Privacy Policy

Privacy policy

Privacy policy — Elite Medical & Dental Clinic, Smithfield, Dublin.

Last updated: 2026-10-02

Draft for legal review. This is not legal advice or a certification of GDPR compliance. Bracketed details require confirmation before publication.

Who is responsible and how to contact us

The proposed data controller is [CLINIC_LEGAL_NAME], registration [CLINIC_REGISTRATION_NUMBER], registered address [CLINIC_REGISTERED_ADDRESS], operating as Elite Medical & Dental Clinic. The clinic's advertised location is Unit 3 Block E, Thundercut Alley, Smithfield, Dublin D07VH01. Contact: info@elitemedical.ie; +353 85 102 4218. Data-protection contact: [PRIVACY_CONTACT]. DPO, if appointed: [DPO_DETAILS_OR_NOT_APPLICABLE]. Confirm the controller's legal identity and contact arrangements before approving this notice.

What we collect

The contact form collects your name, email, phone, selected service, message, enquiry consent and security token. Operational systems may process IP addresses, browser information and access logs. The form is for enquiries; please do not send unnecessary medical history, identity documents, payment information or urgent health concerns. The website is not an emergency service: in Ireland call 112 or 999 for an emergency.

Purposes and proposed legal bases

Responding to an appointment enquiry may rely on GDPR Article 6(1)(b), taking steps requested before a contract, where applicable. Security and preventing misuse may rely on Article 6(1)(f), subject to a documented legitimate-interests assessment. Applicable legal duties may rely on Article 6(1)(c); the clinic must identify the actual duties in [APPLICABLE_LEGAL_OBLIGATIONS]. Optional analytics and advertising require the appropriate consent; where consent is the basis, Article 6(1)(a) applies. The enquiry checkbox is not consent to advertising. These bases must be validated for the clinic's actual operations.

Sensitive health information

Your selected service or message can reveal health information, which is special-category data. The clinic must establish an Article 9 condition in addition to an Article 6 basis: [CONFIRMED_ARTICLE_9_CONDITION]. Article 9(2)(h) may apply to healthcare delivered under the required professional-secrecy safeguards; it must not be assumed for every website use. Any explicit-consent process, where appropriate, requires separate legal review. Health information must not be used for advertising profiling or placed in analytics URLs/events. Access, security controls and staff confidentiality arrangements require confirmation in [HEALTH_DATA_SAFEGUARDS].

Recipients, providers and international transfers

The website uses Replit hosting, Resend email delivery and Cloudflare Turnstile security checks. Google Analytics 4 and Google Ads may process measurement data through GTM. Meta services may process data when enabled through GTM; their runtime configuration and consent controls remain unverified. Google, Meta and Cloudflare may act as separate controllers for some processing, rather than processors for every purpose. Confirm the roles, contracts, actual enabled services and authorised recipients in [PROVIDER_ROLES_AND_DPAS].

Enquiries are sent to the clinic through the email provider; delivery acceptance does not prove inbox receipt. No promise of exclusively EEA storage is made. Document relevant processing locations, international transfer mechanisms and safeguards in [TRANSFER_LOCATIONS_AND_SAFEGUARDS]; obtain provider agreements and information on sub-processors.

Retention and security

Retention periods remain to be approved: enquiries [ENQUIRY_RETENTION]; security logs [LOG_RETENTION]; consent records [CONSENT_RETENTION]; and clinical records, where relevant, [CLINICAL_RECORD_RETENTION_AND_LEGAL_BASIS]. Delete or anonymise data when its justified retention ends, subject to applicable duties and legal claims. Confirm actual technical and organisational measures, backup retention, deletion procedures and incident response in [SECURITY_AND_DELETION_CONTROLS]. Do not interpret this draft as verification of those controls.

Your rights and complaints

Depending on the circumstances, you may request access, correction, deletion, restriction, portability or object to processing. If processing relies on consent, you can withdraw it without affecting prior lawful processing. Rights may be limited by healthcare or legal obligations. Submit requests to info@elitemedical.ie or [PRIVACY_CONTACT]; identity checks must be proportionate. The usual GDPR response deadline is one month, subject to permitted extensions with notification.

You may complain to Ireland's Data Protection Commission at https://www.dataprotection.ie, or to the competent supervisory authority. No solely automated clinical decision-making is implemented in the inspected enquiry flow; wider clinic systems remain [AUTOMATED_PROCESSING_REVIEW].

Cookies and updates

Read the cookie policy for the observed browser inventory and its limitations. Use Cookie settings in the footer to revisit your choice. Confirm how requests relating to children's data are handled in [CHILDREN_AND_GUARDIAN_PROCESS]. This draft was updated on 2 October 2026; material changes require renewed review and, where necessary, renewed consent.