LIFT DENTAL TECH S.R.L. · Last updated: September 3, 2026
This Security Overview describes the technical and organizational measures LIFT DENTAL TECH S.R.L. ("Lift") applies to protect the Lift platform (the "Service") and the data processed through it. It is provided for informational purposes to help Clients evaluate our security posture and does not modify or expand any obligation set out in our Terms of Service or Data Processing Agreement.
1. Infrastructure & Hosting
— The Service is hosted on reputable cloud infrastructure providers within the European Economic Area, benefiting from the provider's physical security, redundancy, and environmental controls.
— Production environments are logically segregated from development and testing environments.
— Infrastructure is provisioned and configured using version-controlled, auditable configuration practices where feasible.
2. Encryption
— Data in transit is encrypted using industry-standard protocols (TLS 1.2 or higher).
— Data at rest, including databases and file storage containing Client Content, is encrypted using industry-standard encryption algorithms.
3. Access Controls
— The Service enforces role-based access control aligned with the Owner / Admin / Member model, so that each User's permissions correspond to their assigned role.
— Internal access to production systems and Client data is restricted to authorized personnel on a least-privilege, need-to-know basis.
— Multi-factor authentication (MFA) is supported for User accounts and required for internal administrative access to production systems.
— Access rights are reviewed periodically and revoked promptly upon role change or offboarding.
4. Application Security
— Software is developed following a defined software development lifecycle (SDLC) including code review prior to deployment.
— Dependencies and third-party libraries are monitored for known vulnerabilities.
— The Service undergoes periodic security testing, which may include vulnerability scanning and third-party penetration testing.
— Security-relevant findings are triaged and remediated based on severity.
5. Network Security
— Production environments are protected by firewalls, network segmentation, and access restrictions limiting exposure of internal systems.
— Where applicable, web application firewall (WAF) and distributed denial-of-service (DDoS) mitigation capabilities are used to protect public-facing endpoints.
6. Monitoring & Logging
— System and application logs are collected to support security monitoring, troubleshooting, and audit purposes.
— Automated alerting is configured for anomalous activity indicative of a potential security event.
7. Backups & Disaster Recovery
— Client data is backed up on a regular schedule and stored securely, with periodic testing of restoration procedures.
— Lift maintains business continuity procedures designed to restore the Service within a reasonable period following a significant disruption.
8. Incident Response & Breach Notification
— Lift maintains an incident response process for identifying, containing, investigating, and remediating security incidents.
— In the event of a personal data breach affecting a Client's data, Lift will notify the affected Client without undue delay after becoming aware of the breach, consistent with our contractual and, where applicable, GDPR obligations, and will provide reasonably available information to help the Client meet its own notification obligations.
9. Personnel Security
— Personnel with access to production systems or Client data are subject to confidentiality obligations.
— Employees and contractors receive security and data-protection awareness training appropriate to their role.
— Access to sensitive systems is granted only as needed for an individual's role and removed promptly upon departure or role change.
10. Sub-processors & Vendor Management
— Third-party sub-processors that support the Service (e.g., hosting, payment processing) are subject to due diligence and contractual security and confidentiality obligations.
— A current list of sub-processors is available to Clients on request.
11. Compliance
— Lift's data processing practices are designed to support Client compliance with the GDPR and applicable Romanian data protection law.
— Where a Client requires a signed Data Processing Agreement or additional security documentation for its own compliance program, this can be requested from Lift.
12. Responsible Disclosure
If you believe you have discovered a security vulnerability in the Service, please report it to [security email address]. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate it.
13. Changes to This Overview
Our security practices evolve over time. We may update this Security Overview to reflect current measures; it does not by itself create binding contractual commitments beyond those in an executed agreement between Lift and the Client.