Privacy Policy
Last updated: 17 July 2026
This policy explains what personal data we process through the MyStoma mobile app and related services (together, the “App”), why we process it, and what rights you have. The App is intended for dentists, dental students and event organisers.
1. Who we are (the data controller)
The data controller is Lăcătuș Cezar, a natural person acting as the data controller — referred to as “we” or “the operator”. You can reach us at contact@cezarlacatus.com.
2. What data we collect
Account and identity
Your phone number (required — it is the login identifier), name, professional role (dentist, student or organiser), specialty, organisation, and a profile photo if you choose to add one.
Content you create
Community posts and messages, events you create, and reports you submit.
Technical data
App and device version, system logs and IP address (processed by our infrastructure provider), and authentication tokens, which are stored locally on your device.
Analytics and usage data
With your consent, we use analytics and crash-reporting tools (for example Google Analytics for Firebase) to understand how the App is used — screens viewed, actions taken, frequency of use, device type and crash diagnostics. This data is used in aggregate to improve the App, not for cross-app advertising tracking.
How you found us
When you sign up we may optionally ask how you heard about MyStoma (for example a referral, social media or search). Your answer helps us understand which channels we grow through and, in aggregate, measure how effective our promotion is — including via aggregated signals shared with advertising platforms (for example Meta). This answer is optional.
The App does not access your camera, photo library (beyond files you explicitly select), location or contacts. We do not use cross-app advertising tracking (such as IDFA); analytics and promotion measurement happen only with your consent, as described below.
3. Why we use data and the legal bases
We process data under the EU General Data Protection Regulation (GDPR) as follows:
- Providing the service and managing your account — performance of a contract (Art. 6(1)(b)).
- SMS code (OTP) authentication — performance of a contract and our legitimate interest in security (Art. 6(1)(b) and (f)).
- Community, events and news features — performance of a contract.
- Safety, moderation and abuse prevention — legitimate interest.
- Compliance with legal obligations — legal obligation (Art. 6(1)(c)).
- Analytics, diagnostics and measuring our promotion — based on your consent (Art. 6(1)(a)), which you can withdraw at any time in the App settings.
4. SMS authentication
To send you a one-time verification code (OTP), your phone number is processed through our SMS delivery infrastructure. Codes are valid for a short period and then expire.
5. Who we share data with
We share data only with providers that help us operate the App, acting as processors or recipients:
- our SMS delivery provider (for OTP codes);
- our hosting and CDN provider (Cloudflare) — to host and secure traffic;
- our database hosting provider (MongoDB);
- our analytics and crash-reporting providers (for example Google/Firebase) — only with your consent;
- advertising platforms (for example Meta) — which may receive aggregated campaign-measurement signals, only with your consent;
- Apple — to distribute the App through the App Store.
We do not sell your data. We use analytics and advertising measurement only on the basis of your consent, and we do not share your private content (messages, posts) with advertising platforms.
6. International transfers
Some providers may process data outside the European Economic Area. Where they do, we ensure appropriate safeguards are in place, such as the European Commission’s Standard Contractual Clauses.
7. How long we keep data
We keep account data while your account is active and for a reasonable period after deletion, as needed for legal obligations and to resolve disputes. OTP codes expire within minutes. Technical logs are kept for a limited time.
8. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, portability, objection, and to withdraw consent.
To exercise your rights, email us at contact@cezarlacatus.com. You may request deletion of your account and associated data at any time. You also have the right to lodge a complaint with the Romanian Data Protection Authority (ANSPDCP), www.dataprotection.ro.
9. Security
We use reasonable technical and organisational measures, including encrypted transmission (HTTPS), token-based authentication and access controls. No system is completely secure, so we cannot guarantee absolute security.
10. Minors
The App is intended for dental professionals and students and is not directed at anyone under 18.
11. Changes to this policy
We may update this policy from time to time. We will indicate the “last updated” date, and significant changes will be communicated in the App.
12. Contact
Lăcătuș Cezar · Email: contact@cezarlacatus.com.