Skip to content
CephCalc
  • Features
  • Methods
    Steiner McNamara Downs Tweed Ricketts Holdaway Merrifield McNamara airways Jarabak Björk Slavicek Wits Schwarz Bergen / Hasund Schmüth Tübingen
  • Scenarios
    Skeletal class (adult) Vertical facial pattern Extraction vs non-extraction Extraction in Class II/1 (adult) Class III: camouflage vs surgery Jaw discrepancy localization Dentoalveolar compensation in Class III Deep bite / Class II, division 2 Bimaxillary protrusion
  • Services
    Cephalogram analysis Cephalometrics Orthodontic calculator Orthodontist software CBCT 3D Biometrics 3D analysis Treatment plan Braces calculation Aligners calculation
  • Pricing
  • FAQ
  • Contacts
  • EN
  • USD
EN
USD
Start for free
  1. CephCalc
  2. Privacy

Privacy Policy

This document describes how the operator of CephCalc processes personal data and protects it. Prepared in compliance with Federal Law No. 152-FZ of 27.07.2006 "On Personal Data" (including Art. 18.1(2)(1)) and published on the Website.

Version dated 06.09.2026. Published at: https://cephcalc.com/privacy.

1. Operator

The personal data operator is the seller/rights holder of CephCalc. Contacts and details:

Denis Timurovich Usmanov, Sole Proprietor

  • TIN: 026705193002
  • OGRN / OGRNIP: 325169000137714
  • Email: support@cephcalc.com

2. Legal Bases

Processing is based on consent; contract (public offer and acceptance); performance of the Operator's obligations; Russian legal requirements (including fiscal receipts and tax reporting where applicable); Federal Law No. 149-FZ on information and IT; and, where applicable, advertising law with separate marketing consent.

3. Key Terms

This policy uses terms from personal data law: personal data; operator; processing (collection, recording, organization, storage, updating, retrieval, use, transfer, anonymization, blocking, deletion, destruction); personal data information system; blocking; destruction; anonymization; cross-border transfer.

4. Data Subjects and Categories

4.1. Website Users / Account holders: name; email; phone; city; clinic details (if provided); hashed password; order and payment status; session technical data (IP, browser type, necessary cookies).

4.2. Patients entered by the User: information the User uploads to records and calculations (identifier / code; name and other card fields if needed; images; module results). The Operator processes these as data provided by the User under personal data processing agreement; the User warrants lawful submission and legal grounds. The Operator does not determine purposes for patient data and processes only what the Service requires.

4.3. Special-category health data is processed only to the extent the User places it in the Service for calculations and is not requested beyond Service functionality.

4.4. Medical confidentiality. Information about seeking medical care, a patient's health status, diagnosis, and other data obtained during examination and treatment may be protected under applicable medical confidentiality and health privacy laws. Disclosure to third parties without a lawful basis is not permitted. Placing patient data and medical images in the cloud Service constitutes disclosure to the Processor (service infrastructure operator). The User (treating clinician / medical organization) must ensure patient consent and/or another lawful basis for such disclosure. The Operator recommends minimizing personal data: use anonymized identifiers (record code) instead of full name, address, phone, and other direct identifiers when they are not needed for the User's work in the Service. Where Russian law applies, medical confidentiality is governed in particular by Art. 13 of Federal Law No. 323-FZ on the Fundamentals of Protecting Citizens' Health in the Russian Federation.

5. Processing Purposes

  • registration, Account management, authentication;
  • providing Service features and paid volumes;
  • payment processing (including Prodamus) and digital service delivery;
  • technical support and inquiries;
  • security and abuse prevention;
  • legal compliance (accounting, fiscal receipts where applicable);
  • Website improvement via aggregated statistics and cookies (see cookies section);
  • operational Service messages (non-promotional order/access notifications).

Account data is retained while the Account is active and thereafter as needed for processing purposes and legal requirements (including accounting and payment records). After Account deletion or consent withdrawal, data is destroyed per Section 9 unless other legal grounds apply.

Storage location: personal data is stored and processed on servers in the Russian Federation. Intentional cross-border transfer by the Operator does not occur except as described in the third-party disclosure section and where permitted by 152-FZ.

