This Data Protection and Privacy Statement (the “Privacy Statement”) sets out how we, DENTSPLY SIRONA Inc. (a Delaware, United States corporation with its headquarters at 13320-B Ballantyne Corporate Place, Charlotte, NC 28277 USA) and all of our global affiliates (“DENTSPLY SIRONA” or “we” or "us") handle the personal information that we process when you visit our webpages, purchase a product, enroll in one of our email services, request information, register on the websites, enter one of our contests, participate in a promotion, loyalty or rewards program, use any of the other interactive portions of our websites, communicate with us through social media, by phone, through educational conferences, workshops, or other events, or in connection with an actual or potential business or employment relationship with us (together “data subjects”).
If you have any questions or comments about this Privacy Statement, DENTSPLY SIRONA’s privacy practices, or if you would like us to update information or preferences you provided to us, please contact our Information Officer at:
Our Information Officer’s Contact Details:
Andy Cyprianos
General Manager
Dentsply Sirona South Africa
Email: Andy.Cyprianos@dentsplysirona.com
Mobile: +27 834266596
Web: www.dentsplysirona.com and use the information on the “Contact Us” page.
In South Africa ("South Africa")), “personal information” is defined very broadly and includes any information about an identifiable, living, natural person, and in so far as it is applicable, an identifiable, existing juristic person. Personal information may include information relating to our employees, customers, patients, shareholders, contractors or the staff of our suppliers, visitors to our buildings or website users.
The types of personal information, including special personal information we may hold about you include:
DENTSPLY SIRONA needs to process personal information about you for a variety of purposes. DENTSPLY SIRONA will only process your personal information, in accordance with applicable law, for the following purposes:
In South Africa, the Protection of Personal Information Act No. 4 of 2013 ("POPIA") requires us to have a lawful basis before processing any personal information about you and that we must process your personal information in a reasonable manner that does not infringe your privacy rights as a data subject. The lawful basis for us processing your personal information for the abovementioned purposes may be because: (i) you have provided your consent; (ii) it is necessary for the performance of a contract with you; (iii) the processing is necessary for our compliance with a legal obligation; or (iv) the processing is in our legitimate interests of operating and promoting our business.
To the extent provided in POPIA, you may withdraw any consent you previously provided to us, or object at any time on legitimate grounds, to the processing of your personal information. In some circumstances, withdrawing your consent to DENTSPLY SIRONA’s use or disclosure of your personal information will mean that you cannot take advantage of certain DENTSPLY SIRONA products or services.
We intend to keep your personal information confidential, in compliance with our legal obligations. We do not sell, rent, trade or otherwise disclose personal information to third parties, other than as described in this Privacy Statement, for the purposes described above, or as we disclose to you at the time the information is collected.
We may disclose your personal information in accordance with, and where permitted by, applicable law to our subsidiaries, branches, or associated offices:
DENTSPLY SIRONA takes appropriate physical, technical, and organizational security measures designed to safeguard and secure any personal information you provide to us. Nevertheless, unencrypted transmission to DENTSPLY SIRONA via the internet is not completely secure and we cannot guarantee the security of your personal information during any such unencrypted transmission.
We may disclose or transfer your personal information to a third party situated in countries outside South Africa for further processing in accordance with the purposes set out in section 2 above, in particular your personal information may be transferred throughout the DENTSPLY SIRONA group. In these circumstances we will, as required by applicable law, particularly, section 72 of POPIA, ensure that your privacy rights are adequately protected by organizational, technical, contractual and/or other lawful means.
Your personal information will not be retained for longer than required to fulfil the purpose for which the personal information was collected or for a period of time thereafter as required by applicable local law or where we have a legitimate and lawful purpose.
DENTSPLY SIRONA will, with consent from candidates, retain applications of unsuccessful candidates for a reasonable period after the application process to enable us to contact you if another suitable position arises or to comply with our legal obligations.
In terms of POPIA, you have the right to: access, rectify, erase, restrict and object to the processing of, your personal information. You also have the right to lodge a complaint with the Information Regulator, if you believe that your personal information is not being processed in accordance with the provisions of POPIA. If you would like to exercise any of your rights as a data subject, please contact our Information Officer at Andy.Cyprianos@dentsplysirona.com. To assist us in responding to such requests in a timely fashion, please include the phrase “Privacy Rights Request” in the title of your communication to us.
Complaints and objections
As a data subject, you have the right to –
The Information Regulator
In the event that your personal information has not been processed in accordance with the POPI Act and the principles set out above, you have the right to lodge a complaint with the Information Regulator.
For further information regarding the complaints process, please visit the website of the Information Regulator, as indicated below.
Alternatively, you may contact the Information Regulator for further assistance:
The Information Regulator: Adv Pansy Tlakula
Physical Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
Email: complaints.IR@justice.gov.za
Website: https://www.justice.gov.za/inforeg/index.html
This website may make chat rooms, careers, message boards, and/or news groups available to its users at various times. Please remember that, unless otherwise stated, any information that is disclosed in these areas becomes public information and you should exercise caution when deciding to disclose your personal information in these areas. Do not use these areas to post personal information about third parties or discuss information about specific, identifiable patients.
