Skip to main content

Privacy Notice

Effective April 30, 2026

Smile Design Lab (“we,” “us,” or “the platform”) operates a global marketplace that connects dental practices with dental laboratories for the design and manufacture of restorative cases. This notice explains what information we handle, why, and the rights you have over it.

We are a HIPAA Business Associate to the dental practices that submit cases through the platform, and we extend that posture to the labs they engage. For users in the European Economic Area, the United Kingdom, and Switzerland, we are the data controller for account data and a data processor for case-level patient data on behalf of the originating practice.

1. Who we are

Smile Design Lab is operated by Smile Design Lab, Inc. (a Delaware corporation). Our registered contact for privacy matters is privacy@smiledesignlab.com. For HIPAA-related questions, our designated Privacy Officer can be reached at privacy@smiledesignlab.com.

2. Information we collect

2.1 Account information

  • Email address, full name, role on the practice or lab.
  • Profile attributes you choose to provide (specialties, languages, bio).
  • Authentication and session metadata (IP, user-agent, login timestamps).

2.2 Practice and lab onboarding (KYC) information

  • Legal entity name, address, country, region, postal code, phone.
  • Practice: NPI and tax identifier (reviewed by our admins, retained for the regulatory record).
  • Lab: business identifiers, Stripe Connect identity verification fields collected directly by Stripe.

2.3 Case-level information (Protected Health Information)

When a practice submits a case, the data we handle on behalf of that practice may include:

  • Patient first and last name, preferred name, date of birth, internal chart number.
  • Sex, address, email, phone, medical alerts.
  • Doctor notes, restoration specifications, due dates.
  • Files attached to the case: STL scans, DICOM volumes, photographs, lab slips.
  • Messages exchanged between the practice and the assigned lab.

Patient identifiers are only shared with a lab when the practice has recorded the patient's consent for that disclosure. When consent is not recorded, the lab sees the case under its case number alone and the patient name, contact, and chart number remain hidden from them.

2.4 Payment information

Card details and bank-account details are handled by Stripe and never touch our servers. We retain Stripe's opaque identifiers (customer, account, payment intent, charge) so we can reconcile escrow movements and surface receipts.

2.5 Cookies and similar technologies

We use strictly-necessary cookies for authentication and CSRF protection. We do not use advertising or third-party analytics cookies. A short-lived theme preference cookie is stored locally only.

3. Why we use information (and our lawful basis)

PurposeCategoriesGDPR lawful basis
Provide the platform (auth, case workflow, marketplace).Account, KYC, case-level.Contract (Art. 6(1)(b)).
Process payments and disburse lab payouts.Payment identifiers.Contract (Art. 6(1)(b)).
Maintain a tamper-evident audit trail.Account, case-level, security telemetry.Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)).
Detect fraud and abuse.Account, security telemetry.Legitimate interest (Art. 6(1)(f)).
Communicate transactional events (case status, invoices).Account email.Contract (Art. 6(1)(b)).

For PHI specifically, our lawful basis is the Business Associate Agreement we maintain with each practice, plus the practice's own HIPAA authorization where applicable. We do not use PHI for marketing, and we do not train, fine-tune, or improve machine-learning models on identified PHI.

As the Business Associate Agreement expressly authorizes, we may de-identify PHI in accordance with 45 C.F.R. § 164.514(a)–(c). Once de-identified, that information is no longer PHI and is not subject to HIPAA, and we may use it for model development, benchmarking, and research as set out in the Master Subscription Agreement. Where an AI feature processes identified data to do its job for a practice — for example summarizing a case — that processing serves that practice under the Business Associate Agreement and is not used to train models for anyone else. We do not attempt to re-identify de-identified data.

4. Who we share information with

  • The dental labassigned to a case — only the data necessary to fulfill that case, gated by the practice's consent flag for patient identity.
  • Stripe (payment processing, Connect onboarding, tax forms). Stripe is an independent controller under their own privacy notice.
  • Supabase, Inc. (managed Postgres + storage). Our sub-processor under a Business Associate Agreement.
  • Vercel, Inc. (application hosting). Sub-processor under a Data Processing Addendum.
  • Email delivery providers for transactional notices.
  • Government, regulators, or counsel when compelled by a valid legal process or to protect health and safety.

We do not sell personal information. We do not share it for cross-context behavioral advertising.

5. International transfers

Our infrastructure runs primarily in the United States. When EU/UK personal data is transferred outside its origin region, we rely on the European Commission's Standard Contractual Clauses with our sub-processors and conduct supplementary measures (encryption in transit and at rest, access logging, and the contractual safeguards described in §6).

6. How we protect your information

  • Row-level security on every table that contains tenant or patient data — see our security overview.
  • Encryption at rest and in transit; signed URLs for file delivery.
  • Tamper-evident audit log, partitioned by month, accessible only to designated platform administrators.
  • Multi-factor authentication available on every account.
  • Annual penetration tests and continuous vulnerability scanning.
  • Background-checked and trained personnel; least-privilege access to production.

7. How long we keep information

  • Case recordsare retained for as long as the originating practice maintains its account, plus the longer of seven (7) years or the retention period required by the practice's jurisdiction. The practice can request earlier deletion (see §8); we will honour the request unless retaining the record is required for our regulatory obligations.
  • Audit logs are retained for at least seven (7) years to support breach response and regulatory inquiries.
  • Account-level data is retained for the duration of the account plus thirty (30) days, after which it is purged unless a legal hold applies.

8. Your rights

Subject to local law, you can:

  • Access the personal data we hold about you.
  • Correct inaccurate data through your account settings or by writing to us.
  • Request deletion of your account data.
  • Object to processing based on legitimate interest.
  • Restrict processing in certain cases.
  • Receive a portable copy of the data you provided.
  • Withdraw consent at any time, where our basis is consent.

For HIPAA matters, your rights of access, amendment, accounting, and restriction are exercised through your dental practice as the covered entity. If a practice has gone out of business or is unreachable, contact us directly and we will help.

To exercise any right, write to privacy@smiledesignlab.com or, if you are signed in as an admin, use the in-product DSAR export at /admin/dsar. We respond within thirty (30) days.

9. Children's privacy

The platform is not directed to children. Practices may submit cases for pediatric patients; in that situation the parent or legal guardian has authorized the practice to share the data, and we process it under the practice's HIPAA authorization.

10. Changes to this notice

We will post the updated notice here and bump the effective date. For material changes we will also email account owners at least thirty (30) days before the new terms take effect.

11. Contact us

Questions, requests, and complaints can be sent to privacy@smiledesignlab.com. EU/UK users can also lodge a complaint with their local data protection authority.