June ("June," "we," "us," or "our") provides patient management software to dental practices. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit juneportal.com, request a demo, submit a records transfer request, use our admin platform, or otherwise interact with our services.
June is a business-to-business platform. Our customers are dental practices ("Practices"). When we process patients' Protected Health Information ("PHI") in the course of providing our services, we do so as a Business Associate to the Practice under the Health Insurance Portability and Accountability Act ("HIPAA"), governed by a signed Business Associate Agreement ("BAA").
This Policy is intended for users located in the United States. Our services are not directed to or intended for individuals outside the United States.
1. Scope
This Policy applies to:
- Visitors to juneportal.com
- Prospective customers who submit demo requests or otherwise contact us
- Authorized users of the June admin platform (typically Practice staff)
- Patients (or parents and legal guardians of minor patients) who submit records transfer requests through our Patient Record Transfer Portal
- Patients who use the June patient mobile app.
This Policy does not govern PHI processed on behalf of a Practice in the course of our services to that Practice, except as set forth in Section 5. PHI is governed by the Practice's Notice of Privacy Practices, our BAA with the Practice, and applicable law. Patients with questions about their dental records should contact their dental practice directly.
2. Information We Collect
a. Information You Provide
- Business contact and demo request information: Name, email, phone, practice name, role, and the contents of your communications when you request a demo, contact sales, or otherwise interact with us.
- Account and administrative information: Username, hashed password, authentication credentials, role assignments, and contact details for authorized users of the June admin platform.
- Patient Record Transfer Portal submissions: When a patient (or a parent or legal guardian acting on behalf of a minor patient) submits a records transfer request, we collect the patient's name, date of birth, and information identifying the requesting and originating dental practices. This information is treated as PHI and is handled as described in Section 5.
b. Information Collected Automatically
- Technical and device data: IP address, browser type, operating system, referring URLs, pages viewed, timestamps, and similar information collected through cookies, server logs, and similar technologies.
- Platform usage data: Authentication events, audit logs, configuration changes, feature usage, and performance metrics from the June admin platform.
c. Information from Third Parties
We may receive contact information from referral partners, public sources (such as practice directories), or service providers that help us identify and reach prospective customers.
3. Patients Using the June Mobile App
When you use the June patient mobile app we collect: account and identity information you provide (name, date of birth, email address, mobile phone number, and password); authentication data, including biometric sign-in (Face ID/Touch ID) handled on your device; device identifiers and push-notification tokens used to deliver app notifications; usage and diagnostic data; and "Patient Submissions" you choose to provide (such as messages to your practice, photos of insurance cards, and completed forms). The clinical and billing information shown in the app is provided by your dental practice; with respect to that information June acts as a Business Associate of your practice under HIPAA, and your practice's Notice of Privacy Practices governs its use. You can delete your June account at any time in the app under Profile → Delete my account; this closes your login but does not erase the clinical records your dental practice is required by law to retain.
4. How We Use Information
We use the information described above to:
- Provide, operate, secure, monitor, and improve the June platform.
- Respond to demo requests, sales inquiries, and other communications.
- Verify and process records transfer requests on behalf of the requesting Practice.
- Send transactional and service-related communications.
- Send marketing communications to business contacts, subject to the opt-out rights described in Section 10.
- Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our terms.
- Comply with legal, regulatory, and contractual obligations, including those under HIPAA and applicable state law.
We do not sell personal information for money, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act ("CCPA"). We do not use PHI for our own marketing purposes.
5. Protected Health Information (HIPAA)
June acts as a Business Associate to the dental practices that use our platform. PHI is processed only to deliver the services requested by those practices and in accordance with a signed BAA. Specifically:
- We do not sell PHI.
- We do not use or disclose PHI for marketing.
- We use PHI only as permitted by the BAA and HIPAA, primarily to provide and maintain the services and to carry out our obligations to the Practice.
- Breach notification. In the event of a breach of unsecured PHI, we will notify affected Practices without unreasonable delay and in any event within the time period required by HIPAA (no later than 60 days following discovery), and we will provide the information required for the Practice to fulfill its own notification obligations.
- Return or destruction. Upon termination of our agreement with a Practice, we will return or destroy PHI in our possession as instructed by the Practice and as required by the BAA, subject to limited retention permitted by law (for example, in backup systems pending scheduled deletion).
