OpenWide Privacy Policy (v1.0)
This policy applies to all individuals and organizations whose personal information is collected, used, or disclosed by OpenWide in connection with its platform and services.
1. Introduction
OpenWide is a dental patient experience platform operated by Marion LLB Inc., a corporation incorporated in Canada. The platform translates clinical visit notes into plain-language summaries delivered to patients through a secure web portal, extending the care relationship beyond the clinic and giving patients access to their dental information anytime, anywhere.
Marion LLB Inc. is committed to protecting the privacy of all individuals whose personal information it handles. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information and personal health information in connection with the OpenWide platform and any related services.
1.1 Governing Legislation
This policy has been developed in accordance with:
- the Personal Health Information Protection Act, 2004 (PHIPA) (Ontario);
- the Personal Information Protection and Electronic Documents Act (PIPEDA) (federal); and
- any applicable successor legislation, regulations, and guidance issued by the Information and Privacy Commissioner of Ontario (IPC) or the Office of the Privacy Commissioner of Canada (OPC).
1.2 Scope
This policy applies to:
- Patients who access the OpenWide portal to view their dental visit summaries and care communications;
- Dental practices (Subscribers) that subscribe to the OpenWide platform and use it to deliver information to their patients; and
- Visitors to openwidedental.ca.
This policy does not apply to the information practices of subscribing dental practices in their capacity as health information custodians under PHIPA. Practices are independently responsible for their own privacy obligations in relation to patient health records.
1.3 Version Control
This policy will be reviewed and updated at least annually, and whenever there is a material change to our data practices, a change in applicable law, or a significant change to the OpenWide platform. The current version and effective date are noted on the cover page of this document. Previous versions are available upon request by contacting hello@openwidedental.ca.
2. Definitions
In this policy, the following terms have the meanings set out below:
AI System means the artificial intelligence system integrated into the OpenWide platform that processes clinical visit notes to generate plain-language patient summaries.
Custodian has the meaning given to it under PHIPA and refers to a health information custodian, including a subscribing dental practice, that collects, uses, or discloses personal health information in the course of providing health care.
Data Controller refers to the party that determines the purposes and means of processing personal information. In the context of patient personal health information, the subscribing dental practice is the data controller.
Data Processor refers to the party that processes personal information on behalf of a data controller. OpenWide acts as a data processor with respect to patient personal health information that it receives from subscribing dental practices.
Patient means an individual who is a patient of a subscribing dental practice and who accesses or is the subject of information processed through the OpenWide platform.
Personal Health Information (PHI) has the meaning given to it under PHIPA and includes identifying information about an individual that relates to their physical or mental health, the provision of health care to the individual, or payment for health care.
Personal Information means any information about an identifiable individual, including but not limited to name, contact information, and account credentials, but excluding PHI where PHIPA applies.
Platform means the OpenWide dental patient experience platform, including the patient portal, the practice dashboard, and any associated software and services provided by Marion LLB Inc.
Subscriber or Practice means a dental practice that has entered into a subscription agreement with OpenWide.
Sub-processormeans a third-party service provider engaged by OpenWide to process personal information or PHI on OpenWide's behalf in connection with the delivery of the platform.
3. Information We Collect
3.1 Information Collected from Patients
When a patient accesses the OpenWide portal, we may collect the following categories of information:
- Identifying information: name, date of birth, and contact information (email address, phone number) provided by or on behalf of the patient;
- Portal credentials: username, password (stored in hashed form), and authentication tokens;
- Visit summaries: plain-language summaries generated from clinical notes provided to OpenWide by the subscribing dental practice;
- Communications: messages, responses, or other content submitted through the portal; and
- Usage data: device type, browser type, IP address, session duration, and activity logs generated during portal use.
3.2 Information Collected from Subscribing Practices
When a dental practice subscribes to the OpenWide platform, we collect the following categories of information:
- Practice details: practice name, address, and contact information;
- Authorized users: names, email addresses, and roles of dentists, hygienists, and administrative staff granted access to the platform;
- Clinical notes: visit notes and related clinical documentation submitted to the platform for processing by the AI system; and
- Subscription and billing information: contact details for billing purposes. Payment card and banking information is not stored by OpenWide directly and is handled by our payment processor.
