Privacy Policy

Last Updated: July 23, 2026

At Molaris AI, we take privacy and data protection seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard personal and clinical information when you use our Services.

1. Introduction and Scope

This Privacy Policy explains how Molaris AI (“Molaris AI,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you visit our websites, request a demonstration, or use our products and services, including the Clear Path operations platform and Orovia (collectively, the “Services”).

This Policy applies to information about website visitors, prospective customers, and authorized users of the Services. It does not govern our handling of information that a customer (for example, a dental laboratory or practice) submits to the Services about its own patients or personnel; that information is governed by our agreement with that customer and by Section 2 below.

By using our Services, you acknowledge that you have read and understood this Policy. Where required by law, we rely on the legal bases described in Section 6 rather than consent alone.

2. Our Role: Controller and Processor

Our privacy responsibilities depend on the context in which we handle data:

  • As a controller / covered-entity-facing business: For information we collect directly about website visitors, prospects, and account administrators (such as names, business contact details, and usage analytics), Molaris AI determines the purposes and means of processing and acts as the data controller.
  • As a processor / business associate: For case data, scans, prescriptions, and any Protected Health Information (PHI) that a customer submits to the Services, the customer is the controller and Molaris AI processes that data only on the customer’s documented instructions, under a Data Processing Agreement (DPA) and, where applicable, a HIPAA Business Associate Agreement (BAA). See Sections 5 and 10.

3. Information We Collect

Information You Provide

  • Account and profile information (name, work email, role, organization)
  • Demo requests and sales inquiries, and the contents of your communications with us
  • Case data, prescriptions, and clinical inputs you submit into the Services
  • Billing and payment information (processed through our payment providers)
  • Support requests, feedback, and survey responses

Clinical and Case Data

The Services are designed to process dental case data, which may include intraoral scans, imaging, treatment prescriptions, and related clinical parameters. Where this data constitutes PHI or special category data, it is handled under the safeguards described in Sections 6, 9, and 10 and only as instructed by the responsible customer.

Automatically Collected Information

  • Device and connection data (IP address, browser, operating system, device identifiers)
  • Usage data (features accessed, actions taken, timestamps, session duration)
  • Log files, diagnostics, and performance and error telemetry
  • Cookies and similar technologies (see Section 15)

Information From Third Parties

We may receive information from your organization’s administrators, from identity and single sign-on providers you authorize, from payment processors, and from analytics and business data providers, consistent with their terms and applicable law.

4. How We Use Information

We use information for the following purposes:

  • Provide, operate, secure, and maintain the Services
  • Authenticate users and administer accounts and access controls
  • Process transactions, manage billing, and prevent fraud
  • Provide customer support and respond to inquiries
  • Monitor, troubleshoot, and improve reliability and performance
  • Develop new features and improve existing ones (see Section 5)
  • Send service, security, and administrative communications
  • Send marketing communications where permitted, with an opt-out
  • Comply with legal obligations and enforce our agreements

5. Artificial Intelligence and Machine Learning

Our Services use machine learning models to process dental case data. Our commitments regarding model development are:

  • We do notuse customer PHI or identifiable clinical case data to train or improve models that are made available to other customers, except with the controlling customer’s explicit authorization or where the data has been effectively de-identified or anonymized in accordance with applicable law.
  • We may use aggregated, de-identified, or synthetic data to develop, validate, and improve our models and Services.
  • Where the Services incorporate third-party AI components, we impose contractual restrictions prohibiting those providers from using customer data to train their own general-purpose models.

6. Legal Bases for Processing (EEA / UK)

Where the EU or UK General Data Protection Regulation applies, we rely on one or more of the following legal bases:

  • Contract: to provide the Services you or your organization have requested.
  • Legitimate interests: to secure, improve, and market our Services, balanced against your rights.
  • Consent: for certain cookies and marketing, which you may withdraw at any time.
  • Legal obligation: to comply with laws to which we are subject.
  • Special category data (health): processed only on behalf of, and under the instructions of, the controlling customer, relying on the customer’s lawful basis (such as the provision of health or dental care) under Article 9.

