BondedAI LLC and Bonded Payments Pty Ltd – Privacy Policy
BondedAI LLC ("BondedAI", "we", "our", "us") and its Australian subsidiary Bonded Payments Pty Ltd (together, "Bonded") develop payment‑processing software and related services used by dental clinics and their patients. Our Australian office is Level 7, King William St, Adelaide SA 5000, Australia, and our U.S. headquarters is 1100 South Coast Hwy, Laguna Beach CA 92651, USA.
This Policy explains how we collect, use, disclose and protect personal information, including Protected Health Information ("PHI"), across the three main jurisdictions in which we operate or store data:
Where a section applies only to a particular jurisdiction we label it [AU], [US] or [UK]; otherwise it applies globally.
| Category | Examples | Legal basis / APP principle |
|---|---|---|
| Personal identifiers | Name, postal address, email, phone, date of birth, profession | APP 3; HIPAA §164.502; GDPR Art 6(1)(b) (contract) |
| Health & treatment data | Appointment details, treatment plans, clinical notes, XRays [AU & US] | APP 3–4 (health information); HIPAA PHI; GDPR Art 9(2)(h) (healthcare) |
| Payment data | Tokenised card details, PayTo mandate IDs, Direct‑Debit bank account numbers (masked) | PCI‑DSS; APP 11; GDPR Art 6(1)(f) (legitimate interest) |
| Technical & usage data | IP address, device/browser, cookies, log files, support tickets | APP 3; GDPR Art 6(1)(f) |
We collect information directly from clinics, patients or their authorised representatives, via online forms, APIs, secure file upload and during live onboarding calls.
Bonded offers two mobile applications: BondedAI (com.bonded.doctor), a practice management app for orthodontic practitioners, and OrthoHub (com.bonded.patientapp), a patient‑facing app for orthodontic patients. Both apps are available on iOS and are subject to this Privacy Policy.
| Data type | Purpose | Storage |
|---|---|---|
| Camera & photos | Capture clinical photos for treatment records (BondedAI); upload profile or treatment‑related images (OrthoHub) | Uploaded to Supabase storage; not stored locally after upload |
| Push notification token | Deliver appointment reminders, treatment updates and other transactional notifications | Expo Push Token stored server‑side; associated with user account |
| Session credentials | Authenticate and maintain user sessions | Stored locally on device using Expo SecureStore (encrypted keychain storage) |
The apps request only the permissions necessary for their function. Camera access is requested at the time of use and can be revoked at any time in your device settings. Push notification permission is optional; declining will not affect core app functionality.
Our mobile apps integrate the following third‑party services:
These services process data in accordance with their own privacy policies. We do not share personal information with third‑party advertisers or analytics providers through the mobile apps.
We never sell or rent personal information.
We operate as a Business Associate to dental providers (Covered Entities). We sign Business Associate Agreements, implement the Security & Privacy Rules and restrict PHI use to HIPAA‑permitted purposes. De‑identified data follows §164.514(b). Breach notifications are issued within 60 days under §164.404.
We disclose data only to:
We do not sell personal data for monetary consideration as defined under CPRA.
| Jurisdiction | Rights |
|---|---|
| Australia | Access & correction (APP 12‑13); complain to OAIC |
| United States (HIPAA) | Access PHI, request amendment, accounting of disclosures |
| California & other US states | Access, deletion, opt‑out of "sharing" |
| United Kingdom | Access, rectification, erasure, restriction, data portability, objection, complain to ICO |
To exercise any right, email privacy@bondedpayments.com. Identity verification is mandatory.
We use strictly‑necessary cookies for authentication and session management and optional analytics cookies (Google Analytics 4) with IP‑anonymisation. Where required (UK/EEA) we display a cookie banner seeking opt‑in consent.
Our services are not directed to individuals under 13. If we learn we have collected personal information from a child without parental consent, we delete it.
Our website may link to third‑party sites. We are not responsible for their privacy practices.
We will post any changes on this page and, where material, provide 30 days' notice via email or in‑app banner.
Privacy Officer – Nicholas Duncan
Email: privacy@bondedpayments.com
Phone: +1 (949) 339‑6557
Postal: Level 7, King William St, Adelaide, SA, 5000, Australia
If you are not satisfied with our response you may contact: