All-inclusive hygiene — no hidden fees

No fine print in your back

Your data with us, straight up

The legal wording has to be precise, so we kept it precise — but written so you can read it over coffee. Formally: information pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), Czech Act No. 110/2019 Coll., Act No. 480/2004 Coll. and Section 89 of Act No. 127/2005 Coll. Last updated: 23 July 2026.

TL;DR

  • We collect only what we need to book and treat you.
  • We don't sell anything, we don't feed ad databases.
  • Analytics starts only after your "yes" in the cookie banner — silence until then.
  • Medical records we keep because the law says so.
  • Email info@dentplus.cz anytime and we'll delete, correct or hand your data over.

1. Who's behind all this

The controller is Stomatologické centrum DENTplus s.r.o., Company ID 29140897, registered office at Jankovcova 1595/14, 170 00 Prague 7, Czech Republic (the "clinic", "we" or "controller"). We're not required to appoint a Data Protection Officer, so any data-protection question comes straight to us: info@dentplus.cz or +420773694472.

2. What, why, how long

A table without a table. For each activity we say what we use the data for, what we lean on (Art. 6, or Art. 9 where relevant) and how long we keep it before letting it go.

a) The "Request an appointment" form

When you write to us, we need your name, phone, email and message — otherwise we can't book you. Purpose: arranging an appointment and pre-treatment communication. Legal basis: steps taken prior to entering into a healthcare services contract (Art. 6(1)(b) GDPR). Retention: up to 12 months from your last message if no treatment happens; if it does, the data moves into the medical record (see e).

b) Clicks on our phone number

When you tap our number on the site, we log a dry technical record — timestamp, page and an anonymised browser identifier — in our Lovable Cloud database. No name, no caller ID. Purpose: checking that the website actually pulls its weight. Legal basis: our legitimate interest in evaluating the website (Art. 6(1)(f) GDPR). Retention: 24 months, then rolled up into anonymous stats.

c) PDF guide download (lead magnet)

We take your email, proof of consent, its exact wording and a timestamp. Purpose: deliver the guide and occasionally add a related tip. Legal basis: your consent (Art. 6(1)(a) GDPR and Sec. 7 of Act No. 480/2004 Coll.). Retention: until you pull consent back, at most 3 years from last contact.

d) Booking confirmation emails

After you submit a request, a confirmation lands in your inbox and a copy in ours. Purpose: so both sides know what's on. Legal basis: Art. 6(1)(b) GDPR. Retention: same as the related CRM or medical-record entry.

e) Medical records

Once treatment starts we keep the statutory medical record — a special category of health data that we handle with extra care. Legal basis: compliance with a legal obligation (Art. 6(1)(c) and Art. 9(2)(h) GDPR) in conjunction with Act No. 372/2011 Coll. and Decree No. 98/2012 Coll. Retention: under Annex 3 of the Decree (typically 5–10 years, longer for specific records).

f) Accounting and tax records

The boring but non-negotiable bit. Legal basis: compliance with a legal obligation (Act No. 563/1991 Coll. on Accounting and Act No. 235/2004 Coll. on VAT). Retention: 10 years from the end of the accounting period.

g) Website analytics

Google Analytics 4 via Google Tag Manager (GTM-5TQSXH7P). It only kicks in once you tap "accept" in the cookie banner; until then everything runs in Consent Mode v2 with signals set to "denied". Purpose: seeing which pages make sense and how often the form fires. Legal basis: consent (Art. 6(1)(a) GDPR and Sec. 89(3) of Act No. 127/2005 Coll.). Retention: 14 months in GA4, then aggregated only.

3. Cookies, no filler

Cookies are small files a site leaves on your device. We use three flavours — and we'll happily admit none of them are ad cookies:

  • Strictly necessary. Remember your language, your cookie choice and the app's technical state. The site wouldn't work without them, so we set them under Sec. 89(3), second sentence, of Act No. 127/2005 Coll. — not on consent.
  • Analytics. Google Analytics 4 (_ga, _ga_*) and GTM. Set only after your "yes". Lifetime up to 24 months.
  • Marketing / advertising. Zero. If we ever reach for remarketing, you'll get a separate ask — not a fait accompli.

You can flip your consent anytime — clear site data in your browser or email us at info@dentplus.cz. Anything processed before you withdraw stays lawful; withdrawal only kicks in going forward.

4. Who gets to touch the data

Short list. Everyone here is bound by an Art. 28 GDPR agreement:

  • Lovable, Inc. — website hosting, application database and transactional email delivery (Lovable Cloud). Servers in the EU.
  • Google Ireland Ltd. — analytics (Google Analytics 4, Google Tag Manager). Transfers outside the EU are covered by Standard Contractual Clauses and the EU–US Data Privacy Framework.
  • Our accountants — for tax and bookkeeping.
  • Public authorities (health insurers, ÚZIS, supervisory bodies) to the extent required by law.

We do not sell personal data. We don't hand it over to anyone for their own marketing. Full stop.

5. The trip outside the EU

The only data that leaves the EU is what goes to Google (analytics). It's covered by the Standard Contractual Clauses adopted by the European Commission and by Google LLC's participation in the EU–US Data Privacy Framework. Ask and we'll send a copy of the safeguards.

6. Your rights (and how to pull them)

The law hands you eight levers you can pull as a data subject:

  • right of access (Art. 15 GDPR),
  • rectification of anything that's wrong (Art. 16 GDPR),
  • erasure ("right to be forgotten", Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability to another controller (Art. 20 GDPR),
  • object to legitimate-interest processing (Art. 21 GDPR),
  • withdraw consent anytime — for the lead magnet or cookies, no reason required (Art. 7(3) GDPR),
  • lodge a complaint with the Czech Office for Personal Data Protection, uoou.gov.cz.

Email info@dentplus.cz. We reply within 30 days (in justified cases we can add another two months and will tell you). We may ask for a bit more info to make sure the request really is yours.

7. Do you have to give us the data?

Contact details in the form — yes, otherwise we can't book you. Anything else (lead magnet, analytics) is voluntary and saying no doesn't affect your treatment in any way.

8. Does an algorithm decide about you?

No. No automated decision-making under Art. 22 GDPR and no profiling with legal effects. Analytics is just counting people in aggregate.

9. How we keep it safe

The site is served exclusively over HTTPS. The database uses Row-Level Security, admin access requires multi-factor authentication. Paper in the clinic sits behind a lock, and the key isn't handed out on request.

10. Changes

When we deploy a new tool or the law moves, we update this document. The current version lives right here, with the last-updated date at the top. No quiet rewrites behind your back.

Call