• Information Notice

    on the processing and protection of data

    provided by “IcebergDent” LLC and “Sanelen Dent” LLC

    I. IDENTITY OF THE CONTROLLER

    I.1.“ICEBERGDENT” LLC, IDNO – 1024600027394, with its registered office at 48 Dacia Blvd, Chișinău, Republic of Moldova, represented by its administrator Mr. Constantin Racu, and “SANELEN DENT” LLC, IDNO – 1013600001509, with its registered office at 10 Concilierii Naționale St., Anenii Noi, Republic of Moldova (a company using the “Icebergdent” trademark), represented by its administrator Mr. Alexandru Ciorchină, hereby inform you, through this General Information Notice, of the manner in which personal data is processed and protected in the activities carried out by Icebergdent. Further details on the processing and protection of data provided by Icebergdent can be found in the standard forms/questionnaires, contracts and related procedures.

    II. CONTACT DETAILS OF THE DATA PROTECTION OFFICER

    II.1.In order to implement the provisions of Law No. 195/2024 on the protection of personal data, and in particular to be able to demonstrate compliance with Art. 37–39 of that law, Icebergdent has appointed as its data protection officer the company “Privacy by Default” LLC, represented by its administrator Mr. Sergiu Bozianu, office@gdpr.md.

    III. The terms used have the following meaning:

    Responsible authority – refers to the National Center for Personal Data Protection;

    special categories of personal data – data revealing racial or ethnic origin, political, religious or philosophical beliefs, social affiliation, health data, or data concerning sex life;

    profiling – a form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements of that person.

    personal data – any information relating to an identified or identifiable natural person;

    Information society services – informing about and scheduling dental therapy, orthodontic, dental surgery, dental prosthetics and cosmetic dentistry services through the website www.icebergdent.md and social media accounts (Facebook, TikTok, Instagram, etc.);

    data subject – any natural person who can be identified, directly or indirectly, by reference to an identification number or to one or more factors specific to their physical, physiological, psychological, economic, cultural or social identity;

    processing of personal data – any operation or set of operations performed on personal data by automated or non-automated means, such as collection, recording, organisation, storage, retention, restoration, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

    personal data filing system – any structured set of personal data accessible according to specific criteria, whether centralised, decentralised or distributed on a functional or geographical basis;

    controller – a natural or legal person governed by public or private law, including a public authority, or any other institution or organisation which, alone or jointly with others, determines the purposes and means of processing personal data as expressly provided by applicable legislation;

    processor – a natural or legal person governed by public or private law, including a public authority and its territorial subdivisions, which processes personal data on behalf of and under the instructions of the controller;

    third party – a natural or legal person governed by public or private law, other than the data subject, the controller or the processor, and other than persons who, under the direct authority of the controller or the processor, are authorised to process personal data;

    IV. Purpose, categories, sources and retention periods for data processing

    IV.1.Personal data is collected and processed within the filing system for the following purposes:
    a)For recruitment purposes: Name, surname, IDNP, home address, contact details, bank details, education, work performance, CV data, etc. – pursuant to Art. 6(1)(b) of Law No. 195/2024 and Art. 91(a) of the Labour Code.

    Personal data may be obtained from data subjects, former employers and/or state information resources and systems, for the purpose of verifying and validating this data.
    Personal data will be stored for between 3 and 75 years, in accordance with Order No. 57/2016 of the National Archives Agency.

    b)For the provision of information society services / dental medical services.

    Name, surname, IDNP, home address, contact details, bank details, health status, image, nature of the business relationship, medical history, medical prescriptions, contraindications, treatment, guidance, etc., as well as data traffic generated by web resources and medical equipment, and technical data such as IP address, MAC address, geolocation, etc. – in accordance with Art. 6(1)(b) and (f) of Law No. 195/2024.
    Personal data may be obtained from data subjects or from other medical institutions under conditions accepted/presented by the patient.
    Data relating to medical services will be stored for a period of 10 years from the termination of the legal relationship for the provision of services, provided there is no other legitimate interest or legal obligation.

    c)For video surveillance purposes (CCTV system)

