Privacy Policy

Last updated: July 29, 2026

Are you a patient of a dental practice?

If you called a dental office and spoke with its Enamly assistant, your health information belongs to that dental practice, not to Enamly. We handle it strictly on the practice's instruction under a Business Associate Agreement, and this policy does not govern it. To see, correct, or delete your records, please contact your dental practice directly. They are the only party that can authorize those changes. Section 3 explains this in full.

1. Who we are

Enamly Inc. ("Enamly," "we," "us," or "our") provides an AI-powered virtual receptionist service to dental practices. Our phone assistant answers patient calls, answers questions, and books, reschedules, and cancels appointments in the practice's own practice management system.

Enamly Inc. is a Delaware corporation with its principal office at 25675 Nelson Way, Ste 120 PMB 3029, Katy, TX 77494, United States. You can reach us at info@enamly.ai or through our contact page.

This policy applies to enamly.ai, getenamly.com, and the Enamly practice dashboard.

2. We play two different roles with data

Almost every question about how we handle information depends on which of these two roles applies, so we want to be explicit rather than blur them together.

As a service provider to dental practices

When our assistant handles a patient call, the dental practice decides what happens to that information and we act on its instruction. Under United States health privacy law the practice is the "covered entity" and Enamly is its "business associate." Our obligations there come from the Business Associate Agreement we sign with the practice rather than from this policy. Section 3 covers it.

For our own business

When you visit our website, request a demo, subscribe to our emails, or use the practice dashboard as a staff member, we decide how that information is used. That is what the rest of this policy describes, beginning at Section 4.

3. Patient health information

While answering calls, our assistant may handle a patient's name, phone number, date of birth, reason for calling, insurance details, appointment history, and a recording and transcript of the call. Some of this is protected health information under the Health Insurance Portability and Accountability Act.

Our commitments to the practice:

  • We use and disclose this information only as the Business Associate Agreement permits and only to deliver the service. We never sell it, and we never use it for advertising.
  • We apply the administrative, physical, and technical safeguards the HIPAA Security Rule requires. Our security page describes them.
  • Every subcontractor that touches this information is itself under a Business Associate Agreement with us. A current list is available on request.
  • We notify the practice of any breach affecting this information without unreasonable delay and within the timeframes HIPAA and our agreement require, and we support the practice in meeting its own notification duties.
  • We have a formally designated Security Official and Privacy Official accountable for this program.

If you are a patient exercising your rights to see your record, correct it, request deletion, or restrict how it is used, please contact your dental practice. Those rights run against the practice as the covered entity, and we are not permitted to act on them without the practice's authorization. If you contact us by mistake we will point you to the practice rather than leave you without an answer.

Our assistant is also instructed never to discuss account balances or insurance coverage amounts, and never to give clinical or medical advice.

4. Information we collect for our own business

  • Contact and business information: name, email address, phone number, practice name, practice management system, and practice size, provided when you request a demo, subscribe, or correspond with us.
  • Account information: for practice staff using the dashboard, this means name, work email, role, and authentication records.
  • Usage data: pages visited, referring source, browser and device type, and similar technical information from our websites.
  • Communications: the emails, messages, and call notes exchanged between us and you as a business contact.

5. How we use it

  • Providing, maintaining, securing, and improving the service.
  • Responding to enquiries and scheduling demonstrations.
  • Administering accounts, billing, and support.
  • Sending service and account notifications to practice customers.
  • Sending marketing communications to business contacts, which you can stop at any time.
  • Meeting legal obligations and protecting our rights.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

6. Text messages

Two different kinds of text message come from Enamly, and they work differently.

Appointment messages to patients are sent only when a caller asks for one during a call, such as a scheduling link or a confirmation. Consent is captured verbally on that call, and these are sent on behalf of the dental practice. Typically one or two messages follow a single booking.

Business messages may be sent to practice contacts who provide a phone number and opt in. Consent is never a condition of purchase.

For either kind, message frequency varies, message and data rates may apply, and carriers are not liable for delayed or undelivered messages. Reply STOP to unsubscribe. You will get one confirmation and nothing further. Reply HELP for assistance, or email info@enamly.ai. We do not sell or share phone numbers for anyone else's marketing.

7. Where data is stored

Enamly's systems run in the United States on Amazon Web Services infrastructure. Patient information is stored and processed in the United States, and we do not transfer it internationally. Our own business tools, such as our sales and marketing systems, are also based in the United States.

8. How long we keep it

  • Patient call records: retained for the practice for as long as its agreement with us is in effect, and handled on termination as that agreement directs. Recordings and transcripts move into encrypted long-term archival storage on a defined schedule.
  • Compliance records: retained at least six years, as HIPAA requires. Security audit logs are retained in line with that obligation.
  • Business contact and account data: retained while the relationship is active and for a reasonable period afterwards to meet legal, tax, and accounting obligations.

9. Who else is involved

We rely on a limited set of infrastructure and technology providers: cloud hosting and encrypted storage, the voice platform, language models, practice management connectivity, message and email delivery, payment processing, and our own business tools. Each is bound by contract to protect the data it handles, and each provider that touches patient health information is under a Business Associate Agreement with us.

A current list of these providers, what each one does, and whether it handles patient data is available to customers and reviewers on request. Email info@enamly.ai.

We may also disclose information when the law requires it, to protect our rights or someone's safety, or in connection with a merger or acquisition, in which case the acquirer remains bound by commitments at least as protective as these.

10. Security

Protections include encryption of stored data using managed keys, encrypted connections for all traffic, least-privilege credentials, isolation of each practice's data enforced at the database layer, immutable audit logging, and continuous monitoring with automated alerting. Our security page goes into detail. No system can be guaranteed perfectly secure, and we do not claim otherwise.

11. Cookies

Our websites use cookies and similar technologies that are necessary for the site to function and that help us understand aggregate traffic so we can improve the site. We do not use them to build advertising profiles and we do not sell data collected through them. You can block or delete cookies in your browser settings, though some parts of the site may not work as well if you do.

12. Your rights

For information Enamly holds in its own right, as described in Section 4, you may ask us to give you a copy, correct it, delete it, or stop sending you marketing. Depending on where you live you may also have the right to appeal a refusal, and to be free from discrimination for exercising these rights. Because we do not sell personal information or share it for cross-context behavioral advertising, there is nothing to opt out of on that front.

Email info@enamly.ai with "privacy request" in the subject line. We will respond within the time your applicable law allows, and we may need to verify your identity first. You may use an authorized agent where the law permits.

Residents of states with comprehensive privacy laws, including Texas, California, Virginia, Colorado, and Connecticut, have these rights under those laws. Patients should direct requests about health records to their dental practice, as Section 3 explains.

13. Children

Our website and dashboard are intended for business use by adults and are not directed to children. We do not knowingly collect personal information from children through them. Separately, a dental practice may treat patients of any age, and information about a minor patient handled during a call belongs to that practice and is governed by its own privacy practices together with our Business Associate Agreement.

14. Changes

We may update this policy. Material changes will be reflected in the "Last updated" date above, and where a customer agreement requires advance notice we will give it directly.

15. Contact

For questions, requests, or complaints about privacy, email info@enamly.ai or write to Enamly Inc., 25675 Nelson Way, Ste 120 PMB 3029, Katy, TX 77494, United States. Our Privacy Official is responsible for this policy and will handle your request.

See also Terms & Conditions, Security & Compliance.

Never miss another patient call