Privacy Policy
DENTAL LAB NUMERIX LLC, as the author, owner and administrator of the Lab dental digital online platform, respects the privacy and security of the processing of personal data of each person accessing the Lab dental digital online platform.
Our registered users (“ members ”) are either physicians who choose to share their professional identities, interact with their network, exchange knowledge and professional information, publish and view relevant content, learn and find career and professional development opportunities, or patients whose medical records are found on the Lab dental digital platform. The content of our services cannot be viewed by non-members.
Lab dental digital’s mission is:
- on the one hand, to connect you, physician users from all over the world, to enable you to be more productive by having access to your medical records from anywhere, to transfer know-how and to improve your medical activity, keeping you up-to-date with news, events and ideas on professional topics that interest you and from professionals you respect.
- on the other hand, to make sure that you, patient users, can access your record which has been created by the attending physician user at any time, and that you benefit from the best dental care services, provided by several physicians working as a single team.
Our commitment to being transparent about the data we collect, the way we use such data, and who we share such data with is fundamental to this mission.
- What are the legal provisions we observe?
In order to comply with our obligation to process data that is provided to us in an honest, transparent and informed manner, we comply with the following normative acts:
- Regulation (US) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as “GDPR”);
- Law no. 677/2001 on the protection of persons with regard to the processing of personal data and on the free movement of such data;
- Law no. 506/2004 on the processing of personal data and the protection of privacy.
The institution that ensures the application of the aforementioned regulations is the National Supervisory Authority for Personal Data Processing, which has the competence to investigate the processing of personal data falling under Law no. 677/2001 and US Regulation 2016/679, and to impose sanctions if it finds that the data controllers have breached the legal provisions, following ex officio notifications or complaints submitted by persons injured in their rights.
- What data we process
Personal data means any data or information that helps us identify you directly (for example, your last name, first name). Certain information is less obvious (such as your computer’s IP, your computer or mobile phone’s MAC address), but associated with your person helps us to identify you and thus are personal data. At the same time, we also process the personal data you enter about your patients.
Lab dental digital’s policy is to collect and process only the data we need to give you the most enjoyable experience when using the Lab dental digital platform.
II.1 Your data, as users of the platform
We generally process the following types of data about you:
- Last name and first name;
- E-mail address;
- Telephone number;
- Photographs;
- Passport and/or ID card number and series;
- Geo-location of the device from which you navigate/log into your client account;
- Payment (e.g., debit/credit card) and invoicing information;
- The degree of use of the platform, as well as your activities on the online platform.
Some of your personal data (“ data ” or “ personal data ”) are collected directly from you, and the other part is collected indirectly, as a result of your navigation on and use of the SMILECLOUD platform.
Data that you provide directly
To create your user account
We can create a user account on the Lab dental digital platform only if you provide us with the following personal data:
- Last name, first name
- E-mail address
- Password
- Telephone number
At the same time, we can create a client account by signing in to your Facebook or Google account using the e-mail or telephone number and password for that social network.
Article 6 (1) letter b) of Regulation 679/2016 – to perform a contract, namely to create a user account.
To log in to the user account
We offer you the option to log in to your client account by signing in to your existing Facebook or Google account. To sign in, you are redirected to your social networking page (Facebook or Google), where you can sign in with your user data. So, your Facebook and/or Google profile is linked to your Lab dental digital client account. Following the sign in, Facebook Inc. and/or Google Inc. will automatically forward the following information:
- Social network numeric ID
- Last name and first name
- Gender
- Username on Facebook or Google
- Your user account has been verified (e.g., “verified”)
At the same time, the social network service provider receives information about your account being linked to our page. We store and use this data transmitted by Facebook or Google to be able to identify you as an authorised client and to allow you access to the Lab dental digital platform.
Article 6 (1) letter b) of Regulation 679/2016 – to perform a contract, namely to create a user account.
Using the Lab dental digital platform
To improve your profile
If you want, you have the option to enter additional personal information about your profile, namely location, specialisation, vision, current job indicating relevant information, and photograph. You do not need to provide additional information; however, your profile information allows you to make better use of our services.
Performance of the contract: to make better use of our services.
