Legal
Imprint & privacy
Last updated: August 2026
Imprint
Empident GmbH
Voglbachlweg 5
85774 Unterföhring, Germany
Represented by the Managing Director: Alexander Knoch
Commercial register: Amtsgericht München (Munich Local Court), HRB 242567
VAT ID pursuant to Sec. 27a of the German VAT Act: DE319411209
Contact: info@empident.de
Contact form: www.empident.de/en/demo-buchen/
Responsible for content pursuant to Sec. 18 (2) MStV: Alexander Knoch, address as above
Consumer dispute resolution: We are neither willing nor obliged to participate in dispute resolution proceedings before a consumer arbitration board (Sec. 36 VSBG).
Privacy Notice (EU) — Empident Care Platform
This Privacy Notice describes how Empident GmbH („Empident", „we", „us") processes your personal data when you use the Empident Care Platform (Empident Care mobile app and dentist dashboard) or access our web pages under the domain www.empident.de. We comply with the EU General Data Protection Regulation (GDPR).
Who is responsible for processing?
Empident GmbH, Voglbachlweg 5, 85774 Unterföhring, Germany. Represented by its Managing Director Alexander Knoch. info@empident.de
What data do we process?
We may collect and process:
Personal Information: name, email address, phone number, postal address, date of birth, contact preferences.
Health Data:
- oral health images and videos
- assessment notes and oral symptoms
- medical history where relevant for dental care
- any inputs or health information entered in our application
Application Data: device information (model, operating system, IP address), crash logs, performance data, session times, in-app behaviour (usage patterns, navigation).
Communication Data: messages, requests or feedback you send to us; feedback from support or usability testing.
Sensitive health data is only processed with your explicit consent or where otherwise permitted by law.
Use of this website
Server log files. When you access the website, your IP address, date and time, the file retrieved, the volume of data transferred, browser type and version, operating system and referrer URL are automatically stored in log files. The purpose is to establish the connection and ensure system security and stability. Legal basis: Art. 6 (1) (f) GDPR. Retention: 7 days, longer only in the event of a security-relevant incident.
Hosting. The website is operated by a service provider with servers located in the EU, which processes the data solely on our behalf under a data processing agreement pursuant to Art. 28 GDPR.
Contact form. Information submitted through the contact form is used solely to handle your request. Legal basis: Art. 6 (1) (b) GDPR for contract-related enquiries, otherwise Art. 6 (1) (f) GDPR. Deleted once your request has been dealt with; statutory retention obligations remain unaffected.
Cookies. We use only technically necessary cookies; no consent is required for these under Sec. 25 (2) no. 2 TDDDG. We do not use analytics, tracking or marketing cookies.
OpenStreetMap map (consent-based). We serve fonts from our own server; there is no connection to Google Fonts. On the contact page we embed a map from OpenStreetMap. It only loads after you have given consent; this establishes a connection to servers of the OpenStreetMap Foundation and transmits your IP address. Without your consent, no connection is made. The legal basis is your consent under Art. 6 (1) (a) GDPR; you may withdraw it at any time with effect for the future.
Why do we process your data and on what legal basis?
- To provide our services and facilitate dental care (e.g. transferring case information to dentists) — Contract performance (Art. 6 (1) (b) GDPR)
- To comply with medical documentation and legal obligations — Legal obligation (Art. 6 (1) (c) GDPR)
- To improve our services, troubleshoot errors and analyse usage patterns for better user experience and safety — Legitimate interests (Art. 6 (1) (f) GDPR)
- To process sensitive health data (e.g. oral images, dental assessments) — Explicit consent (Art. 9 (2) (a) GDPR) or Art. 9 (2) (h) in conjunction with Art. 9 (3) GDPR
Health data is processed for diagnosis or a second opinion where requested by the patient from their treating health professional. Processing takes place by or under the responsibility of persons subject to an obligation of professional secrecy. Our legitimate interest includes ensuring the security, functionality and continuous improvement of our platform.
Who do we share your data with?
Your data may be shared:
- with your chosen dental professional, provided there is a separate service and treatment agreement between you and the dentist. Dentists are bound by professional secrecy under GDPR and local medical laws.
- for second opinions, with your consent or at your request.
- with service providers (e.g. hosting, cloud services) under strict GDPR-compliant data processing agreements (Art. 28 GDPR).
We do not sell your data. Data is stored inside the EU.
No transfers to third countries
Personal data is not transferred to recipients outside the EU or the EEA.
No automated decision-making
Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place. Images and information are not evaluated automatically; the clinical assessment is always made by a dental professional.
Do you have to provide your data?
Providing your data is neither required by law nor by contract. However, without the information marked as mandatory we cannot process your request or your case. No further disadvantage arises for you.
How long do we store your data?
We retain your personal data only as long as necessary:
- for providing services and ensuring medical documentation
- as required by applicable laws; for treatment documentation the ten-year retention period under Sec. 630f (3) of the German Civil Code applies in particular
Afterwards, data is securely deleted or anonymised.
Your rights under GDPR
You have the right to:
- access your personal data
- correct inaccuracies
- request deletion (where lawful)
- restrict processing
- data portability
- withdraw your consent at any time with effect for the future; the lawfulness of processing carried out up to the point of withdrawal remains unaffected
- lodge a complaint with a data protection supervisory authority
Right to object under Art. 21 GDPR: You have the right to object at any time, on grounds relating to your particular situation, to processing based on Art. 6 (1) (f) GDPR. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
To exercise your rights, please contact us at info@empident.de.
Supervisory authority responsible for us: Bavarian Data Protection Authority (BayLDA), Promenade 27, 91522 Ansbach, Germany.
Security
We implement technical and organisational measures to protect your data (e.g. encryption, secure access controls). However, no system is 100% secure, and risks inherent to internet transmission remain. This website uses SSL/TLS encryption.
Contact
If you have any questions or concerns regarding data protection, you may contact our Data Protection Officer: dataprotection@empident.de.