Privacy Policy

Last updated: 18 August 2026

1. Controller

The controller of personal data described in this policy is Dentmall s.r.o., Company ID (IČO): 09041036, VAT ID (DIČ): CZ09041036, registered office Pivovarská 214/4, 370 01 České Budějovice, Czech Republic, registered with the Regional Court in České Budějovice, file no. C 29761. Contact for all personal data matters: dentmall@email.cz.

We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR"). The Provider is not obliged to appoint a data protection officer pursuant to Article 37 GDPR and has not appointed one.

2. Scope of this policy

This policy covers the DentVIS application (macOS, Windows, iPadOS), the web dashboard at app.dentvis.com, the cloud services and the website www.dentvis.com. DentVIS is a Class I medical device pursuant to Regulation (EU) 2017/745 (MDR); regulatory information is available on the regulatory information page.

Our website and the Service may contain links to third-party websites and services. We are not responsible for their content or privacy practices; their own terms and privacy policies apply.

3. Data-minimised by design

DentVIS is built to avoid processing personal data of the persons to whom the dental models belong. Case records are identified by a case label chosen by the user — users are contractually obliged not to enter names or other data identifying those persons into the Service, and not to upload photographs or documents identifying any person (see our Terms of Service). The cloud service is therefore designed to hold only case data that does not contain directly identifying information.

If and to the extent case data synchronized to the cloud service contains personal data of third parties, the user (the dental professional or practice) acts as the controller of such data and we act strictly as the user's processor under Article 28 GDPR, processing it solely to provide the Service. A data processing agreement is available on request at dentmall@email.cz.

Data that users process solely locally on their devices is not transmitted to us; with respect to such data we are neither a controller nor a processor. The software is a tool under the exclusive control of the dental professional.

A 3D dental model or other case content may, in the hands of the dental professional, constitute data concerning health within the meaning of Article 4(15) GDPR. Where that is the case, the professional — as the controller — is responsible for satisfying one of the conditions of Article 9(2) GDPR for its processing (typically the provision of health care under Article 9(2)(h)); our role remains limited to that of a processor acting on the professional's instructions.

4. What we process, why and on what legal basis

Account data — e-mail address, name, country, profession type, practice/organisation identification (including company and VAT numbers and billing address where provided), profile picture (avatar) if you set one, and licence information. Purpose: creation and administration of your account, provision of the Service, communication. Legal basis: performance of a contract (Art. 6(1)(b) GDPR); invoicing data also legal obligation (Art. 6(1)(c)).

Billing data — payments are processed by our merchant of record, Paddle.com Market Ltd, which acts as an independent controller for payment processing. We do not receive or store your full card details; we receive order and invoicing information (product, amount, country, invoicing details). Legal basis: performance of a contract and legal obligations (accounting and tax law).

Case data — the 3D dental models, case labels, photographs you attach to a case and related content you upload are processed solely to provide the Service: local processing on your device and, where your licence includes it and you use it, cloud synchronization between your devices and sharing you invoke. Case data is not intended to contain personal data (see the previous Section). Legal basis: performance of a contract.

Records of legal acceptance — when you accept the Terms, this policy or other legal documents, we record the accepted document and version, the timestamp, and technical identifiers of the acceptance (such as device identifier, application version, IP address and browser/user agent). Purpose: evidence of the conclusion of the agreement and of consents required by law. Legal basis: performance of a contract and legitimate interest in the ability to prove acceptance.

Technical and security data — technical logs necessary to operate and secure the Service (e.g. authentication events, licence checks, error logs). Legal basis: legitimate interest in the security and reliability of the Service.

Communication — if you contact us (e-mail, support requests, incident reports), we process the communication and the data you provide in it for the purpose of handling your request. Legal basis: performance of a contract or legitimate interest. Service e-mails (e.g. account confirmation, licence and retention notifications) are sent as part of the provision of the Service.

Aggregated statistics — we may create and use aggregated, statistical information about the use of the Service (for example, numbers of active licences or feature usage counts derived from technical logs) to operate, secure and improve the Service. Such statistics do not contain Customer Data content and do not identify any person.

There is no automated individual decision-making within the meaning of Article 22 GDPR.

5. Processors and recipients

We use a limited number of service providers. Those acting as our processors are bound by data processing agreements under Article 28 GDPR; providers marked as independent controllers process personal data under their own responsibility and their own privacy terms:

  • Supabase — hosting of the database, authentication and file storage for the cloud service, on infrastructure located in the European Union (Frankfurt, Germany);
  • Paddle.com Market Ltd — merchant of record for purchases (independent controller for payment processing);
  • Resend (United States) — delivery of transactional e-mails (e.g. account confirmation and service notifications);
  • Netlify — hosting of the website and dashboard (static content);
  • Apple — distribution of the iPadOS application through the App Store (independent controller under your relationship with Apple).