To create medical records by physician users
By creating medical records, Lab dental digital collects and processes the personal data of Patient Users.
In this context, we process sensitive personal data, which can also be found in photographs, videos, files obtained using intraoral scanners (STLs) or conical-beam CT scanners (CBCTs), radiographs.
By agreeing to the terms and conditions of the platform, the Patient User agrees to the use of his or her personal data, including medical information, in order to create medical records and establish diagnoses, the treatment plan and the treatment, and consents to the Physician User’s adding of other users to the medical team to facilitate the establishment of diagnoses. At the same time, the Patient User agrees that physicians who have been given access may additionally add other physician users.
Performance of the contract: to make better use of our services.
To pay the monthly subscription
The details of the card you use for the 3D Secure payment of your chosen subscription will not be accessible and will not be stored by Lab dental digital , but only by the transaction authorisation entity – NAVIDOR.
[3D Secure means a security measure that involves redirecting the client to a secure page when making a payment where the registration of each cardholder is done by assigning an authorisation code for each online transaction. Accepted payment cards are those issued by VISA (Classic and Electron) and MASTERCARD (including Maestro if they have a CVV/CV2 code)].
Lab dental digital processes only the following data that it sends to the online payments/transaction authorisation partner:
- Last name, first name
- account
- payment state (paid/unpaid)
- amount transferred (as the case may be)
Performance of the contract: To ensure the support required by our authorised partners to process the payment of your subscription.
Client support
In order to be able to provide support for your client account, we will identify you with confirmation of your:
- last name and first name
- e-mail address
Performance of the contract: Fulfilling our responsibilities/ activities during the performance of the contract
Data we collect automatically
Online navigation
When you sign in to your client account, with the help of cookies, we also collect data from your computer, telephone, tablet, or other device you use (“the device”) with which we can identify you online (“online identifiers”) and which we use to improve your experience as a platform user:
- IP Address/MAC Address
- The Internet browser you are using and the operating system version of your device
- HHTP/HTTPS protocol data
- The duration of your activity on the Lab dental digital platform
- How you use the platform from a UX point of view ( user experience)
- What space limit you use
- The general location of the device (if geo-location is enabled) you use to log in to the platform.
[Please note that most devices give you the option to disable geo-location services from the settings of the device itself]
[“Cookies” – files that a server sends to your device, placed on the platform. The purpose and the way we process cookies are detailed in the Cookies Policy, available on the Lab dental digital platform]
Consent: For profiling and personalized offers purposes via the communication channels you agree to (SMS, e-mail, push-up notifications). More details on how we profile you for direct marketing can be found below in the “Profiling” section. You have the right at any time to object to profiling.
Newsletters
For physician users, we also use your e-mail address to provide you with newsletters that contain information useful to you as physicians.
If you no longer wish to receive these newsletters, you can click on the “unsubscribe” button at any time.
Consent: For the transmission of newsletters
Maintaining and securing the Lab dental digital platform
We use the following online identifiers for maintaining and securing the Lab dental digital platform:
- IP Address/MAC Address
- The web browser you are using and the operating system version of the device you are using to log in
- HHTP/HTTPS protocol data
- platform
Specifically, we process your data:
- Location of the device (if geo-location is enabled) you use to log in to the Lab dental digital
- to ensure the proper operation of the platform, namely
- to display the Lab dental digital platform content correctly
- to retain your login information (when prompted)
- to improve the Lab dental digital platform
- to fine-tune the device you are using to log in/authenticate to match the requirements of the Lab dental digital platform
- to ensure website security and ensure that we protect you against fraud or any IT security breach on the Lab dental digital platform
- to identify and fix malfunctions that prevent you from using your client account
Legitimate interest: Implement, configure and maintain the Lab dental digital platform security measures
Audit and reporting
We process your data for the annual financial audit, as well as for submitting tax and accounting statements to the tax authorities.
Legal requirements: To comply with the legal obligations imposed by the applicable legal provisions in tax and accounting matters
Defend our rights in court
When we defend our rights in court to recover amounts due or when we protect our interests against unjustified claims/complaints, we will process your data to prepare the necessary statements of defence, written conclusions, requests and specific documents.