Our websites may contain links to other websites. DENTSPLY SIRONA is not responsible for the privacy practices or the content of unaffiliated third-party websites.
To help ensure the protection of your privacy, we recommend that you review the privacy policy of any website you visit via a link from our websites.
We may at any time in our sole discretion revise or update this Privacy Statement.
We will indicate at the top of the Privacy Statement when it was most recently updated. All changes are effective immediately when they are posted and apply to all access to and use of the websites thereafter. If you object to any modification, your sole recourse is to stop using the websites and providing us with your personal information.
In order to collect certain information described in this Privacy Statement, we may use cookie technology on our websites.
A cookie is a small text file which is sent to your browser and stored on your computer's hard drive, mobile phone or other device. Session cookies make it easier for you to navigate our websites and expire when you close your browser. Tracking cookies remain longer and help in understanding how you use our websites and enhance your user experience. You can set your browser to notify you when you receive a cookie. This enables you to decide if you want to accept it or not. However, some of the services and features offered through our websites may not function properly if your cookies are disabled.
The following are examples of cookies that may be used on our websites:
Our websites also use social and video plugins such as those provided by Facebook, Twitter, Instagram, LinkedIn, or YouTube.
When you visit a page of our websites that contains a social, video or other plugin, your browser establishes a direct connection to the server for that plugin and provides them with the information that you have accessed on the corresponding page of our websites. If you are logged into that service as well, your visit can be connected to your account with that service. Therefore, if you interact with the plugins, for example by clicking “Like,” or entering a comment, the corresponding information is transmitted from your browser directly to that party. Your interaction with those services is governed by their applicable privacy policy and other policies which can be located on their websites.
When you visit our websites, we may allow some third parties (such as advertising networks and data analytics companies) to collect personal information about your online activities over time and across different websites. For example, session recording tools, record your preferences and track your use of the websites. To find out more about your choices with respect to these tracking technologies, see “Your Choices.”
If you no longer wish to receive promotional emails, you may unsubscribe at any time by clicking the “unsubscribe” link in the promotional emails sent to you or by contacting the Data Protection Contact whose details are provided above. If you have an account with us, you may also unsubscribe from promotional emails through your account. Please note that even if you opt-out of receiving promotional emails from us, we may continue to send you non-promotional emails.
If you have an account with us, you may make changes to your personal information by logging into your account and making changes manually on your account.
If necessary, to comply with applicable law, we will ask for your consent to place cookies on your device. Once your consent has been provided, this consent message will not appear again when you revisit our websites. If you, or another user of your computer, wish to withdraw your consent at any time, you can do so by altering your browser settings or by contacting our Information Officer at Andy.Cyprianos@dentsplysirona.com. You can find more information about cookies at: www.allaboutcookies.org.
Regular cookies generally may be disabled or removed using tools available as part of most commercial browsers, and in some instances blocked in the future by selecting certain settings. Browsers offer different functionalities and options so you may need to set them separately. Also, tools from commercial browsers may not be effective with regard to Flash cookies (also known as locally shared objects), HTML5 cookies or other tracking technologies. For information on disabling Flash cookies, visit:
Please be aware that if you disable or remove these technologies, some part of our websites may not work and when you revisit our websites your ability to limit browser based tracking technologies is subject to your browser settings and limitations. Your browser settings may allow you to automatically transmit a “Do Not Track” signal to websites and online services you visit. However, there is no consensus among industry participants as to what “Do Not Track” means in this context. Like many websites and online services, our websites currently do not recognize when they receive a “Do Not Track” signal from a visitor’s browser. To find out more about “Do Not Track,” visit http://www.allaboutdnt.com.
Purposes for processing
To provide and operate our Services, communicate with you about your use of our Services, respond to your inquiries, gather feedback, fulfill your requests, communicate with you, run our day-to-day operations, and for similar support purposes.
Category of personal information processed
Contact information; professional contact information and details; communications; health information*; account and registration information; and transaction information.
Legal bases for processing
Performance of our contract with you where necessary to fulfill the terms of our contract or agreement, or to take steps leading to such a contract.
Purposes for processing
To manage our business relationship with you, for example, to process your transactions, manage and maintain your account with us, respond to your questions and comments, set up a Dentsply Sirona loyalty program account, allocate a Territory Sales Manager or equivalent to be your dedicated account manager, and for other similar purposes.
Category of personal information processed
Contact information; professional contact information and details; communications; health information*; account and registration information; and transaction information.
Legal bases for processing
Performance of our contract with you where necessary to fulfill the terms of our contract or agreement, or to take steps leading to such a contract.
We have a legitimate interest in organizing our activities efficiently.
Purposes for processing
To evaluate your interest in employment and contact you regarding possible employment with us, to process your application, assess your ability to meet the job specifications, verify references and professional qualifications, monitor recruitment statistics, improve our application process, ensure the security of our premises, assets, information, employees and other personnel, and to comply with legal and regulatory requirements such as health and safety requirements, government reporting requirements, equal opportunity monitoring, and to ensure compliance with our Code of Ethics & Business Conduct.
Category of personal information processed
Contact information; professional contact information and details; and references and assessments.
