Privacy Policy

WhatClinic (“we”) are committed to safeguarding the privacy of our website visitors and registered users of the WhatClinic platform; this Notice sets out how we will treat your personal data when we act as the controller of that data and when its processing is governed by the EU General Data Protection Regulation (GDPR), which came into force on 25th May 2018 (a copy of the GDPR is available here).

Topics:

Definitions

We use the term “personal data” to refer to any information collected or processed by, or in connection with, this website or the platform, that directly, or indirectly, identifies you or factors specific to you, such as your name, IP address or user preferences.

Below we describe “lawful grounds” for processing your personal data. These lawful grounds (sometimes also referred to as “legal basis”) are the justification under GDPR for the processing of your personal data. If there are no lawful grounds for processing your personal data neither we nor anyone else is permitted to access or process your personal data.

Lawful grounds

If you are a registered platform user, or a website user, the lawful grounds for processing your Collected Information is our legitimate interest in understanding how users interact with this website and the platform, and to improve how we promote our products and services. These are described in more detail in the sections on how and what data we collect and how we use it.

What data do we collect?

We may collect, store and use the following kinds of information and personal data (“Collected Information”):

  1. Information and personal data about your visits to and use of this website and our platform. We collect data about your computer and your visits to this website or the platform, including your IP address, geographical location, browser type, referral source, length of visit, and number of page views, all of which are also Collected Information.
  2. Information about any transactions carried out between you and us on this website, including information relating to any purchases you make of our goods or services. Depending on your type of interaction, we may collect:
    • Contact information (where provided: First and last name, title, email, phone, address, postcode) Connection data (IP address, browser type, user agent)
    • Localisation data (geographical location)
    • Application usage data (referral source, length of visit, number of page views)
    • Information relating to your enquiries made to clinics
    • Information relating to your reviews left about clinics
    • Email communication data, if made via our platform/service
    • Phone call and call recording data, if made via our platform/service
    • WhatsApp and SMS communication data, if made via our platform/service
  3. Information that you provide to us for the purpose of registering with us on the website or platform and/or subscribing to our website services and/or email notifications. We collect first and last name, email address, and phone number for these purposes.

How do we collect your data?

You directly provide us with most of the data we collect. We collect data and process data when you:

We may also receive your data indirectly from the following third-party sources:

How will we use your data?

Collected Information, including personal data, will be used to:

  1. Create an enquiry with the clinics you have personally selected to contact;
  2. Provide public feedback about the clinics you have personally selected to review;
  3. Administer and improve this website’s and the platform’s usability;
  4. Improve your browsing experience by modification and replacement of text, images, videos, or links to increase relevance to the visitor; such as localising phone numbers and currency to match the user country;
  5. Where you have consented, send you marketing and other communications relating to our business or the businesses of carefully selected third parties which we think may be of interest to you by post, by email or similar technology. We use Campaign Monitor for this purpose;
  6. Provide other companies with statistical information about our users. Information we provide to other companies will not identify any individual user. We use YesWare and Google Analytics for this purpose. Allow us to see what enquiries made through our system get responded to, though we restrict who can see the content of the responses. WhatClinic uses a third party, MailGun, to route emails between Clinics and Users and vice versa; We have a similar system for phone calls, routing them through a company called Twilio. We record these calls only with the express permission of the Clinic and notify users prior to commencing the call.
  7. Collect feedback about our own services from independent third-party companies. We use Trustpilot for this purpose.

Sharing collected data

We may share Collected Information about you:

  1. With third-party service providers (Clinics) that you have personally selected via the website or through communication with our User Support Team. Only the data you have provided will be shared. We will send you details of the Clinics you have selected and their contact information at the time of enquiry creation, should you require a copy of this information, please contact us. Please note, we are not responsible for the Privacy Policies of third-party service providers.
  2. To enable our third-party sub-processors to provide data centre hosting services (AWS), database hosting services (AWS), dialer infrastructure services (Twilio), email sync services (Mailgun), and to enable our third party processors to provide sales and marketing operations services (Campaign Monitor, YesWare, Google Analytics, TrustPilot);
  3. To enable our partners, 121BPO, with whom we have a NDA, to respond to user enquiries and maintain clinic data;
  4. To the extent that we are required to do so by law;
  5. In connection with any legal proceedings or prospective legal proceedings;
  6. In order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk).
  7. In response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

How do we store and secure your data?

We will take reasonable precautions to prevent the loss, misuse, or alteration of your personal data. Our website uses HTTPS, which ensures secure transmission of data from your browser to our servers. We will store all the personal data you provide or that we collect about you on our secure servers. Our servers are hosted on AWS in Dublin, Ireland. Sensitive data is encrypted and access is restricted. Personally identifying information is anonymised where used for test or training purposes.

You are responsible for keeping your passwords confidential. We will not ask you for your passwords.

Retention of data

We retain essential personal data related to your use of the website or the platform until this data is requested to be purged from our systems by you or an authorised member of your organisation. Your data protection rights are described in more detail below. If you would like to request access, rectification, transfer, or erasure of your data please contact us.

We regularly conduct internal audits to purge data that is no longer relevant or for which the purpose has been fulfilled.

Server log files are automatically purged after one year.

Access to your data

If you use this website, upon request, WhatClinic will grant you access to your personal data and allow you to correct, amend or delete information that we hold on you. See Contact Us details on our website.

If you are a platform user, we depend on you to update and correct your personal data to the extent necessary for the purposes for which that data was collected, such as contact information you provide to us so that we can provide you with invoicing information.

What are your data protection rights?

You are entitled to have any inadequate, incomplete, or incorrect personal data corrected (that is, rectified).

You also have the right to request access to your personal data (including receiving a copy thereof) as well as additional information about how the data was processed.

If we ever process your personal data, with the lawful grounds of your consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Furthermore, you are entitled to have your personal data erased under certain circumstances.

As of May 25, 2018, you also have the following additional rights:

Where your personal data is subject to restriction we will only process it with your consent or for the establishment, exercise or defence of legal claims.

You also have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work or place of alleged infringement, if you consider that the processing of your personal data infringes an applicable law.

You may contact us if you wish to exercise any of your rights in respect of your personal data processed by this website or the platform. If you make a request, we have one month to respond to you.

Please Contact Us for any further information or to make a request.

Marketing

If you have agreed to receive marketing, you may always opt out at a later date. If you no longer wish to be contacted for marketing purposes, please click here.

Cookies and other tracking technology

We use cookies on this website. A cookie is a text file sent by a web server to a web browser and stored by that browser. The text file is then sent back to the server each time the browser requests a page from the server. This enables the web server to identify and track the web browser.

We may send one or more cookies which may be stored by your browser on your computer. The information we obtain from cookies is part of the Collected Information. Our advertisers and service providers may also send you cookies.

Most browsers allow you to refuse to accept cookies. (For example, in Internet Explorer you can refuse all cookies by clicking “Tools”, “Internet Options”, “Privacy”, and selecting “Block all cookies” using the sliding selector.) This will, however, have a negative impact upon the usability of many websites, including this one.

To improve our services and this site, we may retain third-party service providers to operate this site and help us monitor, collect and analyse information regarding your interactions with this website and data you input, including through the use of such providers’ cookies on your computer.

For more information about cookies and other tracking technologies we use, please see our Cookies Policy or visit allaboutcookies.org.

Privacy policies of other websites

The website contains links to other websites. We are not responsible for the privacy policies of third-party websites or such site operators’ actions including the collection or use of your personal data.

We use YouTube API Services in relation to certain content that we offer. By using the Services, you agree to be bound by the YouTube Terms of Service, YouTube API Terms of Service, and Google Privacy and Terms. You can modify your Google privacy and security settings in your Google Account Settings.

Changes to our privacy policy

We keep our privacy policy under regular review and place any updates on this web page. This privacy policy was last updated May 2023.

How to contact us

If you have any questions about our privacy policy, the data we hold on you, or you would like to exercise one of your data protection rights, please contact us.

How to contact the appropriate authority

Should you wish to report a complaint or if you feel that we have not addressed your concern in a satisfactory manner, you may contact the Irish Data Protection Commission.