What this policy covers
This policy applies to this website and to the information the site itself handles. That means the ordinary technical records created when any browser loads a page, the details you type into a form or an email, and the two optional features that load from another company only if you allow them.
It does not cover your dental record. Once you are a patient here, what we hold about your diagnoses, treatment, images and billing is protected health information under the federal Health Insurance Portability and Accountability Act, known as HIPAA, and under California law. This practice is a covered entity under HIPAA because it is a health care provider that transmits health information electronically. How that information may be used and disclosed, and the rights you have over it, are set out in our Notice of Privacy Practices.
If something you send through this website later becomes part of your dental record, an appointment request that we file in your chart for example, the Notice of Privacy Practices governs it from that point forward.
This policy does not cover anyone else. Follow a link away from here and you are reading a site we do not control, under a policy we did not write. See also our Terms of Use and our Accessibility Statement.
What this site does not do
It is quicker to describe this site by what is absent from it. None of the following appears on any page:
- Google Analytics, or any other analytics, measurement or audience service.
- Advertising pixels, conversion tags or retargeting scripts of any kind, including the Meta pixel.
- Session recording, heat mapping, mouse tracking or keystroke capture.
- Cross-site or cross-device tracking, behavioral profiling, or building an advertising audience from your visit.
- Third-party font services. Typefaces are stored on our own server, so opening a page makes no request to a font provider.
- Social network embeds, comment systems, chat widgets or accessibility overlays.
- Selling or sharing personal information. This practice does not sell personal information and does not share it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act as amended by the California Privacy Rights Act. We have not done either in the twelve months before the effective date above.
- Automated decision making or profiling that produces legal or similarly significant effects about you.
There are exactly two features on this site that contact another company, and neither one runs until you say yes. Both are described below.
Information we collect
There are three sources, and that is the whole list.
- What you choose to send
- If you use the appointment request form you give us your name, contact details and whatever you write in the message. If you email or call the office we receive what you tell us. Please keep clinical details out of forms and email, for the reason given further down this page.
- Server logs
- Our host records standard web server information for each request: the IP address it came from, the date and time, the page or file requested, the response code, the amount of data sent, the referring page if your browser sends one, and the browser user agent string. These records exist to deliver pages, keep the site available and identify abuse such as automated scanning or denial of service traffic.
- Browser storage on your own device
- Two small entries are saved by your browser and stay there. They are listed in the next section, and nothing about them is transmitted to us.
- What the site never asks for
- No Social Security number, no driver license number, no financial account or card number, no insurance identifier, no biometric data and no precise geolocation. There is no login, no account and no visitor profile, because the site has no database of visitors to put one in.
Browser storage, not cookies
This site sets no cookies. It writes two keys to your browser's local storage instead. Local storage stays on your device and is not attached to the requests your browser sends to our server, so its contents never reach us. You can clear it at any time in your browser settings.
- brosi:consent
- Records whether you allowed the two optional third-party features, together with the date and time you decided. Without it the consent banner would have to ask you again on every page.
- brosi:display
- Records the choices you make in the Display and accessibility panel: text size, contrast, motion, link underlining, typeface, and whether background video is hidden. It exists so your settings survive between visits on that device. Our Accessibility Statement explains what each setting does.
The two third-party features
Both are switched off by default. Neither loads, and neither company receives your IP address, until you choose to allow it in the consent banner.
- OpenStreetMap
- Draws the interactive map on the Contact page when you ask for it. It is operated by OpenStreetMap Foundation. Until you allow it the map is a still placeholder. When it loads, your browser requests map tiles directly from servers run by the OpenStreetMap Foundation, so those servers see your IP address and the part of the map you are looking at. If you would rather not load it, the same page carries our street address, written directions and a telephone number in plain text. Read the OpenStreetMap Foundation privacy policy.
- Jotform appointment request form
- Delivers the online appointment request form. It is operated by Jotform Inc. The form is rendered inside our page from Jotform servers, and it appears only after you allow it. What you type goes to Jotform, which passes it to the practice. Use it to ask for an appointment, not to describe symptoms, medications or anything else about your health. Read the Jotform Inc. privacy policy.
