How BioLign collects, uses, and protects your information across our products and services.
On this page
Last updated: July 6, 2026
BioLign is a product of Smile Elements Orthodontics, based in Alberta, Canada. This Privacy Policy is a single policy that covers all of our products. Sections that apply only to a specific product are marked with a tag such as BioLign Track. You can jump to any section using the menu.
This Privacy Policy describes how BioLign ("we", "us", or "our") collects, uses, stores, and shares your personal information when you use our products and services, including:
BioLign Track: mobile companion app for orthodontic aligner treatment tracking (iOS and Android)
BioLign Cloud: web-based practice management system and lab coordination platform
BioLign3D: AI-assisted 3D treatment planning software
biolign.ca: our website
Please read this policy alongside our Terms of Service. Where we rely on your consent, we ask for it separately and you can withdraw it at any time, as described below. Where we process health information on behalf of your orthodontic provider, we do so under that provider's direction and under a written agreement with them.
The short version
We never sell your personal information or use it for advertising.
Your data is encrypted and hosted in Canada (Microsoft Azure, Canada Central).
You can export your data or permanently delete your account at any time.
AI analysis of 3D scans runs on your clinician's device, not an outside AI service.
This summary is for convenience only; the full policy below governs.
1. Information We Collect
Account Information
Full name and email address
Phone number (doctors and practice staff; optional for patients)
Date of birth, used to verify minimum age and to obtain parental or guardian consent where required by law
For practice patients, additional contact and demographic details entered by the practice: gender, mailing address and postal/ZIP code, phone number type, and, for a minor, the name of the responsible parent or guardian
Consent record (a timestamp of when you accepted the Terms of Service and Privacy Policy, and, where applicable, when a parent or guardian gave consent)
Authentication credentials, managed by Auth0 (an Okta company). BioLign does not see or store your password.
Patient Treatment Data BioLign TrackBioLign Cloud
Current tray number, total trays per arch (upper / lower), days per tray, and daily wear target
Treatment start date, estimated end date, and treatment status (active, pending, complete)
Bout history (multiple treatment phases over time)
Daily wear time logs (minutes per day, with timestamps)
Wear sessions (start and stop times when actively tracking)
Tray change history (dates, which arch changed, fit status, clinical notes)
Computed treatment compliance metrics (total compliance, 7-day rolling average, streaks). Streaks and milestone badges shown to patients are calculated from your wear logs.
Your device time zone, stored to anchor wear-time calculations correctly
Clinical and Health Data BioLign CloudBioLign3D
Medical alerts and clinical notes recorded by your provider
Treatment photos uploaded by you or your provider (categorized as intraoral, extraoral, X-ray, smile, with aligners, or other)
3D dental models and scans (such as STL meshes), tooth segmentation data, and treatment-plan state used for treatment planning in BioLign3D and BioLign Cloud
Prescriptions, treatment plans, case records, staged aligner models, and fabrication orders
Insurance and billing information, when applicable (BioLign Cloud only; not collected by BioLign Track). This can include the insurance subscriber's name, date of birth, and relationship to the patient.
Consultation requests sent from the Discover directory (patient-initiated only)
Appointment booking and scheduling data (dates, times, notes)
Support requests you send us
Community / Discover Content BioLign Track
If you choose to use the in-app Discover feed:
Posts, comments, and likes you create (visible to other signed-in users)
Optional treatment-context tags attached to posts (for example, "Tray 5 of 12 - Day 14")
If you post anonymously, your name is hidden from other users, but BioLign retains the link between the post and your account for moderation and abuse-prevention purposes
Photos you attach to posts, including before/after case studies (case studies require explicit patient consent before upload, with an audit record of who affirmed consent and when)
Reports you file against other users' content, including the reason category and any free-text explanation
Doctor Public Profile Data BioLign Track
If you are a doctor who opts into the public directory:
Display name, specialty/specialties, bio, and credentials shown in your public profile
Profile and cover photos (uploaded by you)
Gallery and case study images you choose to publish
Practice location: city, province/state, country, and an approximate city-level latitude/longitude. Coordinates are used to power patient "Near Me" searches and are shown only at city granularity; an exact street-level position is not derived or shown.