A current list of processors is available on request. Beyond that, personal data may be disclosed to competent public authorities upon a lawful request, and to our professional advisers where necessary to protect our rights. Recipients may not process the data for any other purpose.

We do not sell or rent personal data, and we do not share it with third parties for their marketing purposes. If the Provider or its assets are involved in a merger, acquisition, financing, reorganisation or sale, personal data may be transferred to the legal successor or acquirer as part of that transaction, subject to this policy and applicable law; we will inform you of such a change.

6. International transfers

Service data (account and case data) is stored in the European Union. Some supporting providers may process limited personal data (such as e-mail address and message content of transactional e-mails) outside the EU/EEA; in such cases the transfer is safeguarded in accordance with Chapter V GDPR, in particular by the European Commission's Standard Contractual Clauses or an adequacy decision. This applies in particular to the delivery of transactional e-mails through Resend (United States). A copy of the relevant safeguards, or information on where they are available, can be obtained at dentmall@email.cz.

7. Retention

Account and contract data — for the duration of the contractual relationship and thereafter for the time necessary to protect legal claims arising from it: as a rule up to 10 years from termination, corresponding to the objective limitation periods under the Civil Code; records directly evidencing the conclusion and content of the agreement (including records of legal acceptance) may be retained for up to 15 years where necessary with regard to the limitation period applicable to intentionally caused damage.

Billing records — for the periods required by tax and accounting law.

Case data in the cloud service — for the duration of your licence. Case data untouched for 12 months is archived automatically; approximately one month before permanent deletion we notify you by e-mail, and after the notified period the data is permanently deleted. Restoring a case from the archive restarts the period. For a reasonable period after termination of your account you may request an export of your cloud-stored case data; after that period the data is deleted.

Technical logs — for a period appropriate to their security purpose.

After expiry of the retention period, personal data is deleted.

8. Cookies and local storage

The website www.dentvis.com is static and uses no advertising, analytics or tracking cookies; it stores only a local acknowledgement of the cookie notice in your browser. The DentVIS web dashboard (app.dentvis.com) uses only strictly necessary cookies and local storage — for example to keep you signed in. Strictly necessary cookies do not require consent under the ePrivacy rules. We do not use third-party marketing or profiling cookies.

9. Security

We have adopted appropriate technical and organizational measures to secure personal data, taking into account the state of the art and the nature of the processing. Data is encrypted in transit; access to production data is restricted to authorised persons and protected by authentication; cloud data is logically separated per account. Only persons authorised by the Provider have access to personal data. No method of transmission or storage is completely secure; we will notify you and the supervisory authority of personal data breaches where required by Articles 33 and 34 GDPR.

10. Your rights

Under the conditions set out in the GDPR you have the right of access to your personal data (Art. 15), the right to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), the right to object to processing based on legitimate interest (Art. 21), and — where processing is based on consent — the right to withdraw consent at any time.

You can exercise these rights at dentmall@email.cz. We will respond without undue delay, at the latest within one month. In the case of manifestly unfounded or repeated requests we may charge a reasonable fee or refuse to act, as permitted by the GDPR.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work or of the alleged infringement. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz. We would, however, appreciate the opportunity to address your concern first — please contact us at dentmall@email.cz.

11. Children

The Service and the website are intended for professionals and business users aged 18 or over. We do not knowingly collect personal data from children. This does not affect the processing of case data concerning persons of any age carried out by dental professionals in their role as controllers (see the following section).

12. Persons whose dental models are processed

If your dental professional or dental laboratory uses DentVIS to prepare a digital model concerning you, the controller of any personal data involved is that professional or laboratory — please direct any requests concerning your data to them. Data processed only locally on the professional's device never reaches us. Where the professional uses the optional cloud synchronization, we act solely as their processor: we do not decide on the purposes of the processing, and we are contractually prevented from using the data for our own purposes. If you send us a request and identify the professional concerned, we will forward it to them without undue delay; please note that cases are stored under neutral labels, so we are generally unable to locate data from a person's name alone.

13. Changes to this policy

We may update this policy from time to time, for example due to changes in legislation or in the Service. The current version is always available at www.dentvis.com/privacy; material changes will be announced through the Service or by e-mail, and where required you will be asked to acknowledge the new version.

This policy is effective as of 18 August 2026 and replaces all previous versions.