CrystalDentCrystalDent
ГлавнаяHomeStartHomeУслугиServicesLeistungenServicesКонтактыContactKontaktContact
EN
EN

Legal

Privacy Policy

Last updated: 24 September 2026

1. Controller

CrystalDent, Obkirchergasse 40, 1190 Wien, Österreich

Practice owner: [Praxisinhaber:in — Vor- und Nachname]

Phone: +43 660 3411433 · E-mail: hello@crystaldent.at

2. What we process and why

Appointment request via the website: name, phone number, e-mail address (if given), requested time, service of interest, your message and the chosen language. Purpose: arranging and organising your appointment. Legal basis: Art. 6(1)(b) GDPR (steps prior to a treatment contract). If your message contains health information, we process it under Art. 9(2)(h) GDPR (provision of health care) and your explicit consent (Art. 9(2)(a) GDPR), given when you submit the form.

Abuse protection: when a request is submitted, the IP address and timestamp are kept briefly in the server's memory to block automated mass requests. They are not stored permanently and are discarded within 24 hours. Legal basis: Art. 6(1)(f) GDPR (security of the service).

Phone, e-mail, Instagram: data you share through these channels is used only to answer your enquiry.

3. Recipients and processors

Hosting and database: Railway Corp., San Francisco, USA. The website and the database run in the EU West region (data centre in the Netherlands); your data is stored and processed there. A data processing agreement with standard contractual clauses (Art. 46(2)(c) GDPR) is in place.

Map: the location map uses map data from CARTO (CartoDB Inc., USA) and OpenStreetMap. When the map loads, your IP address is transmitted to CARTO. Legal basis: Art. 6(1)(f) GDPR (directions); transfer based on standard contractual clauses.

Staff notifications: our team is notified of new appointment requests by Telegram message. The message contains only the request number, the requested time and the service — no personal data. Your name, phone number and message remain exclusively in the access-protected staff area.

We use no analytics, tracking or advertising services. Fonts are served from our own server; no Google Fonts are loaded.

4. Cookies and local storage

For patients the website sets no cookies that require consent. Your language choice is kept in your browser's local storage (cd-lang). The staff area uses one strictly necessary session cookie (cd_panel) that concerns staff only. A cookie banner is therefore not required (§ 165(3) TKG 2021).

5. Retention

Appointment requests that do not lead to treatment (cancelled or unconfirmed) are deleted automatically 12 months after the requested date.

Data that becomes part of your treatment records is subject to the statutory 10-year retention period (§ 18 ZÄG) and is kept in the practice's patient file.

On request we delete your enquiry earlier at any time, unless a legal obligation prevents it.

6. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw consent at any time with effect for the future.

Contact hello@crystaldent.at or +43 660 3411433.

Complaints may be lodged with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.

7. Security

Data is transmitted encrypted (TLS). Access to appointment requests is limited to the practice team and protected by an access lock. The request form is protected against automated entries and mass submissions.

Private dentistry for long-term health and confidence.

Obkirchergasse 40, 1190 Vienna+43 660 3411433

© 2026 CrystalDent ClinicImprintPrivacy