Privacy Policy
Contents
1. Who We Are, and What the Present Policy Covers
1.1 DTCONCIERGE S.R.L., a limited liability company incorporated under the laws of Romania, with registered office at Aleea Călărașilor nr. 5, bl. G, ap. 54, Municipiul Sibiu, județul Sibiu, Romania, registered with the Trade Register under number J2026003869000, unique registration code 53369247, intra-Community VAT identification number RO54852877, operates the DentalPolyglot service (the "Service"). References to "we", "us", and "our" are references to that company.
1.2 The present Policy explains how we process personal data when we act as controller, namely in relation to the dental clinics and other professional undertakings that subscribe to the Service, the individuals who use those subscribers' accounts, the individuals who contact us, and the professional contacts we approach about the Service.
1.3 Personal data relating to patients of a subscribing clinic is processed by us as a processor acting on that clinic's instructions. Section 6 explains the distinction and identifies where a patient will find the information addressed to them.
1.4 Processing described here is governed by Regulation (EU) 2016/679 (the "GDPR") and by Romanian Law no. 190/2018 on measures implementing that Regulation. Processing carried out through electronic communications is additionally governed by Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector.
1.5 Our privacy contact is privacy@dentalpolyglot.com. Correspondence sent to that address reaches a member of staff responsible for data protection matters.
2. Our Two Roles
2.1 We act as controller for the personal data of our subscribers and their personnel, for billing and accounting data, for support correspondence, for the data of professional contacts we approach, and for the technical data generated when the Service is operated and secured. We determine the purposes and the means of that processing.
2.2 We act as processor for personal data relating to patients and prospective patients that a clinic causes to be processed through the Service, including data concerning health within the meaning of Article 9 of the GDPR. The clinic is the controller of that data, determines why and how it is processed, and instructs us through the Data Processing Agreement concluded with us.
2.3 Because we process special categories of personal data on behalf of controllers, the exemption in Article 30(5) of the GDPR for undertakings employing fewer than 250 persons does not apply to us. We maintain records of processing activities covering both our controller processing and our processor processing, in accordance with Article 30(1) and Article 30(2) of the GDPR.
2.4 Assigning the roles in Sections 2.1 and 2.2 does not diminish anyone's rights. A patient exercising a right addresses the clinic as controller, and we assist the clinic in responding, as Section 13.5 explains.
3. Personal Data We Process as Controller
3.1 Account and identity data. The legal name of the subscribing undertaking, its registered office or place of business, its registration number, its VAT identification number where it holds one, and the name, professional email address, professional telephone number, and role of the individuals authorised to use the account.
3.2 Authentication data. Credentials associated with each authorised user, held in the form of a password hash produced by the Argon2id algorithm rather than as a recoverable password, together with second-factor configuration where enabled, session identifiers, and records of sign-in events.
3.3 Billing data. Subscription tier, billing period, invoice history, amounts charged, tax status, and the payment records produced by our payment provider. Full payment-card numbers do not reach our systems, because card details are collected and held by our payment provider on its own infrastructure, and we receive only a token, the card type, the last digits, and the expiry date.
3.4 Support and correspondence data. The content of messages sent to us, the address they are sent from, the attachments they carry, and the notes we make when handling a request.
3.5 Prospect data. The professional contact particulars of dental practices we approach about the Service, comprising the practice name, a business email address, a business telephone number where published, the practice website, the country of establishment, and the source from which the particulars were obtained, together with the record of any contact and of any objection received.
3.6 Technical and security data. Internet protocol addresses, request metadata, user-agent strings, rate-limiting counters, error diagnostics, and audit records generated when the Service is used. Diagnostic records transmitted to our error-monitoring provider are stripped of personal data before transmission, and session replay is not enabled.
3.7 Onboarding data. The address of the clinic's existing public website, the materials the clinic supplies for the build, the language selections it makes, and a rendered image of its public website captured during onboarding. Personal data appearing within that material is present because the clinic has published it or supplied it, and we process it in order to construct the Tenant Site.
3.8 We do not process special categories of personal data in our capacity as controller. Where such data reaches us, it does so within Patient Data and is governed by Section 6.
4. Purposes and Legal Bases
4.1 Supplying the Service. Creating and administering accounts, building and hosting the Tenant Site, operating the enquiry and messaging tools, and providing support. The legal basis is performance of a contract, or steps taken at the request of the subscriber before entering into one, under Article 6(1)(b) of the GDPR.
