Who is responsible for your data
The controller is Vojtech Gazi, operating under the Dent Solution name and using the business address below. For privacy questions or to exercise a data-protection right, email gazivojtech@inbox.eu.
- Controller
- Vojtech Gazi, trading as Dent Solution
- Business address
- 46 Greyfriars Road, Exeter, EX4 7BS, United Kingdom
- Country of legal establishment
- United Kingdom
- Legal form
- Sole trader
- Company registration
- Not applicable — unincorporated sole trader
- Telephone
- +44 7462 226631
- gazivojtech@inbox.eu
If Dent Solution intentionally offers products to people in the EEA and Article 27 EU GDPR applies, an EEA representative must be appointed and identified here unless an exemption is validly documented.
Personal data we process
Depending on how you interact with us, this may include:
- identity and contact data, such as name, email, telephone and clinic or company details;
- order, invoice, payment-status, refund, booking and course-access data;
- clinic-marketing information you submit for a diagnostic or strategy session;
- messages, support requests, feedback and records of our communications;
- technical and security information, such as IP address, browser, device and access logs; and
- marketing preferences and records showing when consent was given or withdrawn.
We receive this information directly from you, automatically through the website and hosting infrastructure, or from the checkout, payment, booking or course provider used for your transaction.
Contact-form information is collected directly from you through our own website endpoint and transmitted to FormSubmit (formsubmit.co), which forwards the submission to our Inbox.eu mailbox. The website and hosting infrastructure may also process the technical request data needed to deliver and protect the form, such as IP address, browser information, date and time, and security logs.
Do not submit patient names, contact details, photographs, medical records, treatment histories or other information that identifies a patient. Our marketing audits and consultations are designed to work with aggregated or properly anonymised clinic information.
Why we process data
| Purpose | Data | UK GDPR legal basis |
|---|---|---|
| Respond to a contact-form, product or service enquiry | Name, email, optional telephone and clinic details, message, and necessary form-security metadata | Article 6(1)(b) where you ask us to take steps before entering a contract; otherwise Article 6(1)(f), our legitimate interest in receiving and answering genuine business enquiries |
| Process an order and supply a course, diagnostic or session | Identity, contact, order, booking, access and service inputs | Article 6(1)(b), contract |
| Take payment, issue a refund and manage transaction evidence | Billing details, payment status and transaction identifiers | Article 6(1)(b), contract; Article 6(1)(c) where financial records are legally required |
| Maintain invoices, tax and accounting records | Identity, business and transaction data | Article 6(1)(c), legal obligation |
| Protect the website, accounts and services from misuse | IP address, device, access and security logs | Article 6(1)(f), legitimate interests in service security and fraud prevention |
| Send optional marketing communications | Email, preferences and consent record | Article 6(1)(a), consent, unless a specific lawful customer exception applies |
| Use non-essential analytics or tracking | Online identifiers and usage data | Article 6(1)(a), prior consent |
| Handle complaints or legal claims | Relevant orders, service records and communications | Article 6(1)(c) where required; otherwise Article 6(1)(f), establishment or defence of legal claims |
Where we rely on legitimate interests, we consider the necessity and impact of the processing and do not use that basis where your rights and freedoms override our interest. You may object as described below.
When information is required
Information marked as required at checkout or in a service form is needed to enter into or perform the contract, provide access, arrange delivery or meet a legal requirement. Without it, we may be unable to accept the order or provide the requested service. Marketing and non-essential cookie consent are optional and refusing them does not prevent a purchase.
On the contact form, your name, email, selected area of interest and message are required so that we can understand and respond to the enquiry. Telephone, clinic name and clinic website are optional. If you do not provide the required fields, the form cannot be sent.
Who receives personal data
We disclose only the data reasonably needed to:
- website hosting, infrastructure, security and access-control providers;
- FormSubmit (formsubmit.co), which transmits the contact form to our mailbox and states that it temporarily retains submissions;
- SIA INBOKSS, Latvia, which operates the Inbox.eu email service used to receive and answer enquiries;
- checkout, payment and refund providers identified during the transaction;
- course delivery, email, booking and video-meeting providers used for the selected product;
- professional legal, tax and accounting advisers where necessary; and
- public authorities where disclosure is required by law.
