Privacy policy
Last updated: 27 September 2026
In short
We use your data to book you in, to treat you and to comply with the law. We do not sell it and we do not use it for advertising without your consent. Health data in requests and signed forms is encrypted. We keep data only as long as necessary and then delete it automatically.
Who processes the data
The controller is CLINICA EPIDENT S.R.L. (EpiDent), tax ID (CUI) 41747276, Trade Register no. J2019003169229. Registered office: Iași county, Valea Adâncă village, Miroslava commune, Strada Parcului nr. 26, ground floor, room 3. The clinic is at Strada Livezilor nr. 2, Miroslava 707317, Iași county.
For any question or request about personal data: . Requests are received and handled directly by the clinic.
What data we process and where it comes from
- The appointment request on the website, sent by you or by the dentist referring you: full name, phone, email (optional), preferred language, which tooth or teeth need treatment or what is bothering you (health data). For a referral, also the name of the referring dentist and clinic.
- What we add to the request: the appointment date, how we notified you, the request status, the dentist's notes and files received from you or from the referring dentist (for example radiographs).
- Electronically signed forms (the personal data agreement and the consent to treatment): the identification details the form asks for (name, phone and, where applicable, address, identity document, personal numeric code (CNP), legal representative), your answers, your signature, the date and time, and the IP address and browser you signed from. You sign on a link received from the clinic or on a tablet at the clinic.
- The medical record (diagnosis, treatment, radiographs, prescriptions), which the clinic keeps as the law requires.
- Website visits: measured anonymously, without cookies. Details in the cookie policy.
Why we use the data and on what legal basis
- The appointment you request — Steps taken at your request before treatment (Art. 6(1)(b) GDPR). For the health data in the request: the explicit consent you give by ticking the agreement in the form (Art. 9(2)(a)).
- A referral by a dentist — Health care provided by professionals bound by professional secrecy (Art. 9(2)(h) and 9(3)). The referring dentist's data: our legitimate interest in communicating with them (Art. 6(1)(f)).
- Notifying you of the appointment (phone, email, WhatsApp or in person) — Steps before treatment (Art. 6(1)(b)).
- Medical care: diagnosis, treatment, radiology, prescriptions, prosthetic work, medical documents — Legal obligations and the care contract (Art. 6(1)(b) and (c); Art. 9(2)(h) and 9(3); Law no. 95/2006, Law no. 46/2003).
- The written consent to treatment — Legal obligation (Law no. 95/2006, Art. 660; Order no. 482/2007, Art. 8).
- Reminders, birthday messages and news, only if you chose "YES" — Your consent (Art. 6(1)(a)). Commercial messages: Law no. 506/2004, Art. 12.
- Keeping evidence and defending legal claims — Legal obligations and legitimate interest (Art. 6(1)(c) and (f); Art. 9(2)(f)).
- Security: anti-robot verification and the access log — The duty to protect data (Art. 32 GDPR) and legitimate interest (Art. 6(1)(c) and (f)). The Cloudflare verification loads only with your consent.
- Answering your data protection requests — Legal obligation (Art. 12–22 GDPR).
Health data
Health data is a special category of data (Art. 9 GDPR). Only authorised staff bound by professional secrecy see it. We do not use it for advertising, and no decision is taken about you on its basis without a dentist.
Who we share data with
- The dentist who referred you: the information needed to continue your treatment.
- Medical collaborators (other doctors, dental technicians, laboratories), only when treatment requires it.
- People you designate in writing to be informed about your health.
- Authorities, only when the law requires it.
- Providers that help us technically, under contract and only on our instructions: hosting and email: [TO BE COMPLETED: name and company ID of the hosting and email provider], which hosts the website and database and sends appointment emails, under a data processing agreement (Art. 28 GDPR); Cloudflare, Inc.: website delivery, security and anti-robot verification; Meta (WhatsApp Business): the clinic's internal alerts about new requests. An alert contains only a reference code, none of your data.
Transfers outside the European Economic Area
Data from requests and signed forms is stored in Romania. Cloudflare may process the IP address and technical browser signals outside the European Economic Area as well, including in the United States. The safeguards for these transfers are described in Cloudflare's privacy policy.
How long we keep data
- An appointment request that did not become an appointment or was cancelled — Personal and medical data is deleted 6 months after the last activity.
- A request that became an appointment — Personal and medical data is deleted 90 days after the appointment date. What treatment needs moves to the medical record.
- The record left after deletion (reference, dates, status, type, referring clinic), with no personal data — 3 years from the last activity.
- Signed forms (the personal data agreement, the consent to treatment) — 10 years from signing.
- The medical record — At least 5 years from the last contact (Art. 35 of the Code of Ethics for Dentists).
- Signing links — Valid for 7 days; deleted 30 days after signing, expiry or cancellation.
- The access log (who viewed or changed data) — 3 years.
- Your data protection requests and our answers — 4 years from closing the request.
- Anonymous visit statistics — 400 days.
If you withdraw a consent, we stop that processing. We keep the signed document as evidence until the period above ends.
Your rights
You have the right:
- to find out what data we hold about you and to receive a copy (Art. 15);
- to have wrong or incomplete data corrected (Art. 16);
- to ask for your data to be erased (Art. 17). We erase appointment requests on request. We cannot erase signed forms and the medical record before the period ends, because the law requires us to keep them and they may be needed in a legal dispute (Art. 17(3)(b), (c) and (e));
- to ask for processing to be restricted, for example while we check a complaint (Art. 18);
- to receive the data you gave us in a common electronic format, or have it sent to another controller (Art. 20);
- to object to processing based on our legitimate interest, and at any time to marketing messages (Art. 21);
- to withdraw your consent at any time, as easily as you gave it, without affecting what was done before (Art. 7(3));
- to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, postcode 010336, Bucharest, www.dataprotection.ro.
If a personal data breach puts your rights at risk, we will tell you without undue delay (Art. 34).
How to exercise your rights
Write to us at or come to the clinic at Strada Livezilor nr. 2, Miroslava. We may ask you to confirm your identity. We answer free of charge within one month. If the request is complex, the period may be extended by two more months; we will tell you so within the first month.
Automated decisions
We take no automated decisions about you. Every appointment request is read and assessed by the dentist.
How we protect data
- Data in requests, notes, attached files and signed forms is encrypted before it is stored.
- Only authorised people have access, each with the rights of their role.
- Every view and change of the data is recorded in the access log.
- Alerts sent to the clinic contain no patient data.
- Data is deleted automatically at the periods above.
Children
For children under 16, the optional consents are given by a parent or legal representative. Consent to treatment is given by the legal representative until the age of 18, with the exceptions provided by law (Law no. 95/2006, Art. 661).
Changes
We may update this policy. The version in force is published on this page.