Skip to content

Privacy Policy

Information provided pursuant to Articles 13–14 of EU Regulation 2016/679 (GDPR) regarding the processing of personal data collected through Dentra's website and app.

This is an automatic translation. The binding version of this document is the Italian one.

1. Data Controller

  • Data controllerHundredjack OÜ — marchio «Dentra»
  • Registered officeTelliskivi tn 57, 10412 Tallinn (Põhja-Tallinna linnaosa, Harju maakond), Estonia
  • VAT numberVAT EE102905090 — registrikood 17310584

Personal data collected through this site and through the app are processed by the Data Controller indicated below.

Email: [email protected]

2. Data Protection Officer (DPO)

The Data Controller has appointed a Data Protection Officer. For any matter relating to the processing of personal data or the exercise of rights, the DPO can be contacted at: [email protected]

3. Data Collected

In the context of using the app and providing services, we collect the following categories of data:

  • Identification and company datacompany name, contact person's first and last name, registered office address, VAT number, Tax ID, SDI Code, PEC.
  • Contact dataemail address, phone number.
  • Authentication dataemail address and password (encrypted) for app access.
  • Order-related datadesign files, technical specifications, requested materials.
  • Billing datatax information required for issuing electronic invoices.
  • Payment databank details (IBAN) and SEPA direct debit mandate data, collected and stored by the payment processor; we retain mandate references and collection outcomes.
  • Recordings and transcriptsaudio/video recordings of video consultations with the team (recording start is always indicated) and their related transcripts and operational summaries.
  • Messagingmessages, photos, and documents sent to the official WhatsApp number, archived in our system to ensure service continuity.

4. Purposes of Processing

Personal data are processed for the following purposes:

Management of user accounts and app access.

Receipt, processing, and tracking of work orders.

Issuance of electronic invoices and fulfillment of tax and accounting obligations.

Digital delivery of completed design files.

Service communications regarding order status and operational notifications.

Automatic collection of invoices via SEPA direct debit mandate.

Assistance, consulting, and training via video consultations, including recordings and operational summaries.

Operational communications via WhatsApp, when chosen by the client.

5. Legal Basis

The processing of data is based on the following legal bases:

  • Performance of a contract(Art. 6, para. 1, lit. b GDPR): processing is necessary for the performance of commissioned services, management of the commercial relationship, and collection of payments via the SEPA direct debit mandate authorized by the client.
  • Legal obligation(Art. 6, para. 1, lit. c GDPR): processing is necessary for compliance with tax, accounting, and regulatory obligations under Italian law.
  • Explicit consent(Art. 6, para. 1, lit. a GDPR): for optional opt-in processing, such as the publication of an anonymous work in the public gallery or a case study of one's practice. Consent can be revoked at any time from the client profile.
  • Legitimate interest(Art. 6, para. 1, lit. f GDPR): for the recording and summary of operational video consultations (continuity and quality of assistance) and for platform security. The start of recording is always indicated before it begins.

6. Our Clients' Patient Data

When a client dentist uses Dentra to produce a dental technical work, they may upload files and images concerning their patient (3D intraoral scans, oral cavity photos, frontal smile photos). For this data:

Dentra acts as a data processor, while the client dentist remains the data controller. A data processing agreement exists pursuant to Art. 28 GDPR, regulated by the platform's terms of service.

We receive from the dentist only what is necessary for processing. The workflow does not require patient identification data: demographic fields are optional, and a pseudonymous patient code is available as an alternative. We invite the dentist to use the code and anonymize files before uploading; if they choose to indicate the patient's name or date of birth, this data is processed on their behalf with the same protections as other clinical data. We never ask for the patient's tax ID or contact details.

Patient data is accessible only to the Dentra operational team (freelance collaborators assigned to the work, bound by contractual NDA; authorized internal staff). They are tracked at an audit log level for consultation.

Requests for exercising patient GDPR rights (access, erasure, rectification) should be addressed to the data controller dentist. Dentra collaborates with the dentist to fulfill the request (e.g., deletion of order files within 30 days).

7. Data Transfers Outside the European Union

Dentra's main infrastructure is entirely within the European Union. Some ancillary processing relies on providers with headquarters or continuity systems outside the EU; for each, we indicate purposes, safeguards, and technical measures.

