Privacy Policy
This policy explains how PROTECH SOLUTIONS LTD, Israeli company 516280435, registered at 1 Almazera, Mi'ilya 2514000, Israel (“Dental Solutions”, “we”), handles personal data when you use ds-implant.com, the Dental Solutions mobile applications, customer support and related services. We are the controller for the activities described here. The service is intended for dental professionals, clinics and laboratories, not patients or children.
What we collect
- Account and identity data — name, email address, profession, organization, country, language preference, consents and account-security records.
- Social sign-in data — when you choose Google, Facebook or Apple, we receive the provider account identifier and the profile information you authorize, such as name or verified email. We do not receive the provider password.
- Order and support data — shipping and billing details, order history, invoices, delivery records, returns and messages you send to us. Our payment provider handles full card details; we may retain its payment token and limited display information such as brand and last four digits, but not the full card number or security code.
- Loyalty data — wallet transactions, membership tier, credits, and cashback history.
- App, device and security data — IP address, browser, device and app information, sign-in sessions, push-notification token and preferences, request logs, crash context and security events needed to operate and protect the service.
- Optional analytics data — if you enable Analytics, pages and product categories viewed, product, search, cart and checkout interactions, purchase and refund events, browser and device information, approximate country-level location, and pseudonymous visit identifiers.
Where the data comes from
Most data comes directly from you or your use of the service. We also receive data from identity providers you select, payment and delivery providers, and anti-fraud or security signals. To preserve customer continuity, eligible account, address, wallet and order records from the previous Dental Solutions platform may be imported through a controlled read-only integration and matched primarily by normalized email address and verified legacy identifiers.
How and why we use data
We use data to provide your account and cart, fulfil and deliver orders, process payments and refunds, operate the loyalty program, provide support, prevent fraud and abuse, meet legal and accounting duties, and send service messages such as order confirmations and shipping updates. Where applicable, these uses are necessary to perform our contract with you, comply with law, or pursue our legitimate interests in operating and securing the store.
Marketing communications and optional analytics are used only with your consent. You can withdraw that consent at any time without affecting processing that occurred before withdrawal.
Social sign-in and connected accounts
Social sign-in is optional. We use the provider credential to verify identity and link the provider identifier to your Dental Solutions account. Apple may supply a private relay address and generally supplies a name only on the first authorization. When you unlink a provider or delete your account, we remove the link and, where technically and legally required, request revocation of the corresponding authorization. The provider may retain its own records under its privacy notice.
Mobile applications and notifications
The applications use the same account and commerce systems as the website. If you allow push notifications, Apple Push Notification service or Firebase Cloud Messaging receives a device token and the information needed to route the message. We store notification preferences and delivery status. You can disable push permission in the device settings and adjust optional notification categories in your account.
Google Analytics and cookies
If you enable Analytics in our privacy choices, we use Google Analytics 4 through the Google tag and, for consented order and refund measurement, Google Analytics Measurement Protocol. Google processes this analytics data for us under the Google Analytics terms and data-processing terms. Pseudonymous client and session identifiers may associate an order or refund with the same consented store visit.
We do not send Google Analytics card details, names, email addresses, shipping or billing addresses, support or form contents, precise location, or patient, clinical, or health data. Analytics is off by default: no Google Analytics tag is downloaded and no analytics event is sent to Google before you opt in. You can reject Analytics or change a previous choice at any time through “Manage privacy choices” in the footer. Learn more about how Google uses information from sites and apps that use its services.
Google Customer Reviews
When the Google Customer Reviews program is active, the paid-order confirmation page loads Google's survey opt-in module. To display that choice, the module sends Google the unique order number, the confirmation email address, the two-letter delivery-country code, and the estimated delivery date. If you choose to opt in, Google may email you after that date to ask about your shopping experience.
The module may use cookies or web beacons as described in Google's information-use notice. Participation is voluntary, and declining does not affect the order. We do not provide Google Customer Reviews with card details or patient, clinical, or health data.
