Privacy Policy

Last updated: 1 October 2026

This Privacy Policy explains how XGATE Dental Group GmbH (“XGATE”, “we”) processes personal data when you visit xgate.dental, contact us or use a customer account. The website is intended exclusively for dental professionals, dental laboratories and distributors.

1. Controller

The controller within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR) is:

XGATE Dental Group GmbH
Falkensteiner Straße 77, 60322 Frankfurt am Main, Germany
E-mail: [email protected]

2. Website operation and security

Server and security logs. Each time you access the website, our server automatically records technical data: your IP address, the date and time of the request, the page requested, the referrer URL and information about your browser and operating system. This data is required to deliver the website, ensure its stability and detect attacks (Art. 6(1)(f) GDPR). Log files are deleted once they are no longer required for secure operation, unless they are needed to investigate a specific security incident. In addition, our security software records the IP addresses associated with failed login attempts and blocks suspicious requests; these records are deleted after 60 days.

Hosting. The website is hosted by an external hosting provider on servers located in the USA (see section 8). The provider acts as our processor under Art. 28 GDPR.

Cloudflare. All requests to the website are routed through the content delivery network and security services of Cloudflare, Inc. (USA), which protect the website against attacks and accelerate its delivery. For this purpose, Cloudflare processes your IP address and technical request data as our processor (Art. 6(1)(f) GDPR).

Cloudflare Turnstile. Our forms are protected against spam and automated abuse by Cloudflare Turnstile, which evaluates technical signals from your browser, such as the IP address, browser characteristics and connection data. This is necessary to protect our forms and our website (Art. 6(1)(f) GDPR; § 25(2) no. 2 TDDDG). Cloudflare processes these signals as our processor to secure our website and, as an independent controller, to improve its bot detection. Further information is available in Cloudflare’s Turnstile Privacy Addendum.

3. Cookies and consent

Technologies that are strictly necessary to provide the website, such as the cookies that store your consent choice, language and login session, are used on the basis of § 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR.

All other technologies (analytics and marketing) are used only with your consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR, which you give or refuse in our cookie banner. Consent is managed by a tool that runs locally on our website; your choice is stored in your browser for 12 months and is not transmitted to third parties. Storing your choice enables us to demonstrate your consent (Art. 6(1)(c) in conjunction with Art. 7(1) GDPR).

You may withdraw or change your consent at any time with effect for the future via “Manage consent” at the bottom of every page. A complete list of cookies, providers and storage periods is set out in our Cookie Policy.

4. Analytics and marketing

Google Tag Manager. We use Google Tag Manager, a service of Google Ireland Limited (Ireland), to manage the tools described in this section. Tag Manager does not set cookies and does not create user profiles; when it is loaded, Google processes your IP address for technical reasons (Art. 6(1)(f) GDPR). The tools below are activated only after you have given the relevant consent (Art. 6(1)(a) GDPR; § 25(1) TDDDG). Unless a shorter period is stated below, the data is processed until you withdraw your consent; cookie lifetimes are listed in the Cookie Policy.

Google Analytics 4. We use Google Analytics 4, a service of Google Ireland Limited, to analyse how the website is used, for example which pages are viewed and how visitors reach us. Google processes pseudonymous usage data, device data and online identifiers. IP addresses are not stored, and Google signals is disabled, so the data is not linked to Google accounts. Event data is deleted after 2 months and user-level data after 14 months.

Meta Pixel. We use the Meta Pixel of Meta Platforms Ireland Ltd. (Ireland) to measure the effectiveness of our advertising on Facebook and Instagram and to present it to relevant professional audiences. Meta receives your IP address, browser data, the pages visited and a cookie identifier, and may link this data to your Meta account if you are logged in. For the collection and transmission of this data, we and Meta are joint controllers under Art. 26 GDPR on the basis of Meta’s Controller Addendum. Under this agreement, we are responsible for informing you about the joint processing and for obtaining your consent, while Meta is responsible for the security of the processing and for responding to data subject requests concerning the data it holds. You may exercise your rights against us or against Meta. Meta is solely responsible for any subsequent processing.

HubSpot tracking. HubSpot (see section 5) sets cookies that record the pages you visit. If you subsequently contact us, this history may be associated with your contact record. Without your consent, no HubSpot tracking cookies are set.

