For protected health information (PHI) handled by our CBCT imaging service, see also the HIPAA Notice of Privacy Practices.
1. Who We Are
This privacy policy is published by MyNavi Scan, LLC (“MyNavi Scan,” “we,” “us”), a mobile CBCT imaging service operating in Chicago, Illinois. Website: mynaviscan.com. Contact: mynaviscan@gmail.com · 312-999-0550.
2. Information We Collect
2.1 Information you give us
- Booking forms (patient or clinic): name, phone, email, referring practice, clinical indication (if provided).
- Contact form: name, email, message.
- Direct communication: phone, WhatsApp, SMS, email content you send us.
2.2 Information collected automatically
- IP address, browser type and version, operating system
- Pages visited, time on page, referring URL
- Approximate location at the city level (from IP)
2.3 Cookies and similar technologies
Our site uses a minimal set of strictly-necessary cookies for session continuity. We do not currently set advertising or cross-site tracking cookies. If we add analytics in the future, this policy will be updated and the cookie banner will list each cookie.
3. How We Use Information
- To schedule and perform CBCT scans
- To respond to your inquiries
- To send appointment confirmations and DICOM-delivery notifications
- To improve the website and detect abuse
- To comply with legal obligations under Illinois and federal law
4. Legal Bases (for visitors covered by GDPR/CPRA)
Where applicable, we process personal information on the bases of (a) your consent, (b) performance of a contract (delivering a scan you booked), (c) our legitimate interest in operating a safe and efficient service, and (d) compliance with legal obligations.
5. Sharing of Information
We share information only with:
- The referring dental or medical practice that ordered the scan.
- Sub-processors who help us operate — Google Workspace (DICOM delivery and email), Twilio (SMS appointment notifications), n8n (workflow automation, self-hosted), and Bitrix24 (CRM). Each is bound by contractual confidentiality obligations and, where applicable, a HIPAA Business Associate Agreement.
- Authorities, when required by law.
We do not sell personal information and we do not share PHI with advertising platforms.
6. Data Retention
Booking-form data is retained for the period required to deliver the scan and to satisfy Illinois recordkeeping requirements (typically seven (7) years for medical-imaging records). Website analytics, where collected, are retained for no longer than fourteen (14) months.
7. Your Rights
- Access, correct, or delete personal information about you
- Object to or restrict certain processing
- Withdraw consent at any time
- Receive a copy of your information in a portable format
- Lodge a complaint with a supervisory authority
To exercise any right: mynaviscan@gmail.com.
8. Security
We use TLS encryption for all data in transit, encrypted storage at rest, role-based access controls, and audit logging. No method of transmission over the Internet is 100% secure, but we apply the safeguards required by HIPAA and reasonable industry practice.
9. Children
Our website is not directed to children under 13. We do scan patients under 13 only on the prescription of their dentist or physician, with the consent of a parent or legal guardian, and the resulting PHI is handled under HIPAA.
10. Changes
This policy may be updated. Material changes will be posted on this page with an updated date. Continued use of the site after a change indicates acceptance.
11. Contact
MyNavi Scan, LLC · Chicago, IL · 312-999-0550 · mynaviscan@gmail.com