MTS

LEGAL

Privacy Policy

Last updated: 20 August 2026

Back to Trust Center
On this page

MTS (referred to below as MTS, we, or us) builds and operates the MTS Revenue Infrastructure: the AI SDR, AI Receptionist, and related automation agents dental clinics use to contact leads, answer calls, confirm appointments, and bring patients back. This policy covers three different kinds of people, and treats them differently on purpose: the clinic staff who use the dashboard, the website visitors reading this page, and the patients whose information a clinic processes through the Service.

1. Who We Are

MTS is currently operated pre-incorporation, ahead of our first client. [LEGAL ENTITY NAME TO BE CONFIRMED] is a placeholder for the registered entity that will operate MTS once formed. This policy will be updated with that entity's name as soon as it exists.

2. Information We Collect

  • Website visitors: pages viewed and general usage information. This website does not currently run analytics or advertising scripts, see Cookie Policy.
  • Account and staff information: name, email, phone, role, and authentication data for anyone who logs into the MTS dashboard.
  • Clinic information: business name, locations, hours, services, and configuration a clinic sets up in the dashboard.
  • Patient-related information, processed through a clinic's connected infrastructure: name, phone, email, appointment history, call and conversation content, and message content, entered by the clinic, its patients, or its connected systems.
  • Communication information: calls, SMS, WhatsApp, email, and website-chat content processed to run an AI agent a clinic has enabled.
  • Appointment information: bookings, reschedules, cancellations, reminders, and confirmations.
  • CRM information: lead and pipeline records the Service reads from or writes to a clinic's connected CRM.
  • AI conversation information: the content of conversations handled by an AI agent, including voice transcripts, and the context sent to the AI providers that generate responses.
  • Technical and analytics information: dashboard usage, timestamps, and event logs, used to operate the product and show a clinic its own activity, never sold or shared for advertising.

3. How We Use Information

  • To operate the AI SDR, AI Receptionist, Reminder, Recall, Reviews, and related agents a clinic has enabled.
  • To show a clinic real, logged outcomes in the dashboard: bookings, response times, and revenue attribution.
  • To respond to support requests and keep the Service secure and available.

4. Your CRM Is the Source of Truth

A clinic's own CRM is the source of truth for its contacts and appointments. MTS provides the infrastructure required to process information across connected workflows, and may process or retain related information within MTS-controlled systems and third-party services as necessary to provide the Service. Being the source of truth for a record does not mean MTS never touches a copy of it, the next section explains where those copies can exist.

5. How Information Moves Through Our Infrastructure

Patient-related information can pass through several systems to complete a workflow:

  • n8n (workflow automation): every automation run stores its inputs and outputs, which can include names, phone numbers, and conversation content, in n8n's own execution history.
  • Retell (voice AI): phone calls handled by an AI voice agent are processed, and may be recorded and transcribed, by Retell before the result reaches a clinic's CRM.
  • AI language providers (Gemini, OpenRouter): conversation context is sent to these providers to generate an AI agent's responses. MTS does not claim these providers retain nothing, their own logging and retention terms govern what happens on their side.
  • Twilio (SMS): where SMS is enabled for a clinic, Twilio processes the phone numbers, message content, and delivery metadata needed to send it.
  • Gmail / Google Workspace: where email is sent on a clinic's behalf, sent messages remain in the connected mailbox according to that account's own settings, MTS does not control Gmail's retention.
  • The MTS reporting layer: revenue, pipeline, and KPI aggregation in the dashboard uses MTS-managed storage, which can include patient-linked information such as a lead's name, phone number, pipeline stage, appointment outcome, and associated value.

We do not describe MTS as retaining zero patient data, the systems above are exactly why that statement would not be accurate.

7. Data Sharing and Third-Party Services

We use a limited set of infrastructure and communication providers to run the Service: Supabase (database and authentication), Vercel (hosting), n8n (workflow orchestration), Retell (voice AI), Gemini and OpenRouter (AI language processing), Twilio (SMS, where enabled), and Google Workspace (email, where used). Each processes information only as needed to perform its function for us, none of them may use a clinic's or patient's data for their own purposes. See the Trust Center for the full list. We do not sell patient or clinic data, to anyone, ever.

8. Data Retention

The dashboard's Settings screen includes a configurable data-retention setting. As of this policy's last update, that setting is not yet connected to an automated enforcement process, information is not automatically deleted when it is reached. We retain information for as long as necessary to provide the Service, subject to the legal, contractual, and security requirements described in full on our Data Retention Policy. Specific retention periods are marked [RETENTION PERIOD TO BE CONFIRMED] there until enforcement is built and confirmed.

9. Security

Dashboard access runs through Supabase Auth, and every clinic's data is isolated at the database level by Postgres Row-Level Security. Traffic to the dashboard and its APIs is encrypted in transit. Full detail lives on our Security Overview, which only describes controls that are actually implemented.

10. Deletion

Where deletion functionality is available, MTS will delete or remove information from applicable MTS-controlled systems in accordance with the relevant deletion process. Information maintained by connected third-party services, clinic systems, backups, security records, or other systems may be subject to separate retention and deletion requirements. A clinic can also request deletion directly by contacting us, see Contact below.

11. Your Rights

  • Access and export: a clinic can see and export what the Service holds on any patient from its own dashboard.
  • Correction: edit or correct any record directly in the dashboard.
  • Deletion: request deletion of a specific record, or a clinic's full dataset, as described above.
  • Opt-out: a patient who no longer wants to hear from an AI agent can be marked opted-out in the CRM at any time, automations respect that flag.

12. Cookies

This website does not currently set analytics, advertising, or marketing cookies. Full detail lives on our Cookie Policy.

13. International Data Transfers

Our primary infrastructure runs in a single Supabase region. Where a clinic's use of the Service involves transferring personal data across borders, we rely on the safeguards required by applicable law. We do not currently operate separate regional infrastructure per country, if that changes, this section will be updated to reflect it accurately.

14. Children's Data

The Service is intended for use by dental clinics and their staff, not by children. We do not knowingly collect information directly from children through this website.

15. Changes to This Policy

We will update this page as our infrastructure, providers, or practices change, and update the “Last updated” date above. Material changes affecting how patient data is handled will be communicated to clinic accounts directly.

16. Contact

Email privacy@mtsgrowth.com with any privacy question, or use our Contact page.