5. Enquiries and customer relationship management

Website forms and e-mail. When you contact us via a form on the website (for example the contact form or the “Find a distributor” form) or by e-mail, we process the data you provide, typically your name, e-mail address, company, role, country, telephone number and message, in order to respond to your request. The legal basis is Art. 6(1)(b) GDPR where your request relates to a contract with you personally or to steps prior to entering into such a contract. Where you contact us on behalf of a company, practice or laboratory, and in all other cases, the legal basis is Art. 6(1)(f) GDPR (our legitimate interest in handling business enquiries). Our e-mail is operated by an external service provider acting as our processor.

Distributor requests. If you ask us to put you in touch with a distributor, we forward your contact details and your message to the authorised XGATE distributor responsible for your country so that it can contact you. The distributor processes this data as an independent controller. If the distributor is located outside the EU/EEA, the transfer takes place at your request and is necessary to handle it (Art. 49(1)(b) GDPR).

HubSpot CRM. Enquiries and customer account data are stored in the customer relationship management platform of HubSpot Ireland Ltd. (Ireland), a subsidiary of HubSpot, Inc. (USA). Our HubSpot account is hosted in the EU, and HubSpot acts as our processor under a data processing agreement.

Retention. Enquiry data is deleted once the request has been fully dealt with and no further contact is expected, and no later than 3 years after our last contact with you, unless statutory retention obligations apply.

Patient data and incident reports. Please do not send identifiable patient data via the website or by e-mail. Complaints and incident reports concerning our medical devices are processed to fulfil our obligations under the EU Medical Device Regulation (Art. 6(1)(c) GDPR and, for health data, Art. 9(2)(i) GDPR in conjunction with § 22(1) no. 1(c) BDSG).

6. Customer account

You may register a customer account with your e-mail address in order to download our CAD/CAM libraries and other files for dental professionals. We process your e-mail address, the details you add to your account (such as name and company) and your download history to provide the downloads, notify you of updates to the libraries you have downloaded and offer technical support. We do not use account data to send marketing e-mails. The legal basis is Art. 6(1)(b) GDPR. Account data is stored until the account is deleted; you may request deletion at any time.

7. YouTube and social media links

Videos on our website link to our YouTube channel and are played on YouTube only after you click on them. Preview images are loaded from the servers of YouTube (Google Ireland Limited), which receives your IP address when the page is loaded (Art. 6(1)(f) GDPR). Social media icons and share buttons are plain links; no data is transmitted to the platforms until you click on them.

8. Recipients and international transfers

We disclose personal data only where this is necessary for the purposes described above: to service providers acting on our behalf under Art. 28 GDPR (hosting, Cloudflare, HubSpot, e-mail, IT support and website maintenance), to authorised distributors for distributor requests (section 5), to Meta as joint controller (section 4) and to public authorities where required by law.

The website is hosted in the USA, and our hosting provider, Cloudflare, Google, Meta and HubSpot are based in the USA or may access data from there. These providers are certified under the EU-US Data Privacy Framework, for which the European Commission has adopted an adequacy decision (Art. 45 GDPR). Where a recipient is not certified, transfers are based on the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR), a copy of which is available on request.

9. Retention

Personal data is deleted as soon as it is no longer required for the purpose for which it was collected; the applicable periods are set out in the relevant sections above. Where an enquiry results in a business relationship, the related business and tax records are subject to the statutory retention periods under commercial and tax law (6, 8 or 10 years depending on the type of document; § 257 HGB, § 147 AO).

10. Your rights

Under the GDPR, you have the right to:

  • access your personal data (Art. 15);
  • rectification of inaccurate data (Art. 16);
  • erasure (Art. 17) and restriction of processing (Art. 18);
  • data portability (Art. 20);
  • withdraw consent at any time with effect for the future (Art. 7(3)), for cookies via “Manage consent” on every page;
  • lodge a complaint with a supervisory authority (Art. 77). The authority competent for us is the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit), Wiesbaden, Germany. You may also contact the authority in your country of residence.

Right to object (Art. 21 GDPR). Where we process your data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation. We will then cease the processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims. You may object to the use of your data for direct marketing at any time without giving reasons.

To exercise your rights, please contact us at [email protected] or at the postal address given in section 1. We will respond within one month.

11. Provision of data and automated decision-making

You are under no statutory or contractual obligation to provide personal data. However, the fields marked as mandatory in our forms are required to process your request or to create an account. We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).