Privacy Policy
Last updated 06/04/2026SmileMatrix AI Privacy Policy
Effective Date: 06/04/2026
1. INTRODUCTION
Welcome to SmileMatrix AI (“SmileMatrix,” “Company,” “we,” “our,” or “us”).
SmileMatrix AI is committed to protecting the privacy, confidentiality, and security of the information entrusted to us by our users. This Privacy Policy describes how we collect, use, disclose, store, transfer, retain, and otherwise process information obtained through our website, cloud-based software platform, artificial intelligence services, downloadable design files, customer support services, application programming interfaces (APIs), integrations, and any related products or services (collectively, the “Services”).
SmileMatrix AI develops artificial intelligence software intended to assist qualified dental professionals and dental laboratories with computer-aided dental design workflows. Our software is intended solely as a professional software tool and is not intended to replace professional clinical judgment.
Your privacy is important to us. We believe transparency builds trust, and this Privacy Policy is intended to explain, in clear language, the categories of information we collect, how we use that information, the circumstances under which it may be disclosed, and the choices available to you.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.
2. SCOPE
This Privacy Policy applies to:
visitors to our website;
registered users;
subscribers;
dental professionals;
dental laboratories;
educational institutions;
authorized employees;
contractors;
API users;
beta testers;
customer support interactions;
mobile applications;
future SmileMatrix products unless expressly excluded.
This Privacy Policy applies regardless of the device used to access the Services, including desktop computers, tablets, mobile phones, scanners, intraoral scanners, laboratory workstations, and integrated software platforms.
3. DEFINITIONS
For purposes of this Privacy Policy:
“Account” means a registered SmileMatrix user account.
“AI Output” means any digital design, STL file, restoration proposal, smile design, wax-up, restoration anatomy, or other computer-generated output produced by the Services.
“Clinical Data” means any digital dental information uploaded or generated in connection with patient treatment, including intraoral scans, STL files, CBCT scans, photographs, treatment plans, annotations, prescriptions, implant planning data, occlusal information, and related metadata.
“Customer” means the individual or entity that registers for or purchases access to the Services.
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable person.
“Protected Health Information” (“PHI”) has the meaning assigned under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended.
“Services” means all SmileMatrix products, software, websites, cloud services, APIs, downloadable software, mobile applications, AI tools, customer support services, and related offerings.
“User” means any individual accessing or using the Services.
4. INFORMATION WE COLLECT
The information collected depends upon how the Services are used.
4.1 Account Information
When you create an account, we may collect:
name;
email address;
business name;
professional title;
dental license information;
laboratory information;
billing address;
country;
phone number;
login credentials;
authentication information;
subscription details.
4.2 Billing Information
When you purchase downloadable STL files or subscribe to paid Services, we may collect:
billing name;
payment method;
billing address;
tax information;
invoices;
payment history;
transaction identifiers.
SmileMatrix does not intentionally store complete payment card numbers where payment processing is performed by third-party payment processors.
4.3 Clinical Data
Users may upload clinical information necessary to generate AI-assisted dental designs.
Examples include:
intraoral scans;
STL files;
CBCT images;
facial photographs;
smile photographs;
implant planning files;
restoration designs;
wax-ups;
occlusal registrations;
digital impressions;
annotations;
tooth selections;
design preferences;
restoration libraries;
treatment planning information.
Users are solely responsible for ensuring they possess all necessary legal authority to upload such information.
4.4 Device Information
We may automatically collect:
IP address;
browser type;
operating system;
language settings;
referring URLs;
device identifiers;
screen resolution;
software version;
hardware identifiers;
network information;
crash diagnostics.
4.5 Usage Information
We may collect information regarding how the Services are used, including:
login frequency;
pages visited;
tools utilized;
time spent within the platform;
downloaded STL files;
subscription activity;
support interactions;
search queries;
software performance metrics.
4.6 Cookies and Similar Technologies
SmileMatrix may use cookies, web beacons, local storage, session identifiers, analytics technologies, pixels, SDKs, and similar technologies to:
authenticate users;
maintain sessions;
improve security;
remember preferences;
analyze performance;
detect fraud;
improve usability.
Users may modify browser settings to limit certain cookies; however, doing so may impair portions of the Services.
5. INFORMATION PROVIDED BY THIRD PARTIES
We may receive information from third parties, including:
payment processors;
authentication providers;
cloud hosting providers;
analytics providers;
fraud prevention services;
identity verification services;
customer support platforms;
marketing partners;
authorized integrations.
