Последна актуализация: 27 юли 2026 г.

GDPR известие

Това известие обобщава информацията за прозрачност и правата на лицата, които използват CrocoDent, в случаите, в които тези правила се прилагат.

1. Администратор и обхват

Операторът на CrocoDent е администратор за операциите, които определя. Таблицата за доставчиците по-долу посочва за всяка операция дали Supabase, хостингът, Stripe, Google, OpenAI и SMTP действат като обработващ или самостоятелен администратор. Непубликувано поле е пречка за продукционно внедряване.

2. Цели и правни основания

Матрицата за обработване по-долу свързва всяка конкретна операция, категория данни и цел с определено основание по член 6 и, когато е приложимо, условие по член 9. За пациентско свързване CrocoDent използва съгласие по член 6(1)(а) и изрично съгласие по член 9(2)(а); отказът не засяга публичните страници или поддръжката.

3. Категории лични данни

Основните категории са: потвърждение за навършени 18 години, отговор дали зъболекар е поставил диагноза, избрани оплаквания или поставени диагнози, предпочитания за час, данни от студентските профили, университетска проверка, предпочитания за контакт, информация за профила, статус на плащането, CAPTCHA сигнали, данни за устройството и логовете, както и комуникация, свързана с услугата. Посоченото оплакване или дентално състояние може да е здравна информация, за която се прилагат правилата за специални категории данни.

4. Получатели

Матрицата и таблицата за доставчиците по-долу посочват действителните получатели и минималните данни за всяка операция. Студентите не получават от CrocoDent отговорите от анкетата или изведените кодове за лечение; видимите контактни данни се показват само след защитения процес за разкриване.

5. Международни трансфери

Таблицата за доставчиците по-долу публикува действителните местоназначения и приложимото решение за адекватност, участие в рамка за защита на данните или модул на стандартните договорни клаузи. Непубликувано поле е пречка за внедряване, а не твърдение, че съществува неопределена гаранция. Копие от приложимата гаранция може да се поиска от support@crocodent.org при необходимите заличавания.

6. Вашите права

Когато правилата се прилагат, може да имате право:

  • Да бъдете информирани как се обработват личните ви данни.
  • Да получите достъп до личните данни, съхранявани за вас.
  • Да поискате коригиране на неточни или непълни лични данни.
  • Да поискате изтриване на лични данни при определени обстоятелства.
  • Да поискате ограничаване на обработването при определени обстоятелства.
  • Да получите определени лични данни в преносим формат.
  • Да възразите срещу определено обработване, включително директен маркетинг.
  • Да поискате преглед от човек при изцяло автоматизирани решения с правен или подобен значим ефект.

Може също така да имате право да оттеглите съгласието си, когато обработването се основава на съгласие, и да подадете жалба до орган за защита на личните данни.

7. Автоматизирано вземане на решения

CrocoDent може да подрежда или филтрира студентските профили според избрано потвърдено от зъболекар състояние или оплакване, свободните часове, статуса на абонамента и настройките на студентския профил. Предложенията според оплакванията не поставят диагноза, не създават план за лечение и не водят до решение с правен или подобен значим ефект.

8. Упражняване на правата

За да упражните право, свързано със защитата на личните данни, моля, свържете се с CrocoDent чрез официалния канал за поддръжка, посочен в платформата. CrocoDent може да се наложи да потвърди самоличността ви, преди да предприеме действия по искането.

Съгласие за директен маркетинг

CrocoDent използва имейл адрес на пациент за известия за свободни часове или директен маркетинг само след свободно дадено, конкретно, информирано и недвусмислено съгласие. Отказът или оттеглянето не засяга достъпа до свързване с пациенти. Съгласието може да бъде оттеглено по всяко време и безплатно чрез връзката във всеки маркетингов имейл или на support@crocodent.org. Оттеглянето не засяга законосъобразното обработване преди него. След оттегляне CrocoDent прекратява директния маркетинг и при необходимост пази само ограничен запис за отписването и отчетността. Лицата имат и безусловно право да възразят срещу директния маркетинг.

Operational schedule · privacy-operations-2026-07-27

Processing matrix

This schedule replaces generic references to “typical” legal bases or undefined retention. Each row states what CrocoDent currently does. A materially different purpose requires a notice and, where applicable, fresh consent.

