‍

Privacy Policy

GSR Dental LLC

‍ ‍

This Privacy Policy outlines the policies and practices of GSR Dental LLC regarding the collection, use, disclosure, retention, protection, and processing of personal data and Protected Health Information (“PHI”) when you use our services, website, dental laboratory services, patient-related services, or other business services.

This Privacy Policy also explains certain privacy rights and protections that may apply under federal law, including the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended, and applicable Texas privacy laws, including the Texas Data Privacy and Security Act (“TDPSA”), where applicable.

By using GSR Dental LLC's website or services, you acknowledge this Privacy Policy. Where applicable law requires consent or authorization for a particular collection, use, or disclosure, GSR Dental LLC will obtain such consent or authorization as required by law.

Definitions

Account

“Account” means a unique account created for you to access our Service.

Company

“Company,” “GSR Dental,” “we,” “our,” and “us” refer to GSR Dental LLC, a Texas limited liability company doing business as GSR Dental.

Cookies

“Cookies” are small data files placed on your device that may be used to support website functionality, security, preferences, analytics, and other permitted purposes.

Personal Data

“Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual, to the extent such information is covered by an applicable privacy law.

Protected Health Information / PHI

“Protected Health Information” or “PHI” means individually identifiable health information protected under HIPAA when GSR Dental is subject to HIPAA requirements with respect to that information.

Service

“Service” refers to our website, including www.gsrdental.com, and other services provided by GSR Dental LLC.

Service Provider

“Service Provider” means a third-party person or entity that processes information on behalf of GSR Dental LLC to provide, maintain, secure, support, or administer our services.

Usage Data

“Usage Data” means information automatically collected regarding interaction with our Service, such as page visits, timestamps, browser information, device information, diagnostic information, and security-related information.

You

“You” means the individual or entity using or interacting with our Service.

Texas Registered Dental Laboratory and Company Identity

GSR Dental LLC, doing business as GSR Dental, is a Texas Registered Dental Laboratory licensed and registered with the Texas State Board of Dental Examiners (“TSBDE”).

As a registered dental laboratory, GSR Dental provides dental laboratory services, including the manufacture, repair, processing, and delivery of dental prosthetic devices and restorations prescribed or authorized by licensed dentists.

Throughout this Privacy Policy, the terms “GSR Dental,” “we,” “our,” and “us” refer to GSR Dental LLC and, where applicable, its lawful business operations conducted under the GSR Dental name.

Nothing in this Privacy Policy expands or modifies any legal, regulatory, licensing, professional, or contractual obligation imposed upon GSR Dental under applicable federal or Texas law.

Doing Business As (DBA)

GSR Dental LLC conducts business under the registered trade name GSR Dental.

Unless otherwise stated, references to GSR Dental include GSR Dental LLC and its applicable business operations conducted under the GSR Dental name.

References to affiliates, subsidiaries, successors, assigns, or related entities apply only where such entities actually exist and where such reference is applicable to the particular service or transaction.

Nothing in this section expands the legal obligations of any separate legal entity.

HIPAA Compliance

GSR Dental recognizes that, in connection with dental laboratory services, it may receive, create, maintain, use, or transmit information that constitutes Protected Health Information (“PHI”) under HIPAA.

GSR Dental will handle PHI in accordance with applicable HIPAA requirements when HIPAA applies to GSR Dental's activities and relationship with a dentist, dental practice, healthcare provider, or other covered entity.

GSR Dental maintains administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI and electronic PHI (“ePHI”), consistent with applicable HIPAA requirements.

These safeguards may include:

  • Limiting access to PHI to personnel who have a legitimate need to access the information for authorized business or healthcare purposes.

  • Applying the minimum necessary principle where applicable.

  • Using access controls and authentication mechanisms.

  • Using reasonable encryption and secure transmission and storage practices.

  • Training personnel regarding privacy and security requirements.

  • Maintaining policies and procedures governing the handling of PHI.

  • Investigating suspected or confirmed security incidents.