Location Data BioLign Track
Patients searching for doctors near them may grant the app permission to access device location. When granted, your latitude and longitude are sent to BioLign servers only at the moment you perform a "Near Me" search, are used in memory to compute distance to listed doctors, and are not stored against your account.
Alternatively, you may search by city; in that case, only the city you select is processed.
Location access is foreground-only and opt-in. The app does not track your location in the background. If you deny the permission, the app falls back to manual city search.
Authentication and App-Lock Data
BioLign Track can lock itself after a period of inactivity and require Face ID, Touch ID, or your device passcode to resume. This biometric check is performed locally by your operating system, which returns only a pass/fail result. Your biometric data (face or fingerprint templates) never leaves your device and is never transmitted to BioLign or Auth0.
If your sign-in method uses a passkey, the private key and biometric template remain on your device in its secure hardware; only a public key is held by our identity provider. BioLign never receives your biometric data.
Practice Information BioLign Cloud
Practice name, phone number, and address
Office hours and scheduling preferences
Staff profiles, roles, and permissions
Staff attendance and timesheet records, where the practice uses those features
Fabrication orders and lab coordination data
Device and Technical Data
Device push notification token (used by BioLign servers to deliver notifications via Apple Push Notification Service on iOS or Google's equivalent on Android)
Calendar access (only when you tap "Add to calendar" for a tray change; BioLign does not read your existing calendar entries)
Camera and photo library access (only when you take or pick a treatment photo)
App version, OS version, and device model, used for support and reliability
Application performance and diagnostic data (for example, request timing and error traces). These diagnostics are designed to exclude clinical content, though technical identifiers such as record IDs may appear in server logs.
For our website, server logs may include your IP address and basic request information (see "Cookies and Website Analytics" below)
2. How We Use Your Information
We use the information we collect to:
Provide treatment tracking and compliance monitoring for aligner patients
Enable communication between patients and their orthodontic providers
Facilitate appointment scheduling and reminders
Send wear time reminders, tray change notifications, and other in-app or push notifications you have enabled
Visualize treatment progress for patients and their providers
Generate and manage 3D treatment plans, scans, staged models, and clinical workflows
Power the in-app Discover feed and the doctor directory, including "Near Me" search when you have granted location permission
Allow patient-initiated consultation requests to doctors who have published a public profile (doctors cannot initiate outreach to patients)
Review user reports of community content and take moderation action on posts and comments that violate our policies
Manage practice operations, patient records, lab coordination, staff scheduling, and attendance
Process payments and manage billing (BioLign Cloud only)
Verify age requirements and obtain parental or guardian consent where the law requires it
Authenticate sign-in attempts and maintain session security, including the in-app inactivity lock
Maintain, secure, troubleshoot, and improve our products, including diagnosing errors and monitoring performance
Improve the accuracy of our clinical tools, including AI features, using treatment data as described in "Automated Processing and AI" below
Detect and prevent fraud, abuse, and security incidents
Provide customer support
Comply with legal obligations and respond to lawful requests from regulators
BioLign does not use your personal information for advertising, behavioral targeting, or to build advertising profiles. We do not sell your personal information, and we do not share it with third parties for their own marketing.
3. Legal Bases for Processing
Where the European Union or United Kingdom General Data Protection Regulation (GDPR) applies to you, we rely on the following legal bases. This framework also helps explain, for all users, why we process each type of information.
To provide the Services (accounts, treatment tracking, messaging, scheduling, and support): performance of our contract with you (GDPR Article 6(1)(b)).
To process health and clinical data to support your care: for special-category health data, the provision of health care under the responsibility of a health professional (Article 9(2)(h)) and, where your provider relies on it, your explicit consent (Article 9(2)(a)). Your provider directs this processing.
Discover posts, the public doctor directory, "Near Me" location search, and case-study photos: your consent (Article 6(1)(a)), and your explicit consent for any health information you choose to post (Article 9(2)(a)). You can withdraw this consent at any time.
Security, fraud prevention, content moderation, service improvement, and product reliability: our legitimate interests in operating a safe and functional platform (Article 6(1)(f)). You can object to this processing as described in "Your Rights and Choices."
Age verification, breach notification, lawful disclosures, and clinical record retention: compliance with a legal obligation (Article 6(1)(c)).
Providing your account and treatment information is necessary to create an account and use the core Services; without it, we cannot provide treatment tracking. Location, calendar, camera, and Discover participation are optional, and the app works without them.
4. How We Share Your Information
With Your Orthodontic Provider
If you are a patient, your treatment data, wear compliance, tray history, photos, and messages are shared with the orthodontic provider (doctor or practice) you are linked to. When you link to a provider, the app shows you exactly what will be shared and asks you to confirm. This sharing is essential for your provider to monitor your treatment and communicate with you. A provider can only see data for patients linked to them.
Within a Practice BioLign Cloud
Staff members at your linked practice can access your patient record based on their assigned role and permissions, on a minimum-necessary basis. Corporate administrators can view data across the practices within their own organization. Practice-level data isolation is designed so that staff at one practice cannot access patient records at another organization unless access has been explicitly granted.
Clinic-to-Lab Coordination BioLign CloudBioLign3D
To fabricate aligners, a treating practice may submit a case to a partner laboratory through BioLign. The case shared with the lab can include the patient's 3D scans and treatment models, clinical photos, the prescription and clinical instructions, treatment timing, and the referring doctor's name. The lab uses this information only to plan and produce the aligners for that case.
Publicly in the Discover Feed and Doctor Directory BioLign Track
If you post in the Discover feed, your post, comments, and likes are visible to all signed-in BioLign Track users. Anonymous posting hides your display name from other users but does not hide your content. If you publish a doctor public profile, the information in it (including city-level location, specialties, bio, and gallery) is visible to all users browsing the directory.
You can delete your own posts and comments at any time. A post you delete individually is hidden from other users and may be retained for a limited period for moderation, dispute resolution, or legal purposes. If you delete your entire account, your posts, comments, and likes are permanently removed (see "Your Rights and Choices").
Service Providers Who Process Data for Us
We use the following service providers to operate our platform. They process data on our behalf under written contracts that require them to protect your information and use it only to provide services to us. We remain accountable for personal information handled by our service providers.
Auth0 (an Okta company): authentication, identity management, and credential storage
Microsoft Azure: cloud hosting, database, file storage, and application infrastructure (Canada Central region)
Azure Blob Storage: storage of treatment photos, 3D models and scans, gallery images, and documents, kept private and served only through short-lived, time-limited signed links
Azure SQL Database: encrypted relational storage of account, treatment, and clinical data
Stripe: payment processing (BioLign Cloud only). BioLign does not store full card numbers; Stripe handles card data under PCI DSS.
Azure Communication Services: transactional email delivery (account verification, password resets, treatment and case notifications, invoices)
Microsoft Application Insights / Azure Monitor: application performance monitoring and error diagnostics. This may include technical request data, which can contain record identifiers.
Expo Push Service: relays mobile push notifications to Apple Push Notification Service (iOS) and Google's messaging service (Android)
We use a bundled worldwide city and geography reference dataset to power city search; no personal data is sent to any external geocoding service. A doctor may choose to add their own external booking link (such as Calendly) or review link to their public profile; if you follow such a link, you leave BioLign and the third party's own terms and privacy policy apply. BioLign does not use Google Analytics, Firebase Analytics, Facebook SDKs, or any advertising network in our mobile apps.