Operation and dataPurposeArticle 6 / Article 9Recipients and transfersRetentionRequired? ConsequenceRights and automation

Patient matching with a dentist-confirmed condition

Adult confirmation, selected dentist-confirmed dental conditions, minimal derived treatment codes, selected clinic slots, consent-session identifier, and security metadata.

Create and rank a short list of dental-student profiles whose stated case needs and clinic availability may fit the patient's selections.

Consent, GDPR Article 6(1)(a).

Explicit consent, GDPR Article 9(2)(a).

Authorised CrocoDent operators, hosting and Supabase processors. Students do not receive survey selections or derived codes; the patient decides whether to contact a student.

Only the configured hosting and Supabase destinations. The vendor schedule below publishes the deployment-specific mechanism.

Selections and derived codes remain in current-tab memory and short-lived requests. The patient session expires after 30 minutes. Immutable consent evidence, containing the wording and purposes but not the selected condition, is retained for 6 years after withdrawal or expiry.Optional. Without explicit consent CrocoDent cannot provide patient matching; public pages and support remain available.

Withdraw through Clear matching data or support, and request access, restriction, erasure, or portability where applicable. Withdrawal stops future processing and does not affect prior lawful processing.

Rules filter and rank profiles. The output is a non-diagnostic shortlist, has no legal or similarly significant effect, and does not create a treatment plan.

Complaint-based matching without a dentist-confirmed condition

Adult confirmation, selected complaints, selected clinic slots, consent-session identifier, and security metadata. No diagnosis or treatment is inferred.

Return a short list of students who accept at least one selected complaint and whose clinic availability may fit.

Consent, GDPR Article 6(1)(a).

Explicit consent, GDPR Article 9(2)(a), is requested because complaint selections are health-related data.

Authorised CrocoDent operators, hosting and Supabase processors. Students receive no patient selections from CrocoDent.

Only the configured hosting and Supabase destinations. The vendor schedule below publishes the deployment-specific mechanism.

Current-tab memory and short-lived requests only; session expiry after 30 minutes. Consent evidence is retained for 6 years.Optional. Without consent, matching is unavailable; public information and support remain available.

The same consent withdrawal and data-subject rights as condition-based matching.

A rules-based complaint and availability filter produces a non-diagnostic shortlist with no legal or similarly significant effect.

Patient health-consent evidence

Consent-event identifier, wording snapshot and hash, version, locale, controller, purpose identifiers, timestamp, expiry, withdrawal event, and minimal request-security evidence. No survey answer or condition code is stored in the evidence ledger.

Prove what explicit consent was requested and given, bind it to one short-lived session, and honour withdrawal.

Legitimate interests in accountability and legal-claim defence, GDPR Article 6(1)(f), after the active consent session ends.

The ledger intentionally excludes health selections. If an event is nevertheless special-category data, Article 9(2)(f) applies only where necessary for legal claims.

Restricted CrocoDent administrators, hosting and Supabase processors, and a competent authority where legally required.

Configured hosting and Supabase destinations only.

6 years after the session expires or consent is withdrawn, then deletion or irreversible aggregation.Created only if the person elects to use patient matching.

Access, restriction, objection, and erasure where the accountability or legal-claim need no longer overrides the request.

No decision is made from the consent ledger.

Patient account, bookmarks and star ratings

First name, last name, email, phone number, authentication and email-verification status, student bookmarks, and one 1-to-5 star rating per rated student.

Authenticate patients, protect student contact details, keep private bookmarks, and publish simple aggregate student ratings after visits.

Contract steps and performance, GDPR Article 6(1)(b); legitimate interests, Article 6(1)(f), for verification, rating integrity and abuse prevention.

No complaint selection, condition selection, derived matching code or other Article 9 health field is stored in the patient account, bookmarks, or ratings.

Supabase and hosting processors. A student and visitors can see only aggregate rating results, never the patient's identity or bookmarks.

Configured hosting and Supabase destinations only. The vendor schedule below publishes the deployment-specific mechanism.

