Privacy policy
Last updated: 24 September 2026
This document explains what data we process, why, for how long, and what rights you have. It applies to the dentflow.md website, to the DentFlow software (app.dentflow.md and the clinics' subdomains) and to the patient portal. Controller, wherever we decide the purpose of the processing: SRL "FEMMINITY BEAUTY LAB", IDNO 1024611006511, str. Alba-Iulia 168, of. 21, MD-2051, Chișinău, Republic of Moldova. We comply with Law no. 133/2011 on the protection of personal data and with the acts amending or replacing it. We have not appointed a data protection officer; questions go to contact@b4b.md.
1. Two kinds of data, two different roles
The distinction matters:
- The clinic's data as a visitor or customer — your name, phone, email, clinic, our conversations with you, billing details. For these, we are the controller.
- The data entered into the software — patients' data (names, contact details, treatments, payments, radiographs, medical documents) and clinic staff's data (accounts, roles, actions recorded in the audit log). For these, the clinic is the controller, and we are only the processor: we process them solely on the clinic's instruction, under clause 6 of the Terms and conditions. We do not use them for our own purposes, do not sell them, and do not show them to anyone outside the clinic.
It is the clinic that informs its patients and staff about the processing of their data in the software. We provide it with this document and the support it needs.
2. What we process and why
- The messages you send us — on WhatsApp, by email or by phone: name, phone, clinic, message. So that we can contact you and reply. Basis: your request, and our legitimate interest in replying.
- The account in the software — name, email, role, time of last sign-in, actions recorded in the audit log. So that authentication, role-based permissions and traceability work. Controller: the clinic.
- The patient portal — if the clinic switches it on, the patient sees their appointments and documents in an account of their own: name, contact details, sign-in credentials. Controller: the clinic.
- Billing — company details, the contract and payment history. Basis: performance of the contract and accounting and tax obligations.
- The +Starter website — the logo, clinic details and dentists' photographs you send us, so that we can build and publish the site. Basis: the contract. The clinic is responsible for the dentists' consent to the publication of their photographs.
- Technical logs — IP address, browser type, access times, errors. To keep the service running, prevent abuse and investigate security incidents. Basis: our legitimate interest.
- Notifications to patients — the phone number and message text, passed to the SMS aggregator on the clinic's instruction. Controller: the clinic.
We take no automated decisions with legal effects on anyone. The AI assistant proposes; a person at the clinic confirms.
3. Health data
The software contains patients' health data, which enjoys heightened protection. It is visible only to the users the clinic has authorised. Our technical staff, bound by a duty of confidentiality, access it only when the clinic asks for help and only as far as strictly necessary to resolve the problem reported; each such access is justified by a request from the clinic.
3.1. The AI assistant
The AI assistant is off by default and works only at clinics that have asked for it to be switched on. Where it is active, in order to answer a question it sends the model provider — Anthropic, PBC, based in the United States — the question and the data needed to formulate the answer. That may include data from the clinic's software and patient data: names, appointments, treatments or amounts, depending on what was asked.
- The provider processes the data only to generate the answer, under its commercial contract, and does not use it to train its models.
- The transfer takes place outside the European Union and the Republic of Moldova. It rests on the contract concluded with the provider, which includes standard contractual clauses for data protection and security obligations.
- The clinic remains the controller of patient data and decides whether to switch the assistant on. Doing so is its instruction and authorisation for this transfer; the clinic is responsible for the legal basis of the transfer towards its patients and for informing them, and we provide it with the information it needs. If it does not switch the assistant on, nothing goes to the model provider.
- Questions and answers remain in the clinic's account so that they can be reviewed later, and are deleted together with the clinic's data.
4. Where the data is kept
On servers in the European Union, at DigitalOcean, in the Frankfurt data centre (Germany) — the software, the database and the uploaded files (radiographs, photographs and scanned documents) all sit there. The connection between browser and server is encrypted. Backups run automatically, daily, and are kept for seven days — we retain the seven most recent copies, and older ones are deleted automatically. Every subscription includes storage for this data; exceeding it is billed under clause 4 of the Terms and conditions and never leads to data being deleted.
5. Who we pass data to
We do not sell data and do not pass it on for marketing. The following providers may process it, strictly to operate the service and bound by contract to confidentiality and security obligations:
- DigitalOcean, LLC — hosting, database and file storage, in the Frankfurt data centre, European Union.
- An SMS aggregator in the Republic of Moldova — through which notifications to patients are sent; we pass it the phone number and the message text, nothing more.
- Anthropic, PBC (United States) — the provider of the model behind the AI assistant, only for clinics that have asked for the assistant to be switched on, under section 3.1.
We notify you at least 30 days before adding or changing a provider that processes patient data; if you object on reasonable grounds, you may terminate the contract without penalty. If we introduce card payment, we will list the payment processor here before using it. We may also pass on data where the law or an authority requires it, in which case we notify the clinic where permitted.
6. How long we keep data
- Messages received on WhatsApp, by email or by phone: 12 months from the last conversation.
- Data in the software: for the term of the contract. On termination we export it, keep it for 60 days so that you can collect it, then delete it permanently, backups included, within 30 days after that — except for data the law requires us to retain.
- Technical logs: 90 days.
- Contract and billing documents: as long as accounting and tax law requires.
7. Your rights
You have the right to know what data we hold about you, to ask for it to be corrected, deleted or its processing restricted, to object to processing based on legitimate interest, and to receive the data in a workable format. Write to contact@b4b.md and we reply within 30 days at most. Exporting the clinic's data carries no fee of its own; the volume downloaded counts towards the month's transfer under clause 4 of the Terms and conditions.
If a clinic's patient or employee has such a request, they address it to the clinic, which is the controller of their data; we help the clinic reply in time.
If you consider that the processing infringes your rights, you may apply to the National Centre for Personal Data Protection of the Republic of Moldova (datepersonale.md). We would prefer you write to us first.
8. Cookies
The presentation website uses only the browser's local storage, for the chosen language. The software uses one technical cookie strictly necessary for authentication. We do not use Google Analytics, Meta Pixel or other tools that track visitors from one site to another, and we set no marketing cookies. We count visits only from server logs, without cookies, so there is no banner for you to accept.
9. Security
- An encrypted connection (TLS) and separate data for each clinic, in separate databases.
- Role-based permissions, so that everyone sees only what concerns them; individual accounts, no shared passwords.
- An audit log for deletions, price changes and other important actions.
- Daily backups, kept for seven days, monitored automatically.
- Technical access to the clinic's data only at its request and only as far as necessary.
If a security breach occurs that could affect a clinic's patients or staff, we notify the clinic without undue delay and within 48 hours of discovery, with the information we have, so that it can meet its statutory notification duties.
10. Changes
We may update this policy. We publish the new version here and, if the change is significant, notify clinics by email at least 15 days in advance.
11. Language
The policy is drawn up in Romanian. The Russian and English translations are provided for convenience; in the event of any discrepancy, the Romanian version prevails.
12. Contact
SRL "FEMMINITY BEAUTY LAB" · contact@b4b.md · +373 78 000 019 · str. Alba-Iulia 168, of. 21, MD-2051, Chișinău, Republic of Moldova.