VIAHLINK PRIVACY POLICY
Xviahlink Inc. (“Xviahlink”)
Effective Date: August 25, 2026 | Last Updated: August 25, 2026
This Privacy Policy describes how Xviahlink (“Xviahlink,” “we,” “us,” or “our”), the U.S. customer-facing platform operator collects, uses, discloses, stores, and protects personal information in connection with viahlink.com and related services.
1. Who We Are
Xviahlink Inc
200 Gates Rd Suite D
Little Ferry, New Jersey 07643
United States
Email: jinyongyoo@gmail.com
2. Information We Collect
We may collect business and account information such as business or practice name, representative or administrator name, business address, email address, telephone number, professional or business-license information, job title, username, login information, and other information necessary to establish and manage an Account.
Customers may submit case information including patient name or identifier where provided, Xviahlink case ID, tooth number, STL, PLY, OBJ, DICOM and similar files, intraoral scans, dental photographs, prescriptions, materials, shades, implant information, design Instructions, and case communications.
Case information may contain PHI or other sensitive information.
We may also collect billing contact information, invoice information, transaction records, payment status, and limited payment-method information.
Full payment card numbers may be processed directly by authorized payment providers rather than stored by Xviahlink.
We may automatically collect IP address, browser information, device information, login activity, service usage, security and audit logs, cookies, and diagnostic information.
3. How We Use Information
We may use information to create and manage accounts, verify customers, process cases, assign designers, provide and revise CAD designs, deliver files, issue invoices, process payments, provide support, communicate about cases, prevent fraud, maintain security, troubleshoot technical issues, improve the service, and comply with applicable legal obligations.
We do not use patient PHI for advertising or unrelated marketing purposes.
4. Patient Information and Data Minimization
Xviahlink may receive patient-related information necessary to provide CAD design services.
Where reasonably practicable, Xviahlink uses case IDs and access controls to reduce unnecessary disclosure of patient-identifying information.
Designers are intended to receive only information reasonably necessary to complete assigned cases.
Removing a patient name alone does not necessarily make health information legally de-identified under HIPAA.
5. HIPAA and Protected Health Information
Where Xviahlink creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity, Xviahlink may act as a Business Associate and the applicable BAA will govern PHI processing.
In the event of a conflict between this Privacy Policy and an applicable BAA concerning PHI, the BAA controls.
6. How We Share Information
Xviahlink does not sell personal information.
Information may be shared with authorized designers, affiliates, cloud and infrastructure providers, payment processors, email and communication providers, authentication services, security providers, professional advisers, government authorities where legally required, and parties involved in a merger, acquisition, financing, restructuring, or sale of the business.
Access is limited according to the applicable business purpose.
7. Designers and Subcontractors
Xviahlink may engage employees, independent contractors, affiliates, and third-party designers.
Where a third party creates, receives, maintains, or transmits PHI on behalf of Xviahlink and qualifies as a Business Associate subcontractor, Xviahlink will require applicable written HIPAA protections.
8. International Processing
Xviahlink may use authorized designers, affiliates, infrastructure providers, and service providers located in the United States, the Republic of Korea, Vietnam, or other jurisdictions.
Xviahlink’s primary service data and Case Files are hosted and stored on cloud infrastructure located in the Republic of Korea. Accordingly, personal information and Protected Health Information (“PHI”), where applicable, may be transferred to, stored, and processed in the Republic of Korea.
Xviahlink may also permit authorized designers and service providers located in other jurisdictions, including the United States and Vietnam, to access information as reasonably necessary to provide the Service.
Where personal information or PHI is transferred, stored, accessed, or processed outside the jurisdiction in which the Customer or patient is located, Xviahlink implements applicable contractual, administrative, technical, and organizational safeguards designed to protect such information in accordance with applicable privacy and security requirements.
Where PHI is involved, such processing will also be subject to the applicable Business Associate Agreement (“BAA”) and HIPAA requirements.
9. Security
Xviahlink implements reasonable administrative, technical, and physical safeguards designed to protect personal information and Protected Health Information (“PHI”), where applicable, against unauthorized access, use, alteration, disclosure, or destruction.