While the patient account remains active. Bookmarks and ratings are deleted if the patient or student account is deleted, subject to documented backup expiry and any overriding legal requirement.The account fields are required to create a patient account. Without verified email, contact reveal, bookmarks, and ratings remain unavailable.

Request access, correction, portability or deletion through support, and update an existing rating by scanning the same student QR again.

Email verification gates trust-sensitive actions. Aggregate ratings do not diagnose, select treatment or make a legal or similarly significant decision.

Student account and patient-facing profile

University email, name, course and university, profile details, accepted patient-complaint preferences, clinical case needs, availability, cost responsibility, selected contact channels, optional phone and photo where needed, account status, and opaque public identifier.

Authenticate eligible students, operate their account, and show a minimal profile to relevant patients when a dental student opts into matching.

Contract steps and performance, Article 6(1)(b); legitimate interests, Article 6(1)(f), for verification and abuse prevention.

No Article 9 patient health record belongs in a student profile. Accepted-complaint preferences and clinical case-need categories describe the student's matching preferences and training requirements, not a patient's record.

Supabase and hosting processors; patients receive only the minimum public profile fields and only opted-in contact channels after deliberate verification.

Configured hosting and Supabase destinations. Contact reveal can also activate Google reCAPTCHA as described below.

While the account is active. On deletion, active access is removed immediately; browser cleanup has a 24-hour acknowledgement grace; backups have a proposed maximum 35-day expiry pending provider confirmation. Erasure-job evidence is retained for 24 months.Core account and university-verification data are required. Phone and face photo are optional for study-only accounts; a dental student provides a contact value only for a channel they enable.

Dashboard correction, visibility choices, export and deletion request, plus the GDPR rights described below.

Profile eligibility and ranking use configured rules. No solely automated decision has legal or similarly significant effect.

Unconfirmed student registration

University email, registration draft metadata, verification status, and an optional pending photo only when the selected account path needs one.

Complete email verification and create the requested account without retaining abandoned drafts indefinitely.

Steps at the person's request before contract, Article 6(1)(b).

No special-category data is requested.

Hosting and Supabase authentication and private-storage processors.

Configured hosting and Supabase destinations.

72 hours from authentication-user creation; editing an email does not extend the deadline. Cleanup retries up to 12 times with exponential delay capped at 6 hours. Signup and orphan-cleanup evidence is retained for 90 days.University email and the minimum course fields are required to verify eligibility. Study-only users do not have to provide a phone or face photo.

Abandon registration, request deletion, or contact support.

Domain and eligibility checks may reject an ineligible registration; support can review errors.

Student billing and invoices

Account and customer identifiers, product, price, transaction status, invoice and tax records. Full card details are entered directly with Stripe and are not stored by CrocoDent.

Take payment, administer subscriptions, prevent fraud, and keep accounts.

Contract, Article 6(1)(b); legal obligation, Article 6(1)(c), for required financial records; legitimate interests, Article 6(1)(f), for fraud and claims.

No special-category data is required.

Stripe, hosting, Supabase, professional advisers, tax authorities, and payment-network participants where required.

Stripe's configured destinations and safeguards are published in the vendor schedule.

Active billing state for the account lifetime. Invoices and legally required accounting records are segregated from the deleted profile and retained for 10 years, unless the applicable law requires a different period.Payment information is required only for a paid feature. Refusal means that feature cannot be supplied.

Access and correction apply; erasure may be limited for mandatory accounting, fraud, chargeback, or legal-claim records.

Stripe may run fraud checks under its own notice. CrocoDent does not make a solely automated legally significant decision from survey health data.

Student AI study tools

Study notes, uploaded learning material, generated output, usage and job metadata. Patient-identifiable or clinical case data is prohibited.

Generate study aids requested by the authenticated student.

Contract, GDPR Article 6(1)(b).

No Article 9 data is intended or permitted. Users are warned not to submit patient-identifiable content.

Hosting, Supabase and OpenAI as configured processors.

OpenAI and infrastructure destinations and mechanisms are published below.

Memory-map working files and job payloads expire after about 24 hours; account-level usage and billing records follow their separate schedules.Optional. Without the submitted study content, the requested tool cannot generate an output.

Delete generated content and exercise account data rights.

AI generates study content, not a decision about a person. Students must review output for accuracy.