    Photo/video, the location of the visit/workplace and all details that can be understood from these recordings – pursuant to Art. 6(f) of Law No. 195/2024.
    Personal data will be obtained directly from data subjects.
    Personal data will be stored for a period of up to 30 days from the date of recording.

    d)For the purpose of keeping records of staff and visitors

    Name, surname, date, month, year, time of passing the checkpoint, access card ID, other technical data – in accordance with Art. 6(1)(f) of Law No. 195/2024.
    Data will be obtained directly from the data subject.
    Personal data will be stored for a period of up to 12 months.

    e)For the purpose of recording telephone conversations

    Name, surname, bank details, medical data, appointment scheduling, other identification data, voice and any information communicated by the data subject during the phone call – in accordance with Art. 6(1)(a) and, where applicable, (f) of Law No. 195/2024.
    Personal data will be obtained directly from the data subject, as well as data managed by Icebergdent in its record-keeping systems.
    Personal data will be stored for up to 6 months.

    f)For the purpose of ensuring communication and managing medical services and document management

    Name, surname, email address, home address, data contained in correspondence/replies, position held, data regarding services received, etc. – in accordance with Art. 6(1)(f) of Law No. 195/2024.
    Data is collected from data subjects and from Icebergdent’s record-keeping systems or relevant state information systems.
    Personal data will be kept for a period of 5 years, unless other legal requirements or interests arise.

    g)Icebergdent also informs you that it may process personal data for other purposes, such as fulfilling a legal obligation or where a legitimate interest exists, such as: dispute resolution, debt recovery, etc., processing data for statistical purposes, and ensuring the availability, security and non-repudiation of data, including when implementing new services.

    Personal data for these purposes will be processed directly from the data subject or from Icebergdent’s or state systems.
    Personal data will be stored until the purposes are achieved and the retention periods imposed by law are reached.

    V. Notification regarding processors and cross-border transfer

    V.1.Personal data will be stored on servers located in the Republic of Moldova, managed by “It Concept” LLC as hosting service provider, or by its subcontractors, who will be located in countries that ensure an adequate level of data protection. Further details will be provided as relevant to the requested service.

    VI. Recipients of personal data

    VI.1.The controller may disclose personal data to:
    a)Employees – within the limits of the functional duties assigned through internal acts;
    b)Contractual beneficiaries – clients (data subjects or their legal representatives);
    c)Processors appointed by the controller:
    Companies responsible for the maintenance and servicing of technical equipment – to the extent the specific situation requires it and it is authorised by management;
    Companies responsible for software maintenance;
    Companies responsible for external financial audits;
    Companies responsible for providing electronic communications (internet) services;
    d)Other personal data controllers:
    The National Center for Personal Data Protection;
    The State Tax Service;
    Law enforcement bodies1;
    e)Contractual partners or institutions to which you have consented to the transmission of personal data.
    VI.2.Disclosure to other third parties without the data subject’s consent is prohibited.
    VI.3.In all cases of data transmission to the recipients listed above, the purpose, legal basis and causal connection with the relevant information will be verified.
    VI.4.Data relating to communications traffic may, without the consent of the person concerned, be disclosed only where there is a legal warrant presented in written form (a court warrant or the reasoned justification of the criminal investigation body), issued in accordance with the legislation of the Republic of Moldova and Art. 12 of Law No. 263/2005 on patients’ rights and responsibilities.

    VII. Rights of data subjects

    Data subjects (employees, patients/clients, visitors and/or any person intending to enter into an employment or medical services relationship, including any other category of persons) have the following rights:

    VII.1.Right of access to data – means that the data subject has the ability to receive confirmation/denial of the processing of their personal data, including the right to consult and access their personal data.
    VII.2.Right to rectification of data – the data subject has the right to have their data rectified, meaning the correction or completion of existing information processed by Icebergdent.
    VII.3.Right to erasure of data, the “right to be forgotten” – through this right of erasure, also called “the right to be forgotten,” a data subject may request the deletion of their personal data.