3.3 Information Collected Automatically
When any user accesses the OpenWide platform or website, we automatically collect:
- Cookies and session tokens used to maintain authentication and platform functionality;
- IP addresses and approximate geolocation data;
- Browser and device information; and
- Activity and access logs for security and audit purposes.
We do not use advertising or targeting cookies. For further information on our cookie practices, see Section 10.
3.4 Data Minimization
OpenWide collects only the information necessary to provide the platform and deliver visit summaries to patients. Clinical notes submitted to the AI system are processed for the purpose of generating a plain-language summary and are not retained beyond the period described in Section 7. OpenWide does not collect or retain audio recordings of patient consultations.
4. How We Use Information
4.1 Use of Patient Information
We use patient information for the following purposes:
- Delivering plain-language visit summaries and care communications through the patient portal;
- Authenticating and managing patient portal access;
- Responding to patient support inquiries; and
- Maintaining audit logs for security and compliance purposes.
4.2 Use of Practice Information
We use practice information for the following purposes:
- Provisioning and managing platform subscriptions;
- Processing subscription billing and account administration;
- Communicating with practices regarding platform updates, maintenance, and product improvements; and
- Maintaining audit logs for security and compliance purposes.
4.3 Use for Platform Improvement
OpenWide may use de-identified and aggregated data derived from platform usage to improve the accuracy and performance of the AI system and the overall platform. De-identified data is information from which all identifying information has been removed such that there is no reasonable basis to believe that the information could be used to identify an individual. No personal information or PHI is used for model training or platform improvement without first being de-identified in compliance with applicable law.
4.4 Limitations on Use
OpenWide does not use personal information or PHI for any purpose other than those described in this policy or as otherwise authorized by the subscribing dental practice in accordance with PHIPA. OpenWide does not use personal information for advertising, marketing to third parties, or any commercial purpose unrelated to delivering the platform.
5. Legal Basis for Collection and Use
OpenWide's collection and use of personal information and PHI is grounded in the following legal bases:
- Consent: Patient consent to the collection and use of their PHI through the OpenWide platform is obtained by the subscribing dental practice at the point of care, in accordance with PHIPA. Practices are responsible for ensuring that valid, informed consent is obtained from patients prior to submitting clinical notes to the platform. OpenWide processes PHI only on the instruction of the subscribing practice as the custodian.
- Contractual necessity:OpenWide's collection and use of practice information is necessary to perform the subscription agreement between OpenWide and the subscribing practice.
- Legitimate interests: OpenWide processes usage and security data on the basis of its legitimate interests in operating a secure and reliable platform, preventing fraud, and maintaining system integrity.
- Legal obligation: OpenWide may collect, use, or disclose information to the extent required to comply with applicable law, including PHIPA, PIPEDA, and any order of a regulatory authority or court.
6. How Information Is Shared
6.1 With Subscribing Dental Practices
Patient PHI processed through the platform is accessible to the subscribing dental practice that submitted it. Practices access patient information solely in their capacity as the health information custodian under PHIPA.
6.2 With Sub-processors
OpenWide engages third-party service providers (sub-processors) to support the delivery of the platform. Sub-processors may process personal information or PHI on OpenWide's behalf in connection with the following functions:
- Cloud infrastructure and data hosting;
- AI processing: clinical visit notes are submitted to a third-party large language model (LLM) API for the purpose of generating plain-language summaries. PHI is processed by the LLM provider for this purpose. OpenWide takes contractual measures to restrict the LLM provider from retaining, training on, or otherwise using PHI beyond generating the requested output; and
- Payment processing.
A current list of sub-processors and their roles is available upon request. OpenWide enters into written data processing agreements with all sub-processors that impose obligations consistent with PHIPA, PIPEDA, and this policy.