- Patient Record Transfer Portal. When patients use the Patient Record Transfer Portal, June processes the submission on behalf of the requesting Practice, which is the relevant covered entity under HIPAA. The Practice remains responsible for verifying patient identity and authorizing the transfer. Patients should direct questions about their PHI to that Practice.
6. Cookies and Analytics
Our marketing site uses cookies and similar technologies to operate the site, remember preferences, and measure aggregate usage. The categories of cookies we use are:
- Strictly necessary cookies are required to operate the site (e.g., session management, security and abuse prevention, load balancing). These are always active.
- Preference cookies remember your choices (such as your cookie banner selection).
- Analytics cookies are used to measure aggregate site usage. These are loaded only if you consent through our cookie banner.
If you consent, we load Google Analytics 4 to measure aggregate marketing-site traffic (pageviews, demo-form interactions, and outbound clicks). IP addresses are anonymized, and we do not transmit your name, email, practice information, or any PHI to Google Analytics. If you select "Essential only" or dismiss the banner, no analytics scripts are loaded.
You can manage cookies through your browser settings. Disabling strictly necessary cookies may impair site functionality.
We do not currently respond to "Do Not Track" browser signals. We honor the Global Privacy Control ("GPC") signal as an opt-out of sale and sharing for the limited categories of personal information addressed by GPC.
7. Service Providers and Subprocessors
We share information with vetted third parties only as necessary to operate the platform and under appropriate contractual protections, including Business Associate Agreements where applicable. Current key subprocessors include:
- Sikka Software: Practice-management system integration
- Helcim: Payment processing (June Payments)
- Twilio (including SendGrid): SMS messaging, multi-factor authentication, and transactional email
- Deepgram: Speech-to-text transcription of recorded visits
- Stedi: Insurance eligibility verification
- Amazon Web Services (AWS): Application hosting, storage, and AI processing (under BAA)
A current list of subprocessors is maintained at https://juneportal.com/subprocessors and is available on request. We require subprocessors that access PHI to execute a BAA and to apply safeguards substantially similar to ours.
We may also disclose information:
- To comply with applicable law, legal process, or governmental requests.
- To enforce our agreements, including the investigation of potential violations.
- To protect the rights, property, or safety of June, our customers, or others.
- In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
8. Security
We apply enterprise-grade safeguards, including AES-256-GCM encryption for data at rest, TLS encryption in transit, separated key management, role-based access control, multi-factor authentication, and PHI-free application logs. Access to production systems is restricted, monitored, and audited. We conduct regular risk assessments and maintain administrative, technical, and physical safeguards consistent with the HIPAA Security Rule.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Data Retention
We retain personal information for as long as needed to provide the services, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:
- Demo and sales lead information: Up to 24 months from last meaningful contact, unless you become a customer or request earlier deletion.
- Account and authentication data: Duration of the customer relationship, plus up to 12 months following termination, except as required for legal, audit, or security purposes.
- Audit logs and security logs: Up to 6 years, consistent with HIPAA recordkeeping requirements.
- Marketing site analytics: Up to 14 months in aggregate form.
- PHI: Retained and disposed of in accordance with the instructions of the dental practice that provided it, the applicable BAA, and applicable law.
10. Marketing Communications
We may send marketing emails to business contacts (such as demo requesters and customer administrators). All marketing emails include an unsubscribe link, and you can opt out at any time by clicking that link or emailing info@juneportal.com. Opting out of marketing emails does not affect transactional or service-related communications, such as account notices, security alerts, or billing communications.
11. SMS / Text Messaging
With your consent, given when you provide your mobile number during registration in the June mobile app or at your dental practice, June sends transactional text messages, on your behalf and on behalf of your dental practice, including appointment reminders and confirmations, one-time security and login codes, and account, billing, and form notifications. Message frequency varies. Message and data rates may apply. You can reply STOP to any message to unsubscribe, or HELP for help. We do not sell, rent, or share your mobile phone number or SMS opt-in information with third parties or affiliates for their own marketing purposes. SMS opt-in is never a condition of receiving dental care.
12. Your Privacy Rights
a. General Rights
Depending on your jurisdiction, you may have rights to:
- Access or know the personal information we hold about you and how it is processed.
- Correct inaccurate or incomplete personal information.
- Delete personal information.
- Restrict or object to certain processing.
- Portability of personal information you provided to us.
- Opt out of sale or sharing of personal information (we do not sell or share, but you may submit a request to confirm).
- Limit use of sensitive personal information.
- Appeal a denial of a privacy request, where applicable.
