Privacy Policy

Information on Data Processing Related to Controller Activities

This Privacy Policy has been issued by the data controllers specified in Section I (hereinafter: the “Controller”) for the purpose of providing data subjects with the most important information regarding data processing in connection with the services provided, in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”).


I. Data Controller Details

Data processing is carried out jointly by the following controllers:

Brilliant Fogászat Kft.
Registered office: 1139 Budapest, Fiastyúk utca 24/d, door 164
Clinic address: 1134 Budapest, Kassák Lajos utca 39
Company registration number: 01-09-292448
Tax number: 25848894-1-41
Represented by: Dr. Bernadett Katona
Phone: +36 30 329 8564
Email: fogaszat@brilliantdent.hu
Website: www.brilliantdent.hu

Dr. Bernadett Katona (sole proprietor)
Registered office: 1139 Budapest, Fiastyúk utca 24/d, door 164
Tax number: 60412830-1-41
Phone: +36 30 329 8564
Email: fogaszat@brilliantdent.hu
Website: www.brilliantdent.hu


II. Definitions (according to GDPR)

  • Personal Data: any information relating to an identified or identifiable natural person
  • Processing: any operation performed on personal data (collection, storage, modification, etc.)
  • Controller: the entity determining the purposes and means of processing
  • Processor: the entity processing data on behalf of the controller
  • Data Subject: the individual to whom the data relates (e.g. patient)
  • Consent: freely given, specific, informed and unambiguous indication of wishes
  • Health Data: personal data related to physical or mental health

III. Rights of the Data Subject

The data subject has the right to:

  • access their personal data
  • request correction (rectification)
  • request deletion (erasure)
  • request restriction of processing
  • data portability
  • object to processing
  • object to automated decision-making
  • seek legal remedy

Contact:
Email: fogaszat@brilliantdent.hu
Phone: +36 70 535 6466

Supervisory Authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9–11


IV. Source of Personal Data

Personal data is primarily collected directly from the data subject.

If a patient provides data of another person, they are responsible for obtaining that person’s consent.


V. Automated Decision-Making

The Controller:

  • does not carry out automated decision-making
  • does not perform profiling

VI. Applicable Legislation

  • GDPR (EU 2016/679)
  • Hungarian Act CXII of 2011 (Infotv.)
  • Hungarian Civil Code
  • Accounting Act
  • VAT Act
  • Healthcare-related legislation

Data Processing Activities

1. Appointment Booking and Contact

Purpose: scheduling appointments and communication
Data processed: name, phone number, email address, dental complaint
Legal basis: contract
Retention: until the appointment date


2. Healthcare Treatment

Purpose: examination, treatment, and documentation
Data processed: personal and health data
Legal basis: legal obligation
Retention:

  • 30 years (general records)
  • 50 years (final reports)
  • 10 years (imaging data)

3. Treatment Plan

Purpose: informing the patient about treatment options
Data processed: name, email, social security number (TAJ), medical issue
Retention:

  • up to 6 months if not used
  • otherwise part of medical documentation

4. Provision of Healthcare Services

Purpose: providing healthcare services and fulfilling contractual obligations
Data processed:

  • identification data
  • contact data
  • health data
  • X-rays and photographs

Retention: 30–50 years


5. Billing

Purpose: financial accounting
Data processed: name, address, service details
Legal basis: legal obligation
Retention: 8 years


6. Photographic Documentation

Purpose: documentation and presentation (e.g. website, social media)
Data processed: non-identifiable photos (teeth, mouth area)
Legal basis: consent
Retention: until consent is withdrawn


7. Complaint Handling

Purpose: investigation and handling of complaints
Data processed: name, contact details, complaint details
Retention: 5 years