Cookie Policy
Privacy Policy
Last updated: 19 June 2026
Seapoint Clinic (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store and protect your personal data when you visit our website www.seapointclinic.ie, contact us, or attend one of our clinics. It also explains your rights under the General Data Protection Regulation (GDPR) and the Irish Data Protection Acts.
Please read this policy carefully. By using our website or our services, you acknowledge that you have read and understood it.
1. Who We Are (Data Controller)
The data controller responsible for your personal data is:
Granite Bungalow Research & Technologies Unlimited Company, trading as Seapoint Clinic Registered in Ireland under company number 493725 Registered address: The Mall, Sandyford, Dublin, D18 KF78, Ireland
Our clinic locations:
- Blackrock, Co. Dublin
- Sandyford, Dublin 18
- Cork
If you have any questions about this policy or how we handle your data, you can contact us at info@seapointclinic.ie or by post at the address above.
2. The Information We Collect
We may collect and process the following categories of personal data:
Information you give us directly:
- Identity and contact details — name, address, email address, telephone number, date of birth
- Appointment details — the clinic, treatment or service you are enquiring about, preferred times
- Health information — your medical and dental history, treatment records, clinical notes, images, scans and x-rays (see Section 4 on special category data)
- Payment details — information needed to process payments, including bank details for SEPA Direct Debit or card payment information processed by our payment provider
- Correspondence — any information you provide when you contact us by phone, email, web form or social media
- Social messaging (Facebook, Instagram & WhatsApp). When you contact us through Facebook Messenger, Instagram Direct or WhatsApp, we receive and store the messages you send,
▎ together with your name, profile photo and the account identifier provided by Meta Platforms Ireland Ltd, so our staff can read and reply to your enquiry. We use this
▎ information solely to communicate with you about your enquiry and care — never for advertising, and we do not sell or share it with third parties. You can stop these messages
▎ at any time by replying STOP, and you can request deletion of this data at any time by emailing info@seapointclinic.ie or through Facebook/Instagram’s built-in data-deletion
▎ request.
Information we collect automatically when you use our website:
- Technical data — IP address, browser type, device information, operating system
- Usage data — pages visited, time spent on the site, referral source, and other analytics data
- Cookie data — see Section 5
3. How We Use Your Information and Our Legal Basis
Under GDPR we must have a lawful basis for processing your personal data. We rely on the following:
| Purpose | Legal Basis |
|---|---|
| Responding to enquiries and booking appointments | Contract / steps prior to entering a contract |
| Providing dental and clinical care | Contract; legal obligation; and for health data, the bases set out in Section 4 |
| Processing payments and managing accounts | Contract; legal obligation (e.g. tax/accounting law) |
| Sending appointment reminders and recall notices | Legitimate interests; consent where required |
| Sending marketing communications (where you have opted in) | Consent |
| Improving our website and services through analytics | Consent (for non-essential cookies); legitimate interests |
| Meeting our legal, regulatory and professional obligations | Legal obligation |
You can withdraw consent at any time where we rely on it (for example, by unsubscribing from marketing emails).
4. Health Data (Special Category Data)
As a healthcare provider, we process information about your health, which is “special category data” under Article 9 of the GDPR and receives additional protection. We process this data on the following bases:
- Article 9(2)(h) — for the provision of healthcare and the management of healthcare services, and
- Article 9(2)(c) — where necessary to protect vital interests (e.g. in a medical emergency), and/or
- Your explicit consent where appropriate.
This processing is carried out by, or under the responsibility of, our clinical professionals who are subject to a duty of professional confidentiality.
5. Cookies and Website Analytics
Our website uses cookies and similar technologies to function correctly and to help us understand how visitors use the site. We use analytics tools (such as Google Analytics) to measure website traffic and improve our services.
Non-essential cookies (including analytics and marketing cookies) are only set with your consent, which you can give or refuse through our cookie banner. You can also manage cookies through your browser settings.
6. Sharing Your Information
We do not sell your personal data. We may share it with:
- Our clinical and administrative staff, on a need-to-know basis to provide your care.
- Service providers (data processors) who act on our behalf, such as our practice management software provider, IT and hosting providers, payment processors, and communication/reminder services. These providers are bound by contract to protect your data and may only use it on our instructions.
- Other healthcare professionals (e.g. your GP, a specialist, or a laboratory) where necessary for your treatment, with your knowledge.
- Regulatory, professional or legal bodies where we are required to do so by law or professional obligation.
- Professional advisers such as accountants, insurers and lawyers, where necessary.
7. International Transfers
Some of our service providers may process data outside the European Economic Area (EEA). Where this happens, we ensure appropriate safeguards are in place, such as European Commission adequacy decisions or Standard Contractual Clauses, so that your data continues to receive an adequate level of protection.
8. How Long We Keep Your Data
We keep your personal data only for as long as necessary for the purposes set out in this policy and to meet our legal and professional obligations.
- Patient/clinical records are retained indefinitely. As a healthcare provider, we keep clinical records for the long term to support your ongoing and future care, to meet our professional and regulatory obligations, and to be able to respond to any clinical or medico-legal matters that may arise over time.
- Financial and accounting records are retained as required by Irish tax and company law (generally six years).
- Website enquiry and marketing data is retained until you unsubscribe or ask us to stop contacting you. We review our marketing contacts periodically and remove details that are no longer relevant.
When data is no longer needed, it is securely deleted or anonymised.
9. How We Protect Your Data
We use appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration or disclosure. These include access controls, secure storage, staff confidentiality obligations, and the use of reputable, secure service providers.
10. Your Rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your data in certain circumstances (“right to be forgotten”).
- Restriction of processing in certain circumstances.
- Object to processing based on legitimate interests or to direct marketing.
- Data portability — to receive your data in a structured, commonly used format.
- Withdraw consent at any time where we rely on consent.
To exercise any of these rights, please contact us at info@seapointclinic.ie. We will respond within one month. We may need to verify your identity before acting on a request. There is normally no charge.
Please note that some rights (such as erasure) may be limited where we are legally required to retain clinical records.
11. Children’s Privacy
We provide treatment to patients of all ages, including children. Where we treat a minor, we obtain consent from a parent or guardian as appropriate and handle their data with the same care and protections described in this policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website, and the “Last updated” date at the top will reflect the most recent revision.
13. How to Contact Us and Your Right to Complain
If you have any questions, concerns or requests regarding this policy or your personal data, please contact us:
Granite Bungalow Research & Technologies Unlimited Company, trading as Seapoint Clinic Email: info@seapointclinic.ie Address: The Mall, Sandyford, Dublin, D18 KF78, Ireland
If you are not satisfied with how we have handled your data, you have the right to lodge a complaint with the Irish supervisory authority:
Data Protection Commission (DPC) Website: www.dataprotection.ie Address: 21 Fitzwilliam Square South, Dublin 2, D02 RD28 Telephone: +353 (0)1 765 0100 / 1800 437 737
[cmplz-document type=”cookie-statement” region=”eu”]