  • Maintaining appropriate records and audit information regarding access to protected information.

  • Requiring appropriate contractual protections from vendors or service providers when required by applicable law.

GSR Dental will not use or disclose PHI except as permitted or required by applicable law, an applicable agreement, a patient's authorization, or the instructions of an authorized healthcare provider, as appropriate.

Dental Laboratory Treatment Relationship

GSR Dental LLC operates as a registered dental laboratory providing dental laboratory services to licensed dentists and their patients. In connection with these services, GSR Dental may receive patient information, including Protected Health Information (PHI), that is necessary to manufacture, process, repair, adjust, or otherwise provide prescribed dental prosthetic devices and related laboratory services.

Under HIPAA, a dental laboratory may qualify as a health care provider when providing treatment-related dental laboratory services. The American Dental Association (ADA) states that dental laboratories are considered health care providers and that, under most circumstances, a Business Associate Agreement (BAA) is not necessary for a dental practice to share PHI with a dental laboratory concerning the treatment of an individual. The ADA explains that HIPAA does not require a BAA when a covered dental practice discloses PHI to another health care provider for treatment purposes.

The Texas Dental Association (TDA) is the state dental association representing Texas dentists and provides HIPAA and regulatory information to Texas dental practices. GSR Dental recognizes and follows the treatment-provider principles reflected in applicable ADA and TDA guidance when receiving PHI for the purpose of providing prescribed dental laboratory treatment services.

Texas law separately contains exemptions relating to the regulation of dental laboratory services under Texas Occupations Code Chapter 266. Those statutory exemptions concern the applicability of Texas dental-laboratory licensing and regulatory requirements and should not be interpreted as eliminating HIPAA obligations where HIPAA otherwise applies.

Accordingly, GSR Dental's position is that a Business Associate Agreement is not required solely because a dentist or dental practice discloses PHI to GSR Dental for the treatment of the patient through prescribed dental laboratory services, provided the relationship falls within HIPAA's treatment-provider provisions.

This treatment relationship may include receiving a dentist's laboratory prescription, patient identifiers, dental records, impressions, models, scans, photographs, shade information, allergy information, treatment specifications, and other information reasonably necessary to manufacture or provide the prescribed dental device or laboratory service.

A BAA may nevertheless be appropriate or required where GSR Dental performs a separate function or service for or on behalf of a covered dental practice that falls within the HIPAA definition of a Business Associate rather than functioning as a health care provider for the patient's treatment. Each relationship should therefore be evaluated based on the actual services being provided and the purpose for which PHI is disclosed.

Nothing in this section prevents GSR Dental and a dental practice from voluntarily entering into a BAA or other contractual agreement when the parties determine that doing so is appropriate.

This section is intended to describe GSR Dental's understanding of the applicable HIPAA treatment-provider provisions and does not constitute legal advice. Dental practices and other covered entities should consult qualified legal counsel regarding their specific HIPAA and state-law obligations.

No Sale of PHI or Personal Data

GSR Dental Does Not Sell Your PHI or Personal Data

GSR Dental LLC does not sell Protected Health Information (“PHI”) or Personal Data.

GSR Dental does not sell, rent, lease, or otherwise transfer PHI or Personal Data to third parties for monetary or other valuable consideration for the purpose of allowing those third parties to independently market, advertise to, profile, or otherwise commercially exploit that information.

GSR Dental does not sell PHI or Personal Data to data brokers.

GSR Dental does not sell patient information, dental treatment information, prescription information, laboratory case information, or other PHI for advertising or marketing purposes.

GSR Dental does not use PHI for targeted advertising or behavioral advertising.

PHI received or maintained in connection with dental laboratory services is used only for authorized purposes, including providing dental laboratory services, processing and fulfilling prescriptions and orders, communicating with authorized healthcare providers, maintaining records, protecting the security of our systems, complying with legal obligations, and other purposes permitted or required by applicable law.

