PRIVACY POLICY
1. Introduction
Welcome to the Odonta360 platform.
Bolutions LTD, company number 16576182, 71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UNITED KINGDOM, E-mail: office@odonta360.com
the provider of the Odonta360 platform available at odonta360.com (hereinafter: “Bolutions”, the “Operator”, “we” or “our”) is committed to protecting the privacy and security of the personal data of all users of the Platform.
This Privacy Policy explains:
- what data we collect;
- why we collect it;
- how we use it;
- how long we retain it;
- with whom we may share it;
- what rights you have in relation to your data.
When processing data we apply the principles of lawfulness, fairness, transparency, data minimisation, purpose limitation, accuracy, storage limitation, integrity and confidentiality, in accordance with the applicable personal data protection regulations.
2. Who is the data controller
The controller of the personal data processed under this Privacy Policy is:
- Bolutions LTD, company number 16576182, 71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UNITED KINGDOM, E-mail: office@odonta360.com
Should Bolutions LTD appoint a Data Protection Officer (DPO), their contact details will be published on the Platform's website.
3. To whom this Privacy Policy applies
This Privacy Policy applies to the processing of the personal data of:
- registered users of the Platform;
- administrators of dental practices;
- employees and associates of practices who have been granted access to the Platform;
- prospective customers who get in touch with Bolutions;
- visitors to the Odonta360 website.
4. Patient data
IMPORTANT NOTE
This Privacy Policy does not govern the processing of patients' medical records by dental practices.
Patient data processed through the Platform (including medical records, photographs, panoramic radiographs, treatment plans and other health data) is processed by the dental practice as the data controller, while Bolutions acts solely as a data processor, processing the data on behalf of and on the instructions of the practice.
Bolutions:
- does not determine the purposes of processing patient data;
- does not decide which data the practice will collect;
- does not determine the retention periods for medical records;
- does not make medical decisions;
- does not use patient data for its own marketing or other commercial purposes.
The dental practice, as the data controller, is responsible for the lawfulness of the processing of patient data, for fulfilling the obligation to inform patients, for determining the legal basis for processing and for giving effect to patients' rights.
The same applies to messages received by a practice through the chatbot on its website or through connected accounts on messaging services (WhatsApp, Instagram, Messenger). The controller of that data is the practice, and Bolutions processes it solely on the practice's instructions, for the purpose of receiving, displaying and storing communications within the Platform.
5. What data we collect
In order to enable use of the Platform, we may process the following data about users:
Identification data
- first name;
- surname;
- name of the practice;
- job title;
- user role.
Contact details
- e-mail;
- telephone number;
- business address.
User account data
- username;
- encrypted password;
- date of registration;
- account status;
- user permissions.
Technical data
- IP address;
- device identifier;
- browser type;
- operating system;
- time of access;
- system logs;
- audit log records.
Communications
- the content of communications with customer support;
- reports of technical issues;
- support requests;
- other communications voluntarily provided to Bolutions by the user.
6. Data we do not collect
As a rule, Bolutions does not collect or process:
- users' payment card details;
- PIN numbers;
- CVV/CVC codes;
- data from identity cards or passports;
- biometric data, unless a particular Platform functionality requires it and there is an appropriate legal basis for such processing.
The Platform does not collect, process or store the unique citizen identification number (JMBG).
7. Purposes of processing personal data
Bolutions processes personal data solely to the extent necessary to pursue legitimate business and contractual purposes, or to comply with legal obligations.
Personal data may be processed in particular for the following purposes:
- registering and administering user accounts;
- enabling the use of Platform functionalities;
- authenticating users and controlling access to the Platform;
- providing technical support to users;
- maintaining, improving and developing the Platform;
- detecting, preventing and resolving security incidents;
- keeping records of the operation of the information system;
- complying with legal obligations to which Bolutions is subject;
- protecting the rights, property and safety of Bolutions, of Platform users and of third parties;
- responding to users' enquiries, requests and communications;
- establishing or defending legal claims.
Bolutions will not use personal data for purposes incompatible with this Privacy Policy, unless there is an appropriate legal basis for such processing under the applicable regulations.
8. Legal basis for processing
Bolutions processes personal data only where there is an appropriate legal basis for such processing under the applicable personal data protection regulations.
Depending on the specific circumstances, processing may be based on one or more of the following legal bases:
Performance of a contract
Where processing is necessary for the conclusion or performance of a contract entered into with a user or a dental practice, in accordance with Article 12 of the Personal Data Protection Act of the Republic of Serbia (“Official Gazette of the RS”, No. 87/2018) and Article 6 of the GDPR.
Compliance with legal obligations
Where processing is necessary for compliance with obligations arising from the applicable regulations, in accordance with Article 12 of the Personal Data Protection Act of the Republic of Serbia (“Official Gazette of the RS”, No. 87/2018) and Article 6 of the GDPR.
