Additional information on the processing of patient data
This section supplements the automatically generated statement and describes the processing specific to the dental care we provide.
1. Controller
DONTODENT SRL, a Romanian limited liability company, tax ID (CUI) 17946225, Trade Register no. J2005002309229, registered office at Str. Prof. Ion Inculeț nr. 20, bl. 948, sc. B, ground floor, ap. 3, 700720 Iași, Romania. Contact for any request concerning personal data: office@dontodentclinic.ro, telephone (+4) 0332 800 211.
We have not appointed a Data Protection Officer: the activity of a single dental practice does not amount to large-scale processing within the meaning of Article 37(1)(c) GDPR, as explained in Recital 91. Data protection requests are handled directly at the address above.
2. What we process as a dental practice
- Identification and contact data: name, date of birth, address, telephone number, email address.
- Personal numeric code (CNP), where required for medical or tax documents, subject to the safeguards laid down by Romanian Law no. 190/2018.
- Health data (special category, Article 9 GDPR): medical and dental history, allergies, medication, diagnosis, treatment plan, procedures performed, radiographs and other medical images, treatment progress.
- Financial data: the information needed to issue invoices and collect payment for our services.
3. Legal bases
- Article 9(2)(h) GDPR in conjunction with Article 6(1)(b) — processing of health data for preventive medicine, medical diagnosis and the provision of health care, on the basis of the patient relationship. Processing is carried out by staff bound by the obligation of professional secrecy.
- Article 6(1)(c) GDPR — compliance with our legal obligations, in particular those set out in Law no. 95/2006 on healthcare reform, Law no. 46/2003 on patients’ rights, and accounting and tax legislation.
- Article 6(1)(f) GDPR — our legitimate interest in operating and securing the website and in responding to people who contact us.
Providing medical data is necessary for treatment. If it is withheld, dental procedures cannot be carried out safely.
4. Retention periods
- Medical records are kept for the period laid down by Ministry of Health rules and by archiving legislation, which extends beyond the end of the patient relationship.
- Accounting records are kept for 10 years, under Article 25 of Accounting Law no. 82/1991.
- Correspondence received by email or telephone is kept for as long as needed to deal with the request and thereafter for the applicable limitation periods.
5. Who we disclose data to
We do not sell data and do not use it for marketing. It may be disclosed only to: dental laboratories and imaging providers involved in your treatment; practitioners you are referred to, with your agreement; our accountant and auditors; IT service providers (hosting, email, maintenance) under processing agreements concluded pursuant to Article 28 GDPR; and public authorities where the law requires it.
6. Transfers outside the European Union
Medical data is held at the practice and is not transferred outside the European Economic Area. Certain technical suppliers of the website (the transactional email service and the content delivery network) are United States companies; any transfers take place on the basis of the Standard Contractual Clauses adopted by the European Commission and/or the EU–US Data Privacy Framework. The map tile provider is established in Switzerland, a country covered by a European Commission adequacy decision.
7. Your rights
You have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and objection (Article 21), as well as the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
Please note that the right to erasure does not apply where retention is necessary for compliance with a legal obligation or for preventive medicine or health care purposes, under Article 17(3) GDPR.
Under Romanian Law no. 46/2003 on patients' rights, you are entitled to access your personal medical data and to obtain copies of your medical records.
8. How to exercise your rights and where to complain
Requests may be sent to office@dontodentclinic.ro or delivered at the practice. We reply within one month of receipt, a period that may be extended by two further months for complex requests, in which case we will inform you.
If you consider that we have infringed your rights, you may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 Bucharest, telephone +40.318.059.211, email anspdcp@dataprotection.ro, www.dataprotection.ro. You also have the right to seek a judicial remedy.
9. Minors
Treatment of patients under 18 is carried out with the agreement of a parent or legal guardian, who also provides the necessary data. The website is not directed at children and does not knowingly collect data from them.
10. Security
Medical records are kept in areas with restricted access, and our IT systems are protected by individual accounts, passwords and an encrypted connection (HTTPS). All staff are bound by the legal obligation of medical professional secrecy.
11. Automated decision-making
We do not take decisions based solely on automated processing and we do not profile patients or website visitors.