Permitted Sharing of Information

Although GSR Dental does not sell PHI or Personal Data, GSR Dental may disclose or make information available when reasonably necessary for legitimate business, healthcare, security, legal, or operational purposes.

Depending upon the circumstances, information may be shared with:

  • Dentists and dental practices involved in a patient's treatment.

  • Healthcare providers involved in treatment or care coordination.

  • Authorized employees and personnel.

  • Service providers that assist GSR Dental with hosting, information technology, cybersecurity, communications, document storage, software, payment processing, or other business functions.

  • Professional advisors, such as attorneys, accountants, insurers, auditors, or consultants, when appropriate.

  • Government agencies or regulators when required or permitted by law.

  • Law enforcement when legally required or permitted.

  • Courts, governmental authorities, or other parties when necessary to comply with legal process.

  • Parties involved in a lawful merger, acquisition, financing, restructuring, sale, or transfer of business assets, subject to applicable law and contractual protections.

Where a third party receives PHI on behalf of GSR Dental or a covered entity and applicable law requires a Business Associate Agreement or other contractual protection, GSR Dental will use appropriate contractual safeguards.

A disclosure to a service provider does not constitute a sale of Personal Data merely because the service provider receives or processes information to provide services to GSR Dental.

Texas Data Privacy and Security Act

GSR Dental recognizes the Texas Data Privacy and Security Act (“TDPSA”), Chapter 541 of the Texas Business & Commerce Code, and will comply with the Act to the extent the Act applies to GSR Dental and the particular information or processing activity.

The TDPSA provides Texas residents with certain rights concerning covered Personal Data and establishes obligations for covered businesses.

The TDPSA also contains exemptions and exclusions, including provisions relating to certain entities, regulated information, and information governed by other federal laws.

Accordingly, GSR Dental does not represent that every category of information collected or processed by the Company is governed by the TDPSA.

Where the TDPSA applies, GSR Dental intends to process covered Personal Data in accordance with applicable requirements, including applicable obligations concerning:

  • Transparency regarding the collection and use of Personal Data.

  • Data minimization.

  • Reasonable administrative, technical, and physical safeguards.

  • Applicable consumer rights.

  • Processing purposes.

  • Applicable disclosures.

  • Sensitive data requirements.

  • Applicable data protection assessments or other compliance obligations.

  • Requests concerning consumer Personal Data.

Data Minimization

GSR Dental seeks to collect and process only the information reasonably necessary for the purposes described in this Privacy Policy or otherwise permitted or required by law.

For dental laboratory services, information may be necessary to identify a patient, identify a dental case, understand the dentist's prescription, manufacture or repair a dental device, communicate with the prescribing provider, document delivery, process payments, or comply with applicable legal and regulatory requirements.

Where PHI is involved, GSR Dental will use and disclose information consistent with applicable HIPAA requirements and the minimum necessary principle where applicable.

Types of Data Collected

Personal Data

Depending upon the services used, GSR Dental may collect information such as:

  • First and last name.

  • Email address.

  • Telephone number.

  • Mailing or business address.

  • Account credentials and authentication information.

  • Practice or business information.

  • Transaction information.

  • Communications with GSR Dental.

  • Information submitted through forms or service requests.

Dental and Patient Information

When providing dental laboratory services, GSR Dental may receive information supplied by dentists, dental practices, or authorized healthcare providers, including:

  • Patient name.

  • Patient identification number or external patient ID.

  • Dental case information.

  • Prescription information.

  • Dental treatment information.

  • Tooth numbers and shade information.

  • Laboratory instructions.

  • Allergies or material sensitivities when provided for treatment purposes.

  • Dates associated with laboratory cases.

  • Dental images, models, scans, photographs, or related files when provided.

  • Other information necessary to manufacture or deliver a prescribed dental product.

When such information constitutes PHI, GSR Dental will handle it in accordance with applicable HIPAA requirements.

Usage Data

GSR Dental may automatically collect certain technical and security information, including:

  • IP address.

  • Browser type and version.

  • Operating system.

