Privacy Policy - Impress Group
1) Who is responsible?
The main data controller is SMILE2IMPRESS S.L., together with the entities of the Impress Group (hereinafter, Impress Group) involved in providing the service in each country, which may act as joint controllers where appropriate, in accordance with Article 26 of the GDPR, with which you contract or interact (e.g. as a patient/user, healthcare professional, partner, supplier, candidate or website visitor).
Privacy contact: gdpr@smile2impress.com
Data Protection Officer (DPO): dpo@smile2impress.com
The Group's entities are listed in ANNEX II.
2) What data do we process?
A. Clinical data (health data – special category):
X-rays, 3D scans, clinical photographs, diagnosis, treatment plan, progress, and clinical communications.
B. Commercial and account data:
identification and contact details, appointments, preferences, incidents, support communications.
C. Financial data:
billing, payments, financing (financial institutions usually act as independent controllers).
D. Technical data:
IP, logs, device, browsing and cookies (depending on your choice).
3) What do we use your data for?
- To provide dental care and follow-up.
- To plan and manufacture devices (aligners and associated elements) with laboratories and technical suppliers.
- To manage appointments, support and service quality.
- Billing and collections, including financing if requested.
- Security and fraud prevention.
- Legal compliance (health, tax, etc.).
- Marketing (only according to clear rules below).
4) Marketing
- Customers/patients: we may send information about similar services (soft opt-in in accordance with applicable commercial communications regulations). Always with easy unsubscribe option.
- Non-customers: only with express consent.
- Personalised advertising: only if you accept advertising cookies or enable "personalised ads" in the app/settings.
5) Do we use Artificial Intelligence (AI)?
We may use AI as a support tool (e.g. to organise support or help plan/visualise treatments).
It never replaces clinical decision-making: there is human intervention and validation by healthcare professionals.
6) Who do we share data with?
Only when necessary:
- Partner clinics/healthcare professionals
- Laboratories and technical manufacturing suppliers
- Technology providers (hosting, CRM, communications)
- Payment gateways
- Financial institutions (if you request financing)
- Authorities, when legally applicable
We never sell personal data.
7) International transfers
If any supplier is outside the EEA, we use legal safeguards (e.g. Standard Contractual Clauses or adequacy decisions) and, where necessary, additional technical and organisational measures to ensure a level of protection equivalent to that in Europe.
8) Your rights
Access, rectification, erasure, objection, restriction, portability, withdrawal of consent and objection to marketing/profiling.
Exercise: gdpr@smile2impress.com
You can lodge a complaint with the supervisory authority in the country where you usually reside (in Spain, the AEPD).
FULL POLICY (LEGAL DEVELOPMENT)
1. SCOPE AND COMMITMENT
This Policy explains how we process the personal data of:
- Users/Patients
- Healthcare professionals
- Partners (collaborating clinics), Suppliers and Consultants
- Investors
- Candidates
- Potential customers
- Website visitors
We undertake to process data lawfully, fairly, transparently, minimally and securely, in accordance with the GDPR and applicable local regulations.
2. DATA CONTROLLER, CONTACT AND DPO
2.1 Data controller
The controller is the Impress Group entity with which you have a relationship. As a corporate reference in Spain:
SMILE2IMPRESS S.L.
Tax ID: B67402032
Address: Av. Roma 81, 2º Núcleo E-F, 08029 Barcelona (Spain)
Email: gdpr@smile2impress.com
2.2 Data Protection Officer (DPO)
Email: dpo@smile2impress.com
2.3 Group Entities
See ANNEX II.
3. CATEGORIES OF DATA WE PROCESS (CLINICAL VS COMMERCIAL)
3.1 Clinical data (health data – Art. 9 GDPR)
- X-rays, 3D scans, clinical photos
- Diagnoses and clinical notes
- Treatment planning, progress and check-ups
- Information provided during consultations or on the patient portal
- Clinical communications (where applicable)
3.2 Commercial and account data
- Registration, identity, contact details
- Appointments and schedule management
- Service preferences, incidents and complaints
- Support communications (email, chat, telephone)
3.3 Financial data
- Billing and payments
- Data required for payments
- Financing (if requested)
3.4 Technical data
- IP, security logs
- Device, browser, cookies (as selected)
3.5 Data from third parties
We may receive data if you authorise it (e.g. social login) or if you interact with us via social media/messaging.