    Icebergdent must consider the possibility of erasing the data subject’s personal data where:

    The legal basis for processing is consent, and the data subject exercises their right to withdraw consent, and there is no other legal basis for continued processing;
    The legal basis for processing is legitimate interest, and the data subject objects to the processing, and the legitimate interest does not override the request for erasure;
    The personal data has been processed unlawfully;
    The purpose for which the personal data was collected and processed is no longer valid, so the data is no longer necessary;
    Regardless of the legal basis for direct marketing processing (legitimate interest or consent), the data subject objects to the processing;
    There is a legal obligation to erase the personal data;
    The data was collected in connection with the direct offering of information society services to a child under the age of 14, without the consent of their legal representative.

    The right to erasure of data may be refused where the following situations prevail:

    the right to freedom of expression and information;
    reasons of public interest in the area of public authorities;
    archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, where erasure would seriously impair the achievement of the objectives of the processing;
    for the establishment, exercise or defence of a legal claim;
    for reasons of necessity of processing for purposes relating to public health, in the public interest (e.g. protection against health threats, in a cross-border context);
    if processing is necessary for purposes relating to occupational health and safety.
    VII.4.Right to restriction of processing – the data subject may exercise their right to restrict the processing of their personal data; in that case Icebergdent has the right to retain/store the relevant data without using it, until the situation is resolved. This is not an absolute right and can only be applied in certain situations, being linked to the right to object or to rectify their data. Icebergdent is legally obliged to notify the client before lifting the restriction.
    VII.5.Right to data portability – the data subject may exercise their right to portability of their personal data, meaning the ability to obtain the personal data they have provided directly to Icebergdent, in a structured, commonly used and machine-readable (electronic) format, and to reuse it for other purposes, with other services, etc. In practice, the data is transferred from one information system to another, securely, without the data subject having to intervene in the transfer.

    Accordingly, the data subject may:

    receive a copy of their personal data (e.g. either the data is provided in electronic format, or access is granted through software from which the data subject can extract the information);
    request the transfer of personal data from one company to another, if technically feasible (there is no specific obligation to implement an information system compatible with others, but it is recommended to work within an “interoperable” system with others).

    The right to portability applies when data processing takes place in automated (electronic) form, and where the legal basis is consent or the performance of a contract.

    VII.6.Right to object – the data subject may exercise their right to object, at any time, to the processing of their personal data, including profiling, and this right may be effectively applied — meaning Icebergdent will cease processing the data — only when the objection is justified and there is no other legal basis for the processing. Where personal data is processed for direct marketing purposes, the data subject has the right to object at any time to the processing of their personal data for this purpose, including profiling, to the extent it relates to such direct marketing. Where the data subject objects to processing for direct marketing purposes, the personal data will no longer be processed for that purpose.
    VII.7.Right relating to automated decision-making, including profiling – the data subject has rights concerning:
    automated individual decision-making, meaning decisions taken solely on the basis of automated means/systems, without human intervention;
    profiling, meaning the automated processing of personal data to evaluate certain aspects of an individual (e.g. preferences, predictable behaviour, etc.).

    Where automated individual decision-making, including profiling, produces significant effects (legal or otherwise) on the data subject, such processing is restricted. These effects are presumed to have a negative impact on the data subject and may include, for example: automatic rejection of an e-recruitment application, denial of a service, etc.

    The above restrictions may be lifted only if the processing:

    is necessary for the performance of a contract;
    is authorised by legislation;
    is based on the explicit consent of the data subject.
    VII.8.Responses to requests exercising data subjects’ rights will be provided within a limited period, not exceeding one month. If requests are complex, or a series of requests has been received from the data subject, the response time may be extended by a further maximum of two months, provided the reason for the extension is explained within the initially set one-month period.
    VII.9.Where requests are made excessively, abusively, or repeatedly by a data subject, an administrative fee based on associated costs may be charged.
    VII.10.Rights may be exercised by submitting a request to Icebergdent’s registered address or by email at: office@gdpr.md

    VII.11. Right to lodge a complaint with the personal data protection authority

    VII.12.If you consider that the processing of data or the data protection measures do not comply with the requirements of Law No. 195/2024 on the protection of personal data, you may lodge a complaint with the National Center for Personal Data Protection, mun. Chișinău, 48 S. Lazo St., centru@datepersonale.md
    VII.13.You may also refuse to provide personal data to Icebergdent. Refusal to provide such data may result in the inability to provide services.