Platform Administration
A small number of authorized BioLign personnel can access platform data across organizations to operate the service, provide support, investigate security or billing issues, and onboard new practices. This access is limited to what is needed for those purposes and is subject to our confidentiality and security obligations.
Legal Disclosure
We may disclose personal information when required to do so by law, court order, or government request, or when we believe in good faith that disclosure is necessary to protect our rights, the safety of our users, or to investigate fraud or security incidents. Where permitted by law, we will notify you before complying with such a request.
What We Do Not Do
We do not sell your personal information to third parties
We do not use your data for advertising or marketing profiling
We do not share your data with third parties for their own marketing purposes
We do not transmit biometric data (Face ID, Touch ID, fingerprint templates) off your device
5. Automated Processing and Artificial Intelligence
BioLign uses software, including artificial intelligence, to assist clinical work and to summarize information. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, without human involvement.
3D treatment planning (BioLign3D): AI helps generate proposed tooth segmentation and treatment-planning options. The AI analysis of your 3D scans runs on the clinician's own device, not on an outside AI service. Every proposed plan is reviewed, adjusted, and approved by a qualified clinician, who makes all treatment decisions.
Compliance metrics (BioLign Track): we calculate wear-time summaries, streaks, and milestone badges from the wear data you log.
Content moderation (Discover): we may use automated tools to help flag content for review, but moderation decisions involve human review.
Improving our clinical tools: we may use treatment data, including scans and segmentation labels, to improve the accuracy of our AI features. This use stays within BioLign and our service providers; we never sell this data or use it to train models for unrelated third parties. We are working to de-identify clinical data used for model improvement, and you or your provider can ask us not to use a case for this purpose.
You can ask us what information was used in an automated process that you believe affected you, and you can raise concerns with your provider or our Privacy Officer and request human review.
6. Data Storage and Security
We take the security of your data seriously and implement multiple layers of protection:
Encryption in transit: data between the app and our servers is sent over TLS (HTTPS).
Encryption at rest: databases and file storage are encrypted at rest using Microsoft Azure's managed encryption.
Data residency: our production databases and file storage are hosted in the Microsoft Azure Canada Central region.
Secure token storage: authentication tokens are stored in iOS Keychain or the Android Keystore on mobile devices; web sessions are held in memory only.
Biometric data: Face ID, Touch ID, and fingerprint data never leave your device. They are processed by your operating system's secure hardware; BioLign and our identity provider receive only a pass/fail result of the local check.
Private file storage: treatment photos, 3D models, and gallery images are kept in private storage and served only through short-lived, time-limited signed links.
Role-based access controls: patients see only their own data; doctors and staff see only the patients assigned to them or their practice, on a minimum-necessary basis.
Organization isolation: each organization's data is logically separated so it cannot be accessed by other organizations without explicit authorization.
In-app session lock: the mobile app automatically locks after a period of inactivity and requires Face ID, Touch ID, or your device passcode to resume, supporting an automatic-logoff safeguard.
Session limits: you are required to fully re-authenticate periodically even during an active session.
Audit logging: authentication events, treatment and fabrication changes, and certain administrative actions are logged for security and compliance review.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We work continually to protect your information and to improve our safeguards.
7. Data Breach Notification
If a security breach affects your personal information and creates a real risk of significant harm, we will act without unreasonable delay to investigate, contain, and remediate it, and we will notify you and the relevant authorities as required by law. In particular:
Canada: we will report qualifying breaches to the Office of the Privacy Commissioner of Canada and, where applicable, the Office of the Information and Privacy Commissioner of Alberta and your provincial regulator, notify affected individuals, and keep records of breaches as required by PIPEDA and provincial law.
Health-provider context: where we hold information on behalf of a healthcare provider, we will notify that provider without unreasonable delay so they can meet their own obligations, including, for US providers covered by HIPAA, notification no later than 60 days after discovery.