- Non-discrimination for exercising your privacy rights.
To submit a request, email info@juneportal.com with the subject line "Privacy Request." We will verify your identity before fulfilling the request, typically by matching information you provide with information we already hold. You may authorize an agent to submit a request on your behalf; we will require evidence of authorization and may contact you directly to verify.
We will respond within the timeframes required by applicable law (generally within 45 days under U.S. state laws, with a possible extension on notice). We will not discriminate against you for exercising your privacy rights.
For PHI held on behalf of a dental practice, please direct requests to that practice. We will assist the practice in fulfilling such requests as required by HIPAA and the BAA.
b. California Residents (CCPA / CPRA)
In the 12 months preceding the effective date of this Policy, we have collected the following categories of personal information:
| CCPA Category | Examples | Sources | Business Purposes | Disclosed To |
|---|---|---|---|---|
| Identifiers | Name, email, phone, IP address, online identifiers | You; automated collection; referral partners | Service delivery, sales, security | Service providers, subprocessors |
| Commercial information | Practice name, role, transaction records | You; Practices | Service delivery, billing | Payment processors, hosting providers |
| Internet/network activity | Browser type, pages viewed, interactions, usage data | Automated collection | Service operation, analytics (with consent), security | Analytics providers (with consent), hosting providers |
| Professional/employment information | Job title, practice affiliation | You | Sales, account management | Service providers |
| Sensitive personal information | Account credentials; health-related data submitted via the Patient Record Transfer Portal | You; patients (via Practice) | Service delivery; authentication | Subprocessors under BAA |
Health information that constitutes PHI under HIPAA is exempt from the CCPA and is governed by HIPAA, our BAA, and the Practice's Notice of Privacy Practices.
California residents have the rights described in Section 12(a), including the right to know, delete, correct, opt out of sale and sharing, limit use of sensitive personal information, and non-discrimination. We do not sell personal information and do not share personal information for cross-context behavioral advertising. We use sensitive personal information only for the purposes permitted under CCPA section 7027(m), including providing the services you request, security and integrity, and ensuring quality and safety. We retain personal information for the periods described in Section 9.
California's "Shine the Light" law (Civil Code § 1798.83) permits California residents to request information about disclosures of personal information to third parties for those third parties' direct marketing purposes. We do not currently disclose personal information to third parties for their own direct marketing.
c. Other U.S. State Residents
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Tennessee, Indiana, Iowa, New Hampshire, New Jersey, and other states with comprehensive consumer privacy laws may have rights similar to those described in Section 12(a), subject to state-specific exceptions, thresholds, and procedures. To exercise these rights, use the contact information in Section 16. Where state law requires, we offer an internal appeal process for denied requests.
d. Washington Residents (My Health My Data Act)
Information we collect through the marketing site (such as IP address and cookie identifiers in connection with a visit) may, in some circumstances, constitute "consumer health data" under Washington's My Health My Data Act. We do not collect, use, or share consumer health data without obtaining the affirmative, opt-in consent required by that law, and we do not sell consumer health data. Where Washington residents have rights with respect to consumer health data, those rights may be exercised by contacting us at info@juneportal.com.
13. Children's Privacy
Our marketing site and admin platform are intended for dental practice professionals and are not directed to children. We do not knowingly collect personal information from children through our marketing site or admin platform.
The Patient Record Transfer Portal may, in the ordinary course, process records relating to minor patients. We rely on parents or legal guardians to submit requests on behalf of minors and on the requesting Practice to verify authority. Records relating to minors that constitute PHI are governed by HIPAA, the applicable BAA, and the Practice's policies, not by this Policy.
If you believe we have inadvertently collected information from a child in violation of this Policy, please contact us at info@juneportal.com so we can promptly delete it.
14. International Users
Our services are intended for use in the United States. Personal information we collect is processed and stored in the United States. If you access our services from outside the United States, you do so at your own initiative and are responsible for compliance with applicable local law. We do not offer rights under the EU General Data Protection Regulation, the UK GDPR, or other non-U.S. data protection regimes to users outside the United States.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last Updated" date at the top of this Policy and, where appropriate, by additional notice (such as email to customer administrators or a banner on our site). Your continued use of our services after the effective date constitutes acceptance of the updated Policy.
16. Contact Us
Questions, requests, or complaints about this Privacy Policy or our privacy practices:
June972 Hawthorne Dr.
Walnut Creek, CA 94596
Email: info@juneportal.com