MSDI LTD.
Privacy Policy & Cookie Policy
Last Updated: 23/02/2026
1. Who We Are
MSDI Ltd. (“MSDI”, “we”, “our”, or “us”) is a dental implant manufacturing company headquartered in Israel. We design, manufacture, and distribute medical-grade dental implant systems and related components to dental professionals, clinics, and authorized distributors worldwide.
We are committed to protecting your personal data and complying with all applicable privacy and data protection regulations, including:
- The Israeli Privacy Protection Law, 5741-1981 (PPL) and its regulations
- The European Union General Data Protection Regulation (EU) 2016/679 (GDPR)
- The California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)
- Other applicable U.S. state privacy laws (e.g., Virginia VCDPA, Colorado CPA, Connecticut CTDPA)
- Any other applicable data protection laws in regions where we operate or market our products
Data Controller: MSDI Ltd., Israel
Contact Email: marketing@msdi-ltd.com
Website: https://msdi-dental.com/
If you are located in the European Economic Area (EEA) or the United Kingdom, MSDI Ltd. acts as the data controller for your personal data processed through our website and services.
EU Authorized Representative (GDPR Article 27):
MedNet EC-REP IIb GmbH
Borkstrasse 10, 48163 Münster, Germany
2. Scope of This Policy
This Privacy Policy applies to personal data collected through:
- Our website(s) and e-commerce platforms
- Contact forms, inquiries, and customer support interactions
- Product orders and distribution partnerships
- Marketing communications, including email newsletters, SMS messages, and WhatsApp messages
- Events, trade shows, and professional conferences
- Social media interactions
This policy does not cover data processed by third-party websites linked from our site. We encourage you to review the privacy policies of any third-party services you interact with.
Medical Device Disclaimer: MSDI manufactures dental implant systems sold to dental professionals and authorized distributors. We do not typically collect patient health information (PHI) directly. If we receive any health-related data in connection with adverse event reporting, product complaints, or post-market surveillance as required by medical device regulations (e.g., FDA, EU MDR), such data is processed strictly for regulatory compliance purposes and handled with enhanced security measures.
3. What Personal Data We Collect
3.1 Categories of Personal Data
We may collect and process the following categories of personal data:
- Identifiers: Full name, email address, phone number, mailing address, professional title, business name, and account credentials.
- Professional Information: Dental license number, clinic/practice name, specialty, and professional affiliations (collected from dental professionals and distributors).
- Commercial/Transaction Data: Purchase history, order details, payment information (processed securely by PCI-DSS compliant third-party payment processors — we do not store full credit card numbers), shipping details, and invoicing records.
- Technical/Device Data: IP address, browser type and version, operating system, device identifiers, referring URLs, and access timestamps.
- Usage Data: Pages visited, time spent on pages, navigation paths, click patterns, and search queries on our website.
- Communication Data: Messages, emails, comments, feedback, support tickets, and any content you submit to us.
- Marketing Data: Preferences, opt-in/opt-out status, communication history, and engagement metrics.
- Event Data: Registration details for events, conferences, and educational sessions we organize.
3.2 Sensitive Data
We do not intentionally collect sensitive personal data (such as health data, racial or ethnic origin, political opinions, religious beliefs, or biometric data) through our website or marketing activities. In the rare event that health-related data is received in the context of adverse event reporting or regulatory obligations, it is processed solely for those purposes under applicable medical device regulations.
3.3 Children’s Data
Our website and services are intended for dental professionals and business contacts. We do not knowingly collect personal data from individuals under the age of 16 (or the applicable minimum age in your jurisdiction). If we become aware that we have inadvertently collected data from a minor, we will promptly delete it and notify the relevant supervisory authority if required.
4. How We Collect Your Data
We collect personal data through the following means:
- Directly from you: When you fill out contact forms, place orders, create an account, subscribe to newsletters, register for events, or communicate with us.
- Automatically: Through cookies, web beacons, pixels, and similar tracking technologies when you visit our website.
- From third parties: From authorized distributors, business partners, trade show organizers, social media platforms, and publicly available professional directories.
- Through embedded content: Third-party content embedded on our site (e.g., YouTube videos, social media widgets, analytics tools) may collect data subject to their own privacy policies.
