Privacy Policy
Privacy notice pursuant to Articles 13–14 of EU Regulation 2016/679 (GDPR) regarding the processing of personal data collected through the Dentra website and app.
Data Controller
Dentra (Hundredjack OÜ)
Telliskivi tn 57, 10412 Tallinn, Estonia
VAT EE102905090
Email: [email protected]
Data Protection Officer (DPO)
The Controller has appointed a Data Protection Officer. For any matter relating to the processing of your personal data or the exercise of your rights, you can contact the DPO at: [email protected]
Data Collected
In the context of app usage and service provision, we collect the following categories of data:
- Identification and business data: company name, contact person name and surname, office address, VAT number, fiscal code, SDI code, certified email (PEC).
- Contact data: email address, phone number.
- Authentication data: email address and password (encrypted) for app access.
- Order data: design files, technical specifications, requested materials.
- Billing data: fiscal information necessary for electronic invoice issuance.
- Payment data: bank details (IBAN) and SEPA direct debit mandate data, collected and held by the payment processor; we keep the mandate references and the outcome of collections.
- Recordings and transcripts: audio/video recordings of video consultations with the team (recording is always announced) and the related transcripts and operational summaries.
- Messaging: messages, photos and documents sent to the official WhatsApp number, stored in our system to ensure service continuity.
Purpose of Processing
Personal data is processed for the following purposes:
- User account management and app access.
- Receiving, processing, and tracking manufacturing orders.
- Issuing electronic invoices and fulfilling fiscal and accounting obligations.
- Digital delivery of completed design files.
- Service communications regarding order status and operational notifications.
- Automatic collection of invoices via the SEPA direct debit mandate.
- Support, consulting and training via video consultations, including recordings and operational summaries.
- Operational communications via WhatsApp, where chosen by the client.
Legal Basis
Data processing is based on the following legal grounds:
- Performance of a contract (Art. 6(1)(b) GDPR): processing is necessary for the performance of the commissioned services, the management of the business relationship and the collection of fees via the SEPA direct debit mandate authorised by the client.
- Legal obligation (Art. 6(1)(c) GDPR): processing is necessary to comply with fiscal, accounting, and regulatory obligations under Italian law.
- Legitimate interest (Art. 6(1)(f) GDPR): for recording and summarising operational video consultations (continuity and quality of support) and for platform security. Recording is always announced before it starts.
- Explicit consent (Art. 6(1)(a) GDPR): for optional opt-in processing, such as publishing anonymous work in the public gallery or a case history of your practice. Consent can be revoked at any time from the client profile.
Patient Data from Our Clients
When a dentist client uses Dentra to produce dental work, they may upload files and images related to one of their patients (3D intraoral scans, intraoral photos, frontal photos of the smile). For such data:
- Dentra acts as data processor, while the dentist client remains data controller. A responsibility relationship under Art. 28 GDPR applies, governed by the platform's terms of service.
- We receive from the dentist only what is necessary for the work. The workflow does not require the patient's identifying data: the personal-data fields are optional and a pseudonymous patient code is available as an alternative. We invite the dentist to use the code and to anonymize files before uploading; if they choose to enter the patient's name or date of birth, that data is processed on their behalf with the same protections as the other clinical data. We never request the patient's fiscal code or contact details.
- Patient data is accessible only to the Dentra operational team (freelance collaborators assigned to the job, bound by contractual NDA; authorized internal staff). Access is tracked via audit log.
- Requests to exercise the patient's GDPR rights (access, deletion, rectification) must be addressed to the controlling dentist. Dentra cooperates with the dentist to execute the request (e.g., order file deletion within 30 days).
Artificial intelligence
We use artificial intelligence tools only as an accessory support to the service. AI does not design the medical devices and does not make clinical decisions or automated decisions about people: design is always carried out by human technicians and every decision remains with a person. Specifically, we use it for:
- a conversational assistant that helps clients and staff find information and get support;
- automatic transcription and summary of video consultations, for internal team use;
- automatic analysis of the images published in the site's public gallery;
- generating internal operational suggestions for the team;
- internal support for drafting content and organizing work.
We do not carry out automated processing that produces legal or similarly significant effects on people under Art. 22 GDPR: human oversight is always in place.
Only the minimum necessary for each request is sent to the models, and the data is not used to train the models themselves.
For these tools we carry out a dedicated impact assessment, in line with the EU Artificial Intelligence Regulation.
Some AI providers may also process data outside the European Union, on the basis of adequate safeguards: see the «Transfers outside the European Union» section.