Hosting, delivery and server logs
This is a static website. Pages are built ahead of time and served as files. There is no visitor database, no application server processing your input and no account system, which removes most of the places personal information usually accumulates.
The site is hosted on Cloudflare Pages and delivered over the Cloudflare content delivery network. Cloudflare is our hosting provider and network operator. In that role it processes server log data, including IP addresses, in order to route each request to a nearby server, serve the page over an encrypted connection, and filter malicious traffic such as bots and denial of service attacks. It handles that data as our service provider and is not permitted to use it for its own advertising. Cloudflare publishes its own policy at cloudflare.com.
Because Cloudflare operates a global network, the server that answers your request may sit outside California.
Giving and withdrawing consent
On your first visit a banner explains that two features need to contact another company and asks you to choose. Essential only means nothing third party ever loads. Allow these features turns on the map and the appointment form for that browser.
You can change your answer whenever you like. Select Cookie and data choices in the footer of any page and the banner reopens with both options available. Withdrawing consent stops anything further from loading. It cannot recall information already sent to the OpenStreetMap Foundation or Jotform while consent was in place, and for that you would contact those companies directly using the links above.
Your choice lives in your own browser, so it applies to the device and browser you made it on. Use a different device, or clear your browser storage, and the site will ask again.
Why we use this information, and how long we keep it
Each category has one purpose, and it is kept only for as long as that purpose lasts. Where a use rests on your consent, you can withdraw it as described above.
- To answer you
- When you send an appointment request or an email, we use it to reply, offer times and prepare for your visit. We do that because you asked us to. Correspondence that never becomes part of a dental record is kept while it is useful for scheduling and follow up and is then deleted or shredded. Correspondence that does become part of your record is retained under the rules in our Notice of Privacy Practices and under California record retention requirements, which are longer.
- To deliver and defend the site
- Server logs are used to serve pages, diagnose faults and detect abuse. That is a necessary part of operating any website. The records are kept for a short period in the ordinary course of running the service and are then discarded by our host.
- To remember your choices
- Your consent decision and your display preferences are used to honor what you asked for, and for nothing else. They stay in your browser until you clear them.
- To meet a legal obligation
- Where a law, a court order, a subpoena or a regulator with authority over the practice requires us to keep or produce records, we do. Health information is handled under the separate rules described in the Notice of Privacy Practices.
When information leaves the practice
We do not sell personal information and we do not share it for advertising. Website information reaches another party in only these situations:
- Service providers. Our host, and the two opt-in features described above, each acting on our instructions for the stated purpose and nothing else.
- Professional advisers. Attorneys, accountants and insurers who owe the practice a duty of confidentiality, and only where their work requires it.
- Legal process and safety. Where required by law, in response to a valid subpoena, court order or other lawful request, or where disclosure is necessary to protect the rights, property or safety of a patient, the practice or the public.
- A transfer of the practice. If the practice is sold, merged or transferred to another dentist, records may transfer with it. Health information would move under the protections described in the Notice of Privacy Practices, and you would be told as the law requires.
Your California privacy rights
California residents have the rights below under the California Consumer Privacy Act as amended by the California Privacy Rights Act. Medical information governed by HIPAA and by the California Confidentiality of Medical Information Act is handled under those laws instead, and your rights over your dental record are set out in our Notice of Privacy Practices.
- The right to know
- You may ask what categories of personal information we collected about you, where it came from, why we collected it and who received it, and you may ask for a copy of the specific pieces we hold.
- The right to delete
- You may ask us to delete personal information we collected from you. Some records have to be kept, for instance where a law requires retention or where the information forms part of a dental record, and we will tell you plainly if that is the reason something cannot be deleted.
- The right to correct
- You may ask us to correct personal information you believe is inaccurate. Tell us what is wrong and what it should say.
- The right to opt out of sale or sharing
- This practice does not sell personal information and does not share it for cross-context behavioral advertising, so there is nothing here to opt out of. We state it plainly so you know the answer without having to ask, and there is no "do not sell" link on this site because there is no sale to stop.
- The right to limit sensitive personal information
- Where a business uses sensitive personal information to infer characteristics about a person, that use can be limited. This site does not collect sensitive personal information and does not use anything to infer characteristics about you, so there is no such use to limit.
