Profit Smiles Inc — Legal Center
The agreements that govern your use of Profit Smiles
What these documents are, in one line each.
- Master Subscription Agreement — the contract between your practice and us.
- Privacy Policy — what information we handle, and what we do with it.
- Business Associate Agreement — how we protect patient health information under HIPAA. It applies automatically; you do not need to sign or request it.
- Data Deletion & Subprocessors — how to get data deleted, and every third party we use.
1. Master Subscription Agreement
For dental practices subscribing to Profit Smiles.
This Master Subscription Agreement (the “Agreement”) is a binding contract between Profit Smiles Inc, a Texas corporation (“Profit Smiles,” “we,” “us,” or “our”), and the dental practice or other business entity that creates an account for the Service (“Practice,” “you,” or “your”).
By clicking to accept this Agreement, creating an account, or accessing or using the Service, you agree to be bound by it. If you are entering into this Agreement on behalf of a practice or other legal entity, you represent that you have authority to bind that entity, and “you” refers to that entity. If you do not agree, do not create an account and do not use the Service.
This Agreement incorporates by reference our Privacy Policy and, where we create, receive, maintain, or transmit Protected Health Information on your behalf, our Business Associate Agreement. Together these form the entire agreement between us regarding the Service.
1. Definitions
“Service” means the Profit Smiles software-as-a-service platform, including the web application, the tools listed in Section 2, the patient-facing membership portal, the Getting Started training materials, and any associated websites, applications, and services we make available to you.
“Tools” means the individually subscribable modules described in Section 2.
“Practice Data” means all data, content, and information you or your Users submit to, or generate through, the Service — including patient records, treatment plans, fee schedules, membership plan configurations, inventory records, notes, and business settings.
“Patient” means an individual patient of your Practice whose information you enter into the Service, or who interacts with the Service through the membership portal, a survey, a referral link, or a patient-facing communication.
“PHI” means Protected Health Information as defined at 45 C.F.R. § 160.103, limited to information we create, receive, maintain, or transmit on your behalf.
“User” means an individual you authorize to access the Service under your account, including you, your employees, and your contractors.
2. The Service
2.1 What the Service is
Profit Smiles provides a software platform that helps dental practices analyze and improve practice profitability. The Service consists of seven separately subscribable Tools:
| Tool | Function |
|---|---|
| PPO Inspector | Analyzes insurance plans, calculates write-offs, generates profitability scores, and runs out-of-network what-if scenarios |
| Club Creator | Configures and administers an in-house dental membership plan, including a patient-facing membership portal |
| Patient Pipeline | Surveys patients, tracks NPS, and automates referral and review requests |
| Content Caddy | Connects to your Facebook and Instagram accounts and publishes educational dental content on your behalf |
| Case Closer | Runs an automated follow-up sequence for unscheduled treatment plans by email, text, and voice |
| Payment Flexer | Configures in-house installment payment plans charged through your own payment processor account |
| Stock Sentry | Tracks dental supply inventory, reorder points, and expiry |
An Invisalign tracking add-on is included at no additional charge with a subscription to any one or more Tools.
2.2 What the Service is not
We are a software provider. We do not practice dentistry, do not give clinical advice, do not review or approve treatment plans, and do not participate in any clinical decision. Every clinical, financial, and business decision you make using the Service remains yours, and you remain solely responsible for it.
We do not provide legal, tax, accounting, insurance-contracting, or regulatory advice. PPO Inspector’s analyses, profitability scores, and what-if scenarios are informational tools built on data you supply. They are not a recommendation to terminate, retain, or renegotiate any insurance contract, and we make no representation that any projected outcome will be achieved. Decisions about your network participation, your fee schedules, your membership plan design, and your patient pricing are yours alone, and you should take professional advice before making them.
We do not set your prices. You establish your own membership fees, treatment fees, member discounts, payment plan terms, referral rewards, and refund policies. The Service is the instrument you use to administer them.
2.3 Single location
The Service is designed and licensed for single-location practices. If you operate more than one location, contact us before subscribing; we do not currently support multi-location configurations and do not warrant that the Service will function correctly if used that way.
2.4 Changes to the Service
We improve the Service continuously and may add, modify, or remove features. Where a change materially reduces functionality you subscribe to, we will give you reasonable advance notice where feasible, and Section 15.3 (Feature Removal Remedy) applies.
3. Eligibility and Accounts
3.1 Eligibility. You must be at least 18 years old and authorized to act on behalf of a dental practice or business entity. The Service is offered only in the United States and is not directed to individuals or entities outside it.
3.2 Account information. You agree to provide true, accurate, current, and complete information when you register, and to keep it that way. If you provide information that is untrue, inaccurate, or incomplete — or if we have reasonable grounds to believe you have violated or intend to violate this Agreement — we may suspend or terminate your account under Section 19.
3.3 Credentials and account security. You are solely responsible for maintaining the confidentiality of your credentials, for controlling which of your Users have access, and for all activity that occurs under your account. Do not share credentials between individuals; create a separate User for each person who needs access. You must notify us immediately at support@profitsmiles.com if you become aware of any unauthorized use of your account.
Because your account can contain PHI, credential-sharing is not merely a security risk — it undermines the access controls that the Business Associate Agreement requires both of us to maintain.
3.4 Your Users. You are responsible for your Users’ compliance with this Agreement, and for promptly removing access for any User who leaves your Practice or no longer requires it. Acts and omissions of your Users are treated as your own.
4. Free Trial and Founding Member Pricing
4.1 The 100-day free trial. New accounts receive 100 days of access at no charge, with no payment method required. The 100-day period begins on the date you create your account. During the trial you have full access to the Tools you have selected.
4.2 What happens at the end of the trial. At the end of the 100 days, your access to paid Tools ends unless you subscribe. We will not charge you automatically at the end of the trial, because we do not hold a payment method during it. Your Practice Data remains available to you in read-only form under Section 18.3.
4.3 Founding member rate and price lock. Where we offer a promotional “founding member” rate, the rate in effect on the day you create your account is locked to that account and will apply to your subscription if and when you subscribe, for as long as your subscription remains continuously active. The founding member rate is a limited-time offer and will be withdrawn; once withdrawn, new accounts pay our standard rate.
The price lock is tied to continuous subscription. If you cancel and later resubscribe, the rate then in effect applies, not your original locked rate.
We may change our standard rates at any time on at least 30 days’ notice, which will not affect a locked founding member rate while your subscription remains continuously active.
5. Subscriptions, Fees, and Payment
5.1 Per-Tool subscriptions. Each Tool is subscribed to and priced separately. You may subscribe to any combination of Tools, add Tools at any time, and remove Tools at any time. Bundle pricing applies where you subscribe to all Tools.
5.2 Billing. Subscriptions are billed monthly in advance and renew automatically each month until cancelled. There is no minimum term and no long-term contract. Fees are stated in U.S. dollars and are exclusive of any applicable taxes, which are your responsibility except for taxes on our net income.
5.3 Payment method. You authorize us to charge your designated payment method for all fees when due. Subscription payments are processed by Stripe, Inc.; we do not store your full card details. If a charge fails, we may retry it, and we may suspend access to paid Tools until payment succeeds. You remain responsible for fees accrued before suspension.
5.4 Cancellation. You may cancel any Tool subscription, or your entire subscription, at any time from within the Service. Cancellation takes effect at the end of the then-current billing month. You retain access to the cancelled Tool until that date.
5.5 Refunds. Except as expressly provided in Section 15.3 (Feature Removal Remedy) or as required by law, fees are non-refundable and we do not provide refunds or credits for partial months, unused periods, or Tools you did not use. This reflects the 100-day free trial: you have the opportunity to evaluate the Service fully before paying anything.
5.6 Disputed charges. If you believe you have been charged in error, contact us at support@profitsmiles.com within 60 days of the charge and we will investigate in good faith. We ask that you contact us before initiating a chargeback, so we have the opportunity to resolve it directly.
6. Practice Data — Ownership, Licence, and Your Responsibilities
6.1 You own your data. As between you and Profit Smiles, you own all Practice Data. We claim no ownership of it. Nothing in this Agreement transfers ownership of Practice Data to us.
6.2 The licence you grant us. You grant us a limited, non-exclusive, worldwide, royalty-free licence to host, store, process, transmit, display, and otherwise use Practice Data solely to: (a) provide, maintain, secure, and support the Service for you; (b) perform the functions you direct the Service to perform, including sending communications to your Patients on your behalf; and (c) comply with law. This licence terminates when the Practice Data is deleted, except for copies retained in routine backups until they expire on their normal cycle.
Where Practice Data constitutes PHI, this licence is further limited by the Business Associate Agreement, which controls in the event of any conflict.
6.3 De-identified and aggregated data. We may create de-identified and aggregated data from Practice Data — for example, benchmark statistics across practices — and use it to operate, analyze, and improve the Service and to produce industry benchmarks. De-identification of PHI will be performed in accordance with 45 C.F.R. § 164.514(b). De-identified and aggregated data will never identify you, your Practice, or any Patient, and we will not disclose it in a form that could reasonably be used to re-identify any individual or practice.
