Privacy Policy

Stand: 10/1/2026

The legally binding version of this privacy policy is the German original. This English version is provided for convenience. 1. Controller The controller within the meaning of the General Data Protection Regulation (GDPR) is: Aura Dental Systems GmbH Warschauer Straße 69 10243 Berlin Germany Email: kontakt@halloaura.com You will also find our contact details in our Imprint. 2. Your rights You have the right at any time to: - obtain information about the personal data we hold about you (Art. 15 GDPR), - have inaccurate data corrected (Art. 16 GDPR), - have your data deleted (Art. 17 GDPR), - have processing restricted (Art. 18 GDPR), - receive your data in a structured, commonly used format (Art. 20 GDPR), - object to processing that is based on our legitimate interests (Art. 21 GDPR), and - lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Our competent supervisory authority is the Berlin Commissioner for Data Protection and Freedom of Information. You can withdraw any consent you have given (e.g. for cookies, external content or marketing emails) at any time with effect for the future — via the "Cookie settings" link at the bottom of our websites, via the unsubscribe link in every email, or in your profile in the Pro Portal. Processing carried out before withdrawal remains lawful. You can delete your Pro Portal account and your profile photo yourself at any time (see section 8). For anything else, an informal email to kontakt@halloaura.com is enough. 3. Providing our websites (server log files) When you visit our websites, our hosting provider automatically collects technical information transmitted by your browser: IP address, date and time of the request, page requested, browser and operating system, and the referring page (referrer URL). This is necessary to deliver the website and keep it secure (Art. 6(1)(f) GDPR, legitimate interest) and is deleted automatically after a short time. Our websites are hosted by Vercel Inc. (USA); our database and file storage (Supabase) run in a data centre in Frankfurt am Main (EU). We serve fonts and icons from our own servers. Visiting our websites does not open a connection to Google servers for this purpose. 4. Cookies, local storage and your consent Our websites only use cookies and similar technologies that are strictly necessary for operation or that you have explicitly requested (e.g. your language setting, your cookie choice, your login session in the Pro Portal, and — in the SmartCase portal — your display preference and checklist progress in your device's local storage). These are set without separate consent (Section 25(2) TDDDG, Art. 6(1)(f) GDPR). For all other content that transfers data to third parties or sets cookies (e.g. the Google map in the practice finder), we actively ask for your consent beforehand (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). You can change or withdraw your choice at any time via the "Cookie settings" link. 5. Forms (forms.halloaura.com) When you fill in a form on forms.halloaura.com we process the information you voluntarily enter (e.g. name, email address, answers to questions, uploaded files such as a photo) and the technical data needed to provide the form. Processing is based on your consent (Art. 6(1)(a) GDPR) or, where it serves to perform a contract or pre-contractual measures, Art. 6(1)(b) GDPR — for example to contact you or handle enquiries from dental practices and clinicians. Uploaded files are not stored publicly. 6. Google Maps (practice finder) To display practice locations in our practice finder we use Google Maps, a map service of Google Ireland Limited (or Google LLC, USA). The map is only loaded after your explicit consent. Once loaded, your browser transmits your IP address and possibly other data to Google servers, which may also process data outside the EU. For more information see Google's privacy policy: https://policies.google.com/privacy When you search for a postcode or address in the practice finder, our server converts the search term to coordinates using Google's geocoding service. Only the search term is transmitted, not your IP address. 7. Contact forms, email and telephone If you contact us via a contact form, email or telephone, we process the data you give us (e.g. name, email address, message) solely to handle your enquiry (Art. 6(1)(b) or (f) GDPR). If you leave a voicemail, it is stored and automatically converted to text for handling (speech recognition by OpenAI as processor). Data is deleted once it is no longer needed, unless statutory retention obligations apply. 8. User accounts (Pro Portal, patient portal, SmartCase) Pro Portal (for dentists and practice teams): A Pro Portal account is required. We process account data (title, name, email address, phone number, job title, employment type, practice affiliation), usage and progress data (e.g. Academy progress, exam results, certificates, CME points), orders, invoices and support requests. The legal basis is performance of the user relationship (Art. 6(1)(b) GDPR) or our legitimate interest in secure, smooth operation (Art. 6(1)(f) GDPR). We also send service emails as part of the user relationship (e.g. order confirmations, setup and usage tips for the portal); these are not advertising. Profile photo (optional): You can upload a profile photo. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by uploading and can withdraw at any time by removing the photo. Your photo is stored in our file storage under an unguessable address (URL). The address is not access-protected: anyone who knows it can open the image without logging in. The photo is visible to Aura staff and to patients you treat with an Aura kit (SmartCase portal). On upload we remove metadata (e.g. location and camera data) from the image. If you replace or remove the photo, the old file is permanently deleted from our file storage. Account deletion: You can delete your Pro Portal account yourself at any time under "Profile". We then delete your login, photo and subscription to our email information and anonymise your personal data. We must keep orders and invoices for commercial and tax law reasons (up to 10 years, Section 147 AO, Section 257 HGB); after deletion they are no longer linked to a person. SmartCase portal (for patients): You reach the SmartCase portal by NFC or QR code from your Aura kit. No account is needed. We process the order number belonging to your kit and information you enter in the portal yourself (e.g. your chosen protocol, application dates, consultation answers). This information is linked to the kit's order number, not to your name. Display settings and checklist progress are also stored in your device's local storage. The legal basis is providing the functions you use (Art. 6(1)(b) GDPR). Where you voluntarily give us data that qualifies as health data under Art. 9 GDPR, we process it solely on the basis of your explicit consent (Art. 9(2)(a) GDPR). Scan files for custom kits: When ordering a custom kit, practices upload digital impressions (scans) of the teeth to us. We use these files solely to manufacture the aligner trays; they are not publicly accessible and are deleted when the order is completed. The practice is responsible for obtaining the patient's consent; we process the data on its behalf. 