This is the current internal text while cofounder/legal review and missing operator/provider facts are completed. It is not an effective public policy.
Draft for cofounder and legal review — not approved for external use Updated: 26 September 2026
This notice explains how the operator of the NameN service ("NameN", "we", "us") handles personal data when an authorised representative of a dental clinic or other eligible business uses the service.
Before publication, this notice must identify the actual legal operator/controller, legal form, physical or registered address, applicable registration details, and the final provider/subprocessor list. Until then, support@namen.ai is the review-draft contact route only.
1. Scope
This notice covers the public website, free Quick Scan, customer account, paid Baseline, eligible Fix Pack, later Monitoring, support, billing, privacy requests, and the related internal administration tools.
The MVP is a business service. It is not intended for patients, children, or personal healthcare use.
2. Data we handle
Depending on the feature, we may handle:
- account and contact data, such as business email, authentication status, and service preferences;
- clinic and business data, such as domain, business name, address, city or metro, services, public profiles, and customer-confirmed facts;
- product inputs, support messages, attachments, corrections, and implementation markers;
- public-source and consumer-AI evidence about the business and visible competitors;
- reports, observations, citations, run metadata, QA history, and Monitoring history;
- purchase, invoice, subscription, refund, dispute, and payment-provider references, but not raw payment-card details;
- device, security, access, delivery, diagnostic, and limited analytics events;
- privacy-request, legal-acceptance, and deletion-audit records.
We obtain this information from the user, public business sources, consumer-facing AI services, our service providers, and our own product operations.
3. No patient data or PHI
Do not submit patient names, contact details, appointments, diagnoses, treatment information, insurance data, records, images, or any other patient-identifiable information or protected health information (PHI).
NameN does not request or use PHI, does not offer a Business Associate Agreement (BAA), and is not designed to act as a HIPAA business associate. If we confirm accidental receipt, we restrict access and delete or irreversibly redact the material as soon as reasonably possible, with an operational target of 72 hours. It is not used in a report, AI measurement, training, or other product processing.
4. Why we use data
We use the minimum data reasonably needed to:
- create and secure an account and deliver requested access;
- run, QA, correct, and deliver Quick Scans, Baselines, Fix Packs, and later Monitoring;
- establish clinic ground truth and produce evidence-linked comparisons;
- process orders, taxes, receipts, refunds, disputes, and subscription changes;
- answer support and privacy requests;
- prevent abuse, enforce the one-free-scan rule, protect accounts, and diagnose failures;
- measure product funnel, quality, cost, and reliability using minimised event data;
- comply with legal, accounting, tax, and dispute obligations;
- send mandatory service communications and, only with the required permission, optional marketing.
Where applicable, we rely on performance of a contract or steps requested before a contract, legitimate interests in operating and securing the service, legal obligations, and consent where consent is required. The final published notice must confirm the legal bases that apply to the actual operator and users.
5. Sharing and service providers
The selected MVP infrastructure providers are Supabase for authentication, product PostgreSQL, and private file storage in a dedicated GEO project; Vercel for the web/API runtime in a separate GEO project; and Postmark for authentication and other transactional email. Self-hosted Umami remains optional supplementary analytics in one portfolio analytics Vercel project and dedicated database shared with Collab Me Now, but outside both product databases. Each product and environment uses a separate Umami Website identifier and configuration boundary, and no customer report content or unrestricted form data enters analytics. The payment provider and exact measurement-surface roles remain to be finalised.
We disclose data only as necessary to provider categories such as:
- hosting, database, storage, authentication, and security;
- transactional email and support delivery;
- payment, invoicing, tax, refund, and dispute handling;
- privacy-respecting analytics and diagnostics;
- consumer AI and public-source measurement surfaces used for the requested report;
- professional advisers, authorities, or counterparties when legally required or necessary to establish or defend a claim.
We do not sell personal data. We do not use patient data. We do not provide customer report content to advertising networks. The final provider roles, locations, transfer safeguards, subprocessors, and deletion/export/backup behaviour must be published before launch.
6. International processing
The service is intended initially for US dental clinics. The selected primary GEO production regions are Supabase us-east-1 (East US, North Virginia) for product identity/data/files and Vercel iad1 (Washington, D.C.) for web/API Functions. Static delivery, provider support, email, analytics, payment, backups, subprocessors, and measurement services may involve other locations. Before launch, we will document the complete processor-region matrix and applicable transfer safeguards. Choosing England and Wales law for the service contract does not remove privacy rights or mandatory protections that apply elsewhere.
7. Retention
We apply purpose-specific periods:
| Record | Normal period |
|---|---|
| Free-only inactive account | Review after 12 months of inactivity; 30-day notice, then deletion if not reactivated |
| Paid account, delivered report, Monitoring history, and supporting evidence | While the account is open; no automatic paid-account deletion in the MVP |
| Active-system data after verified account deletion | Removed within 30 days, except listed legal/financial/minimal records |
| Duplicate captures, caches, and intermediate exports | Up to 30 days after delivery/QA |
| Privacy-export file/link | Up to 7 days, or first successful download where practical |
| Support messages | 24 months after closure |
| Support attachments | 30 days after the latest support response |
| Security/access logs | 180 days |
| Rate-limit, retry, idempotency, and abandoned-checkout traces | 30 days |
| Transactional-email delivery/bounce/complaint metadata | 180 days |
| Event-level analytics | 180 days, then deletion or irreversible aggregation |
| Payment, invoice, tax, refund, dispute, and chargeback records | 7 years after the later of transaction or account closure |
| Contract, order, accepted-policy version, and material-consent records | 6 years after the contract or order ends |
| Completed privacy-request correspondence | 3 years |
| Minimal deletion audit | 6 years |
| Sanitised security or accidental-PHI incident record | 3 years after closure |
| Provider rolling backups | Maximum 30 days |
A shorter mandatory period controls. A documented legal hold may extend only the affected record. Genuinely anonymous aggregate measurements may be retained without a fixed expiry. The detailed operational schedule is maintained in DATA-RETENTION-AND-DELETION-SCHEDULE.md.
8. Your choices and rights
The account Privacy Center provides Export my data and Delete my account. Verified deletion is irreversible and has no recovery window. It removes account access, contact data, business inputs, personal reports, and Monitoring history, while retaining only the minimum lawful financial, contract, fraud, dispute, opt-out, and deletion-audit records described above.
Depending on applicable law, a person may request access, correction, deletion, portability, restriction, or information about processing, and may object to or withdraw consent for certain uses. Marketing can be unsubscribed from without disabling mandatory security, billing, privacy, or paid-delivery messages. We will not discriminate against a person for making a valid privacy request.
Requests may be sent to support@namen.ai. We may verify identity and authority before acting. The final notice must identify any regulator or appeal route required for the actual operator and jurisdiction.
9. Security
We use access controls, scoped provider credentials, encryption in transit, audit trails, environment separation, minimised logs, backups, and testing appropriate to the service. Supabase product tables and private Storage buckets require least-privilege grants and tested Row Level Security; privileged keys remain server-side. No system is perfectly secure. A customer must protect its access links and notify us promptly of suspected misuse.
10. Cookies and analytics
Strictly necessary storage may support security, authentication, checkout, and requested service operation. Non-essential analytics or similar storage remains disabled until any required consent is obtained. Details are in the Cookie and Analytics Notice.
11. Changes
We may update this notice when the service, providers, or law changes. Material changes are brought to users' attention before the new use begins where required. We retain the accepted notice version and timestamp for relevant account and order events.
12. Contact
Draft contact: support@namen.ai
Release blocker: add the actual operator/controller legal name and physical or registered address before external use.