Privacy Policy
How DentaConnect processes personal data when you use our website and platform services.
Last updated: 28 September 2026
The Dutch version governs. The English version is provided as a translation for information.
For privacy questions or requests, email privacy@dentaconnect.nl.
Who we are
DentaConnect provides an online platform where dental offices and dental professionals can create accounts, manage profiles, and coordinate work opportunities.
This notice applies to DentaConnect. We handle privacy questions and requests through privacy@dentaconnect.nl, and general service questions through support@dentaconnect.nl.
Data we process
We process data you provide, such as account and contact details, profile information, availability, requests, offers, platform contract data, messages in a contract conversation, support messages, preferences, and verification, qualification, and registration data.
We also process technical data needed for security and operation, such as session data, logs, device information, and language preference. We do not use advertising or marketing cookies.
Messages about signed assignments
For contract conversations, we process message text, sender, associated signed assignment, sending and reading times, and data needed for delivery, unread status, and security. This is necessary to provide the messaging feature chosen by users and coordinate the assignment (performance of our agreement with the user, Article 6(1)(b) GDPR). To investigate specific reports, prevent abuse, and handle disputes, we process only necessary data based on our legitimate interests (Article 6(1)(f) GDPR). A legal obligation or specific legal claim may require further retention in an individual case.
Messages are visible to the relevant Professional and the Practice's current authorized members. A Practice member authorized later can also read earlier messages for that assignment while they have access. Authorized staff receive access only where needed for a specific support, safety, or legal task. We do not put message text in email or push notifications, Realtime signals, or product analytics. The sections on providers, security, and transfers outside the EEA also apply to this data.
Do not send patient information or other unnecessary sensitive data through messaging. If such data is nevertheless shared, we may restrict access or hide the content after review and handle the incident under our privacy and safety procedures.
Why we use data
We use data to provide the service, secure accounts, display profiles and work opportunities, support verification and access control, facilitate communication, prevent abuse, and manage the service.
At a high level, we use performance of the service for account and platform functions, legitimate interests for security and improvement, legal obligations for administration or requests, and consent where required.
Product analytics
Where product analytics are allowed by the current account setting and legal basis, we use PostHog EU Cloud to improve the reliability, usability, and development of DentaConnect. PostHog receives a server-generated pseudonymous account subject ID, not a name, email address, user ID, route, search term, free text, or form content.
Allowed events are limited to session and screen use; onboarding, profile, verification, and availability milestones; marketplace, offer, and agreement stages; settings and account safety; and classified operational failures or recovery. They contain only the bounded categories and values allowed by the event catalog.
The legal basis can be legitimate interests with an easy account-level objection, or prior consent where that is required. Where consent applies, analytics remain off until you enable them; in either mode you can withdraw consent or object by disabling product analytics in your account settings. We retain product-analytics events for no longer than twelve months.
Matching and automated support
DentaConnect may use profile, availability, region, role, and status data to show relevant work opportunities and support access to parts of the service.
We do not currently make solely automated decisions that produce legal effects or similarly significant effects for you. If that changes, we will update this policy and provide appropriate information and safeguards.
Who we share data with
We share data with other users where it is visible in the service or needed to coordinate work opportunities.
We use service providers for hosting, authentication, storage, email, support and, where product analytics are allowed, PostHog EU Cloud. We may also share data where legally required or to protect rights and safety.
International processing
Our service and providers may process data inside and outside the European Economic Area.
Where data is processed outside the EEA, we use appropriate safeguards, such as adequacy decisions or standard contractual clauses where the GDPR requires them.
How long we keep data
We keep personal data for as long as needed for the service, account management, security, administration, disputes, or legal obligations.
A contract conversation and its messages are deleted during scheduled maintenance after 24 months have passed since the latest of the shift end, the final message, and signing. An existing moderation case about a message postpones deletion of the whole conversation while that case exists. A documented legal duty or specific legal claim may require longer retention in an individual case. The signed agreement and agreement evidence follow their own retention policy.
When other data is no longer needed, we delete or anonymise it within a reasonable time, unless longer retention is necessary or permitted. Allowed product-analytics events have a maximum retention period of twelve months.
Deleting your account
You can request deletion through the app or through /en/account-deletion. We require a recent email-code sign-in and a separate confirmation before we process the request.
After a request, we restrict new public discovery and marketplace participation. You can cancel the request for seven days. If product analytics were ever allowed for your account, we erase the related PostHog person and events before permanently deleting the authentication account; an unresolved provider erasure blocks that permanent step. We delete or anonymise data where possible, but may retain minimal data or existing commitments where needed for a legal obligation, contract, dispute, fraud prevention, or security. We do not invent a fixed retention period for such data.
Your privacy rights
You can ask for access, correction, deletion, restriction, transfer, or objection to certain processing. You can withdraw consent for product analytics where processing is based on consent, or object at account level to analytics based on legitimate interests.
Send an access or deletion request, including about messages, to privacy@dentaconnect.nl. We verify identity and assess requests individually, considering the other participant's rights, legal obligations, and specific legal claims. We erase or anonymise data no longer needed, provide a secure export where applicable, and record any exception and the handling. You can also file a complaint with the Dutch Data Protection Authority.
Security and cookies
We take appropriate technical and organisational measures to protect personal data, taking into account the nature of the service and the risks.
We use functional cookies and similar technologies needed for sessions, language preference, and security. Product analytics use only the permitted pseudonymous account events described above; advertising and marketing cookies are not in use.
Changes
We may update this Privacy Policy when the service, law, or our processing changes.
For important changes, we will make the new version available through the website or, where appropriate, through the service.