  • Device information.

  • Pages visited.

  • Date and time of access.

  • Interaction information.

  • Diagnostic information.

  • Security and fraud-prevention information.

  • Network-related information.

Usage Data is not intentionally combined with PHI for advertising purposes.

Cookies and Tracking Technologies

GSR Dental may use cookies and similar technologies to operate and secure the website, remember user preferences, support authentication, analyze website performance, and improve the user experience.

These technologies may include:

  • Necessary or essential cookies.

  • Session cookies.

  • Preference or functionality cookies.

  • Security and fraud-prevention technologies.

  • Limited analytics technologies.

GSR Dental does not use PHI for targeted advertising, behavioral advertising, or cross-context behavioral advertising.

Where applicable law provides choices regarding non-essential cookies or tracking technologies, GSR Dental will provide those choices through appropriate website controls or notices.

Use of Personal Data

GSR Dental may collect and use Personal Data for purposes including:

Service and Account Management

  • Providing and maintaining the Service.

  • Creating and managing accounts.

  • Authenticating users.

  • Providing requested functionality.

  • Securing accounts and systems.

  • Preventing fraud and abuse.

Dental Laboratory Services

  • Receiving and processing dental prescriptions.

  • Manufacturing, repairing, processing, and delivering dental products.

  • Communicating with dentists and dental practices.

  • Managing dental laboratory cases.

  • Processing case documentation.

  • Providing case status information.

  • Handling remakes, adjustments, returns, and related services.

  • Maintaining business and treatment records.

Contracts and Transactions

  • Processing orders.

  • GSR Dental establishes and maintains the pricing for all products and services. Prices are subject to change at GSR Dental’s discretion. (Including Lab & Chairside service pricing)

  • Processing payments.

  • Managing invoices.

  • Communicating regarding transactions.

  • Enforcing contractual rights and obligations. (Laboratory Prescription Form / Invoices / Service Agreements, and any other Contracts or Agreements.)

  • Laboratory Prescription Form, whether it's in paper form or digital form these are Contracts between GSR Dental and Dentist or Dental Office.

  • Resolving disputes.

Communications

GSR Dental may contact users by email, telephone, SMS, or other appropriate communication methods regarding:

  • Account activity.

  • Security alerts.

  • Orders and cases.

  • Service-related communications.

  • Transaction information.

  • Customer support.

Marketing communications will be handled in accordance with applicable law and applicable consent or opt-out requirements.

GSR Dental will not use PHI for marketing communications unless permitted by applicable law and, where required, the appropriate authorization has been obtained.

Marketing and Advertising

GSR Dental does not sell PHI or Personal Data for advertising purposes.

GSR Dental does not use PHI for targeted advertising.

GSR Dental may provide general information about its own products and services to customers and website users where permitted by applicable law.

GSR Dental will provide legally required choices regarding marketing communications.

GSR Dental does not knowingly provide PHI to advertising networks, data brokers, or unrelated third parties for independent advertising purposes.

Personal Data Sharing

GSR Dental may disclose Personal Data when reasonably necessary for the purposes described in this Privacy Policy.

Examples include:

Service Providers

GSR Dental may use third-party providers for services such as:

  • Website hosting.

  • Cloud storage.

  • Cybersecurity.

  • Software.

  • Information technology.

  • Customer support.

  • Communications.

  • Payment processing.

  • Document management.

  • Backup and disaster recovery.

  • Professional services.

These providers are authorized to process information only as reasonably necessary to provide their services to GSR Dental and subject to applicable contractual and legal requirements.

Healthcare Providers

GSR Dental may communicate with dentists, dental practices, laboratories, and other healthcare providers as necessary to provide or coordinate treatment and dental laboratory services.

Legal and Regulatory Requirements

GSR Dental may disclose information when required or permitted by law, regulation, court order, subpoena, or governmental request.

Business Transactions

Information may be transferred as part of a lawful merger, acquisition, financing, reorganization, sale, or transfer of business assets, subject to applicable law.

