Privacy Policy

Privacy Policy

Vectisify | Effective date: August 14, 2026

1. Who This Policy Covers

Vectisify operates Benji, a software platform used by dental offices ("Clients") to verify patient insurance eligibility and manage related claims workflows. This policy describes how Vectisify collects, uses, and protects information encountered through:

  • The Benji web portal (office staff logins, dashboards).
  • Backend processing of eligibility/claims data on behalf of Clients (via Stedi, Telnyx, and other integrations).
  • Vectisify's own business website and communications.

Vectisify acts as a Business Associate to each dental office Client under HIPAA. Patients are not Vectisify's direct customers — the dental office is. Patient data (PHI) is processed strictly on behalf of, and under the direction of, the Client, per the Business Associate Agreement (BAA) executed with that Client.

2. What We Collect

  • Client account data: office staff names, emails, login credentials (hashed), role/permissions.
  • Patient data processed on behalf of Clients (PHI): patient name, date of birth, insurance member ID, coverage/eligibility results, claim data (CDT procedure codes, billed amounts, claim status), billing/payment data (payments posted to the practice management system, remittance/EOB details), and subscriber information when the patient is not the insured party (subscriber name and date of birth). This data belongs to the Client (Covered Entity) and is processed only as instructed by the Client and permitted by the applicable BAA.
  • Call recordings: when electronic verification is insufficient, Benji places AI-assisted phone calls to insurance payers on behalf of the Client to complete a benefits verification. These calls are recorded and may contain the patient data listed above, spoken aloud to a payer representative.
  • Clinical attachments: documents uploaded to support a claim (e.g., radiographs, referral forms), scanned for malware before storage.
  • Prospect contact data: name, email, phone, and practice details submitted through our demo request form by people evaluating Benji who are not yet Clients.
  • Technical/usage data: standard server logs (IP address, timestamps, request paths) generated by Vercel and Supabase infrastructure for operational and security purposes.

Vectisify does not use tracking pixels (e.g., Meta Pixel), third-party ad trackers, or behavioral advertising technology on the Benji portal.

3. How We Use Information

  • To operate the Benji platform: submit eligibility checks, process claims, conduct AI-assisted verification calls to insurance payers when needed, display results to Client staff.
  • To maintain security and audit trails (see the companion Written Information Security Policy and Incident Response Plan).
  • To communicate with Clients about their account and the service.

We do not sell personal information or PHI, and we do not use PHI to train AI models beyond what is explicitly permitted under a Client's BAA.

4. Subprocessors

Vectisify uses the following subprocessors to operate Benji. Each subprocessor that may handle PHI is required to support a Business Associate Agreement:

SubprocessorPurposeBAA
SupabaseDatabase, authenticationAvailable (HIPAA add-on)
VercelApplication hostingAvailable (HIPAA add-on)
TelnyxVoice AI calls to insurance payersIncluded on all plans
StediClearinghouse (eligibility checks, claims submission)Operates as a HIPAA-covered clearinghouse

5. Security

Vectisify protects information using the safeguards described in its Written Information Security Policy, including encryption in transit and at rest, access controls, and multi-factor authentication on privileged accounts. In the event of a security incident affecting PHI, Vectisify follows its Incident Response Plan and notifies affected Clients without unreasonable delay, consistent with the timelines required by the applicable BAA and the HIPAA Breach Notification Rule.

6. Data Retention

PHI is retained only as long as needed to provide the service to the Client, or as required by the applicable BAA and by law, whichever is longer. Upon termination of a Client relationship, PHI is returned or destroyed per the terms of that Client's BAA.

7. Individual Rights

Because Vectisify acts as a Business Associate, individuals (patients) seeking to exercise rights over their health information (access, amendment, etc.) should contact their dental office (the Covered Entity) directly. Vectisify supports the Client in fulfilling such requests as required under HIPAA and the applicable BAA.

For CCPA/GDPR-type requests relating to non-PHI business contact data (e.g., a Client staff member's own account information), contact Vectisify directly (see Contact below).

8. Review

This policy is reviewed at least annually, and any time Vectisify's data practices, subprocessors, or applicable law changes materially.

9. Contact

Questions about this policy: hello@vectisify.com