Optional appointment-availability emails

Email, locale, narrow purpose identifier, exact consent wording and hash, pending and confirmation events, send history, withdrawal history, and hashed confirmation and unsubscribe tokens.

Send low-frequency, irregular appointment-availability announcements only. General news and unrelated marketing are excluded.

Consent, GDPR Article 6(1)(a).

No Article 9 health selection is attached to the mailing record or message.

Supabase, hosting and the configured SMTP provider.

Configured hosting, Supabase and SMTP destinations and safeguards.

Pending confirmation expires after 24 hours. Active consent is reviewed on a defined cadence. Consent and withdrawal evidence follows the immutable-ledger schedule; suppression prevents silent reactivation.Entirely optional and separate from matching. Refusal or withdrawal has no effect on patient matching.

Withdraw through every message or support and object to direct marketing at any time. A withdrawn address cannot be reactivated without fresh mailbox confirmation.

No profiling or significant automated decision.

General support contact

Name, email, subject, message and delivery metadata. The form warns against symptoms and patient-identifiable information.

Answer platform, account, privacy and billing support requests.

Contract or pre-contract steps, Article 6(1)(b), when account-related; legitimate interests, Article 6(1)(f), for general support; legal obligation, Article 6(1)(c), for rights requests.

No Article 9 processing is intended in the general mailbox, which is not a clinical channel. Unexpected health data is restricted and deleted or redirected promptly unless a legal duty requires handling.

Authorised support staff, hosting and the configured SMTP provider.

Configured hosting and SMTP destinations and safeguards.

Ordinary support messages are deleted 12 months after closure. Verified privacy requests and dispute records are segregated and retained for up to 6 years.Optional, but a reply requires contact details. Do not send symptoms or identifiable patient information.

Access, correction, deletion, restriction and objection as applicable.

No automated significant decision.

Security, anti-scraping, audit and deletion reconciliation

IP-derived rate-limit keys, request and device metadata, authentication events, CAPTCHA result, opaque public identifiers, deletion job state, provider acknowledgements and tombstones. Application logs must redact survey and token fields.

Protect accounts and contact details, limit scraping, investigate incidents, prove processor deletion, retry failures, and prevent deleted data from silently reappearing.

Legitimate interests, Article 6(1)(f); legal obligation, Article 6(1)(c), where incident or accountability records are required.

No Article 9 health selections are included in logs. If incident evidence unavoidably contains special-category data, access and retention are restricted to strict necessity.

Restricted CrocoDent administrators, hosting, Supabase, Google after deliberate CAPTCHA activation, and affected providers during deletion propagation.

The relevant configured vendor destinations and safeguards below.

Operational request logs: 30 days. Confirmed abuse and incident evidence: up to 12 months, or longer only for a documented legal claim. Signup cleanup evidence is kept 90 days; account-erasure and retired-ID evidence is kept 24 months. Jobs retry up to 12 times with exponential delay capped at 6 hours.Generated automatically when needed to secure the service. CAPTCHA is activated only by deliberate user action.

Object and request restriction or deletion, subject to overriding security, legal and accountability needs.

Rate limits and CAPTCHA can temporarily block a request. They do not determine treatment or make a legal or similarly significant decision.

Patient data flow

Raw choices, derived treatment codes, processor access and the student-facing boundary are separated below.

  1. 1

    Current browser tab

    Receives
    Adult confirmation, complaint or dentist-confirmed condition selections, and clinic slots.
    Keeps
    Only in JavaScript memory for the active tab. No health selection is written to localStorage, a URL, browser history or referrer.
    Who can see it
    The person using the tab.
  2. 2

    CrocoDent consent endpoint and Supabase

    Receives
    The explicit-consent event, locale, wording version and snapshot, purposes and minimal security evidence.
    Keeps
    An immutable accountability record without the selected complaints or conditions, plus a short-lived consent-bound patient session.
    Who can see it
    Restricted CrocoDent administrators and contracted processors.
  3. 3

    CrocoDent matching endpoint

    Receives
    A POST request tied to the short-lived patient session, containing only minimal complaint IDs or treatment codes and clinic slots needed for that request.
    Keeps
    No reusable health state in a URL or general application log. Responses are private, no-store and limited to a small shortlist.
    Who can see it
    Hosting and Supabase processors while completing the request.
  4. 4

