Privacy questions or requests: info@dentistowners.com, Attention: Privacy — Dentist Owners LLC.