Legal bases for processing
Performance of our contract with you where necessary to fulfill the terms of our contract or agreement, or to take steps leading to such a contract.
Some of the personal information we collect or process will be pursuant to an EEA, UK or Swiss legal obligation.
Other personal information may be collected on the basis of your consent, in which case you will be informed before the information is collected or processed.
In all other cases, we have a legitimate interest in ensuring our recruiting process effectively meets the needs of our business and the reasonable expectations of individuals who seek employment with us.
Purposes for processing
To administer the promotional programs we offer.
Category of personal information processed
Contact information; professional contact information and details; and profession and educational history and achievements.
Legal bases for processing
Performance of our contract with you where necessary to fulfill the terms of our contract or agreement, or to take steps leading to such a contract.
Purposes for processing
To better understand how users access and use our Services, products, and offerings, and for other research and analytical purposes, such as to evaluate and improve our Services and business operations, to develop Services, features and new products and offerings, and for internal quality control and training purposes.
Category of personal information processed
Preferences; device and browsing information; activities and usage information; and survey responses.
Legal bases for processing
We have a legitimate interest in improving our products and Services to expand our outreach and customer base.
Purposes for processing
To tailor the content that we may send you, including to offer personalized help and instructions, and to otherwise personalize your experience.
Category of personal information processed
Contact information; professional contact information and details; communications; health information*; account and registration information; preferences; device and browsing information; activities and usage information; and location information.
Legal bases for processing
Consent, where required by law (such as where we obtain consent via cookies and other trackers).
In all other cases, we have a legitimate interest in promoting our products and Services in order to expand our outreach and customer base.
Purposes for processing
For marketing, advertising, and public relations purposes. For example, to send you information about our Services and the products and services of our affiliates, such as newsletters, and other marketing content, as well as any other information that you sign up to receive and to provide you with information about, or samples of, our product range for marketing purposes. We also may use certain personal information that we collect to manage and improve our advertising campaigns (both online and offline) so that we can better reach individuals with relevant content based on your interests and geographic region.
Category of personal information processed
Contact information; professional contact information and details; communications; health information; account and registration information; preferences; device and browsing information; activities and usage information; and location information.
Legal bases for processing
Consent, where required by law (such as where we obtain consent via cookies and other trackers or when you opt-in to receive marketing communications from us).
In all other cases, we have a legitimate interest in promoting our products and Services in order to expand our outreach and customer base.
Purposes for processing
For event planning and management, including registration, attendance, connecting you with other event attendees, providing relevant educational opportunities, assisting you with ongoing certification requirements, and contacting you about relevant events and Services.
Category of personal information processed
Contact information; professional contact information and details; training and professional education history; communications; account and registration information; travel details; dietary preferences; and certifications.
Legal bases for processing
Performance of our contract with you where necessary to fulfill the terms of our contract or agreement, or to take steps leading to such a contract.
In all other cases, we have a legitimate interest in providing our customers with meaningful opportunities to engage with us and others in our industry, as well as provide a positive event experience that meets the reasonable expectations of our attendees.
Purposes for processing
To administer surveys, such as for market research, customer satisfaction purposes or improving our Services, to conduct statistical and data analytics, and for other similar purposes.
Category of personal information processed
Contact information; professional contact information and details; device and browsing information; activities and usage information; location information; and preferences.
Legal bases for processing
We have a legitimate interest in improving the relevancy of our Services, products and advertising in order to encourage interactions with us and grow our customer base and financial support.
Purposes for processing
To manage our professional relationship with you; to help promote and influence the adoption of our Services; to keep you updated with relevant information related to your area of expertise; to keep track of the level of interactions the Company has with our KOLs and to build and maintain a community of KOLs; to send informational newsletters; to make informed and objective decisions when identifying which KOLs to engage for research collaboration, clinical trials, patient support programs, involvement in advisory boards or consulting services; and to help assess Fair Market Value when we engage with other KOLs.
Category of personal information processed
Contact information; professional contact information and details; communications and interactions; and social mediation information.
Legal bases for processing
Performance of our contract with you where necessary to fulfill the terms of our contract or agreement, or to take steps leading to such a contract.
Purposes for processing
To protect our Services and our business operations; to prevent and detect fraud, unauthorized activities and access, and other misuse, where we believe necessary to investigate, prevent or take action regarding illegal activities, suspected fraud, situations involving potential threats to the safety or legal rights of any person or third party, violations of our Terms of Use, Code of Ethics & Business Conduct, other applicable policies or other agreements we have with you or this Notice, to defend our rights, including through legal or other dispute resolution processes.
Category of personal information processed
Contact information; professional contact information and details; communications; account and registration information; preferences; device and browsing information; activities and usage information; location information; and transaction information.
Legal bases for processing
We have a legitimate interest in conducting our activities in a lawful manner and protecting our rights and interests as well as those of our stakeholders and society at large.
Purposes for processing
To comply with the law and our legal obligations, for example with respect to internal functions such as accounting, auditing, compliance and recordkeeping, as well as for external purposes, such as to respond to legal process, subpoenas, and related legal proceedings, court orders, national security or law enforcement disclosure requirements, and other lawful requests by regulators and law enforcement.