Such information is processed in accordance with this Privacy Policy and applicable law.
6. ARTIFICIAL INTELLIGENCE PROCESSING
SmileMatrix uses artificial intelligence, machine learning, computer vision, and related computational technologies to generate AI-assisted dental design outputs.
Uploaded files may be processed through automated systems for purposes including:
segmentation;
tooth recognition;
anatomy generation;
restoration proposal generation;
digital wax-ups;
margin identification;
morphology prediction;
visualization;
software optimization.
AI-generated outputs are software-generated recommendations intended solely to assist qualified professionals.
They are not medical advice, do not constitute treatment recommendations, and must be independently reviewed and approved by a qualified dental professional before any manufacturing, fabrication, or patient use.
The treating clinician remains solely responsible for all diagnostic, treatment planning, restorative, surgical, prosthetic, and clinical decisions.
7. HOW WE USE INFORMATION
SmileMatrix AI processes information only for legitimate business, operational, contractual, security, research, regulatory, and legal purposes consistent with this Privacy Policy and applicable law.
Depending upon the nature of your relationship with SmileMatrix, we may use collected information to:
create and administer user accounts;
authenticate users and maintain account security;
provide access to the Services;
process uploaded dental files;
generate AI-assisted dental designs;
enable visualization tools and downloadable STL files;
process subscription fees and individual STL purchases;
provide customer support;
respond to technical questions;
troubleshoot software issues;
monitor platform stability;
detect software defects;
improve platform performance;
prevent fraud and unauthorized access;
comply with legal obligations;
protect the rights, property, safety, and security of SmileMatrix, its users, and third parties;
develop new software features;
maintain audit logs;
enforce contractual agreements;
communicate updates, security notices, invoices, and administrative information.
Where permitted by applicable law and subject to appropriate safeguards, SmileMatrix may also use aggregated or de-identified information to evaluate system performance, improve AI algorithms, measure software accuracy, conduct internal research and quality assurance, develop new features, and improve user experience. SmileMatrix will not intentionally use identifiable patient information for these purposes without an appropriate legal basis or required authorization.
8. LEGAL BASIS FOR PROCESSING
Where the General Data Protection Regulation (“GDPR”), UK GDPR, or similar laws apply, SmileMatrix processes personal information only where a lawful basis exists.
These lawful bases may include:
Performance of a Contract
Processing necessary to provide the Services requested by the user, including creation of accounts, AI processing, customer support, billing, and downloadable design files.
Legitimate Interests
Processing reasonably necessary to:
improve software;
detect fraud;
maintain cybersecurity;
develop new functionality;
enforce contractual rights;
conduct internal analytics;
ensure platform reliability;
protect intellectual property.
SmileMatrix balances these legitimate interests against users’ privacy rights before relying on this legal basis.
Consent
Where required by law, SmileMatrix will obtain consent before processing information for specific purposes such as certain marketing communications or optional cookies. Consent may generally be withdrawn at any time, although withdrawal does not affect processing performed before withdrawal.
Legal Obligations
Processing necessary to comply with applicable laws, court orders, governmental requests, tax obligations, regulatory requirements, and lawful investigations.
9. HIPAA CONSIDERATIONS
SmileMatrix recognizes that certain uploaded information may relate to healthcare treatment.
SmileMatrix is designed primarily as a software platform used by licensed dental professionals and dental laboratories.
Unless SmileMatrix has expressly entered into a written Business Associate Agreement (“BAA”) with a covered entity, SmileMatrix does not represent that it is acting as a HIPAA Business Associate.
Accordingly:
Users remain solely responsible for determining whether uploaded information constitutes Protected Health Information.
Users remain responsible for obtaining any required patient authorizations or consents.
Users are responsible for complying with HIPAA, HITECH, state privacy laws, professional licensing requirements, and all other applicable healthcare regulations.
Users should upload only the minimum information reasonably necessary to accomplish the intended clinical purpose.
Users are encouraged, where practical, to de-identify patient information before uploading files.
Nothing contained in this Privacy Policy modifies or replaces any separately executed Business Associate Agreement.
10. AI MODEL IMPROVEMENT
SmileMatrix continuously improves its software through engineering, validation, testing, quality assurance, and machine learning development.
