LIFT DENTAL TECH S.R.L. · Last updated: September 3, 2026
This Privacy Policy explains how LIFT DENTAL TECH S.R.L., a company organized under the laws of Romania, with its registered office at [registered address], registration code (CUI) [●] ("Lift," "we," "us"), collects, uses, discloses, and protects personal data in connection with the Lift platform (the "Service"). It applies to dental practices and clinics that use the Service ("Clients") and their Owners, Admins, and Members (together, "Users"), as well as visitors to our websites.
This Policy should be read together with our Terms of Service, Cookie Policy, and, where applicable, the Data Processing Agreement entered into with the Client.
1. Two Roles: Lift as Controller and Lift as Processor
1.1 As data controller. Lift acts as an independent data controller for personal data relating to account administration and the business relationship with the Client, such as: the personal data of Owners, Admins, and Members used to create and manage accounts (name, email, phone number, role); billing and payment data of Owners; and technical, usage, and log data generated through use of the Service.
1.2 As data processor. Where the Client or its Users submit Content through the Service that includes personal data of the Client's patients (for example, diagnostic notes, treatment plans, or images associated with a case), Lift acts as a data processor, processing such data solely on the Client's documented instructions and for the purpose of providing the Service. The Client remains the data controller for such patient-related personal data and is responsible for establishing a lawful basis for processing it and for satisfying any patient notice or consent obligations. Processing of such data is governed by the Data Processing Agreement between Lift and the Client, which prevails over this Policy to the extent of any conflict regarding that data.
2. Personal Data We Collect
Account data — Account data Source: Name, work email, phone number, job role (Owner/Admin/Member), clinic name
Billing data — Billing data Source: Billing name, address, payment method details (processed by our payment processor)
Usage data — Usage data Source: Log-in times, feature usage, pages viewed, session duration, device and browser type
Technical data — Technical data Source: IP address, device identifiers, operating system, cookies/similar technologies
Support data — Support data Source: Communications, attachments, and information you provide when contacting support
Content (processor role) — Content (processor role) Source: Diagnostic/treatment information and case-related images submitted through the Service
Provided by Client/Users; may include patient personal data
3. How We Use Personal Data
— To provide, operate, and maintain the Service, including account provisioning and role-based access (Owner/Admin/Member);
— To process Subscription payments and manage billing, invoicing, and renewals;
— To communicate with Users about the Service, including security notices, updates, and support responses;
— To monitor, secure, and improve the Service, including diagnosing technical issues and preventing fraud or abuse;
— To comply with legal, tax, and regulatory obligations; and
— With consent, to send product updates or marketing communications, which Users may opt out of at any time.
4. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
— Performance of a contract — to provide the Service and manage the Client relationship;
— Legitimate interests — to secure and improve the Service, prevent fraud, and for direct communications relevant to the business relationship, provided such interests are not overridden by the individual's rights;
— Legal obligation — for tax, accounting, and regulatory compliance; and
— Consent — for optional marketing communications and non-essential cookies, which may be withdrawn at any time.
5. Sharing of Personal Data
We do not sell personal data. We may share personal data with:
— Sub-processors and service providers who support the Service (e.g., cloud hosting, payment processing, customer support tooling, analytics), under written agreements imposing confidentiality and security obligations consistent with this Policy;
— Professional advisors (legal, accounting) where necessary;
— Regulators, courts, or law enforcement where required by law; and
— A successor entity in the event of a merger, acquisition, or sale of assets, subject to equivalent protections.
A current list of sub-processors is available on request to the Client's Owner.
6. International Data Transfers
Personal data is primarily hosted within the European Economic Area (EEA). Where personal data is transferred outside the EEA, we rely on appropriate safeguards recognized under GDPR, such as the European Commission's Standard Contractual Clauses, or transfers to jurisdictions benefiting from an adequacy decision.
7. Data Retention
We retain personal data for as long as necessary to provide the Service and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements. Account data is generally retained for the duration of the Subscription plus [●] following termination, after which it is deleted or anonymized, subject to residual copies in backups deleted on a rolling schedule. Content is handled as described in the Terms of Service and applicable Data Processing Agreement.
8. Security
We implement technical and organizational measures designed to protect personal data against unauthorized access, loss, or misuse, as further described in our Security Overview. No system is completely secure, and we cannot guarantee absolute security.
9. Your Rights
Subject to applicable law, individuals whose personal data we control may have the right to: access their personal data; request correction of inaccurate data; request erasure; restrict or object to processing; request data portability; and withdraw consent at any time where processing is based on consent. Requests can be made by contacting us at [privacy email address]. Where Lift acts as a processor for patient data, such requests should generally be directed to the Client (the treating dental practice), who is the data controller for that data.
Individuals also have the right to lodge a complaint with a competent data protection supervisory authority, including the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).
10. Children's Data
The Service is intended for use by dental practices and their professional staff, not by children. We do not knowingly collect personal data directly from children through the Service in Lift's capacity as controller.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to Owners in accordance with the Terms of Service. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
12. Contact Us
Questions or requests regarding this Privacy Policy or our data practices can be directed to [privacy email address] or [registered address]. [If applicable: Our Data Protection Officer can be reached at [DPO email].]