    VIII. General data protection measures in place

    VIII.1.The controller’s security perimeter comprises the registered office, as well as the locations of processors appointed by the controller, where personal data is stored and processed;
    VIII.2.A security perimeter means an area representing a physical boundary secured by physical (door) and/or technical (turnstile) access-control means;
    VIII.3.Access to the personal data controller’s security perimeter is prohibited, except in cases of authorised inspection, and it is equipped with access-control and video-surveillance means;
    VIII.4.Employees of the personal data controller are entitled to access the premises and/or locations for which they have been granted approval by management.
    VIII.5.Access by other persons to the security perimeter may only take place under the supervision of employees;
    VIII.6.Law enforcement or oversight bodies may access the security perimeter if they hold appropriate authorisation (in original), a copy of which is provided to the controller’s representatives;
    VIII.7.The premises where personal data processing equipment is located are physically secure. The exterior walls of the rooms are solid, and entrances are fitted with locks. The keys to the door locks are kept by the administrator. The administrator keeps a record of keys and of persons granted access to the personal data controller’s security perimeter;
    VIII.8.Doors and windows within the security perimeter are locked when employees leave the premises;
    VIII.9.The use of photo, video, audio or other recording equipment within the security perimeter is permitted only with the permission of those responsible;
    VIII.10.Where an employee’s employment contract has ended or been suspended, the administrator of the personal data controller is required, on that same day, to withdraw their keys to access points, cabinets or safes, as well as their computer access rights;
    VIII.11.Before taking up their position, all employees are informed, against signature, of the Security Policy, and also sign a non-disclosure clause regarding restricted-access information they will come into possession of in the course of performing their assigned tasks and duties;
    VIII.12.Disclosure of personal data or other confidential information via electronic means to unidentified persons is not permitted.
    VIII.13.Where paper-based or electronic (digital) information carriers containing personal data are temporarily not in use, they are kept in a specially designated, locked storage area;
    VIII.14.Computers, access terminals and printers are disconnected at the end of working sessions.

    IX. Technical security measures:

    IX.1.The controller keeps a record of computing equipment that stores personal data and other confidential information under its management;
    IX.2.The use of personal computing devices such as laptops, tablets, media sticks, etc. for carrying out the personal data controller’s tasks is prohibited;
    IX.3.Access to computers is granted based on a user profile and password, which is confidential and may not be disclosed to anyone, written down, or displayed for unrestricted access. Passwords must contain a minimum of 8 characters, must not be related to the user’s personal information, must not contain consecutive identical characters, and must not be composed entirely of groups of digits or letters. Passwords will be changed every 3 months;
    IX.4.Computing devices are equipped with antivirus software and licensed operating systems;
    IX.5.Transmission of restricted-access information will only be carried out through secure methods;
    IX.6.Computing devices for each user are individually configured with access filters and hardware usage restrictions, depending on their tasks and functional duties;
    IX.7.Removing restricted-access information from the security perimeter without the personal data controller’s permission is prohibited;
    IX.8.The use of remote-access software on computing equipment is prohibited.
    IX.9.Technical and administrative conditions for electrical-power and fire safety are ensured;

    X. Cookie files

    X.1.The data controller processes two types of cookies: session and persistent. The latter are temporary files that remain on the user’s device until the end of the session or until the application (web browser) is closed.
    X.2.Cookies themselves do not request, and are not combined with, additional information that could lead to the identification of unregistered visitors.
    X.3.At the end of the internet session, session cookies are automatically deleted or retained in accordance with the retention periods indicated in the push notification.

    1 a public authority or a subdivision of such an authority, competent for the prevention, investigation and detection of offences, for the purpose of implementing criminal proceedings, prosecuting offences or executing criminal penalties, including protecting against and preventing threats to public order, such as, but not limited to: the police, prosecution bodies, customs authorities, penitentiary institutions, bodies for the prevention and combating of corruption, money laundering and terrorist financing, asset-recovery bodies, probation bodies, and state security bodies.