Privacy Policy

Dion Insights · Dion Health Management Company LLC · Effective July 3, 2026

Dion Insights is an analytics platform for dental and medical practices. We process data on behalf of the practice that owns it — the practice is the data controller (and, for protected health information, the covered entity), and Dion Health acts as its service provider and business associate. This policy explains what data we handle, why, where it lives, and how we protect it.

Data we process

CategoryExamplesSource
Practice financialsProduction, collections, A/R aging, overheadPractice management system, QuickBooks
Aggregate clinical metricsRecare/perio cohorts, procedure-group mix, case acceptancePractice management system
Provider identifiersProvider names, role, per-provider productionPractice management system
Connection credentialsPractice-management API keys, accounting and bank tokensPractice administrator
Account identityUser email, role, organizationOur identity provider
Audit metadataActor, action, IP address, user agent, timestampsThe application

We do not store clinical free text — no diagnoses, chart notes, or patient names. Our analytics need aggregates and identifiers, not the underlying patient record.

Financial account data (via Plaid)

When a practice connects a bank or financial account, it does so through Plaid. Plaid securely retrieves account and transaction information and passes it to Dion Insights so we can produce cash-flow, reconciliation, and quality-of-earnings analytics for that practice. We request only the account and transaction data required for these analytics; we do not move money, initiate payments, or use the data for lending decisions. Plaid's handling of the data it collects is governed by Plaid's End User Privacy Policy.

Why we process it

Solely to compute and present practice-performance analytics and opportunity models to the practice that owns the data. We do not sell data, use it for advertising, or apply it to any secondary purpose.

Where it lives

Data is stored with vetted infrastructure providers, each engaged under a Data Processing Agreement and, where applicable, a Business Associate Agreement:

ProviderRole
SupabasePrimary database, encrypted at rest
VercelApplication compute and logs
WorkOSIdentity and single sign-on
PlaidFinancial account connectivity
Sentry (if enabled)Error telemetry — no protected health information; redacted

How it is protected

Encryption in transitTLS 1.2 or higher on all connections; unencrypted HTTP is rejected
Encryption at restDatabase-level AES-256, plus application-layer AES-256-GCM for credentials and provider identifiers
Tenant isolationEach practice's data is structurally isolated from every other practice
Access controlLeast-privilege, role-based access; multi-factor authentication on all production systems
AuditingFull audit trail of access-relevant actions; secrets and PHI redacted from logs

Your rights

Access & export. A practice may request a copy of its data at any time.
Deletion.On offboarding, a practice's records are deleted; audit-log retention follows our data-retention schedule.
Correction. Practices correct source data in their practice management system; the next sync propagates the change.

Contact

Privacy questions or data requests: privacy@dionhealth.com. Security concerns: security@dionhealth.com.

Dion Health Management Company LLC. This policy may be updated; the effective date above reflects the most recent revision.