Where you use BioLign without a covered healthcare provider, or where other law requires it, we will notify affected individuals and regulators directly within the timeframes those laws require, including under the US Federal Trade Commission's Health Breach Notification Rule and applicable state breach-notification laws.
EU / UK: where GDPR applies, we will notify the competent supervisory authority within 72 hours where required, and affected individuals without undue delay where the breach is likely to result in a high risk to their rights.
8. Your Rights and Choices
Account Deletion
You can delete your account at any time:
BioLign Track: go to Profile and select "Delete Account." Your account and personal data are hidden from the app immediately and scheduled for permanent deletion. For a 30-day recovery window they are retained (not yet erased) so that an accidental deletion can be undone: where your account still has a sign-in, signing back in within those 30 days lets you restore your data — treatment tracking, wear logs, messages, your doctor connection, and the posts, comments, and likes you created in Discover — or choose to start fresh and erase it right away. If you take no action, after 30 days your personal data and your sign-in account are permanently deleted and your email becomes available again for re-registration. If a parent or guardian account is deleted, the children it manages are hidden and deleted on the same 30-day schedule, and are restored together with the guardian if the account is recovered. If an orthodontic provider treated you, the clinical records that provider created about your care (which may include your treatment chart, scans, photos, notes, and appointments) remain part of that practice's own records, de-linked from your account, and are retained by the practice in accordance with applicable medical record-keeping laws (see "Leave Your Provider" below and "Patient Data Ownership" in our Terms).
BioLign Cloud: staff and practice accounts are managed by your practice administrator. Contact your practice administrator, or email us at biolign@smileelements.ca, to request account deletion.
When you delete your account, your personal data is hidden from our active systems immediately and retained for a 30-day recovery window before it is permanently deleted; if you do not restore the account within that window, we then erase it. Residual copies may persist in encrypted backups and in audit or transaction logs for a limited period thereafter, where required for security, fraud prevention, or legal compliance, before being overwritten or purged.
Leave Your Provider
In BioLign Track, you can leave your linked doctor or practice at any time from your Profile settings. This ends the data-sharing relationship with that provider; your tracking history with them is retained on the provider's side as part of their records, and your future logs stop being shared with them. If the practice you leave was your only linked practice, you can keep using BioLign Track on your own as a self-tracking user.
If Your Provider Removes You
A doctor or practice can remove you from their patient list. This is an unlink, not a deletion of your account: your BioLign Track account and your personal progress (wear history, streak, and milestone badges) are kept, and you can continue tracking on your own, set up your own treatment plan, or connect with a new provider whenever you are ready. The provider keeps the clinical records they created during your care, as part of their own practice records, in accordance with applicable medical record-keeping laws. Only you can permanently delete your account and personal data (see Account Deletion above).
Export Your Data
Every BioLign Track user (patient, guardian, standalone doctor, or clinic staff) can request a complete export of their personal data directly from the in-app Profile screen. The export is delivered as a JSON file you can save, share, or transmit to another organization, supporting your right of access and data portability.
For patients, the export includes account information, every treatment record, all wear logs, tray changes, wear sessions, bout history, photos (as links), 3D models (as links), clinical notes recorded about you, medical alerts, appointments, all messages, consultation requests you sent, and your Discover activity (posts, comments, likes, and reports). A guardian's export includes the data of each child they manage.
For doctors and clinic staff, the export includes account information, professional profile, practice metadata, the list of your patient relationships, invitations you sent, messages you authored, your public doctor profile (if any), consultation requests you received, and your Discover activity.
Device push notification tokens are intentionally excluded to prevent credential leakage if the file is mishandled.
Manage Your Community Content
You can edit or delete your own posts and comments in the Discover feed at any time, including those posted anonymously.
You can report another user's post or comment for review by tapping the report option on the item.
You can block another user so you no longer see their content and they can no longer interact with or contact you.
Doctors can disable their public profile at any time from the in-app profile setup screen.
