Privacy

Patient trust, engineered in.

Lumexa answers phone calls for US dental practices. That means we handle voice, names, appointment details, and — sometimes — clinical context. This page explains what we collect, why, and the controls that surround it.

Last updated: August 1, 2026. This page is maintained by Lumexa to answer common privacy questions about our AI receptionist and dashboard.

What we collect

  • Call audio and AI-generated transcripts of after-hours calls routed to Lumexa.
  • Caller-provided information: name, phone number, reason for calling, and any details needed to book an appointment.
  • Practice-configured data: hours, providers, services, booking rules, and PMS credentials the practice chooses to connect.
  • Product usage data from practice staff who sign in to the Lumexa dashboard (email, login events, feature usage).

Why we collect it

  • To answer calls, triage urgency, and book appointments the caller is asking for.
  • To write appointments into your practice management system (Dentrix, Open Dental, Eaglesoft) when you connect one.
  • To produce transcripts, reason-for-call analysis, and reporting inside your practice dashboard.
  • To improve reliability, detect abuse, and support your team when you request help.

How patient information is handled

Lumexa is designed to be HIPAA-conscious. Call recordings and transcripts are treated as protected information: they are encrypted in transit, access-controlled, and only visible to authorized users at your practice and to a small number of Lumexa staff who need access to operate the service. A Business Associate Agreement (BAA) is available to practices before production use.

We do not sell patient information. We do not use identifiable patient data to train third-party models.

Retention & deletion

  • Call audio and transcripts are retained for the period configured for your practice; the default is designed for operational review, not indefinite storage.
  • Practice administrators can request deletion of specific calls, transcripts, or the entire practice's data at any time.
  • Account closure triggers deletion of practice data on a defined schedule, subject to legal or backup-cycle constraints.

Subprocessors & integrations

Lumexa relies on a limited set of infrastructure and AI providers to run the receptionist and dashboard (for example: cloud hosting, telephony, speech, and large language model providers). Each is selected for its security posture and the availability of a BAA where patient data may be processed. A current subprocessor list is available on request.

Your rights & requests

Patients whose calls were handled by Lumexa can contact the dental practice they called; the practice is the data controller for those calls. Practices can contact us directly for access, correction, export, or deletion requests, or to sign a BAA.

Cookies & analytics

Our marketing site uses minimal cookies necessary for the site to function and, where applicable, privacy-respecting analytics to understand aggregate traffic. The practice dashboard uses cookies required for authentication and session security.

Changes to this policy

We update this page as the product evolves. Material changes will be communicated to practice administrators via the dashboard or email before they take effect.

This page describes Lumexa's practices in plain language. It is not a certification and does not create a legal contract. Practices should review the Business Associate Agreement and any signed order form for the terms that apply to their engagement.