Last updated October 3, 2026
Privacy Policy
SedationSync operates a scheduling and coordination platform that connects dental offices with anesthesia providers. This policy explains what information we collect, why we collect it, how we protect it, and the choices you have — including a specific disclosure for data we access through Google APIs.
1. Who we are
This policy applies to the SedationSync platform at sedationsync.comand the services provided through it (the “Service”). In this policy, “SedationSync”, “we”, “us” and “our” refer to the operator of that platform. “You” refers to anyone who uses the Service, including anesthesia providers, anesthesia groups, dental offices, dental support organizations (DSOs) and their staff.
2. Information we collect
Information you give us
- Account and profile data — name, email address, password (stored only as a cryptographic hash), phone number, role, professional credentials, licence and certification details, practice or group name, service areas and profile content you choose to publish.
- Scheduling data — availability, booking requests, confirmations, cancellations, case details, locations and times.
- Billing data — invoices, amounts, payment status and subscription plan. Card details are handled by our payment processor; we do not store full card numbers.
- Communications — messages you send through the platform, support requests and documents or files you upload.
Patient information
Dental offices and providers use the Service to record patient information needed to deliver sedation care — including patient names, dates of birth, contact details, health history questionnaire responses, medications, allergies, ASA classification and related clinical documents. This information is entered by the practice, not by us. Where this information is protected health information (PHI) under HIPAA, we handle it as a business associate on behalf of the practice and only as described in section 8.
Information we collect automatically
- Technical and usage data — IP address, browser and device type, pages viewed, actions taken in the app, timestamps and error reports.
- Cookies and local storage — we use these to keep you signed in, remember your preferences and keep the Service secure. See section 10.
Information from connected services
If you choose to connect an external calendar — Google Calendar, Microsoft Outlook, or an ICS feed — we receive calendar information from that service. Google data is covered in detail in section 3.
3. Google user data
Connecting Google Calendar is entirely optional. If you connect it, SedationSync requests access to your Google account through Google’s OAuth consent screen, where the exact permissions are shown to you before you approve them. We request the narrowest permissions that allow the feature to work:
| What we access | Why we need it |
|---|---|
| Your Google account email address and basic profile | To show you which Google account is connected, and to keep the connection linked to the right SedationSync account. |
| Your calendar list and existing calendar events | To overlay commitments you already have onto your SedationSync availability, so you are not booked for a time when you are busy and double-bookings are flagged before they happen. |
| Permission to create and update calendar events | To write your confirmed SedationSync bookings onto the calendar you select, and to keep those events up to date if a booking changes or is cancelled. |
How we use and store Google data
- Google Calendar data is used only to provide the calendar sync features described above, inside your own SedationSync account.
- We store the minimum needed to show your schedule — event start and end times, titles, all-day and busy/free status, and calendar identifiers — along with the OAuth tokens required to keep the connection working. Tokens are stored encrypted.
- Events written by SedationSync contain only the booking information needed for the case. We do not modify or delete events that SedationSync did not create.
- We do not use Google user data for advertising, we do not sell it, and we do not use it to train generalised artificial intelligence or machine learning models.
- No human at SedationSync reads your Google Calendar data, except where you give explicit permission (for example, when you ask us to investigate a sync problem), where it is necessary for security purposes such as investigating abuse, or where we are required to by law.
Limited Use disclosure
SedationSync’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and deletion
You can disconnect Google Calendar at any time from the Calendar page in SedationSync. Disconnecting revokes our access and deletes the stored OAuth tokens and the synced event data we hold for that connection. You can also review and revoke access directly in your Google account at myaccount.google.com/permissions. Events that SedationSync already wrote to your calendar remain on your calendar and are yours to keep or delete.
4. How we use information
- To create and administer your account and verify your credentials.
- To operate core features: provider search, availability, booking requests, confirmations, calendars, patient records, health forms, documents, messaging, invoicing and analytics.
- To send transactional notifications about bookings, messages and billing.
- To process subscriptions and payments.
- To keep the Service secure — authentication, session management, fraud and abuse prevention, and audit logging.
- To diagnose problems, measure usage in aggregate and improve the Service.
- To comply with legal, regulatory and professional obligations.
We do not sell your personal information, and we do not share it with third parties for their own advertising.
5. How we share information
- With the other party to a booking — when a dental office requests a provider, each side sees the information needed to deliver care: contact details, case details and the relevant patient records.
- Within your organisation — group coordinators, DSO administrators and office staff can see the records belonging to their organisation, according to the role you have been given.
- Service providers — hosting, database, email delivery, file storage, payment processing and error monitoring vendors who process data on our instructions and under contract, including business associate agreements where PHI is involved.
- Legal and safety — where required by law, subpoena or court order, or to protect the rights, safety and property of users or the public.
- Business transfers — if the Service is involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction; this policy continues to apply until replaced.
6. Data retention
We keep account and booking records for as long as your account is active and afterwards for as long as needed to meet legal, clinical-recordkeeping, tax and audit obligations. Clinical and patient records are retained according to the instructions of the practice that owns them and applicable retention law. Synced calendar data and OAuth tokens are deleted when you disconnect the integration. Backups are rotated on a defined schedule and expire automatically.
7. Security
We protect information with encryption in transit (TLS) and at rest, hashed passwords, optional two-factor authentication, role-based access control, automatic session timeout after inactivity, security headers and a content security policy, audit logging and least-privilege access for personnel. No system is perfectly secure, but we work to protect your information and will notify you and any required authority of a breach as the law requires.
8. HIPAA
For patient information, the dental office or provider organisation is the covered entity and SedationSync acts as a business associate. We use and disclose PHI only as permitted by our business associate agreement and applicable law — to provide the Service, for our own proper management and legal obligations, and as otherwise required by law. Patients with questions about their health information should contact the practice that treated them.
9. Your rights and choices
- Access and correction — view and update your profile and account data in the app at any time.
- Deletion — ask us to delete your account and associated personal data. Some records must be retained where law or clinical recordkeeping requires it, and we will tell you when that applies.
- Export — request a copy of the personal data you have provided.
- Connected services — disconnect any calendar integration at any time.
- Email preferences — opt out of non-essential email. Transactional messages about your bookings, security and billing are part of the Service.
Depending on where you live you may have additional rights, such as the right to object to or restrict processing, or to lodge a complaint with a supervisory authority. To exercise any of these rights, email info@sedationsync.com.
10. Cookies and similar technologies
We use cookies and browser storage that are strictly necessary to run the Service — keeping you signed in, preserving your session, remembering interface preferences and protecting against abuse. We do not use third-party advertising cookies. Blocking necessary cookies will prevent you from signing in.
11. Children
The Service is intended for use by healthcare professionals and practice staff, and is not directed to children. Where a patient is a minor, their information is entered and controlled by the treating practice under that practice’s own privacy notice and HIPAA obligations.
12. International users
The Service is operated in the United States and information is processed and stored there. If you access it from elsewhere, you understand that your information will be transferred to and processed in the United States, where data protection law may differ from that of your country.
13. Changes to this policy
We may update this policy as the Service changes or the law requires. We will update the date at the top of this page and, for material changes, give notice in the app or by email before the change takes effect.
14. Contact us
Questions, requests or privacy concerns: info@sedationsync.com.