5. Purposes and Legal Basis for Processing
We process your personal data for the following purposes, each supported by a lawful legal basis:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Fulfilling orders and providing products/services | Performance of Contract |
| Managing your account and customer relationships | Performance of Contract / Legitimate Interest |
| Processing payments (via third-party processors) | Performance of Contract |
| Responding to inquiries and providing customer support | Legitimate Interest / Contract |
| Sending marketing communications (email, SMS, WhatsApp) | Consent |
| Personalizing your website experience | Consent (cookies) / Legitimate Interest |
| Analyzing website usage and improving our services | Legitimate Interest / Consent (analytics cookies) |
| Complying with legal, tax, and regulatory obligations | Legal Obligation |
| Adverse event reporting and post-market surveillance | Legal Obligation (Medical Device Regulations) |
| Preventing fraud and ensuring website security | Legitimate Interest |
| Managing distributor and business partner relationships | Legitimate Interest / Contract |
| Organizing events and professional education sessions | Consent / Legitimate Interest |
6. Marketing Communications & Messaging Privacy
MSDI may communicate with you through the following marketing channels, based on your consent:
- Email newsletters (via platforms such as Klaviyo or similar email service providers)
- SMS / Text messages
- WhatsApp messages (via the WhatsApp Business platform)
- Social media messaging (e.g., Facebook Messenger, Instagram DM)
If you opt in to receive marketing communications from MSDI:
- You may opt out at any time by replying STOP to any SMS or WhatsApp message, clicking the “unsubscribe” link in any email, or contacting us at marketing@msdi-ltd.com.
- Message frequency varies by channel. Message and data rates may apply for SMS and WhatsApp.
- We will not share your phone number, WhatsApp contact information, email address, or any messaging opt-in consent data with any third party for their own marketing purposes.
- Consent to receive marketing communications is not a condition of purchase.
- Opting out of one channel does not automatically opt you out of others. You may manage your preferences for each channel separately.
7. Cookies and Tracking Technologies
7.1 What Are Cookies?
Cookies are small text files stored on your device when you visit our website. They help us recognize your browser, remember preferences, and analyze site usage.
7.2 Types of Cookies We Use
- Strictly Necessary Cookies: Essential for core website functions such as login, security, shopping cart, and session management. These cannot be disabled.
- Performance & Analytics Cookies: Collect anonymized data about how visitors use our site (e.g., pages visited, bounce rates). We use Google Analytics with IP anonymization enabled. These help us improve website performance and user experience.
- Functional/Preference Cookies: Remember your preferences such as language, region, and display settings to provide a more personalized experience.
- Marketing & Targeting Cookies: Used to deliver relevant advertisements and measure campaign effectiveness. These are placed by us or third-party advertising partners (e.g., Google Ads, Meta/Facebook Pixel) and are activated only with your explicit consent.
7.3 Third-Party Cookies
Some cookies are placed by third-party services embedded on our website (e.g., YouTube, social media plugins, analytics providers). These third parties may collect data according to their own privacy policies, over which we have limited control.
7.4 Cookie Consent
On your first visit, you will see a cookie consent banner. You may accept all cookies, reject non-essential cookies, or customize your preferences. Strictly necessary cookies do not require consent. You can withdraw or change your cookie consent at any time through:
- Our cookie preference center (accessible via the cookie banner or footer link)
- Your browser settings
Common browser cookie management links:
- Chrome: support.google.com/chrome/answer/95647
- Firefox: support.mozilla.org/en-US/kb/enable-and-disable-cookies
- Safari: support.apple.com/guide/safari/manage-cookies
- Edge: support.microsoft.com/help/4027947
7.5 Do Not Track / Global Privacy Control
We respect “Do Not Track” (DNT) browser signals and Global Privacy Control (GPC) signals to the extent required by applicable law, including the CPRA. When we detect a GPC signal, we treat it as a valid opt-out of the sale or sharing of personal information.
8. Who We Share Your Data With
We do not sell your personal information. We do not share your personal data for third-party marketing purposes without your explicit consent.
We may share your data with the following categories of recipients, only to the extent necessary:
- Service Providers: Hosting providers, payment processors, email marketing platforms, CRM systems, analytics providers, and IT support — all bound by data processing agreements.
- Authorized Distributors & Business Partners: When necessary to fulfill your product orders or service requests, and only with appropriate contractual safeguards.
- Legal & Regulatory Authorities: When required by law, court order, or to comply with medical device regulatory requirements (e.g., adverse event reporting to FDA, EU competent authorities, or Israel’s Ministry of Health).
- Professional Advisors: Lawyers, accountants, and auditors in the course of professional services they provide to us.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction, subject to this Privacy Policy.
9. International Data Transfers
MSDI is headquartered in Israel. Your data may be stored or processed in Israel, or transferred to other countries where our service providers or business partners operate.
Israel Adequacy Decision: The European Commission has recognized Israel as providing an adequate level of data protection under GDPR Article 45, facilitating lawful data transfers from the EU/EEA to Israel.
For transfers to countries not covered by an adequacy decision, we implement appropriate safeguards including:
- EU Standard Contractual Clauses (SCCs)
- UK International Data Transfer Agreement (IDTA) or Addendum, where applicable
- Binding Corporate Rules, where applicable
- Any other legally recognized transfer mechanism
You may request a copy of the relevant transfer safeguards by contacting us at the email address above.