Legitimate interest: Exercise of any defence/rights before the courts or public/ supervisory authorities or institutions
Procedures and investigations of authorities and/or judicial bodies
Exceptionally and in accordance with the law, we will provide the following data to competent authorities and institutions in the framework of formal proceedings/inquiries or other procedures provided by law, in accordance with the procedure provided by law: last name, first name, address, e-mail, telephone. Lab dental digital shall inform you of any such steps.
Legal requirements: In order to comply with specific legal obligations imposed by the applicable legal provisions in the field of fraud protection, money laundering and terrorism.
Data we collect from other sources
Social network navigation
If you log in to your client account with your Facebook address and password, we will receive this data and use them only to communicate with you.
III. What are your rights
In accordance with the provisions of the GDPR, you have the following rights:
Right to information. You have the right to receive clear, transparent, easily understandable and easily accessible information about how we process your data, including details about your rights as a data subject. This information on the data, purpose, and manner in which we process your data is also included in this Policy.
Right of access to personal data. You have the right to access the data we process about you without incurring any charge for the first data provided. If you will need copies of the data already provided, we may charge a reasonable fee, considering the administrative costs of providing such data.
Right to rectification of personal data. If you find that your data that we process is incorrect, incomplete or inaccurate: you may submit a rectification request at: [support@labdentaldigital.com] or you can rectify it directly in your client account.
Right to object. At any time, you have the right to object, for reasons related to your particular situation, to the processing of your personal data. We will no longer process your personal data unless (i) we have legitimate and compelling reasons that justify the processing and that prevail over the interests, rights and freedoms of any data subject; or (ii) if the data is necessary to establish, exercise or defend our rights in court.
Right not to be the subject of a decision based solely on automatic processing. You have the right not to be the subject of such a decision, including profiling, which produces legal effects concerning you or similarly significantly affects you. Your right does not apply if the decision: (i) is necessary for entering into, or performance of, a contract between the you and Lab dental digital ; (ii) is authorised by US law and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests.
Right to erasure (right to be forgotten). You have the right to ask us to delete your data in any of the following situations: (a) the personal data are no longer necessary in relation to the purposes for which they were previously processed; (b) you withdraw your consent on which the processing is based, and there is no other legal ground for the processing; (c) you object to the processing based on our legitimate interest and we cannot prove that we have any legitimate interests to justify the processing, and that prevail over your interests, rights and freedoms; (d) the personal data have been unlawfully processed; (e) the personal data have to be erased for compliance with our legal obligations.
This is not an absolute right. We will be able to reject your request for data erasure if: (i) we are compelled to comply with legal obligations to keep the data; (ii) your data has been included in specialised articles and/or spotlights for which you have given your consent; or (iii) if the data are necessary to establish, exercise or defend our rights in court.
Right to data portability . When processing your data on the basis of your consent or for the performance of the contract, you will automatically have the right to request the transfer of your data: (a) to you, or (b) to another controller indicated by you. The second situation assumes that you have the option of requesting us to transfer the data associated with the User account to another data controller. Please note that you will only be able to request the porting of your personal data that you have disclosed directly and actively.
Right to bring a matter to the courts. You have the right to submit any complaints to the US Supervisory Authority for Personal Data Processing, ., on how we process your personal data. However, we hope you decide to talk to us first before submitting any complaints to US supervisory . Protecting your data is very important to us, which is why we ensure you that we will take all the necessary measures to solve any problem with your data control and security.
- How long do we keep the data?
Lab dental digital processes your data for the period necessary to meet the purposes for which they were collected, as well as according to our personal data retention policies. In some situations, some legal provisions may impose or allow us to retain the data for a longer period.
For the purposes for which you have given us your consent to data processing, as outlined in the table above, we will process your data in relation to that purpose until you withdraw your consent to the processing for that purpose, unless we are required to retain these data for a longer period according to the law, for reporting to public authorities or to defend our rights in court.
Your consent implies your free, specific and informed{” “} consent by which you agree unequivocally that your data will be processed by us for the purpose for which you gave your consent.
You can express your consent by ticking the relevant box associated with the purpose and means of processing specified in the User Account Registration Form.