6.4 Your responsibilities for the data you enter. You represent and warrant that:
- you have the right to provide all Practice Data to us and to authorize the processing described in this Agreement;
- you have obtained every consent, authorization, and permission required by law before entering Patient information into the Service — including any consent required to contact a Patient by email, text message, or automated telephone call (see Section 9);
- your own notice of privacy practices permits you to disclose PHI to us for the purposes described in the Business Associate Agreement; and
- the Practice Data does not infringe any third party’s rights and does not violate any law.
6.5 Accuracy. The Service computes outputs — write-off analyses, profitability scores, savings figures, ROI reporting, inventory levels, payment schedules — from the data you enter. If your fee schedules, reimbursement figures, baseline numbers, or patient records are inaccurate or out of date, the outputs will be too. You are responsible for the accuracy of Practice Data, and for verifying any output before you rely on it for a business or clinical decision.
6.6 Third-party data restrictions. Some data you enter — insurance fee schedules in particular — may be subject to confidentiality obligations you owe to a third party under your own network contracts. You are responsible for confirming that you may lawfully enter such data into the Service. We do not review your contracts and cannot assess those obligations for you.
7. Protected Health Information and HIPAA
7.1 The roles. For PHI you place in the Service, you are the Covered Entity and Profit Smiles is your Business Associate, as those terms are defined under HIPAA.
7.2 The BAA governs. Our Business Associate Agreement governs our creation, receipt, maintenance, transmission, use, and disclosure of PHI. It is incorporated into this Agreement and is effective automatically upon your acceptance of this Agreement — you do not need to request or separately sign it. Where the BAA conflicts with this Agreement in relation to PHI, the BAA controls.
7.3 Minimum necessary. Enter only the Patient information the Service needs to perform the functions you are using. The Service is not a dental record system and is not designed to hold complete clinical records, radiographs, or chart notes. Do not enter clinical detail the Service does not ask for.
7.4 We are not a Covered Entity. Profit Smiles is a Business Associate and does not issue a Notice of Privacy Practices. Your Patients’ privacy notice is yours to maintain and provide.
8. Patient Payments — Stripe Connect
8.1 Two separate payment flows. There are two distinct flows of money in connection with the Service, and they are not the same:
(a) Your subscription fees. You pay Profit Smiles. We are the merchant of record. Section 5 governs.
(b) Your Patients’ payments to you. Membership fees, membership renewals, payment plan installments, and any other Patient payment are charged through your own Stripe connected account, established during setup. The funds are yours and settle to your Stripe account. Profit Smiles is not the merchant of record, does not take custody of Patient funds, and is not a party to the transaction between you and your Patient.
8.2 What this means in practice. Because you are the merchant for Patient payments:
- You are responsible for refunds, chargebacks, disputes, and reversals, including any fees Stripe charges in connection with them.
- You set your own refund and cancellation policy for membership plans and payment plans, and you are responsible for honoring it and for disclosing it to your Patients.
- You are responsible for compliance with card network rules, applicable consumer protection law, and any automatic renewal statutes that apply to the recurring charges you configure — including the disclosure, consent, and cancellation requirements that attach to automatically renewing charges.
- You are bound by Stripe’s Connected Account Agreement, directly with Stripe. That agreement is between you and Stripe, and we are not a party to it.
- If Stripe suspends, restricts, or terminates your connected account, the Tools that depend on it will stop functioning, and we cannot override Stripe’s decision.
8.3 Our role. We instruct Stripe to create charges on your connected account according to the configuration you set and the actions you or your staff take in the Service. We are responsible for instructing correctly; we are not responsible for the underlying commercial transaction, for the goods or services you provide, or for the outcome of any dispute between you and a Patient.
8.4 Automated charges. Certain Tools charge Patients automatically on a schedule you configure — membership renewals and payment plan installments in particular. You are responsible for the configuration, including the amounts, the timing, and confirming that you hold valid, documented Patient authorization for each recurring charge. Review your scheduled charges regularly. If you become aware of an incorrect charge, notify us promptly so we can help you identify its cause, and issue any refund from your Stripe account.
9. Patient Communications
9.1 We send on your behalf. The Service sends email and text messages to your Patients in your name and at your direction — surveys, referral requests, review requests, treatment plan follow-ups, membership notices, payment receipts, and failed-charge notices. You are the sender for legal purposes. We are the technical means by which the message is delivered.
9.2 Consent is your responsibility. You represent and warrant that you have obtained all consents required by law from each Patient before entering their contact details into the Service, including any prior express written consent required under the Telephone Consumer Protection Act (TCPA) for automated calls or text messages to a mobile number, and any consent required under applicable state law. You are responsible for maintaining records of those consents.
We provide the sending infrastructure and the opt-out mechanisms described below. We do not obtain consent for you and cannot verify that you have obtained it.
9.3 Opt-outs. The Service honors opt-outs automatically:
- Text messages include “Reply STOP to opt out.” A Patient who replies STOP — or CANCEL, END, QUIT, UNSUBSCRIBE, STOPALL, REVOKE, or OPTOUT — is unsubscribed from further text messages, and the Service will not send to them again. Replying START, YES, or UNSTOP resubscribes them.
- Marketing and non-transactional emails include an unsubscribe link, and unsubscribed Patients are suppressed from further sends.
- Transactional messages — payment receipts and failed-charge notices in particular — do not carry an unsubscribe link, because they relate to a transaction the Patient has entered into.
You must not attempt to circumvent an opt-out, including by re-entering a Patient who has opted out, or by contacting them through another channel about the same subject matter after they have opted out.
9.4 Message frequency and carrier charges. Message frequency depends on the Tools you use and the configuration you set. Patients may incur charges from their carrier. Neither you nor we control carrier behavior, delivery timing, or deliverability.
9.5 Compliance with A2P messaging requirements. Text messaging in the United States is subject to carrier registration requirements (A2P 10DLC) and to carrier filtering. We maintain the platform-level registration required for the Service to send. You are responsible for the content and lawfulness of the messages you configure, and you must not use the Service to send messages that violate carrier rules or applicable law.
10. Social Media Connections and Published Content
10.1 Authorization. If you use Content Caddy, you authorize us to use the Meta APIs to: (a) authenticate your Facebook and Instagram accounts; (b) publish content to those accounts as you direct or as scheduled; and (c) retrieve engagement metrics for the content published. We use these APIs for no other purpose. We do not scrape, resell, or otherwise use your social media data.
10.2 Disconnection. You may disconnect at any time using the “Disconnect from Facebook” control in the Service. On disconnection, all Meta API connection data — access tokens, account and page identifiers, and granted permissions — is immediately and permanently deleted from our systems. Content already published to your accounts remains there; you control it through the platforms themselves.
10.3 Platform terms. Your use of Facebook and Instagram is governed by Meta’s own terms and policies, directly between you and Meta. We are not responsible for changes Meta makes to its APIs, policies, or platform behavior, or for any action Meta takes in relation to your accounts. If Meta restricts or revokes API access, the affected functionality may become unavailable.
10.4 Content published on your behalf. Content Caddy publishes educational content from a library we curate and, where applicable, renders it with your practice name, location, and branding. You are responsible for the content published to your accounts. You may review, approve, and unapprove library content before it is scheduled, and we recommend you do so.
The library content is general dental education. It is not clinical advice, is not tailored to any individual patient, and should not be presented as a substitute for professional consultation. You are responsible for confirming that content you allow to publish is appropriate for your practice, your jurisdiction, and any advertising rules that apply to dentists in your state.
10.5 AI-generated and AI-assisted content. Some content available through the Service is generated or assisted by artificial intelligence, including educational social media posts, images composed for publication, and training and marketing videos.
Videos we produce that feature Dr. Prachi Deore use an AI-generated visual likeness and AI-generated narration, produced with her authorization. The dentist, the practice, and the results presented are real. Where these videos appear on surfaces we control, we disclose this. If you republish or embed our video content, you must not represent it as unaltered recorded footage or as her recorded voice.
You are responsible for any disclosure obligations that attach to AI-generated content you publish through the Service on your own accounts, including platform-level AI labeling requirements imposed by Meta or any other platform, and any applicable advertising-disclosure rules.
11. Membership Plans
11.1 The plan is yours. Club Creator is administration software. The membership plan is offered by you to your Patients. Profit Smiles is not a party to it, does not administer it, and has no obligation to any member.
You establish the plan’s fees, the services it includes, its discounts, its term, its renewal behavior, and its refund policy.
You are responsible for ensuring your plan complies with the law of your state. A number of states regulate dental membership plans, discount medical plan organizations, or similar arrangements — with requirements that may include registration, specific mandatory disclosure language, minimum cancellation and refund rights, and restrictions on how a plan may be described. These requirements vary by state, they change, and we do not monitor them for you. Obtain legal advice before launching a membership plan.
11.3 Plan descriptions. You are responsible for how you describe your plan to Patients, in the Service and elsewhere. Do not describe it as insurance, as coverage, or as a benefit plan.
12. Referral and Reward Programs
Patient Pipeline allows you to configure referral rewards for existing Patients and promotions for new Patients.