7. How We Share Information

We do not sell your personal information and do not “share” it for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws. We disclose information only as follows:

  • Service providers / sub-processors: with vendors who process data on our behalf under written contracts (see Section 8).
  • At your direction: with integrations and recipients you authorize.
  • Legal and safety: to comply with law, valid legal process, or to protect the rights, property, or safety of Molaris AI, our users, or others.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

8. Sub-Processors

We engage a limited set of sub-processors to deliver the Services, such as cloud infrastructure and hosting providers, and payment, analytics, and communications providers. Each sub-processor is bound by confidentiality and data protection obligations no less protective than those in this Policy and our customer agreements. A current list of sub-processors is available on request at privacy@molaris.ai.

9. Data Security

We maintain administrative, technical, and physical safeguards designed to protect information, including:

  • Encryption of data in transit and at rest
  • Role-based access controls and least-privilege principles
  • Audit logging and monitoring
  • Network segmentation and tenant isolation
  • Secret management and periodic credential rotation
  • Vulnerability management and regular security assessments

No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security. We maintain an incident response process and will notify affected parties of security incidents as required by law and by our customer agreements.

10. HIPAA and Protected Health Information

For customers subject to the U.S. Health Insurance Portability and Accountability Act (HIPAA), Molaris AI acts as a Business Associate and will enter into a Business Associate Agreement (BAA). We handle Protected Health Information (PHI) in accordance with the HIPAA Privacy, Security, and Breach Notification Rules, including access controls, audit logging, encryption, and defined breach notification procedures. PHI is processed only to provide the Services and as permitted by the applicable BAA.

11. Data Retention

We retain personal information for as long as necessary to provide the Services, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Retention periods are determined by the nature and sensitivity of the data, the purposes for processing, and applicable legal requirements. For data processed on behalf of a customer, retention and deletion follow the customer agreement and DPA. When information is no longer required, we securely delete or anonymize it.

12. International Data Transfers

We may process and store information in countries other than your own, including the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision, together with supplementary measures where necessary.

13. Your Privacy Rights (EEA / UK / Switzerland)

Subject to applicable law, you may have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data in certain circumstances
  • Restrict or object to certain processing
  • Portability of data you provided to us
  • Withdraw consent where processing relies on consent
  • Lodge a complaint with your supervisory authority

Where we process data on behalf of a customer, we will refer your request to that customer and support them in responding. To exercise your rights, contact privacy@molaris.ai.

14. U.S. State Privacy Rights

Depending on your state of residence (including California, Virginia, Colorado, Connecticut, Utah, and others), you may have the right to know, access, correct, delete, and obtain a portable copy of your personal information, and to appeal a denial of a request.

  • We do not sell personal information and do not share it for cross-context behavioral advertising.
  • We do not use or disclose sensitive personal information for purposes other than those permitted under applicable law.
  • We will not discriminate against you for exercising your privacy rights.

To submit a request, contact privacy@molaris.ai. We will verify your request and may ask for information to confirm your identity. You may use an authorized agent where permitted.

15. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Enable core site functionality and security
  • Remember your preferences and settings
  • Measure and analyze usage and performance

Where required, we request consent for non-essential cookies through our cookie banner, and you can change your choices at any time through the cookie preferences control. You can also manage cookies through your browser settings. Disabling certain cookies may affect functionality.

16. Automated Decision-Making

The Services provide analytical outputs and recommendations to assist qualified professionals. We do not use these outputs to make decisions that produce legal or similarly significant effects about you without meaningful human involvement. Clinical and treatment decisions remain the responsibility of the licensed professionals who use the Services.

17. Children's Privacy

The Services are intended for business and professional use and are not directed to individuals under 18. We do not knowingly collect personal information directly from children. Clinical case data about minors may be processed on behalf of a customer solely for the provision of dental care, under that customer’s instructions and lawful basis.

18. Third-Party Links and Services

Our Services may link to or integrate with third-party websites and services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their practices. We encourage you to review their privacy policies.

19. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version with a revised “Last Updated” date and, for material changes, provide additional notice by email or through the Services. Your continued use of the Services after an update takes effect constitutes acceptance of the revised Policy.

20. Contact Us

For questions, concerns, or requests regarding this Policy or our data practices, contact:

Molaris AI
Attn: Privacy Team
Email: privacy@molaris.ai