Who receives data and international transfers
We disclose only what is needed to providers that support the service, including Vercel for application hosting, Neon for managed database infrastructure, Cloudflare for stored media and delivery, PayPlus for payment processing, selected carriers for fulfillment, email and support delivery providers, Apple and Google for mobile delivery, and Google, Apple or Meta when you choose their sign-in service. Google receives analytics or Customer Reviews data only in the circumstances described above. A provider is used only when the corresponding feature is configured.
We may also disclose data to professional advisers, a lawful successor to the business, or public authorities where legally required or necessary to establish, exercise or defend legal claims. We do not sell personal data. We do not use patient, clinical or health data for advertising, and you must not submit patient-identifiable information through the service.
Some providers process data outside your country. Transfers are protected through applicable adequacy decisions, contractual commitments or other legally recognized safeguards. Israel is the primary business jurisdiction; European Economic Area data is handled subject to the applicable GDPR transfer rules, and transfers from Israeli databases are handled subject to Israeli transfer requirements.
Retention
We retain account data while the account is active and then delete or de-identify it unless a continuing purpose or legal duty applies. Order, invoice, payment, refund, tax and dispute records are kept for the applicable accounting, tax, warranty, fraud-prevention and limitation periods. Active sessions, device tokens and social links are removed when they expire, are revoked, or the account is deleted, subject to limited security evidence. Optional visit analytics are retained for no more than 395 days and are then deleted; security logs follow separate limited operational periods. Backups age out under controlled retention schedules.
Your rights and choices
Depending on your location and subject to legal exceptions, you may request access, correction, a copy or portability, deletion, restriction, or objection; withdraw consent; and complain to a competent data-protection authority. Israeli law provides rights including inspection and correction of qualifying database information. EEA and UK residents may also object to legitimate-interest processing and contact their local supervisory authority. Where California privacy law applies, residents may request to know, correct or delete covered information and to receive equal service for exercising a right. We do not sell personal data or share it for cross-context behavioral advertising.
You can change marketing and analytics choices, manage connected social accounts, sign out active sessions, and request account deletion in account settings. For another request, use the Contact page. We may verify identity and authority, ask you to clarify the request, and retain information that law requires. An authorized agent must provide evidence of authority. You may appeal an adverse response by replying to it.
Account and social-login data deletion
- Sign in and open Account → Privacy & data to request deletion of the Dental Solutions account. A seven-day cooling-off period lets you cancel an accidental request; after it expires, personal account data is deleted or de-identified, while limited order, invoice, tax, fraud-prevention and dispute records remain only where law or a legitimate continuing obligation requires them.
- To remove only a Facebook, Google or Apple connection, open Account → Security and unlink that provider. The service requires another usable sign-in method before removing the last credential, so you do not lock yourself out.
- If you cannot access the account, submit a request through Contact using the account email where possible and include enough non-sensitive order information for us to verify the request. Do not send passwords, card numbers or patient data.
Removing Dental Solutions from your Facebook settings revokes our future Facebook access. Because the Dental Solutions account may also contain direct purchases and legally retained transaction records, use the steps above if you also want the connected identifier or the full account record removed.
Children and patient data
The service is for professional purchasers aged 18 or over and is not directed to children. We do not knowingly collect children's personal data. The service is not a patient-record system; do not enter patient names, images, health histories or other patient-identifiable clinical information in search, orders, reviews or support messages.
Security
We use technical and organizational safeguards designed for the risk, including encryption in transit, restricted administrative access, authentication controls, audit records, secret management, rate limiting, backups and provider due diligence. No online system can guarantee absolute security. If you believe your account or data is at risk, contact us promptly and change any reusable credentials.
Changes and contact
We may update this notice when practices, providers or legal duties change. Material changes are published as a new version and, where appropriate, brought to your attention. Privacy questions and rights requests can be submitted through the Contact page. The controller is PROTECH SOLUTIONS LTD, company 516280435, registered office: 1 Almazera, Mi'ilya 2514000, Israel. You may also contact the competent supervisory authority, including the Israel Privacy Protection Authority where applicable.