1. Who we are
[LEGAL BUSINESS NAME] is the data controller responsible for the personal information described in this policy. Contact: [CLINIC ADDRESS], [COUNTRY], [CLINIC EMAIL].
2. What we collect
When you submit the consultation form, we collect your name, email address, phone number, preferred appointment date, selected service and the message you write. Please avoid describing sensitive medical details in the message field beyond a general reason for your enquiry — discuss specifics with us directly once contact is established.
3. Website access and log files
Each time this website is accessed, our server automatically records your IP address, the date and time of access, your browser type and version, your operating system, and the referring URL. This is stored in server log files, separately from any consultation form data, and is standard technical operation under Art. 6(1)(f) GDPR.
4. Legal basis for processing
We process enquiry information under Art. 6(1)(b) GDPR, as steps taken at your request prior to a possible appointment. Basic technical safeguards (such as the CSRF token stored in your session) rely on our legitimate interest under Art. 6(1)(f) GDPR in keeping the form secure. If you voluntarily share health-related information, we treat this as special category data under Art. 9 GDPR and rely on your explicit consent in submitting it.
5. How we use it
Enquiry information is used to respond to you, coordinate a possible consultation, and keep a record of that communication. We do not sell it or use it for unrelated marketing without a separate lawful basis and your consent.
6. Storage and retention
Submissions are stored in our MySQL database, accessible only to authorised staff. [Retention period to be defined by the clinic — for example, deletion after a fixed period if no appointment follows]. Until a formal retention schedule is set, submissions should be reviewed and deleted manually on a regular basis.
7. Cookies and technical data
This site sets one strictly necessary session cookie (used for security and language preference) — no marketing or analytics cookies are used. Web fonts are loaded from Google Fonts' servers, which transmits your IP address to Google when the page loads; this can be avoided by self-hosting the fonts instead, which the clinic should consider before launch.
8. Third parties and transfers
The WhatsApp button links to Meta/WhatsApp — once you use it, WhatsApp's own privacy policy applies, not ours. Google Fonts is served from Google infrastructure, which may involve data transfer outside the EU/EEA.
9. Your rights under GDPR
You may request access, correction, deletion, or restriction of your data, object to its processing, request a portable copy, and withdraw any consent given, at any time, by contacting [CLINIC EMAIL]. You may also lodge a complaint with your local data protection supervisory authority.
10. Data security
This website uses SSL/TLS encryption for all data transmitted between your browser and our server. We apply appropriate technical and organisational measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorised access.
11. Children
This website is not directed at children, and we do not knowingly collect information from them.
12. Changes to this policy
This policy may be updated as the clinic, its providers, or applicable law change. The current version is always published on this page with an updated date.