InpeDent Fogászati Stúdió
This privacy notice is a reviewed, detailed version of the practice’s earlier statement, aligned with how the website and the practice actually work. Effective: 11 September 2026. Cookies are described in the cookie notice; the treatment relationship is described in the Terms (ÁSZF).
For InpeDent Dental Studio the protection of personal data of patients, enquirers and website visitors is essential. This notice is given under Articles 13 and 14 GDPR and the Hungarian Privacy Act: it explains what personal data we process, for what purpose, on what legal basis, for how long, with whom we share them, and what rights you have.
Please read it carefully. It is available before you send the contact form, request an appointment or start treatment. Questions: info@inpedent.hu or at the practice.
The controller is a sole trader. Appointing a data-protection officer is generally not required under Article 37 GDPR for an individual dental practice; we have not appointed a DPO. Privacy requests are handled at the contacts above by the representative or a colleague they designate.
Dentists, a dental hygienist and dental assistants work at the practice. They access only the data they need for their task, under confidentiality and the Provider’s instructions.
Processing follows in particular:
We process personal data only to the extent needed for the purpose, lawfully, fairly, transparently, accurately and for a limited time (Article 5 GDPR). Special-category (health) data are also governed by Article 9 GDPR and the stricter Eüak. rules.
Personal data means any information that identifies you directly or indirectly (name, contact details, TAJ number, an IP address on its own, a photograph, health data related to treatment).
You are a data subject in particular if you:
We process data of a person under sixteen on the website only with a legal representative. Care for a person under eighteen needs the representative’s consent; see the Terms.
The following are the operations that actually occur at the practice and on the website. We do not list activities we do not carry out (for example a newsletter database, card acceptance, health-fund settlement, a web account). If the operation expands, we update this notice.
Purpose: receiving an enquiry, appointment or quote request, and calling you back.
Data: name (how we may address you), phone number (required), email (optional), topic, message, the fact and time of consent / acceptance of the Terms. The form checks that the phone number has 9–15 digits. The site offers topic suggestions (booking, toothache, quote, check-up, whitening, dentures / implants); you may also write freely.
Legal basis: your consent (Article 6(1)(a) GDPR). If the enquiry becomes contractual negotiation, further contact is a step prior to a contract (Article 6(1)(b)).
Source: you. Storage: the practice’s closed internal system (the site’s own form handling), not a public form service.
Retention: until we have answered, then — if you do not become a patient — for as long as needed to establish or defend a claim, typically at most 3 years. If you become a patient, the data may form part of the records in 4.3.
Purpose: the same as 4.1: appointment, information, callback.
Data: calling number, name given when you introduce yourself, email address and content, requested time, a short description of the complaint if you give one.
Legal basis: steps prior to a contract (Article 6(1)(b)), or legitimate interest in answering the enquiry (Article 6(1)(f)); if you give health details, 4.3 also applies.
Retention: as in 4.1, or as in 4.3 if an appointment is made.
Purpose: identification, safe professional outpatient care, treatment plan, check-ups, warranty, statutory documentation.
Data: birth name, place and date of birth, address, TAJ number, phone, email; anamnesis (illnesses, operations, medicines, allergies, pregnancy, smoking, bruxism and other risks you disclose); findings; panoramic and intraoral X-rays; intraoral camera and clinical photo documentation; gnathological registration; oral cancer screening; treatment plan and quote; procedures performed (fillings, root-canal treatment, replacements, implants, oral surgery, hygiene, whitening, etc.); check-up notes; laboratory-work data; consent forms.
Legal basis: legal obligation (Article 6(1)(c) GDPR, Eüak., Eütv.); performance of the mandate / treatment contract (Article 6(1)(b)); health care and diagnostics (Article 9(2)(h), Eüak. section 4). Under the Eüak. the intervention cannot start without the data required for it.
Access: the treating dentist, the dental hygienist, assistants who must take part, and administration indispensable for invoicing and appointments — under medical confidentiality and only to the extent of their task.
Retention: Eüak. section 30 — health records at least 30 years from recording, discharge summaries at least 50 years, imaging 10 years, the report on the image 30 years. After the mandatory period, further retention is allowed only in the cases in the Act; otherwise the file must be destroyed or — if it has scientific importance — transferred to the archive required by law.
Purpose: recording, changing or cancelling Tuesday (08:00–16:00) and Thursday (12:00–20:00) slots, or other times arranged in advance; applying the HUF 25,000 per hour started standby fee if cancellation is late.
Data: name, phone, email, time, planned care, the fact of cancellation or non-attendance.
Legal basis: performance of a contract (Article 6(1)(b)). We may send an email about the agreed time via Google’s email service; Google then acts as a mail / processor-type auxiliary.
Retention: with the treatment file, and until a fee claim becomes time-barred.
On request we also send the treatment plan and quote by email. The email may contain health data. Legal basis: contract (Article 6(1)(b)) and Article 9(2)(h). Please protect your mailbox; ordinary email is not an encrypted channel.
Purpose: issuing invoices, collecting fees, tax and accounting duties. Payment is currently in cash (HUF) or by bank transfer notified in advance.
Data: billing name, address, description of the service, amount, method and time of payment, transfer reference.
Legal basis: legal obligation (Article 6(1)(c), accounting and tax laws) and the contract (Article 6(1)(b)).
Retention: typically 8 years under the Accounting Act.
Official reporting (for example to the tax authority) occurs only in the circle required by law.
Purpose: investigating a complaint or quality objection, minutes, reply, warranty repair.
Data: the complainant’s identity and contact details, the content of the complaint, examination minutes, the decision.
Legal basis: legal obligation (Consumer Protection Act, Eütv., Article 6(1)(c) GDPR), the contract and legal claims (Article 6(1)(b) and (f), Article 9(2)(f) or (h)).
Retention: consumer-complaint records for 5 years under the Consumer Protection Act; warranty papers until the warranty and the claim become time-barred; if the paper is a health record, the Eüak. period applies.
Images may be taken in the practice for security. Actual operation, field of view and retention are set out in the notice and camera policy posted on site. Purpose: protecting the practice, equipment, staff and patients, and recording the circumstances of an accident or offence. Legal basis: legitimate interest (Article 6(1)(f) GDPR), within the Szvtv. Footage is not used for marketing and is not published. Retention: for the short period needed for the purpose, as in the posted policy; commonly a few days unless the policy says otherwise or the footage must be used in an official or legal procedure.
The website is in Hungarian and English. Non-essential cookies and storage on your device need prior consent (Article 6(1)(a) GDPR, Eht. section 155(4)). On the banner, “Accept all” and “Necessary only” are on the same level, one click each; Settings lets you choose by category.
Necessary: ip_consent (180 days, remembers your choice), inpedent_lang (1 year, only if you switch language), and on the private admin area ip_admin_sid. Legal basis: providing the service you requested, not consent.
Statistics (only after consent): first-party measurement — the ip_aid cookie and a log of path (without query string), language and time. We do not store IP address or User-Agent. Nothing is sent to a third party. The same path with the same id counts once within 30 minutes. Retention: 395 days. If a Google Analytics ID is later configured, it also loads only in this category, under Consent Mode v2.
External media: the Google Map on the contact page. Without consent the map does not load; it can still be opened on Google Maps itself.
Marketing: starts only if a Google Ads or Meta Pixel ID is set in the admin and you consent. By default there is none.
Fonts (Inter, Sora) are served from this site; we do not call Google Fonts.
Consent is evidenced by an HMAC-signed receipt (random id, time, categories, version; no IP, name or email) for 24 months. Details: cookie notice. You can change the choice at any time via Cookie settings in the footer.
The website has ordinary links to the Facebook and Instagram pages, not embedded tracking buttons. If you message, comment or review on InpeDent’s page, Meta is controller of that platform. A message that reaches us is handled as an enquiry under 4.2. Meta’s own cookies and ads follow Meta’s notice.
Quotes on the website come from reviews already published or given to the Provider, and may include a name (or part of it). We put a new identifiable review on the website only with the person’s consent. Google reviews appear on Google’s own surface; Google is their controller.
Blog articles are general information and do not collect a reader account. The author may be given as the clinical team (dentists and dental hygienist). Measurement of visits follows 4.9, after consent.
Clinical photos and intraoral-camera images made for treatment are part of care under 4.3, not marketing. Scientific, teaching or Website / social-media presentation needs separate, voluntary consent. Accepting the Terms does not cover this. Consent may be withdrawn; how far an already published, non-identifying item can be withdrawn depends on the nature of the publication; we explain this when we ask for consent.
