Privacy Policy
Effective date: 28 August 2026
AMV Consulting LLC (“AMV”, “we”, “us”, or “our”), the developer and provider of the SmileInspector software platform (“SmileInspector”), respects the privacy of our customers, users, patients whose information is processed through our Services, and visitors to our websites.
This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information in connection with the SmileInspector website, software applications, web portal, APIs, cloud services, Doctor Viewer, Patient Viewer, treatment planning services, support services, and other products or services that link to this Privacy Policy (collectively, the “Services”).
Certain customer relationships may also be governed by a Software License and Services Agreement, Order, Business Associate Agreement (“BAA”), Data Processing Agreement (“DPA”), or other written agreement with AMV. Where such an agreement governs AMV’s processing of Customer Data and conflicts with this Privacy Policy, the applicable agreement will control to the extent of the conflict.
1. Who we are
The Services are provided by:
AMV Consulting LLC
19125 North Creek Parkway, Suite 120
Bothell, WA 98011
United States
SmileInspector website: smileinspector.io
Privacy inquiries: privacy@smileinspector.io
General support: support@smileinspector.io
2. Our role
AMV provides the SmileInspector software platform and related Services primarily to dentists, orthodontists, dental practices, dental laboratories, manufacturers, and other dental-industry organizations (“Customers”).
Our Customers determine which patient information is submitted to or processed through the Services and the purposes for which that information is processed.
When AMV processes patient or treatment information on behalf of a Customer, AMV generally acts as a service provider or data processor to that Customer. Where HIPAA applies, AMV may also act as a Business Associate pursuant to a BAA.
For personal information that AMV collects for its own business purposes, such as information about account administrators, prospective customers, website visitors, billing contacts, and individuals communicating directly with AMV, AMV generally acts as the controller or business responsible for that information.
3. Information we collect
The information we collect depends on how you interact with the Services.
A. Customer, account, and business information
We may collect information about Customers, Authorized Users, prospective customers, and other business contacts, including:
- name;
- business email address;
- telephone number;
- company, dental practice, or laboratory name;
- job title and professional role;
- account username and credentials;
- account and subscription information;
- communications with AMV;
- support requests;
- demo requests;
- marketing preferences; and
- other information provided to us in the course of our business relationship.
We may maintain this information in our customer relationship management systems, including HubSpot.
B. Billing and payment information
We use third-party payment processors, including Stripe, to process payments from Customers such as dental practices, orthodontists, and dental laboratories.
Payment card information provided through Stripe is processed by Stripe under its own applicable privacy and security practices. AMV may receive payment-related information such as billing contact information, transaction status, subscription information, payment identifiers, and related transaction records.
Patient payment information is not required to use SmileInspector’s treatment-planning Services.
C. Customer Data and Patient Data
Our Customers may upload, submit, transmit, create, or otherwise process information through SmileInspector (“Customer Data”).
Customer Data may include information relating to dental patients and treatment cases (“Patient Data”), including, depending on how the Customer uses the Services:
- patient or case identifiers;
- patient demographic information;
- dental scans and three-dimensional dental models;
- intraoral images and photographs;
- dental and orthodontic measurements;
- treatment prescriptions and clinical instructions;
- treatment plans;
- tooth positions and movements;
- treatment stages;
- dental appliance and aligner information;
- annotations, notes, and communications relating to treatment;
- treatment status and history; and
- other dental, health, or treatment-related information submitted by the Customer.
Patient Data may constitute health information, sensitive personal information, Protected Health Information (“PHI”), or special-category personal data under applicable law.
Customers are responsible for ensuring that they have an appropriate legal basis, authorization, consent, or other authority required to submit Patient Data to SmileInspector and instruct AMV to process that information.
D. Patient Viewer
A treating clinician, dental practice, laboratory, or other authorized Customer may choose to provide a patient with a read-only link that allows the patient to review a proposed treatment using the SmileInspector Patient Viewer.
Patients do not create SmileInspector accounts and are not asked by AMV to provide personal or clinical information through the Patient Viewer.
When a Patient Viewer link is accessed, however, our systems may automatically process limited technical information necessary to deliver and secure the Viewer, such as IP address, browser and device information, access time, security information, and system logs.
The Customer that provides the Patient Viewer link controls the underlying treatment information displayed through that link.
E. Technical and usage information
When the Services are accessed or used, we may automatically collect technical and operational information, including:
- IP address;
- browser and operating system;
- device type;
- application version;
- login and authentication events;
- features accessed;
- pages or screens viewed;
- dates and times of access;
- application activity;
- error and crash information;
- performance information;
- security events; and
- other diagnostic information.
We refer to information relating to the operation and use of the Services as “Usage Data.”