Paying or giving anything of value in exchange for patient referrals is restricted or prohibited in many states, and may implicate federal law where federal healthcare program beneficiaries are involved. The rules differ substantially between states, and between cash rewards, account credits, discounts, and gifts.
You are solely responsible for determining whether the referral rewards and promotions you configure are lawful in your state, and for the amounts and forms you choose. The Service provides the mechanism; it does not evaluate legality, and the presence of a configurable field is not our advice that any particular reward is permissible. Obtain legal advice before configuring a referral reward program.
13. Acceptable Use
You will not, and will not permit any User or third party to:
- use the Service for any unlawful purpose, or in violation of any applicable regulation, professional rule, or advertising standard;
- access or use the Service to build a competing product, or for competitive benchmarking;
- reverse engineer, decompile, disassemble, or attempt to derive the source code or underlying structure of the Service, except to the extent this restriction is unenforceable under applicable law;
- resell, sublicense, rent, lease, or provide the Service to any third party, or use it to provide services to any practice other than your own;
- use any robot, spider, scraper, or automated means to access the Service, or extract data other than through functionality we provide;
- circumvent or attempt to circumvent any access control, rate limit, usage limit, subscription gate, or security measure;
- upload or transmit malware, or take any action that damages, disables, overburdens, or impairs the Service or interferes with any other customer’s use of it;
- enter data about any individual without the rights and consents required by Section 6.4;
- use the Service to send unsolicited commercial messages, or messages that violate the TCPA, CAN-SPAM, or carrier rules;
- misrepresent your identity or your affiliation with any person or entity; or
- remove, obscure, or alter any proprietary notice in the Service.
We may investigate any suspected violation and take the action described in Section 19.
14. Third-Party Services and Subprocessors
14.1 Subprocessors. We use third-party service providers to deliver the Service. Our current subprocessors are listed in the Subprocessor List below. Each is bound by written agreement to confidentiality obligations and, where they may handle PHI, to HIPAA-compliant terms consistent with our Business Associate Agreement.
We may add or replace subprocessors as the Service evolves. We will update the published list when we do.
14.2 Third-party services you connect. Where you connect a third-party service — your Stripe account, your Meta accounts — your relationship with that provider is governed by its terms, directly between you and it. We are not responsible for those services, their availability, their pricing, or any action they take.
15. Availability, Support, and the Feature Removal Remedy
15.1 Availability. We work to keep the Service available and reliable, but we do not commit to any specific uptime percentage and the Service is not offered with a service level agreement. Availability may be affected by maintenance, third-party providers, internet conditions, and events outside our control. Where planned maintenance will cause material downtime, we will give notice where feasible.
The Service is not designed for emergency use. Do not rely on it for any time-critical clinical purpose.
15.2 Support. Support is provided by email at support@profitsmiles.com, and through the feedback and meeting-scheduling functions inside the Service, during our normal business hours.
15.3 Feature Removal Remedy. If we materially remove core functionality from a Tool you subscribe to, and do not restore it or provide substantially equivalent functionality within 60 days, you may request a pro-rata refund of the fees you paid for that affected Tool for the remaining portion of the period for which you have paid.
To claim, email support@profitsmiles.com within 90 days of the removal, identifying the functionality removed. This remedy is limited to fees for the affected Tool and does not extend to other Tools or to your subscription as a whole. This is your sole and exclusive remedy for removed functionality.
16. Confidentiality
Each party may receive non-public information of the other. Each party will protect the other’s confidential information with at least reasonable care, use it only to perform under this Agreement, and disclose it only to personnel and subprocessors who need it and are bound by comparable obligations.
These obligations do not apply to information that is or becomes public through no fault of the recipient, was rightfully known before disclosure, is rightfully received from a third party without restriction, or is independently developed. A party may disclose confidential information where legally compelled, after giving notice where lawfully permitted.
PHI is governed by the Business Associate Agreement, not by this Section.
17. Intellectual Property
17.1 Ours. The Service — including its software, design, text, graphics, video and audio content, training materials, content libraries, trademarks, and the compilation of all of it — is owned by Profit Smiles or its licensors and is protected by intellectual property law. We grant you a limited, non-exclusive, non-transferable, revocable licence to access and use the Service for your Practice’s internal business purposes during your subscription. All rights not expressly granted are reserved.
You may not copy, distribute, publicly display, or create derivative works from the Service or its content except as the Service’s functionality expressly permits — for example, publishing library content to your own connected social accounts, or printing training materials for use inside your Practice.
17.2 Feedback. If you give us suggestions, feature requests, or other feedback, you grant us a perpetual, irrevocable, worldwide, royalty-free licence to use it without restriction or obligation to you. We are not obliged to act on feedback, and feedback is given without any expectation of confidentiality or compensation.
17.3 Publicity. We will not use your Practice’s name, logo, or any patient outcome in marketing without your prior written consent. Where you give consent, you may withdraw it prospectively at any time by notifying us; we will stop using it in new materials within a reasonable period, though we are not obliged to recall materials already distributed.
18. Term, Cancellation, and Your Data Afterwards
18.1 Term. This Agreement begins when you first accept it or first use the Service, and continues until your account is terminated under this Section or Section 19.
18.2 Cancellation by you. You may cancel at any time under Section 5.4. You may also close your account entirely by contacting us.
18.3 Read-only access after cancellation. After cancellation, your Practice Data remains available to you in read-only form. You can view your historical records; you cannot create new records or use the paid functionality of cancelled Tools. We provide this because your practice records should not be held hostage to a subscription.
We retain Practice Data in this read-only state indefinitely unless and until you request deletion. Retention is a service to you, not an obligation we owe ourselves — you may request deletion at any time under Section 18.4.
18.4 Deletion. You may request permanent deletion of your Practice Data, including PHI and billing records, by emailing support@profitsmiles.com from an authorized account. We will delete it — including from backups as those backups expire on their normal cycle — and confirm when complete, except where retention is required by law. Deletion is permanent and irreversible. The procedure and timing are described in Data Deletion Instructions below.
Ask us for an export before you request deletion. We will provide your Practice Data in a usable format on request, at no charge. You are responsible for retaining anything your state’s dental record-retention rules require you to keep, and we cannot restore data once it is deleted.
Where the data includes PHI, deletion on your request satisfies the return-or-destroy obligation in the Business Associate Agreement.
18.5 Survival. Sections 6.1, 6.3, 16, 17, 20, 21, 22, 23, and 24, and any obligation to pay accrued fees, survive termination.
19. Suspension and Termination by Us
19.1 Suspension. We may suspend your access, in whole or in part, where: (a) fees are overdue; (b) we reasonably believe your use is causing or is likely to cause harm to the Service, to us, or to another customer; (c) we reasonably suspect fraudulent, unlawful, or abusive activity; or (d) suspension is required by law.
Where practicable we will notify you first and give you an opportunity to cure. Where the risk is immediate, we may suspend first and notify promptly afterwards.
19.2 Termination. We may terminate this Agreement for material breach if you do not cure within 30 days of written notice. We may terminate immediately, without a cure period, for conduct that is unlawful, fraudulent, or that presents an immediate risk of harm to the Service, to us, to another customer, or to any Patient.
We may also discontinue the Service entirely on 90 days’ notice, in which case we will refund any prepaid fees for the period after discontinuation and give you a reasonable opportunity to obtain an export of your Practice Data.
19.3 Effect. On termination, your right to use the Service ends. Section 18.3 (read-only access) applies unless termination was for the conduct described in the second sentence of Section 19.2, in which case we may withhold read-only access — though we will still, on request, provide you an export of your Practice Data, because your patient records are not ours to withhold.
20. Disclaimers
THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE,” WITHOUT WARRANTY OF ANY KIND. TO THE FULLEST EXTENT PERMITTED BY LAW, PROFIT SMILES AND ITS SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESS, IMPLIED, AND STATUTORY, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.
WE DO NOT WARRANT THAT: the Service will be uninterrupted, timely, secure, or error-free; that defects will be corrected; that the Service will meet your requirements; or that any result, saving, revenue increase, return on investment, or other outcome will be achieved.
ANY FIGURES WE PUBLISH — INCLUDING EXPECTED IMPACT, RETURN ON INVESTMENT, AND BENCHMARK RESULTS — ARE ILLUSTRATIONS BASED ON PARTICULAR PRACTICES AND DATA. THEY ARE NOT A PREDICTION, PROMISE, OR GUARANTEE OF YOUR RESULTS. Your results depend on your market, your patients, your fees, your team, and your execution.
Spokesperson; no liability of individuals or third parties. Dr. Prachi Deore is a practicing dentist whose practice's results appear in our marketing and educational materials with her consent. She is not an officer, director, employee, or agent of Profit Smiles Inc, holds no management role in it, and has no authority to make any commitment on its behalf. Her dental practice, Coppell Smiles, is a separate business with no role in providing the Service. Neither Dr. Deore, nor Coppell Smiles, nor any other spokesperson, presenter, or individual appearing in our materials is a party to this Agreement or has any obligation or liability to you under it. This Agreement is between you and Profit Smiles Inc alone, and any claim arising out of or relating to it or the Service lies solely against Profit Smiles Inc.
Some jurisdictions do not allow the exclusion of certain warranties, so parts of this Section may not apply to you.
