Privacy notice
Last updated: 4 October 2026.
Who is responsible for your information
GOLDEN DANSKE DENT SRL, trading under the Urban-Dent brand and operating Osteon, is the controller of personal data collected through this website. Our CUI is 45049012 and our Trade Register number is J39/1045/2021. See our company details. For privacy questions or requests, email [email protected].
This notice covers website visitors, people contacting Team Osteon and staff using the private portal. Clinical records and information collected directly by a treating professional are subject to the information that provider gives you when arranging care.
Information we collect
- Enquiries: your name, email address, message and the type of request you submit, such as a general enquiry, consultation or membership enquiry. We also record submission dates, request identifiers, processing status and staff status changes.
- Consultation checkout: we keep your name, email, message, preferred contact method and, if you choose WhatsApp, your phone number while checkout is pending. We send Stripe your email, a request identifier and your preferred contact method to create checkout. Stripe collects the payment details and information needed to process and protect the transaction. After successful payment, we receive the payment amount and any promotion code used, save your consultation request and email you the next steps. Our website database does not receive your full card number. Unpaid consultation drafts are removed after seven days.
- Website security: connection information such as IP address, request time, requested resource and browser information may be processed by the server. The forms use protected identifiers derived from email and network addresses to limit repeated submissions and prevent abuse.
- Staff accounts: staff name, email, password hash, account records and sign-in sessions, including IP address, browser information and expiry times.
- Preferences: the light or dark appearance you choose is saved in your browser.
We receive enquiry information directly from you. Your name, email and message are needed to handle a form submission; without them we cannot accept it or reply. A WhatsApp number is needed only if you choose WhatsApp follow-up; otherwise we contact you by email. Please send only what is necessary for your initial question. Do not submit scans, medical records, identity documents or payment card details through these forms. Ask the team how to provide clinical information when it is needed.
Why we use your information
We use consultation and service enquiries, including consultation checkout, to respond and take steps you request before entering into or performing a contract (GDPR Article 6(1)(b)). General correspondence, secure website operation and staff access rely on our legitimate interests in answering questions, managing our services and preventing misuse (Article 6(1)(f)). Where a legal obligation requires processing, including applicable payment records, Article 6(1)(c) applies.
Sending a message does not subscribe you to marketing. We do not sell enquiry data or use it for advertising profiles. The website does not make automated decisions about your treatment or eligibility. Automated security checks may block excessive or suspicious submissions; email us if you cannot use a form.
Who can access your information
Authorised Team Osteon staff access enquiries through a sign-in protected workspace and the team mailbox at [email protected]. Notification emails include your name, email address, request type, submission time and message, with a link to the staff panel. Paid consultation notifications also include your contact preference, WhatsApp number if supplied, payment amount and any referral code. Staff can reply directly to your email address or contact you at the WhatsApp number you chose. Our website, database and mail services run on a Hetzner server in Finland. Hosting and technical support providers may process data as needed to operate and protect those services. Stripe processes consultation checkout and payment information; see Stripe’s privacy information. Email correspondence also passes through the email providers used by the sender and recipient.
Information may be shared with professional advisers or competent authorities where necessary for legal obligations or claims. Arranging clinical care may require information to be provided to a treating professional; the team will explain the recipient and purpose when arranging that step.
The website database is hosted in the European Economic Area. If a service or recipient requires a transfer outside the EEA, that transfer must have an applicable legal safeguard, such as an adequacy decision or standard contractual clauses. You can contact us for information about the safeguards relevant to your data.
How long information is kept
We keep enquiries for handling your request and related follow-up or service arrangements, and where a record remains necessary for an applicable legal obligation or claim. Retention is assessed against those purposes, including whether the matter is resolved and any relevant legal retention or limitation period. Deletion requires an authorised review; closing a request in the staff portal does not automatically delete it. You can ask us to review or erase your enquiry at any time.
Staff sessions expire after eight hours unless renewed during use. Theme preferences remain on your device until you change them, choose the device setting or clear browser storage. Security records are kept as needed to investigate misuse and protect the service. Database backups rotate on an approximately fourteen-day schedule; removed records can remain in protected backups until those copies expire.
Cookies, browser storage and external links
The public site has no advertising trackers. We use first-party, cookieless audience measurement to understand which pages are useful and improve the website. After interaction and at least five seconds on a visible page, it records the public page path, referring domain, broad device category, visible time and whether consultation checkout was opened. The temporary page identifier stays in memory, expires after 30 minutes and does not identify you across pages or visits. Analytics does not store raw IP addresses, full browser identifiers, query strings, form contents or clinical information. A rotating protected network identifier is used only for short-lived abuse limits. Measurement records are removed after 90 days. This service improvement processing relies on our legitimate interests (Article 6(1)(f)). Stripe.js is loaded for consultation checkout and may process browser and device information for payment security and fraud prevention. The appearance control uses local storage named osteon-theme. Staff sign-in uses essential authentication cookies; blocking these prevents access to the staff portal. Fonts and gallery images are served by this website. Following a link to another website, such as Urban-Dent, brings you under that website’s privacy notice.
We respect Do Not Track and Global Privacy Control. You can also turn off website measurement below. This choice is saved on this browser in local storage named osteon-analytics-disabled; no analytics identifier is saved there. Changing browser or clearing storage resets the choice. Turning measurement off also removes the currently measured page visit when possible.
Your choices and rights
Subject to the applicable conditions, you can request access, correction, erasure, restriction or portability, and object to processing based on legitimate interests. Where consent is used, it can be withdrawn without affecting earlier lawful processing. Email [email protected]. We may need proportionate identity verification and normally respond within one month; if a permitted extension is needed, we will explain it within that month.
You can complain to Romania’s National Supervisory Authority for Personal Data Processing (ANSPDCP), or the competent authority where you live, work or believe an infringement occurred.
Updates to this notice
We update this page when the website’s data practices change. The date above identifies the latest version. Contact us if you need clarification about how this notice applies to your enquiry.