Before publication, the website owner must confirm the full legal name and address of the operator, its registration data, the actual location of database storage, the list of contractors, deletion terms, and the status of Roskomnadzor notifications, including cross-border data transfers. Until then, the document cannot be considered a final legal policy.
1. General Provisions and Operator Details
This Policy was developed in accordance with Federal Law No. 152-ФЗ of July 27, 2006 'On Personal Data' and applies to data processing on the dental center's website.
Pre-designated operator: Dental Center of Heihe First People's Hospital.
- Address: China, Heilongjiang Province, Heihe City, Central St., 230.
- Contact regarding data issues: heihe1.ru@yandex.ru.
- Phone: +7-914-048-76-66.
- Full legal name, registration number, and details of the Russian representative/coordinator: require completion by the website owner.
If the Russian coordinator independently determines the purposes and means of processing requests, they may also act as an operator or joint operator. Their details and allocation of responsibility must be added prior to the start of commercial processing.
2. What Personal Data Is Processed
Data provided directly by the user
- name;
- phone number;
- preferred contact method;
- text of the inquiry and other information voluntarily specified in the comment;
- x-rays, medical records, and health information — only if the user separately submits them to the coordinator after initial inquiry.
Technical data
- form submission date and time;
- hashed network address to protect against abuse and limit request rate;
- browser and device type (User-Agent);
- secure session identifier and CSRF protection token.
Do not include diagnoses or detailed medical history in the free comment field of the form. A separately agreed secure channel must be used for medical information and X-rays.
3. Purposes, Data Categories, and Legal Grounds
| Goal | Data | Preliminary grounds | Planned duration |
|---|---|---|---|
| Response to request and consultation organization | Name, phone number, contact method, comment | User consent; actions upon request prior to contract conclusion | Until communication is completed, then up to 3 years to confirm inquiry history |
| Preliminary assessment of the dental task | Scans, reports, health information | Separate explicit consent for special categories of data | Until the purpose is achieved or consent is revoked, unless storage is required by law |
| Website security and spam prevention | Address hash, User-Agent, request time, session data | Legitimate interest of the operator and the necessity of secure service operation | Session data — until the end of the session; application log — according to the approved regulations |
| Traffic analysis and website improvement | Online identifiers, device and browser information, approximate location, viewed pages, and anonymized interface events | Prior user consent | Analytical cookies — up to 180 days; data in Google Analytics 4 and Yandex.Metrika — according to periods set by the operator |
| Compliance with legal requirements and protection of rights | Inquiry data and service logs | Operator duties and protection of legitimate interests | Within the period established by law or the statute of limitations |
Marketing mailings must not be sent based on feedback consent. Advertising requires separate, specific, and voluntary consent.
4. Processing Actions and Methods
The operator may collect, record, systematize, accumulate, store, clarify, retrieve, use, provide to specific recipients, block, delete, and destroy data using automated means and, if necessary, without them.
Data is not published or disclosed to an unspecified circle of persons. Automated decisions that generate legal consequences for the user are not made on the website.
5. Cookies and Similar Technologies
In its current version, the website uses necessary session technologies for form operation, CSRF protection, and abuse prevention. They are not intended for advertising or cross-site tracking.
- Essential cookies: maintain a secure session and are not disabled via the banner, as individual site features will not work without them.
- Preference cookie:
heihe1_cookie_consentstores the selected option for up to 180 days so that the website does not request a decision on every visit. - Analytical cookies: upon consent, Google Analytics 4 may set
_gaand_ga_<identifier>for up to 180 days to distinguish visits and compile statistics. - Yandex technologies: upon consent, Yandex.Metrica may use cookies
_ym_*and localStorage entries for visit statistics. The same selection includes loading an external Yandex Business rating widget.
Until "Allow analytics" is selected, external Google Analytics 4 and Yandex.Metrica tags are not loaded, and the Yandex Business rating widget does not create a request to Yandex. Google permissions for advertising, ad user data, and ad personalization always remain rejected; Google Signals is disabled.
Page address and title, technical characteristics of the browser and device, approximate location, and interaction events without name, phone number, application text, and medical information may be transferred to analytics. When loading the widget, Yandex may receive technical data of the request and use its own cookies under its own terms. You can change your decision via the 'Cookie settings' link in the footer. Upon revocation of consent, further analytics are blocked, the external widget is disabled, and analytical cookies available to the site as well as Yandex.Metrica records are deleted; previously transferred information is not deleted automatically.
6. Storage, Updating, and Destruction
Data is stored no longer than required by the stated purposes, law, or the need to protect rights. Upon achieving the purpose or revoking consent, data is subject to deletion or destruction unless there is another legal basis for storage.
Before launching the website, the owner is required to approve actual retention periods for each information system and configure technical deletion of requests. The current file-based request handler does not contain an automated deletion scheduler.
When collecting data of Russian Federation citizens via the Internet, the operator must verify compliance with requirements for primary recording, systematization, accumulation, storage, clarification, and extraction using databases located within the Russian Federation.
7. Recipients and Cross-Border Transfer
Within the scope of the purpose, data may be received by authorized employees of the operator, a Russian-speaking coordinator, attending physicians, the hosting provider, and technical contractors maintaining the website. The messenger selected by the user processes data under its own terms.
If the user has enabled analytics and an external widget, technical and statistical information may be received by Google as the provider of Google Analytics 4 and Yandex as the provider of Yandex.Metrica and the Yandex Business widget. Prior to launch, the operator must verify contractual terms, actual processing locations, and applicable cross-border transfer requirements for each provider.
For preliminary treatment assessment, information may be transferred to China to the dental center staff. Such transfer is cross-border. Before it begins, the operator is required to conduct a legally prescribed assessment, identify recipients and protection measures, and check the necessity of notifying Roskomnadzor.
Health information belongs to a special category. Its transfer for medical evaluation should occur only after separate notice and obtaining proper consent or if another applicable basis exists.
8. Rights of the Data Subject
The user has the right to receive information about the processing of their data, request its clarification, blocking, or destruction, revoke consent, and appeal the operator's actions in Roskomnadzor or court.
The request must allow identification of the applicant and the data to which it pertains. The operator reserves the right to request reasonable proof of identity to prevent disclosing information to an unauthorized person.
Revocation of consent does not affect the lawfulness of processing based on consent before its withdrawal. Some data may continue to be stored if expressly required by law.
9. Security Measures
The operator must implement legal, organizational, and technical measures corresponding to the nature and risks of processing: access control, logging of actions, secure transmission, data backup, software updates, contractor oversight, and incident response procedures.
No method of transmission over the Internet guarantees absolute security. The user should not send medical documents via open or unapproved channels.
10. Inquiries and Policy Amendments
Write to heihe1.ru@yandex.ru with the subject "Personal Data". Specify the nature of the request and contact details for a response.
The policy may be updated when processes, contractors, or legislation change. The new version takes effect from the date of publication, unless a different period is specified therein.

