Last updated: 30 September 2026.
1. Controller
“NPS DENT” Ltd. (ЕНПИЕС ДЕНТ ЕООД). Company registration number (ЕИК): 206283984. Address: Тракия, Блок 1, Вход Г, Апартамент 12, Пловдив България. Contact: nps-dent@nps-dent.com, +359 886 998 394. Main website: https://nps-dent.com.
2. Data and purposes
Depending on the functions used, data includes name, telephone, email, delivery address, business/invoice details, requests/orders, correspondence and technical information. Purposes include receiving and confirming requests, contact, delivery, accounting, complaints, statutory duties and security. The website does not collect bank card details. We collect only data necessary for the purpose. A Bulgarian personal identification number (ЕГН) is not collected without a specific legal basis. Personal data is not sold. A separate consent checkbox is not required for processing necessary to handle a request or perform a contract.
3. Legal bases
Receiving and confirming a request relies on steps taken at your request before a contract and, if concluded, performance of the contract (GDPR Article 6(1)(b)). Accounting and other mandatory records rely on legal obligations (6(1)(c)). Security, abuse prevention and legal claims may rely on legitimate interests (6(1)(f)), subject to balancing your rights and interests. Consent, where required for optional cookies or marketing, is requested separately (6(1)(a)).
4. Recipients
Authorised people handling your request have access. Necessary data is shared with hosting, technical support and company email providers, the accountant and the selected carrier: SPEEDY, ECONT or Geniki Taxydromiki. Where payment is by bank transfer, the banks involved also process payment data. Competent authorities receive data where legally required. Recipients act according to their applicable roles and obligations. We do not use an external CRM or newsletter service for these requests. Do not include patient data or other sensitive information in request notes.
5. International transfers
Where a service involves personal data transfers outside the European Economic Area, the requirements of GDPR Chapter V apply: an adequacy decision or appropriate safeguards where required. You may request information about recipients, processing locations and applicable safeguards using the controller’s contact details above.
6. Retention
Requests that do not result in a sale are kept for up to 12 months from the last communication about them. Routine customer service correspondence is kept for up to 24 months after the matter is closed. Data is then deleted or anonymised unless specific records are needed for a legal obligation or to establish, exercise or defend legal claims. Completed sales, invoices and accounting records are subject to applicable statutory retention periods; for complaints or disputes, only necessary records are retained until resolution and expiry of relevant claim periods. Active customer account data is kept to maintain the account; you may request closure, without overriding mandatory retention of particular records. Technical logs are retained only while necessary for security and investigating specific incidents. These periods apply to records in the website and company email.
7. Your rights
Subject to legal conditions, you have rights of access, correction, erasure, restriction, portability and objection. You may object to direct marketing at any time. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Erasure does not override mandatory legal retention.
8. Exercising rights
Send your request to nps-dent@nps-dent.com with sufficient detail to identify the relevant record. If there is reasonable doubt about identity, necessary additional verification may be requested. The normal response period is one month. Complexity or multiple requests may allow two additional months, with notice during the first month. Requests are normally free, subject to statutory exceptions for manifestly unfounded or excessive requests.
9. Supervisory authority
You may complain to the competent supervisory authority. In Bulgaria: Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, https://cpdp.bg, email kzld@cpdp.bg. Follow the authority’s current filing and signature requirements.
10. Required fields and automation
Required fields are needed to receive and process the request; without them the form cannot be submitted. Notes are optional unless model details are necessary. A person confirms the request. Automated emails and calculated totals do not automatically accept a sale. If profiling or other significant automated processing is introduced, the policy must be updated in advance.
11. Cookies, security and changes
Optional cookie choices are separate from accepting the terms and can be changed in Cookie settings. See the cookie policy for current categories. Access is limited according to need and appropriate technical and organisational safeguards are used. Do not send card or patient details. Material changes require an updated policy and fresh consent where necessary. Last updated: 30 September 2026.