1. Personal data collected
As part of the use of the application, certain personal data is collected in order to identify patients and provide access to their medical records. The information collected includes, in particular, the patient’s first name, last name, and email address. This data is required to create a secure account and to associate the user of the application with their existing patient file held by the dental office.
No additional sensitive data is collected by the application beyond what is strictly necessary for the proper functioning of the service. All data provided by the user is processed confidentially and used solely to enable personalized access to the services offered.
2. Use of data
The data collected through the application is used exclusively to allow the patient to access their medical and financial documents, to review the history of their payments, and to facilitate the administrative management of their dental care. This information is used by the dental office to match the identity declared in the application with the patient record already registered by the practitioner.
The data is not used for commercial prospecting, targeted advertising, or profiling. It is never transmitted or sold to third parties. Its use is strictly limited to the relationship between the patient and the dental office, in full compliance with medical obligations and applicable law.
3. Payments
All payments made through the application are fully managed by the service provider Stripe. As such, no banking information or card numbers pass through or are stored on the application’s infrastructure or by the dental office. Stripe is solely responsible for the technical processing and security of payment information, in compliance with international PCI DSS standards.
The dental office never has access to the patients’ banking details and only receives confirmation of the successful completion of a transaction in order to ensure proper accounting follow-up. Patients can therefore make payments with full confidence, benefiting from enhanced protection in accordance with recognized security standards.
4. Data retention and deletion
The personal data collected through the application is retained only for the period strictly necessary to provide the associated services. When a user chooses to delete their account, all information stored on the application’s infrastructure is permanently erased and cannot be restored.
It should be noted, however, that medical documents and personal data transmitted to the dental office as part of the patient’s treatment may continue to be retained by the office in accordance with its legal and regulatory obligations. In particular, legislation requires dentists to keep medical records for a minimum period defined by public health regulations, regardless of the continued existence of an account within the application.
5. Access and consultation of data
Access to data is strictly limited to the patient concerned and the dental office responsible for their care. No third party is authorized to consult or use this information. The user accesses their documents and financial information through a secure personal account, while the dental office consults them exclusively within the context of the medical relationship and the patient’s treatment.
This framework ensures that only the parties directly involved have the right to access the data, in a spirit of absolute confidentiality and protection of privacy.
6. Security and confidentiality
The protection of personal data is a fundamental priority. Exchanges between the application and the servers are carried out using secure protocols, guaranteeing the integrity of the information transmitted and preventing any unauthorized access.
Each request sent by the application is subject to strict authentication in order to verify the user’s identity and to prevent any attempt at fraudulent access. The security measures in place ensure that only authorized persons may consult the data, in full compliance with applicable legal requirements.
7. Users’ rights
In accordance with applicable data protection regulations, each user has the right to access, rectify, and delete their information. These rights may be exercised directly through the application’s settings or by submitting a request to the dental office.
Users also retain the ability to request a restriction of the processing of their data or to object to its use, within the limits established by law. Any request regarding the exercise of these rights should be addressed to the dental office at the following address: dentistebr@gmail.com.
8. Data controller
The data controller responsible for the processing of information collected through the application is Dr. Stéphane BERG, dentist, practicing at the office located at 52a Grand’Rue, 67360 Walbourg.
For any question regarding data protection or this privacy policy, the dental office may be contacted by email at dentistebr@gmail.com, or by postal mail at the office address listed above.