21. Limitation of Liability
21.1 Exclusion of indirect damages. TO THE FULLEST EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, BUSINESS, GOODWILL, ANTICIPATED SAVINGS, OR DATA, however caused and under any theory of liability, even if advised of the possibility.
21.2 General cap. EXCEPT AS PROVIDED IN SECTIONS 21.3 AND 21.4, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE GREATER OF (a) THE FEES YOU PAID US IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (b) ONE THOUSAND U.S. DOLLARS ($1,000).
21.3 PHI and data breach — enhanced cap. FOR CLAIMS ARISING FROM A BREACH OF UNSECURED PHI, OR FROM UNAUTHORIZED ACCESS TO OR DISCLOSURE OF PRACTICE DATA, IN EACH CASE CAUSED BY PROFIT SMILES’ FAILURE TO MEET ITS OBLIGATIONS UNDER THIS AGREEMENT OR THE BUSINESS ASSOCIATE AGREEMENT, PROFIT SMILES’ TOTAL AGGREGATE LIABILITY WILL NOT EXCEED THE GREATER OF (a) THREE (3) TIMES THE AMOUNT DETERMINED UNDER SECTION 21.2, OR (b) TWENTY-FIVE THOUSAND U.S. DOLLARS ($25,000). This enhanced cap replaces, and does not add to, the general cap for such claims.
21.4 Exclusions from the caps. THE CAPS IN SECTIONS 21.2 AND 21.3 DO NOT APPLY TO: (a) either party’s indemnification obligations under Section 22; (b) breach of confidentiality obligations under Section 16; (c) gross negligence or willful misconduct; (d) your obligation to pay fees; or (e) any liability that cannot be limited under applicable law.
21.5 Basis of the bargain. The limitations in this Section are an essential part of the bargain between us and are reflected in the pricing of the Service. They apply even if a limited remedy fails of its essential purpose.
22. Indemnification
22.1 By you. You will defend, indemnify, and hold harmless Profit Smiles, its officers, directors, employees, and agents from any third-party claim, and any resulting loss, damage, liability, settlement, or reasonable legal fee, arising out of or relating to: (a) your Practice Data, including any claim that you lacked the rights or consents required by Section 6.4; (b) your provision of dental or other professional services, or any clinical decision you make; (c) your membership plan, including any claim that it constitutes unlawful insurance or violates a state plan statute; (d) your referral or reward program; (e) communications sent to your Patients, including any TCPA, CAN-SPAM, or state consumer-protection claim; (f) any Patient payment, refund, or chargeback dispute; or (g) your breach of this Agreement or violation of law.
22.2 By us. We will defend, indemnify, and hold harmless you and your officers, directors, and employees from any third-party claim that the Service, as provided by us and used in accordance with this Agreement, infringes that third party’s U.S. intellectual property rights, and any resulting loss, damage, liability, settlement, or reasonable legal fee.
This obligation does not apply to any claim arising from Practice Data, from your combination of the Service with anything we did not supply, or from your use of the Service in breach of this Agreement. If the Service becomes, or we believe it may become, the subject of such a claim, we may at our option procure the right to continue using it, modify it so it is non-infringing, or terminate the affected subscription and refund prepaid fees for the unused period.
22.3 Procedure. The indemnified party must promptly notify the indemnifying party of the claim, give it sole control of the defense and settlement (except that it may not settle in a way that admits liability or imposes an obligation on the indemnified party without consent), and provide reasonable cooperation at the indemnifying party’s expense. Failure to notify promptly relieves the indemnifying party only to the extent it is prejudiced.
23. Governing Law and Dispute Resolution
23.1 Governing law. This Agreement is governed by the laws of the State of Texas, excluding its conflict of laws rules and excluding the United Nations Convention on Contracts for the International Sale of Goods.
23.2 Informal resolution first. Before initiating arbitration, the parties will attempt in good faith to resolve the dispute informally for 30 days after written notice describing the dispute and the relief sought, sent to support@profitsmiles.com (for a claim against us) or to your account’s registered contact (for a claim against you).
23.3 Mandatory arbitration. Any dispute, controversy, or claim arising out of or relating to this Agreement, or to your access to or use of the Service — including the existence, breach, termination, enforcement, interpretation, or validity of this Agreement, and including the arbitrability of any claim — will be resolved by binding arbitration, and not by a judge or jury in a court of law.
The arbitration will be administered by the American Arbitration Association (“AAA”) under its Commercial Arbitration Rules. If the AAA is unavailable and the parties cannot agree on a replacement, a court of competent jurisdiction will appoint the administrator. The Federal Arbitration Act, 9 U.S.C. § 1 et seq., governs the interpretation and enforcement of this Section. The arbitration will be seated in Dallas County, Texas, before a single arbitrator, and the award will be final and binding, subject only to the appeal rights provided by the Federal Arbitration Act.
23.4 Exceptions. Either party may: (a) bring an individual claim in small claims court in Dallas County, Texas, if it qualifies; and (b) seek injunctive or other equitable relief in a court of competent jurisdiction to prevent actual or threatened infringement, misappropriation, or violation of its copyrights, trademarks, trade secrets, patents, other intellectual property rights, or confidential information.
23.5 Jury and class waiver. THE PARTIES KNOWINGLY AND VOLUNTARILY WAIVE ANY RIGHT TO: (a) A TRIAL BY JUDGE OR JURY; (b) PARTICIPATE IN A CLASS ACTION, COLLECTIVE ACTION, OR OTHER REPRESENTATIVE ACTION, WHETHER IN COURT OR IN ARBITRATION, AS A CLASS REPRESENTATIVE, CLASS MEMBER, PRIVATE ATTORNEY GENERAL, OR OTHERWISE; AND (c) JOIN OR CONSOLIDATE CLAIMS WITH THOSE OF ANY OTHER PERSON.
If the class and representative action waiver in clause (b) is found unenforceable, then only that clause is severed and the remainder of Section 23.3 is null and void as to the affected claim — meaning that claim proceeds in court — provided that any determination regarding the waiver is subject to appeal. The remainder of this Agreement is unaffected.
23.6 Court venue where arbitration does not apply. Where a claim is not subject to arbitration, the parties consent to the exclusive jurisdiction and venue of the state and federal courts located in Dallas County, Texas, and waive any objection to that venue.
23.7 Survival. This Section survives termination of this Agreement and any assignment, cancellation, or bankruptcy of either party.
24. General
24.1 Entire agreement. This Agreement, together with the Privacy Policy and the Business Associate Agreement, is the entire agreement between the parties regarding the Service and supersedes all prior or contemporaneous communications, proposals, and agreements on the subject. Any purchase order, vendor form, or other document you issue is of no effect, and any additional or conflicting terms in it are rejected.
24.2 Changes to this Agreement. We may update this Agreement. For material changes we will give at least 30 days’ notice — by email to your registered address, by notice inside the Service, or both — and the change takes effect at the end of that period. Your continued use of the Service after a change takes effect constitutes acceptance. If you do not accept a material change, your remedy is to cancel before it takes effect. Non-material changes are effective on posting. The “Last Updated” date at the top of this page always reflects the current version.
24.3 Assignment. You may not assign this Agreement without our prior written consent, except to a successor to all or substantially all of your practice’s assets or equity, on written notice to us. We may assign this Agreement without your consent to an affiliate, or to an acquirer of Profit Smiles or of substantially all of its assets, or to a successor by merger. Any attempted assignment in breach of this Section is void.
24.4 Severability. If any provision of this Agreement is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or if that is not possible, severed — and the remainder of the Agreement continues in full force. Section 23.5 governs severability of the class waiver and controls over this Section as to that clause.
24.5 Waiver. No failure or delay in exercising a right waives it, and no single or partial exercise precludes any further exercise. A waiver is effective only if in writing and signed by the waiving party.
24.6 Notices. We may give notice by email to your registered address, by posting in the Service, or by mail. You give notice to us at support@profitsmiles.com, and for legal notices also by mail to our mailing address listed in Section 25. Notice by email is deemed given when sent, absent a bounce.
24.7 Electronic communications and signatures. You consent to receive communications from us electronically, and agree that electronic communications, agreements, and records satisfy any legal requirement that they be in writing. You agree that clicking to accept, or using the Service, constitutes your signature for purposes of the E-SIGN Act and comparable state law.
24.8 Force majeure. Neither party is liable for a failure or delay caused by an event beyond its reasonable control — including natural disaster, epidemic, war, terrorism, civil unrest, labor action, government action, internet or telecommunications failure, power failure, or the failure of a third-party provider. This does not excuse an obligation to pay.
24.9 Independent contractors. The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, agency, franchise, or employment relationship.
24.10 No third-party beneficiaries. This Agreement is for the benefit of the parties only. No Patient, User, or other third party acquires any right under it.
24.11 Export and sanctions. You represent that you are not located in, and are not a national of, any country subject to U.S. embargo, and that you are not on any U.S. government restricted-party list.
24.12 Interpretation. Section headings are for convenience only. “Including” means “including without limitation.” This Agreement is drawn up in English, and the English version governs.