A provider may act as our processor under documented instructions or as an independent controller for its own regulated functions, such as payment processing. The relevant checkout or service interface identifies the provider and links to its own privacy information where required.
FormSubmit’s public privacy notice and Inbox.eu’s privacy policy provide additional information about those services. Do not submit patient or health information through the contact form.
The final public version must name the actual hosting, checkout, payment, email, booking, video and course-platform providers after those services have been selected and their processing terms verified.
International transfers
Some technology providers may process data outside the United Kingdom. Before such a transfer is used, the destination, recipient and legal mechanism must be verified. Where required, the transfer will rely on UK adequacy regulations, the UK International Data Transfer Agreement or UK Addendum with appropriate supplementary measures, or another lawful safeguard. If the EU GDPR also applies, an EU adequacy decision, Standard Contractual Clauses or another EU safeguard will be used as required. You may request information about an applicable safeguard by email.
SIA INBOKSS states that its email servers are located in Latvia. FormSubmit’s public information does not identify a UK-only processing location, so its processing may involve a country outside the United Kingdom or EEA. Where a restricted transfer occurs, an applicable UK or EU transfer mechanism and supplementary measures must be used. If you prefer not to use FormSubmit, you may contact us directly by email or telephone.
How long we keep data
| Record | Planned retention |
|---|---|
| General enquiries that do not become a contract | 12 months after the last meaningful contact |
| Temporary copy held by FormSubmit | 30 days, according to FormSubmit’s published documentation |
| Diagnostic or session working materials | 12 months after delivery, unless needed for an unresolved complaint or you request earlier deletion where applicable |
| Contract, order and complaint records | For the contract and applicable limitation period, ordinarily 3 years after completion or final resolution |
| Invoices and records required by tax or accounting law | For the applicable UK statutory period—commonly at least 5 years after the relevant tax-return deadline for a sole trader, or the period required for the confirmed legal form |
| Security and access logs | According to the verified hosting/security settings and no longer than necessary for security, incident response or a legal claim |
| Marketing consent | Until withdrawal; a minimal suppression record may remain as needed to honour the withdrawal |
At the end of the relevant period, data is deleted or irreversibly anonymised unless continued retention is legally required. These periods must be aligned with the settings of every operational provider before public launch.
Your data-protection rights
Subject to the conditions and limits in the UK GDPR and Data Protection Act 2018, you may:
- request access to and a copy of your personal data;
- correct inaccurate or incomplete information;
- request erasure or restriction of processing;
- receive data you provided in a structured, commonly used, machine-readable format where portability applies;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- withdraw consent at any time, without affecting earlier lawful processing; and
- lodge a complaint with a competent supervisory authority.
Where the EU GDPR applies because Dent Solution offers products to people in the EEA, the corresponding EU GDPR rights also apply. Send a request to gazivojtech@inbox.eu. We normally respond within one month. Where the applicable law allows an extension, we will explain it within the initial period. We may request proportionate information to confirm your identity.
Automated decisions
The current website does not make solely automated decisions that produce legal or similarly significant effects. Any future AI-generated marketing audit is intended as informational support and will not determine a legal right, eligibility or access to a service. This notice will be updated if that changes.
Security
We use technical and organisational measures appropriate to the nature of the data and the risks of processing, and require relevant providers to protect data within their roles. No internet transmission or storage method can be guaranteed completely secure. If you believe data has been exposed, contact us promptly.
Complaints about data protection
First, you may submit a data-protection complaint to Dent Solution by emailing gazivojtech@inbox.eu. We will acknowledge it within 30 days and respond without undue delay, in line with the Data (Use and Access) Act 2025.
You may also complain to the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom; telephone 0303 123 1113. Use the ICO data-protection complaint service. If the EU GDPR applies, you may also complain to a competent EEA supervisory authority, particularly in the country of your residence, work or the alleged infringement.
Changes to this notice
We will update this notice when our processing or legal obligations change, publish the new date above and provide an additional notice where a material change requires it.
Legal framework
This policy is designed around the following official legal and regulatory materials. Mandatory consumer rights always prevail.