General Privacy Policy

Information on the processing of personal data

General Privacy Policy

This Policy explains how personal data are collected, used, stored and protected in connection
with drciobanu.md, appointment requests and the dental
services provided by DrCiobanu Clinic.

Last updated
Effective from

1. Who controls your data

The controller responsible for the processing described in this Policy is:

Individual Enterprise “NICOLETA-CIOBANU”

IDNO: 1004600026937

Registered office: MD-6824, Ialoveni district, Puhoi village, Republic of Moldova

Clinic: 65 Tighina Street, 2nd floor, ICAM, Chișinău, Republic of Moldova

Email: contact@drciobanu.md

Telephone: +373 607 46 274

Data Protection Officer: Nicoleta Ciobanu — contact@drciobanu.md

2. Scope and legal framework

This Policy applies to visitors, people who contact us or request an appointment, patients,
their representatives and other people whose data are processed in connection with our services.
Processing is carried out under the
Law No. 195/2024 on personal data protection,
applicable healthcare legislation and other legal obligations.

Cookies and similar technologies are explained separately in our
Cookie Policy.

3. Personal data we process

Category Examples
Identity and contact data Name, surname, email address, telephone number and, where legally required, other identification details.
Appointment data Selected doctor, preferred date and time, message, reason for contact and communication history.
Health data Medical history, symptoms, diagnosis, treatment, images, test results and other information needed for dental care.
Administrative and financial data Services provided, invoices, payments and accounting records.
Technical and online data IP address, device and browser information, language, technical logs, cookie choices and, subject to consent, analytics or advertising identifiers.
Communications Telephone, email, form and messaging correspondence, including attachments you choose to send.

Please do not include detailed medical information in the website’s free-text fields unless it is necessary for the request.

4. Purposes and legal grounds

Purpose Legal ground
Handling requests, answering questions and arranging appointments Steps requested before providing services and performance of the service relationship — Article 6(1)(b) of Law No. 195/2024; where appropriate, legitimate interests in organising and documenting communications — Article 6(1)(f).
Providing dental care and maintaining medical records Medical diagnosis, treatment and management of healthcare by professionals bound by confidentiality, together with applicable legal obligations — Articles 6 and 9 of Law No. 195/2024.
Billing, accounting and statutory reporting Compliance with legal obligations — Article 6(1)(c).
Website operation, security, fraud prevention and incident investigation Legitimate interests in operating a secure service — Article 6(1)(f), and legal obligations where applicable.
Analytics, advertising and other non-essential technologies Consent given through the cookie banner — Article 6(1)(a). Consent may be withdrawn at any time.
Defending legal claims and responding to authorities Legal obligations and legitimate interests in establishing, exercising or defending rights.

We do not use appointment-form acknowledgement as consent to process a request. It confirms that this information has been made available to you.

5. Health data

Health data are a special category of personal data. They are processed only when necessary for
diagnosis, dental treatment, continuity of care and compliance with healthcare duties, by or under
the responsibility of professionals subject to professional secrecy. Where another legal ground is
required, we will request explicit consent or rely on another condition allowed by law.

6. Sources and required information

We may obtain data directly from you, from a parent, guardian or legal representative, from another healthcare provider where authorised or permitted by law, and automatically through technical logs and cookie choices.

Fields marked as required are needed to contact you and arrange the appointment. Without them, we may be unable to process the request. Optional fields may be left blank.

7. Recipients

Data may be accessed, strictly as necessary, by authorised clinic staff, healthcare professionals and laboratories involved in care, IT, hosting, email, backup, security and antispam suppliers, professional advisers, insurers and public authorities where required or permitted by law.

Technology suppliers used in connection with the website include:

  • VIMSOFT DIGITAL PRODUCTION SRL, for website administration and maintenance, including limited technical access and temporary receipt of copies of some appointment requests for delivery checks and incident diagnosis;
  • Hetzner Online GmbH, for website hosting infrastructure and email services;
  • QSOFT LLC (Kommo, formerly amoCRM), for providing the CRM platform used to record and manage enquiries, responses and appointments. For this purpose, the person’s name, telephone number, email address, message and selected doctor may be transmitted. The clinic does not use the platform for direct marketing, and Kommo AI features are not enabled;
  • Google Ireland Limited and relevant affiliates, for services such as reCAPTCHA, Google Maps, Google Analytics, Google Ads, Google Tag Manager or Gmail.