We use Usage Data to operate, maintain, secure, troubleshoot, support, analyze, and improve the Services.
F. Website information, cookies, and analytics
When you visit smileinspector.io or related public-facing websites, we may use cookies, pixels, local storage, analytics services, advertising technologies, and similar tools.
These technologies may collect information about your browser, device, IP address, referring website, pages visited, interaction with the Website, and advertising identifiers.
Our use of these technologies is further described in our Cookie Policy.
Advertising and marketing technologies used on our public website are not intended to receive Patient Data or clinical Customer Data.
4. How we use information
We may use personal information to:
- provide, operate, maintain, and administer the Services;
- create and manage Customer and Authorized User accounts;
- authenticate users and protect account security;
- process and display dental and orthodontic cases;
- enable collaboration among clinicians, laboratories, technicians, and other parties authorized by our Customers;
- provide Doctor Viewer and Patient Viewer functionality;
- provide treatment-planning, analysis, visualization, and other software functionality;
- process Customer payments and subscriptions;
- respond to support requests and communications;
- diagnose errors and improve system reliability and performance;
- maintain security and prevent unauthorized access, fraud, or abuse;
- communicate regarding accounts, Services, security incidents, product updates, and support;
- conduct analytics and improve our website and user experience;
- send marketing communications where permitted by applicable law;
- comply with legal, regulatory, and contractual obligations;
- establish, exercise, or defend legal rights; and
- develop and improve SmileInspector products and technologies as described below.
5. De-identified information and artificial intelligence
AMV develops and uses proprietary algorithms, artificial intelligence, machine learning, computer vision, and other automated technologies to provide and improve features relating to dental scans, dental analysis, treatment setup, treatment planning, positioning, staging, visualization, and other dental workflows.
Identifiable Patient Data
AMV does not use identifiable Patient Data or PHI to train generalized artificial intelligence or machine-learning models.
AMV does not send Customer Data or Patient Data to OpenAI, Anthropic, or other third-party general-purpose artificial-intelligence model providers for purposes of providing the Services or training their models.
Third-party artificial-intelligence providers are not permitted to use Customer Data processed through the SmileInspector Services to train their models.
De-identified information
AMV may create and use aggregated or de-identified information derived from use of the Services to develop, train, test, validate, evaluate, and improve SmileInspector algorithms, artificial-intelligence models, machine-learning systems, computer-vision technologies, products, and Services.
Before Patient Data is used for such generalized development or AI-training purposes, it will be de-identified in accordance with applicable law.
Where HIPAA applies, PHI used for these purposes will be de-identified in accordance with applicable HIPAA de-identification requirements.
Where European or United Kingdom data-protection law applies, information will only be treated as anonymous information if it has been rendered anonymous to the standard required by applicable law. Pseudonymized information that remains reasonably capable of being associated with an individual will continue to be treated as personal data.
AMV takes reasonable measures designed to prevent de-identified information from being associated with an identified individual and does not attempt to re-identify information that AMV has designated and uses as de-identified information.
De-identified information is not used to target advertising to patients.
Clinical decision-making
SmileInspector’s automated and AI-assisted features are designed to assist qualified dental professionals.
AMV does not independently diagnose patients or make final treatment decisions on behalf of a treating clinician. Final clinical decisions and responsibility for patient treatment remain with the appropriately qualified treating healthcare professional.
6. HIPAA and Protected Health Information
Some SmileInspector Customers are healthcare providers or other organizations subject to the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”).
Where AMV creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity or business associate, AMV will process that PHI in accordance with HIPAA and the applicable BAA.
As provided in the SmileInspector Software License and Services Agreement, a Customer that is subject to HIPAA and intends to upload or process PHI through the Services must execute an applicable BAA with AMV before doing so.
Where a BAA applies, AMV will use and disclose PHI only as permitted by the BAA or as otherwise required by applicable law.
This Privacy Policy is not a HIPAA Notice of Privacy Practices and does not replace the Notice of Privacy Practices provided by a dentist, orthodontist, dental practice, health plan, or other healthcare provider.
If you are a patient seeking access to, correction of, deletion of, or other rights concerning information maintained through SmileInspector by your treating provider, you should normally contact that provider directly. AMV will assist its Customer in responding to such requests as required by applicable law or the applicable BAA.
7. How we disclose information
We disclose information only as reasonably necessary for the purposes described in this Privacy Policy, at a Customer’s direction, or as otherwise permitted or required by law.
Customer-directed sharing
AMV supports collaboration among parties participating in dental treatment and manufacturing workflows.
At a Customer’s direction, Customer Data may be made available to authorized:
- dentists and orthodontists;
- dental practices;
- dental laboratories;
- technicians;
- treatment-planning personnel;
- supervisors;
- manufacturing providers;
- patients through read-only Patient Viewer links; and
- other persons or organizations selected or authorized by the Customer.