We inform you that we rely on your consent when we process your data to send you the newsletters you have requested.
You also have the option to delete the medical record belonging to you. However, you can restore its contents within 30 days. After this deadline, the deleted data, including personal data, will no longer be retained, except as indicated below.
In addition, if you choose to close your account, all data, documents, information uploaded to your User Account ceases to be visible to other people within the platform within 10 days. We generally delete the information in closed accounts within 2 years, except as indicated below.
However, following the deletion of the medical data, the Lab dental digital Platform will keep a copy of the medical record for the attending physician for the sole purpose and only for the period necessary to ensure the legal period for medical data archiving in Romania.
- How do we secure your data?
Lab dental digital uses advanced security methods and technologies, along with strict employee policies and work procedures, including regular audit to protect personal data collected and processed in accordance with applicable law.
At the same time, we analyse the new technologies in the field and, if necessary, we apply them to upgrade our security systems.
- Who do we share your data with?
Your personal data can be forwarded to and processed by our trusted partners so you can enjoy the Lab dental digital experience.
In order to offer you the services provided within the platform, we will share your data with our trusted partners. We select the partners and providers who perform on our behalf operations supporting our activity very carefully. We share with them only the personal data needed to carry out the specific activities we entrust to them.
When outsourcing certain activities to our trusted partners, we make every reasonable effort to check in advance whether they are protecting your data by strict data security measures and we will conclude with each of them data processing contracts.
Specifically, we pass some data to third parties (our partners) to perform the functions and services required to operate the Lab dental digital platform, such as:
- the provider that provides cloud data storage services – Amazon Web Services, located in Dublin, Ireland;
- the provider that provides the user authentication, Auth0;
- the provider of communication and mailing services Sendgrid located in Denver, Colorado, US, who holds the sendgrid.com;
- payment processors that are authorized by us to mediate payments in the 3D Secure payment system (NAVIDOR – who holds the Privacy Shield (EU-US Privacy Shield certification);
- the provider Baremetrics authorised by us to create specialised reports on user activities in order to improve user experience;
- the provider Full Story authorised by us to use anonymized data in order to provide insights for customer support;
- the provider Zendesk that provides communication service only with users who contact the support email address;
Transmitting data to authorities and public institutions or judicial bodies
We may pass some of your personal data to competent authorities or public institutions where this is required by law (e.g., to investigate fraud; to prevent money laundering; to file statements, financial statements with tax authorities, etc.), or we may pass this data to the courts when we defend ourselves in court or before other public authorities.
Auditor and consultant access
If we decide in the future to alienate our Lab dental digital shares or business, we will provide access to or send our users’ data to the potential buyer’s/buyers’ auditors and consultants for the purpose of carrying out the audit required to acquire the shares/business. To this end, we will ensure that any potential buyer follows and implements the security measures required to protect your data, and the parties will first sign a data processing contract for the purpose of the transaction.
VII. Transferring your data outside of the European Union or EEA
As a rule, your data is not stored in a country outside the US or the European Economic Area (“EEA”).
However, some data may be transferred to our partners who will help us with the Lab dental digital platform and who may be located outside of the US or European Union.
Therefore, if we transfer your data to other Lab dental digital partners/providers located in states that do not provide an adequate level of data protection, we commit ourselves to take all necessary measures to ensure that those partners/providers comply with the terms and conditions established in this Policy. These measures may also include the implementation of data protection standards (e.g., ISO 27001), standard contractual clauses adopted by the EU Commission, as well as direct control systems for these mechanisms.
VIII. Contact information
If you have any questions or complaints about this Policy, please contact us first.
We have appointed a Personal Data Protection Officer. For any questions or concerns about this Policy, the way we process your data or your rights, you can contact us at the following e-mail address: dpo@labdentaldigital.com or at the following postal address: Dental lab numerix LLC , 6923 8TH AVE , BROOKLYN NY 11228.
- Amendments
This Privacy Policy may be amended or updated at any time by Lab dental digital when we believe that certain changes occur in the activities used to process your data. Any such changes will be published on our platform, and we will also properly inform you by e-mail.