Category of personal information processed
Contact information; professional contact information and details; communications; health information*; account and registration information; preferences; device and browsing information; activities and usage information; location information; transaction information; and references and assessments.
Legal bases for processing
Legal obligation, where we need to comply with EEA, Swiss or UK law.
In all other cases, we have a legitimate interest in ensuring that our business practices comply with applicable law in the jurisdictions where we operate and do business.
Purposes for processing
To consider and implement mergers, acquisitions, reorganizations, bankruptcies, and other transactions such as financings, and related to the administration of our general business, accounting, auditing, compliance, recordkeeping, and legal functions.
Category of personal information processed
Contact information; professional contact information and details; communications; health information*; account and registration information; preferences; location information; transaction information; device and browsing information; and activities and usage information.
Legal bases for processing
Our legitimate interests in organizing our activities efficiently.
*Unless otherwise noted in a separate privacy notice and consent for a specific type of service, for the noted purpose, we process health information in the course of providing Services to health care professionals, and in doing so we act as a processor and not as a controller.
Where we process your personal information to perform a contract with you or to comply with a legal obligation, the provision of your personal data is compulsory so far as it is either a contractual or statutory requirement, or a necessary requirement to enter into a contract. In such cases, provision of your personal information is mandatory since it would not otherwise be possible to enter and perform our contract with you, or to comply with our legal obligations.
Your Rights in Respect to Your Personal Information. GDPR as well as other laws in the EMEA region allow you to exercise certain rights in relation to the personal information that we hold about you, subject to certain conditions and exceptions. These rights may include:
You can exercise your rights by contacting us using the information set out under “How to Contact Us” below. As noted above, these rights may be subject to specific conditions and exceptions depending on our relationship with you and the legal basis for processing your personal information. Each submission will be evaluated promptly and in accordance with applicable law.
You have the right to submit a complaint with the relevant data protection authority of your habitual residence, your place of work, or the place of the alleged infringement/violation of your rights. This link will redirect you to the European Data Protection Board website with an up-to-date list of all European Economic Area Data Protection Authorities: https://edpb.europa.eu/about-edpb/board/members_en. The UK authority, the ICO, can be reached here: https://ico.org.uk/. The Swiss Federal Data Protection and Information Commissioner can be reached here: https://www.edoeb.admin.ch/.
International Data Transfers. By using our Services, you understand and agree that your personal information is transferred to countries outside of the EMEA region, and notably to the United States. Some of the countries where your personal information is transferred may not provide an adequate level of personal information protection according to your country’s regulatory authorities. We have implemented measures to protect your personal information, including contractual terms such as the European Commission-approved Standard Contractual Clauses and their UK equivalent and the UK International Data Transfer Addendum. You can obtain a copy of these terms by contacting us using the information set out below.
Cookies. Some of our cookies are strictly necessary for the Site to function as intended, while others are not strictly necessary and are designed to optimize your experience, help us understand our users better and for advertising purposes. Your consent is required for the use of non-strictly necessary cookies – we obtain this consent through our pop-up cookie preference manager. You can withdraw your consent at any time using the preference manager or your browser settings. More information about the individual cookies used on the Sites can also be found through the Cookie Settings link in the footer of this page.
Please note the following information in addition to the details provided above:
Collection and processing of sensitive data. For the purposes informed in this Notice, we will process the following personal information that is considered sensitive, and which requires special protection:
Collection of information that is not necessary for the requested services. We may collect and use your personal information for the following purposes that are not necessary for the requested Services, but which allow and facilitate us to provide you with a better service:
In case you do not want your personal data to be processed for these additional purposes, from this moment you can inform us of your preference by sending an email to the Dentsply Sirona Privacy Office at the address privacy@dentsplysirona.com. Refusal to use your personal data for these purposes will not be a reason for us to deny you the services and products you request or contract with us.
We inform you that your personal data is shared inside and outside the country with the following people, companies, organizations and authorities other than us, for the following purposes:
Recipient of personal data
Dentsply Sirona Affiliates & Subsidiaries under common control. A list of Dentsply Sirona companies and their locations can be found here.
Purpose
The Dentsply Sirona Group operates in many countries and shares personal data internally within the DS Group for general business management purposes, to meet customer needs, for regulatory or reporting purposes and other legitimate business purposes.
Recipient of personal data
Service providers such as payment processors, internet service providers, professional consultants and advisors, outsourced services such as IT and/or cloud-based service providers and event management providers
Purpose
We ask third parties to carry out certain business functions for us and disclose your personal data to them so that they can perform those functions on our behalf. These third parties are processors and not controllers.
Recipient of personal data
Distributors, business partners, ad networks, social media*
Purpose
Deliver products and services to our customers in the most efficient way.
Recipient of personal data
Regulators, government and tax authorities, and law enforcement authorities
Purpose
As required by law
Recipient of personal data
Others with your consent or as required by law
Purpose
Based on your consent or our legal obligations
Tacit consent notice (applicable to residents of Mexico): we inform you that for transfers indicated with an asterisk (*) we require your consent. If you do not express your refusal to such transfers, we will understand that you have granted it to us. You may communicate such refusal by email to privacy@dentsplysirona.com.