AMV does not independently determine which treatment participants a Customer chooses to authorize.
Service providers
We use service providers to operate our business and Services.
These may include providers of:
- cloud hosting and data storage;
- database and backup infrastructure;
- network and security services;
- authentication;
- communications;
- technical support;
- software monitoring;
- analytics;
- payment processing;
- customer relationship management; and
- other business and technical services.
Our principal cloud infrastructure is provided through Amazon Web Services (“AWS”).
Stripe is used primarily for Customer billing and payment processing.
HubSpot is used primarily for sales, customer relationship management, and business communications.
Stripe and HubSpot are not used by SmileInspector software as repositories for Patient Data used in treatment planning.
Where required by law or contract, service providers that process personal information for AMV are subject to contractual restrictions regarding confidentiality, security, and permitted use of that information.
Where a service provider processes PHI on behalf of AMV and HIPAA requires a BAA, AMV will enter into an appropriate BAA with that provider.
Legal and safety requirements
We may disclose information if we reasonably believe disclosure is necessary to:
- comply with a law, regulation, subpoena, court order, or other legal process;
- respond to a lawful governmental request;
- investigate fraud, abuse, or security incidents;
- enforce our agreements;
- protect the security or integrity of the Services;
- protect the rights, safety, or property of AMV, our Customers, users, patients, or others; or
- establish, exercise, or defend legal claims.
Business transactions
Information may be disclosed or transferred as part of a merger, acquisition, financing, corporate reorganization, sale of assets, bankruptcy, or similar business transaction, subject to applicable contractual and legal protections.
8. We do not sell Patient Data
AMV does not sell Patient Data or PHI.
AMV does not disclose Patient Data or PHI to advertising companies, data brokers, or other third parties for their own advertising or marketing purposes.
Our public website may use analytics and advertising technologies. Some privacy laws define certain disclosures of website identifiers or online activity to advertising providers as a “sale,” “sharing,” or use for “targeted advertising” even where no money is exchanged.
Where applicable law provides an opt-out right for such website activity, users may exercise that right through our cookie preference controls, legally recognized browser preference signals where applicable, or by contacting us.
Advertising technologies used on the public SmileInspector website are not intended to collect Patient Data or PHI.
9. Marketing
We may send information about SmileInspector products, features, events, educational materials, promotions, or related services to business contacts where permitted by applicable law.
You may unsubscribe from promotional email communications by following the unsubscribe instructions contained in those messages.
Opting out of promotional communications does not prevent us from sending necessary account, transaction, security, support, regulatory, or service-related communications.
10. Data retention and deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, to provide the Services, comply with applicable agreements, meet legal and regulatory obligations, resolve disputes, maintain security, and enforce our rights.
Retention of Customer Data may depend on the Customer’s subscription, configuration, Order, BAA, DPA, or other applicable agreement.
When Customer Data is deleted through the Services or pursuant to a Customer request, AMV deletes the applicable data from its active production systems in accordance with its normal deletion procedures.
Copies or fragments of deleted data may remain temporarily in encrypted database backups, disaster-recovery systems, system snapshots, security records, or similar backup systems until those backups expire or are overwritten in accordance with AMV’s normal backup-retention processes.
Backup copies are maintained for resilience and disaster-recovery purposes and are not treated as active production records.
Certain records may also be retained when required by applicable law, to establish or defend legal rights, maintain security and audit records, or satisfy contractual obligations.
Properly de-identified or aggregated information may be retained and used for the purposes described in this Privacy Policy after the underlying identifiable Customer Data has been deleted.
11. Security
AMV maintains administrative, technical, physical, and organizational safeguards designed to protect personal information and Customer Data against unauthorized access, use, disclosure, alteration, loss, or destruction.
Depending on the systems and information involved, our safeguards may include:
- encryption;
- access controls;
- authentication controls;
- least-privilege access;
- network and infrastructure security;
- logging and monitoring;
- backup and disaster-recovery procedures;
- vulnerability management;
- confidentiality obligations; and
- security policies and procedures.
Access to Patient Data is limited to personnel and service providers with an authorized business need for access.
No electronic transmission, storage system, or security measure can guarantee absolute security. Customers and Authorized Users are also responsible for maintaining the confidentiality of their credentials and appropriately securing devices used to access SmileInspector.
12. International customers and data transfers
AMV provides the SmileInspector Services to Customers in the United States and other countries.
Personal information may therefore be transferred to, stored in, or processed in the United States and other countries in which AMV or its service providers operate.