Security and Fraud Prevention

GSR Dental may disclose information when reasonably necessary to investigate, prevent, or respond to fraud, security incidents, unauthorized activity, or threats to individuals or systems.

No Sale; Service Provider Processing

GSR Dental's use of service providers does not constitute a sale of Personal Data merely because a service provider receives, stores, or processes information on GSR Dental's behalf.

GSR Dental does not authorize service providers to independently sell GSR Dental's PHI or Personal Data.

Where applicable law requires contractual restrictions concerning Personal Data, GSR Dental will use commercially reasonable measures to impose appropriate restrictions.

Personal Data Retention

GSR Dental retains Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including:

  • Providing services.

  • Maintaining dental laboratory records.

  • Completing transactions.

  • Maintaining accounting and business records.

  • Meeting legal and regulatory requirements.

  • Resolving disputes.

  • Enforcing agreements.

  • Maintaining security.

  • Preventing fraud.

  • Protecting the rights and property of GSR Dental and others.

PHI may be retained for periods required by HIPAA, applicable law, professional requirements, contractual obligations, or legitimate recordkeeping requirements.

When information is no longer required and applicable law permits disposal, GSR Dental may securely delete, destroy, anonymize, or otherwise dispose of the information.

Security of Personal Data and PHI

GSR Dental prioritizes the security of Personal Data and PHI.

GSR Dental maintains reasonable administrative, technical, and physical safeguards appropriate to the nature and sensitivity of information processed by the Company.

Security measures may include:

  • Access controls.

  • Authentication.

  • Role-based access.

  • Encryption where appropriate.

  • Secure transmission.

  • Secure storage.

  • System monitoring.

  • Security logging.

  • Personnel training.

  • Incident response procedures.

  • Backup and recovery procedures.

  • Vendor security controls.

No method of electronic transmission or storage is guaranteed to be completely secure.

GSR Dental does not publicly disclose security configurations, passwords, encryption keys, system credentials, or detailed security architecture where disclosure could compromise the security of the Company, its customers, patients, or systems.

HIPAA Security and Breach Response

When HIPAA applies, GSR Dental maintains procedures designed to identify, investigate, mitigate, and respond to suspected or confirmed unauthorized access, use, disclosure, or breach of PHI.

Where a reportable breach of unsecured PHI occurs, GSR Dental will provide required notifications in accordance with applicable law and any applicable contractual obligations.

Where GSR Dental acts as a business associate, applicable notification and cooperation obligations will be governed by HIPAA and the applicable Business Associate Agreement.

Patient and Consumer Privacy Rights

Depending upon the applicable law and GSR Dental's role in processing the information, individuals may have rights concerning their Personal Data or PHI.

These rights may include, where applicable:

  • Requesting access to information.

  • Requesting correction of inaccurate information.

  • Requesting deletion of certain Personal Data.

  • Requesting information regarding processing activities.

  • Requesting information regarding disclosures.

  • Exercising applicable opt-out rights.

  • Withdrawing consent where processing is based on consent.

  • Filing a privacy complaint.

Rights relating to PHI under HIPAA may differ from rights relating to general Personal Data under state privacy laws.

Requests concerning PHI may be subject to HIPAA procedures, applicable Business Associate Agreements, and the individual's relationship with the prescribing dentist or covered entity.

GSR Dental may need to verify the identity and authority of a person submitting a privacy request before providing access to information.

GSR Dental will not unlawfully discriminate against an individual for exercising a privacy right protected by applicable law.

Requests Concerning Patient PHI

Because GSR Dental may provide dental laboratory services to dentists and dental practices, the prescribing dentist or covered healthcare provider may maintain the primary patient record.

If you are seeking access to your complete dental record or requesting correction of your healthcare information, GSR Dental may direct you to the prescribing dentist or healthcare provider when appropriate.

GSR Dental will cooperate with applicable lawful requests concerning PHI to the extent required by HIPAA, applicable law, or an applicable agreement.