Your rights as a data subject: How can you access, rectify or delete your personal data, object to its use or exercise other rights?
Data subjects have several rights in accordance with the applicable law in the place where they reside. These rights may include the right to be informed (e.g., through a privacy notice such as this one); the right to know whether your personal data is being processed and, if so, to access the personal data we hold about you; the right to request correction of personal data that is out of date, inaccurate or incomplete; the right to request the erasure of your personal data when you consider that they are not being used in accordance with the principles, duties and obligations provided for in the applicable legislation; as well as to object to the use of your personal data for specific purposes; the right to portability of your personal data to other service providers in a structured and commonly used format; COOI the right to know the public and private entities with which your personal data has been shared; information on the possibility of not giving consent and on the consequences of such refusal; the right to revoke your consent; the right to review decisions based on the processing of personal data by automated means; the right not to be subject to automated decision-making; and the right to lodge a complaint with the applicable regulatory authority for non-compliance with data protection law. To exercise your rights, you can contact our Privacy Department at privacy@dentsplysirona.com. We will process requests to exercise these rights and resolve any questions you may have about the processing of your data.
How can you revoke your consent to the use of your personal data?
You may revoke the consent you have given us for the processing of your personal data. However, it is important that you bear in mind that your withdrawal of consent will not apply retroactively to the processing that took place before the revocation was communicated, and that in all cases we will not be able to respond to your request or terminate the use immediately, as it is possible that due to some legal obligation, we may be required to continue processing your personal data. You should also consider that for certain purposes, the revocation of your consent will mean that we will no longer be able to provide you with Services and/or the termination of your relationship with us.
To revoke your consent, or to learn about the procedure and requirements for revoking consent, you must send your request by email to privacy@dentsplysirona.com.
How can you limit the use or disclosure of your personal information?
In order for you to limit the use and disclosure of your personal information, we make available to you the following means:
A. United States - federal
In certain circumstances, we may collect or use your information through our Services while acting as a “business associate” or “covered entity” under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), which may constitute Protected Health Information (PHI).
A business associate includes an entity that provides services to a HIPAA covered entity that involves the use or disclosure of PHI. If your health care professional or health insurance company qualifies as a HIPAA covered entity, and we provide services to them or on their behalf, we may qualify as their business associate. PHI as defined under HIPAA, generally means information about you that identifies you and that relates to your physical or mental health or condition, the provision of health care to you, or payment for health care provided to you. To the extent we are acting as a business associate, we will only use and disclose your information as permitted by HIPAA, which may include, but is not limited to, fulfilling our service obligations, our internal management and administration, executing our legal responsibilities, de-identifying or aggregating data, or as otherwise required by law.
Where we act as a covered entity under HIPAA with respect to the information we collect from you, our Notice of Privacy Practices, and not this Notice, will apply.
B. U.S. State Law Privacy Disclosures
Sale of Personal Information
While we do not disclose personal information to third parties in exchange for monetary compensation, we may “sell” or “share” the following categories of personal information: identifiers, such as unique personal identifiers, online identifiers, IP address, or other similar identifiers; commercial information; location data; and Internet and network activity information. We may disclose these categories to third-party advertising networks, analytics providers, and social networks for purposes of marketing and advertising and to improve and measure our ad campaigns.
Consumer Rights
Residents of certain U.S. states may have additional rights under applicable privacy laws, subject to certain limitations, which may include:
You may submit a request to exercise most of your privacy rights under U.S. state privacy laws through our webform here or by emailing us at privacy@dentsplysirona.com.
To opt out of targeted advertising by us, you can adjust your cookies settings here (click the link in the footer) or on your device. In addition, our Site responds to global privacy control (GPC) signals, which means that if we detect that your browser is communicating a GPC signal, we will process that as a request to opt that particular browser and device out of sales and sharing (i.e., via cookies and tracking tools) on our Site. Note that if you come back to our Site from a different device or use a different browser on the same device, you will need to opt out (or set GPC for) that browser and device as well. More information about GPC is available at: https://globalprivacycontrol.org/. See Section 6 Cookies and Tracking and Section 7 Your Privacy Choices for more information.
We will respond to your request as required under applicable U.S. privacy law(s). When you submit a request, we will take steps to verify your identity and request by matching the information provided by you with the information we have in our records. In some cases, we may request additional information in order to verify your identity, or where necessary to process your request. If we are unable to verify your identity after a good faith attempt, we may deny the request. If your request is denied, we will explain the basis for the denial.
If we deny your request, in certain jurisdictions you may be able to appeal our decision according to the instructions we provide in our response.
To the extent permitted under applicable U.S. privacy laws, you may also designate someone as an authorized agent to submit requests and act on your behalf. Authorized agents may be required to provide proof of their authorization and we may also require the relevant consumer to directly verify the identity and authority of the authorized agent.
C. California Notice at Collection and Privacy Rights
This Section of the Notice provides additional information for California residents and describes our information practices pursuant to applicable privacy laws, including the California Consumer Privacy Act and the regulations issued thereto, each as amended (“CCPA”). To the extent you are a California resident, and we collect “personal information” subject to the CCPA, the following applies.
