Privacy Policy.
At Flondar ("Flondar", "we", "us" or "our"), we are committed to protecting the privacy of our clients and website visitors. This Privacy Policy explains how we collect, use, store and protect personal data. We apply the standards of the EU General Data Protection Regulation (GDPR) as our baseline globally, and we honor the rights available to residents of the United States and other jurisdictions under applicable law. For US dental practices, where protected health information (PHI) is involved, we operate under HIPAA-aligned controls and sign a Business Associate Agreement (BAA) before any PHI is processed.
Data controller
The party responsible for processing your personal data is:
Personal data we collect
We collect the following categories of personal data:
2.1 — Business contact data
When you request a free analysis or get in touch with us:
- First and last name.
- Name of the dental practice.
- Contact phone number.
- Email address.
- Information about your dental practice management software.
2.2 — Operational data about your practice
To run the free analysis and diagnose your practice's needs:
- Approximate number of monthly appointments.
- No-show rate.
- Average revenue per visit.
- Information about treatment plans sent and close rates.
- Operational problems identified.
- Current appointment confirmation and follow-up methods.
This operational data concerns your practice's business metrics. It does not, by itself, include patient health records. We do not require, and you should not send us, protected health information (PHI) to obtain the free analysis.
2.3 — Website browsing data
- IP address.
- Browser type and version.
- Operating system.
- Pages visited on our website.
- Cookie data and similar technologies (see our Cookie Policy).
- Web analytics information (Google Analytics, Microsoft Clarity).
2.4 — Client data (contracted services)
If you engage our services:
- Billing details (legal entity name, tax ID, billing address).
- Contractual information.
- History of service-related communications.
- Data needed to deploy and operate the system within your practice. Where this involves PHI, it is governed by a separate Business Associate Agreement (BAA).
Purposes and legal basis for processing
We process your personal data for the following purposes. Where the GDPR applies, the corresponding legal basis is indicated; where US state privacy laws apply, processing is limited to the purposes described and disclosed below.
3.1 — Handling requests and sales inquiries
- Respond to free analysis requests.
- Run an operational diagnosis of your practice.
- Present tailored proposals.
- Answer questions and information requests.
3.2 — Providing the service
- Deploy and operate the system in your dental practice.
- Run operational analysis and diagnostics.
- Configure and integrate management tools.
- Provide technical support and follow-up.
- Manage the contractual relationship.
3.3 — Billing and accounting obligations
- Issue invoices and tax documents.
- Comply with tax and accounting obligations.
3.4 — Analytics and service improvement
- Analyze how our website is used.
- Improve our services and methodology.
- Produce aggregated statistical insights.
3.5 — Marketing communications (optional)
Only if you have given your express consent will we send you information about our services, updates and useful content for dental practice management. You can withdraw your consent at any time, and every email includes an unsubscribe link. We do not sell your personal data.
Recipients and international transfers
Your personal data may be shared with the following categories of recipients:
4.1 — Technology service providers
- Google LLC — Google Analytics for web traffic analysis.
- Microsoft Corporation — Microsoft Clarity for website behavior analysis.
- Cloudflare, Inc. — security, bot protection and content delivery.
- Hosting and infrastructure providers.
- Communication platforms (email, video calls) for customer support.
These providers act as our processors under written agreements. Where data is transferred internationally (including to and from the United States and the European Union), we rely on appropriate safeguards such as the EU Standard Contractual Clauses and equivalent mechanisms.
4.2 — Professional advisors
Where applicable, we share data with legal, tax or accounting advisors bound by confidentiality, to meet legal obligations or manage the contractual relationship.
4.3 — Authorities and public bodies
When required by law or to comply with legal obligations, we may share your data with competent authorities, courts or regulators.
Data retention
We keep your personal data for the following periods:
Once these periods elapse, we delete or anonymize your personal data, unless a legal obligation requires us to keep it longer.
Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- Access / Know — confirm whether we process your data and obtain a copy.
- Rectification — request correction of inaccurate or incomplete data.
- Deletion — request erasure of your data when no longer necessary.
- Restriction — request that we limit processing in certain cases.
- Portability — receive your data in a structured format and transmit it to another controller.
- Object — object to processing based on your particular situation.
- Opt out — opt out of marketing and of any "sale" or "sharing" of personal data (we do not sell personal data).
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Non-discrimination — we will not discriminate against you for exercising your rights.
How to exercise your rights
To exercise any of these rights, you can:
- Email a request to privacy@flondar.com.
- Contact us by mail at the address in section 1.
We will respond within 45 days (US) or 1 month (EU) of receipt. For complex requests we may extend this period and will inform you accordingly. We may need to verify your identity before acting on a request.
Right to complain
Security measures
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction or alteration, including:
- Encryption of data in transit via SSL/TLS certificates (HTTPS).
- Secure data storage on protected servers.
- Access controls and authentication.
- Regular backups.
- Confidentiality agreements with service providers, and BAAs where PHI is involved.
- Security incident response procedures.
No security system is completely infallible. We encourage you to take care when sharing sensitive information over the Internet.
Cookies and similar technologies
Our website uses cookies and similar technologies to improve your browsing experience and analyze site usage. For details on which cookies we use, their purposes and how to manage them, see our Cookie Policy.
Children
Our services are directed exclusively to professionals and businesses in the dental sector. We do not knowingly collect personal data from children. If you become aware that a minor has provided personal data without parental consent, please contact us so we can delete it.
Changes to this privacy policy
We reserve the right to amend this Privacy Policy at any time. Material changes will be announced on our website a reasonable time before they take effect. The last-updated date appears at the top of this document. We recommend reviewing this policy periodically.
Contact
For any question, concern or request related to this Privacy Policy or the processing of your personal data, contact us at: