Last Updated: January 22, 2026
At Mala Group LLC ("Mala," "we," "us," or "our"), we are committed to protecting the privacy and security of your information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our AI-powered dental support platform (the "Service").
This Privacy Policy applies to information we collect through our website, software applications, and services. Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
We collect several types of information from and about users of our Service, including:
Account Information: When you register for an account, we collect:
Communications Data: When you use our communication features, we collect:
Protected Health Information (PHI): As a Business Associate under HIPAA, we process PHI on your behalf, including:
Usage Information: We automatically collect information about how you use the Service:
Cookies and Tracking Technologies: We use cookies, web beacons, pixels, and similar tracking technologies to:
We may receive information from third-party sources, including:
We use the information we collect for the following purposes:
When you use our SMS features to communicate with patients:
When you use our email features:
We act as a "Business Associate" under the Health Insurance Portability and Accountability Act (HIPAA). We enter into a Business Associate Agreement (BAA) with each customer, which governs our handling of Protected Health Information (PHI).
We use and disclose PHI only as permitted by the BAA and HIPAA regulations:
We implement appropriate administrative, physical, and technical safeguards to protect PHI, including:
We do not sell your personal information or PHI. We may share your information in the following circumstances:
We share information with third-party vendors who perform services on our behalf:
These service providers are bound by contractual obligations to keep information confidential and use it only for the purposes we specify. Where applicable, we enter into BAAs with service providers who handle PHI.
With your authorization, we integrate with and share data with your chosen PMS to provide scheduling and patient management functionality.
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction.
We may disclose information if required to do so by law or in response to:
We may share information with third parties when you explicitly consent to such sharing.
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
| Type of Data | Retention Period |
|---|---|
| Account Information | Duration of account plus 7 years |
| PHI and Patient Communications | As required by HIPAA and state law (typically 6-7 years after last activity) |
| Billing and Payment Records | 7 years from date of transaction |
| Usage and Log Data | 90 days to 2 years depending on type |
| Marketing Communications | Until you opt out or close your account |
After the retention period expires, we securely delete or anonymize your information. In some cases, we may retain aggregated or de-identified data indefinitely for analytical purposes.
We implement industry-standard security measures to protect your information from unauthorized access, alteration, disclosure, or destruction. Our security practices include:
While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
You have the right to access and update your account information at any time through your account settings or by contacting us.
You can export your data from the Service at any time. We provide tools to download your information in common formats.
You can request deletion of your account and associated data by contacting us. Note that we may retain certain information as required by law or for legitimate business purposes.
You can opt out of marketing emails by clicking the unsubscribe link in any marketing email or adjusting your account settings. You cannot opt out of transactional or service-related communications.
You can control cookies through your browser settings. Note that disabling cookies may limit your ability to use certain features of the Service.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
You have the right to request information about the personal information we collect, use, and disclose about you.
You have the right to request deletion of your personal information, subject to certain exceptions.
You have the right to opt out of the "sale" or "sharing" of your personal information. We do not sell personal information and do not share it for cross-context behavioral advertising.
We will not discriminate against you for exercising any of your privacy rights.
To exercise your California privacy rights, contact us at hellomalagroup@gmail.com. We will verify your identity before processing your request.
The Service is operated from the United States. If you are located outside the United States, your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to this transfer.
We implement appropriate safeguards for international data transfers, including standard contractual clauses where applicable.
The Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us immediately.
Note: We may process PHI related to minor patients as part of providing services to dental practices, but this is done on behalf of the practice as a Business Associate under HIPAA.
The Service may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you access.
Some browsers support "Do Not Track" signals. Currently, our Service does not respond to Do Not Track signals.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:
Your continued use of the Service after changes become effective constitutes your acceptance of the revised Privacy Policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Mala Group LLC
Privacy Officer
1 West St, New York, NY 10004
Email: hellomalagroup@gmail.com
By using the Service, you consent to the collection, use, and sharing of your information as described in this Privacy Policy.
This Privacy Policy is effective as of the Last Updated date above. We are committed to protecting your privacy and handling your information with care and transparency.