6. Processing and Consent

6.1. Processing uses automation and, where necessary, manual methods.

6.2. User consent is obtained at registration via checkbox and confirmation of this policy and consent to personal data processing. Subsequent payments use the accepted offer and active consent unless withdrawn.

6.3. The Operator assumes Users provide accurate information and are 18+. The Website is not for minors; child data without guardian consent is deleted within a reasonable time.

6.4. The Operator is not obliged to verify capacity or accuracy of all data; the subject (or User who entered patient data) bears inaccuracy risk.

7. Third-Party Disclosure

7.1. Disclosure without consent occurs only when:

  • required by authorized government bodies under law;
  • processing is entrusted to partners (hosting, mail and infrastructure, Prodamus, Yandex.Metrica on public pages) under partner agreements and only for purposes stated herein;
  • the subject has consented.

7.2. Card data is entered on the payment partner's side; the Operator receives status, amount, and payment ID needed to credit services.

7.3. Intentional cross-border transfer by the Operator does not occur. If partner infrastructure implies such transfer, it is allowed only in compliance with 152-FZ.

8. Cookies, Analytics, and Statistics

The Website uses cookies and technical logs (IP, browser type, access time, page URLs) for authentication, security, and improvement. On public pages, Yandex.Metrica (Yandex LLC) collects anonymized or pseudonymized visit statistics and may set its own cookies. Metrica is not loaded on patient charts, calculation screens, or admin. Terms: yandex.ru/legal/metrika_termsofuse.

Users may limit cookies in browser settings; some features may become unavailable. Refusing analytics cookies does not affect mandatory technical cookies required for login and the account area.

9. Retention, Backups, and Destruction

9.1. Data is kept no longer than required by processing purposes, contract, or law.

9.2. Upon purpose achievement, consent withdrawal (if no other grounds), or lawful subject request, the Operator stops processing and destroys data in active systems within typically 10 calendar days, with possible reasoned extension up to 5 business days.

9.3. Backups. For resilience, the Operator creates backups. Deleted active records may persist briefly in backup archives (typically up to 90 calendar days) before rotation without restoring deleted content.

9.4. Destruction in information systems is by record deletion / irrecoverable removal from active databases; destruction is documented internally.

9.5. Account deletion. Users may request deletion in the account area (with password). Deletion occurs automatically after 7 calendar days; cancellation is possible until then in the account or via email link. Alternatively, by email to support. Deletion ends Service access. Patient data in the Account is deleted under the same rules. Consent withdrawal and deletion do not cancel payment for access already granted unless required by law.

10. Security Measures

The Operator applies legal, organizational, and technical measures proportionate to risk: access control; action logging; secure channels; backups; staff training; internal control. Specific technologies may change without reducing protection. For incidents requiring authority notification, the Operator acts within legal deadlines.

11. Data Subject Rights

Subjects may request processing information; demand correction, blocking, or destruction where grounds exist; withdraw consent; complain to Roskomnadzor or court; and protect interests as provided by law.

Requests go to support email with information identifying the subject and confirming processing (e.g., Account email) and the request substance. Electronic requests may be signed where law requires for a specific request type.

12. Policy Changes

A new version takes effect upon publication on the Website unless otherwise stated.

13. Contacts

Personal data inquiries: support@cephcalc.com_link · contacts and billing details · public offer · consent to personal data processing · personal data processing agreement.

© 2026 CephCalc — All rights reserved
Denis Timurovich Usmanov, Sole Proprietor TIN 026705193002 OGRNIP 325169000137714
Pricing & payment Contacts Terms of service Privacy Personal data consent Data processing agreement support@cephcalc.com
  • Visa
  • Mastercard
  • Maestro

Payment by bank card, Visa, Mastercard and Maestro is processed by Prodamus. You can choose a payment method on the checkout page.

Log in

Forgot password? · No account yet?

We use technical browser data for site operation, authentication, and analytics. Third-party services (including Yandex.Metrica) may also store data in your browser.
Privacy policy Consent to data processing