Notification, Location, and Calendar Controls
You can control which notifications you receive through the app's notification settings, and you can revoke notification, location, or calendar permission entirely through your device settings at any time without affecting your ability to use the rest of the app.
Access, Correction, and How to Exercise Your Rights
You can view and update much of your personal information directly in your profile. Depending on where you live, you may also have the right to access, correct, delete, restrict, or object to our processing of your personal information, to withdraw consent, and to data portability. To make a request, email us at biolign@smileelements.ca. We will respond within the time required by the law that applies to you (generally 30 days in Canada and for access requests, and one month under GDPR, each extendable with notice for complex requests), at little or no cost. If we cannot fulfill a request, we will explain why. We may need to verify your identity before acting. You will not be treated differently for exercising your rights.
For records your orthodontic provider created or controls, requests to access or amend that information are fulfilled by your provider; contact your provider directly, or contact us and we will route your request to them as required by our agreements.
Withdraw Consent
You can withdraw consent for the sharing of treatment data with your provider at any time by leaving the practice or deleting your account. Withdrawing consent does not affect the lawfulness of processing that occurred before your withdrawal, and some processing may continue where the law requires it (for example, audit logs and clinical records held by your provider).
9. Raising a Concern or Complaint
If you believe we have not handled your personal information properly, please contact our Privacy Officer first at biolign@smileelements.ca. We will acknowledge your concern, investigate it, respond to you, and tell you what we have done to resolve it.
If you are not satisfied, you may escalate to your regulator, including the Office of the Privacy Commissioner of Canada, the Office of the Information and Privacy Commissioner of Alberta, the Commission d'acces a l'information du Quebec, your provincial health-information regulator, the US Department of Health and Human Services Office for Civil Rights, your US state attorney general, or your supervisory authority in the EU or UK.
10. Data Retention
We keep personal information only as long as needed for the purposes described in this policy, or as required by law. In practice:
Account and treatment data: retained while your account is active. When you delete your account, your personal data is hidden immediately and retained for a 30-day recovery window (so an accidental deletion can be undone by signing back in), after which it is permanently deleted from our active systems.
Backups: residual copies in encrypted backups are overwritten on a rolling cycle, after which deleted data is no longer recoverable.
Discover content: a post you delete individually may be retained for a limited period for moderation and dispute resolution; on account deletion your community content is permanently removed.
"Near Me" location coordinates: not stored; used only for the duration of the search.
Audit, security, billing, and invoice records: retained as long as required for security, accounting, tax, and legal compliance.
Clinical records held by your provider: retained by the practice for the minimum period required by the applicable medical-records law. For example, in Alberta this is commonly at least 10 years for adults, and for a minor at least 10 years past the age of majority.
De-identified or aggregated data that cannot reasonably identify you may be retained for product improvement; we do not attempt to re-identify it.
11. Communications and Your Consent
We send you service messages necessary to operate the Services, such as account verification, password resets, treatment and appointment notifications, and case updates. These are part of providing the Services.
We will only send you promotional or newsletter emails with your consent. Every such message identifies BioLign / Smile Elements Orthodontics, includes our contact information, and provides an easy way to unsubscribe, which we honor promptly, consistent with Canada's Anti-Spam Legislation (CASL). You can also control in-app and push notifications by category in the app or through your device settings. We do not currently send marketing text messages; if we ever send transactional SMS, we will obtain the consent the law requires and provide opt-out instructions.
12. Cookies and Website Analytics
This section describes our website, biolign.ca. Our mobile apps do not use advertising trackers or third-party analytics SDKs.
Our website uses only the cookies and similar technologies needed to display pages, remember your preferences, and keep the site secure. We do not use the website to build advertising profiles or to sell or share your information for cross-context behavioral advertising. Some pages may load fonts or embedded content from third parties to render correctly. Where required in your region, we present a consent banner that lets you accept or reject non-essential cookies, and you can also control cookies through your browser settings. If we add website analytics in the future, we will update this section and obtain consent where the law requires it.