4.2 Billing, invoicing, and accounting. Charging fees, issuing invoices, maintaining accounting records, and meeting our tax obligations. The legal basis is compliance with a legal obligation under Article 6(1)(c) of the GDPR, read with Law no. 82/1991 on accounting and with Romanian fiscal legislation.
4.3 Security, integrity, and prevention of abuse. Authenticating users, detecting and investigating unauthorised access, applying rate limits, protecting against automated abuse, and maintaining audit records. The legal basis is our legitimate interest under Article 6(1)(f) of the GDPR in protecting the Service, its subscribers, and the individuals whose data it holds. We have assessed that interest against the interests and fundamental rights of the individuals concerned and recorded the assessment.
4.4 Diagnosing faults and maintaining the Service. Monitoring errors, investigating incidents, and correcting defects. The legal basis is our legitimate interest under Article 6(1)(f) of the GDPR in supplying a functioning and reliable service, exercised through diagnostic records from which personal data has been removed before transmission.
4.5 Service communications. Sending messages concerning the operation of the Service, including renewal reminders, notices of change, security notices, and information about a change of sub-processor. The legal basis is performance of the contract under Article 6(1)(b) of the GDPR and, for notices we are obliged to send, compliance with a legal obligation under Article 6(1)(c).
4.6 Approaching prospective customers. Identifying dental practices that may benefit from the Service and contacting them about it. The legal basis for the underlying processing is our legitimate interest under Article 6(1)(f) of the GDPR in promoting our business, and Section 5 sets out the separate and stricter rules that govern the sending of the communication itself.
4.7 Meeting obligations under digital services law. Operating contact points, receiving and assessing notices concerning content, issuing statements of reasons, acting on orders from competent authorities, and notifying suspicions of serious criminal offences where Article 18 of Regulation (EU) 2022/2065 requires it. The legal basis is compliance with a legal obligation under Article 6(1)(c) of the GDPR.
4.8 Establishing, exercising, and defending legal claims. Retaining the records necessary to demonstrate what was agreed, what was supplied, and what was accepted, including the record of clause-by-clause acceptance required by Article 1203 of the Romanian Civil Code. The legal basis is our legitimate interest under Article 6(1)(f) of the GDPR, and, where a retention period is imposed by law, compliance with a legal obligation under Article 6(1)(c).
4.9 Where we rely on legitimate interests, an individual may object at any time under Article 21 of the GDPR, and Section 13 explains how. Where the objection concerns direct marketing, we stop without assessing the balance of interests.
5. Approaching Professional Contacts, and Commercial Communications
5.1 Article 12 of Law no. 506/2004 prohibits the sending of commercial communications by electronic mail, by automated calling systems, or by fax unless the subscriber has given prior express consent. Article 12 applies to subscribers that are legal persons in the same way as it applies to natural persons, so the requirement is not displaced by the fact that we address businesses rather than individuals.
5.2 We therefore send commercial electronic mail only where prior consent has been recorded, or where the narrow exception for existing customers applies, namely where we obtained the address directly in the course of supplying a service to that customer, where the communication concerns similar services of our own, and where the recipient was given, and continues to be given at each communication, a clear and free means of objecting.
5.3 Every commercial communication we send identifies us clearly, discloses on whose behalf it is sent, and carries a valid address to which a request to stop may be sent. We do not conceal or falsify the identity of the sender, and we do not omit a means of objection.
5.4 Where a professional contact asks not to be approached again, we record the request and honour it. The record is retained for the reason given in Section 10.5, and it exists solely in order to prevent further contact.
5.5 Approaching a contact through a channel other than those listed in Section 5.1, such as ordinary post or a telephone call made by a person rather than by an automated system, remains subject to the GDPR and to the transparency and objection rights described in Sections 4.9 and 13.
6. Patient Data, and Our Role as Processor
6.1 When a clinic uses the Service, patients and prospective patients send enquiries, exchange messages, receive treatment plans, upload documents, and arrange appointments from the scheduling page attached to a treatment plan. The personal data generated by those activities is Patient Data, the clinic is its controller, and we process it only on the clinic's documented instructions.
6.2 Patient Data commonly includes contact particulars, the content of messages, data concerning health such as diagnoses, findings, and treatment plans, uploaded medical documents such as radiographs, identity or insurance documents where the clinic requests them, and appointment details. Data concerning health constitutes a special category under Article 9 of the GDPR.