Subject to applicable law and contractual commitments, SmileMatrix may use:
aggregated information;
anonymized information;
de-identified information;
statistical information;
software performance metrics;
diagnostic information;
usage analytics
for purposes including:
improving AI accuracy;
reducing software errors;
optimizing restoration anatomy generation;
improving segmentation algorithms;
improving restoration morphology prediction;
evaluating software performance;
improving computational efficiency;
developing future features.
SmileMatrix will not intentionally disclose identifiable patient information publicly or use identifiable patient information to train publicly available AI systems without an appropriate legal basis or applicable authorization.
11. DISCLOSURE OF INFORMATION
SmileMatrix does not sell personal information in exchange for monetary consideration unless expressly disclosed and permitted by applicable law.
SmileMatrix may disclose information under the following circumstances.
Service Providers
Information may be shared with vendors providing services including:
cloud hosting;
payment processing;
authentication;
email delivery;
analytics;
customer support;
security monitoring;
infrastructure management.
These providers are contractually required to protect information consistent with applicable law.
Corporate Transactions
If SmileMatrix participates in:
merger;
acquisition;
financing;
asset sale;
bankruptcy;
restructuring;
information may be transferred as part of the transaction, subject to applicable confidentiality obligations.
Legal Requirements
SmileMatrix may disclose information where reasonably necessary to:
comply with law;
respond to subpoenas;
comply with court orders;
cooperate with regulators;
protect public safety;
investigate fraud;
enforce contractual rights;
protect SmileMatrix intellectual property;
prevent illegal activity.
Protection of Rights
SmileMatrix may disclose information when reasonably necessary to protect:
users;
patients;
employees;
contractors;
investors;
business partners;
the public;
SmileMatrix property;
SmileMatrix software;
SmileMatrix intellectual property.
12. INTERNATIONAL DATA TRANSFERS
SmileMatrix may process information in countries other than the country where it was originally collected.
Where required by applicable law, SmileMatrix will implement appropriate safeguards for international transfers, which may include:
Standard Contractual Clauses;
adequacy decisions;
contractual safeguards;
technical security controls;
organizational safeguards.
Users acknowledge that information transmitted electronically across international networks may be processed in multiple jurisdictions.
13. DATA SECURITY
Protecting information is one of SmileMatrix’s highest priorities.
SmileMatrix employs commercially reasonable administrative, organizational, technical, and physical safeguards designed to protect information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Security measures may include:
encryption in transit using industry-standard protocols;
encryption at rest where implemented;
multi-factor authentication for administrative access;
role-based access controls;
least-privilege access principles;
audit logging;
intrusion detection;
vulnerability management;
software patch management;
network monitoring;
penetration testing where appropriate;
disaster recovery planning;
backup procedures;
employee confidentiality obligations;
vendor security assessments.
Despite these safeguards, no method of electronic transmission, cloud storage, or computer security is completely secure. Accordingly, SmileMatrix cannot and does not guarantee absolute security.
Users are responsible for maintaining the confidentiality of their account credentials and for promptly notifying SmileMatrix of any suspected unauthorized access.
14. DATA RETENTION
SmileMatrix retains information only for as long as reasonably necessary to:
provide the Services;
fulfill contractual obligations;
comply with applicable law;
maintain security;
resolve disputes;
enforce agreements;
satisfy tax and accounting obligations;
preserve backup integrity.
Retention periods vary depending upon the type of information involved.
Factors considered include:
legal requirements;
contractual obligations;
user requests;
security needs;
fraud prevention;
litigation holds;
regulatory obligations.
Following expiration of applicable retention periods, SmileMatrix may securely delete, anonymize, aggregate, or otherwise render information incapable of identifying an individual, except where continued retention is required or permitted by law.
15. COOKIES AND SIMILAR TECHNOLOGIES
SmileMatrix AI uses cookies, software development kits (“SDKs”), local storage objects, web beacons, pixels, session identifiers, log files, and similar technologies (collectively, “Cookies”) to operate, secure, analyze, and improve the Services.
Cookies may be categorized as follows:
15.1 Essential Cookies
Essential Cookies are required for the operation of the Services and cannot generally be disabled. These Cookies enable functions such as:
user authentication;
secure login sessions;
fraud prevention;
load balancing;
security monitoring;
account preferences;
navigation functionality.
Disabling Essential Cookies may prevent portions of the Services from functioning properly.
15.2 Functional Cookies
Functional Cookies improve usability by remembering preferences such as:
preferred language;
user interface settings;
display preferences;
dashboard configuration;
recently accessed projects.
15.3 Analytics Cookies
SmileMatrix may use analytics technologies to understand how users interact with the Services.