10. Data Retention
We retain personal data only as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Our general retention guidelines are:
- Account Data: Retained for the duration of your account and for up to 3 years after account closure, unless longer retention is required by law.
- Transaction/Order Data: Retained for 7 years to comply with tax, accounting, and regulatory obligations.
- Marketing Communications Data: Retained until you withdraw consent or unsubscribe, after which it is deleted or anonymized within 30 days.
- Website Analytics Data: Anonymized and/or aggregated within 26 months.
- Contact Form Inquiries: Retained for up to 2 years after the last interaction.
- Adverse Event/Regulatory Data: Retained in accordance with applicable medical device regulations (typically 10–15 years as required by EU MDR, FDA, and Israeli medical device regulations).
- Comments & User-Generated Content: Retained indefinitely for moderation purposes, unless you request deletion.
When data is no longer needed, we securely delete or anonymize it in accordance with our data retention schedule.
11. Your Privacy Rights
11.1 Rights Under GDPR (EU/EEA/UK Residents)
If you are located in the EU, EEA, or UK, you have the following rights:
- Right of Access: Obtain confirmation and a copy of the personal data we process about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure (“Right to Be Forgotten”): Request deletion of your data, subject to legal retention requirements.
- Right to Restrict Processing: Request temporary restriction of processing in certain circumstances.
- Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal.
- Right to Lodge a Complaint: File a complaint with a supervisory authority (e.g., the Israel Privacy Protection Authority, or your local EU/UK data protection authority).
11.2 Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:
- Right to Know: Request details about the categories and specific pieces of personal information we have collected, the sources, purposes, and third parties with whom we share it.
- Right to Delete: Request deletion of your personal information, subject to exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out: Opt out of the sale or sharing of your personal information. Note: MSDI does not sell personal information.
- Right to Limit Use of Sensitive Personal Information: Where applicable.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
California “Shine the Light”: California residents may also request information about our disclosure of personal data to third parties for their direct marketing purposes. As stated, we do not share personal data for third-party marketing.
11.3 Rights Under Israeli Privacy Protection Law
Under the Israeli PPL, you have the right to access your personal data held in our databases, request correction or deletion of inaccurate data, and object to the use of your data for direct marketing purposes. You may contact the Israeli Privacy Protection Authority (PPA) at www.gov.il/en/departments/the_privacy_protection_authority for complaints.
11.4 How to Exercise Your Rights
To exercise any of the above rights, please contact us at:
Email: marketing@msdi-ltd.com
We will respond to your request within 30 days (GDPR) or 45 days (CCPA/CPRA). We may need to verify your identity before processing your request. If you have authorized an agent to make a request on your behalf, we may require verification of the agent’s authority.
12. Automated Decision-Making and Profiling
MSDI does not engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals. If this changes in the future, we will update this policy and, where required, obtain your explicit consent.
13. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/SSL) and at rest where applicable
- Access controls and authentication measures
- Regular security assessments and vulnerability testing
- Employee training on data protection and security awareness
- Secure third-party processor vetting and data processing agreements
- Incident response and breach notification procedures
While we strive to protect your personal data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
14. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR Article 33).
- Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34).
- Comply with applicable U.S. state breach notification laws, including California’s data breach notification requirements.
- Comply with the Israeli Privacy Protection Regulations regarding data security breach notifications.
- Document all breaches and remedial actions taken.
15. Third-Party Content and Links
Our website may contain links to third-party websites, embedded content (e.g., YouTube videos, social media widgets), and integrations. These third parties operate under their own privacy policies, and we are not responsible for their data practices. We encourage you to review their policies before providing any personal data.
16. “Do Not Sell or Share My Personal Information”
MSDI does not sell or share (as defined by the CCPA/CPRA) your personal information to third parties. If our practices change, we will update this policy and provide a clear opt-out mechanism before any sale or sharing occurs.
17. Updates to This Policy
We may update this Privacy Policy and Cookie Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make material changes, we will:
- Post the updated policy on our website with a revised “Last Updated” date.
- Where required by law, notify you via email or a prominent notice on our website.
We encourage you to review this policy periodically. Your continued use of our website and services after any changes constitutes acceptance of the updated policy.
18. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
MSDI Medical Systems and Devices International Ltd.
Email: marketing@msdi-ltd.com
Address: Derech Haifa 37, Kiryat Ata, Israel
Phone: +972528460950
EU Authorized Representative (GDPR Article 27):
MedNet EC-REP IIb GmbH
Borkstrasse 10, 48163 Münster, Germany
For EU/EEA inquiries, you may also contact your local data protection authority. A list of EU DPAs is available at: edpb.europa.eu/about-edpb/about-edpb/members_en
For Israeli inquiries, you may contact the Israel Privacy Protection Authority at: www.gov.il/en/departments/the_privacy_protection_authority
For California inquiries, you may contact the California Attorney General’s Office at: oag.ca.gov/privacy