Cookies and Tracking Technologies
This site uses the following categories of cookies:
- Technical cookies (necessary): authentication session management and app operation. These are always active and do not require consent.
- Analytics cookies: we use a website traffic analytics tool to study site usage in aggregated and anonymous form. The provider may also process data outside the European Union (United States) on the basis of adequate safeguards: see the «Transfers outside the European Union» section. These cookies are activated only with your explicit consent.
You can manage your preferences at any time by clicking "Cookie Settings" in the site footer. The preference is stored locally in your browser and is not transmitted to external servers.
The site adopts a prior-consent mode: no analytics or marketing scripts are loaded until the user expresses consent.
Third-Party Services
To provide our services, we rely on external providers acting as data processors, or on the basis of dedicated service or data processing agreements (SLA/DPA). Below are the categories of recipients and their purposes:
- Cloud infrastructure and authentication — data hosting and account authentication, on servers in the European Union.
- File storage (EU) — storage of work files, the implant library, videocall recordings, and media received via messaging, on cloud storage with servers in the European Union.
- Electronic invoicing — management of the supplier invoice cycle, archiving of issued invoices and — transitionally, until the switch to direct invoicing is complete — issuing of customer invoices (EU servers).
- Shipping — shipment management and shipping label generation.
- Usage-based payments — payment processing: management of the SEPA direct debit mandate (bank details, mandate data) and collection of the monthly invoice. It also processes card payments for the patient-facing configurators.
- Messaging — service communications via WhatsApp (phone number, messages, and any attachments sent by the client).
- Transactional emails — delivery of transactional emails (order confirmations, notifications, service communications).
- Domain email mailboxes — management of email mailboxes for the @dentra.it domain (EU servers).
- Video consultations — infrastructure for video consultations between client and Dentra team. Recordings are stored on servers in the European Union and accessible only to authorized staff.
- Audio transcription — automatic transcription of videocall recordings (artificial intelligence service).
- Conversational analysis — text processing of video and voice call recordings to produce operational summaries for the internal team (provider based in the United States). Covered by DPA + Standard Contractual Clauses.
- Artificial intelligence services — other AI services used for: conversational assistance in the app, automatic analysis of public gallery images, and operational suggestions to the team, with processing on servers in the European Union. Data passed to the models is limited to the minimum necessary for the specific request and is not used for training the models themselves.
Data Transfers Outside the European Union
Dentra's main infrastructure is entirely within the European Union. Some ancillary processing relies on providers based or with failover outside the EU; for each one we indicate purpose, safeguards, and technical measures.
- Site usage statistics: the statistics tool is provided by an operator based in the United States. It is active only with your consent and processes browsing data in aggregated and anonymous form; the transfer is covered by adequate safeguards (adequacy decision for the United States and standard contractual clauses).
- Payments for usage-based services: Primary servers in the European Union, with failover in the United States for resilience. Covered by a data processing agreement (DPA) and Standard Contractual Clauses (SCC).
- Transactional emails: Servers in the United States. Covered by DPA + SCC. Volume limited to operational notifications.
- Automatic summarization of internal recordings: Servers in the United States. Used in limited functionality (summarization of internal video and voice call recordings). Covered by DPA + SCC.
- Audio transcription: Servers in the United Kingdom (country deemed adequate by the European Commission for personal data protection).
- Domain email mailboxes: Servers in Switzerland (country deemed adequate by the European Commission).
Data Retention
Personal data is retained for the time strictly necessary to pursue the stated purposes:
- Accounting and fiscal data: retained for 7 years, as required by Estonian accounting law for fiscal and accounting records (including invoices issued and received).
- Order data: retained for the duration of the business relationship; data with accounting relevance follows the accounting retention period indicated above.
- Account data: retained until the account is deleted by the user or the business relationship ends.
- Mandate and collection data: kept for the duration of the mandate; data with accounting relevance follows the accounting retention period indicated above.
- Video consultation recordings: kept for as long as needed for support and internal training purposes, with periodic review; transcripts follow the same rule.
- WhatsApp messaging: kept for the duration of the business relationship.
Data Subject Rights
Under Articles 15–22 of the GDPR, the data subject has the right to:
- Access their personal data and obtain a copy.
- Request rectification of inaccurate or incomplete data.
- Request erasure of data, within the limits provided by law.
- Request restriction of processing.
- Request data portability in a structured format.
- Object to processing, on legitimate grounds.
- Lodge a complaint with the Italian Data Protection Authority ( www.garanteprivacy.it).
Contact
To exercise your rights or for any information regarding the processing of personal data, you may contact the Data Controller at: [email protected]
Last updated: July 21, 2026