6.3 The exemption in Article 9(2)(h) of the GDPR for the provision of health care is available only where processing is carried out by or under the responsibility of a professional subject to an obligation of professional secrecy under Article 9(3). The condition is satisfied by the clinic and is never satisfied by us, a point we record so that no clinic assumes otherwise when selecting its lawful basis.
6.4 Identity documents may contain a national identification number, which in Romania is the personal numerical code. Article 4 of Law no. 190/2018 attaches additional safeguards, including the mandatory designation of a data protection officer, where such a number is processed on the basis of legitimate interests. Our processing instructions accordingly exclude legitimate interests as a basis for processing a national identification number, so that neither we nor our clinics are drawn into that regime inadvertently.
6.5 We do not use Patient Data for our own purposes. Patient Data is not sold, is not used for advertising, and is not used to train or to improve any artificial intelligence model, whether ours or a third party's.
6.6 Patients are informed about the processing by the clinic, through the privacy notice published on the clinic's site. We maintain the master text of that notice and keep current the particulars it contains concerning our sub-processors and our transfer mechanisms, as a technical and organisational measure assisting the controller under Article 28(3)(e) and (f) of the GDPR.
6.7 The full description of the processing, the security measures applied, and the list of authorised sub-processors are set out in the Data Processing Agreement and its annexes, available at https://dentalpolyglot.com/en/legal/dpa.
7. Where the Data Comes From
7.1 Most of the personal data we hold as controller is supplied to us directly by the subscriber, by its authorised users, or by the person who contacts us.
7.2 Billing records are generated by our payment provider in the course of processing a payment, and are returned to us in the form described in Section 3.3.
7.3 Technical and security data is generated automatically by the systems that operate the Service.
7.4 Prospect data is obtained from publicly accessible sources, principally the practice's own website, public professional directories, and public business registers. We collect the professional contact particulars of the practice and do not compile profiles of the individuals working within it.
7.5 Onboarding material is retrieved from the public website the subscriber identifies, with the subscriber's authorisation and on its instruction.
8. Recipients and Sub-Processors
8.1 Personal data is disclosed within our organisation only to those who need it in order to perform their function, and each of them is bound by an obligation of confidentiality.
8.2 We engage the following providers. Vercel Inc. supplies hosting, content delivery, file storage, custom-domain management, cookieless analytics, and bot protection, with compute and storage located in the European Union, in the Frankfurt region, and with access from the United States remaining possible for support and operational purposes. Neon, LLC supplies the primary database, located in the European Union, in the Frankfurt region. Anthropic Ireland, Limited, which is the entity contracting with customers established in the European Economic Area, supplies the artificial intelligence processing used for translation, for extraction of treatment-plan text, and for the conversational assistant, carried out on infrastructure operated in the United States by Anthropic, PBC. Resend delivers transactional email and handles bounces and complaints. Upstash supplies rate limiting and short-lived caching, holding technical identifiers only. Functional Software, Inc., trading as Sentry, supplies application error monitoring, with data stored in the European Union, in the Frankfurt region, and with personal data removed before transmission. Stripe operates subscription billing for our subscribers, and no Patient Data reaches it. ScreenshotOne renders an image of the clinic's own public website during onboarding and receives only a public address.
8.3 An optional relay of patient messages over the WhatsApp Business Platform, supplied to businesses in the European Economic Area by WhatsApp Ireland Limited under its Business Data Processing Terms and Business Data Transfer Addendum, has been built but is not activated. Activation is a decision for the individual clinic, and until a clinic activates it no message is relayed through that channel and no data is disclosed to that provider.
8.4 We disclose personal data to our professional advisers, to our accountants, and to our auditors where they need it in order to advise us, each of them being bound by professional or contractual confidentiality.
8.5 We disclose personal data to a competent authority where an order, a judgment, or a statutory requirement obliges us to do so. We examine each request for validity, we resist requests that are defective or excessive, and, unless prohibited, we inform the affected subscriber.
8.6 Where our business or a relevant part of it is transferred, personal data may be disclosed to the acquirer and to its advisers, subject to appropriate confidentiality undertakings, and subscribers are informed.
8.7 We do not sell personal data, we do not disclose it to advertising networks, and we do not use it for cross-site tracking or profiling for advertising.
8.8 The current list of sub-processors engaged in the processing of Patient Data, with the function, the location, and the transfer mechanism applicable to each, is maintained in Annex B to the Data Processing Agreement. Subscribers receive at least thirty days' notice before a sub-processor is added or replaced, and may object on reasonable grounds relating to data protection.