- The right to non-discrimination
- We will not deny you dental care, charge you a different price, give you a lower level of service or treat you differently in any way because you exercised a privacy right.
How to exercise your rights
Requests are handled by the practice directly. There is no web form for this, and there does not need to be.
-
Send the request
Call (559) 683-4694, write to Robert J. Brosi, DDS Inc., PO Box 2407, Oakhurst, CA 93644-2407, or email drbrosi@sti.net. Say which right you are exercising and what you are asking for. Please leave health details out of email.
-
We verify who you are
Before acting we need to be reasonably sure you are the person the information belongs to. For most requests we ask you to confirm two or three pieces of information we already hold, such as the name, telephone number and email address you used when you contacted us. For a request to receive specific pieces of information we need a higher degree of certainty, which may mean confirming details in person at the office or providing a signed declaration under penalty of perjury. If we cannot verify you we will say so and will not act on the request.
-
Authorized agents
You may use an authorized agent. The agent must give us written permission signed by you, and we may still contact you to confirm you gave that permission and to verify your own identity. An agent holding a valid power of attorney under the California Probate Code does not need separate written permission.
-
We respond
We confirm receipt within ten business days and answer within forty five calendar days. If we need longer we will tell you why, and any extension will be no more than a further forty five days. There is no charge unless a request is manifestly unfounded or excessive, and in that case we will explain the reason and any fee before doing the work.
-
If you disagree with our answer
Tell us, and we will look again. You may also contact the California Privacy Protection Agency or the California Attorney General. A complaint about your health information follows a different route, described in our Notice of Privacy Practices.
Do Not Track and Global Privacy Control
Some browsers send a Do Not Track header. There has never been a common agreement on what a website should do when it receives one, and this site takes no action on it, because there is no tracking here to switch off. Nothing on this site follows you across other websites whether the header is present or not.
Global Privacy Control is a different signal. It is a browser or extension setting that communicates an opt out of the sale and sharing of personal information, and California treats it as a valid opt-out request. This practice does not sell or share personal information, so a Global Privacy Control signal changes nothing about how the site behaves. There is nothing being sold or shared with it or without it.
The two optional third-party features stay off until you allow them, regardless of either signal.
Children's privacy
This website is written for adults and is not directed to children under thirteen. We do not knowingly collect personal information online from a child under thirteen, and there is nothing on the site aimed at getting a child to submit anything.
We do treat children as patients. When a child is a patient, a parent or legal guardian provides the information, signs the forms and exercises the child's rights on the child's behalf, subject to the limited situations in which California law allows a minor to consent to their own care and to control the resulting record.
If you believe a child has sent us information through this website, call the office at (559) 683-4694 and we will delete it.
How we protect information
The site is served only over an encrypted HTTPS connection. Because it is static there is no visitor database and no application server for an attacker to query for personal information. Access to the accounts that publish the site is limited to the people who maintain it and is protected by multi-factor authentication. Paper and electronic records inside the office are handled under the safeguards required of a dental practice, which are described in our Notice of Privacy Practices.
What we will not tell you is that any of this makes the internet safe. No method of transmitting or storing information is completely secure, and we cannot guarantee that something sent to us over the internet will not be intercepted or altered on the way. That is the honest position, and it is exactly why we ask you to keep health details off this website and out of email.
Changes to this policy
We update this policy when the site changes or when the law does. The effective date at the top of the page tells you which version you are reading. When a change is significant we will say what changed rather than quietly replacing the text.
Continuing to use the site after a change means the current version applies to your use of it.
How to reach us
Any question about this policy, or any request under it, can go to any of these.
- Practice
- Robert J. Brosi, DDS Inc., a California professional dental corporation
- Office
- 49414 Road 426, Oakhurst, California 93644
- PO Box 2407, Oakhurst, CA 93644-2407
- Phone
- (559) 683-4694
- Fax
- (559) 642-6219
- drbrosi@sti.net. Please keep health details out of email.
- In person
- You are welcome to raise anything in this policy at the front desk. Hours, directions and parking are on our contact page.
Related pages
- Notice of Privacy Practices, which governs your dental record and your protected health information.
- Terms of Use, which covers using this website.
- Accessibility Statement, which covers how the site is built and how to report a barrier.
- Contact, for our address, office hours, directions and telephone number.