Documents
Privacy policy
1. Data controller
The controller of your personal data is Indywidualna praktyka lekarsko-dentystyczna lek. dent. Wojciech Kresta, registered business address ul. Łabędzia 20, 72-002 Kościno, Polish tax identification number (NIP) 8571904621, REGON 381673353. Contact: wojciech@kresta.pl.
The kresta.pl website represents Wojciech Kresta's individual dental practice. Any collaboration with dental facilities in Szczecin (Stettin) is conducted on a B2B basis and does not change the data controller named above.
2. Purposes and legal bases of processing
- Replying to inquiries received through the contact form or by email - Article 6(1)(f) of the GDPR (legitimate interest of the controller in responding to a sender) and Article 6(1)(b) GDPR (steps prior to entering into a possible service relationship).
- Provision of dental services, where a treatment relationship is established - Article 9(2)(h) GDPR in conjunction with Polish patient rights and healthcare legislation.
- Compliance with legal obligations (accounting, medical records, regulatory reporting) - Article 6(1)(c) GDPR.
- Publication of patient feedback submitted voluntarily through the website - Article 6(1)(a) GDPR (consent).
3. Contact form data
The contact form collects your full name, email address, the topic you select, the message text, and your reply-format preference. This data is used only to reply to your message. The form does not accept file uploads. Please do not send full medical documentation before I ask for it; if your case requires detailed assessment, I may ask for additional information or diagnostic images in a separate written exchange.
4. Special category (medical) data
Personal data revealing health information is treated as a special category under Article 9 GDPR. The contact form is not intended for the routine submission of medical data. If you choose to include health-related information in a message, it will be processed only for the purpose of responding to your inquiry and assessing the scope of a possible consultation. Please avoid sharing sensitive medical details until they are needed.
5. Email communication
Email is the primary contact channel. Standard email is not end-to-end encrypted in transit between most providers; please bear this in mind when describing your situation. If a secure channel is required for documentation exchange, it will be agreed separately.
6. Cookies and analytics
The website uses strictly necessary cookies for session handling. Analytics or marketing cookies, if introduced, will be loaded only after explicit consent through a cookie banner. No third-party tracking is active by default.
7. Retention
Inquiry data sent through the contact form is retained for the time needed to respond and to keep a record of the exchange, after which it is deleted. Medical documentation arising from an established treatment relationship is retained for the statutory period required by Polish patient rights law (currently 20 years).
8. Recipients of data
Data may be processed by service providers acting as processors on the basis of a data processing agreement (for example: hosting, transactional email delivery). No personal data is sold or shared with third parties for marketing purposes.
9. Your rights
- Right of access, rectification, and erasure (subject to medical record retention).
- Right to restriction of processing, objection, and data portability.
- Right to withdraw consent at any time - without affecting processing carried out before withdrawal.
- Right to lodge a complaint with the Polish supervisory authority - President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl).
10. Contact about data
Questions about data processing can be sent to wojciech@kresta.pl.
11. Language of communication
English-language contact through this website is handled by form or email. This website does not provide telephone booking in English. Written communication with the controller is available in Polish or English.