Privacy Policy
TERMS AND CONDITIONS, PRIVACY POLICY, COOKIE POLICY AND ARTIFICIAL INTELLIGENCE TRANSPARENCY
One policy, two capacities: for the data you create in your own account, Perioskoup is the data controller; for the clinical records your dentist or clinic uploads about you, the dentist or clinic is the controller and Perioskoup acts as their processor — see Part II, Section 2. Dentists: your own account and practice data are covered by the Dentist Data Notice, the Dentist Terms and the Data Processing Agreement.
Last updated: 4 August 2026
This page publishes Part II (Privacy Policy), Part III (Cookie Policy) and Part IV (artificial intelligence transparency). Part I (Terms and Conditions for Users) and Part V (compliance with the app stores) are published on the Terms of Service page.
PART II — PRIVACY POLICY
1. The controller and contact details
The controller of your personal data is Perioskoup SRL, with its registered office in Buzău, strada Victoriei nr. 20, CUI 52008589. You may contact us for any data protection matter at privacy@perioskoup.com. The processing of data is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and with Legea nr. 190/2018 [Romanian Law No. 190/2018 implementing the GDPR].
2. Perioskoup's roles
Perioskoup acts in two distinct capacities. For the data you generate in your own account (account data, oral hygiene habits, conversations with the AI assistant, usage data), Perioskoup is the controller, and this policy applies to you in full. For the data uploaded about you by the dentist or by the clinic (records, medical histories, medical documents, treatment plans), the controller is the dentist or the clinic, and Perioskoup acts as a processor, on the basis of a processing agreement in accordance with Article 28 GDPR. For that data, requests concerning your rights are to be addressed to the dentist or to the clinic, and we provide them with the support necessary to respond to you.
3. The data we collect
- identification and account data: surname, first name, e-mail address, password (stored exclusively in encrypted form, as a hash), connection code;
- oral health data provided voluntarily: hygiene habits, information entered in the application or communicated to the AI assistant;
- data concerning use of the application and technical data: actions within the application, device type, technical identifiers, error diagnostic data;
- preference data: personalisation and notification settings;
- billing data, in the case of subscriptions.
4. The purposes and legal bases of the processing
- the provision of the Service, the creation and administration of the account, and operational communications, on the basis of performance of the contract, pursuant to Article 6(1)(b) GDPR;
- the processing of oral health data, including for the personalised recommendations generated with the assistance of artificial intelligence, on the basis of your explicit consent, pursuant to Article 9(2)(a) GDPR and Article 3(1) of Legea nr. 190/2018, given through the mechanism described in section 5;
- usage analysis and the improvement of functionalities, on the basis of the Controller's legitimate interest, pursuant to Article 6(1)(f) GDPR, with a documented legitimate interest assessment and on the basis of pseudonymised data;
- marketing communications, on the basis of consent, pursuant to Article 6(1)(a) GDPR and Article 12 of Legea nr. 506/2004 [Romanian Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector], with the possibility of withdrawal at any time;
- compliance with legal obligations, including tax obligations and obligations of cooperation with the authorities, on the basis of the legal obligation, pursuant to Article 6(1)(c) GDPR.
5. Consent for health data
The processing of oral health data is carried out exclusively on the basis of your explicit consent, obtained through a separate checkbox in the application, distinct from acceptance of the Terms and Conditions and not pre-ticked. We record the moment consent is given, the version of the text accepted and the method by which it is given, with an audit log. A refusal to give consent does not block your access to the functionalities which do not involve health data.
Consent may be withdrawn at any time from within the application, in Settings, the Privacy section, the Health Data option, or by request to privacy@perioskoup.com. Withdrawal does not affect the lawfulness of prior processing and triggers the deletion of the health data from your account within 30 days, with the exception of the data which the law obliges us to retain.
6. Recipients of the data. Sub-processors
For the provision of the Service we use the following providers, with access strictly limited to the data necessary for the role of each:
The up-to-date list of sub-processors — with the role, data categories, processing location and transfer safeguards of each — is published at https://perioskoup.com/legal/subprocessors.
Payments are processed by Stripe, and subscriptions taken out through the Apple and Google stores are processed by Apple and Google, in the capacity of independent controllers. Data may be disclosed to public authorities where the law so requires.
7. International transfers
The data is stored on servers located in the European Union. Certain services involve transfers to the United States, based on the adequacy decision concerning the EU-US data protection framework, for certified providers, or on the Standard Contractual Clauses approved by Implementing Decision (EU) 2021/914, accompanied, where appropriate, by supplementary measures. We periodically verify the compliance of each transfer.