Analytics information may include:
page visits;
feature utilization;
software performance;
browser characteristics;
clickstream data;
navigation paths;
session duration;
software errors;
feature adoption.
Analytics information is used solely for legitimate business purposes including improving software performance, user experience, and platform reliability.
15.4 Marketing Cookies
Where applicable and permitted by law, SmileMatrix may use marketing technologies to:
measure advertising effectiveness;
understand referral sources;
improve marketing campaigns;
measure conversion performance.
Users may control certain Cookies through browser settings or available consent management tools where required by applicable law.
16. USER RIGHTS
Depending upon applicable law and the user’s jurisdiction, individuals may possess certain rights regarding their personal information.
These rights may include:
Right to Access
Users may request confirmation regarding whether SmileMatrix processes their personal information and may request access to certain information maintained by SmileMatrix.
Right to Correction
Users may request correction of inaccurate or incomplete personal information.
Right to Deletion
Subject to legal exceptions, users may request deletion of personal information maintained by SmileMatrix.
SmileMatrix may retain information where necessary to:
comply with law;
complete transactions;
prevent fraud;
resolve disputes;
enforce agreements;
maintain security;
preserve backup integrity.
Right to Data Portability
Where applicable, users may request a copy of certain personal information in a structured, commonly used, machine-readable format.
Right to Restrict Processing
Users may request limitation of processing under circumstances recognized by applicable law.
Right to Object
Where processing is based upon legitimate interests, users may object to such processing subject to applicable legal limitations.
Right to Withdraw Consent
Where processing is based upon consent, users may withdraw consent at any time.
Withdrawal of consent shall not affect the lawfulness of processing occurring prior to withdrawal.
Identity Verification
Before fulfilling privacy requests, SmileMatrix may verify the identity of the requesting individual to protect against unauthorized disclosure.
SmileMatrix may decline requests that cannot reasonably be verified or that are otherwise exempt under applicable law.
17. CALIFORNIA PRIVACY RIGHTS
For California residents, SmileMatrix intends to comply with applicable provisions of the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), to the extent those laws apply.
California residents may possess rights including:
the right to know;
the right to access;
the right to correct;
the right to delete;
the right to limit certain uses of sensitive personal information where applicable;
the right to opt out of certain sales or sharing where applicable;
the right not to be discriminated against for exercising privacy rights.
SmileMatrix does not intentionally discriminate against individuals for exercising applicable privacy rights.
18. OTHER U.S. STATE PRIVACY LAWS
SmileMatrix intends to comply with applicable state privacy laws, including, where applicable:
Virginia Consumer Data Protection Act (VCDPA);
Colorado Privacy Act (CPA);
Connecticut Data Privacy Act (CTDPA);
Utah Consumer Privacy Act (UCPA);
and other applicable state privacy legislation.
Where these laws apply, SmileMatrix will honor legally required privacy rights consistent with applicable statutory requirements.
19. CHILDREN’S PRIVACY
The Services are designed primarily for licensed dental professionals and dental laboratories.
SmileMatrix does not knowingly market the Services directly to children under the age of thirteen (13).
If SmileMatrix becomes aware that personal information has been collected directly from a child in violation of applicable law, SmileMatrix will take reasonable steps to delete such information.
Nothing in this section prohibits licensed healthcare professionals from using the Services in connection with lawful treatment of pediatric patients where permitted by applicable law.
20. MARKETING COMMUNICATIONS
SmileMatrix may send administrative communications regarding:
invoices;
subscriptions;
software updates;
security notices;
maintenance;
product changes;
customer support.
Where legally permitted, SmileMatrix may also send promotional communications regarding:
new software features;
webinars;
educational materials;
conferences;
promotions;
new AI capabilities.
Users may opt out of promotional communications by following unsubscribe instructions or contacting SmileMatrix.
Administrative communications necessary to provide the Services may continue regardless of marketing preferences.
21. AUTOMATED PROCESSING
SmileMatrix uses automated computational systems, including artificial intelligence, machine learning, computer vision, and algorithmic processing, to generate dental design recommendations.
Users acknowledge that:
AI-generated outputs are computational predictions;
outputs may contain inaccuracies;
outputs may require modification;
outputs are intended solely as software-assisted design tools.
SmileMatrix does not guarantee that automated outputs are clinically appropriate, manufacturable, diagnostically accurate, or suitable for any individual patient.
