Privacy Policy and Data Processing (GDPR)v1.4
Last updated: June 25, 2026
1. Data ControllerUpdated
Inspicio SRL, based in Tulcea, Romania, is the data controller. You can reach us anytime at info@inspicio.ro.
The data controller is Inspicio SRL, a Romanian legal entity, registered office at 10 Lopatarului St., Tulcea, Romania (E.U.) 820096, registered with the Trade Registry under no. J2019000476362, VAT ID 41306440, email: info@inspicio.ro, phone: +40 750 195 554.
Agora Dentist (hereinafter referred to as the 'Platform') is a dental marketplace that connects patients with partner clinics and provides digital management tools for dental practices. This policy applies to all Platform users: patients, doctors, clinics, and website visitors.
2. Categories of Data Collected
We only collect data strictly necessary for the Platform: identification info, medical data (with your explicit consent), appointment data, and technical browsing data.
We collect the following categories of personal data, depending on your relationship with the Platform:
- Identification data: first and last name, email address, phone number, date of birth, physical address (optional).
- Authentication data: username, encrypted password, session tokens, IP address, device type, browser type, application version.
- Medical data (special category — Art. 9 GDPR): dental history, X-rays (panoramic, CBCT, periapical), treatment plans, FDI dental chart findings, intraoral photos, medical alerts, appointment history.
- Appointment data: chosen clinic, doctor, date and time, appointment status, appointment history, reminders sent.
- Financial data: for subscriptions — billing information (company name, VAT ID, address), payment history, balances, and instalment plans. We do not store full bank card details — payments are processed by PCI DSS-certified third-party processors.
- Usage data: pages visited, time spent, feature interactions, clicks, language and theme preferences, form and survey responses.
- Communication data: content of messages sent through the contact form, WhatsApp chat, support emails, and in-app notifications.
- Browsing and device data: IP address, browser type, operating system, time zone settings, screen type, internet service provider.
- Cookies and similar technologies: essential, analytics, and preference cookies. Full details in the dedicated cookies section.
3. Legal Basis for Processing
We process your data only on the basis of explicit consent (for medical data), contract performance, legal obligations, or legitimate interest — each processing activity has a clearly defined legal basis.
We process your personal data in accordance with Regulation (EU) 2016/679 (GDPR), Romanian Law 190/2018 supplementing the GDPR, and Law 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, based on the following legal grounds:
- Explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) — for medical data (special category) and non-essential cookies. Consent may be withdrawn at any time without affecting the lawfulness of processing prior to withdrawal.
- Performance of a contract (Art. 6(1)(b) GDPR) — for account creation and management, appointment processing, payment processing, and provision of Platform services.
- Legal obligation (Art. 6(1)(c) GDPR) — for keeping accounting and tax records in accordance with Romanian Fiscal Code and Accounting Law 82/1991.
- Legitimate interest (Art. 6(1)(f) GDPR) — for improving services, securing the Platform, fraud prevention, aggregate statistical analysis, and direct marketing (with guaranteed right to object).
4. Purposes of Data Processing
Collected data is used exclusively for providing Platform services — account management, appointments, digital medical records, and operational communications. We never use data for undisclosed purposes.
We use the collected data for the following purposes:
- Providing and managing user accounts, including authentication, security, and technical support.
- Managing appointments: creation, modification, cancellation, confirmation, and sending automatic reminders.
- Storing and sharing the digital medical record based on explicit consent between patient and clinic.
- Processing subscription payments (through authorized third-party processors).
- Operational communications: in-app notifications, transactional emails (appointment confirmations, reminders, account updates).
- Improving and developing the Platform through aggregated and anonymized usage analytics.
- Legal compliance: record keeping in accordance with tax and accounting obligations.
- Direct marketing (only with prior consent): newsletters, personalised offers, promotional communications. You may unsubscribe at any time, free of charge.
5. Cookies and Similar Technologies
We use essential cookies for site functionality and Google Analytics cookies (anonymised) for traffic analysis. Non-essential cookies are only activated with your explicit consent.
The Platform uses cookies and similar technologies to ensure proper functionality, improve user experience, and analyze traffic. In accordance with the ePrivacy Directive (Directive 2002/58/EC) and the GDPR, we request your consent for non-essential cookies.
