Privacy Policy
Dion Insights · Dion Health Management Company LLC · Effective July 3, 2026
Dion Insights is an analytics platform for dental and medical practices. We process data on behalf of the practice that owns it — the practice is the data controller (and, for protected health information, the covered entity), and Dion Health acts as its service provider and business associate. This policy explains what data we handle, why, where it lives, and how we protect it.
Data we process
| Category | Examples | Source |
|---|---|---|
| Practice financials | Production, collections, A/R aging, overhead | Practice management system, QuickBooks |
| Aggregate clinical metrics | Recare/perio cohorts, procedure-group mix, case acceptance | Practice management system |
| Provider identifiers | Provider names, role, per-provider production | Practice management system |
| Connection credentials | Practice-management API keys, accounting and bank tokens | Practice administrator |
| Account identity | User email, role, organization | Our identity provider |
| Audit metadata | Actor, action, IP address, user agent, timestamps | The application |
We do not store clinical free text — no diagnoses, chart notes, or patient names. Our analytics need aggregates and identifiers, not the underlying patient record.
Financial account data (via Plaid)
When a practice connects a bank or financial account, it does so through Plaid. Plaid securely retrieves account and transaction information and passes it to Dion Insights so we can produce cash-flow, reconciliation, and quality-of-earnings analytics for that practice. We request only the account and transaction data required for these analytics; we do not move money, initiate payments, or use the data for lending decisions. Plaid's handling of the data it collects is governed by Plaid's End User Privacy Policy.
Why we process it
Solely to compute and present practice-performance analytics and opportunity models to the practice that owns the data. We do not sell data, use it for advertising, or apply it to any secondary purpose.
Where it lives
Data is stored with vetted infrastructure providers, each engaged under a Data Processing Agreement and, where applicable, a Business Associate Agreement:
| Provider | Role |
|---|---|
| Supabase | Primary database, encrypted at rest |
| Vercel | Application compute and logs |
| WorkOS | Identity and single sign-on |
| Plaid | Financial account connectivity |
| Sentry (if enabled) | Error telemetry — no protected health information; redacted |
How it is protected
| Encryption in transit | TLS 1.2 or higher on all connections; unencrypted HTTP is rejected |
| Encryption at rest | Database-level AES-256, plus application-layer AES-256-GCM for credentials and provider identifiers |
| Tenant isolation | Each practice's data is structurally isolated from every other practice |
| Access control | Least-privilege, role-based access; multi-factor authentication on all production systems |
| Auditing | Full audit trail of access-relevant actions; secrets and PHI redacted from logs |
Your rights
Access & export. A practice may request a copy of its data at any time.
Deletion.On offboarding, a practice's records are deleted; audit-log retention follows our data-retention schedule.
Correction. Practices correct source data in their practice management system; the next sync propagates the change.
Contact
Privacy questions or data requests: privacy@dionhealth.com. Security concerns: security@dionhealth.com.
Dion Health Management Company LLC. This policy may be updated; the effective date above reflects the most recent revision.