Privacy policy
Version: 2026-08-18
Preliminary version: the operator's registration data has not been filled in yet and this text has not received legal review.
01Who processes your data
The data controller is SMILE DISTRICT SRL, tax ID (CUI) 40516451, trade registry J03/376/2019, EUID ROONRC.J3/376/2019, registered office at TODO strada, nr., Sibiu, județul Sibiu. For any data question contact cristina.c.dumitrascu@gmail.com.
02What we collect
When you send an SOS request, we collect:
- identity and contact data: name, age, phone number, email address, the address where the medic is needed;
- health data: the tooth you pointed at and your own description of the problem. Under art. 9 GDPR this is a special category, processed only with your explicit consent;
- approximate location, only if you choose to attach it;
- preferred language and the time of the request;
- for abuse prevention: a cryptographic identifier derived from your IP address and phone number (the anti-abuse counters never store the raw IP);
- aggregate statistics about progression through the SOS form (daily counts of opens and completed steps), with no personal identifier.
Until you accept the statistics, the site loads no third-party service and writes nothing to your browser beyond your own choice from the banner. If you accept, Google Tag Manager loads as well, and measures the same things through it: pages opened, not people. We use no advertising or remarketing cookies. Clause 09 describes everything that happens after an Accept.
03Why, and on what legal basis
- to forward your request to dentists and schedule the intervention: performance of the contract between you and us (art. 6(1)(b) GDPR);
- for health data: your explicit consent, given via the checkbox at submission (art. 9(2)(a) GDPR). You can withdraw it at any time, without affecting processing already performed;
- to limit abuse and protect the medics from fake requests: our legitimate interest (art. 6(1)(f) GDPR);
- legal obligations, where applicable.
04Who receives the data
The request data (name, age, phone, email, address, the description of the problem, location if present) goes exclusively to the dentist who accepts your case, so they can contact and treat you. The dentists are independent professionals bound by professional secrecy.
The technical infrastructure is provided by Google Cloud (Firebase) as a processor, with data stored in the europe-west1 region (Belgium, European Union).
If you accept the statistics described in clause 09, the technical details of the visit also reach Google, through Google Tag Manager. The data from your SOS request is not sent there.
We do not sell your data and do not use it for marketing.
05How long we keep it
- case data: 12 months after the case closes, then deleted or anonymized;
- anti-abuse counters: at most a few days, then they expire automatically;
- technical server logs: at most 30 days.
06Your rights
You have the right of access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent. Write to cristina.c.dumitrascu@gmail.com from or referencing the phone number used in the request; we reply within 30 days.
If you believe the processing breaks the law, you can complain to the Romanian supervisory authority (ANSPDCP): dataprotection.ro.
07How to request deletion
Email cristina.c.dumitrascu@gmail.com with the phone number used in the request. We delete or anonymize your case data, except what the law requires us to keep.
08Security and automated decisions
Case data is not publicly readable; access is restricted by server-side rules, and until direct contact the patient sees only the medic's first name and a partially masked number.
Requests are routed to medics automatically, but no decision with legal or similarly significant effect is made solely by automation: accepting a case is always a medic's decision.
09Site usage statistics
PENDING LEGAL REVIEW. A new clause, added together with our own traffic measurement, not yet checked by a lawyer. To verify: the field list below against the code that collects it, the 90 day period, the legal references, and, as of 18 August 2026, the paragraph on Google Tag Manager, the transfer outside the EU and the consent signals sent to Google.
We measure how much the site is used with our own system, hosted on the same infrastructure as the rest of the application.
If you accept, we additionally load Google Tag Manager, provided by Google Ireland Limited, which is how we administer our measurement tags. It loads only after your acceptance: until then your browser makes no request to Google for this service. Once loaded, it receives the technical details of the visit, that is the page opened, the page you came from, the browser, the device and the IP address. Through Consent Mode we also tell it that you allowed statistics only: advertising and remarketing tags stay blocked. Google may process this data outside the European Union as well, under the European Commission's standard contractual clauses.
Pages whose address contains an identifier, meaning your case status page and the confirmation link sent to the medic, are handled separately: our own system replaces the identifier with a generic marker before recording anything, and Google Tag Manager does not start on them at all. Nothing you wrote in the SOS form, not your name, phone number or description of the problem, reaches Google.
If you accept, we record for each visit: the page opened, the page you came from, the language and device type, the time of the visit, and a randomly generated session identifier. The identifier lasts only for the visit, is not linked to your name or phone number, and is not used to recognize you later. We build no profiles.
The legal basis is your consent (art. 6(1)(a) GDPR), and storing information in your browser also rests on the consent required by electronic communications law (Legea nr. 506/2004). Until you tap Accept, nothing is collected or stored for statistics. In the banner shown on your first visit, Accept and Refuse are the same size and equally visible, nothing is preselected, and closing the banner without choosing counts as a refusal.
Raw events are kept for 90 days from the time they are recorded, then deleted automatically. What remains after that is aggregate totals only, from which no person can be identified.
You can withdraw consent at any time, as easily as you gave it: press the button below and choose Refuse. From that moment we collect nothing. Your choice is held locally in your browser under the key ud_consent: if you clear the site data, you return to the state of not having chosen, and statistics stay off until you choose again.
10Changes
The current version of this policy is identified by the date above. Changes are published on this page, and your consent is recorded together with the version in force at the time of your request.