4. SOURCE OF DATA
Data may come from:
- You (forms, app, clinic, calls, chats)
- Your activity on the app/patient portal
- Suppliers necessary to provide the service (e.g., payment gateway)
- Third parties authorised by you (e.g., social login)
5. PURPOSES AND LEGAL BASES (SINGLE MATRIX)
Key note: Health data is generally processed for healthcare purposes (Art. 9.2.h GDPR) and/or compliance with healthcare obligations, with access restricted to authorised personnel.
5.1 Users/Patients. Main purposes:
a) Provision of dental services (diagnosis, planning, follow-up)
- Legal basis: performance of a contract + Art. 9.2.h GDPR + healthcare obligations.
b) Manufacture and logistics of the device (aligners and associated elements)
- Legal basis: performance of a contract + Art. 9.2.h GDPR (as necessary) + product/device obligations.
- Clarification of roles (important and "competitor-grade"):
- Responsible for medical records: the Group's healthcare entity providing the treatment and/or the clinic performing it (as applicable).
- Manufacturer/laboratory: processes the data strictly necessary for the manufacture and control of the product. Depending on the flow, it may act as a processor or as an independent controller for its own regulated activity; in any case, there is a contract and guarantees of confidentiality and security.
c) Administrative management (appointments, customer service, incidents, quality)
- Legal basis: performance of a contract + legitimate interest (quality and improvement) where applicable.
d) Billing, collections and accounting
- Legal basis: performance of contract + legal obligation.
e) Financing (if you request it)
- Legal basis: performance of contract / pre-contractual measures at the request of the data subject.
- Financial institutions/brokers usually act as independent controllers for creditworthiness analysis and formalisation.
f) Security and fraud prevention
- Legal basis: legitimate interest (security and protection of the platform, fraud prevention, account security).
g) Research, statistics and improvement (preferably with anonymised or aggregated data)
- Legal basis: legitimate interest and/or legal obligation/clinical standards, as applicable.
- Wherever possible, we will use anonymisation or pseudonymisation.
5.2 Marketing (fair rules)
a) Soft opt-in (customers/patients only):
We may send communications about services similar to those contracted.
- Legal basis: legitimate interest / applicable regulations on commercial communications - LSSI in Spain.
- Right to object: unsubscribe in each communication and/or by email.
b) Non-customers (leads):
Only marketing with express consent.
c) Personalised advertising/audiences:
Only if:
- you accept advertising cookies, or
- you activate the corresponding option in settings ("personalised ads"), or
- you give equivalent express consent.
d) Partners (transfer to third parties for marketing):
Only with express, informed and unambiguous consent, identifying the recipient/categories.
6. RECIPIENTS (WHO RECEIVES THE DATA AND WHY)
We may share data only when necessary, with the following categories:
- Partner clinics and healthcare professionals
For diagnosis, imaging, check-ups, clinical support and treatment. - Dental laboratories and technical suppliers
For scanning, designing and manufacturing aligners or other medical devices, and associated logistics. - Technology providers
Hosting, secure storage, CRM, communications, security (e.g., reCAPTCHA), analytics (based on cookies). - Payment platforms
For processing payments (we do not store complete card details; tokenisation where applicable). - Financial institutions/brokers (if you request financing)
For assessment, formalisation and management of payment in instalments (usually as independent controllers). - Insurers
When necessary for the management of incidents or associated claims. - Public authorities
When necessary for legal compliance (health, tax, judicial).
We never sell personal data.
7. INTERNATIONAL TRANSFERS
If we transfer data outside the EEA (e.g. certain support/call centre services, telecommunications or technology providers), we will do so by applying:
- European Commission Standard Contractual Clauses and supplementary measures, and/or
- adequacy decisions, where applicable.
You can request additional information about the safeguards applied by writing to gdpr@smile2impress.com.
8. AUTOMATED DECISIONS AND PROFILING
8.1 Automated decisions (Art. 22 GDPR)
We do not make decisions that produce legal effects or significantly affect you based solely on automated processing in the clinical field.
8.2 Profiling/segmentation
We may perform non-clinical segmentation to:
- personalise your experience,
- display relevant content,
- improve service,
- limit fraud,
- or personalise marketing (only where applicable).
You may object to profiling with relevant effects and, in any case, always object to direct marketing.