Dental care requires health data. We use them only for safe treatment, documentation and legal duties. We do not use them for profiling, advertising or automated decisions.
Besides the Eüak. and Article 9(2)(h) GDPR, another Article 9 exception (vital interest, public health, legal claims) arises only if the facts justify it (emergency, official procedure).
Where the law requires it, the Provider may transmit examination, intervention, e-prescription or e-referral data to the Electronic Health Service Space (EESZT). The EESZT operator is an independent controller. You may also reach the documents on the EESZT public portal with Client Gate / DÁP identification.
When an implant is placed, removed or replaced, the data required by law must be sent to the Central Implant Registry, and an implant card must be given if prescribed. The legal basis is a legal obligation (Eüak., Eütv., Article 6(1)(c) and Article 9(2)(h) / (i) GDPR).
We share personal data with a third party only if a law requires it, it is needed to perform the contract, or you have consented. We do not sell data and we do not pass them to external partners for marketing.
Categories of recipients or auxiliaries — always only with the data needed for their task:
The dental laboratory and authorities are typically independent controllers of their own activity. Hosting, the accountant and email are processors or independent controllers under their contracts; where they are processors we conclude an Article 28 GDPR or confidentiality agreement.
We process health records in Hungary and in mandatory registers inside the EEA. We transfer data to a third country only if you allow an embedded Google Map, Google Analytics, Google Ads or Meta Pixel, or we use Google mail to send a confirmation to your email address. Those recipients (Google, Meta) may rely on their own appropriate safeguards (for example standard contractual clauses). Without the map and tracking codes the website remains readable and the practice remains reachable.
For transfers to the United States the recipient may be certified under the EU–US Data Privacy Framework, or may use Commission-approved contractual clauses. Details are in Google’s and Meta’s own notices.
| Data / processing | Period |
|---|---|
| Health records | at least 30 years (Eüak.) |
| Discharge summary | at least 50 years |
| Imaging (X-ray, etc.) | 10 years; the report 30 years |
| Invoices, accounts | 8 years |
| Contact form if no treatment follows | until answered, then typically max. 3 years |
| Consumer-complaint register | 5 years |
| Camera footage | short period in the posted policy |
ip_consent | 180 days |
inpedent_lang | 1 year |
ip_aid and first-party view log | 395 days |
| Cookie-consent receipt | 24 months |
If several periods apply to the same data, we keep the longer statutory one.
We use technical and organisational measures so that data are protected against unauthorised access, loss, alteration and disclosure. Only colleagues with checked access rights can reach our systems, and only the volume of data their task requires. We store data securely, log access where the system allows it, and review our measures. The website uses HTTPS. Cookie receipts are protected by an HMAC signature.
Please also protect your own device and mailbox when you contact us electronically. Do not send passwords or card numbers by email; we do not ask for them.
If a personal-data breach is likely to result in a high risk, we notify NAIH within 72 hours and you without undue delay, where Articles 33–34 GDPR so require.
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR). We do not profile for marketing. The first-party view log does not identify you by name or IP address.
Under Articles 15–22 GDPR — with the Eüak. and Eütv. variations for health data in 4.3 — you may:
Inspection of health records and a copy are also due under the Eütv.; the first copy is free. Access to a deceased person’s data follows the relatives’ order in the Eüak. / Eütv.
To exercise your rights write to info@inpedent.hu or contact us in the practice. We may ask you to identify yourself so that we do not release data to someone else. We handle the request without undue delay and at the latest within one month; in a complex case we may extend this by two further months under the GDPR and we tell you within one month. The first information is free. For a repetitive, manifestly unfounded or excessive request we may charge a reasonable fee or refuse under Article 12(5) GDPR.
If you believe processing breaches the law, you may complain to the National Authority for Data Protection and Freedom of Information (NAIH) or go to court (regional court; in the capital also the Budapest-Capital Regional Court).
For patients’ rights questions the Integrated Legal Protection Service (IJSZ) and the locally competent patients’ rights representative may also act: ijsz.hu, green number +36 80 620 055, email ijsz@ijsz.bm.gov.hu.
We update this notice if the law or our operation changes. The current version is always on the website; we draw attention to a material change on the website or in the practice. Cookies and consent are described in the cookie notice; the treatment contract is described in the Terms; the provider and hosting details are in the legal notice.
Budapest, 11 September 2026
InpeDent Dental Studio
Dr Péter Incze, sole trader