
Privacy Policy
1. The data controller and contact details
This Privacy Policy describes how the personal data of website visitors and of persons who submit a request through it is processed, as well as the rights you are entitled to. The processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR), with Legea nr. 190/2018 (Romania's national law implementing the GDPR) and with Legea nr. 506/2004 (the Romanian law on the processing of personal data in the electronic communications sector).
I recommend that you read this document carefully. For any query, you can write to me using the contact details below.
This website is published by Dr. Ana-Maria Spiridon, dentist, a member of the Colegiul Medicilor Stomatologi din România (the Romanian College of Dentists). For the processing carried out by the website — the requests submitted through the contact form and the appointment form, correspondence by e-mail and through the messaging channels, cookies, the virtual assistant and the information forum — the data controller is Dr. Ana-Maria Spiridon.
The clinical activity is carried out as a collaborating dentist at DentaField Clinic, Bulevardul Constantin Brâncoveanu nr. 18, Sector 4, 041451 București, https://dentafield-clinic.com. DentaField Clinic is the provider of the medical services presented on this website: consultations and treatments are provided within the clinic, and the clinic is the data controller for the patient's medical record and for the medical documentation drawn up on the occasion of treatment.
When a request submitted through the website leads to an appointment, the data necessary for organising the consultation is communicated to DentaField Clinic, as the provider at which treatment is given. From the moment the medical record is opened, the clinic is the controller for the data contained in it and applies its own data protection notices and procedures.
You can contact me as follows:
• E-mail: contact@dranamariaspiridon.com
• Messaging: Facebook Messenger and Instagram Direct, through the buttons available on the website
• Where the services are provided: DentaField Clinic, Bulevardul Constantin Brâncoveanu nr. 18, Sector 4, 041451 București
For any question or request concerning the processing of your data and the exercise of the rights provided by the GDPR, you can write to me at the e-mail address above, marked "Data protection". Please do not include detailed health data in the messages you send through the messaging channels.
I have not appointed a Data Protection Officer (DPO). The processing described in this policy is not carried out by a public authority or body, does not involve regular and systematic monitoring of data subjects on a large scale and does not have as its core activity the large-scale processing of special categories of data, so that the conditions laid down by Art. 37(1) GDPR for the mandatory appointment of a DPO are not met. The contact point for all data protection matters remains the e-mail address indicated above.
The website's forms do not request the personal numerical code (CNP). Where processing of the personal numerical code is necessary for drawing up medical or fiscal documents, this takes place within DentaField Clinic, with the additional safeguards required by Art. 4 of Legea nr. 190/2018.
2. What categories of data are processed
Depending on how you interact with the website, the following categories of data may be processed:
• Identification and contact data: surname, first name, e-mail address and telephone number, provided by you in the website's forms so that your request can be acted upon.
• Data submitted through the website's forms (the contact form and the form for requesting a dental consultation): the content of the message, the reason for the request, the preferred appointment slot and any other information you choose to include. The "reason for the visit" may, by its nature, reveal a health concern.
• Health data — a special category of data (Art. 9 GDPR): the information about your oral health that you choose to communicate through the online channels. The clinical documentation itself — medical history, diagnoses, dental treatment plans and records (crowns, bridges, veneers, implants, dentures), dental X-rays (including orthopantomography, cephalometric radiography, 3D CBCT), clinical images, allergies and relevant medical history — is drawn up and kept at DentaField Clinic, in the patient's medical record.
• Data from correspondence: the messages exchanged by e-mail or through the messaging channels, the history of the requests submitted through the website and the questions asked in the information forum.
• Data from your interaction with the virtual assistant (chatbot): the content of the conversation and the questions you ask.
• Technical and website usage data: IP address, device and browser identifiers, the pages accessed, the date and time of access, as well as the data collected through cookies and similar technologies (including Google Analytics 4), under the conditions described in the Cookie Policy and only on the basis of your consent.
• Data from public reviews: the displayed name and the content of the review you have published on Google.
