Privacy policy
Version: August 2026
1. Controller
[FIRMA EINTRAGEN], [STRASSE + HAUSNUMMER EINTRAGEN], [PLZ EINTRAGEN] [ORT EINTRAGEN], [LAND EINTRAGEN] — Email: [E-MAIL EINTRAGEN], Phone: [TELEFON EINTRAGEN]
2. Overview
Pontiq is a platform for dental laboratories. This policy covers (a) visiting this website and (b) using the platform. Hosting and data processing take place exclusively in data centers within the European Union.
3. Visiting this website
- Server logs: technically necessary data (IP address, time, requested page, user agent) is processed to deliver the site and ensure security (Art. 6 (1) (f) GDPR) and deleted or anonymized after 14 days at the latest.
- Cookies: this website uses only technically necessary storage (e.g. the website assistant's chat history in your browser's session storage). There is no advertising tracking and no analytics or marketing cookies, so no cookie banner is required.
- Contact and demo forms: the data you provide (name, email, optionally phone, lab name, message) is processed to handle your request (Art. 6 (1) (b) GDPR) and deleted once no longer required, subject to statutory retention duties.
- Website assistant (chat): your chat messages are sent to our backend and processed by an AI language model (section 5). The history is stored only locally in your browser session.
4. Using the platform
- Account and contract data (name, email, lab details, roles, billing data) is processed to perform the contract (Art. 6 (1) (b) GDPR).
- Case and order data: content that labs process via the platform — in particular cases from scanner clouds with patient-related information and scan files — is processed by us as a processor under Art. 28 GDPR, exclusively on the instructions of the respective lab. A data processing agreement is concluded with every lab; the lab is the controller of this data.
- Scanner cloud connections: access tokens are stored encrypted.
5. AI features (Mistral AI)
For AI features (case summaries, material/shade extraction, template suggestions, voice feature, website assistant) we use language models from Mistral AI (Mistral AI SAS, France). Processing takes place on servers within the EU under a data processing agreement; inputs are not used to train the models. Only the content required for the respective feature is transmitted.
6. Recipients and processors
We use carefully selected service providers (EU hosting, email delivery, AI processing) under Art. 28 GDPR agreements. No transfers to third countries outside the EU/EEA take place.
7. Retention
Account and contract data for the duration of the contract and statutory retention periods; lab order and document data for the duration of the contract; raw scan files according to the plan-dependent retention period; server logs a maximum of 14 days; assistant chat history only in your browser session.
8. Your rights
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection to processing based on Art. 6 (1) (f) GDPR (Art. 21). Contact: [E-MAIL EINTRAGEN]. You may also lodge a complaint with a supervisory authority (Art. 77 GDPR).
9. Security
We implement technical and organizational measures under Art. 32 GDPR, including TLS transport encryption, encrypted token storage, role-based access control, tenant isolation and regular backups.
10. Changes
We update this policy when the legal situation or our processing changes. The version published on this page applies.