1. Who is responsible?
Frölundatandläkarna AB, company registration number 556764-4728, is the data controller for personal data processed in the clinic and through this website.
- Clinic and visiting address: Frölunda Torg, 421 42 Västra Frölunda
- Registered address: Näverlursgatan 38, 421 44 Västra Frölunda
- Email: reception@vftandlakarna.se
- Phone: 031-47 95 25
2. Data we process
Depending on how you contact us and which care you receive, we may process:
- identity and contact details, including name, personal identity number, phone number and email;
- appointments, communications, reminders and administrative notes;
- health information required for safe dental care, including medical history, diagnoses, treatment plans, images, X-rays, prescriptions and patient records;
- payment, dental-care support and insurance information; and
- technical information needed for website security, privacy choices and service logs, and — only with your consent — pseudonymous, aggregate website statistics. Analytics uses random browser identifiers and a one-way abuse-prevention network hash that changes each UTC day; the raw IP address is not stored in the analytics database.
Please do not include sensitive health information in an ordinary email or callback request.
3. Why and on what legal basis?
We process data to provide and document safe dental care, identify patients, manage appointments and reminders, administer payments and dental-care support, communicate with you, meet statutory requirements, defend legal claims and protect our systems.
Processing is based, as applicable, on performance of a contract, legal obligations, tasks and obligations in healthcare, and legitimate interests in secure administration. Health information is processed where necessary for healthcare under Article 9(2)(h) GDPR and Swedish healthcare legislation, including the Patient Data Act. A callback request is processed on the basis of your consent, which you may withdraw before the request has been handled.
4. Patient records and confidentiality
Healthcare providers must keep patient records. Access is limited to people who need the information for their work, and healthcare confidentiality applies. You may ask to read your record and request that an incorrect or misleading entry is corrected or supplemented. A provider cannot simply delete information that must remain under the Patient Data Act. Applications to destroy a record are handled by the Health and Social Care Inspectorate, IVO, where statutory conditions are met.
5. Online booking and BankID
The online-booking button opens an external service at 2873.etand.se. Information you enter there is processed to identify you and manage the appointment, then relevant booking information is made available to the clinic. If BankID is offered, BankID and your issuing bank process identification data under their own privacy notices.
Always check which organisation you identify yourself to in the BankID app. The clinic will never ask you to disclose your BankID security code.
7. How long is data retained?
- Patient records are retained for at least ten years after the final entry, and longer where required or justified by law.
- Accounting records are normally retained for at least seven years.
- Callback details are deleted when the request has been handled, normally within 30 days, unless the information must become part of care administration or a patient record.
- Security and service logs are retained only as long as necessary for security, troubleshooting and legal requirements.
- Any direct-marketing data is retained until you object, withdraw consent or the purpose no longer applies.
8. Your rights
Depending on the processing, you may request access, correction, deletion, restriction, portability or object to processing. You may also withdraw consent at any time without affecting earlier lawful processing. These rights are not absolute: patient-record and accounting law may require information to be kept.
Contact the clinic first so we can investigate. You may also lodge a complaint with the Swedish Authority for Privacy Protection, IMY, at imy.se.
9. Security and incidents
We use access control, confidentiality obligations, secure systems, backups, logging and supplier requirements appropriate to the sensitivity of health information. If a personal-data incident is likely to create a risk, it is handled and reported in accordance with GDPR. No internet service can promise absolute security, so use phone or an agreed secure channel for sensitive matters.
10. Children and guardians
Dental care for children may require information about both the child and a guardian. The child’s maturity, confidentiality, consent and the guardian’s responsibilities are assessed under applicable healthcare law.
11. Changes to this policy
We update this notice if our services, suppliers or legal duties change. The current version and update date are always published on this page.
Frölundatandläkarna AB
Questions about personal data, privacy or these terms can be sent to reception@vftandlakarna.se or raised by phone on 031-47 95 25.
