Legal
Privacy policy
How nexam GmbH processes personal data when you use the Dentcloud website and platform, in accordance with the GDPR.
1. Controller
- Company
- nexam GmbH
- Address
- Wilhelm-Hauff-Straße 74
30880 Laatzen
Germany - info@dentcloud.ai
- Data protection officer
- To be added
2. Hosting and data location
The Dentcloud platform and this website are hosted on Microsoft Azure in Germany. All personal data is stored and processed within the EU/EEA. Data is encrypted in transit (TLS) and at rest (AES-256).
3. Data collected when visiting the website
When you visit this website, the browser on your device automatically sends information to our server, which is stored temporarily in a log file: IP address, date and time of access, name and URL of the retrieved file, referrer URL, browser type and operating system. Legal basis is Art. 6 para. 1 lit. f GDPR; our legitimate interest is the smooth operation, security and stability of the site. Log data is deleted automatically after a short retention period.
4. Early access form
If you submit the early access form, we process the data you enter (name, laboratory name, email address, platform selection, case volume, message) to handle your request and contact you about early access. Legal basis is Art. 6 para. 1 lit. b GDPR (pre-contractual steps). We delete this data as soon as it is no longer required for this purpose. It is not used for unrelated marketing and not passed on to third parties.
5. Case and patient data in the platform
For laboratories using Dentcloud, we act as a processor (Art. 28 GDPR) on your behalf. Case data and scan files synchronised from connected scanner platforms are processed exclusively for order handling, stored isolated per organisation, and accessible only to users you invite. A data processing agreement is concluded with every customer.
6. Cookies
We use only technically necessary cookies required to operate the site and keep you signed in (Art. 6 para. 1 lit. f GDPR). We do not use analytics, advertising or cross-site tracking cookies, so no cookie consent banner is required.
7. Data sharing
Your personal data is only transferred to third parties if this is necessary for contract performance, if a legal obligation exists, or if you have expressly consented. Processing takes place exclusively in the EU/EEA.
8. Data security
We use TLS encryption for all connections and appropriate technical and organisational measures to protect your data against manipulation, loss, destruction and unauthorised access. Our security measures are continuously improved in line with technological developments.
9. Retention and deletion
We retain personal data only as long as necessary for the purposes described or as required by statutory retention obligations. Customers can request export or deletion of their workspace data at any time.
10. Changes to this privacy policy
This privacy policy is current as of July 2026. We reserve the right to amend it with effect for the future as our website and platform evolve.
11. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Access to your personal data (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure of your data (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing (Art. 21)
- Withdrawal of consent given (Art. 7 para. 3)
- Complaint to a supervisory authority (Art. 77)
To exercise any of these rights, contact us at info@dentcloud.ai
The competent supervisory authority is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover.
Note: this page is a template. The final privacy policy must be reviewed by legal counsel and completed with hosting, processor and cookie details before going live.