25. Contact
Profit Smiles Inc
7750 N MacArthur Blvd Ste 120-153, Irving, TX 75063-7501
Email: support@profitsmiles.com
Web: profitsmiles.com
2. Privacy Policy
For everyone — practices, patients, website visitors, prospects, and affiliates.
Profit Smiles Inc, a Texas corporation, provides software to dental practices. This Privacy Policy explains what information we collect, why, who we share it with, and what choices you have.
It covers profitsmiles.com, our marketing pages and landing pages, the Profit Smiles application used by dental practices, the patient membership portal, our short links, and the emails and text messages we send.
1. The most important thing: our two different roles
We handle information in two fundamentally different capacities, and your rights depend on which one applies.
Role 1 — We are a service provider to your dental practice (this covers patient health information)
When a dental practice enters patient information into our software, the practice decides what is collected and why. We only process it on the practice’s instructions.
Under HIPAA the practice is the Covered Entity and we are its Business Associate. We handle Protected Health Information (“PHI”) only as permitted by our Business Associate Agreement with that practice — to run the software for them and for no other purpose. We do not use PHI for our own purposes. We do not sell it. We do not use it for advertising.
Role 2 — We control information about our own customers, prospects, and visitors
For information about dental practices as our customers, people who visit our websites, people we contact about our product, and affiliates, we decide how it is used, and this Policy describes those decisions directly.
Where the two conflict, Role 1 wins. The Business Associate Agreement controls anything involving PHI.
2. Information we collect
2.1 From dental practices (our customers)
- Account and business information — practice name, address, phone, website, the names and email addresses of users you create, your role, and your account settings.
- Subscription and billing information — which tools you subscribe to, your subscription history, payment records, and billing references. We do not store full payment card numbers; Stripe handles those.
- Configuration and operational data — your fee schedules, insurance plan data, membership plan setup, discounts, inventory records, baseline numbers, and the settings you choose.
- Support communications — messages you send us, feedback you submit, and meeting requests.
2.2 About patients (entered by the practice)
Practices enter information about their patients. Depending on the tools they use, this can include:
- Contact and identity — name, date of birth, email address, phone number, and mailing address.
- Family relationships — where a practice enrolls family members or dependents under one account.
- Health and treatment information — treatment plans and their status, membership enrollment and savings records, Invisalign tracking stages, and free-text notes entered by practice staff. This is PHI, and Role 1 above applies to it.
- Payment information — membership fees, payment plan schedules, and payment history. Card details are held by Stripe, not by us.
- Survey and feedback data — satisfaction scores, NPS responses, referral activity, and review request outcomes.
- Communication records — which emails and text messages were sent, when, and whether the recipient opted out.
Patients: we did not collect this from you. Your practice provided it to us so we can run their software.
2.3 From patients directly (the membership portal)
If you create a portal account, we collect your email address, phone number, login credentials, and the actions you take in the portal.
2.4 From website visitors and prospective customers
- Landing page and contact form submissions — name, email address, practice website, and anything else you enter.
- Traffic and campaign data — the page you landed on, the campaign parameters in the link you followed (source, medium, campaign, content), the referring site, and whether you went on to create an account.
- Short link clicks — when you follow one of our short links (for example a referral, survey, or membership portal link), we record that the link was used and count the click.
- Device and usage information — IP address, browser and operating system type, pages viewed, timestamps, and performance and error logs.
2.5 About prospective customers we contact
We maintain a database of dental practices for business-to-business outreach, built from publicly available and commercially available business sources. It holds business contact information — practice name, business address, business phone, business email, website, and where available the name of the practice owner.
This is business contact information about practices as businesses, not patient information and not personal health information. If you would rather we did not contact you, see Section 8.4 — we will remove you on request.
2.6 From affiliates
If you join our affiliate program, we collect your name, contact details, the referrals you make, and the information we need to pay you.
3. Cookies, analytics, and tracking
3.1 What we use
Essential cookies. Our application sets a session cookie so you stay logged in and so security features work. These cannot be turned off without breaking the service.
Google Tag Manager and Google Analytics. We use Google Tag Manager to load Google Analytics on our marketing website, our landing pages, and the business-facing application. These tell us how many people visit, which pages they use, and which marketing channels bring practices to us. Google may set cookies to do this and processes the data as described in Google’s own privacy policy. You can learn about Google’s practices at policies.google.com and opt out of Google Analytics using Google’s browser add-on.
3.2 What we do NOT do
This is deliberate. The portal is where patients log in to see membership and billing information connected to their care, and we do not consider third-party tracking appropriate there.
We do not use advertising cookies, retargeting pixels, or cross-site behavioral advertising trackers, and we do not permit third parties to collect information about your activity across other websites through our services.
3.3 Do Not Track and Global Privacy Control
There is no consistent industry standard for “Do Not Track” browser signals, and our sites do not currently respond to them.
Where required by law, we honor the Global Privacy Control (GPC) signal as an opt-out of any sale or sharing of personal information — though note that, as stated in Section 5, we do not sell or share personal information at all.
3.4 Email and message tracking
Emails we send on a practice’s behalf may record whether the message was delivered, opened, or clicked, so the practice can see whether patients are receiving them. Text messages record delivery status and opt-outs. We do not use this information to build advertising profiles.
4. How we use information
To run the service: provide, maintain, secure, and support it; authenticate users; perform the functions practices direct — sending surveys, follow-ups, receipts, renewal notices; generate the analyses and reports practices ask for.
To handle payments: charge practices their subscription fees, and instruct Stripe to charge patients on behalf of practices (Section 6.2).
To communicate: respond to support requests; send service, security, and billing notices; and, for practices and prospects, send product and marketing communications you can opt out of at any time.
To improve the service: understand which features are used, diagnose errors, monitor performance, and develop new functionality. Where this involves PHI, it is limited to what the Business Associate Agreement permits.
To produce de-identified benchmarks: we may create aggregated, de-identified statistics — for example typical write-off percentages or referral rates across practices. PHI is de-identified in accordance with 45 C.F.R. § 164.514(b) before being used this way, and the result never identifies any practice, patient, or individual.
To market our own product: to prospective practices, using the business contact information described in Section 2.5.
To meet legal obligations: comply with law, respond to lawful requests, enforce our agreements, and protect the rights, safety, and property of Profit Smiles, our customers, and the public.
4.1 Automated processing. The service produces automated outputs — suggested posting times, engagement trends, profitability scores, what-if projections. These are informational and advisory only. We do not make decisions producing legal or similarly significant effects about any patient or practice through automated processing alone, and no clinical decision is ever made by the software.
4.2 We do not use your data to train third-party AI models. We do not send Practice Data, patient information, or PHI to any third-party artificial intelligence provider for the purpose of training that provider’s models. Where the service uses AI to generate content — for example educational social posts, composed images, or narration for our own training and marketing videos — that content is produced from our own libraries and materials, not from your data or your patients’ data.
5. We do not sell your information
This applies to practice information, patient information, portal user information, and prospect information alike. We do not disclose PHI for marketing or fundraising, and we do not permit any subprocessor to use information we give them for their own purposes.
6. Who we share information with
6.1 Subprocessors. We use third-party providers to run the service. Each is bound by written agreement to confidentiality and security obligations, and each that may handle PHI is bound by HIPAA-compliant terms. The full list, with what each one does, is in Section 4 — Data Deletion & Subprocessors below.
6.2 Between practices and patients. Patient payment information flows to the practice’s own Stripe connected account, because the practice — not Profit Smiles — is the merchant for patient payments. Patient contact and treatment information is visible to the practice’s authorized users, as the practice intends.
6.3 Legal and safety. We disclose information where legally required — court order, subpoena, or lawful government request — and where we reasonably believe disclosure is necessary to investigate fraud, enforce our agreements, or protect the rights, safety, or property of any person. Where PHI is involved, we follow the Business Associate Agreement and notify the practice unless legally prohibited.
6.4 Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. Any acquirer will remain bound by this Policy and by our Business Associate Agreements with respect to information transferred, or we will give affected practices notice and an opportunity to object.
6.5 Our own people and contractors. Employees and contractors access information only where they need it for their role, under confidentiality obligations and least-privilege access controls.
7. How long we keep information
| Category | Retention |
|---|---|
| Practice Data (including PHI) | Kept while the account is active, and afterwards in read-only form indefinitely unless the practice requests deletion — so practices never lose their history. Deleted on request. |
| Meta connection data (tokens, page IDs, permissions) | Deleted immediately and permanently on disconnection. |
| Payment and billing records | Kept while needed for accounting, tax, and audit purposes; deleted on request where we are not legally required to retain them. |
| Portal accounts | Kept while active; deleted on request. |
| Security and audit logs | Kept only as long as needed for security purposes, then purged on a rolling schedule. |
| Prospect business contact data | Kept until you ask us to remove it, or until we determine it is no longer useful. Opt-out records are kept permanently, so we do not contact you again. |
| Backups | Deleted data is removed from backups as those backups expire on their normal cycle. |
8. Your choices and rights
8.1 If you are a patient. Your health information rights run through your dental practice, not through us. Contact them to see, correct, or delete your records, or to get an accounting of disclosures. Their Notice of Privacy Practices explains how.
You can control messages directly — reply STOP to any text message, or use the unsubscribe link in any marketing email. You can turn off automatic membership renewal in your portal.
8.2 If you are a dental practice. You control your own data. You can view and correct it in the application, request an export at any time by emailing us, and request permanent deletion at any time from an authorized account. See Data Deletion Instructions below.
8.3 State privacy rights. Depending on where you live, you may have rights to know what personal information we hold, access a copy, correct inaccuracies, delete it, opt out of sale, sharing, targeted advertising, or profiling, and not be discriminated against for exercising these rights.
Residents of Texas (under the Texas Data Privacy and Security Act), California (under the CCPA/CPRA), and other states with comprehensive privacy laws may exercise these rights by emailing support@profitsmiles.com with the subject “Privacy Request.”
How we handle a request: we will verify your identity — usually by confirming you control the email address on the account — respond within the period your state’s law requires (generally 45 days, extendable once where permitted), and tell you if we cannot fulfill the request and why. You may use an authorized agent, with proof of authorization. If we deny your request you may appeal by replying to our response; we will inform you of the outcome and, where required, of your right to complain to your state Attorney General.
Two important limits:
- PHI is exempt. Information covered by HIPAA is carved out of these state laws. Requests about health information go to your dental practice.
- We do not sell or share personal information, so an opt-out request has nothing to act on — but you are welcome to send one and we will confirm.
8.4 If you are a prospective customer we contacted. Reply to any message asking us to stop, or email support@profitsmiles.com, and we will remove you from all outreach permanently. You do not need to give a reason, and we keep a record of the request so you are not contacted again.
Every marketing email we send includes an unsubscribe mechanism and our physical mailing address, as required by the CAN-SPAM Act.
8.5 Marketing communications generally. You can opt out of marketing at any time using the unsubscribe link or by contacting us. You cannot opt out of transactional and service messages — billing notices, security alerts, and material changes to our terms — while you hold an active account, because you need them.
9. Security
We protect information using encryption in transit and at rest, least-privilege access controls, individually credentialed user accounts, network and application-level safeguards, monitoring and logging, and vulnerability management. Our infrastructure runs on AWS in the United States, within its physical and environmental security controls.
We will notify affected practices of any breach of unsecured PHI without unreasonable delay and no later than 30 days after discovery — sooner than HIPAA requires — with the detail specified in our Business Associate Agreement.
No system is perfectly secure, and we cannot guarantee absolute security. Email is not a secure channel — please do not send us health information or other sensitive details by email. Use the application, or contact your practice.
You have a part in this too: use a strong, unique password, do not share credentials between people, and tell us immediately if you suspect unauthorized access.
10. Children’s privacy
The service is not directed to children, and individuals under 18 may not create an account — practice-side or portal-side.
A dental practice may enter information about a minor patient as part of that patient’s record, at the direction of the parent or guardian who has authorized their care. That information is PHI and is governed by the practice’s obligations and our Business Associate Agreement, not by our own collection practices.
We do not knowingly collect personal information directly from children. If we learn we have, we will delete it promptly. Contact support@profitsmiles.com if you believe a child has provided information to us directly.
11. Where information is held, and international users
The service is intended for use in the United States, and all information is stored and processed in the United States.
If you access the service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws differ from those in your country. Where the GDPR or UK GDPR applies to our processing, we rely on appropriate safeguards, including standard contractual clauses where required, and you may have rights of access, rectification, erasure, restriction, portability, and objection — exercisable at support@profitsmiles.com.
12. Links to other sites
Our services link to sites we do not control — Google, Meta, Stripe, and others. This Policy does not apply to them. Read their privacy policies before providing information.
13. Changes to this Policy
We may update this Policy. For material changes we will give at least 30 days’ notice by email or in the application, and we will update the “Last Updated” date at the top of this page. Continuing to use the service after a change takes effect means you accept it. We keep prior versions available on request.
14. Contact us
Profit Smiles Inc
7750 N MacArthur Blvd Ste 120-153, Irving, TX 75063-7501
Email: support@profitsmiles.com (subject line:
“Privacy Request”)
Web: profitsmiles.com
Patients: for anything about your health information, your treatment, or your bill, contact your dental practice — they hold those records and those rights run through them.
3. Business Associate Agreement
For dental practices, as Covered Entity under HIPAA.
This Business Associate Agreement (this “BAA”) is entered into by and between Profit Smiles Inc, a Texas corporation (“Business Associate”), and the dental practice or other covered entity that has accepted the Master Subscription Agreement (“Covered Entity”). Each is a “Party” and together the “Parties.”
This BAA amends and is incorporated into the Master Subscription Agreement between the Parties (the “Service Agreement”). To the extent any provision of this BAA conflicts with the Service Agreement, this BAA controls with respect to Protected Health Information.
Recitals
WHEREAS, Business Associate provides a software-as-a-service platform (the “Services”) to Covered Entity, and in performing the Services creates, receives, maintains, or transmits Protected Health Information for or on behalf of Covered Entity;
WHEREAS, the Parties intend to satisfy their respective obligations under the Standards for Privacy of Individually Identifiable Health Information (the “Privacy Rule”) and the Security Standards for the Protection of Electronic Protected Health Information (the “Security Rule”), published by the U.S. Department of Health and Human Services (“HHS”) at 45 C.F.R. Parts 160 and 164, promulgated under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”); the Health Information Technology for Economic and Clinical Health Act of 2009 (“HITECH”); and their implementing regulations, each as amended;
WHEREAS, the Parties wish to set out the terms on which Protected Health Information received from, or created, received, maintained, or transmitted on behalf of, Covered Entity will be used, disclosed, and safeguarded;
NOW THEREFORE, in consideration of the mutual promises below and other good and valuable consideration, the receipt and sufficiency of which are acknowledged, the Parties agree as follows.
1. Definitions
1.1 Capitalized terms used but not defined in this BAA have the meanings given to them in HIPAA and HITECH, as each is amended from time to time.
1.2 “Breach” means the acquisition, access, use, or disclosure of Protected Health Information in a manner not permitted by the Privacy Rule which compromises the security or privacy of the Protected Health Information, as defined and subject to the exceptions at 45 C.F.R. § 164.402.
1.3 “Designated Record Set” has the meaning given at 45 C.F.R. § 164.501.
1.4 “Electronic Protected Health Information” or “ePHI” means Protected Health Information transmitted by or maintained in electronic media, as defined at 45 C.F.R. § 160.103.
1.5 “Individual” has the meaning given at 45 C.F.R. § 160.103 and includes a person qualifying as a personal representative under 45 C.F.R. § 164.502(g).
1.6 “Protected Health Information” or “PHI” has the meaning given at 45 C.F.R. § 160.103, and for purposes of this BAA is limited to Protected Health Information received from, or created, received, maintained, or transmitted on behalf of, Covered Entity by Business Associate in performing the Services.
1.7 “Privacy Rule” means the federal privacy regulations at 45 C.F.R. Parts 160 and 164, Subparts A and E, as amended.
1.8 “Required by Law” has the meaning given at 45 C.F.R. § 164.103.
1.9 “Security Incident” has the meaning given at 45 C.F.R. § 164.304.
1.10 “Security Rule” means the federal security regulations at 45 C.F.R. Parts 160 and 164, Subparts A and C, as amended.
1.11 “Subcontractor” means a person or entity to whom Business Associate delegates a function, activity, or service involving the creation, receipt, maintenance, or transmission of PHI, other than in the capacity of a member of Business Associate’s workforce.
1.12 “Unsecured PHI” has the meaning given at 45 C.F.R. § 164.402.
2. Permitted Uses and Disclosures of PHI
2.1 The Services.
(a) Business Associate provides software-as-a-service functions to Covered Entity that involve the use and disclosure of PHI — including patient record management, membership plan administration, treatment plan follow-up communications, patient surveys and referral tracking, payment plan administration, and related data processing and analytic functions. Except as otherwise limited in this BAA, Business Associate may use and disclose PHI as necessary to perform its obligations under the Service Agreement, and as Required by Law.
(b) Business Associate may provide Data Aggregation services relating to the Health Care Operations of Covered Entity, in accordance with 45 C.F.R. § 164.504(e)(2)(i)(B).
(c) Business Associate will not use or disclose PHI for marketing or fundraising, or in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as expressly permitted by this BAA.
(d) Business Associate will not sell PHI, and will not receive remuneration in exchange for PHI, in violation of 42 U.S.C. § 17935(d) or 45 C.F.R. § 164.502(a)(5)(ii).
2.2 Management, administration, and legal responsibilities. Consistent with 45 C.F.R. §§ 164.504(e)(4)(i) and (ii), Business Associate may use PHI in its possession for its proper management and administration and to carry out its legal responsibilities; and may disclose PHI for those purposes only if (i) the disclosure is Required by Law, or (ii) Business Associate obtains reasonable assurances from the recipient that the information will be held confidentially, used or further disclosed only as Required by Law or for the purpose for which it was disclosed, and that the recipient will notify Business Associate promptly of any breach of confidentiality of which it becomes aware.
