ZenHub Services
Privacy Policy
// Last updated May 13, 2026
ZenHub Services LLC ("ZenHub", "we", "us", "our") operates zenhubservices.com (the "Site") and provides managed dental front-office and revenue-cycle services ("Services") to U.S. dental practices. This Privacy Policy explains what information we collect, why we collect it, how we use and share it, the choices you have, and the rights you may exercise.
// Contents
- Scope & relationship to our clients
- Information we collect
- How we collect information
- How we use information
- Legal bases for processing
- When and with whom we share information
- SMS & mobile messaging privacy
- Protected Health Information (HIPAA)
- Retention & deletion
- Security safeguards
- Cookies, tracking & analytics
- Your rights (incl. CA, VA, CO, CT, UT, TX residents)
- Children's privacy
- International users
- Changes to this Policy
- Contact us
1. Scope & relationship to our clients
This Policy applies to information we collect from visitors to the Site, prospective clients, current clients, vendors, and employees or contractors of dental practices we work with. We act in two distinct capacities:
- Controller of personal information we collect directly through the Site (e.g. contact-form submissions, business email, phone number, IP address).
- Business Associate / processor of Protected Health Information ("PHI") and other client data we process on behalf of dental practices under a Business Associate Agreement ("BAA") and master Service Agreement.
Where we act as a Business Associate, the dental practice's own privacy notice governs the relationship with its patients. Patients should direct PHI-related requests to their dental practice.
2. Information we collect
2.1 Identifiers & contact details
- Name, business email, phone number, practice name, role / title.
- Mailing address (when provided for an engagement).
2.2 Commercial & engagement data
- Information about your practice (location, size, PMS in use, payer mix) and the services you inquire about.
- Records of communications with us (emails, call notes, support requests).
- Credentials and access tokens for PMS, payer portals, and phone systems, stored encrypted.
- Insurance contract documents, fee schedules, provider credentialing files provided during onboarding.
2.3 Operational data generated by the Services
- Claims filed, verifications completed, payment posting records, AR notes, and internal communication logs.
2.4 Internet activity
- IP address, device type, browser, operating system, referrer, pages viewed, time on page, approximate location at city level.
- Cookies and similar technologies (see section 11).
2.5 Protected Health Information (PHI)
When acting as a Business Associate, we process PHI on behalf of the dental practice. See section 8 and our HIPAA Notice.
3. How we collect information
- Directly from you when you complete a form, send us an email, call us, or sign an agreement.
- Automatically through cookies, analytics, and server logs as you use the Site.
- From our clients when they share data we need to perform the Services (PMS credentials, payer contracts, patient records).
- From third-party sources such as payers, clearinghouses, public business registries, and credentialing databases (e.g. CAQH).
4. How we use information
We use information to:
- Respond to inquiries and provide quotes;
- Deliver, support, and improve the Services under our agreements with clients;
- Operate, secure, and monitor the Site and our systems;
- Detect, investigate, and prevent fraud, abuse, and security incidents;
- Comply with legal obligations and enforce our agreements;
- Send transactional and service-related communications;
- Where permitted, send marketing communications about our Services (you may opt out at any time).
We do not sell personal information for money. We do not use PHI for marketing.
5. Legal bases for processing
For visitors located in jurisdictions that require a legal basis, we rely on (i) your consent, (ii) performance of a contract with you or your practice, (iii) our legitimate interests in operating and improving the Site and Services, and (iv) compliance with legal obligations. You may withdraw consent at any time by contacting us.
6. When and with whom we share information
We share information only as described below, and never sell it:
- Sub-processors bound by written confidentiality and, where PHI is involved, BAAs — including hosting providers, email and meeting platforms, encrypted communication tools, and analytics providers.
- Our managed specialist team — a dedicated channel manager and trained specialists — operating under HIPAA-compliant protocols, role-based access, and audit logging.
- Professional advisors (lawyers, accountants, auditors) under confidentiality.
- Business transfers — in the event of a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections and continued application of this Policy or an equivalent one.
- Authorities when required by law, subpoena, or other valid legal process, or to protect rights, safety, and property.
7. SMS & mobile messaging privacy
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
SMS consent is not shared with third parties or affiliates.
8. Protected Health Information (HIPAA)
Our handling of PHI is governed by HIPAA and the BAA we sign with each dental practice. We use and disclose PHI only as permitted by the BAA, to perform the Services, for our own management and administration as a Business Associate, and as otherwise permitted by law. Patients should direct PHI requests to their dental practice; if a practice routes such a request to us under the BAA, we respond on its behalf within the timelines required by law. See our HIPAA Notice for the full disclosure.
9. Retention & deletion
We retain personal information only as long as needed for the purposes for which it was collected, plus any legally-required retention period. Specific guidelines:
- Marketing-form submissions: up to 24 months from last interaction.
- Engagement records (non-PHI): duration of the engagement plus 6 years.
- PHI: retained and disposed of per the BAA and applicable retention laws.
- Backups and logs: retained for limited periods then securely destroyed.
You may request deletion of personal information that is not subject to a legal retention requirement (see section 12).
10. Security safeguards
We implement administrative, technical, and physical safeguards designed to protect personal information and PHI, including:
- Encryption in transit (TLS 1.2+) and at rest where supported by the underlying system;
- Role-based access controls and least-privilege provisioning;
- Multi-factor authentication on all team accounts;
- Audit logging on all account access;
- Background-checked personnel and HIPAA training renewed annually;
- Documented incident response and breach-notification procedures.
No system is perfectly secure. In the event of a confirmed breach of unsecured PHI, we follow the breach-notification timelines required by HIPAA and the applicable BAA.
11. Cookies, tracking & analytics
The Site uses a small number of cookies and similar technologies to remember your preferences and to measure traffic via privacy-respecting analytics. You can disable cookies via your browser settings. Disabling cookies will not prevent you from using the Site, but some functionality may be limited.
We honor Global Privacy Control (GPC) signals as a request to opt out of "sharing" or "selling" personal information where applicable under state law.
12. Your rights
Depending on your state of residence, you may have one or more of the following rights:
- Access — receive a copy of the personal information we hold about you;
- Correction — request that we correct inaccurate personal information;
- Deletion — request that we delete personal information (subject to legal retention requirements);
- Portability — receive your information in a portable, machine-readable format;
- Opt out — opt out of marketing communications and of any "sale" or "sharing" of personal information (we do not sell personal information).
These rights are available, with varying scope, to residents of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and other states with comprehensive privacy laws. To exercise a right, email privacy@zenhubservices.com. We will verify your identity before responding. You may also designate an authorized agent. We will not discriminate against you for exercising your rights.
California "Shine the Light": California residents may request information about disclosures of personal information to third parties for direct-marketing purposes. We do not make such disclosures.
13. Children's privacy
The Site is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe we have collected information from a child, contact us so we can promptly delete it.
14. International users
The Site and Services are intended for U.S. dental practices. If you access the Site from outside the United States, you understand that your information will be processed in the United States, which may have different data-protection laws than your country of residence.
15. Changes to this Policy
We may update this Policy from time to time. We will post the new Policy on this page and update the "Last updated" date. Material changes will be communicated by additional notice (e.g. via email or a prominent Site notice).
16. Contact us
ZenHub Services LLC
Frisco, TX, United States
Privacy inquiries: privacy@zenhubservices.com
General inquiries: sales@zenhubservices.com · 346-537-0020