Categories of cookies used:
- Essential cookies (necessary): enable website navigation and use of basic features — session, authentication, privacy settings. Do not require explicit consent. Duration: current session or up to 12 months.
- Analytics cookies: Google Analytics (GA4) — collects anonymised data on traffic and user behaviour. Data is stored on Google servers within the EU through Standard Contractual Clauses (SCC). Duration: up to 26 months.
- Preference cookies: remember user settings (theme, language, cookie consent). Duration: 12 months.
On your first visit, a cookie consent banner is displayed with 'Accept All' and 'Necessary Only' options. You may modify your preferences at any time through your browser settings. Blocking essential cookies may affect Platform functionality.
6. Data Retention Periods
We keep data only as long as necessary: account data for the active period, medical data for 5 years after the last appointment, and financial data for 10 years as required by law.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, in accordance with the following timeframes:
- User account data: for the entire duration of the active account. Upon account deletion, data is anonymised or deleted within 30 days, except for data required by legal obligations.
- Medical data: retained for the duration of the contractual relationship and 5 years after the last appointment, in accordance with legal obligations in the medical field (Law 95/2006 on healthcare reform).
- Financial and accounting data: 10 years from the end of the financial year, in accordance with the Fiscal Code and Accounting Law 82/1991.
- Traffic and analytics data: up to 26 months (Google Analytics).
- Communication data (email, chat, WhatsApp): 3 years from the last communication.
- Cookies: as specified in the dedicated section above.
- Upon expiry of retention periods, data is permanently deleted, anonymised, or archived in a secure format, depending on applicable legal requirements.
7. Your Rights (GDPR)Updated
You have full control over your data: access, rectification, erasure, portability, objection, and consent withdrawal — anytime, upon simple request at info@inspicio.ro.
As a data subject, you are entitled to the following rights under Regulation (EU) 2016/679 (GDPR, Articles 15–22) and Romanian Law 190/2018:
- Right of access (Art. 15 GDPR) — you may request confirmation as to whether we process your data and obtain a copy of such data in an accessible format.
- Right to rectification (Art. 16 GDPR) — you may request correction of inaccurate data or completion of incomplete data without undue delay.
- Right to erasure ('right to be forgotten', Art. 17 GDPR) — you may request deletion of your data when it is no longer necessary for the original purposes, you withdraw consent, or you object and there are no overriding legitimate grounds.
- Right to restriction of processing (Art. 18 GDPR) — you may request restriction of processing where you contest the accuracy of the data, the processing is unlawful, or you have objected to processing.
- Right to data portability (Art. 20 GDPR) — you may request to receive the data you have provided to us in a structured, commonly used, machine-readable format (JSON, XML, or FHIR for medical data).
- Right to object (Art. 21 GDPR) — you may object at any time to processing based on our legitimate interest, including direct marketing. We will cease processing immediately unless we demonstrate compelling legitimate grounds overriding your interests.
- Right not to be subject to automated individual decision-making (Art. 22 GDPR) — we do not use automated decisions that produce legal effects or similarly significantly affect you.
- Right to lodge a complaint (Art. 77 GDPR) — you may address the National Supervisory Authority for Personal Data Processing (ANSPDCP), without prejudice to any other administrative or judicial remedies.
To exercise any of the above rights, you may contact us at info@inspicio.ro or at the postal address in section 1. We will respond to your request within 30 days, in accordance with Art. 12 GDPR. In complex cases or high volume of requests, the deadline may be extended by up to 60 days, of which you will be informed.
8. International Data Transfers
Your data is stored exclusively on servers within the European Union (Germany). Any transfer to third countries is done only with adequate safeguards through Standard Contractual Clauses.
Your personal data is stored on servers located within the European Union (Hetzner, Nuremberg, Germany), in compliance with the territorial limitation requirements of the GDPR (Chapter V).
For Google Analytics services, data may be transferred to the United States of America based on the Standard Contractual Clauses (SCC) adopted by Commission Implementing Decision (EU) 2021/914, supplemented by additional technical and organisational measures in accordance with EDPB Recommendations 01/2020.
