Privacy policy
In effect as of 10/6/2026
Who this policy is for
This policy is addressed to the professional users of LabLink Smile (dental laboratories and their staff, dental surgeons and their teams) and to visitors of the public website. The software is not intended for patients.
Who is responsible for your data
LabLink Smile is a software made available to dental laboratories. Depending on the nature of the data, the roles under the GDPR differ:
- Data entered by a laboratory (practice clients, orders, quotes, invoices, impression files, prescriptions, messages): the laboratory is the data controller. The software publisher acts as a processor, on its instructions, under a data processing agreement (DPA) concluded with each laboratory.
- Account data of users (identity, professional contact details, login credentials, logs, preferences): the software publisher is the data controller.
- Data of prospects and visitors (demo requests, contact and free-trial forms): the software publisher is the data controller.
Contact details of the data controller
For the processing it is responsible for, the data controller is FBN — 85 allée de l'Aiguebelle, 84320 Entraigues-sur-la-Sorgue — contact@lablink-group.com.
Data processed by the publisher and purposes
For the processing it is responsible for, the publisher collects:
- Professional account data (last name, first name, professional email, phone, role, affiliated laboratory or practice, login credentials): to create and manage your account, secure access and perform the subscription contract. Legal basis: performance of the contract.
- Sign-in with Google (optional) (first name, last name, e-mail address and account identifier sent by Google, only if you choose "Continue with Google"): to identify you without a password. We receive neither your Google password, nor your contacts, nor any other data of your Google account, and keep no access token. Google handles the authentication under its own privacy policy. You can unlink your Google account at any time from your security settings. Legal basis: performance of the contract.
- Subscription billing data (the laboratory's billing details, amount, date and status of payments): to bill the subscription and meet accounting obligations. Payments are processed by a secure payment provider; the publisher never stores card numbers. Legal basis: performance of the contract and legal obligations.
- Login and activity logs (timestamps, actions performed, IP address and the country derived from it): for security, traceability, evidence and alerts (unusual sign-in, repeated attempts, mass export). Legal basis: legitimate interest.
- Demo and contact requests (name, email, phone, laboratory, message): to answer your request, organise a demonstration and handle the resulting follow-up. Legal basis: pre-contractual measures and legitimate interest.
Data processed on behalf of laboratories
The data each laboratory records in the software (practice clients, orders, quotes, invoices, impression files, prescriptions, messages) is processed on its behalf and on its instructions, the software's features constituting those instructions. It is segregated per laboratory: no laboratory can access another's data. The publisher undertakes not to disclose it to anyone, not to use it for commercial, statistical, prospecting or product-development purposes, and not to derive any advantage from it, including in aggregated or anonymised form.
Access by the publisher's staff
The publisher's staff does not access a laboratory's data in the ordinary operation of the software. Access only occurs for assistance requested by the laboratory, the diagnosis or correction of an incident, or a legal obligation, and only to the extent necessary. Only individually authorised persons, bound by a confidentiality obligation, may do so. Every access is flagged on screen throughout the intervention and logged with a timestamp and the person's name; this log can be provided to the laboratory on simple request.
No identifiable patient data
The software is designed to process no data that could directly identify a patient. The patient reference for orders and quotes is an anonymised code chosen by the practitioner or the laboratory, who undertake never to include a name or any identifying detail. Impression files, photographs and prescriptions are health data relating to the practitioners' patients: the practitioner and their laboratory are the controllers of that data, and patients exercise their rights with their practitioner, who remains their point of contact.
Recipients and processors
Account data is accessible to the user's affiliated laboratory or practice and to the FBN team for support and maintenance. It is neither sold nor rented. It may pass through our technical subcontractors (hosting, transactional email delivery, payment provider), bound by confidentiality commitments compliant with the GDPR. The list of sub-processors involved in laboratories' data is set out in the data processing agreement concluded with each of them.
Retention periods
- Account data: for the duration of the subscription contract or of the account, then for the applicable statutory limitation periods.
- Data entered by laboratories: periods defined contractually with each laboratory and by the regulations applicable to medical devices and accounting records. At the end of the subscription, an export is made available to the laboratory before deletion (reversibility).
- Demo and contact requests: as long as needed to handle the request and the resulting commercial follow-up.
- Sign-in and security logs: 12 months, then automatic deletion.
Cookies
LabLink Smile only uses cookies strictly necessary for the service to work: a session cookie to keep you signed in, the storage of your language preference and, during a sign-in with Google, a 15-minute temporary cookie that ties Google’s answer to your browser. No advertising, analytics or social-network cookies are set. These essential cookies do not require prior consent.
Security
Exchanges with the service are encrypted (HTTPS), passwords are stored in hashed form (never in plain text), data is segregated per laboratory with role-based access control, files are only accessible through authenticated routes, and regular encrypted backups are performed. In the event of a data breach likely to result in a risk, the publisher informs the laboratories concerned and, where applicable, the CNIL within the regulatory deadlines.
Data processing agreement (DPA)
A data processing agreement, compliant with Article 28 of the GDPR, is concluded with each subscribing laboratory. It specifies the categories of data processed, the security measures, the sub-processors, the conditions of support access and what happens to the data at the end of the contract. It is provided to each laboratory upon subscription and available on request from the publisher.
Your rights
In accordance with the GDPR and the French Data Protection Act, you have rights of access, rectification, erasure, restriction, objection and portability over the data for which the publisher is the controller. To exercise them, write to us at contact@lablink-group.com. You may also lodge a complaint with the CNIL, the French data protection authority (cnil.fr).
For data entered by a laboratory in the software, send your request to that laboratory, which is the controller; the publisher assists it in handling your request.