9. ARTIFICIAL INTELLIGENCE (AI) — A MODERN AND TRANSPARENT APPROACH
We may use AI in processes such as:
- Customer service (e.g., chatbots assisted by linguistic models) to resolve administrative or support queries.
- Support for treatment planning and visualisation through analysis of clinical images/photos (where applicable).
AI security and control principles
- Human intervention: all relevant clinical decisions are validated by healthcare professionals.
- Minimisation: we use the minimum amount of data necessary for the purpose.
- We do not train public models with your data: we contractually require suppliers not to use the data to train public models.
- Protection of identifying data: we implement measures to prevent unnecessary exposure and reinforce confidentiality.
10. SECURITY MEASURES
We apply technical and organisational measures appropriate to the risk, including:
- role-based access control and need-to-know,
- encryption in transit and, where appropriate, at rest,
- security logs and monitoring,
- supplier assessment and GDPR contracts,
- payment tokenisation and PCI DSS standards for payment providers,
- measures to prevent unauthorised access, alteration or loss.
11. DATA RETENTION
We retain data for:
- the time necessary for the purpose,
- the contractual relationship and,
- subsequently, the legal retention and limitation periods.
The indicative periods and legal references are in ANNEX I.
Where appropriate, we may retain certain information for up to 15 years if it is necessary for the defence against complex claims or criminal/tax limitation periods, always subject to minimisation and restricted access.
12. INDIVIDUAL RIGHTS
You may exercise:
- Access
- Rectification
- Deletion
- Object
- Restriction
- Portability
- Withdrawal of consent (where applicable)
- Objection to direct marketing and profiling
How to exercise these rights: gdpr@smile2impress.com
You can also contact the DPO: dpo@smile2impress.com
If you consider that we have not correctly responded to your request, you may lodge a complaint with the supervisory authority in the country where you normally reside (in Spain, the AEPD).
13. MINORS
The services are intended for adults, unless the applicable regulations allow processing with legal authorisation/representation and this is verified.
14. SOCIAL NETWORKS AND MESSAGING CHANNELS
If you contact us via social media (e.g. Instagram, Facebook) or messaging (e.g. WhatsApp), we will process the data necessary to:
- respond to queries,
- provide patient/customer support,
- incident management.
The processing may also be subject to the privacy policy of each platform.
15. VIDEO SURVEILLANCE AND ACCESS CONTROL (if applicable in centres)
In centres and clinics, video surveillance may be in place on the basis of legitimate interest in the safety of persons and facilities, in accordance with applicable regulations and informative signage.
16. ETHICS CHANNEL
The Ethics Channel allows for the reporting of conduct or regulatory/ethical breaches.
The data processed will be used to:
- process communications,
- investigate incidents,
- propose resolutions,
- and, where appropriate, notify authorities or take internal measures.
Measures are taken to protect the confidentiality of the identity of the whistleblower and the persons concerned, with restricted access.
Contact: compliance@smile2impress.com (or as indicated in the designated channel)
17. SOCIAL INITIATIVES / APP FUNCTIONALITIES (if applicable)
If the app allows social features (e.g., "add contacts"):
- your address book will only be accessed if you explicitly authorise it,
- it will show which contacts are already users,
- and you control who you add and what you share (aggregate or identifying information).
18. CHANGES TO THIS POLICY
We may update this Policy when necessary.
If there are substantial changes, we will notify you in an appropriate manner.
19. LANGUAGE AND PREVALENCE
In the event of any discrepancy between translations, the English version shall prevail.
This Privacy Policy is also for Kjeld Aamodt DDS MS IL PC, Kjeld Aamodt DDS MS PC NY, Kjeld Aamodt PC and Kjeld Aamodt DDS MS PC (the 'Practice'), professional corporations licensed to practice dentistry. The Practice is supported by its parent company and administrative affiliate, CVSTOM Co dbA IMPRESS (the 'DSO'), which provides non-clinical management and administrative services. Both professional and DSO as the Data Controller and owner of this website, and is intended for users of IMPRESS products and services, patients, suppliers, website visitors and anyone interested in contacting IMPRESS.
The processing of personal data relating to health information is carried out in accordance with the Health Insurance Portability and Accountability Act (HIPAA) and other applicable U.S. laws governing healthcare privacy and medical record retention.