This Section does not address or apply to our handling of personal information that is exempt under the CCPA, such as publicly available information or de-identified or aggregated information. Additionally, this Notice does not apply to personal information we collect, receive, or otherwise maintain about you that is primarily governed by certain federal laws, such as HIPAA. The CCPA recognizes that health information subject to HIPAA is already protected under federal law, so the CCPA does not apply to such information.
Categories of Personal Information Collected and Disclosed
The table below identifies, generally, the categories of personal information we collect or process about California residents, as well as the categories of third parties to whom we may disclose this personal information for a business or commercial purpose.
Categories of Personal Information
Includes direct identifiers such as name, alias, email, phone number, address, unique personal identifier, online identifier, IP address, or other similar identifiers.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Includes your account and profile information and customer records that contain personal information, such as name, demographics and other characteristics or descriptions, contact information, and financial or payment information.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Includes records of Services purchased, obtained, or considered, or other purchasing or use histories or tendencies.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Includes browsing history, clickstream data, search history, and information regarding interactions with our Sites and Services, advertisements, or emails, including other usage data related to your use of any of our Services or other similar online services.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Such as general location information about a particular individual or device.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Includes information collected via call recordings if you are interacting with us in a customer service capacity or if you call us on a recorded line, recorded meetings and webinars, videos, and photographs.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Such as inferences drawn from any of the information described in this Section about a consumer including inferences reflecting consumer preferences, characteristics, behaviors, attitudes, abilities, and aptitudes.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
We may collect some information that is considered a protected classification under California or federal law, which may include your gender, age, date of birth, citizenship, marital status, disability status, gender identity or expression, and medical condition.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
In some circumstances, we may collect payment card information and related details, precise geolocation data, racial or ethnic origin, biometric information, and personal information collected and analyzed concerning a consumer’s health. We may also collect your Social Security, driver’s license, or state identification card number.
Third Party Disclosures for Business or Commercial Purposes
Sales and Sharing of Personal Information. The CCPA defines “sale” as disclosing or making available personal information to a third-party in exchange for monetary or other valuable consideration, and “sharing” includes disclosing or making available personal information to a third party for purposes of cross-contextual behavioral advertising. While we do not disclose personal information to third parties in exchange for monetary compensation, we may “sell” or “share” the following categories of personal information: identifiers; commercial information; location data; and Internet and network activity information. We may disclose these categories to third-party advertising networks, analytics providers, and social networks for purposes of marketing and advertising and to improve and measure our ad campaigns. We may also share limited information, such as name and email address, to data brokers for purposes of marketing and advertising and to improve and measure our ad campaigns.
We do not sell or share sensitive personal information, nor do we sell or share personal information about individuals we know are under age sixteen (16).
Sources of Personal Information. We generally collect personal information from the following categories of sources: directly or indirectly from you; affiliates and subsidiaries; business partners; vendors and service providers; government officials; healthcare professionals and dentists; third-party websites and services; data brokers; public databases; social media platforms and websites; internet service providers; operating systems and platforms; and marketing and data analytics providers.
Purposes of Collection, Use, and Disclosure. See Section 3 Purposes for Collecting and Processing and Section 4 Disclosures of Personal information for a description of the business or commercial purposes for which we may collect, use, disclose, and process your personal information.
Sensitive Personal Information. We do not collect, use, or disclose “sensitive personal information” beyond the purposes authorized by the CCPA. Accordingly, we only use and disclose sensitive personal information as reasonably necessary and proportionate: (i) to perform our Services requested by you; (ii) to help ensure security and integrity, including to prevent, detect, and investigate security incidents; (iii) to detect, prevent and respond to malicious, fraudulent, deceptive, or illegal conduct; (iv) to verify or maintain the quality and safety of our Services; (v) for compliance with our legal obligations; (vi) to our service providers who perform services on our behalf; and (vii) for purposes other than inferring characteristics about you.
Retention. We retain the personal information that we collect only as reasonably necessary for the purposes described above or as otherwise disclosed to you at the time of collection. For example, we will retain your account information for as long as you have an active account with us and additional information as necessary to comply with our tax, accounting, and recordkeeping obligations, to provide you with the Services you have requested, as well as an additional period of time as necessary to protect, defend, or establish our rights, defend against potential claims, and comply with our legal obligations. In some cases, rather than delete your personal information, we may deidentify or aggregate it and use it in compliance with the CCPA.
California Residents’ Rights. Under the CCPA, California residents have the following rights (subject to certain limitations):
Submitting CCPA Requests. California residents may exercise their CCPA privacy rights as set forth below:
When you submit a request, we will take steps to verify your identity and request by matching the information provided by you with the information we have in our records. In some cases, we may request additional information in order to verify your identity, or where necessary to process your request. If we are unable to verify your identity after a good faith attempt, we may deny the request and, if so, will explain the basis for denial.
You may also designate someone as an authorized agent to submit requests and act on your behalf. Authorized agents will be required to provide proof of their authorization and we may also require the relevant consumer to directly verify the identity and the authority of the authorized agent.
