Privacy Policy

I. General Provisions

The controller of personal data pursuant to Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data (hereinafter referred to as the “GDPR”) is SUPERDENT Clinic s.r.o., ID No. 23548576, with its registered office at U půjčovny 953/4, Nové Město, 110 00 Prague 1, registered in the Commercial Register maintained by the Municipal Court in Prague, file reference C 429008/MSPH (hereinafter referred to as the “Controller”).

Controller contact details: Address: U půjčovny 953/4, Nové Město, 110 00 Prague 1 E-mail: info@superdent.cz Phone: +420 776 216 228

The controller has not appointed a data protection officer.

II. Sources and categories of processed personal data

The controller processes personal data that you provide when scheduling an appointment (by phone, e-mail, or via the contact form on the website) or personal data obtained during the provision of healthcare.

The controller processes your identification and contact details (first name, surname, date of birth, address, telephone number, e-mail) and health data necessary for the provision of dental care (medical history, diagnoses, records of procedures, X-ray and other diagnostic images).

III. Legal basis and purpose of personal data processing

The legal basis for the processing of personal data is:

  • performance of a contract for the provision of healthcare pursuant to Article 6(1)(b) of the GDPR,
  • compliance with the controller’s legal obligations pursuant to Article 6(1)(c) of the GDPR (in particular Act No. 372/2011 Coll., on Health Services, and Decree No. 98/2012 Coll., on Medical Documentation),
  • processing of health data for the purpose of providing healthcare pursuant to Article 9(2)(h) of the GDPR.

The purpose of processing personal data is the provision of dental care, the maintenance of medical records, patient scheduling, and compliance with legal obligations. Providing personal data is a necessary requirement for the provision of healthcare; without it, care cannot be provided.

The controller does not engage in automated individual decision-making within the meaning of Article 22 of the GDPR.

IV. Data Retention Period

The controller retains personal data for the period necessary to exercise the rights and obligations arising from the provision of healthcare. Medical records are retained for the period stipulated by Decree No. 98/2012 Coll. (generally 10 years from the last contact with the patient). Accounting documents are retained for a period of 5 years in accordance with Act No. 563/1991 Coll., on Accounting.

Upon the expiration of the retention period, the controller shall delete the personal data.

V. Recipients of personal data

Recipients of personal data may include:

  • health insurance companies (to the extent necessary for the billing of care),
  • laboratories and specialized physicians (to the extent necessary to ensure follow-up care),
  • public authorities in cases prescribed by law.

The administrator’s website loads web fonts from Google Fonts, a service operated by Google Ireland Limited. Consequently, visiting the website may result in the transfer of your device’s IP address to Google servers. Further information regarding data processing by Google can be found at https://policies.google.com/privacy.

The website hosting provider (Forpsi) may technically process the IP addresses of website visitors as a processor pursuant to Article 28 of the GDPR.

The controller does not intend to transfer personal data to third countries outside the EU, with the exception of the aforementioned technical transfer associated with the loading of web fonts.

VI. Cookies

The use of cookies on the controller’s website is governed by a separate Cookie Policy, available on the controller’s website.

VII. Your Rights

Under the conditions set out in the GDPR, you have:

  • the right of access to their personal data pursuant to Article 15 of the GDPR,
  • the right to rectification of personal data pursuant to Article 16 of the GDPR, or, where applicable, to restriction of processing pursuant to Article 18 of the GDPR,
  • the right to erasure of personal data pursuant to Article 17 of the GDPR,
  • the right to object to processing pursuant to Article 21 of the GDPR,
  • the right to data portability pursuant to Article 20 of the GDPR,
  • the right to withdraw consent to the processing in writing or electronically at the controller’s contact address specified in Article I of this policy.

You also have the right to lodge a complaint with the Office for Personal Data Protection (www.uoou.cz) if you believe that your right to the protection of personal data has been violated.

VIII. Conditions for the Protection of Personal Data

The Controller declares that it has implemented all appropriate technical and organizational measures to secure personal data. Medical records in paper form are stored in locked premises. Electronic records are protected by access passwords. The Controller declares that access to personal data is restricted to authorized persons bound by a duty of confidentiality.

IX. Final Provisions

The controller is entitled to amend these principles. It will publish the new version on its website.