The data subject acknowledges that they have been provided access to the applicable Notice of Privacy Practices (NPP), as required under U.S. law, which describes the permitted uses and disclosures of health information, as well as their rights in relation to such information.
All personal data will be processed and safeguarded in compliance with both applicable European regulations, including the General Data Protection Regulation (GDPR), and relevant United States healthcare privacy laws, as applicable.
APPENDIX I — GENERAL RETENTION PERIODS (GUIDELINES)
Retention periods may vary depending on the country, the type of relationship (patient, professional, supplier, etc.) and the specific purpose. We will only retain data for as long as necessary and will apply blocking/limitation where appropriate.
|
Category |
Approximate timeframe |
Purpose |
Legal reference (indicative) |
|
Data protection (breaches) |
1–3 years |
Limitation period for infringements |
LOPDGDD (Spain) |
|
Civil personal actions |
5 years |
Contractual claims |
Art. 1964.2 Civil Code (Spain) |
|
Commercial documentation |
6 years |
Commercial obligations |
Commercial Code (Spain) |
|
Tax documentation |
4 years (min.) |
Tax obligations |
General Tax Law (Spain) |
|
Information relevant to complex criminal proceedings |
10–15 years (max.) |
Defence/prosecution in criminal proceedings |
Art. 131 Criminal Code (Spain) |
|
Candidates (not hired) |
2 years |
Future vacancies |
Good HR practices |
|
Blog comments |
While the article is published |
Site management |
Legitimate interest |
ANNEX II — IMPRESS GROUP COMPANIES
|
Country |
Company |
Tax ID / Identifier |
Registered office |
|
Italy |
Smile2impress S.R.L |
12266090963 |
Via Benedetto Marcello 91, 20124 Milano |
|
Italy |
DS Italia Limited |
11865840968 |
Via Messina 38, 20154 Milano |
|
Portugal |
Smile2impress LDA |
516423614 |
Rua Camilo Castelo Branco Nºs 44 e 44-A, 1050-045 Lisboa |
|
Spain |
Smile2impress S.L. |
B67402032 |
Av. Roma 81, 2º Núcleo E-F, 08029 Barcelona |
|
Spain |
DS Iberia S.L. |
B88481924 |
Av. Roma 81, 2º Núcleo E-F, 08029 Barcelona |
|
United Kingdom |
Smile2impress LTD |
12957895 |
54 Brushfield Street, London, E1 6AG |
|
United Kingdom |
Smile2impress Clinics LTD |
13682612 |
54 Brushfield Street, London, E1 6AG |
|
Switzerland |
Smile2impress, SARL |
UID CHE-365.532.137 |
Rue Jacques-Balmat 5, c/o BianchiSchwald Sàrl, 1204 Genève |
|
France |
Smile2impress S.à.r.l. |
FR14892663485 RCS |
36 Avenue Hoche, 75008 Paris |
|
France |
DS France SAS |
980742530 |
28 Boulevard de la Corderie, 13007 Marseille |
|
Ukraine |
Smile2impress LLC |
44629915 |
Distrito Khmelnytsky, Teofipol, Svobody 27A, apt. 18 |
|
United States |
Cvstom Co |
81-1540779 |
605 Market Street, Suite 1200, San Francisco, California, 94105 |
|
Sweden |
DS Sverige |
559314-8454 |
Nybrogatan 16, 114 39 Stockholm |
|
Netherlands |
DS Benelux BV |
BSN 86141562 |
Nassauplein 30, 2585EC 's-Gravenhage |
|
Netherlands |
PlusDental Netherlands BV |
BSN 82375941 |
Barbara Strozzilaan 101, 1083 HN Amsterdam |
|
Germany |
DZK Deutsche Zahnklinik GmbH |
HRB 191540 B |
Adlerstraße 72-74, 40211 Düsseldorf |
|
Germany |
Urban Technology GmbH |
Company Register No. 186974 B |
Rankestraße 8, 10789 Berlin |
ANNEX III — DEFINITIONS (SHORT)
- Data controller: decides on the purposes and means of processing.
- Processor: processes data on behalf of the controller and under their instructions.
- GDPR: Regulation (EU) 2016/679.
- Health data: data relating to physical or mental health, including dental clinical data and images.
- Profiling: automated processing to evaluate personal aspects (e.g. preferences).
- Automated decision-making: decision based solely on automated processing with legal or similar effects.