9. Transfers Outside the European Economic Area
9.1 The application and the primary database are located in the European Union, in the Frankfurt region. Certain of the providers listed in Section 8.2 are established in the United States, or process data there, and transfers to them are made only where a valid transfer mechanism under Chapter V of the GDPR is in place.
9.2 Transfers to our artificial intelligence provider are made on the basis of the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, applying the module governing transfers from a processor to a sub-processor. We do not rely on any certification of that provider under the EU-US Data Privacy Framework, and no adequacy decision is relied upon in respect of those transfers.
9.3 Transfers to providers that maintain a current certification under the EU-US Data Privacy Framework are made in reliance on Commission Implementing Decision (EU) 2023/1795 of 10 July 2023, with the Standard Contractual Clauses concluded in addition so that a mechanism remains in place should a certification lapse. Certifications are verified against the official list published at https://www.dataprivacyframework.gov before reliance is placed on them, and are reverified at each review of the present Policy.
9.4 Transfers to providers that do not maintain such a certification are made on the basis of the Standard Contractual Clauses alone.
9.5 For every transfer, we have assessed the law and practice of the destination country as it bears on the effectiveness of the mechanism relied upon, and we apply supplementary measures where the assessment calls for them. Measures applied include encryption in transit, minimisation of the data actually transmitted, removal of personal data from diagnostic records before transmission, contractual commitments concerning government access requests, and contractual exclusion of the use of transmitted content for model training.
9.6 Independently of the GDPR, Article 32 of Regulation (EU) 2023/2854 obliges us to take adequate technical, organisational, and legal measures to prevent third-country governmental access to, or transfer of, non-personal data held in the Union where such access would conflict with Union or Member State law. The measures described in Section 9.5 serve that obligation as well.
9.7 A copy of the safeguards applying to a particular transfer, with commercially sensitive terms redacted, is supplied on request to privacy@dentalpolyglot.com.
10. How Long We Keep Personal Data
10.1 Subscriber account data is retained for the duration of the contractual relationship. Following termination, the account remains available in read-only form for ninety days so that the subscriber may export its content and data, and the account and its contents are deleted at the end of that period.
10.2 Accounting records and supporting documents, including invoices, are retained for five years calculated from 1 July of the year following the end of the financial year in which they were drawn up, in accordance with Article 25 of Law no. 82/1991 as amended by Law no. 36/2023. Annual financial statements are retained for ten years.
10.3 Support correspondence is retained for the duration of the relationship and for twenty-four months thereafter, so that a matter raised late in the relationship can be reconstructed, after which it is deleted.
10.4 Prospect data is retained for eighteen months from the last contact, and is deleted at the end of that period unless the contact has become a subscriber, in which case Section 10.1 applies.
10.5 Records of objection to being contacted are retained without a fixed limit. Retention is necessary because the record is the mechanism that prevents further contact, and deleting it would allow a person who has objected to be approached again in error. The record contains only what is required to achieve suppression, namely the address or number to be excluded and the date of the objection, and is used for no other purpose.
10.6 Patient Data is retained in accordance with the instructions of the clinic that controls it. Under the retention rules configured in the Service, an enquiry that does not result in a treatment plan is deleted twenty-four months after the last activity on it. A request for erasure is executed within thirty days of receipt. Where a clinic instructs a different period in order to meet its own medical-record obligations, the clinic's instruction governs.
10.7 Backups operate through two distinct mechanisms, described separately because their consequences for deleted data differ. The primary database maintains a continuous recovery window of approximately six hours, from which the state of the data at any moment falling within that window can be restored. An encrypted nightly snapshot of the database is taken in addition and held outside the platform on which the Service runs, under AES-256-GCM encryption, so that an incident affecting the platform does not carry away the only copy of the data.
10.8 Snapshot retention is fixed at thirty days from the date on which each snapshot is taken, after which the snapshot is destroyed, and no further archival copy is created or kept. Data deleted from the live systems accordingly ceases to be recoverable from the continuous window once six hours have elapsed, and ceases to be recoverable from the snapshots once the last snapshot containing it has been destroyed, which occurs within thirty days of the deletion. Where the deletion is executed in response to a request under Section 10.6, the thirty-day period runs from the execution of the deletion and not from the date on which the request was received.
10.9 Use of a snapshot is confined to recovery from a failure, a corruption, or a comparable incident affecting the live systems. A snapshot is not consulted in order to retrieve a record that has been deleted, and is not used to reinstate data whose erasure a clinic or a data subject has caused. Where a restoration nevertheless reinstates a record deleted before the incident, the deletion is applied again to the restored system as soon as the restoration is complete, and the event is entered in our records. Access to a snapshot is governed by the principle of least privilege described in Section 11.3.
