Last updated: 2026-04-23
Data controller: Dr. Semion Roitman — Endodonzia e R&D ("Operator"), reachable at dr.s.roitman@gmail.com. No formal Data Protection Officer is required at this scale; the Operator is the contact for privacy matters.
- Server access logs (HTTP request, timestamp, user-agent). Retained 30 days.
- Anonymous IP hash for rate-limiting and anti-spam. Plaintext IP is not stored.
- Name, email address, hashed password. Retained while your account exists.
- Contribution history (pages you edited, reviews you wrote). Permanent part of the encyclopedic record; your username is displayed.
- Review content + author name (required, publicly displayed).
- Author email (optional, private, not displayed). Used to contact you about reports/appeals.
- Report content + reporter name and email (optional). Visible only to the moderation team.
- A session cookie (required, set by Wiki.js to keep you signed in).
- Browser localStorage for the moderation admin token (admin users only).
We do not use analytics cookies, advertising cookies, or cross-site tracking.
- Account + contributions: contract performance (Art. 6(1)(b)) — to provide the service you asked for.
- Moderation + reports: legitimate interest (Art. 6(1)(f)) — maintaining content quality and DSA compliance.
- Server logs: legitimate interest — security and troubleshooting.
We do not sell personal data. We share data only:
- With hosting providers (Hetzner/DigitalOcean/Namecheap) as technical processors under a DPA.
- With law enforcement on valid legal request.
- Publicly, for content you chose to publish (review content + author name).
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure ("right to be forgotten") — delete your account and dissociate your contributions (content remains under CC BY-SA but without personal attribution).
- Restriction and objection to processing.
- Data portability — receive your data in machine-readable form.
- Withdraw consent at any time where processing relies on consent.
- Complain to the Italian data-protection authority (Garante per la protezione dei dati personali, www.garanteprivacy.it).
Requests: dr.s.roitman@gmail.com, replied within 30 days.
- Active accounts: indefinite.
- Deleted accounts: contributions dissociated; logs purged within 30 days.
- Server logs: 30 days.
- Moderation records and audit log: 6 years (necessary for DSA compliance and legal defense).
The service is intended for dental professionals and students. We do not knowingly collect data from anyone under 18.
The service is hosted within the EU. If we use non-EU processors we will rely on Standard Contractual Clauses.
- Passwords are salted and hashed (bcrypt).
- HTTPS enforced in production.
- Access to moderation data is limited to site operators.
- Breach notification to affected users and the supervisory authority within 72 hours where applicable.
We will announce material changes by banner on the home page at least 30 days in advance.