Effective Date: May 1, 2026
This Privacy Policy describes how Crystal Smile Technology LLC ("Crystal Smile," "we," "our," or "us") collects, uses, shares, and protects information about you when you visit our website, contact us, or do business with our dental laboratory. We operate primarily in the State of Texas and our practices are designed to comply with applicable federal law and Texas law, including the Health Insurance Portability and Accountability Act (HIPAA), the Texas Medical Records Privacy Act (Texas Health & Safety Code Chapter 181, originally enacted as House Bill 300), and the Texas Identity Theft Enforcement and Protection Act (Texas Business & Commerce Code Chapter 521). By using our website or services, you agree to the practices described below.
1. Information We Collect
We collect information in the following ways:
Information you provide
- Contact details such as your name, practice name, email address, phone number, and mailing address.
- Account information when you set up a lab account, including billing information and authorized contacts.
- Case-related information submitted through prescriptions, digital scans, impressions, photos, or other communications.
- Messages and inquiries you send us through our website, email, phone, or other channels.
Information collected automatically
- Device and usage data such as IP address, browser type, operating system, referring URLs, and pages viewed.
- Cookies and similar technologies used to operate the website, remember preferences, and measure performance.
2. How We Use Information
We use the information we collect to:
- Provide, fulfill, and improve our dental laboratory services and products.
- Communicate with you about cases, quotes, orders, shipments, and account matters.
- Respond to your inquiries and customer service requests.
- Process payments and maintain financial records.
- Operate, secure, and improve our website and digital workflows.
- Comply with legal, regulatory, and contractual obligations.
3. Patient Information, HIPAA & Texas HB 300
When dental practices share information about their patients with us in the course of fabricating restorations or providing services, we treat that information as Protected Health Information (PHI) under HIPAA and as Protected Health Information / Sensitive Personal Information under the Texas Medical Records Privacy Act (Texas HB 300, codified at Texas Health & Safety Code Chapter 181). As a "covered entity" under Texas HB 300 and a "business associate" under HIPAA, we:
- Use and disclose PHI only as necessary to perform our services, in accordance with our agreements with the dental practice (including any Business Associate Agreement), and as permitted or required by law.
- Train our workforce on the proper handling of PHI in accordance with Texas HB 300 requirements.
- Do not sell PHI for marketing purposes.
- Provide notice and assistance to dental-practice clients in the unlikely event of a breach of unsecured PHI, in accordance with HIPAA, Texas HB 300, and Texas Business & Commerce Code § 521.053 (breach notification).
4. How We Share Information
We do not sell personal information. We share information only as needed to operate our business, including with:
- Service providers who support our operations (for example, shipping carriers, payment processors, IT, email, and analytics providers), under contracts that require them to protect your information.
- The dental practice that submitted a case, regarding that case.
- Authorities and other parties when required by law, subpoena, or other legal process, or to protect the rights, safety, or property of Crystal Smile, our clients, or the public.
- Successors in connection with a merger, acquisition, financing, or sale of business assets, in which case appropriate confidentiality protections will apply.
5. Cookies & Tracking Technologies
Our website uses cookies and similar technologies to keep the site running, remember your preferences, and analyze how the site is used. You can control cookies through your browser settings; disabling cookies may affect parts of the site. We may also use analytics tools that collect aggregated, non-identifying information about site usage.
6. Data Security
We use reasonable administrative, technical, and physical safeguards designed to protect information we collect against unauthorized access, use, alteration, and disclosure. No method of transmission or storage is fully secure, however, and we cannot guarantee absolute security.
7. Data Retention
We retain information for as long as needed to provide our services, comply with legal and regulatory obligations, resolve disputes, and enforce our agreements. Retention periods vary based on the type of information and the purpose for which it was collected.
8. Your Choices & Rights
You may:
- Update your contact information by emailing us at lab@crystalsmile.org.
- Opt out of marketing communications by following the unsubscribe instructions in any marketing email.
- Request access to, correction of, or deletion of your personal information, subject to applicable law and any legal or contractual record-keeping obligations.
Patients whose PHI is held by us as a Business Associate should direct rights requests (such as access, amendment, or accounting of disclosures) to their dental practice, which is the HIPAA Covered Entity.
9. Children's Privacy
Our website is intended for dental professionals and adults. We do not knowingly collect personal information directly from children under 13 through our website.
10. Third-Party Links
Our website may contain links to third-party sites. We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" above. Material changes will be communicated through our website. Your continued use of our services constitutes acceptance of the updated policy.
12. Texas Residents — Your Privacy Rights
If you are a Texas resident, you have specific rights under Texas law in addition to the choices described in Section 8:
- Access & copy of medical records. Under Texas HB 300 and Texas Health & Safety Code § 181.102, you generally have the right to obtain an electronic copy of your electronic health record from a covered entity within fifteen (15) business days of a written request. Because Crystal Smile typically holds patient information only as a business associate of your dental practice, please direct medical-records requests to the dental practice that treats you. We will support that practice in fulfilling your request.
- Notice of data breach. If a breach involves your sensitive personal information, you will receive notice as required by Texas Business & Commerce Code § 521.053 — generally without unreasonable delay and no later than sixty (60) days after determination of the breach, except where law enforcement requires a delay.
- Identity-theft protections. We maintain reasonable safeguards required by the Texas Identity Theft Enforcement and Protection Act and dispose of records containing sensitive personal information in a manner designed to make the information unreadable or undecipherable.
- Marketing & sale of PHI. We will not use or disclose your PHI for marketing or sell your PHI without authorization, except as permitted by HIPAA and Texas HB 300.
- Complaints. You may file a complaint with us using the contact information below. You may also file a complaint with the Texas Attorney General, the Texas Health and Human Services Commission, or the U.S. Department of Health and Human Services Office for Civil Rights. We will not retaliate against you for filing a complaint.
13. Contact Us
If you have questions about this Privacy Policy or our practices, contact us at:
Crystal Smile Technology LLC
Austin Office: 11651 Jollyville Rd, Suite 100, Austin, TX 78759
Houston Office: 9630 Clarewood Dr A6, Houston, TX 77036
Phone: (800) 326-2276 | (281) 721-0348
Email: lab@crystalsmile.org (Austin) | tech.support@icodentalgroup.com (Houston)