6.3 Cross-Border Data Transfers
Some sub-processors, including the LLM API provider, may process data on servers located outside of Canada, including in the United States. Where PHI is processed outside Canada, OpenWide takes contractual measures to ensure that the information receives equivalent protection to that required under PHIPA, including data processing agreements that restrict use, require security safeguards, and prohibit retention beyond the purpose of processing.
Patients and practices should be aware that information processed outside Canada may be subject to the laws of the jurisdiction in which it is processed, including lawful access by government authorities in that jurisdiction. Subscribing practices are responsible for disclosing to patients any cross-border processing of their PHI in accordance with their own transparency obligations under PHIPA.
6.4 Legal Disclosure
OpenWide may disclose personal information or PHI to a regulator, law enforcement authority, or court where required to do so by applicable law, a court order, or a lawful demand, and only to the extent necessary to comply with that requirement. Where permissible, OpenWide will notify the affected practice prior to making such a disclosure.
6.5 No Sale of Information
OpenWide does not sell, rent, or trade personal information or PHI to any third party for any purpose, including advertising. This commitment is unconditional.
7. Data Retention
OpenWide retains personal information and PHI only for as long as necessary to fulfil the purposes described in this policy, subject to any longer retention period required by law.
- Clinical visit notes submitted for processing: deleted from OpenWide's systems following generation of the patient summary, subject to any residual retention required by applicable law or the terms of the subscription agreement.
- Patient portal accounts and associated visit summaries: retained for the duration of the practice's active subscription. Upon cancellation of a practice's subscription, patient portal data is retained and deleted in accordance with applicable health-record retention requirements under PHIPA (ten (10) years), subject to any legal hold obligations.
- Practice account and billing information: retained for the duration of the subscription and for a period of seven (7) years following termination, in accordance with applicable tax and commercial record-keeping requirements.
- Security and audit logs: retained on a rolling basis for a period of ninety (90) days, unless a longer period is required for an active investigation or legal obligation.
- De-identified and aggregated analytics data: may be retained indefinitely as it does not constitute personal information.
Where a practice or patient submits a deletion request, OpenWide will process that request in accordance with Section 9 and applicable law.
8. Security
8.1 Safeguards
OpenWide implements administrative, technical, and physical safeguards appropriate to the sensitivity of the information it holds, including:
- Encryption of PHI and personal information in transit using Transport Layer Security (TLS);
- Encryption of PHI and personal information at rest;
- Role-based access controls limiting access to personal information and PHI to authorized personnel only;
- Audit logging of access to and processing of PHI;
- Vulnerability management and patch management procedures; and
- Confidentiality obligations for all OpenWide personnel and contractors who access personal information or PHI.
8.2 AI System Oversight
OpenWide maintains human oversight processes over the AI system used to generate patient summaries. Specifically:
- Clinical notes are processed by the AI system solely for the purpose of generating a plain-language summary for the relevant patient;
- OpenWide monitors the AI system on an ongoing basis for accuracy, unexpected outputs, and potential bias;
- Where the AI system produces outputs that fall outside acceptable parameters, OpenWide has the ability to suspend or decommission the system and will notify affected practices; and
- Subscribing dental practices are contractually required to review AI-generated summaries for clinical accuracy before those summaries are disclosed to patients.
8.3 Breach Response
In the event of a privacy breach or suspected breach involving PHI, OpenWide will:
- Take immediate steps to contain the breach and determine its scope;
- Notify the affected subscribing practice at the first reasonable opportunity;
- Assist the practice in meeting its breach notification obligations under PHIPA, including notification to the IPC and affected individuals as required;
- Investigate the root cause of the breach and implement remedial measures to reduce the risk of recurrence; and
- Maintain a record of all breaches and their disposition.
OpenWide periodically tests its breach response procedures to ensure they remain effective.
8.4 Reporting Security Concerns
Any person who believes that their personal information or PHI may have been compromised in connection with the OpenWide platform is encouraged to contact OpenWide immediately at hello@openwidedental.ca. Subscribing practices are contractually required to notify OpenWide of any suspected breach at the first reasonable opportunity.
9. Your Rights
9.1 Rights of Patients
Patients whose PHI is processed through the OpenWide platform have the following rights, subject to applicable law:
- Access: the right to request access to personal information held by OpenWide about them in connection with their portal account;
- Correction: the right to request correction of inaccurate personal information held by OpenWide;
- Deletion: the right to request deletion of their portal account and associated personal information, subject to any legal retention obligations;
- Consent withdrawal: the right to withdraw consent to the collection, use, or disclosure of their PHI through the OpenWide platform. Withdrawal of consent must be communicated to the subscribing dental practice in the first instance, as the practice is the health information custodian. Patients who withdraw consent will continue to receive the same quality of dental care; consent withdrawal will not affect their entitlement to care; and
- Complaint: the right to file a complaint with the Information and Privacy Commissioner of Ontario (ipc.on.ca) or the Office of the Privacy Commissioner of Canada (priv.gc.ca) if they believe their privacy rights have been violated.
Note: Rights relating to the clinical health record (for example, access to or correction of the full dental record) rest with the subscribing dental practice as the health information custodian under PHIPA. Patients should contact their dental practice directly regarding such requests.
9.2 Rights of Subscribing Practices
Subscribing dental practices have the following rights in connection with their use of the OpenWide platform:
- Access and correction: the right to access and correct their practice account and billing information;
- Data export: the right to request an export of their practice data upon termination of the subscription;
- Breach notification: the right to be notified by OpenWide of any privacy breach that affects their patients' PHI; and
- Complaints: the right to raise concerns or complaints regarding OpenWide's privacy practices by contacting hello@openwidedental.ca.
10. Cookies and Tracking
OpenWide uses cookies and similar tracking technologies on the patient portal and the openwidedental.ca website. We use the following categories of cookies:
- Strictly necessary cookies: required for the portal to function, including session management and authentication. These cannot be disabled without affecting platform functionality.
- Functional cookies: used to remember user preferences and improve the portal experience.
- Analytics cookies: used to collect aggregated, de-identified data about how the platform is used, for the purpose of improving performance and functionality.
We do not use advertising, targeting, or third-party tracking cookies.
Users may manage cookie preferences through their browser settings. Disabling cookies beyond strictly necessary cookies may limit certain platform features.
11. Third-Party Services and Links
The OpenWide platform may contain links to the websites of subscribing dental practices or other third parties. OpenWide is not responsible for the privacy practices of those third-party websites. We encourage users to review the privacy policies of any third-party sites they visit.
Where OpenWide engages sub-processors to deliver platform functionality, those sub-processors are subject to data processing agreements as described in Section 6.2.
12. AI Governance
12.1 Our Commitment
OpenWide is committed to the responsible use of artificial intelligence in the delivery of its platform. The AI system used by OpenWide is designed and operated in accordance with the following principles:
- Accuracy: OpenWide takes reasonable steps to ensure that AI-generated summaries are accurate representations of the clinical information provided. The AI system is monitored on an ongoing basis for accuracy and performance;
- Human oversight: AI-generated summaries are subject to review by the subscribing dental practice before disclosure to patients. OpenWide personnel maintain oversight of the AI system's outputs and performance;
- Data minimization: clinical notes submitted to the AI system are processed solely for the purpose of generating a patient summary and are not used to train the AI model or for any other purpose;
- Bias awareness: OpenWide monitors the AI system for potential bias and takes steps to address any identified bias in the system's outputs; and
- Transparency: OpenWide discloses its use of AI in the delivery of the platform in this policy and in its communications with subscribing practices.
12.2 AI Accountability
OpenWide has designated an accountable individual within its leadership to oversee AI governance. This individual is responsible for:
- Maintaining an AI risk management framework appropriate to the scale and risk profile of the platform;
- Ensuring that personnel and contractors who work with the AI system are trained on their obligations regarding PHI and accurate outputs;
- Monitoring regulatory guidance issued by the IPC and other relevant authorities regarding AI in the health sector; and
- Reviewing and updating AI governance practices on a regular basis.
12.3 Practice Obligations Regarding the AI System
Subscribing dental practices are contractually required to:
- Obtain express patient consent prior to submitting clinical notes to the OpenWide platform for AI processing, in accordance with PHIPA;
- Inform patients about the use of AI in generating their visit summaries, including a description of the AI system's purpose, its limitations, and any risks associated with automated processing;
- Review all AI-generated summaries for clinical accuracy before those summaries are delivered to patients;
- Inform patients of their right to withhold or withdraw consent to AI processing without affecting the quality of their care;
- Maintain an up-to-date written public statement on their practice's use of AI systems, including OpenWide, in accordance with their obligations under PHIPA; and
- Notify OpenWide of any suspected privacy breach or unexpected AI output at the first reasonable opportunity.
13. Children's Privacy
The OpenWide platform is not directed at children under the age of 13. OpenWide does not knowingly collect personal information directly from children under 13. Where a patient is a minor, their PHI is handled through the subscribing dental practice. Consent for the collection and use of a minor's PHI is governed by PHIPA and applicable provincial law and must be obtained by the practice in accordance with those requirements.
14. Transparency Statement for Subscribing Practices
As part of their own transparency obligations under PHIPA, subscribing dental practices are required to maintain a written public statement disclosing their use of the OpenWide platform. OpenWide provides the following template language to assist practices in meeting this obligation. Practices should review and adapt this language to their specific circumstances with the assistance of their own legal counsel.
Template: Practice Public AI Disclosure Statement
Our practice uses OpenWide, a digital health platform operated by Marion LLB Inc. (openwidedental.ca), to generate plain-language summaries of your dental visit for delivery through a secure patient portal.
OpenWide uses an artificial intelligence system to translate clinical visit notes into patient-friendly summaries. Your clinical notes are submitted to a third-party AI provider for processing. That provider is contractually restricted from retaining or using your information for any purpose other than generating your summary. Some data processing may occur outside Canada, including in the United States.
Your consent to the use of OpenWide is obtained at the time of your appointment. You may withhold or withdraw consent at any time without affecting the quality of your dental care. If you have questions about your privacy rights or wish to withdraw consent, please speak with our front desk team.
For further information about OpenWide's privacy practices, please visit openwidedental.ca or contact hello@openwidedental.ca.
15. Changes to This Policy
OpenWide reserves the right to update this Privacy Policy at any time. Where changes are material, we will notify subscribing practices by email to their registered account address no fewer than 30 days before the changes take effect. For patients, updated policies will be posted on the OpenWide portal and on openwidedental.ca with the updated effective date prominently displayed.
Continued use of the platform following the effective date of an updated policy constitutes acceptance of the revised policy. If a subscribing practice does not accept the revised policy, it may terminate its subscription in accordance with the terms of its service agreement.
A version history of this policy is maintained and available upon request.
16. Contact and Complaints
16.1 Privacy Officer
Questions, access requests, deletion requests, and complaints regarding this policy or OpenWide's privacy practices should be directed to:
Privacy Officer
Marion LLB Inc., operating as OpenWide
Email: hello@openwidedental.ca
Website: openwidedental.ca
16.2 Submitting a Request
To submit an access, correction, or deletion request, please contact us at hello@openwidedental.ca with the subject line "Privacy Request." We will acknowledge your request within five (5) business days and respond within thirty (30) days, or as otherwise required by applicable law.
16.3 Regulatory Complaints
If you are not satisfied with OpenWide's response to your privacy concern, you have the right to file a complaint with:
Information and Privacy Commissioner of Ontario (IPC)
2 Bloor Street East, Suite 1400, Toronto, Ontario M4W 1A8
Tel: 416-326-3333 | Website: ipc.on.ca
Office of the Privacy Commissioner of Canada (OPC)
30 Victoria Street, Gatineau, Quebec K1A 1H3
Tel: 1-800-282-1376 | Website: priv.gc.ca