I do not ask for, and do not wish to receive, through the online channels, more data than is necessary for the specific purpose of the interaction.
3. The purposes of the processing and the legal bases
I process your data only for specific purposes and on the basis of a legal ground provided by the GDPR:
• Handling requests submitted through the contact form, by e-mail or through the messaging channels — legal basis: taking steps at your request prior to entering into a contract [Art. 6(1)(b) GDPR] and, where applicable, the legitimate interest in responding to you and communicating effectively [Art. 6(1)(f) GDPR].
• Handling appointment requests and transmitting to DentaField Clinic the data necessary for organising the consultation — legal basis: pre-contractual steps at your request [Art. 6(1)(b) GDPR].
• Providing dental medicine services and drawing up the medical documentation — this takes place within DentaField Clinic, as the provider; the specific legal bases for health data are set out in the following section.
• Complying with legal obligations (for example, retaining the correspondence needed to resolve a complaint, or responding to requests from the competent authorities) — legal basis: the legal obligation [Art. 6(1)(c) GDPR].
• Cookies and analytics tools (Google Analytics 4) — legal basis: your consent [Art. 6(1)(a) GDPR], which you can give or refuse from the cookie banner and which you can withdraw at any time.
• Ensuring the security of the website and of the systems, preventing abuse and diagnosing technical problems — legal basis: the legitimate interest in maintaining a secure and functional online environment [Art. 6(1)(f) GDPR].
• Establishing, exercising or defending a legal claim in court — legal basis: the legitimate interest [Art. 6(1)(f) GDPR] or the legal obligation [Art. 6(1)(c) GDPR].
4. Health data and professional medical secrecy
Health data enjoys special protection and is processed as follows:
• Within dental care (consultation, diagnosis, dental treatment plan, monitoring), processing is necessary for the purposes of preventive medicine, establishing a diagnosis and providing dental medical care, under Art. 9(2)(h) read together with Art. 9(3) GDPR. This data is processed within DentaField Clinic, by the treating doctor and the clinic's staff, who are bound by the legal obligation of professional secrecy, in accordance with Legea nr. 46/2003 (the Romanian Patients' Rights Law) and with the Codul deontologic al medicului stomatolog (the Dentists' Code of Professional Conduct).
• If you choose, on your own initiative, to communicate information about your health to me online (through a form, e-mail, messaging, the information forum or the virtual assistant), I process it strictly in order to contact you and act upon your request, under Art. 9(2)(h) read together with Art. 9(3) GDPR and the legitimate interest in responding to you [Art. 6(1)(f) GDPR].
Professional medical secrecy and the obligation of confidentiality are not limited in time and remain in force even after the end of the relationship with the patient. Please do not send detailed health data (diagnoses, conditions, clinical images) through the online forms, by e-mail, through messaging or through the virtual assistant; these matters are discussed safely during a consultation.
5. Recipients of the data and processors
I do not sell your data. It may be disclosed or made accessible to the following categories of recipients, strictly to the extent necessary:
• DentaField Clinic — the provider at which consultations and treatments are given, to which I communicate the data necessary for organising the appointment and carrying out the medical procedure; the clinic processes this data as its own controller.
• The web hosting and infrastructure provider — Amazon Web Services (AWS), through the AWS Amplify service, which hosts the website and securely stores the data associated with the forms.
• Amazon Web Services (Amazon Bedrock) — for the operation of the virtual assistant (chatbot), which processes the content of the conversations in order to generate responses; the service is used in a European Union region.
• Google — for displaying maps (Google Maps) and, only with your consent, for statistical analysis (Google Analytics 4).
• Meta Platforms — when you choose to write to me through Facebook Messenger or Instagram Direct, the messages are transmitted to and stored on Meta's infrastructure, in accordance with its own policies.
• The message delivery service provider — a specialised provider of e-mail and message delivery services, on the basis of contractual confidentiality and security guarantees.
• Public authorities, courts or other bodies, when there is a legal obligation to that effect.