In addition, if we detect that your browser or device is transmitting an opt out preference signal, such as the GPC signal, we will opt that browser or device out of cookies that result in a “sale” or “sharing” of your personal information. If you come to our Site or use our Services from a different device or from a different browser on the same device, you will need to opt out, or use an opt out preference signal, for that browser and/or device as well. More information about GPC is available at globalprivacycontrol.org.
Notice of Financial Incentive. With respect to some of our Services, we may make available certain programs or offerings, and other sweepstakes, contests, or similar promotional offerings (each a “Program”) which may include certain offers, rewards, discounts, services, perks, and promotions (“Rewards and Offers”). These Programs may be considered “financial incentives” under the CCPA. We provide these Rewards and Offers to participating users in order to understand and improve customer satisfaction and experiences, and to foster positive customer relationships.
As a basis for offering these Rewards and Offers, we have valued the personal information we obtain based on a reasonable and good faith calculation determined by considering expenses related to the Programs. In doing so, we value the personal information collected through the programs as the equivalent of the costs and expenses incurred to provide the program, including IT, administration, direct costs, third party costs, discounts, and Service development costs.
Your personal information is collected and retained, and may be disclosed to our business partners, vendors and service providers, and other third parties, as described in this Notice, including in order (i) to administer the Program, (ii) for research and analytics purposes, (iii) to improve our products and Services, (iv) to better reach you with more relevant, targeted offers, and (v) to send you Company-related news, updates and offers by email and postal mail (in accordance with your communications preferences).
You may withdraw from participating in a Program at any time by contacting us at privacy@dentsplysirona.com. Please note that if you withdraw from a Program (or submit a CCPA request to delete your Program information), your participation in that Program will be terminated, which means that you will no longer be eligible to earn, use, access or redeem any Program Rewards and Offers, subject to the applicable Program terms.
California Shine the Light Rights. California’s “Shine the Light” law (Cal. Civ. Code § 1798.83) permits California residents who provide us certain personal information to request and obtain from us, free of charge, information about the personal information (if any) we have shared with third parties for their own direct marketing purposes. To make a California Shine the Light request, please call 1-800-461-9330 or email us at privacy@dentsplysirona.com. Requests may be made once per year.
This Section of the Notice provides additional information for Canadian residents and describes our information practices pursuant to applicable privacy laws, including the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and other applicable provincial laws.
Personal Information Collected and Purposes
For a list of the personal information collected, please see Section 2 Personal Information Collected.
For a list of the business purposes for which each type of personal information is collected, please see Section 3 Purposes for Collecting and Processing.
Categories of Personal Information Disclosed. The table below identifies, generally, the categories of personal information shared with third parties for a business or commercial purpose.
Categories of Personal Information
Includes direct identifiers such as name, alias, email, phone number, address, unique personal identifier, online identifier, IP address, or other similar identifiers.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Includes your account and profile information and customer records that contain personal information, such as name, demographics and other characteristics or descriptions, contact information, and financial or payment information.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Includes records of Services purchased, obtained, or considered, or other purchasing or use histories or tendencies.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Includes browsing history, clickstream data, search history, and information regarding interactions with our Sites and Services, advertisements, or emails, including other usage data related to your use of any of our Services or other similar online services.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Such as general location information about a particular individual or device.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Includes information collected via call recordings if you are interacting with us in a customer service capacity or if you call us on a recorded line, recorded meetings and webinars, videos, and photographs.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
Such as inferences drawn from any of the information described in this Section about a consumer including inferences reflecting consumer preferences, characteristics, behaviors, attitudes, abilities, and aptitudes.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
We may collect some information that is considered a protected classification such as gender, age, date of birth, citizenship, marital status, disability status, gender identity or expression, and medical condition.
Third Party Disclosures for Business or Commercial Purposes
Categories of Personal Information
In some circumstances, we may collect health data, payment card information and related details, precise geolocation data, racial or ethnic origin, biometric information, and other information considered sensitive under Canadian law.
Third Party Disclosures for Business or Commercial Purposes
Sensitive personal information, such as medical information, is collected with explicit consent where legally required, unless an exception applies. We may process sensitive information when acting as processor/service provider for another controller who has obtained your consent.
Circumstances where Personal Information will be shared or transferred across borders
Personal information may be communicated outside of the province where you reside or where the information was collected. See Section 10 International Transfers of Personal Information. When such transfer occurs, we take reasonable steps to ensure that the receiving entity uses the information only for the purposes specified in this Notice.
You are welcome to contact us about our policies regarding service providers outside of Canada. See Section 14 Contact Us for instructions on how to reach our Data Protection Officer.
By submitting your personal information or engaging with the Services, you consent to this transfer, storage or processing.
Your Privacy Choices
See Section 7 Your Privacy Choices.
Your Privacy Rights
Under applicable federal or provincial law, you may have the following privacy rights available to you:
To exercise your privacy rights, contact us at privacy@dentsplysirona.com. When you submit a request, we will take steps to verify your identity and request by matching the information provided by you with the information we have in our records. In some cases, we may request additional information in order to verify your identity, or where necessary to process your request. Requests will be evaluated in accordance with applicable law. Your request may be denied if we are unable to verify your identity after a good faith attempt, or for other reasons as may be applicable under local law. In such case, we will inform you of our decision and the reasons for it. If we deny your request, in certain jurisdictions you may be able to appeal our decision according to the instructions we provide in our response. In some cases and in accordance with applicable law, we may charge a fee to process your request. If a fee is applicable, we will provide you with this relevant information before fulfilling your request.
