Cookie Policy
Contents
1. Scope, and Who Is Responsible
1.1 The present Policy explains what is stored on, and read from, the terminal equipment of a person who visits the website of DentalPolyglot, who signs in to the clinic dashboard, or who visits a multilingual website we host on behalf of a dental clinic.
1.2 Responsibility for the Service rests with DTCONCIERGE S.R.L., a company incorporated in Romania whose registered office is at Aleea Călărașilor nr. 5, bl. G, ap. 54, Municipiul Sibiu, județul Sibiu, Romania, entered in the Trade Register under number J2026003869000, holding unique registration code 53369247 and intra-Community VAT identification number RO54852877. Questions concerning the present Policy reach us at privacy@dentalpolyglot.com.
1.3 The present Policy forms part of the Agreement described in Section 1.3 of the Terms of Service and complements the Privacy Policy, which explains how personal data is processed once it has been collected. Storage and access are addressed here, and the processing that follows is addressed there.
2. The Legal Framework
2.1 Storing information on, or gaining access to information already stored on, the terminal equipment of a subscriber or user is regulated in Romania by Article 4(5) of Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, which transposes Article 5(3) of Directive 2002/58/EC. As a rule, the operation is permitted only where the subscriber or user has consented after receiving clear and complete information.
2.2 Article 4(6) of the same Law establishes an exception. Consent is not required where the storage or the access is carried out exclusively for the purpose of transmitting a communication over an electronic communications network, or where it is strictly necessary in order to supply an information society service expressly requested by the subscriber or the user.
2.3 Where the information stored or accessed also constitutes personal data, Regulation (EU) 2016/679 governs the subsequent processing, and the Privacy Policy describes it.
2.4 Reform of the framework described above is under discussion at Union level. Until an amending instrument is adopted and becomes applicable, the rules stated in Sections 2.1 and 2.2 are the rules in force, and the present Policy is written to them. The position is reassessed at each review under Section 11.
3. Cookies We Set
3.1 Five cookies are set across the surfaces we operate, and no others. All five are first-party, and none is used to track a person across websites or over time. Four of them are strictly necessary within the meaning of Article 4(6)(b) of Law no. 506/2004, in the sense that the function the visitor has asked for cannot be supplied without them, and each of those four carries the HttpOnly attribute so that it cannot be read by scripts running in the browser. The fifth records the language the visitor has selected, does not carry that attribute, holds nothing beyond a language code, and is exempt for the reasons set out in Section 3.5.
dp_session
- Purpose: Keeps a clinic user signed in to the dashboard between requests, so that authentication does not have to be repeated on every page. Without it the dashboard cannot function.
- Duration: 7 days
- Type: First-party, strictly necessary, HttpOnly
dp_demo
- Purpose: Identifies the read-only public demonstration session, so that a visitor exploring the demonstration sees a consistent state. Without it the demonstration cannot be presented.
- Duration: 3 hours
- Type: First-party, strictly necessary, HttpOnly
dp_preview
- Purpose: Grants access to a private preview of a website build when the visitor opens a preview link we have supplied. Without it the preview requested through the link cannot be displayed.
- Duration: The remaining life of the preview link that set it: thirty minutes for an internal operational link, and up to thirty days for a demonstration link supplied to a prospective customer
- Type: First-party, strictly necessary, HttpOnly
dp_admin
- Purpose: Keeps a member of our own staff signed in to the internal administration panel. It is set only in the course of staff access, and never on the device of a subscriber, a patient, or an ordinary visitor.
- Duration: 4 hours
- Type: First-party, strictly necessary, HttpOnly
NEXT_LOCALE
- Purpose: Records the language the visitor has selected, so that the selection is honoured as the visitor moves between pages. It is written only where the language selected differs from the language that would otherwise be presented, and it holds the language code and nothing else.
- Duration: Browser session (deleted when the browser is closed)
- Type: First-party, user-interface customisation expressly requested by the visitor, exempt under Article 4(6)(b), not HttpOnly
3.2 None of these cookies carries an advertising identifier, none is shared with an advertising network, and none is used to build a profile. The value each cookie holds is a session reference or a language code and nothing more.
3.3 We set no advertising cookies, no social-network cookies, and no cross-site tracking technologies. Facebook and Meta pixels, Google Analytics, Google Tag Manager, and comparable third-party marketing tools are not present on any surface we operate.
3.4 No fingerprinting technique is used, whether based on canvas rendering, on font enumeration, on device characteristics, or on any comparable method, and no attempt is made to identify a device other than through the cookies described above.
3.5 The classification of the language cookie is stated separately, since it is the only cookie in the table that does not keep a function running. Storage of a display preference the user has chosen expressly falls within the same exception, as the Article 29 Working Party held in Opinion 04/2012 on Cookie Consent Exemption, which treats a language preference cookie set by the user's own act of selection as exempt where the storage lasts no longer than the browser session or a short period beyond it. Our cookie is written only in consequence of a selection made by the visitor, is not linked to a username or to any other persistent identifier, and is deleted when the browser is closed. Were it ever written automatically, in the absence of a selection, or were its life extended beyond the session, the exemption would cease to be available, and consent would be obtained before the change took effect.
4. Why No Consent Banner Is Displayed
4.1 A consent banner is required where storage or access falls outside the exception in Article 4(6) of Law no. 506/2004. Four of the cookies we set are strictly necessary in order to supply the service the visitor has expressly requested, namely a working dashboard session, a working demonstration, a working preview link, or an authenticated administrative session, and the fifth is exempt on the ground explained in Section 3.5. Because every cookie present on our surfaces falls within the exception, consent is not required for any of them.
4.2 Displaying a banner in those circumstances would present the visitor with a choice that has no object, since refusing the cookies would mean refusing the service requested. Regulatory guidance discourages consent requests that offer no genuine alternative, and we have taken the view that the more transparent course is to explain the position rather than to ask a question whose answer cannot change anything.
4.3 The position is contingent on the facts remaining as described. Should we introduce any cookie or similar technology falling outside the exception, whether for measurement, for personalisation, or for any other purpose, we will implement a consent mechanism satisfying Article 4(5) of Law no. 506/2004 and Article 7 of Regulation (EU) 2016/679 before that technology is deployed, and we will amend the present Policy accordingly.
5. Local Storage
5.1 The clinic dashboard stores a small quantity of information in the browser's local storage, comprising interface preferences, the record of introductory tour steps already seen, timestamps used to avoid repeating a notification the user has already seen, and, during onboarding, a short history of the website addresses entered into the import field. None of it leaves the browser, none of it is accessible to any third party, and none of it is used for measurement.
5.2 The public marketing website stores one item in local storage where a visitor opens a conversation with our assistant and asks to be contacted, comprising an identifier of the enquiry together with the access token that allows the visitor to return to that conversation on a later visit. Unlike the items described in Section 5.1, the token is transmitted to our servers when the visitor resumes the conversation, because transmission is what re-opens the thread. It serves no other purpose and is not shared with any third party.
5.3 A website we host on behalf of a clinic stores one item in local storage where a visitor selects a display currency for prices, comprising the currency code selected. The information never leaves the browser.
5.4 Clearing site data through the browser removes the stored items. Removal has no consequence beyond the interface reverting to its defaults and, in the case of Section 5.2, the conversation no longer being retrievable from that device.
5.5 Local storage is governed by the same provision as cookies. Article 4(5) of Law no. 506/2004 speaks of storing information in, or gaining access to information stored in, the terminal equipment of a subscriber or user, and attaches no significance to the technique employed or to whether the information amounts to personal data. The European Data Protection Board confirmed the reading in Guidelines 2/2023 on the technical scope of Article 5(3) of Directive 2002/58/EC, adopted in their present form on 7 October 2024, which treat information kept strictly inside the device as falling outside the notion of access, and information transmitted from the device, or derived from it and transmitted, as falling within.
5.6 Each item described in Sections 5.1 to 5.3 is stored in order to supply something the visitor has expressly asked for, whether a dashboard presented as the user left it, a conversation capable of being resumed, or prices displayed in a currency the visitor has chosen, and each is accordingly exempt under Article 4(6)(b). The qualification recorded in Section 5.2 is made precisely because the exemption, rather than the absence of transmission, is what renders the storage lawful.
6. Measurement Without Cookies
6.1 We measure traffic and performance using Vercel Web Analytics and Vercel Speed Insights. Neither product sets a cookie, neither stores an identifier in the browser, and neither follows a visitor from one website to another. Measurement is aggregated, and we do not receive a record attributable to an identified visitor.
6.2 Application errors are monitored using Sentry, supplied by Functional Software, Inc. The error-monitoring integration sets no cookie on the visitor's device. Personal data is removed from diagnostic records before they are transmitted, and the session replay feature is not enabled.