We do not transfer personal data to third countries or international organisations without adequate safeguards in accordance with Chapter V of the GDPR.
9. Data Security
We protect your data with TLS 1.3 and AES-256 encryption, multi-factor authentication, encrypted daily backups, and role-based access control — compliant with Art. 32 GDPR.
We have implemented advanced technical and organisational measures to protect your data, in compliance with Art. 32 GDPR and industry standards:
- End-to-end encryption for data in transit (TLS 1.3) and at rest (AES-256).
- Storage on secure servers in Germany (Hetzner), with restricted physical access, firewall, intrusion detection/prevention system (IDS/IPS), and automated encrypted daily backups.
- Mandatory multi-factor authentication (MFA) for access to critical infrastructure and administrative data.
- Periodic security audits, penetration tests, and vulnerability assessments performed by specialised third parties.
- Role-based access control (RBAC) — employees only have access to data strictly necessary for their duties.
- Pseudonymisation and separation of medical data from direct identifiers where possible.
- Formalised security incident response procedure, with notification to the ANSPDCP within 72 hours of incident confirmation (Art. 33–34 GDPR).
- Daily automated backups with encrypted storage in a separate geographic location, periodically tested for integrity and restoration capability.
10. Data Shared with Third Parties
We do not sell or share personal data for behavioural advertising. Data is only shared with partner clinics (with your consent) and authorised processors.
We may share your data with the following categories of recipients, exclusively for the purposes set out in sections 3 and 4:
- Partner clinics — digital medical records are shared only on the basis of explicit consent, for the purpose of ensuring continuity of medical care.
- Payment processors (PCI DSS certified) — financial data strictly necessary for payment processing. We do not share or store full bank card details.
- Cloud and hosting service providers: Hetzner (Germany) — data stored exclusively in the EU, with processing contracts in accordance with Art. 28 GDPR.
- Google LLC — Google Analytics (GA4) — anonymised usage and traffic data, through SCC and additional measures compliant with EDPB recommendations.
- Legal authorities — when required by law, court order, or request from competent authorities (Police, Prosecutor's Office, ANSPDCP, ANAF, courts).
We do not sell personal data to third parties. We do not share data for behavioural advertising or commercial profiling.
11. Children's Privacy
Accounts for minors can only be created by parents or legal guardians, with explicit consent for medical data processing.
The Platform allows the creation of accounts for minors (under 18) exclusively through the accounts of parents or legal guardians. Processing of children's medical data is carried out with the explicit consent of the parent or legal guardian, in accordance with Art. 8 GDPR and applicable Romanian legislation.
We encourage parents to monitor their children's online activity and not to disclose access passwords. If you discover that a minor's data has been collected without your consent, please contact us immediately.
12. Changes to the Privacy Policy
Any material change to this policy will be notified at least 30 days in advance, via email or a notice on the Platform.
We reserve the right to periodically update this policy to reflect changes in legislation, technology, or operations. Material changes will be notified by email (if you have an active account) or by displaying a notice on the Platform at least 30 days before they become effective.
We recommend that you periodically review this page to stay informed of the latest information regarding the protection of your personal data.
13. Contact and Supervisory AuthorityUpdated
For questions or to exercise your GDPR rights, reach us at info@inspicio.ro or at our Tulcea office. You may also contact the ANSPDCP (www.dataprotection.ro).
For any questions, requests regarding your personal data, or exercise of your GDPR rights, you may contact us:
- Email: info@inspicio.ro
- Phone: +40 750 195 554
- WhatsApp: Chat on WhatsApp
- Postal address: 10 Lopatarului St., Tulcea, 820096, Romania
National Supervisory Authority for Personal Data Processing (ANSPDCP):
- Address: 28–30 G-ral. Gheorghe Magheru Blvd., Sector 1, Bucharest, 010336
- Website: www.dataprotection.ro
- Email: anspdcp@dataprotection.ro
Consumer Protection (ANPC): If you believe your consumer rights have been violated, you may contact the National Authority for Consumer Protection through:
- SAL Platform: https://anpc.ro/ce-este-sal
- ODR Platform: https://ec.europa.eu/consumers/odr