10.10 Security and audit records are retained for the period necessary to investigate an incident and to demonstrate the integrity of the Service, and are deleted once that period has elapsed. Diagnostic records transmitted to our error-monitoring provider are retained for the shorter of the period configured in that service and the period necessary to correct the defect.
10.11 Where personal data is required in order to establish, exercise, or defend a legal claim, or in order to comply with an obligation imposed on us, retention continues for so long as the claim or the obligation subsists, notwithstanding the periods above, and is limited to the data actually required for that purpose.
11. Security
11.1 We apply technical and organisational measures appropriate to the risk, in accordance with Article 32 of the GDPR, and we review them as the Service and the threat environment change.
11.2 Measures in force include encryption of data in transit, storage of passwords as Argon2id hashes rather than in recoverable form, isolation of each subscriber's data at the database level through row-level security, role-based access control, second-factor authentication on administrative access, restriction of administrative access to the smallest workable group, rate limiting on sensitive endpoints, removal of personal data from error diagnostics before transmission, and backups comprising point-in-time recovery within the database together with encrypted snapshots held apart from it.
11.3 Personnel with access to personal data are bound by confidentiality and receive instruction appropriate to their role. Access is granted on the principle of least privilege and is withdrawn when it ceases to be required.
11.4 No measure eliminates risk entirely. Where an individual believes that an account has been compromised or that a vulnerability exists, the matter should be reported to privacy@dentalpolyglot.com, and we will investigate.
12. Personal Data Breaches
12.1 We maintain a documented procedure for detecting, assessing, containing, and recording personal data breaches, and every breach is recorded whether or not it becomes notifiable.
12.2 Where we act as controller and a breach is likely to result in a risk to the rights and freedoms of natural persons, we notify the competent supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of it, in accordance with Article 33 of the GDPR. Where the risk is high, we also inform the affected individuals in accordance with Article 34.
12.3 Where we act as processor, we notify the affected clinic without undue delay after becoming aware of a breach, and in any event within forty-eight hours, in accordance with Article 33(2) of the GDPR and with the Data Processing Agreement. The clinic then determines what notification its own obligations require.
12.4 Our notification states the nature of the breach, the categories and approximate number of individuals and records concerned, the likely consequences, the measures taken or proposed, and the point of contact from which further information may be obtained.
13. Your Rights
13.1 Subject to the conditions the GDPR attaches to each of them, an individual has the right of access under Article 15, the right to rectification under Article 16, the right to erasure under Article 17, the right to restriction of processing under Article 18, the right to data portability under Article 20, and the right to object under Article 21. Where processing rests on consent, consent may be withdrawn at any time under Article 7(3), without affecting the lawfulness of processing carried out before the withdrawal.
13.2 A request may be sent to privacy@dentalpolyglot.com or, where a request form is published on our website, submitted through that form. No fee is charged, save where a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, explaining why.
13.3 We respond without undue delay and in any event within one month of receipt. Where a request is complex, or where several requests have been received, the period may be extended by two further months, and we inform the individual of the extension and of the reasons for it within the first month.
13.4 Where we cannot identify the individual from the information supplied, we may ask for further particulars sufficient to confirm identity. We ask only for what is necessary, and we do not use the information supplied for that purpose for any other end.
13.5 Where a request concerns Patient Data, the clinic is the controller and the request is properly addressed to it. Where a patient contacts us directly, we forward the request to the clinic concerned without undue delay, inform the patient that we have done so, and assist the clinic in responding as Article 28(3)(e) of the GDPR requires.
14. Complaining to a Supervisory Authority
14.1 An individual who considers that our processing infringes data protection law may lodge a complaint with a supervisory authority, in the Member State of their habitual residence, of their place of work, or of the alleged infringement, in accordance with Article 77 of the GDPR.
14.2 Our lead supervisory authority is the National Supervisory Authority for Personal Data Processing of Romania, at B-dul General Gheorghe Magheru nr. 28-30, Sector 1, 010336 Bucharest, Romania, reachable at anspdcp@dataprotection.ro and at https://www.dataprotection.ro.
14.3 Recourse to a supervisory authority does not exclude a judicial remedy, and an individual may also bring proceedings before the competent courts under Articles 79 and 82 of the GDPR.
14.4 We would ordinarily prefer the opportunity to resolve a concern directly, and an approach to privacy@dentalpolyglot.com is often the quicker route, but nothing obliges an individual to contact us before approaching an authority.