Consent to Store Payment Information

By providing payment information, you authorize GSR Dental and its payment-processing providers to process the transaction for the purposes described at the time of payment.

GSR Dental does not intentionally store full credit or debit card numbers or card verification codes when such information can be processed directly through a payment processor.

Where GSR Dental retains limited payment-related records, such as transaction confirmations, invoice amounts, or the last four digits of a payment card, such records are retained only as reasonably necessary for accounting, tax, dispute resolution, security, or legal purposes.

Payment Processing and PCI Compliance

GSR Dental does not directly store full credit or debit card numbers, CVV codes, or other sensitive cardholder authentication data on its own systems when payment processing is handled by a third-party payment processor.

Payment information may be transmitted directly to payment processors through secure channels.

Payment processors may maintain their own privacy policies and security practices. GSR Dental does not control the independent privacy practices of third-party payment processors.

Transfer of Personal Data

GSR Dental may use service providers located in Texas, other states, or other jurisdictions.

Information may therefore be processed or stored outside the jurisdiction in which it was originally collected.

GSR Dental will use reasonable safeguards appropriate to the nature of the information and applicable legal requirements.

Where PHI is involved, applicable HIPAA requirements and contractual restrictions will continue to apply regardless of where the information is processed or stored.

Disclosure of Personal Data

Business Transactions

If GSR Dental participates in a lawful merger, acquisition, financing, restructuring, sale, or transfer of assets, information may be transferred as part of that transaction, subject to applicable law.

GSR Dental will not use such a transaction as a means of selling Personal Data to data brokers or unrelated third parties for independent advertising purposes.

Law Enforcement and Legal Requirements

GSR Dental may disclose information when reasonably necessary or legally required to:

  • Comply with applicable law.

  • Respond to subpoenas, court orders, or other legal process.

  • Protect the rights or property of GSR Dental.

  • Prevent or investigate fraud or wrongdoing.

  • Protect the safety of individuals or the public.

  • Defend against legal claims.

  • Comply with regulatory requirements.

Third-Party Websites and Services

The Service may contain links to websites or services operated by third parties.

GSR Dental does not control the privacy or security practices of third-party websites.

Users should review the privacy policies of third-party websites and services before providing information to them.

A third-party website's collection or use of information is governed by that third party's privacy policy, not this Privacy Policy.

Children's Privacy

GSR Dental's services are primarily intended for dentists, dental practices, healthcare providers, business customers, patients receiving dental services, and other authorized users.

GSR Dental does not knowingly sell Personal Data of children.

GSR Dental does not knowingly sell sensitive Personal Data.

Where information concerning a child is processed as part of dental treatment, GSR Dental will handle the information in accordance with applicable healthcare, privacy, and other legal requirements.

De-Identified and Aggregated Information

Where permitted by applicable law, GSR Dental may use information that has been properly de-identified or aggregated so that it cannot reasonably be used to identify an individual.

GSR Dental may use properly de-identified or aggregated information for legitimate business purposes such as:

  • Quality improvement.

  • Service improvement.

  • Security.

  • Operational analysis.

  • Business analytics.

  • Research or statistical analysis where legally permitted.

GSR Dental will not attempt to re-identify properly de-identified information except as permitted by applicable law.

Changes to This Privacy Policy

GSR Dental may periodically update this Privacy Policy.

Changes may be communicated by:

  • Posting an updated Privacy Policy on the website.

  • Updating the “Latest Update” date.

  • Providing an appropriate notice through the Service.

  • Sending an email or other communication where legally required.

The updated Privacy Policy becomes effective when posted unless a different effective date is stated.

Users are encouraged to periodically review this Privacy Policy.

Contact Us

Questions concerning this Privacy Policy, privacy practices, Personal Data, or PHI may be directed to:

GSR Dental LLC

Email:privacy@gsrdental.us

Website:www.gsrdental.com

GSR Dental will make reasonable efforts to respond to privacy inquiries in accordance with applicable law and the nature of the request. ‍