Privacy Policy
Last updated: March 2026
Data Controller
Lana Chaineux
Avenue Hanlet 6A, 4802 Verviers, Belgium
Email: [email protected]
Data Collected
We collect personal data at two levels:
1. The landing website (denturis.be): data submitted through the contact form.
2. The SaaS platform (for subscribed dental practices): data related to account management, patients and activity.
Landing Website Data
The contact form collects: first name, last name, email address, phone number, practice name and message.
This data is sent via email only and is NOT stored in a database.
The IP address is used temporarily for rate limiting (not persisted). Cloudflare Turnstile is used for spam protection.
SaaS Platform Data
For SaaS platform users, the following data is collected:
- User accounts: name, email address, hashed password
- Sessions: IP address, user agent
- Patient messages: name, email, phone, message content, IP address
- Practitioner profiles
- Event and audit logs: event type, IP address, user agent
Data Processors
We use the following data processors. A Data Processing Agreement (DPA) pursuant to GDPR Article 28 is in place with each processor.
- Resend (Resend, Inc., USA): transactional email sending. DPA included in Terms of Service. SOC 2 Type II, ISO 27001 certified.
- Cloudflare (Cloudflare, Inc., USA): CDN, DNS, Turnstile CAPTCHA. DPA included in subscription agreement. SOC 2 Type II, ISO 27001, ISO 27701 certified.
- Railway (Railway, Inc., USA): application and database hosting in EU West region (Amsterdam, Netherlands). SOC 2 Type II, SOC 3 certified.
Legal Basis for Processing
The processing of your data is based on the following legal grounds:
- Consent: contact forms, newsletter
- Contract execution: SaaS subscription, account management
- Legitimate interest: security, fraud prevention, service improvement
Data Retention
- Landing contact form data: not stored (email transmission only)
- User accounts: until account deletion request
- Patient messages: as long as the organization account is active
- Event and audit logs: 12 months
- Sessions: until expiry or revocation
Your Rights
Under the GDPR, you have the following rights:
- Right of access
- Right of rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object
To exercise your rights, contact us at: [email protected]
We will respond within 30 days.
Cookies
Only strictly necessary cookies are used. Cloudflare Turnstile may set security cookies for CAPTCHA verification.
No analytics, advertising, or tracking cookies are used. No cookie consent banner is required as only functional cookies are present.
Data Hosting
All data is hosted in the European Union (Railway EU West — Amsterdam, Netherlands).
International Transfers
All three data processors (Resend, Cloudflare, Railway) are US-based companies. Data transfers are protected by the following mechanisms:
- EU-US Data Privacy Framework: all three processors are certified under the EU-U.S. Data Privacy Framework, recognized by the European Commission as providing adequate data protection.
- Standard Contractual Clauses (SCCs): used as a supplementary safeguard alongside the Data Privacy Framework.
- Data Processing Agreements (DPAs): in place with each processor pursuant to GDPR Article 28.
Application and database data is hosted in the European Union (Railway EU West — Amsterdam, Netherlands).
Complaints
You can file a complaint with the Belgian Data Protection Authority (Autorite de protection des donnees / Gegevensbeschermingsautoriteit).
Address: Rue de la Presse 35, 1000 Brussels
Website: www.autoriteprotectiondonnees.be / www.gegevensbeschermingsautoriteit.be
Policy Changes
This policy may be updated. Users will be notified of significant changes.
Last updated: March 2026.