    Patient results

    Receives
    Only minimum public profile fields, opaque public student identifiers and short-lived photo access.
    Keeps
    Current-tab state until Clear matching data, tab closure or the 30-minute session expiry.
    Who can see it
    The patient. A matched student receives no survey answer or derived code from CrocoDent.
  5. 5

    Private patient account

    Receives
    Name, email, phone, authentication status, student bookmarks, and star ratings.
    Keeps
    Account and trust-action records only. Complaint selections, condition selections, derived codes and clinic slots are never copied into the account.
    Who can see it
    The patient and restricted processors. Students and visitors see only aggregate rating results, never patient identity or bookmarks.
  6. 6

    Patient-initiated contact

    Receives
    A student's opted-in contact channel after deliberate anti-bot verification.
    Keeps
    CrocoDent does not copy the patient's survey into the message. Any later communication occurs through the channel the patient chooses.
    Who can see it
    The patient and the selected student; the channel provider applies its own privacy terms.

Provider roles and international transfers

Provider roles are operation-specific. A field marked “Not yet published” is a deployment blocker, not permission to rely on an unspecified safeguard. Contact support@crocodent.org for a copy of an applicable safeguard, subject to necessary redactions.

Provider and operationRole and dataDestinationsMechanismRetention and controls

Supabase

Authentication, database, immutable consent and deletion ledgers, private object storage and signed media access.

Processor for CrocoDent-controlled operations. Any provider security or legal-compliance use must be assessed separately under the provider terms.

Student and patient accounts and profiles, bookmarks, ratings, consent evidence, marketing records, deletion jobs, private files and database security metadata.

Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.Operation-specific CrocoDent retention; regional project selection, row-level security, service-role isolation, private buckets, signed URLs, DPA, subprocessor review and onward-transfer controls.

Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.

Web delivery, server-side API execution, deployment, request security and operational logs.

Processor for CrocoDent-controlled hosting and request processing.

Request metadata and transient API payloads. Health and token fields must be excluded or redacted from logs, CDN telemetry, APM and error reports.

Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.Private/no-store patient responses, no-referrer policy, log redaction, least-privilege access, short log TTL, DPA, subprocessor review and regional execution where contracted.

Stripe

Checkout, subscriptions, invoices, fraud and payment compliance.

Processor where Stripe follows CrocoDent's payment instructions; independent controller for its own legal, anti-fraud, payment-network and regulatory purposes.

Customer and account identifiers, transaction, subscription, invoice, device and payment-method data. CrocoDent does not store full card details.

Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.Stripe's legally required retention applies to its controller processing. CrocoDent segregates retained invoice references from deleted active profiles and records erasure requests and responses.

Google reCAPTCHA

Anti-bot assessment only when a person deliberately asks to reveal a student's contact details.

Google acts as an independent controller for the device, network and interaction signals it receives under its terms.

IP address, browser and device information, page and interaction signals, reCAPTCHA token and assessment.

Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.No script on focus or hover. The UI explains the transfer before activation and links to Google's terms; CrocoDent retains only the verification outcome needed for security.

OpenAI

Authenticated student study-tool generation only.

Processor for API content submitted under CrocoDent's instructions.

Study notes and generated output. Patient-identifiable and clinical case content is prohibited and is not used for patient matching.

Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.DPA, approved subprocessors, no training use where contracted, least-retention API settings, 24-hour CrocoDent working-file TTL and deletion propagation.

Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.

Support delivery, double-opt-in confirmation and appointment-availability email delivery.

Processor for delivery under CrocoDent's instructions; separate controller duties, if any, must be identified in the configured provider assessment.

Email address, message headers and content, delivery events and narrow campaign purpose. Patient survey selections are excluded.

Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.Not yet published. Production must set the corresponding NEXT_PUBLIC_PRIVACY_* value before relying on this notice.DPA, access controls, restricted mailboxes, defined mailbox retention, hashed bearer tokens, suppression enforcement and erasure propagation.
Controller
Sarbaz Jan
Registered contact address
23 Krastyo Rakovski Street