Where these providers process data on my behalf, they act as processors and are bound by data processing agreements concluded in accordance with Art. 28 GDPR. DentaField Clinic, Google and Meta Platforms act as controllers for their own processing, in accordance with their own notices.
6. Transfers of data outside the European Economic Area
Some of the providers used (in particular Google and Meta Platforms and, where applicable, AWS) may process data on servers located outside the European Economic Area, including in the United States of America.
When such transfers take place, I ensure that they are protected by appropriate safeguards within the meaning of the GDPR: the Standard Contractual Clauses adopted by the European Commission [Art. 46(2)(c) GDPR] and/or the provider's certification under the EU-U.S. Data Privacy Framework. You have the right to obtain information about the safeguards applied by writing to me at the e-mail address indicated in section 1.
7. How long data is kept
Data is kept only for as long as is necessary for the purposes for which it was collected or in order to comply with legal obligations. The main situations are:
• The patient's medical record and the dental medical documentation: are drawn up, kept and archived by DentaField Clinic, within the time limits laid down by the legislation applicable to healthcare providers and by the professional regulations. Requests concerning these documents are addressed to the clinic.
• The financial and accounting documents relating to the dental services (invoices and supporting documents): are issued and kept by DentaField Clinic, within the time limits laid down by Legea contabilității nr. 82/1991 (the Romanian Accounting Law).
• Requests submitted through the contact form and the related correspondence: for the period necessary for their resolution and, thereafter, for a proportionate period, as a rule up to 24 months, except where they are needed for the defence of a legal claim or for the fulfilment of a legal obligation.
• Appointment requests: for the period during which the request is handled; thereafter they are deleted from the website's records, the data necessary for treatment being taken over into the medical record kept by the clinic.
• Conversations with the virtual assistant: short periods, proportionate to the purpose of operating the service and preventing abuse.
• Technical logs and security data: short periods, proportionate to the security and technical diagnostic purpose.
• Data processed on the basis of consent (for example, analytics cookies): until consent is withdrawn or until the cookie's lifespan expires.
Upon expiry of these periods, the data is securely deleted or anonymised.
8. Your rights
As a data subject, you are entitled to the following rights provided by the GDPR:
• The right of access (Art. 15): to obtain confirmation that your data is being processed and a copy of it.
• The right to rectification (Art. 16): to correct inaccurate data or to complete incomplete data.
• The right to erasure — the "right to be forgotten" (Art. 17): to obtain the erasure of the data under certain conditions. This right is not absolute: it does not apply where processing is necessary for the fulfilment of a legal obligation — for example, the documents in the medical record cannot be erased before the expiry of the legal retention periods applicable to the provider.
• The right to restriction of processing (Art. 18).
• The right to data portability (Art. 20), for data processed by automated means, on the basis of consent or a contract.
• The right to object (Art. 21): to object to processing based on the legitimate interest, for reasons relating to your particular situation.
• The right to withdraw consent at any time [Art. 7(3) GDPR], where processing is based on consent. Withdrawal does not affect the lawfulness of the processing carried out beforehand.
• The right to lodge a complaint with the supervisory authority (see the ANSPDCP section).
For the rights relating to the processing described in this policy, you can write to me at the e-mail address indicated in section 1. For the rights relating to the medical record and the clinical documentation, the request is addressed to DentaField Clinic, as the controller for that data. A response is provided, as a rule, within one month of receipt of the request.
9. Retention of documents for the defence of a legal claim
Even if you request the erasure of the data, object to the processing (Art. 21 GDPR) or request its restriction (Art. 18 GDPR), the data and the related documents may continue to be kept and processed, to the extent necessary for the establishment, exercise or defence of a legal claim in court [Art. 17(3)(e), Art. 18(2) and Art. 21(1) GDPR]. This concerns both the correspondence kept in connection with the website and the medical documents held at DentaField Clinic, for the duration of the applicable limitation periods and of the legal archiving periods.
