CrownDental.AI
Legal

Privacy Policy

Last updated: March 2026

CrownDental.AI GmbH ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect information when you use our platform, website, and services. It applies to all users of crowndental.ai and the CD1 device platform.

1. Controller

The controller responsible for processing your personal data under the General Data Protection Regulation (GDPR) is CrownDental.AI GmbH, Rennweg, Vienna, Austria. For all privacy-related inquiries you can reach us at privacy@crowndental.ai.

2. Data We Collect

When you register or use our platform, we may collect the following categories of personal data:

  • Practice identity data (legal name, address, registration number, VAT ID)
  • Contact person data (name, professional email, phone number, role or title)
  • Account access data (email address, hashed passwords, two-factor authentication preferences)
  • Billing and payment data (billing address, IBAN for SEPA, payment method preferences)
  • Usage and analytics data (scan counts, device usage, session metadata)
  • Technical data (IP address, browser type, access timestamps)

3. Purpose and Legal Basis

We process your personal data for the following purposes and on the following legal bases under GDPR Art. 6:

  • Contract performance (Art. 6(1)(b)): To provide, manage, and support your platform account and services.
  • Legal obligation (Art. 6(1)(c)): To comply with applicable tax, regulatory, and medical software laws.
  • Legitimate interest (Art. 6(1)(f)): To improve our services, ensure platform security, and conduct anonymised analytics.
  • Consent (Art. 6(1)(a)): For optional marketing communications and newsletters, where you have explicitly opted in.

4. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes described in this policy or as required by law. Account data is kept for the duration of your active subscription plus a mandatory legal retention period (typically 7 years for financial records under Austrian commercial law). You may request deletion of your data at any time, subject to applicable legal retention obligations.

5. Disclosure to Third Parties

We do not sell your personal data. We may share data with trusted service providers acting as data processors under a GDPR Art. 28 agreement, including:

  • Cloud infrastructure providers (hosting, storage, compute services)
  • Payment processors for billing and invoicing
  • Email delivery providers for transactional notifications
  • Analytics platforms using anonymised, aggregated data only

All processors are contractually bound to process your data solely on our instructions and in full compliance with GDPR.

6. Cookies and Tracking

Our website and platform use technically necessary cookies to ensure proper functionality, including session management and security tokens. We do not use advertising or cross-site tracking cookies without your explicit consent. You may configure your browser to refuse cookies; however, this may affect certain platform features.

7. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15) — Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17) — Request deletion of your data, subject to legal retention obligations.
  • Right to restriction of processing (Art. 18) — Request that we limit how we process your data.
  • Right to data portability (Art. 20) — Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21) — Object to processing based on our legitimate interests.
  • Right to withdraw consent (Art. 7(3)) — Withdraw any previously given consent at any time without affecting prior processing.

To exercise any of these rights, contact us at privacy@crowndental.ai. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde) at www.dsb.gv.at.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. Our measures include TLS encryption for all data in transit, encrypted storage for sensitive fields, role-based access controls, and regular security reviews of our systems and processes.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services or applicable law. We will notify you of material changes by email or in-platform notification prior to the change taking effect. The date at the top of this page shows when the policy was last revised.

10. Contact

For any privacy-related questions or to exercise your data subject rights, please reach us via the following channels:

  • Email: privacy@crowndental.ai
  • General enquiries: office@crowndental.ai
  • Post: CrownDental.AI GmbH, Rennweg, Vienna, Austria