9. AI assistants (chat) On some pages we offer an AI-powered chat assistant. Your messages are sent to our service provider Anthropic PBC (USA) to generate answers. To prevent abuse and for quality assurance we store your question, the answer and a pseudonymised (hashed) identifier of your IP address — not the IP address itself — for up to 12 months. Please do not enter sensitive personal data (e.g. health data) in the chat. The legal basis is providing the service you requested (Art. 6(1)(b) GDPR) or our legitimate interest in preventing abuse and quality assurance (Art. 6(1)(f) GDPR). 10. Camera feature (virtual whitening / AR) If you use the virtual try-on, your browser asks for access to your camera. The camera image and the face detection used to place the effect are processed solely locally in your browser. No images are sent to us or to third parties, and none are stored. The program components required for this are served from our own servers. 11. Webinars When you register for a webinar we process your details (name, email address, where applicable practice and professional group) to run the event, send the registration confirmation, reminders, the access link and — on request — a certificate of attendance (Art. 6(1)(b) GDPR). Your attendance is recorded to issue the certificate. You only receive further information about our products and future webinars if you expressly agreed when registering (Art. 6(1)(a) GDPR). Webinars are held via Google Meet; Google's privacy terms apply in addition. 12. Email information and newsletter If you expressly consent when registering for the Pro Portal, in your profile or when registering for a webinar, we send you emails with relevant information about bleaching, news about our products and tips on getting the most out of Aura (Art. 6(1)(a) GDPR, Section 7(2) no. 3 UWG). Consent is voluntary; you can use the portal in full without it. We record when and where you consented so that we can demonstrate it. We use Mailchimp (Intuit Inc., USA) for sending, which processes your email address, name and details about your profession and language, and can measure opens and clicks. You can withdraw consent at any time with one click via the unsubscribe link in every email or in your profile; we will then remove you from the list. 13. Payments For payments in the Pro Portal (e.g. a kit purchase by staff, the points store) we use Stripe (Stripe Payments Europe Ltd., Ireland, or Stripe Inc., USA). You enter payment details directly with Stripe; we do not receive complete payment details, only the information that payment was made (Art. 6(1)(b) GDPR). 14. Embedded videos (Cloudflare Stream) On some pages we embed videos via Cloudflare Stream, partly as background video. When a video is retrieved, a connection to servers of Cloudflare, Inc. (USA) is established and technical data (including your IP address) is transmitted. This is necessary to deliver the videos to you (Art. 6(1)(f) GDPR). Cloudflare acts as our processor. 15. Audience measurement (Vercel Web Analytics and Speed Insights) We use Vercel Web Analytics and Vercel Speed Insights for anonymised, cookie-free analysis of website use and loading speed (e.g. page views, rough geographic region, device type, load times). No cookies are set, no cross-device profiles are created and no personal identifiers are stored. Processing is based on our legitimate interest in improving our offering (Art. 6(1)(f) GDPR). You may object at any time (Art. 21 GDPR). 16. Recipients and processors We use the following service providers, with each of which a data processing agreement under Art. 28 GDPR exists and which, where they transfer data to the USA, operate on the basis of appropriate safeguards (EU Standard Contractual Clauses or the EU-US Data Privacy Framework): - Vercel Inc. (hosting, web analytics, speed insights) - Supabase Inc. (database and file storage, Frankfurt/EU region) - Resend (email delivery) - Intuit Mailchimp (email information, only with consent) - Anthropic PBC (AI-powered features, e.g. chat assistance) - OpenAI (converting voicemails to text) - Stripe (payment processing) - Google Ireland Limited / Google LLC (Google Maps, only with consent; Google Meet for webinars) - Cloudflare, Inc. (video delivery) - DHL (shipping of orders; we pass name and delivery address to the carrier) 17. Retention We store personal data only as long as necessary for the respective purposes or as required by statutory retention obligations: - Account data and profile photo: until you delete your account or the photo. - Orders, invoices and accounting records: up to 10 years (Section 147 AO, Section 257 HGB), then deleted. - Scan files for custom kits: until the order is completed. - Email information: until you withdraw consent. - Chat logs of the AI assistant: up to 12 months. - Server log files: automatically deleted after a short time. After the purpose lapses or the period expires, data is deleted or anonymised. 18. Data security We use technical and organisational measures to protect your data against accidental or intentional manipulation, loss, destruction or unauthorised access. Transmission is encrypted (TLS); our websites instruct your browser to communicate only over encrypted connections (HSTS). 19. Changes to this privacy policy We update this privacy policy whenever our data processing changes, for example because a new feature processes new personal data. The most recently updated version applies. As of: 1 October 2026

Cookie settings

We only use strictly necessary cookies. Some content requires your consent to load. Privacy policy