15. Automated Decision-Making, Profiling, and Artificial Intelligence
15.1 We do not take decisions producing legal effects concerning an individual, or similarly significantly affecting an individual, based solely on automated processing within the meaning of Article 22 of the GDPR.
15.2 Artificial intelligence is used to translate content and messages, to extract text from treatment-plan documents, and to operate a conversational assistant. None of those functions evaluates a person, scores a person, or determines an outcome concerning a person.
15.3 The conversational assistant discloses that it is an artificial intelligence system at the point of first interaction, in satisfaction of Article 50(1) and Article 50(5) of Regulation (EU) 2024/1689, applicable since 2 August 2026. Automatically translated messages are labelled where they are displayed.
15.4 Content submitted to our artificial intelligence provider is excluded by contract from use in training or improving models, and the transfer safeguards described in Section 9.2 apply to it.
15.5 Automated systems are used in the operation of rate limiting and abuse prevention, and in the automated check on advertising language described in the Copyright, Content Licence, and Notice-and-Action Policy. Where such a check contributes to a decision to restrict content, the decision is disclosed as having involved automated means and a member of staff re-examines it on request.
16. Data Protection Officer, and Our Privacy Contact
16.1 We have not designated a data protection officer. The assessment supporting that position is recorded, is reviewed at least annually, and rests on the following reasoning.
16.2 Article 37(1)(c) of the GDPR requires designation where the core activities of a controller or processor consist of processing special categories of data on a large scale. Receiving, storing, and translating patient health enquiries is inextricable from our product, so the core-activities limb is satisfied and we do not argue otherwise. The large-scale limb is assessed against the number of data subjects, the volume of data, the duration of the processing, and the geographical extent of it, and on the present scale of operations we consider that it is not met.
16.3 The assessment is reconsidered on the occurrence of any of the following, whichever occurs first: reaching ten live clinic subscribers; operating live subscribers in two or more countries; any processing of a national identification number or other special category of data on the basis of legitimate interests, which would in any event engage Article 4 of Law no. 190/2018; any new processing of special categories of data outside the current product scope; or the expiry of twelve months from the last assessment.
16.4 Should designation become mandatory, we will appoint an external data protection officer under a service contract as Article 37(6) of the GDPR permits, notify the National Supervisory Authority for Personal Data Processing, and publish the contact particulars in the present Policy.
16.5 Until then, privacy@dentalpolyglot.com is our designated privacy contact. The address is not a data protection officer within the meaning of Article 37, and we describe it accordingly rather than allowing an impression to the contrary. Requests, complaints, and breach correspondence are routed through it.
17. Children
17.1 The Service is contracted by professional undertakings, and accounts are not opened by or for children.
17.2 Patients who contact a clinic through a Tenant Site may be minors. Determining the age at which a minor may consent, and obtaining the authorisation of a holder of parental responsibility where Article 8 of the GDPR requires it, are matters for the clinic as controller, and the age thresholds differ between Member States. The patient privacy notice we maintain includes short prompts drawing the point to the attention of the person completing a form.
17.3 Where we become aware that a child's data has been submitted without the necessary authorisation, we inform the clinic concerned so that it may act on it.
18. Cookies and Similar Technologies
18.1 We set five first-party cookies and no others, four of them strictly necessary and the fifth recording a language the visitor has selected, we serve no advertising trackers, and we display no consent banner, on the basis explained in the Cookie Policy.
18.2 The Cookie Policy sets out the name, purpose, and duration of each cookie, the treatment of local storage, the cookieless approach to measurement, and the position on hosted clinic sites. The subject is not repeated here.
19. Changes to the Present Policy
19.1 The present Policy is reviewed at least annually and whenever a material change is made to the Service, to our sub-processors, to our transfer mechanisms, or to the law applying to us.
19.2 The current version and the date of its last revision are published at https://dentalpolyglot.com. Where a change materially affects our subscribers, we notify them at their registered email address before it takes effect.
19.3 Superseded versions are retained and supplied on request to privacy@dentalpolyglot.com, so that an individual may establish which version applied at a given time.
20. Contact
20.1 DTCONCIERGE S.R.L., Aleea Călărașilor nr. 5, bl. G, ap. 54, Municipiul Sibiu, județul Sibiu, Romania. Data protection correspondence: privacy@dentalpolyglot.com. General correspondence: service@dentalpolyglot.com. Website: https://dentalpolyglot.com.