Privacy Policy

1. Data controller

The controller of personal data is LinkConnect Ltd. (Линк Кънект ЕООД), with the data-protection contact listed on the contact page. This policy describes how we process personal data under Regulation (EU) 2016/679 (GDPR).

2. What data we collect

For patients: name, email, telephone, age group, appointment preferences and an optional short note. For students: identification and verification data, including proof of student status. We do not require — and ask you not to enter — a national identification number, medical history or diagnoses.

3. Purposes and legal bases

We process data to: provide the service (performance of a contract), ensure security and prevent abuse (legitimate interest), meet accounting obligations (legal obligation), and run analytics where consent has been given.

4. Retention

Your account data is kept while your account is active; you can delete it at any time from your settings, upon which your data is deleted or anonymized. We apply the following periods: appointment and visit records (including free text) are anonymized after up to 24 months; patient–student messages are kept for up to 24 months; dental X-rays are deleted 6 months after upload (see “Dental images and health-related data”); notification logs for 12 months; audit logs for 24 months; analytics data for 14 months. Accounting data is kept for the statutory periods. After the applicable period, data is deleted or anonymized. Waitlist signups (email and any telephone number) are deleted within 30 days of the alert being sent, or 12 months from signup if no match occurs.

5. Recipients

We use processors for hosting and the database, the payment provider (Stripe) for student subscriptions, an email delivery provider, Google (Google Analytics) for web analytics, and Sentry for technical error monitoring. Google Analytics loads ONLY if you have consented to analytics cookies; the IP address is anonymised and the advertising-profiling features (Google Signals and ad personalisation) are switched off. If you have consented to marketing cookies, we also use the Meta advertising pixel to measure the results of our advertising. In respect of the data it collects, we and Meta Platforms Ireland Limited act as joint controllers. The page address, IP address, browser information and a cookie identifier are transmitted to Meta, together with a “registration completed” event. We do NOT transmit to Meta any name, email address, telephone number, complaint, tooth information, X-ray or other health data. We do not sell personal data.

6. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP). You can export your data and delete your account from your settings.

7. Security

We apply technical and organizational measures: encrypted connections (TLS), an authorization check on every request enforced in the application, signed expiring links for verification documents, an audit log of administrative actions, an access log for X-ray images, and the principle of least privilege. Files are stored outside the site’s public directory and are not reachable by direct URL.

International transfers

Google Analytics data may be transferred to Google servers in the United States. The transfer takes place on the basis of the European Commission’s standard contractual clauses and the EU–US Data Privacy Framework, under which Google is certified. Data collected through the Meta advertising pixel is processed by Meta Platforms Ireland Limited and may be transferred to servers in the United States on the same bases. Both are collected only with your consent, and you can withdraw it at any time from “Cookie settings” at the bottom of every page. Technical error data (Sentry) is processed on servers in the European Union (Germany) and does not leave the EU. Hosting, the database and file storage are located in the EU.

Dental images and health-related data

When sending a request, patients may choose to upload dental X-ray images (radiographs) and to describe their complaint. Such information can reveal data concerning health, which is a special category of personal data under Article 9 GDPR. We process it ONLY on the basis of your explicit consent, and solely to let the specific student you contact pre-assess your case before offering one of their limited faculty appointment slots. X-rays are stored outside the site’s public directory, with strictly restricted access and a log recording every time one is opened; they are shared only with the student to whom you send the request, are never made public, and are deleted automatically 6 months after upload, as well as at any time on your request. Providing an X-ray is always optional.

Telephone number for waitlist alerts and contact

If no student matches your search, you can join a waitlist with your email. A telephone number is required to join: a student reaches you by phone, not by email. We hold it because it is necessary to send you the alert you asked for, and we record when it was given. Waitlist alerts themselves are currently sent by email. We use the number to alert you by SMS or Viber message if we add those channels, and to contact you about your own request — by message or by telephone — where something about it needs an answer we cannot get by email. We do not use it for marketing, we do not sell it, and we do not pass it to students or to anyone other than the provider that delivers the message. You may withdraw consent at any time, and ask us to delete your waitlist entry including the number, using the contact details in this policy. We delete the entry, including the number, within 30 days of sending your alert, or within 12 months of signing up if no suitable student ever appears — whichever comes first.

Children's data

If the patient is under 18, the form asks for their exact age, their first name (optional) and how their previous dental visit went. All three are given by the parent or guardian submitting the request and are processed on the basis of their consent. The age is necessary because it determines whether the case can be taken on by a paediatric dentistry student at all; the name exists only so you can tell your own requests apart if you bring more than one child; and the answer about the previous visit helps the student judge whether they can take the case before offering an appointment. We do not ask for or store a national identity number, an address, or any other data about the child. These three fields are visible only to the students the request is routed to, and they are erased together with the rest of the request when you ask for it to be erased. A UniDent account is created by an adult — the platform is not intended for independent registration by anyone under 18.