13. Children's Privacy
BioLign Track uses the date of birth provided at sign-up to enforce minimum age requirements:
We do not knowingly allow children under 13 to create their own account. If we learn that we have collected personal information directly from a child under 13 without the required consent, we delete it promptly.
A child under 13 can participate only through a parent or guardian account, where the parent or guardian holds the account and provides consent. Children managed this way do not sign in themselves.
Users aged 13 to 17 must provide a parent or guardian email and confirm that a parent or legal guardian has reviewed the Terms of Service and Privacy Policy and consented to their use of the app. In Quebec, a parent or guardian must consent for any user under 14. Where GDPR Article 8 applies, the digital-consent age set by your member state (13 to 16) governs.
We do not knowingly use precise geolocation from, serve targeted advertising to, or sell or share the personal data of any user we know to be a minor.
Aligner treatment is a clinical decision; minors should always use BioLign Track in coordination with their orthodontic provider and a parent or guardian.
BioLign Cloud and BioLign3D are intended for orthodontic professionals and are not intended for use by children. If you are a parent or guardian and believe your child has provided us with personal information without your consent, contact us at biolign@smileelements.ca and we will delete the account and associated data promptly.
14. Healthcare Privacy by Region
Because BioLign products handle health-related information, additional protections apply depending on where you live and where your provider practices. This Privacy Policy is not a substitute for, and is not, your provider's own Notice of Privacy Practices; your orthodontic provider is responsible for providing you with its own notice describing how it uses and discloses your health information.
Canada: we are committed to complying with the Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta's Personal Information Protection Act (PIPA), Quebec's Law 25, and applicable provincial health-information statutes such as Ontario's Personal Health Information Protection Act (PHIPA). Where your provider is a health information custodian, BioLign acts as that custodian's service provider, agent, or information manager and processes patient health information only on the custodian's instructions and under a written agreement. In Quebec, we obtain consent appropriate for sensitive information, maintain a record of confidentiality incidents, and assess privacy risks before transferring personal information outside Quebec; our Privacy Officer is the person in charge of the protection of personal information.
United States (HIPAA): when BioLign processes Protected Health Information on behalf of an orthodontic provider that is a HIPAA-covered entity, we act as a Business Associate under HIPAA and the HITECH Act, subject to a Business Associate Agreement with the provider. We have implemented administrative, physical, and technical safeguards designed to meet the requirements of the HIPAA Security Rule, including encryption in transit and at rest, role-based and minimum-necessary access controls, audit logging, and automatic session lock-out. Practices and covered providers can request and execute our Business Associate Agreement before transmitting Protected Health Information.
When HIPAA does not apply: if you use BioLign Track on your own, or with a provider who is not a HIPAA-covered entity, HIPAA may not govern that information. In those cases we protect your health information under the US Federal Trade Commission's Health Breach Notification Rule and applicable state consumer-health-privacy laws, and we honor the consumer-health rights described below regardless of whether HIPAA applies.
European Economic Area / United Kingdom: where GDPR or UK GDPR applies, BioLign acts as a processor on behalf of your provider (the controller) for provider-managed health data, and as a controller for the Discover feed, the doctor directory, "Near Me" search, standalone accounts, the website, and account, billing, and product-improvement data. Health data is treated as special-category personal data under Article 9 and is processed only with explicit consent or where another lawful basis applies. Practices and providers can enter into our data processing agreement under Article 28.
Under these laws you may have the right to know what personal information we hold, to access and obtain a copy of it, to request correction or deletion (subject to legal or clinical retention requirements), to withdraw consent, to restrict or object to certain processing, to data portability, and to file a complaint with your regulator (see "Raising a Concern or Complaint").