Qualified dental professionals remain solely responsible for:
diagnosis;
treatment planning;
restoration approval;
occlusion;
contacts;
margins;
esthetics;
fit;
patient safety;
regulatory compliance.
22. THIRD-PARTY WEBSITES
The Services may contain links to third-party websites, integrations, software platforms, payment processors, laboratories, educational resources, or other external services.
SmileMatrix is not responsible for the privacy practices, security, content, or policies of third parties.
Users should review the privacy policies of third-party services independently.
23. CHANGES TO THIS PRIVACY POLICY
SmileMatrix may revise this Privacy Policy periodically to reflect:
legal developments;
technological changes;
software enhancements;
business operations;
regulatory requirements;
security practices.
Updated versions will become effective upon publication or as otherwise required by applicable law.
Where legally required, SmileMatrix will provide additional notice regarding material changes.
Continued use of the Services following the effective date of revised policies constitutes acceptance of the revised Privacy Policy to the extent permitted by law.
24. FLORIDA PRIVACY RIGHTS
SmileMatrix AI is headquartered in the State of Florida and endeavors to comply with all applicable Florida privacy and data protection laws, including, where applicable, the Florida Digital Bill of Rights, the Florida Information Protection Act of 2014 (“FIPA”), and other applicable Florida statutes governing the collection, use, disclosure, storage, and protection of personal information.
Where applicable, Florida residents may have rights regarding the collection and processing of their personal information under Florida law. SmileMatrix AI will honor such rights to the extent required by applicable law, including rights relating to access, correction, deletion, and other legally recognized consumer protections.
SmileMatrix AI maintains commercially reasonable administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, acquisition, disclosure, alteration, or destruction. In the event of a security incident involving personal information, SmileMatrix AI will investigate the incident and provide notifications required under applicable law, including the Florida Information Protection Act where applicable.
Nothing contained in this Privacy Policy shall be interpreted as creating rights beyond those provided under applicable law or limiting any rights or obligations established by applicable federal or state statutes.
25. CHANGES TO THIS PRIVACY POLICY
SmileMatrix AI reserves the right to modify, amend, supplement, or replace this Privacy Policy at any time to reflect changes in applicable law, regulatory guidance, technological developments, security practices, business operations, or the Services.
Updated versions of this Privacy Policy will become effective upon posting or on the effective date identified in the revised policy, unless a different effective date is required by law.
Where required by applicable law, SmileMatrix AI will provide additional notice regarding material changes before such changes become effective.
Continued access to or use of the Services following the effective date of an updated Privacy Policy constitutes acceptance of the revised Privacy Policy to the maximum extent permitted by applicable law.
26. CONTACT INFORMATION
Questions regarding this Privacy Policy, privacy practices, security matters, data requests, or regulatory compliance may be directed to:
Privacy Officer
Fady ShaabanEmail: fs@smilematrix.ai
Mailing Address: 1120 N Olive Ave, West Palm Beach, FL 33401
Data Subject Requests: executive.office@smilematrix.ai
If you believe your privacy rights have been violated, you may contact SmileMatrix AI using the information above. Where applicable law provides additional rights, you may also submit complaints to the appropriate governmental authority or data protection regulator.
27. GOVERNING LAW
Except where superseded by mandatory privacy legislation, this Privacy Policy shall be governed by and construed in accordance with the laws of the State of Florida, United States, without regard to its conflict of law principles.
Any dispute arising from or relating to this Privacy Policy shall be resolved in accordance with the dispute resolution provisions contained within the SmileMatrix AI Terms of Service, except where applicable law provides otherwise.
28. ENTIRE PRIVACY POLICY
This Privacy Policy constitutes the complete statement of SmileMatrix AI’s privacy practices relating to the Services and supersedes all prior privacy statements, policies, and representations relating to the collection, use, disclosure, storage, processing, retention, and protection of personal information.
If any provision of this Privacy Policy is determined by a court of competent jurisdiction to be invalid, unlawful, or unenforceable, such provision shall be interpreted to the maximum extent permitted by law to reflect its original intent, and the remaining provisions shall remain in full force and effect.
Failure by SmileMatrix AI to enforce any provision of this Privacy Policy shall not constitute a waiver of any right or provision.
The section headings contained herein are for convenience only and shall not affect the interpretation of this Privacy Policy.
SmileMatrix AI intends for this Privacy Policy to be interpreted in a manner consistent with applicable United States federal law, the laws of the State of Florida, the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other applicable privacy and data protection laws to the extent they apply to the Services and the processing activities of SmileMatrix AI.