Privacy policy
What personal data reaches us through this website, why we use it, how long we keep it and what your rights are.
Version in force: 14 September 2026
Who is responsible for your data
Your data is processed by BUTUNOI DENTAL SRL (company registration code 41848521), the company that runs the Smile Designers Studio dental practice — the data controller under Regulation (EU) 2016/679 (GDPR).
Practice address: Colentina Hospital, 1 Doctor Calistrat Grozovici Street, wing D, floor 2, room 4, 021105 Bucharest.
For any question or request about your data, email us at contact@smiledesigners.ro or call 0724 201 189.
When you visit the website
You do not need an account, and we ask for nothing for you to read the website. Still, as with any website, some technical information inevitably reaches the server:
- Server logs: the server records each request — IP address, time, the address of the page requested, the site you came from and the browser used. We use them only to keep the website running and to stop abuse. They are deleted automatically after 15 days at most.
- Visit statistics: we count visits to know which pages are useful. We use no cookies and no analytics services from other companies. We keep only the page, the day and hour, the site you came from and the type of device, browser and operating system. Your IP address is not saved in the statistics: it is used only to calculate a code that changes every day and does not allow identification. Detailed records are deleted within 9 days at most; only totals remain. Practice staff signed in to the admin panel are not counted.
- Map: the map on the contact page comes from OpenStreetMap. When it is shown, your browser sends your IP address and information about your browser to the OpenStreetMap Foundation, in the United Kingdom; see OpenStreetMap’s privacy policy.
The legal basis for this processing is our legitimate interest in keeping the website running, secure and useful (Art. 6(1)(f) GDPR).
When you send us an appointment request or a message
What we keep:
- from the appointment request: your name, phone number, email address (if you give one), the treatment you want, your preferred dentist, your preferred date and time of day, and your message;
- from the contact form: your name, your email address or phone number, and your message;
- in both cases: when you gave your consent and the version of this policy, plus a cryptographic fingerprint of your IP address (not the address itself) and the browser used — so that we can stop abusive submissions and show when and how you gave your consent.
Why: to contact you, to arrange the appointment or to reply to you. If you left an email address with your appointment request, we send you a message confirming that we received it. Each request or message also sends a notification email, with the details from the form, to the people who handle requests.
Legal basis: the consent you give by ticking the box in the form, and the steps you ask us to take before an appointment (Art. 6(1)(a) and (b) GDPR). If you write to us about your health, we use that information only to prepare your visit, based on your explicit consent (Art. 9(2)(a) GDPR) — please write only what is necessary.
How long: for as long as needed to reply to you and to keep a record of appointments. You can ask us at any time to delete a request or a message. If you become a patient, your details move into your patient record, which is kept in accordance with medical legislation.
You can withdraw your consent at any time by writing to us or calling us. Withdrawal does not affect anything done on the basis of your consent before then.
Reviews and cases published on the website
- On the reviews page we republish reviews written by their authors on Google, under the name they published them with and with a link to the original (legitimate interest, Art. 6(1)(f) GDPR). If you would like us to remove your review from the website, write to us.
- The before-and-after photographs on the cases page appear only with the patient’s written consent and without the patient’s name (Art. 9(2)(a) GDPR). Consent can be withdrawn at any time; the case is then removed from the website.
Who else has access to the data
- practice staff, each with their own account and only to the data they need;
- our hosting provider, Hetzner Online GmbH (Germany), on whose servers the website runs and the backups are kept;
- the company that looks after the website, the server and its email — it has access to data as far as that work requires, including the notification emails;
- OpenStreetMap, strictly for the map, as described above.
We do not sell data and do not use it for advertising. We disclose it to authorities only where the law requires us to.
Where the data is
The website, the database and the backups are on servers in Germany, in the European Union. The OpenStreetMap map on the contact page, described above, sends your IP address and information about your browser to the United Kingdom.
How we protect the data
All pages and forms travel encrypted (HTTPS). Medical data in patient records is encrypted in the database, every person at the practice has their own account, and each time a medical record is opened this is logged. Database backups are encrypted and kept for 14 days.
Your rights
You can ask us at any time:
- to tell you what data we hold about you and to give you a copy;
- to correct or complete it;
- to delete it, where we no longer have grounds to keep it;
- to use it only within certain limits (restriction) or to give it to you in a format you can take elsewhere (portability);
- to stop processing based on our legitimate interest (objection);
- to withdraw your consent, without affecting what was done before.
For any of these, email us at contact@smiledesigners.ro or call 0724 201 189. We reply within one month at the latest. For the visit statistics we cannot find the data of a particular person: the daily code can no longer be linked to anyone after midnight, not even by us.
If you are not satisfied with our answer, you can complain to the Romanian data protection authority (ANSPDCP) — www.dataprotection.ro.
Automated decisions
We make no automated decisions about you and do not profile you.
Changes
When something substantial changes — a retention period, a provider, a new service used by the website — we update this page and the version date above. Consent given in a form stays linked to the version in force when you sent it.
