1. Who is who
Dexodent is a brand of [RAZÓN SOCIAL], S.L., which is the entity that processes the data. It acts in two distinct roles.
Controller of the data of its customers (people who use the programme in clinics and centres, subscription invoicing, contact and analytics):
- [RAZÓN SOCIAL], S.L., single-member company.
- Tax ID (NIF) [NIF].
- Registered office: [DOMICILIO].
- Privacy email: [CORREO DE PRIVACIDAD].
Processor of the patient data, clinical records, images, appointments and communications that each clinic enters (art. 28 of the General Data Protection Regulation, GDPR). The controller of that data is the clinic, which decides what it is used for. Dexodent processes it solely on behalf of the clinic and on its instructions, under the terms of the data processing agreement signed with each one. If you are a patient, please address your requests to your clinic; if Dexodent receives them, it forwards them without delay.
No data protection officer has been appointed.
2. What the data is used for, on what basis and for how long
| Processing | Purpose | Legal basis | Retention period |
|---|---|---|---|
| User accounts | Registration, access and service communications | Contract (art. 6.1.b GDPR) | Duration of the contract plus 12 months |
| Subscription invoicing | Payment collection and tax obligations | Contract and legal obligation (art. 6.1.b and 6.1.c) | 6 years |
| Contact and demonstrations | Handling your request | Consent or pre-contractual measures (art. 6.1.a and 6.1.b) | Until resolved; 12 months if no contract is concluded |
| Application analytics | Improving the product | Consent (art. 6.1.a) | 12 months |
| Website analytics | Aggregated visits, without IP address or browser | Legitimate interest (art. 6.1.f) | 12 months |
| Security and audit | Access log, abuse detection | Legitimate interest and art. 32 GDPR | 365 days available and 6 years archived |
| Patient data (as processor) | Dental clinical record, appointments, planning | That of the clinic: healthcare provision (art. 9.2.h GDPR) | As set by the clinic; the legal minimum for the clinical record is 5 years |
Health data is a special category (art. 9 GDPR). It is encrypted at rest and in transit, access is restricted by role and every access is logged.
No automated decisions with effects on individuals are made. Functions using artificial intelligence propose measurements and outlines that the professional reviews.
3. Recipients
Data is not disclosed to third parties except where legally required. The following providers supply services to Dexodent and access data solely for that purpose:
| Provider | Service | Location |
|---|---|---|
| Google (Google Cloud / Firebase) | Database, files, sign-in, notifications | [REGIÓN DE LOS DATOS]; sign-in and notifications are global services |
| OVHcloud | Application server | [CENTRO DE DATOS], European Union |
| RunPod | CBCT segmentation computation. It receives the image volume without headers or patient name, with a random identifier | [UBICACIÓN] |
| Zoho (Zoho Mail, zoho.eu) | Service email and notices to patients | European Union |
| Twilio | SMS to patients | USA |
| Stripe | Subscription billing and card payments | European Union and USA |
| Meta (WhatsApp Business) | WhatsApp messages to patients, only if the clinic enables it | USA and European Union |
| Signaturit | Electronic signature of consents, only if the clinic enables it | Spain |
Clinics may also use their own providers (their email server, their Twilio account, their WhatsApp number, their bank), for which they are responsible.
The conversational assistant uses an in-house engine by default, with no third parties.
4. International transfers
Some of these providers are based in the United States or have part of their service there. Those transfers are covered by the European Commission's standard contractual clauses or by the EU-US Data Privacy Framework, depending on the provider. The IP address of the person signing in is not sent to third parties in order to place it on a map.
5. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction and portability, and withdraw your consent where it is the basis for the processing, by writing to [CORREO DE PRIVACIDAD]. If there are doubts about your identity, you will be asked for the information needed to confirm it. We reply within one month at most (art. 12 GDPR). A patient's data is managed by their clinic.
6. Complaints
If you consider that your rights have not been respected, you may lodge a complaint with the Spanish Data Protection Agency (AEPD) (https://www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.
7. Security and breaches
Dexodent applies technical and organisational measures appropriate to the risk: encryption, role-based access control, access logging, backups and an incident response procedure. A security breach affecting data for which Dexodent is the controller is notified to the Spanish Data Protection Agency (AEPD) within 72 hours and, if it entails a high risk, to the individuals affected (arts. 33 and 34 GDPR). If it affects patient data, it is reported to the responsible clinic without undue delay.
8. Changes
The date of the current version is published here. Significant changes are notified to customers by email.