Legitimate interest
Where processing is necessary for the purposes of the legitimate interests pursued by Bolutions, provided that such interests are not overridden by the rights and freedoms of the data subject, in accordance with Article 12, paragraph 1, item 6 of the Personal Data Protection Act of the Republic of Serbia (“Official Gazette of the RS”, No. 87/2018) and Article 6(1)(f) of the GDPR.
Legitimate interest may include in particular:
- protecting the information system;
- preventing misuse;
- improving the security of the Platform;
- maintaining audit log records;
- protection against fraud;
- protecting the legal interests of Bolutions.
Consent
Where processing is based on consent, the data subject has the right to withdraw that consent at any time, whereby the withdrawal does not affect the lawfulness of processing carried out before the withdrawal, in accordance with Article 15 of the Personal Data Protection Act of the Republic of Serbia (“Official Gazette of the RS”, No. 87/2018) and Article 7 of the GDPR.
9. How data is collected
Bolutions collects personal data in various ways, depending on the type of service and the manner in which the Platform is used.
Data may be collected:
- directly from the user when registering a user account;
- in the course of using Platform functionalities;
- through communications with customer support;
- automatically, through the information and security systems of the Platform;
- from the dental practice that creates or administers the user account of an employee or associate.
Bolutions will not collect more data than is necessary to achieve the purpose for which the data is processed.
10. Data retention period
Bolutions retains personal data only for as long as is necessary to achieve the purpose for which it was collected, or for as long as the applicable regulations require. In determining retention periods, the principle of storage limitation laid down in Article 5 of the GDPR and Article 5 of the Personal Data Protection Act (“Official Gazette of the RS”, No. 87/2018) is applied.
The retention period depends on the type of data and the purpose of its processing.
Upon expiry of the applicable retention period, the data will be:
- permanently deleted;
- anonymised; or
- archived where there is a legal obligation to do so.
Data contained in backups is deleted or anonymised in accordance with internal backup management procedures and the business continuity plan.
Patient data is retained in accordance with the instructions of the dental practice as the data controller, unless the applicable regulations provide otherwise.
The dental record is retained permanently, in accordance with Article 39 of the Act on Health Records and Registries in the Field of Healthcare (“Official Gazette of the RS”, No. 92/2023). A request for erasure cannot extend to data contained in the dental record and in other prescribed medical records which are subject to a statutory retention obligation.
11. Recipients of data
Bolutions will not sell or rent personal data to third parties.
Data may be made available solely to:
- employees of Bolutions who need the data in order to perform their duties;
- authorised providers of IT infrastructure and cloud services;
- providers of technical maintenance and development services for the Platform;
- other subprocessors engaged in accordance with the applicable regulations and the agreements concluded;
- competent state authorities where the disclosure of data is prescribed by law or is based on a binding decision of a competent authority.
All persons who have access to personal data are obliged to process it applying appropriate technical and organisational security measures, and in accordance with their duty of confidentiality.
12. Subprocessors
For the purpose of providing and maintaining the Platform, Bolutions may engage third parties that process personal data on its behalf (hereinafter: subprocessors).
Subprocessors may provide services that include:
- cloud infrastructure;
- hosting;
- data backups;
- maintenance of information systems;
- development and improvement of the Platform;
- security monitoring;
- technical support;
- electronic communications services.
Bolutions engages only subprocessors that provide sufficient guarantees that they will implement appropriate technical and organisational measures for the protection of personal data, in accordance with the applicable regulations.
An appropriate agreement is concluded with every subprocessor, governing the processing of personal data and ensuring a level of protection no lower than that which Bolutions applies towards its own customers.
An up-to-date list of subprocessors, stating the type of service and the country of processing, is published on the Platform's website. Users are notified of any intended change to that list at least 30 days in advance, with a right to object in accordance with the Personal Data Processing Agreement (DPA).
13. Data transfers
Bolutions processes and stores personal data primarily on servers located within the territory of the European Union or the European Economic Area. International transfers of data are carried out in accordance with Articles 63 to 65 of the Personal Data Protection Act (“Official Gazette of the RS”, No. 87/2018), that is, Articles 44 to 49 of the GDPR.
Certain subprocessors of the Operator, as well as the parent companies of certain cloud infrastructure providers, are established in third countries, primarily in the United States of America. For that reason, transfers of data to, or access to data from, a third country may occur regularly, as part of providing the contracted service, and not only exceptionally.
Every such transfer is carried out solely subject to the appropriate safeguards provided for by the applicable regulations.
Such measures may include in particular:
- a decision of the competent authority on an adequate level of protection;
- Standard Contractual Clauses (SCC);
- other appropriate mechanisms provided for by the applicable regulations.