10. The website's information forum
The website provides an information forum of a general nature, in which questions and answers with educational dental content, in the field of dentistry (prosthetics and aesthetics), are published. The forum does not constitute an individualised medical consultation and no doctor–patient relationship arises through it.
The questions and answers published on the forum do not contain identifiable individual medical data. The aliases used (for example "Andreea M.") are pseudonymised or fictitious. If you choose to interact with the forum, please do not include identifiable personal health data.
The content of the forum is reviewed by Dr. Ana-Maria Spiridon before publication and is intended exclusively for informational and educational purposes, without constituting a diagnosis, a treatment recommendation or an individualised medical opinion.
11. Google Reviews
When patient reviews are displayed on the website, data (the displayed name and the content of the review) may be retrieved from the Google platform, where you have published these reviews. Display on the website is based on the legitimate interest in presenting genuine opinions [Art. 6(1)(f) GDPR]. You may object to the display by writing to me at the e-mail address indicated in section 1.
No internally generated rating or average score is published or used, and no reviews or scores are fabricated.
12. Clinical dental photographs and records
Clinical photographs (including "before/after" images used for educational or illustrative purposes), dental X-rays and records made for the purpose of dental diagnosis and treatment form part of the patient's medical record, are kept at DentaField Clinic and are processed under Art. 9(2)(h) GDPR (healthcare).
Any images used for educational purposes or for public presentation are used only with the explicit, prior and written consent of the person concerned and, in the case of minors, of the parent or legal guardian. Withdrawal of consent stops the public educational or presentational use, without affecting the retention of the clinical documents in the medical record.
Identifiable clinical images of minors are not published in the absence of the consents mentioned above.
13. Data security and incident notification
I apply appropriate technical and organisational measures to protect the data against unauthorised access, loss, destruction or disclosure [Art. 32 GDPR]: access control, encryption in transit, need-to-know access restriction and internal confidentiality procedures.
In the event of a security breach involving personal data that is likely to result in a risk to your rights and freedoms, I will notify the ANSPDCP within 72 hours of becoming aware of it [Art. 33 GDPR]. Where the breach is likely to result in a high risk, you too will be informed, without undue delay [Art. 34 GDPR]. Incidents concerning the medical record or DentaField Clinic's systems are handled by the clinic, under the same legal conditions.
14. The virtual assistant and automated decisions
The virtual assistant (chatbot) available on the website provides automated responses to questions of a general nature (information about services, schedule, contact) and has an exclusively informational role. You are informed that you are interacting with an automated system, not a natural person.
No decisions are taken based solely on automated processing that would produce legal or medical effects on you [Art. 22 GDPR]. The virtual assistant does not make diagnoses and does not establish dental treatment plans; any treatment plan is established by Dr. Ana-Maria Spiridon, following a consultation carried out at DentaField Clinic. I recommend that you do not enter sensitive data, including health data, into the conversation.
15. Minors' data
The website and the online channels presented on it are not intended for direct use by minors without the involvement of a parent or legal guardian. Dental services provided to minors are discussed and consented to with the parents or legal guardians, in accordance with Legea nr. 46/2003.
If you are a parent or legal guardian and consider that a minor has submitted data without your consent, please contact me so that the necessary measures can be taken.
16. Supervisory authority and the patient's rights
If you consider that the processing of your data infringes data protection legislation, you have the right to lodge a complaint with the supervisory authority:
The National Supervisory Authority for the Processing of Personal Data (ANSPDCP)
• Address: B-dul G-ral Gheorghe Magheru nr. 28-30, Sector 1, postal code 010336, București, Romania
• E-mail: anspdcp@dataprotection.ro
• Website: www.dataprotection.ro
However, please contact me first — I will endeavour to resolve any complaint directly.
In addition to the rights provided by the GDPR, you also benefit from the specific patient rights regulated by Legea nr. 46/2003: confidentiality of all information concerning your health status, diagnosis, treatment and personal data (Art. 21); disclosure of this information to other persons only with your explicit consent or where the law expressly requires it (Art. 22); access to your personal medical data (Art. 24).