Such safeguards may include encryption of data in transit and at rest, authentication and access controls, role-based and least-privilege access, audit logging, security monitoring, access-management procedures, confidentiality obligations, and other security measures appropriate to the nature and sensitivity of the information.
Xviahlink periodically reviews and updates its security practices as appropriate to address evolving risks, technologies, and legal requirements.
However, no method of electronic transmission or storage is completely secure, and Xviahlink cannot guarantee absolute security.
10. Data Retention
Xviahlink retains personal information only for as long as reasonably necessary to provide the Service, administer Accounts, comply with legal and contractual obligations, resolve disputes, prevent fraud, and maintain the security of the Service.
Unless a longer retention period is required by applicable law, contractual obligation, or an applicable Business Associate Agreement, Xviahlink generally applies the following retention periods:
- Account Information: Maintained while the Account remains active. Accounts with no login or Case activity for twenty-four (24) consecutive months may be designated as inactive and may be deleted after reasonable advance notice to the Customer.
- Completed Case Files: Case Files, including digital scans, STL, PLY, OBJ and similar files, images, Design Instructions, and completed CAD Design files, are generally retained for up to twelve (12) months following completion of the applicable Case and may thereafter be securely deleted.
- Closed or Deleted Accounts: PHI and Case Files associated with a terminated or deleted Account will generally be returned or securely deleted within ninety (90) days, unless continued retention is required by applicable law, the applicable BAA, or is otherwise legally necessary.
- Billing and Transaction Records: Invoice, payment, and transaction records may be retained for up to seven (7) years or for such longer period as required by applicable tax, accounting, or other legal requirements.
- HIPAA and Compliance Records: Documentation required to be maintained under HIPAA will be retained for the period required by applicable law.
Where PHI is subject to a Business Associate Agreement, PHI will be returned, destroyed, or retained in accordance with the applicable BAA and HIPAA requirements.
Deletion from active systems may not result in immediate deletion from secure backup systems. Information contained in backups may remain until overwritten or deleted in accordance with Xviahlink's backup retention procedures.
11. Privacy Rights
Depending on applicable law and jurisdiction, individuals may have rights relating to access, correction, deletion, copies of personal information, and certain restrictions or objections to processing.
To exercise any applicable privacy rights, please submit a request to jinyongyoo@gmail.com.
Xviahlink may take reasonable steps to verify the identity or authority of the person making the request before processing or fulfilling the request.
We will respond to verified requests within the time period required by applicable law.
12. Cookies and Similar Technologies
Xviahlink uses cookies and similar technologies to operate and secure the Service, maintain user sessions, remember user preferences, and improve the performance and functionality of the Service.
Certain cookies are necessary for the Service to function properly, including cookies used for authentication, account security, session management, and fraud prevention. These essential cookies may be used without separate consent where permitted by applicable law.
Xviahlink may also use analytics or similar technologies to understand how users interact with the Service and to improve its functionality and user experience. Where required by applicable law, Xviahlink will obtain consent before using non-essential cookies or similar technologies.
Users may manage certain cookie preferences through their browser settings or through any cookie preference tools made available by Xviahlink. Disabling certain cookies may affect the functionality of the Service.
13. Marketing Communications
Marketing communications may be sent where permitted by law and, where required, after applicable consent.
Marketing consent is optional and may be withdrawn at any time.
Withdrawal from marketing does not prevent Account, billing, Case, security, or other necessary transactional communications.
14. Children's Privacy
The Service is designed for professional and business users and is not directed to children under thirteen (13).
Patient information concerning minors submitted by authorized healthcare Customers is handled in accordance with applicable privacy requirements and, where applicable, the BAA.
15. Security Incidents
If a security incident involving information requires notification under applicable law, Xviahlink will provide the required notification.
Additional requirements relating to PHI are outlined in the applicable BAA.
16. Changes to this Privacy Policy
Xviahlink may update this Privacy Policy from time to time.
Material changes will be communicated through the Service, email, or another reasonable method where required by applicable law.
17. Contact
Xviahlink Inc
200 Gates Rd Suite D
Little Ferry, New Jersey 07643
United States
Privacy Contact: Jin Yong Yoo / CEO
Email: jinyongyoo@gmail.com