  • Website usage statisticsGoogle Analytics — Servers in the United States. It is active only with your consent and processes navigation data in aggregated and anonymous form; the transfer is covered by adequate safeguards (adequacy decision for the United States and standard contractual clauses).
  • Consumption-based service paymentsStripe — Primary servers in the European Union, with continuity system in the United States. Covered by Data Processing Agreement (DPA) and Standard Contractual Clauses (SCC).
  • Sending transactional emailsResend — Servers in the United States. Covered by DPA + SCC. Volume limited to operational notifications.
  • Automatic summary of internal recordingsAnthropic (Claude) — Servers in the United States. Used in limited functionalities (summary of internal video call recordings and voice chats). Covered by DPA + SCC.
  • Audio transcriptionSpeechmatics — Servers in the United Kingdom (country considered adequate by the European Commission for personal data protection).
  • Domain email accountsMigadu — Servers in Switzerland (country considered adequate by the European Commission).
  • Anti-bot protection for formsCloudflare — verification occurs on a globally distributed network: it normally takes place on the node closest to the user, but a transfer outside the European Union is not excluded. It is covered by the provider's data processing agreement, which includes standard contractual clauses for transfers to third countries. The data processed is limited to the technical signals necessary to distinguish a person from an automated program.
  • Service communications via WhatsAppMeta — WhatsApp Business API. Servers in the United States. Concerns phone number, messages, and any attachments sent by the client. Covered by data processing agreement and standard contractual clauses.

8. Artificial Intelligence

We use artificial intelligence tools only as ancillary support to the service. AI does not design medical devices and does not make clinical decisions or automated decisions about individuals: design is always carried out by human technicians, and every decision remains with a person. In particular, we use it for:

We do not carry out automated processing that produces legal or similarly significant effects on individuals pursuant to Art. 22 of the GDPR: human supervision is always provided.

Only the minimum necessary for the single request is transmitted to the models, and the data is not used to train the models themselves.

For these tools, we conduct a dedicated impact assessment, in line with the European Artificial Intelligence Regulation.

Some artificial intelligence providers may also process data outside the European Union, based on adequate safeguards: see the section «Transfers Outside the European Union».

a conversational assistant that helps clients and staff find information and receive support;

the automatic transcription and summary of video consultations, for internal team use;

the automatic analysis of images published in the public gallery of the website;

the generation of internal operational suggestions for the team;

internal support for content creation and work organization.

9. Cookies and Tracking Technologies

This site uses the following categories of cookies:

You can manage your preferences at any time by clicking on «Manage cookies» in the website footer. The preference remains stored in your browser; on our systems, we only record proof of the choice — the time, the chosen option, and the version of the cookie policy — without an IP address or other data that would allow us to identify you, because the law requires us to be able to demonstrate consent.

The site adopts a prior consent mechanism: no analytical or marketing script is loaded until the user expresses their consent.

  • Technical cookies (necessary)management of the authentication session, app functionality, and anti-bot verification of public forms. They are always active and do not require consent.
  • Analytical cookieswe use Google Analytics for statistical traffic analysis to study website usage in aggregated and anonymous form. The service provider may also process data outside the European Union (United States), based on adequate safeguards: see the section «Transfers Outside the European Union». These cookies are activated only with your explicit consent.

10. Categories of Recipients

For the provision of services, we use external providers who act as data processors, or based on specific service agreements or data processing agreements (SLA/DPA). Below are the categories of recipients and their respective purposes:

  • Cloud infrastructure and authenticationSupabase (Ireland) — data hosting and account authentication, on servers in the European Union.
  • File storage (EU)Hetzner (Germany) — storage of work files, implant library, video call recordings, and media received via messaging, on cloud storage with servers in the European Union.
  • Anti-bot protection for public formsautomatic verification that public website forms (registration and login) are filled out by a person and not by an automated system. It operates invisibly, without requiring any action: to distinguish a person from a program, it processes the IP address, technical characteristics of the browser and connection, and the site identifier. These signals are used solely for security verification, are not used for profiling or advertising, and do not allow you to be identified. The processing is described in the provider's dedicated privacy notice, the Turnstile Privacy Addendum: https://www.cloudflare.com/turnstile-privacy-policy/
  • Accounting and tax complianceestx.io OÜ (Estonia) — maintenance of the company's accounting and tax compliance: billing data (company name, address, tax ID or VAT number, amounts) are communicated to the accounting consultant, based in the European Union. Invoices are issued directly by Dentra and stored on cloud storage with servers in the European Union.
  • ShipmentsSendCloud (Netherlands) — management of shipments and generation of shipping labels.
  • Consumption-based service paymentsStripe (Ireland) — payment processing: management of SEPA direct debit mandate (bank details, mandate data) and collection of monthly invoices. It also processes card payments for patient-facing configurators.
  • MessagingMeta — WhatsApp Business API (United States) — service communications via WhatsApp (phone number, messages, and any attachments sent by the client).
  • Transactional emailsResend (United States) — sending transactional emails (order confirmations, notifications, service communications).
  • Domain email accountsMigadu (Switzerland) — management of email accounts for the @dentra.it domain (EU servers).
  • Video consultationsLiveKit (European Union) — infrastructure for video consultations between client and Dentra team. Recordings are stored on servers in the European Union and accessible only to authorized staff.
  • Audio transcriptionSpeechmatics (European Union) — automatic transcription of video call recordings (artificial intelligence service).
  • Conversational summaryAnthropic — Claude (United States) — textual processing of video call recordings and voice chats to produce operational summaries for the internal team. Covered by DPA + Standard Contractual Clauses.
  • Artificial intelligence servicesGoogle Cloud — Vertex AI (Belgium) and fal.ai (United States) — other artificial intelligence services used for: conversational assistance in the app, automatic analysis of public gallery images, and operational suggestions to the team, with processing on servers in the European Union. Data transmitted to the models is limited to the minimum necessary for the specific request and is not used for their training.
  • Partner laboratories (production)physical realization of the artifact: they receive the design files and, when the dental practice has valued them, the patient's identification references necessary for the declaration of conformity. For these processing activities, the laboratories operate as independent controllers.

11. Data Retention

Personal data are retained for the time strictly necessary to achieve the stated purposes:

  • Accounting and tax dataretained for 7 years, as required by Estonian accounting regulations for tax and accounting documents (including issued and received invoices).
  • Order dataretained for the duration of the commercial relationship; data with accounting relevance follow the accounting retention period indicated above.
  • Account dataretained until the account is deleted by the user or the commercial relationship ceases.
  • Mandate and collection dataretained for the duration of the mandate; data with accounting relevance follow the accounting retention period indicated above.
  • Video consultation recordingsretained for the time necessary for internal assistance and training purposes, with periodic review; transcripts follow the same rule.
  • WhatsApp Messagingretained for the duration of the commercial relationship.
  • Acceptances of legal documentsdate, version of the accepted document, IP address, and browser identifier are retained for the entire duration of the relationship and for the subsequent ten years, as proof of acceptance of the contractual conditions.

12. Data Subject Rights

Pursuant to Articles 15–22 of the GDPR, the data subject has the right to:

Access their personal data and obtain a copy.

Request the rectification of inaccurate or incomplete data.

Request the erasure of data, within the limits provided by law.

Request the restriction of processing.

Request data portability in a structured format.

Object to processing, for legitimate reasons.

Lodge a complaint with the Italian Data Protection Authority ( www.garanteprivacy.it).

13. Contacts

To exercise your rights or for any information related to the processing of personal data, you can contact the Data Controller at: [email protected]

14. Access to other products with your Dentra account

Some of the Data Controller's products — for example, Oralsnap — allow access using your Dentra account, without creating separate credentials. This function is activated only upon user request: it opens by pressing the relevant button in the other product and concludes on a Dentra screen that indicates, before proceeding, which data will be transmitted.

Legal basis: performance of a contract and the data subject's request (Art. 6.1.b GDPR), following consent expressed on the authorization screen.

Each authorized application has its own data controller and its own privacy policy, which governs the processing subsequent to transmission. The application's data controller is indicated on the authorization screen. When the application belongs to the same Data Controller (Hundredjack OÜ), the transmission is not a communication to third parties but the use of the same data for an additional purpose requested by the user. When the application belongs to a third party, the transmission is a communication to that third party, carried out at the data subject's request and limited to the data listed above: from the moment of transmission, that data is processed under the responsibility of its controller, according to its privacy policy.

Identity data remains stored and processed within the European Union, under the conditions indicated in Articles 7 and 10.

Authorization is distinct for each application and can be revoked at any time from the Dentra account settings. Revocation prevents subsequent access but does not delete any account created with the requesting product: for data already transmitted, you must also contact that product.

  • Account identifierA stable identifier generated by Dentra, which does not contain personal data and is never reassigned to others.
  • Email addressThe account's email address and information on whether it is verified.
  • Profile nameThe name indicated in the Dentra profile.
  • Practice identifierOnly when the account is linked to a client record: the identifier of the practice or laboratory, which allows the requesting product to recognize the affiliated organization.
  • Data NOT transmittedOrders, work files, patient data, tax or accounting documents are not communicated. The authorization does not allow the requesting product to perform any operation on Dentra on behalf of the user.