14. Technical and organisational security measures
Bolutions implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Depending on the nature of the processing and on technological developments, the measures implemented may include in particular:
- user authentication;
- control of access to data;
- management of user permissions;
- encryption of data in transit, where applicable;
- protection of the server infrastructure;
- protection against malicious software;
- firewalls and other network security mechanisms;
- audit log records;
- data backups;
- a business continuity and incident recovery plan;
- regular updating of information systems;
- restricting access to data to authorised persons only;
- training of employees in personal data protection and information security.
Bolutions regularly reviews and improves the security measures implemented, in line with technological developments, changes in security risks and the applicable regulations.
15. Personal data breach
In the event of a personal data breach that may present a risk to the rights and freedoms of natural persons, Bolutions will act in accordance with Articles 50, 52 and 53 of the Personal Data Protection Act (“Official Gazette of the RS”, No. 87/2018), that is, Articles 32, 33 and 34 of the GDPR where applicable, and will take appropriate technical and organisational measures in order to:
- establish the cause of the incident;
- limit its consequences;
- remedy the security weaknesses;
- prevent similar incidents from recurring.
Where Bolutions acts as a data processor, it will notify the dental practice, as the data controller, without undue delay of any personal data breach of which it becomes aware, so that the controller can fulfil its statutory obligations towards the competent authorities and the data subjects.
16. Rights of data subjects
The rights of data subjects are exercised in accordance with Articles 26 to 40 of the Personal Data Protection Act (“Official Gazette of the RS”, No. 87/2018), that is, Articles 15 to 22 of the GDPR.
A person whose personal data is processed has the right, in accordance with the applicable regulations, to:
- request access to their personal data;
- request the rectification of inaccurate data or the completion of incomplete data;
- request the erasure of data, where the statutory conditions for this are met;
- request the restriction of processing;
- object to the processing of data where the regulations so provide;
- exercise the right to data portability, where the statutory conditions for this are met;
- withdraw previously given consent, where the processing is based on consent;
- lodge a complaint with the competent personal data protection authority.
Where Bolutions processes patient data solely in the capacity of a processor, requests relating to the exercise of rights in respect of that data should primarily be addressed by the individual to the dental practice as the data controller.
Bolutions will, within the scope of its statutory and contractual obligations, provide reasonable assistance to the dental practice in order to enable data subjects to exercise their rights.
17. Cookies
The Odonta360 website and Platform may use cookies and other similar technologies in order to ensure the proper functioning of the system, improve the user experience, analyse use of the Platform and protect the security of the information system.
Cookies may include in particular:
- essential cookies that enable the basic functioning of the Platform;
- functional cookies that make it possible to remember user settings;
- analytical cookies that enable anonymous analysis of the use of the Platform, where used;
- security cookies that serve to protect user accounts and prevent misuse.
Users may manage their cookie settings at any time through their browser, whereby disabling certain cookies may affect the functionality of the Platform.
Where Bolutions uses cookies for which the prior consent of the user is required under the applicable regulations, such consent will be obtained before they are placed.
18. Links to third-party websites
The Platform may contain links to third-party websites or services.
Bolutions has no control over the content, operation or privacy policies of those websites and is not responsible for their processing of personal data.
Users are advised to read the privacy policies and other relevant terms of use of third parties before using their services.
19. Exercising your rights and contact
If a data subject wishes to exercise any of their rights, or has questions concerning this Privacy Policy or the processing of personal data, they may contact Bolutions using the following contact details:
Bolutions LTD
Address: 71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UNITED KINGDOM
E-mail: office@odonta360.com
Telephone: +381 61 7243379
Bolutions will respond to requests submitted within the time limits and in the manner prescribed by the applicable personal data protection regulations.
Where a request relates to patient data that Bolutions processes solely in the capacity of a data processor, Bolutions may forward the request to the dental practice concerned or direct the applicant to contact the practice as the data controller, while providing appropriate assistance within the scope of its statutory and contractual obligations.
20. Changes to the Privacy Policy
Bolutions reserves the right to amend or supplement this Privacy Policy in order to:
- align it with changes in the applicable regulations;
- improve the Platform;
- introduce new functionalities;
- reflect changes in the manner in which personal data is processed;
- address other justified business reasons.
Every amendment will be published on the Platform's website or otherwise made available to users in an appropriate manner.
The amended Privacy Policy will apply from the date of its publication, unless otherwise indicated.
In the event of significant changes affecting the manner in which personal data is processed, Bolutions will, where necessary or required by law, notify users separately.
21. Final provisions
This Privacy Policy applies from the date of its publication on the Platform's website, or from such other date as is expressly specified in it.
Should individual provisions of this Privacy Policy become null, invalid or unenforceable, this will not affect the validity of the remaining provisions.
Matters not governed by this Privacy Policy are subject to the provisions of the applicable personal data protection regulations, as well as other applicable regulations.