2.3 De-identification. Business Associate may de-identify PHI in accordance with 45 C.F.R. § 164.514(b). Covered Entity acknowledges that properly de-identified information is not PHI, and that Business Associate may use and disclose de-identified information for any lawful purpose, including producing aggregated industry benchmarks and improving the Services. Business Associate will not attempt, and will not permit any third party to attempt, to re-identify de-identified information.
2.4 Minimum necessary. Business Associate will limit its requests for, uses of, and disclosures of PHI to the minimum necessary to accomplish the intended purpose, consistent with 45 C.F.R. §§ 164.502(b) and 164.514(d) and any guidance issued by HHS.
3. Obligations of Business Associate
Business Associate agrees to:
3.1 Limits on use and disclosure. Not use or further disclose PHI other than as permitted or required by this BAA, as necessary to perform the Services, or as Required by Law — and in compliance with each applicable requirement of 45 C.F.R. § 164.504(e). To the extent Business Associate carries out any of Covered Entity’s obligations under the Privacy Rule, Business Associate will comply with the requirements of the Privacy Rule that apply to Covered Entity in performing those obligations.
3.2 Safeguards. Implement and use appropriate administrative, physical, and technical safeguards, and comply with the applicable requirements of the Security Rule with respect to ePHI, to prevent use or disclosure of PHI other than as provided by this BAA. These safeguards include, at minimum: encryption of ePHI in transit and at rest; unique user identification and access controls applied on a least-privilege basis; audit logging; workforce training on PHI handling; and vulnerability management.
3.3 Mitigation. Mitigate, to the extent practicable, any harmful effect known to Business Associate of a use or disclosure of PHI in violation of this BAA.
3.4 Reporting of impermissible use or disclosure and Security Incidents. Without unreasonable delay, report to Covered Entity: (i) any use or disclosure of PHI of which Business Associate becomes aware that is not permitted by this BAA, in accordance with 45 C.F.R. § 164.504(e)(2)(ii)(C); and (ii) any Security Incident of which Business Associate becomes aware, in accordance with 45 C.F.R. § 164.314(a)(2)(i)(C).
The Parties acknowledge that Business Associate’s systems, like all internet-connected systems, routinely experience unsuccessful attempts at unauthorized access — including port scans, failed log-on attempts, denied firewall traffic, and pings — that do not result in any unauthorized access to, use of, or disclosure of ePHI. This provision constitutes notice of such unsuccessful attempts, and Business Associate is not required to report them individually. Business Associate will report any Security Incident that does result in unauthorized access, use, disclosure, modification, or destruction of ePHI, or interference with system operations affecting ePHI.
3.5 Breach notification. Following discovery of a Breach of Unsecured PHI, notify Covered Entity without unreasonable delay and in no event later than thirty (30) calendar days after Discovery.
This 30-day commitment is shorter than the 60 days permitted under 45 C.F.R. § 164.410, and is given deliberately so that Covered Entity retains meaningful time to meet its own notification obligations to Individuals, HHS, and where applicable the media.
The notification will include, to the extent known at the time and thereafter as further information becomes available, the information required by 45 C.F.R. § 164.410(c): the identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed; a description of what happened and the date of the Breach and its Discovery; the types of PHI involved; the steps taken to investigate, mitigate harm, and protect against further Breaches; and any other information Covered Entity reasonably requires to make its own notifications. Business Associate will cooperate with Covered Entity’s investigation and response at Business Associate’s expense where the Breach was caused by Business Associate or its Subcontractors.
3.6 Subcontractors. In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions on the use and disclosure of PHI at least as protective as those that apply to Business Associate under this BAA, including the applicable Security Rule requirements for ePHI. A list of Business Associate’s current Subcontractors is maintained in the Subprocessor List below, and Business Associate will update that list when it adds or replaces a Subcontractor.
3.7 Access to HHS. Make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of HHS for purposes of determining Covered Entity’s compliance with the Privacy Rule.
3.8 Access by Individuals. Within fifteen (15) days of a written request from Covered Entity, make available PHI in a Designated Record Set as necessary for Covered Entity to respond to an Individual’s request for access under 45 C.F.R. § 164.524 — including providing a copy in the electronic form and format requested where readily producible, and transmitting a copy to a third party the Individual designates. If an Individual requests access directly from Business Associate, Business Associate will promptly forward the request to Covered Entity rather than responding to it, unless Covered Entity directs otherwise.
3.9 Amendment. Within thirty (30) days of a written request from Covered Entity, make available PHI in a Designated Record Set for amendment, and incorporate any amendment Covered Entity directs, in accordance with 45 C.F.R. § 164.526.
3.10 Accounting of disclosures. Document disclosures of PHI and information related to them as would be required for Covered Entity to respond to a request for an accounting of disclosures under 45 C.F.R. § 164.528, and, within thirty (30) days of a written request from Covered Entity, make that information available.
3.11 Restrictions. Comply with any restriction on the use or disclosure of PHI that Covered Entity has agreed to under 45 C.F.R. § 164.522 and has communicated to Business Associate in writing, and with any confidential communication request Covered Entity has accommodated and communicated in writing.
3.12 Direct liability. Business Associate acknowledges that, under HITECH, it is directly liable for compliance with the applicable provisions of the Privacy Rule and Security Rule, and subject to civil and criminal penalties for violations.
4. Obligations of Covered Entity
4.1 Consents and authorizations. Covered Entity will obtain any consent, authorization, or permission required by the Privacy Rule or by any other applicable federal, state, or local law before providing Business Associate with PHI relating to any Individual — including any consent required to contact an Individual by email, automated telephone call, or text message.
4.2 Notice of Privacy Practices. Covered Entity represents and warrants that its Notice of Privacy Practices permits Covered Entity to use and disclose PHI in the manner that Business Associate is authorized to use and disclose it under this BAA. Covered Entity will notify Business Associate of any limitation in that Notice, of any change in or revocation of an Individual’s permission, and of any restriction agreed under 45 C.F.R. § 164.522, in each case to the extent it affects Business Associate’s use or disclosure of PHI.
4.3 No impermissible requests. Covered Entity will not request that Business Associate use or disclose PHI in any manner that would not be permissible under the Privacy Rule if done by Covered Entity, except as permitted by Sections 2.1(b), 2.2, and 2.3 of this BAA.
4.4 Appropriate use of the Services. Covered Entity will use the security features of the Services appropriately — including maintaining individually credentialed user accounts, promptly removing access for departed personnel, and not sharing credentials — and will enter only the minimum PHI necessary for the functions it uses. Covered Entity acknowledges that the Services are not designed to serve as a complete dental or medical record system and are not intended to hold complete clinical records, radiographic images, or full chart notes.
4.5 Accuracy of contact data. Covered Entity is responsible for the accuracy of the Individual contact information it enters, and for the consequences of PHI being transmitted to an incorrect address or number entered by Covered Entity or its workforce.
5. Term and Termination
5.1 Term. This BAA takes effect on the date Covered Entity accepts the Service Agreement and continues until terminated under this Section, or until all PHI is returned or destroyed under Section 5.4. Certain provisions survive as set out in Section 6.4.
5.2 Termination for cause. If either Party knows of a pattern of activity or practice of the other Party that constitutes a material breach or violation of this BAA, the non-breaching Party will give written notice specifying the nature of the breach. The breaching Party must cure within thirty (30) days of receipt. If the breach is not cured within that period to the non-breaching Party’s reasonable satisfaction, or is reasonably incapable of cure, the non-breaching Party may terminate this BAA and, at its option, the Service Agreement. If neither termination nor cure is feasible, Covered Entity may report the violation to the Secretary of HHS.
5.3 Automatic termination. This BAA terminates automatically, without further action, upon termination or expiration of the Service Agreement — subject to Section 5.4.
5.4 Effect of termination — return or destruction of PHI.
(a) On Covered Entity’s request, made at any time during the term or within a reasonable period after termination, Business Associate will return or destroy all PHI it maintains, including PHI in the possession of its Subcontractors, and will confirm completion in writing. Business Associate will complete this within sixty (60) days of the request, except that PHI in routine backups will be destroyed as those backups expire on their normal cycle.
(b) Absent such a request, and as permitted by Section 18.3 of the Service Agreement, Business Associate will retain Practice Data — including PHI — in read-only form so that Covered Entity retains access to its own historical records. Covered Entity acknowledges and directs this retention, which exists for Covered Entity’s benefit. All protections, limitations, and restrictions in this BAA continue to apply in full to PHI retained under this paragraph, and Business Associate will limit its uses and disclosures of that PHI to those necessary to maintain and provide access to it.
This resolves what would otherwise be a conflict between the Service Agreement’s read-only retention commitment and the return-or-destroy obligation at 45 C.F.R. § 164.504(e)(2)(ii)(J). The obligation is triggered by Covered Entity’s request rather than automatically on termination, and the retained PHI stays fully protected in the meantime.
(c) Where return or destruction of PHI is infeasible — for example because retention is Required by Law — Business Associate will notify Covered Entity in writing, explaining why, and will extend the protections of this BAA to that PHI and limit further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it is retained.
