Privacy Policy

Effective date: 25 September 2025

This Privacy Policy explains how Smile Magic Dentistry (“Smile Magic,” “we,” “us,” or “our”) collects, uses, and shares information when you visit smilemagicdentistry.com (the “Site”) or contact us. This Policy covers website and marketing data. It does not govern your medical/dental records or other “protected health information” (PHI). For PHI, please see our HIPAA Notice of Privacy Practices (the “NPP”).  

If you have questions or want to exercise your privacy rights, contact us at info@smilemagicdentistry.com or the phone numbers listed in Section 13.  

1) Who we are

We operate three locations in Orange County, California:

  • Anaheim Hills: 505 Villa Real Dr., Suite 101-B, Anaheim Hills, CA 92807 • (714) 974-4332
  • Newport Beach: 601 Dover Dr., Suite 12, Newport Beach, CA 92663 • (949) 650-0222
  • Placentia: 300 Yorba Linda Blvd., Suite C, Placentia, CA 92870 • (714) 528-3383.  

2) What this Policy covers vs. HIPAA

  • This Policy applies to information collected via our website, emails, calls, contact/booking forms, and marketing.
  • HIPAA/PHI: If you become a patient or submit health information, those records are handled per our HIPAA Notice of Privacy Practices (NPP). Please review the NPP (posted on the Site) to learn how we use/disclose PHI and your HIPAA rights.  

3) Information we collect

A) Information you provide

  • Contact & appointment requests (e.g., name, email, phone, preferred office, preferred appointment date, and your message). Our contact page includes a form and a CAPTCHA to prevent spam.  
  • Patient forms & documents. If you download, complete, or return patient forms (e.g., registration, HIPAA consent), you may provide identifiers and health-related details. Once tied to your care, that information is handled under the HIPAA NPP.  

B) Information collected automatically

  • Device & usage data such as pages viewed, links clicked, approximate location (derived from IP), and browser type, collected through cookies, pixels, and similar technologies.
  • Anti-abuse/anti-spam data (e.g., CAPTCHA tokens). Our contact page includes a CAPTCHA.  
Note: We may update our analytics or anti-spam providers over time. See Section 7 for how third-party tools may process your data.

4) How we use information

We use information to:

  • Provide and improve the Site and our services;
  • Respond to inquiries, schedule and confirm appointments;
  • Send administrative messages (e.g., confirmations, policy changes);
  • Detect, prevent, and address spam or security issues;
  • Comply with legal obligations.

PHI is used and disclosed per the HIPAA NPP (for treatment, payment, and healthcare operations, among other permitted purposes).  

5) Legal bases (EEA/UK visitors)

Where applicable law requires, we rely on consent, contract, legitimate interests (e.g., site security, service improvement), and legal obligations. You can withdraw consent where we rely on it.

6) Cookies & similar technologies

We use cookies and similar technologies to operate the Site, measure performance, and enhance user experience. You can control cookies via your browser settings. Blocking certain cookies may affect site functionality.

7) How we share information

We may share website-collected information with:

  • Service providers/“processors” (e.g., website hosting, email, security/anti-spam such as CAPTCHA) under contracts requiring them to protect your data and use it only for our instructions. The contact page shows CAPTCHA is in use.  
  • Professional advisors (law, accounting) under confidentiality;
  • Authorities when required by law, to protect rights, safety, and security;
  • Successors in the event of a business transaction (e.g., merger), consistent with applicable law.

We do not sell your personal information and do not share it for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (as amended by CPRA). If that ever changes, we will update this Policy and provide required opt-out mechanisms.

PHI may be shared as permitted by HIPAA (see NPP).  

8) Retention

We keep website-collected information as long as needed for the purposes in this Policy (e.g., to respond to you, maintain security), and as required by law. Patient records and PHI are retained per healthcare and HIPAA requirements—see the NPP for details.  

9) Your choices

  • Marketing: You can opt out of non-transactional emails by using unsubscribe links or contacting us.
  • Cookies: Use your browser settings to manage cookies.
  • Do Not Track: We do not respond to DNT signals due to industry standards variability.

10) California privacy rights (CCPA/CPRA)

Notice at collection – categories & purposes

We may collect the following categories of personal information from website visitors and prospective patients:

  • Identifiers (e.g., name, email, phone), customer records (e.g., messages you send), internet/usage data (e.g., page views), and approximate location (derived from IP).
  • Sources: Directly from you (forms, calls, emails) and automatically via your device when you use the Site. The contact page shows the fields we request.  
  • Purposes: Operate the Site, respond to inquiries, schedule appointments, maintain security, comply with law.
  • Sensitive information: We do not seek sensitive personal information from website visitors. If you submit health information as part of care, that is PHI governed by HIPAA and our NPP.  
  • Retention: See Section 8.
  • Selling/Sharing: We do not sell or share personal information for cross-context behavioral advertising.

Your CPRA rights

California residents can request to know, access, correct, or delete personal information (subject to legal exceptions) and limit use/disclosure of sensitive information. We will not discriminate against you for exercising your rights.

How to submit a request: Email info@smilemagicdentistry.com or call (714) 974-4332 or (949) 650-0222. We will verify your request as required by law. Authorized agents may submit requests with proof of authority.  

11) Children’s privacy

The Site is not directed to children under 13. We do not knowingly collect personal information from children under 13 through the Site. If you believe a child provided us information online, contact us and we will take appropriate action.

12) Security

We use administrative, technical, and physical safeguards appropriate for the nature of the information we handle. For PHI, additional safeguards apply under HIPAA—see the NPP.  

13) How to contact us

Email: info@smilemagicdentistry.com

Phone: (714) 974-4332 • (949) 650-0222

Mail/In-person: see our locations in Section 1.  

For questions or complaints about PHI privacy specifically, please consult and use the contact information in our HIPAA Notice of Privacy Practices.  

14) Third-party links

Our Site may link to third-party sites and services (e.g., maps, social media). We are not responsible for their privacy practices. Review their policies before providing personal information.  

15) Changes to this Policy

We may update this Policy from time to time. Changes take effect when posted on the Site. Your continued use of the Site after changes become effective means you accept the revised Policy.