Privacy
Privacy Notice
Effective date: 15 September 2026
1. Who is responsible for your information
ClinicMatcher Technologies, Unipessoal Lda ("ClinicMatcher") is the controller for the processing described in this Privacy Notice. For privacy questions or to exercise your data-protection rights, email hello@clinicmatcher.com.
Our current statutory particulars appear on the Legal page of this website.
2. What this notice covers
This notice explains how we use personal data when a clinician or another dental-sector professional visits clinicmatcher.com or submits the professional-interest form.
ClinicMatcher is at a limited pre-launch stage. The website does not provide patient care, diagnosis, treatment, clinical advice, a live clinic-matching service, a public marketplace or an emergency service. Do not submit patient information, health information or other special-category personal data.
3. Information we use
When you submit the form, we receive your name, professional email address, clinic or organisation name, selected role, submission time, and the identifiers and status information needed to process the submission.
When you use the website or form, our hosting and security providers process limited device, network and request information needed to deliver and protect the service. This can include pseudonymous rate-limiting identifiers derived from request metadata, timestamps and security events. Application logs are designed not to store names, email addresses or raw IP addresses.
4. Purposes, legal bases and legitimate interests
We use the details you submit, together with the submission time and necessary record identifiers, to receive, assess and respond to the professional enquiry you initiate and to maintain a limited, accurate record of that communication. Our legal basis is Article 6(1)(f) EU GDPR. Our legitimate interest is responding to inbound professional enquiries and managing those communications.
We use limited device, network, request, security, rate-limit and duplicate-prevention data to operate the form, maintain availability, prevent misuse and investigate security events. Our legal basis is Article 6(1)(f) EU GDPR. Our legitimate interest is protecting the website, form and associated systems.
Where we must keep a particular record to comply with a binding legal obligation, the basis is Article 6(1)(c) EU GDPR. Where limited retention is necessary to establish, exercise or defend a specific legal claim, the basis is Article 6(1)(f), based on our legitimate interest in protecting our legal rights.
We have assessed our legitimate interests in responding to inbound professional enquiries and securing the form, including necessity, reasonable expectations, minimisation, retention, safeguards and impact on your rights.
We will not use a professional-interest submission for promotional email or unrelated direct marketing unless we first provide the required separate information and establish a lawful route under applicable data-protection and electronic-marketing law.
5. Whether you must provide information
Providing the information is voluntary. It is not a statutory or contractual requirement and is not necessary to enter a contract. If you do not provide the required fields, you cannot submit the form and we cannot assess or respond through it. Submitting the form does not create a service, matching, appointment, employment or other commercial contract.
6. Recipients
We disclose personal data only to authorised people acting for the controller; verified providers needed to host, secure, store and deliver the form and its operational notification; their subprocessors where needed to provide those services; and courts, regulators, public authorities or professional advisers where required by law or necessary to establish, exercise or defend legal claims.
Our production service uses Google Cloud and Firebase (Google Ireland Limited and affiliated Google entities) for hosting, Firestore storage and Cloud Functions processing in europe-west1, and Zoho ZeptoMail for transactional operator notifications from hello@clinicmatcher.com. Operator notifications can include the submission identifier, submission time, name, professional email, clinic or organisation name, selected role and follow-up status. Provider contracts and privacy notices govern any independent processing they carry out for their own purposes.
7. Transfers outside the EEA
Some providers may process or permit access to personal data outside the European Economic Area, including in the United States. Where required, we rely on adequacy decisions or Standard Contractual Clauses and supplementary measures described in the relevant provider documentation. You may contact hello@clinicmatcher.com for more information about transfers and safeguards.
8. Retention
We keep the main enquiry record for no more than 12 months from the original submission if the enquiry does not progress, or no more than 18 months from the original submission if it progresses. For this purpose, an enquiry progresses only if, after submitting, the clinician replies from the submitted professional email address to confirm that they want the conversation to continue. Receiving or internally reviewing the form, sending an unanswered message, receiving an automated or ambiguous message, receiving a data-protection-rights request, rejecting the enquiry or closing it administratively does not count. The period always runs from the original submission. These periods are maximums, and we delete the record earlier when it is no longer needed.
An enquiry progresses only when a verified clinician sends an unambiguous human-originated reply, after submission, from the submitted professional email address through the approved mailbox or thread, attributable to the same enquiry, confirming that the clinician wants the conversation to continue (CLINICIAN_REPLY_CONTINUE). Calls, bookings, automated replies, delivery receipts, forwarding, operator messages, rights requests and unknown events never qualify.
Rate-limit and duplicate-prevention records expire automatically after about 25 hours and 7 days respectively, subject to Firestore time-to-live deletion.
Notification-outbox fields on the submission record are retained with the submission until notification completes or is exhausted, then follow the main enquiry retention period.
Operator-mailbox copies follow our mailbox retention and deletion procedures and may persist in mailboxes, trash or recoverable items for limited provider-defined periods until deleted.
Infrastructure and security logs retained by Google Cloud Logging follow provider default or configured retention and are accessed only for security, troubleshooting and compliance needs.
Google-managed platform backups and exports may retain data for limited provider periods; deleted enquiry records are not restored into active systems when backups expire or roll over.
If a record must be retained for a binding legal obligation or a specific actual or anticipated legal claim, access will be restricted and it will be deleted when the applicable obligation or claim-related period ends. Any exception is decided case by case, documented with its legal basis, scope and review date, access-restricted, and ended promptly when the binding obligation or specific actual or anticipated claim need ends.
9. Your rights
Subject to the conditions and limits in applicable law, you may ask us to give you access to your personal data, correct it, erase it or restrict its use.
You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f). We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or need the data to establish, exercise or defend legal claims.
The right to data portability does not apply to the processing described here because it is not based on consent or contract.
To exercise a right, contact hello@clinicmatcher.com. We may need enough information to verify your identity and locate the record.
You may lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados, at www.cnpd.pt. You may also complain to the supervisory authority in the EU or EEA Member State of your habitual residence, place of work or the alleged infringement.
10. Automated decisions
We do not use the form information for decisions based solely on automated processing that produce legal effects or similarly significant effects. We do not use it for profiling.
11. Security
We use technical and organisational measures including least-privilege service accounts, Secret Manager references for application secrets, origin-restricted form submission, pseudonymous rate limiting, structured logging without raw personal data in application logs, and monitoring of notification health. Report suspected incidents to hello@clinicmatcher.com.
12. Cookies and similar technologies
This site does not use advertising or analytics cookies. It uses self-hosted styles, scripts and fonts only. When the form is enabled, the browser sends submissions to the same-origin API route configured in runtime-config.js. We do not use non-essential terminal storage for tracking.
13. Changes and new purposes
We may update this notice when the service or legal requirements change. The effective date identifies the version. If we intend to use personal data for a new purpose, we will provide the information required by law before that further processing begins.
14. Contact
Questions about this notice may be sent to hello@clinicmatcher.com.
Return to ClinicMatcher