Where applicable law requires safeguards for international transfers of personal data, we use appropriate transfer mechanisms, which may include adequacy decisions, the European Commission’s Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum or other approved mechanisms, or another legally recognized transfer mechanism.
A Customer requiring a Data Processing Agreement or applicable international data-transfer provisions may contact AMV.
13. EEA, United Kingdom, and other international privacy rights
Where the European Union General Data Protection Regulation (“GDPR”), United Kingdom GDPR, or similar data-protection law applies, AMV’s role depends on the processing activity.
For Patient Data and other Customer Data that we process solely on a Customer’s instructions, the Customer generally acts as the controller and AMV acts as a processor.
The Customer is responsible for determining the lawful basis for processing Patient Data, including any basis required for processing health information or other special-category data. AMV processes such information pursuant to the Customer’s documented instructions and applicable DPA.
Where AMV acts as a controller, including with respect to our own Customers, account administrators, business contacts, website visitors, and marketing activities, our legal bases for processing may include:
- performance of or steps necessary to enter into a contract;
- our legitimate interests in operating, protecting, developing, and promoting our business and Services;
- compliance with legal obligations; and
- consent, where applicable.
Depending on applicable law, individuals may have rights to:
- access personal data;
- correct inaccurate personal data;
- request deletion;
- restrict certain processing;
- object to certain processing;
- receive certain personal data in portable form;
- withdraw consent where processing relies upon consent; and
- lodge a complaint with the applicable data protection authority.
Where AMV is acting solely as a processor for a Customer, individuals should ordinarily exercise these rights through that Customer.
Where AMV is the controller, requests may be submitted to privacy@smileinspector.io.
14. U.S. state privacy rights
Residents of certain U.S. states may have additional rights regarding personal information under applicable state privacy laws.
Depending on the applicable law, these rights may include rights to:
- confirm whether personal information is being processed;
- access personal information;
- correct personal information;
- delete certain personal information;
- obtain a portable copy of certain personal information;
- obtain information about categories of information collected or disclosed;
- opt out of certain sales, sharing, or targeted advertising;
- limit certain uses of sensitive personal information;
- use an authorized agent to make certain requests; and
- appeal certain decisions regarding privacy requests.
These rights are subject to exemptions, exceptions, and limitations under applicable law.
Certain Patient Data may instead be governed by HIPAA, state medical-privacy laws, or other specialized healthcare privacy laws.
AMV does not unlawfully discriminate against individuals for exercising applicable privacy rights.
Requests regarding personal information for which AMV acts as a controller may be submitted to privacy@smileinspector.io.
Patients seeking rights regarding treatment information controlled by their treating dentist, orthodontist, or other provider should generally contact that provider directly.
15. Global Privacy Control and cookies
Where required by applicable law, we honor legally recognized browser-based opt-out preference signals, including Global Privacy Control, for activities within the scope of those signals.
Our Cookie Policy provides additional information about website cookies, analytics, advertising technologies, consent preferences, and how those preferences may be changed.
16. Children and minor patients
SmileInspector professional accounts are intended for dentists, orthodontists, dental laboratories, other dental-industry organizations, and their authorized adult users.
Children are not permitted to independently create professional SmileInspector accounts.
SmileInspector is, however, used in orthodontic and dental treatment, and our Customers may use the Services to process Patient Data concerning children and adolescents.
Such Patient Data is provided by or on behalf of a treating clinician, dental practice, laboratory, or other Customer. AMV processes that information on behalf of the Customer pursuant to applicable agreements and law.
AMV does not solicit personal information directly from minor patients through the Patient Viewer, and Patient Data concerning minors is not used for advertising.
17. Third-party websites and integrations
The Services may link to or integrate with third-party websites, scanners, software, laboratory systems, manufacturing systems, applications, or other services.
Information submitted directly to an independent third party is governed by that third party’s privacy practices.
AMV is not responsible for the privacy or security practices of third parties that are not acting as AMV’s service providers or processors.
18. Privacy requests
To submit a privacy request regarding personal information controlled directly by AMV, contact:
We may request information reasonably necessary to verify your identity and authority to make the request.
Where a request relates to Customer Data that AMV processes solely on behalf of a Customer, we may refer the request to the applicable Customer or assist the Customer in responding.
We will respond to valid requests within the period required by applicable law.
19. Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our Services, technologies, business practices, or legal requirements.
When we update this Privacy Policy, we will revise the Effective Date shown above.
If changes are material, we may provide additional notice through the Services, on our website, by email, or through another appropriate method.
20. Contact us
Questions regarding this Privacy Policy or AMV’s privacy practices may be directed to:
AMV Consulting LLC
19125 North Creek Parkway, Suite 120
Bothell, WA 98011
United States
Privacy: privacy@smileinspector.io
Support: support@smileinspector.io