6.3 Measurement without cookies is a deliberate choice rather than a consequence of scale. We accept a coarser picture of how the Service is used in exchange for not placing identifiers on visitors' devices.
7. Cookies Set by Our Payment Provider
7.1 Subscription payments are processed by Stripe. When a subscriber is taken to a Stripe checkout page in order to enter payment details, Stripe sets its own cookies on that page, under its own policy and for its own purposes, which include fraud prevention and the security of the payment.
7.2 Cookies set by Stripe on its pages are outside our control. We do not read them, we do not receive their contents, and we cannot alter their duration. Information about them is published by Stripe at https://stripe.com/legal/cookies-policy and in its privacy policy at https://stripe.com/privacy.
7.3 Visitors to our public website who do not begin a subscription are not taken to a Stripe page and encounter no Stripe cookie.
8. Websites We Host for Clinics
8.1 A multilingual website we build and host for a dental clinic follows the same approach as the surfaces we operate for ourselves: strictly necessary cookies only, measurement without cookies, and no advertising or cross-site tracking technology.
8.2 Where a clinic asks us to add a tool of its own to its hosted website, whether an analytics product, an advertising pixel, a chat widget supplied by a third party, an embedded video player, a booking script, or any comparable component, the responsibility for any consent that tool requires rests with the clinic as controller of the resulting processing. The clinic must obtain that consent, must document it, and must reflect the tool in its own privacy notice and cookie information.
8.3 We inform a clinic when a tool it asks us to add is likely to require consent, and we will decline to install a component whose deployment would place us in breach of the law. Our informing the clinic does not transfer the obligation to us and does not constitute advice on the clinic's compliance.
8.4 Where a clinic operates its own website and installs the Conversation Layer plugin on it, the cookies present on that website are determined by the clinic and by the other components it has installed. The plugin itself sets no cookie of any kind. Where a patient begins a conversation through the plugin, the identifiers needed to resume that conversation after the page is reloaded are held in the browser's session storage, which the browser deletes when the tab is closed and which the plugin discards in any event after twenty-four hours. Session storage was chosen over persistent storage precisely so that the plugin places nothing durable on the device of a visitor to the clinic's website, and the storage that does occur is strictly necessary in order to continue a conversation the patient has begun, within Article 4(6)(b) of Law no. 506/2004.
9. Controlling Cookies Through Your Browser
9.1 Every current browser allows stored cookies to be inspected and deleted, and allows new cookies to be refused, either generally or for a particular site. The controls are found under the privacy or site-data settings of the browser, and the manufacturer's documentation describes them for each product and version.
9.2 Refusing or deleting the cookies described in Section 3 has practical consequences. Refusing dp_session prevents a clinic user from remaining signed in, so the dashboard becomes unusable. Refusing dp_demo prevents the public demonstration from maintaining a consistent state. Refusing dp_preview prevents a preview link from displaying the preview it points to. Refusing dp_admin concerns our own staff alone. Refusing the language cookie means the selection is not carried from one page to the next, so the visitor may have to make it again.
9.3 Because we set no advertising or measurement cookies, there is nothing to opt out of beyond the cookies described in Section 3, and no opt-out mechanism is offered for technologies we do not use.
10. Automated Preference Signals
10.1 Browser signals such as Do Not Track, and the global privacy control signals emerging in some jurisdictions, are addressed to tracking and to the sale or sharing of personal data. We carry out neither activity, so no such signal alters what we store or what we read.
10.2 Should a legally binding automated preference mechanism become applicable to us, we will honour it and will describe the treatment here.
11. Changes to the Present Policy
11.1 The present Policy is reviewed at least annually, whenever a cookie or similar technology is added, altered, or removed, and whenever a relevant change occurs in the applicable law.
11.2 The version in force, together with the date on which it was last revised, appears at https://dentalpolyglot.com. A change introducing a technology that requires consent takes effect only once the corresponding consent mechanism is in operation.
11.3 Superseded versions are retained and supplied on request to privacy@dentalpolyglot.com.
12. Contact
12.1 DTCONCIERGE S.R.L., Aleea Călărașilor nr. 5, bl. G, ap. 54, Municipiul Sibiu, județul Sibiu, Romania. Questions concerning cookies and similar technologies: privacy@dentalpolyglot.com. General correspondence: service@dentalpolyglot.com. Website: https://dentalpolyglot.com.