During technical form checks, a copy of some appointment requests may be sent temporarily to a Gmail address used by the maintenance provider. Access is limited to authorised technical personnel solely for delivery checks and incident diagnosis. Technical copies are retained only while necessary for this purpose and are then deleted.

A supplier may act as our processor or as an independent controller, depending on the service. Processors are contractually required to protect data and follow documented instructions. Non-essential analytics and advertising services are activated only according to cookie choices. We do not sell personal data.

8. International transfers

Infrastructure, email and online service providers may process data in the European Economic Area,
the United States or other countries where they operate. Data relating to enquiries submitted through the website forms are transferred automatically to the Kommo cloud platform. According to the provider’s documentation, the data may be stored or processed in the United States and other countries where QSOFT LLC or its subprocessors operate.

Transfers are made only under Chapter V
of Law No. 195/2024, using an adequacy decision, appropriate contractual safeguards or another
lawful derogation, as applicable. You may request information about the relevant recipients,
countries and safeguards using the contact details below.

9. How long we keep data

Category Period or criterion
Enquiries and appointment requests, including data stored in Kommo, that do not result in a patient relationship Normally no more than 12 months after resolution, unless needed for an appointment, a legal obligation or defence of a right.
Temporary technical copies of appointment requests Only for delivery checks and incident diagnosis; deleted without undue delay once the technical purpose ends.
Medical files and records For the periods required by healthcare legislation and the applicable records schedule.
Accounting records For the periods required by financial, accounting and tax law.
Technical and security logs For the period necessary to protect systems and investigate incidents; longer where needed as evidence.
Consent records For the consent-based processing and afterwards as needed to demonstrate the choices made and defend legal rights.
Backups Until overwritten under the technical rotation cycle; restored data remain subject to the original retention period.

After the applicable period, data are erased, irreversibly anonymised or archived where required by law. Erasure does not apply to data that we are legally required to retain.

10. Security

We apply technical and organisational measures proportionate to risk, including access control, confidentiality duties, appropriate authentication, encrypted connections, backups, security updates, logging, staff awareness, supplier review and incident response procedures.

No system can guarantee absolute security. If a personal data breach occurs, we assess the risk and notify the National Center for Personal Data Protection and, where required, affected individuals within the statutory deadlines.

11. Your rights

Subject to Law No. 195/2024, you may request information and access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests or direct marketing. Where processing relies on consent, you may withdraw it at any time without affecting earlier processing.

You also have the right not to be subject to a solely automated decision producing legal or similarly significant effects. We do not make such decisions in relation to dental services. Analytics or advertising tools may create profiles only according to your cookie consent.

To exercise a right, contact us using the details below. We may request information needed to verify identity. We normally respond within the period required by law; complex or numerous requests may allow a lawful extension, of which we will inform you.

12. Children’s data

Where a patient is a child, we process the child’s and representative’s data for healthcare and legal purposes. Requests should be made by a parent, guardian or authorised representative where the law requires. We apply additional care to children’s data and consider the child’s best interests and evolving capacity.

13. Cookies, reCAPTCHA, maps and third-party platforms

The website uses essential cookies and may use preference, analytics and advertising technologies according to your choices. Details about providers, purposes, duration and changing your choices are in the Cookie Policy.

Non-essential Google services, including analytics, advertising and maps where they store or access non-essential information, are loaded only after the relevant consent. reCAPTCHA may process technical data to protect forms from abuse; its use is limited to what is necessary for security and is described in the cookie notice. Links to social or messaging platforms take you to services governed by their own privacy policies.

14. Contact and complaints

For questions or to exercise a right, contact the controller or Data Protection Officer, Nicoleta Ciobanu, at contact@drciobanu.md, telephone +373 607 46 274, or by post at the registered-office address above.

You may also lodge a complaint with:

National Center for Personal Data Protection (CNPDCP)
48 Serghei Lazo Street, Chișinău, MD-2004, Republic of Moldova
datepersonale.md

We encourage you to contact us first so that we can promptly examine and resolve the matter.

15. Changes to this Policy

We may update this Policy when legal requirements, services or processing activities change. The current version and update date will be published on this page. Material changes may also be communicated by another appropriate method.

This document is intended to provide transparent information under Law No. 195/2024 and should be applied together with the clinic’s documented data-protection procedures.

DrCiobanu

Our dedicated team of dentists is committed to delivering the highest quality care tailored to your needs.

Follow Us

Connect with DrCiobanu on our social media channels and follow us to stay updated with the latest news.

© 2024 DrCiobanu. All rights reserved.

© 2024 DrCiobanu. All rights reserved.