Where processing of your personal information is based on consent, you may have the legal right to withdraw your consent under certain circumstances. To withdraw your consent, contact us at privacy@dentsplsysirona.com and let us know the program or Services for which you wish to withdraw your consent. Please note that if you withdraw your consent we may not be able to provide you with a particular product or service. We will explain the impact to you at the time to help you with your decision.
You may report any complaints related to personal information protection that arise while using our Services to privacy@dentsplysirona.com. We will provide you prompt and sufficient response to your concern. If you need further assistance, or if you need to report personal information infringements, please contact your local data protection authority.
This Section supplements the Notice with additional disclosures specific to residents of countries in the Asia Pacific (APAC) region.
Data Controller(s)
The primary controller of your personal information will be the Dentsply Sirona business with whom you have interacted, including where you may have entered into a contract with us, in which case the legal entity will be identified in the contract. A list of Dentsply Sirona companies and their locations can be found here. If you have a question about the identity of your applicable controller please see Section 14 Contact Us for instructions on how to reach our Data Protection Officer.
Personal Information Collected
For a list of the personal information collected, please see Section 2 Personal Information Collected.
Business Purposes for which Personal Information will be used or processed
For a list of the business purposes for which each type of personal information is collected, please see Section 3 Purposes for Collecting and Processing.
Sensitive Personal Information
Sensitive personal information, such as medical information, is collected with explicit consent where legally required, unless an exception applies. We may process sensitive information when acting as processor/service provider for another controller who has obtained your consent.
Circumstances where Personal Information is shared or transferred
For information related to circumstances under which your personal information may be transferred, accessed, or shared, please see Section 4 Disclosures of Personal Information.
Circumstances where Personal Information will be shared or transferred across borders
See Section 10 International Transfers of Personal Information.
You may wish to review the offshore report published by Japan’s Personal Information Protection Commission here.
Security
Data Subject Rights
Depending on where you reside, you may have the benefit of data subject rights such as:
You can exercise your data subject rights by sending an email to privacy@dentsplysirona.com with the specifics of your request.
When you submit a request, we will take steps to verify your identity and request by matching the information provided by you with the information we have in our records. In some cases, we may request additional information in order to verify your identity, or where necessary to process your request. Requests will be evaluated in accordance with applicable law. Your request may be denied if we are unable to verify your identity after a good faith attempt, or for other reasons as may be applicable under local law. In such case, we will inform you of our decision and the reasons for it. If we deny your request, in certain jurisdictions you may be able to appeal our decision according to the instructions we provide in our response.
In some cases and in accordance with applicable law, we may charge a fee to process your request. If a fee is applicable, we will provide you with this relevant information before fulfilling your request.
You may report any complaints related to personal information protection that arise while using our Services to privacy@dentsplysirona.com. We will provide you with a prompt and sufficient response to your concern. If you need further assistance, or if you need to report personal information infringements, please contact your local data protection authority.
Retention and Destruction of Personal Information
We retain your personal information for as long as reasonably necessary to fulfill the purposes for which it was collected or as otherwise necessary to comply with our legal obligations, resolve disputes, maintain appropriate business records, and enforce our agreements.
Once the personal information has met its retention period, the information is promptly destroyed or deleted. Information printed on paper is destroyed by shredding or incineration whereas personal information stored in an electronic file format is deleted using a technical method that renders the records unrecoverable.
Public domain
Some of our Services may include public chat rooms, message boards, and news groups for users to use and share information with one another. Any information you disclose or share in these public forums becomes public information, so you should be careful when deciding to disclose your personal information in these areas. Do not disclose personal information about third parties or discuss information about identifiable patients through these areas.
Cookies and Tracking
See Section 6 Cookies and Tracking for more information on how we use cookies and other analytics platforms as part of the Services. Please note that our Services may use social and video plug-ins, such as those provided by Facebook, Instagram, LinkedIn, or YouTube. When you visit a page on one of our Sites that contains a social, video or other plugin, your browser will connect directly to the plugin server and provide that third party with information that you accessed that page on our Site. If you are also logged into that service, your visit may be linked to your account for that service. Therefore, if you interact with the plugin, for example by clicking “Like” or submitting a comment, that information will be transmitted directly from your browser to that party. Your interactions with such services are subject to their respective privacy policies and other policies that may be located on their websites.
When you visit our Sites, we may allow certain third parties (such as advertising networks and data analytics companies) to collect information about your online activities over time and across different websites. Where required by applicable law, we will ask for your consent to place cookies on your device. If you give consent, this message will not appear again when you return to the Site. If you wish to withdraw your consent at any time, you may do so by changing your browser settings.
Notifiable Data Breaches
If there is a loss, or unauthorized access or disclosure of your personal data that is likely to result in serious harm to you, we will investigate and provide notifications to you and the relevant data protection authority (if required) in accordance with applicable law.