15. Consumer Health Data (Washington, Nevada, Connecticut)
This section applies to "consumer health data" as defined by the Washington My Health My Data Act, Nevada SB370, and Connecticut's health-data provisions. The categories of consumer health data we may collect include your treatment status and history, aligner wear and compliance data, clinical notes and photos, and, only when you choose to search for nearby providers, location data you provide for that search. We collect this data from you, your provider, and your use of the app, and we use and share it only as described in this policy, including with your linked provider, partner laboratories for fabrication, and the service providers listed above.
We do not sell consumer health data.
Where these laws require it, we collect and share consumer health data only with your consent, which you can withdraw at any time, and you can request deletion of your consumer health data.
No geofencing: we do not establish geofences around any healthcare facility, dental or orthodontic office, or other location to identify or track consumers, to collect their data, or to send them messages or advertising based on their proximity to such a place. Device location is used only at the moment you tap "Near Me" to calculate distance to listed doctors, and is not used to detect your presence at any clinic.
To exercise these rights or ask a question about your consumer health data, contact us at biolign@smileelements.ca.
16. California Privacy Rights
This section provides information required by the California Consumer Privacy Act, as amended (CCPA/CPRA). In the past 12 months we have collected the following categories of personal information: identifiers (such as name, email, phone, and account identifiers); customer records (such as contact and demographic details); characteristics like age; commercial and billing information; internet and app activity; precise geolocation (only for "Near Me" search, in the moment); audio, visual, or similar information (such as treatment photos); professional information (for doctors and staff); and medical and health information. We collect this information from you, your provider, and your use of the Services, and we use and disclose it for the business purposes described in this policy. Health information and precise geolocation are treated as sensitive personal information.
We do not sell or share (as those terms are defined under the CCPA) your personal information, and we do not use or disclose your sensitive personal information for purposes that would require us to offer a "Limit the Use of My Sensitive Personal Information" option. We do not use your information for cross-context behavioral advertising.
If you are a California resident, you have the right to know and access the personal information we hold about you, to request correction, to request deletion, and to not be discriminated against for exercising your rights. To exercise these rights, email biolign@smileelements.ca or call 1-825-779-5484; we will respond within 45 days (extendable with notice). You may use an authorized agent to submit a request, and we may verify your identity and the agent's authority. Note that health information we hold as a Business Associate under HIPAA, and certain medical information, are handled under those laws rather than the CCPA.
17. Other US State Privacy Rights
If you are a resident of a US state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, Texas, Utah, Oregon, or Montana), you may have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. Because we do not sell personal data, do not use it for targeted advertising, and do not engage in that kind of profiling, browser opt-out preference signals such as Global Privacy Control do not change how we process your data, and we honor such signals where they apply. We process sensitive data, including health data, with the consent these laws require.
To exercise these rights, email biolign@smileelements.ca. If we deny your request, you may appeal by replying to our decision; we will respond within the time your state law allows and tell you how to contact your state attorney general if you remain dissatisfied.
18. Cross-Border Data Transfers
BioLign's production infrastructure is hosted in the Microsoft Azure Canada Central region. Some of our service providers (for example, Auth0, Stripe, and Expo) may process limited data in the United States or other countries. When personal information is transferred across borders, we use appropriate safeguards, such as contractual commitments to standards comparable to PIPEDA and, where applicable, GDPR Standard Contractual Clauses or reliance on a recipient's certification under a recognized transfer framework. You can request more information about these safeguards by contacting our Privacy Officer.
19. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you through the app or by email. Where a change materially affects how we handle your health information in a way that relies on your consent, we will seek your renewed consent before that change applies to you. Your continued use of BioLign products after other changes are posted constitutes your acceptance of the updated policy.
20. Contact Us and Privacy Officer
BioLign is a product of Smile Elements Orthodontics, based in Alberta, Canada. We have designated a Privacy Officer who is accountable for our compliance with this policy and with applicable privacy laws. You can contact the Privacy Officer with any question, access request, correction, or complaint, including questions about how your information is handled outside your country: