Last Updated: 30 October 2018
While 6MS is the controller of personal data that you provide through the website about yourself, we are the data processor for information shared with us by your Provider for the purposes of providing you with our services. In such instances, your Provider is the controller of your data, and we store and process your personal data on behalf of your Provider. We only process the personal data shared by your Provider based on clearly defined instructions from your Provider.
Our legal bases for processing your personal data include your consent, fulfillment of a contractual obligation, and where we have a legitimate interest to process your personal data, provided that our interests do not outweigh your individual rights and freedoms. Our legitimate interests include:
Where we rely on your permission to process your personal data, you have the right to change, withdraw, or withhold your consent.
We collect personal data that you choose to share with us, as well as information provided directly by your browser or device when you visit our website. If you are a patient receiving short-term orthodontic care with 6MS products and/or services, we also collect personal data from your Provider.
Personal Data Collected from You
Emails and Communications
When you send an email or other communication to 6MS, we ask for your name, phone number, and email address, and, if you are a dentist or dentist practice, we will collect your practice name and practice address. We also collect the content of your message or submission to us, which contains any additional information you choose to share with us.
We collect this information when you initiate contact with us for the purpose of responding to your email or other communications. If you have a registered Business Account, we will document this communication to your account for reference, as well as future informational and promotional communications.
Search for a Provider
When you use our “Find a Doctor” feature on our website, we will ask you to input either your zip code or a keyword to help narrow your search (e.g., Provider name, city, street name). We collect this information, upon your request, to enable our search feature to provide you with information on Providers nearest to you.
Inquire About Candidacy
When you choose to submit information via our “Am I a Candidate” form, we will collect your first name, email address, and zip code. You also have the option of providing your last name. We use this information to provide you with information about 6MS dentists near the zip code you provided, and, if you consent to receive additional communications from us, we will also use this information to deliver that requested content.
In addition to this information, we ask you to answer a few simple questions regarding your teeth and your reason for potentially seeking treatment. We collect this information to understand the type of treatment you are seeking and to tailor any subsequent communications with you.
If you choose to download one of our informational guidance documents, we will collect your name and email address. We will also ask you to answer one or two questions about your potential use of or interest in our products.
If you identify yourself as a dentist or dental practice and choose to download our dentist guide, we will also ask you for additional information, including your practice address, personal or office telephone number, country, and state (if in the United States). We also collect information regarding your potential use of or interest in our products via questions contained at the bottom of the submission form. We collect your contact information to update you on new product innovation and, if applicable, upcoming seminar availability. Additionally, we use your responses to our questions to ensure the content we deliver to you is of the highest relevancy. We only collect this information upon your consent, and you can change or withdraw your consent at any time.
Register for a Training Seminar (Providers Only)
To offer 6MS products and services to your patients, you must complete one of our training courses. When you choose to register for a training course, we will ask you to provide your name, practice name, practice address, practice and personal telephone numbers, email address, and orthodontic treatment experience. We also ask you for payment information, including credit card and billing address, to pay for and complete your training course registration.
We collect this information for the purpose of registering you for our training course and completing our transactions with you.
Register for Provider Resource Center Account (Providers Only)
After successfully completing one of our training courses, you will be asked to create a Provider Resource Center Account. As part of creating your account, we collect your name, practice name, practice address, practice telephone number, email address, practice website URL, email subscription preferences, and account username and password. We also will collect payment information, such as credit card and billing address, to process payment and complete transactions initiated through the Provider Resource Center.
We collect this information to provide you with access to our Provider Resource Center, which enables you to submit cases, order tools and supplies, submit a course re-attendance order, and access our Provider Resource Center Knowledge Base and our Six Month Smiles Forum.
Create a Provider Profile (Providers Only)
If you provide 6MS products and services to patients, you will be able to customize your practice’s profile page on our website, which will include your name and the practice information you submitted when registering for a training seminar. You also have the option of providing supplemental information about your practice, including the names of additional practitioners, alternative contact information, insurance plans accepted, and business hours. Any information you choose to provide is done at your discretion, and you can modify or delete this supplementary information at any time.
Submit a Case (Providers Only)
If you are a Provider submitting a case to us, we will collect patient first and last name, age and gender; case-supporting patient photographs and radiographs; and your stated prescription elements necessary to create the custom appliance for patient treatment.
We use this information to create the appropriate custom 6MS appliance for patient treatment and, in the case of CONFIDEX™, devise a customized treatment plan for the application of the 6MS product.
Participate in Community Platforms (Providers Only)
When you participate in our Six Month Smiles Forum, we collect name, practice name, address, phone number, and email address. We also collect the content of your messages shared through the Forum, which may contain any additional information, including personal data, you choose to share.
We only collect this information when you choose to use the Forum for the purpose of facilitating the interactive discussion features of the Forum and to provide access to feedback from peers and our independent Six Month Smiles Clinical Instructors and Mentors.
Browser or Device Information
We automatically receive and record information on our server logs from your browser, including your IP address, 6MS cookie information, and the page(s) you request. We collect this data for the following general purposes:
We also collect your IP address(es) for the purpose of analyzing website trends, administering the site, and tracking user movement for aggregate usage analysis. This website usage information enables 6MS to provide our users with an ever-improving site, service, and general offering. Except where you have provided consent for us to use your identifiable personal data, we only use anonymous, aggregate data that cannot be used to identify you individually for our analytics research.
Cookies and Web Beacons
We may set and access 6MS session cookies on your computer to customize the user experience. “Cookies” are small files placed on your computer by your browser and are often used to make websites work, as well as provide information to the website operator.
Communications you receive from us, as well as pages of our website, may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags and single-pixel gifs) that enable us to analyze email and website statistics, including visits and click-through rates. The web beacons only collect aggregate, anonymous data and cannot be traced back to you individually.
Third-Party Cookies and Web Beacons
We use Facebook Pixel to help us track the effectiveness of our advertising by reporting on the actions users take after viewing our advertisements displayed on Facebook. No personal information is contained or collected as a result of these pixels.
We collect information, such as email address and social media user or account name (“social media handle”), content and other data, you allow to be shared through our social media applications, tools, widgets, and plug-ins. If you choose to post information directly to any of our official social media platforms, we will collect any personal data you choose to include in your post, such as your name, location, and photograph(s). We will also collect the social media handle associated with the social media account you use to post to our official social media platforms. Please note that by opting to upload content to our official social media platforms, depending on your security settings, any personal information you include in your post may be viewed by other visitors to our official social media platforms, which may include people you do not know.
If you submit a form to 6MS through Facebook, we collect your name, phone number, address, email, and any additional information you choose to share in the form. This information is provided with your consent when you submit the form. We use this information to respond to your requests, as well as to provide you with future informational and promotional materials.
Additionally, if you share photographs, comments, or reviews related to 6MS services and products on your personal social media platforms or participate in a 6MS social media campaign, we may also ask you for your permission to repost or share your content on our official website and social media platforms, including Facebook and Instagram. When you consent to our use of this information, we will collect and repost any personal data you included in your original post, such as your name, location, and photograph(s). We will also collect the social media handle associated with the social media account to which you posted the content. We use this information for the purpose of sharing your content and 6MS experiences with visitors of our website and social media platforms.
Certification Course Registration (Providers Only)
If you are registered by someone in your practice to attend one of our training courses, we ask the person registering you to provide your name, practice name, practice address, practice and personal telephone numbers, email address, and orthodontic treatment experience. If you will be personally paying for the training course, we also will collect payment information, including credit card and billing address, to process payment and complete your registration for the course.
We use this information for the purpose of registering you for our certification course and facilitating your Provider relationship with 6MS.
When your Provider submits your case for consideration of our services, we collect your full name, age, and gender; case supportive photographs and radiographs; and your customized orthodontic information of your dentition. This information is necessary to create customized treatment plans, 3D simulations, and fabrication of 6MS appliances customized for you. You provide this information to your Provider as part of requesting our services, and we use this information both for the purpose of evaluating your candidacy for our services, as well as providing our requested services.
This information is collected through our Provider Resource Center, which is accessed by your Provider via our website. We only collect this data when your Provider has initiated a case submission per your request, and we only process this data under clearly defined instructions from your Provider. These instructions include obligations for us to maintain the confidentiality and security of your personal data.
Your personal data will be saved to your Provider’s account until your Provider deletes the account or you request we delete your information. If your case is denied, we delete your personal data from your Provider’s account and our case database. A copy of all completed and canceled cases is retained for case management, quality assurance, accounting, and regulatory purposes.
Six Month Smiles Forum
Your Provider may choose to use our Six Month Smiles Forum to seek guidance about treatment plans and options from other Providers and independent Six Month Smiles Clinical Instructors and Mentors. The Forum is only accessible to Providers via unique login credentials, and all Providers using the Forum are bound by applicable privacy laws and professional conduct obligations, including confidentiality.
If your Provider uses the Forum for guidance regarding your specific treatment plan, your Provider may only discuss your case in generic terms and without disclosing your name. Your Provider may only use the Forum in furtherance of a legitimate treatment need and may only disclose your information in accordance with applicable laws and professional obligations. We will only process information shared via the Forum for the purpose of facilitating Provider-to-Provider communication, and any information posted to the Forum will remain on the Forum indefinitely.
Personal Data Use
How we use your personal data will depend on how you interact with our website and the personal data you have shared with us.
Respond to Your Requests
We use your personal data to respond to your requests, including communications, content downloads, and Provider searches you have initiated. If you are a prospective or current Provider, we also use your personal data to register you for training courses, and, when applicable, enable you to create an account and use our online portals and e-commerce tools.
Provide Short-Term Orthodontic Care Services
When a Provider submits a case for review, we use the personal data collected to evaluate the viability of the case. If the case is accepted, we will use the personal data to create and provide the requested services to the Provider.
Enhance Website and User Experience
We use the information regarding the use of our website to analyze and administer the site and track user movement for web analytics purposes. This website usage information enables 6MS to provide you with an ever-improving site, service, and general offering. Except where you have provided consent for us to use your identifiable personal data for our analytics research, we only use anonymous, aggregate data that cannot be used to identify you individually.
Manage Account (Providers Only)
If you are a Provider and have created a Provider Resource Center Account, we will use your personal data to administer your account, including enabling you to submit cases for evaluation, and to allow you to access the Provider Resource Center, submit orders for tools and supplies, submit orders for course re-attendance, and submit payment for such order types. If necessary, we will also use your personal data to verify your identity and provide you with access to your account should you become locked out or forget your login and password.
Provide Searchable Provider List (Providers Only)
If you are a Provider, we include your name, practice name, practice address, and practice telephone number in our “Find a Dentist” searchable, online database of Providers. We use this information and database for the purpose of matching you with prospective patients in your area.
Conduct Marketing and Advertising
Personal data is used to coordinate the best offers and information to both inquiring patients and to current or interested Providers. Email and other materials delivered from 6MS are sent strictly as part of an opt-in process or in response to communications you have initiated with us. You may change your consent for receiving such communications by clicking the “Unsubscribe” link at the bottom of any electronic marketing communications received from us. You may also contact us at 6MSDataProtectionOffice@sixmonthsmiles.com to request that we remove you from our marketing communications
Meet Legal and Regulatory Obligations
In certain circumstances, we may be required to disclose your personal data, including your health information, to regulators or as otherwise required by law. We will only share the information we are required to disclose by law and only when we are required to do so.
Security and Fraud Prevention
Personal Data Sharing and Disclosure
We share your personal data when you have granted us permission to do so, when it is necessary to fulfill our obligations to you, or when it is in the legitimate interest of our business to do so, provided that our interests do not outweigh your individual rights and freedoms.
When necessary, we share your data with third-party vendors working on our behalf to provide specific business support services, including payment processing, website hosting and management, personalized case treatment planning, and digitization of tooth models.
Website Analytics Companies
We share anonymous, aggregate information regarding visitors to our website with third-party website analytics companies. These companies use this aggregate data, which has been stripped of any personally identifying information about you, to provide us with insight regarding our web usage patterns. As we only share anonymous, aggregate data, this information cannot be traced back to you individually by either us or the website analytics vendors.
We use Google Analytics to provide us website usage and analytic reports, which necessitates us sharing your anonymous, aggregate data. You may choose not to share your data with Google by installing the Google Analytics opt-out browser add-on, which instructs your browser not to provide your website usage data to Google Analytics. To opt-out of Google Analytics, visit https://tools.google.com/dlpage/gaoptout to install the browser add-on.
Please note that installing the Google Analytics opt-out browser add-on will only disable the use of Google Analytics and will not prevent data from being sent to the website itself or to other web analytics services.
Marketing and Advertising Partners
From time to time, we may send emails or other electronic communications to Providers on behalf of our marketing and advertising partners when we believe our partners offer products or services that we think may provide value to you. At no time do we share your email address with our partners, and you can unsubscribe from these communications at any time by clicking the “Unsubscribe” link at the bottom of the email or other electronic communication. You may also contact us at 6MSDataProtectionOffice@sixmonthsmiles.com to request that we remove your email address from our marketing communications.
Additionally, we use tools provided by Facebook to display internet-based advertisements to you when you are using Facebook. We do not share any of your personal information with Facebook. Rather, the tools enable us to convert your email address to a unique number Facebook uses to match to unique numbers Facebook generates from email addresses of its users.
You have choices over the use of your information for these purposes and can visit https://www.facebook.com/ads/website_custom_audiences/
As required by law, regulation, or legal process, we will share your personal data with government authorities, enforcement officials, or third parties as necessary to respond to subpoenas, court orders, or legal process, or to establish or exercise our legal rights or defend against legal claims.
Security and Fraud Prevention Efforts
Sale of Business
EU Data Subject Rights
Your rights include:
You also have the right to lodge a complaint with your supervisory authority if you believe we have violated your privacy rights or applicable laws and regulations.
California Privacy Rights
If you are a resident of the State of California and you have provided your personal data to us, you have the right to request a list of all third parties to which we have disclosed your personal data for direct marketing purposes. If you exercise your right to submit such a request to us, we will send you the following information:
California law also requires that we disclose how we respond to “do-not-track requests” from our users. At this time, we do not currently respond to “do-not-track” requests from our users’ browsers.
Cross-Border Data Transfers
We process data both inside and outside the United States. It is important to know that data protection laws in the United States may not be as strong as those in your country. Where we transfer your personal data from the European Economic Area (“EEA”) to a location outside the EEA, we will only transfer your data if an appropriate level of protection for your personal data is guaranteed, such as where we have contractual obligations to protect or transfer data with certain safeguards in place. To ensure the continued protection of your personal data while in our care, we take appropriate organizational and technical measures. In addition, we may transfer your personal data if one of the legal exceptions for such transfer can be invoked, such as with your consent or in execution of an agreement you have with us.
We have implemented organizational and technical safeguards for protecting the personal data you share with us. These measures include internet standard 128 bit encryption of information submitted via our web portals, managed firewall protocols for all network traffic, and qualified, secured credential access of all data storage systems. Additionally, all 6MS personnel are routinely trained on general commerce data security measures.
Unless stated otherwise, we retain all personal data and other information collected for 10 years. If you would like your personal data deleted earlier than the 10-year retention period, you may exercise your right to request the deletion of your data at any time.
Children Under the Age of 16
We do not knowingly collect personal data from individuals under the age of 16, unless the personal data is submitted by a Provider for use of our services and with parental consent. Our website is not intended for anyone under the age of 16, and no one under the age of 16 may provide information on this website.
Data Protection Officer
6270 Morning Star Dr. Ste. 120
The Colony, TX 75056