How dentisti.pro collects, processes, stores, and protects personal data within our dental clinic management platform.
The operator of the dentisti.pro platform is the controller for platform-level business data such as clinic accounts, billing, and support records. Each clinic using the platform remains the independent controller for patient health data entered into the system.
dentisti.pro processes patient records strictly as a processor under GDPR Article 28 and the applicable Data Processing Agreement.
Where required by law or operationally appointed, a Data Protection Officer coordinates privacy governance, advises on compliance, and acts as a contact point for data subject and supervisory authority inquiries.
You can contact the DPO using the dedicated public contact route or by email at dpo@dentisti.pro.
The platform may process patient identity data, contact information, appointment records, clinical notes, dental charts, imaging files, billing records, communication logs, and consent records.
We also process clinic staff account data, role and permission settings, audit logs, security events, profile data, clinic identity data, subscription data, and limited technical telemetry required to operate the service securely.
Automatically collected data may include IP address, browser type, device metadata, session identifiers, feature usage events, and error or security logs.
We rely on contractual necessity, legal obligation, explicit consent where required, legitimate interests, and vital interests in emergency situations, depending on the specific processing activity.
Health data is special category data under Article 9 GDPR and is processed for healthcare delivery, clinical record management, and related regulated treatment operations carried out by authorized professionals.
Personal data is processed only for specific and legitimate purposes including patient record management, appointment coordination, billing, communications, reporting, security monitoring, customer support, product maintenance, and legal compliance.
We do not use personal data for automated decision-making that produces legal or similarly significant effects on patients or staff.
Data is retained only as long as necessary for the purpose collected or for applicable legal retention duties. Clinical, billing, audit, security, backup, and consent records may each have different retention schedules depending on regulatory and operational need.
Once retention periods expire, data is deleted or irreversibly anonymized using methods appropriate to the storage medium and risk level.
Under GDPR, data subjects may have rights of access, rectification, erasure, restriction, portability, objection, and complaint. Patients should usually exercise these rights first with their clinic, because the clinic is the controller of patient care records.
Clinic staff or platform-level requesters may contact our DPO for rights requests related to platform-operated data.
Obtain confirmation and a copy of personal data.
Correct inaccurate or incomplete data.
Request deletion when lawful grounds apply.
Limit processing while disputes are assessed.
Receive data in a structured export where applicable.
Object to certain processing based on legitimate interests.
We use carefully selected service providers for hosting, payments, backups, communications, and operational support. Where subprocessors are involved, they are bound by contractual and data protection obligations appropriate to their role.
Primary data hosting is designed around EU-first storage. Where third-country transfers occur, they rely on safeguards such as Standard Contractual Clauses, technical controls, minimization, and vendor contractual commitments where required.
We apply technical and organizational measures proportionate to the risks of processing health and operational data. These may include encryption, RBAC, MFA support, session safeguards, input validation, logging, backup protection, and vendor infrastructure controls.
Security controls depend in part on the hosting environment and service configuration, but the design goal is confidentiality, integrity, availability, and traceability.
We use necessary cookies for sessions, consent, and security. Functional cookies may support interface preferences such as theme or language. Optional analytics are only loaded where consent and configuration allow it.
We do not rely on third-party marketing trackers or advertising pixels as a default part of the platform experience.
We maintain incident response processes and breach records. Where applicable law requires notification, relevant authorities and affected parties are informed within the legally required timelines, taking into account the severity and scope of the event.
Security-related inquiries can be directed to security@dentisti.pro.
Data subjects may lodge a complaint with a competent supervisory authority in their place of residence, work, or the place of the alleged infringement. We encourage direct contact first so concerns can be reviewed and resolved promptly where possible.
We may update this Privacy Policy to reflect changes in law, operations, infrastructure, or product features. Material changes are communicated in advance when required.
The current version is always published at this URL.