Privacy policy

AURRA PRIVACY POLICY


Effective Date: May 20, 2026


Aurra (“Aurra”, “we”, “our”, or “us”) is committed to protecting the privacy, confidentiality, and security of information submitted through the Aurra platform (“Platform”).


This Privacy Policy explains how Aurra collects, uses, stores, processes, discloses, and protects information in connection with the use of the Platform and related services.


By accessing or using the Platform, you acknowledge and agree to the practices described in this Privacy Policy.



1. SCOPE OF THIS POLICY


This Privacy Policy applies to:


  • Licensed dental professionals and clinics using the Platform;
  • Information submitted in connection with treatment cases;
  • Users accessing Aurra websites, portals, and digital services.


The Platform is intended solely for professional dental use and is not directed toward the general public or minors.



2. INFORMATION WE COLLECT


Aurra may collect and process the following categories of information:


A. Clinical & Patient Information


Submitted by treating providers, including:


  • Intraoral scans;
  • Photographs;
  • Radiographs/X-rays;
  • Treatment prescriptions;
  • Clinical notes;
  • Patient demographic information;
  • Patient identifiers where required for treatment processing.



B. Account Information


Information relating to doctors, clinics, and authorized users, including:


  • Name;
  • Clinic name;
  • Email address;
  • Phone number;
  • Billing information;
  • Login credentials.



C. Technical Information


We may automatically collect certain technical information including:


  • IP address;
  • Browser type;
  • Device information;
  • Operating system;
  • Usage activity;
  • Login timestamps;
  • Platform analytics data.



3. PURPOSE OF COLLECTION


Aurra collects and uses information solely for legitimate business and operational purposes, including:


  • Case intake and processing;
  • Treatment visualization and workflow management;
  • Manufacturing aligners and related appliances;
  • Providing customer support;
  • Account management and billing;
  • Platform maintenance and security;
  • Improving products, workflows, and system performance;
  • Regulatory compliance.


Aurra does not sell personal health information or patient data.



4. CLINICAL RESPONSIBILITY


The treating Doctor remains solely responsible for:


  • Obtaining all required patient consents;
  • Ensuring lawful submission of patient information;
  • Compliance with applicable healthcare privacy laws and professional obligations.


Aurra functions solely as a manufacturing and digital workflow platform and does not establish doctor-patient relationships.



5. DE-IDENTIFICATION & CASE NUMBERING


Where operationally appropriate, Aurra may:


  • Remove certain patient identifiers;
  • Assign anonymized case numbers;
  • Use de-identified information for manufacturing, analytics, quality assurance, and product improvement purposes.


Aurra takes commercially reasonable steps to minimize unnecessary disclosure of identifiable information.



6. CROSS-BORDER DATA TRANSFERS


The Doctor acknowledges and agrees that information submitted through the Platform may be processed, transferred, or stored outside the province, state, or country in which it originated.


This may include transfers to:


  • Manufacturing facilities;
  • Cloud infrastructure providers;
  • Technology vendors;
  • Service providers supporting Platform operations.


Where possible, case information may be anonymized or de-identified prior to international processing.


By using the Platform, the User consents to such transfers where permitted by law.



7. THIRD-PARTY SERVICE PROVIDERS


Aurra may engage trusted third-party providers to assist with:


  • Cloud hosting;
  • Payment processing;
  • Manufacturing;
  • Technical support;
  • Analytics;
  • Security monitoring.


These providers may have access to information only to the extent necessary to perform services on Aurra’s behalf and are expected to maintain appropriate confidentiality and security safeguards.


Payment information is processed by third-party payment providers. Aurra does not store full payment card details.



8. DATA SECURITY


Aurra implements commercially reasonable administrative, technical, and organizational safeguards designed to protect information against:


  • Unauthorized access;
  • Loss;
  • Theft;
  • Misuse;
  • Disclosure;
  • Alteration;
  • Destruction.


Security measures may include:


  • Restricted access controls;
  • Encryption where appropriate;
  • Secure servers;
  • Authentication protocols;
  • Monitoring systems.


Despite these measures, no method of electronic transmission or storage can be guaranteed completely secure.