6. Miscellaneous
6.1 Limitation of liability. Business Associate’s liability arising out of or relating to this BAA, whether in contract, tort (including negligence, gross negligence, or strict liability), or under any other theory, is subject to the limitation of liability provisions of the Service Agreement. Covered Entity’s attention is directed to Section 21.3 of the Service Agreement, which establishes an enhanced liability cap for claims arising from a Breach of Unsecured PHI or unauthorized access to Practice Data caused by Business Associate’s failure to meet its obligations — set at the greater of three (3) times the general cap or $25,000 — and to Section 21.4, which excludes indemnification obligations, breach of confidentiality, and gross negligence or willful misconduct from all caps. Any reference to Business Associate’s liability means its aggregate liability under the Service Agreement and this BAA taken together.
6.2 Entire agreement. This BAA, together with the Service Agreement, constitutes the entire agreement between the Parties with respect to the handling of PHI, and supersedes all prior or contemporaneous understandings on that subject.
6.3 Change of law. The Parties will negotiate in good faith to amend this BAA as necessary to comply with any amendment to HIPAA, HITECH, or their implementing regulations that materially alters either Party’s obligations. Each Party will notify the other of any such change of which it becomes aware within ninety (90) days. If the Parties cannot agree on an amendment within ninety (90) days of the change taking effect, either Party may terminate this BAA under Sections 5.2 and 5.4.
6.4 Survival. Sections 1, 2.3, 3.5, 5.4, 6.1, 6.3, 6.5, 6.9, 6.10, 6.11, and this Section 6.4 survive expiration or termination of this BAA.
6.5 Construction. Any ambiguity in this BAA will be resolved in favor of a meaning that permits both Parties to comply with HIPAA and HITECH. Any provision of the Service Agreement that directly contradicts a term of this BAA is superseded by this BAA, but only to the extent of the contradiction, only for purposes of HIPAA and HITECH compliance, and only where it is not reasonably possible to comply with both.
6.6 Amendment and waiver. This BAA may not be modified, and no provision waived, except in a writing signed by authorized representatives of both Parties — save that Business Associate may update this BAA prospectively on thirty (30) days’ notice where required to maintain compliance with a change in law, in which case Covered Entity’s remedy if it objects is to terminate under Section 5.2. A waiver as to one event is not continuing and does not waive any right as to any later event.
6.7 Notices. Notices under this BAA are given as provided in the Service Agreement. Notices to Business Associate concerning this BAA may be sent to support@profitsmiles.com.
6.8 Counterparts and electronic acceptance. Covered Entity’s acceptance of the Service Agreement constitutes execution of this BAA. Electronic acceptance and electronic copies have the same effect as originals.
6.9 Independent contractors. The Parties are and remain independent contractors. Nothing in this BAA creates a partnership, joint venture, agency, or employment relationship, and neither Party is the agent of the other for purposes of HIPAA or otherwise.
6.10 No third-party beneficiaries. Nothing in this BAA confers any right, remedy, or obligation on any person other than the Parties and their respective successors and permitted assigns. No Individual acquires any right of action under this BAA.
6.11 Governing law and venue. This BAA is governed by the laws of the State of Texas, without regard to its conflict of laws principles. Disputes are subject to the dispute resolution provisions of the Service Agreement, including its mandatory arbitration clause; where a claim is not arbitrable, venue lies exclusively in the state and federal courts located in Dallas County, Texas.
6.12 Binding effect and assignment. This BAA binds the Parties and their successors and permitted assigns, and is assignable on the same terms as the Service Agreement.
6.13 Privacy contact. Each Party may update its privacy contact from time to time. Covered Entity may direct inquiries regarding this BAA to support@profitsmiles.com.
Contact
Profit Smiles Inc
7750 N MacArthur Blvd Ste 120-153, Irving, TX 75063-7501
Email: support@profitsmiles.com
4. Data Deletion Instructions & Subprocessor List
For everyone.
We do not hold data you no longer want us to have. This explains exactly how to get it deleted, depending on who you are and what data you mean.
Part 1 — Data Deletion Instructions
1. If you are a PATIENT
Start with your dental practice. Your records belong to their patient files, and your rights over them run through the practice under HIPAA — not through us. We hold your information only as their service provider.
| What you want | Where to go |
|---|---|
| See, correct, or delete your health or treatment information | Your dental practice |
| Know who your information has been shared with | Your dental practice |
| Cancel your membership plan or stop auto-renewal | Your dental practice, or turn off auto-renewal in your member portal |
| Stop text messages | Reply STOP to any text — immediate and permanent. CANCEL, END, QUIT, UNSUBSCRIBE, STOPALL, REVOKE and OPTOUT also work. Reply START, YES or UNSTOP to resume |
| Stop marketing emails | Click unsubscribe at the bottom of any marketing email |
| Delete your member portal login | Email support@profitsmiles.com from your registered address, or ask your practice |
Deleting your portal login does not delete your practice’s records about you, and does not cancel your membership. Those are separate — talk to your practice.
If you email us asking us to delete health information, we will refer you to your practice and, where they instruct us, help them carry it out. We cannot delete a practice’s patient records on a patient’s instruction — doing so would breach our obligations to them and could destroy records they are required to keep.
2. If you are a DENTAL PRACTICE
2.1 Social media connection data — instant, self-service. In your account settings, click “Disconnect from Facebook.”
On disconnection, all Meta API connection data — access tokens, account and page identifiers, and granted permissions — is immediately and permanently deleted from our systems. Nothing is retained and no further posting is possible.
Content already published to your Facebook or Instagram accounts stays there; it is yours, on your accounts, and you remove it through those platforms.
2.2 Practice data — including patient records and PHI. After you cancel, your data stays available to you in read-only form indefinitely, so you never lose your history. We keep it for your benefit, not ours — and you can have it deleted whenever you want.
To request permanent deletion:
- Email support@profitsmiles.com from an email address on your account, with the subject line “Data Deletion Request.”
- Tell us the scope — everything, or a specific category (for example, patient records only, or billing records only).
- We will verify that the request comes from someone authorized to make it. Deletion is irreversible, so we confirm before acting.
- We delete, and confirm in writing when it is done.
Timing. We complete deletion within 30 days of verifying the request, and always within 60 days. Copies in routine backups are removed as those backups expire on their normal cycle — backups are not selectively edited, because doing so would compromise their integrity as a recovery mechanism. All deleted data in backups remains protected under our Business Associate Agreement until it ages out.
What we may have to keep. We may retain a minimal record where law requires it — for example transaction records needed for tax and accounting. We will tell you if this applies, and what it covers.
2.3 Billing records. Deletable on request, along with or separately from practice data, except where we are legally required to retain them for tax or accounting purposes.
2.4 Individual user accounts. To remove a member of your team, delete their user in Settings → Users. Do this promptly when someone leaves — it is an access-control obligation under our Business Associate Agreement, and it is yours to perform.
3. If you are a PROSPECTIVE CUSTOMER we contacted
Reply to any message asking us to stop, or email support@profitsmiles.com.
We remove you from all outreach permanently, across every channel. You do not need to give a reason or explain yourself. We keep a minimal record of the opt-out itself — your email address and the fact you asked — precisely so that you are never contacted again. That record is not used for anything else.
4. If you are an AFFILIATE
Email support@profitsmiles.com to close your affiliate account and delete your data. We may need to retain payment and tax records where law requires it — 1099 filings in particular.
5. If you are unsure, just ask
Email support@profitsmiles.com and describe what you want deleted in your own words. We would rather work it out with you than have you give up because the process was unclear.
Part 2 — Subprocessor List
These are the third parties that process data on our behalf. Each is bound by written agreement to confidentiality and security obligations, and each that may handle Protected Health Information is bound by HIPAA-compliant terms consistent with our Business Associate Agreement.
| Subprocessor | Purpose | Data processed | May handle PHI | Location |
|---|---|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting and compute; database and file storage (S3); transactional email delivery (SES) | All service data | Yes | United States |
| Stripe, Inc. | Subscription billing; patient payment processing through practices’ connected accounts; affiliate payouts and tax reporting | Payment, billing, and payout data; patient name and contact details for payment records | Yes (limited) | United States |
| Twilio Inc. | Text message delivery to patients | Patient name, mobile number, message content, delivery and opt-out status | Yes | United States |
| Meta Platforms, Inc. | Publishing content to a practice’s own Facebook and Instagram accounts | Practice social account tokens and identifiers; published content and engagement metrics | No | United States |
| Google LLC | Website and application analytics (marketing site, landing pages, and the business-facing application only — not the patient portal) | Website usage data; IP address; device and browser information | No | United States |
All processing takes place in the United States.
Changes to this list. We may add or replace subprocessors as the service develops. We will update this page when we do. Practices with a concern about a new subprocessor may raise it at support@profitsmiles.com; where a practice objects on reasonable grounds and we cannot accommodate it, the practice may cancel without penalty.
Not subprocessors. Some services are used by you, under your own agreement with the provider, rather than by us on your behalf — your own Stripe connected account, and your own Facebook and Instagram accounts. Those relationships are direct between you and the provider.
Contact
Profit Smiles Inc
7750 N MacArthur Blvd Ste 120-153, Irving, TX 75063-7501
Email: support@profitsmiles.com
Web: profitsmiles.com