8. Retention periods
- account data: for the duration of the active account and 6 months after the last activity;
- oral health data in your account: for the duration of the active account and no more than 12 months after its termination, or 30 days from the withdrawal of consent or from the deletion request;
- usage and analytics data: no more than 26 months;
- backups: encrypted, with rotation at no more than 90 days;
- billing data: 10 years, in accordance with tax legislation.
The data uploaded about you by the dentist or by the clinic is retained in accordance with their decisions and legal obligations, in their capacity as controllers, including the obligations to archive medical documentation.
9. Your rights
You have the right of access, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, the right to object (Article 21 GDPR), the right to withdraw your consent at any time and the right to lodge a complaint with the ANSPDCP (www.dataprotection.ro).
Requests are to be sent to privacy@perioskoup.com and receive a reply within one month at the latest, with the possibility of an extension by two months in complex cases, with notice to you (Article 12 GDPR). For portability, we make the data available to you in a structured, commonly used and machine-readable format. Deletion of the account can also be carried out directly from the application. The deletion of data may be limited only in the cases provided for by Article 17(3) GDPR, for example in respect of billing data for the duration of the legal retention obligation, in which case we will inform you of the specific legal basis.
10. Data security
The detailed list concerning the security of the application is published and kept up to date at https://perioskoup.com/legal/security.
11. Personal data breaches
In the event of a personal data breach, the Controller will notify the ANSPDCP within 72 hours of becoming aware of it, pursuant to Article 33 GDPR. If the breach is likely to result in a high risk to your rights and freedoms, you will be informed without undue delay, pursuant to Article 34 GDPR.
12. Minors
Information society services offered directly to minors may be used on the basis of the minor's own consent only from the age of 16, pursuant to Article 8 GDPR. The Platform is intended for persons who have reached the age of 18, and accounts for minor patients are created exclusively under the conditions set out in section 5 of Part I, with the explicit and verifiable consent of the parent or legal representative, who exercises the rights provided for by the GDPR on the minor's behalf. Accounts created in breach of these rules will be closed and the data deleted.
13. Automated decisions and profiling
The personalised recommendations generated by artificial intelligence constitute a form of profiling on the basis of oral health data, carried out exclusively with your explicit consent, pursuant to sections 4 and 5. These recommendations do not produce legal effects concerning you and do not similarly significantly affect you within the meaning of Article 22 GDPR: they are indicative in nature, and any element with medical relevance is validated by the dentist. You have the right to obtain human intervention, to express your point of view and to contest automatically generated results. You may disable personalisation entirely from within the application, in Settings, the Privacy section, the AI Personalisation option, in which case you will receive exclusively generic recommendations.
14. Impact assessment
The Controller has carried out, and keeps up to date, a data protection impact assessment (DPIA), pursuant to Article 35 GDPR, having regard to the processing of health data and the use of artificial intelligence systems. The relevant conclusions are made available to the ANSPDCP on request.
15. Updating this policy
This policy may be updated. Material changes will be notified to you through the application or by e-mail. The date of the last update is indicated at the beginning of the document.
PART III — COOKIE POLICY
The website uses cookies for technical functioning and, with your consent, for usage analysis. On your first visit, a consent banner asks for your explicit agreement before the activation of cookies which are not strictly necessary, pursuant to Article 4 of Legea nr. 506/2004. Essential cookies do not require consent. You may change your choices at any time from the website's cookie settings, and cookies can also be controlled from your browser settings.
Disabling certain cookies may affect the functionality of the website. The list is updated whenever the cookies used change.
PART IV — TRANSPARENCY REGARDING THE USE OF ARTIFICIAL INTELLIGENCE
In accordance with Regulation (EU) 2024/1689 on artificial intelligence and with the transparency principle under the GDPR, we provide you with the following information about the use of artificial intelligence in the Platform.
1. The providers and the functions
- Amazon Web Services — generation of oral hygiene recommendations, processing of text documents and transcription of audio recordings;
- Google (Gemini) — artificial intelligence assisted analysis of images and informational support.
2. The data transmitted to the artificial intelligence providers
- the data is pseudonymised before transmission: the name, the e-mail address and the other direct identifiers are removed; the data remains personal data and is protected in accordance with Part II;
- the providers do not use the data to train their own models, by virtue of the contractual clauses concluded with them;
- all transmissions take place over encrypted channels (TLS 1.2 or higher).
3. Safeguards concerning the results
You are informed at the first interaction when you communicate with the conversational assistant based on artificial intelligence. The generated content is visibly marked with the label "AI-generated" and, at the technical level, in a machine-readable format. Artificial intelligence systems may generate errors, which is why the results are exclusively informational in nature, and any element with medical relevance is subject to the manual validation of the dentist before it produces effects. No medical decision is taken automatically by the Platform.