Legal
Privacy Policy
How SANFI Diagnostics collects, uses and protects the personal information you give us through this website.
Draft for review. This document was prepared as a starting point and has not been reviewed by a solicitor. It must be checked against the clinic's actual practices and approved by an Irish solicitor before the site goes live. Last updated: August 2026.
Who we are
SANFI Diagnostics (1 Blanchardstown Corporate Park, Ballycoolin Road, Blanchardstown, Dublin 15) is the data controller for the personal information described in this policy. You can contact us at info@sanfidiagnostics.com or on +353 87 382 1454.
[TO CONFIRM] Company registration number, and the name and contact details of the person responsible for data protection at the clinic.
What this policy covers
This policy covers information collected through this website only. Information collected when you attend the clinic, meaning your clinical record, images and reports, is covered separately by our patient data notice.
What we collect through this website
When you send an appointment enquiry, we collect:
- your name;
- your phone number and email address;
- the type of scan you are asking about, and your preferred appointment time;
- anything you choose to write in the message box;
- your IP address and browser information, recorded for security purposes;
- the date and time you gave consent.
The type of scan you request can reveal information about your health. Under the GDPR this is special-category data and receives additional protection.
Why we use it, and our legal basis
- To respond to your enquiry and arrange an appointment. Our legal basis is your consent under Article 6(1)(a), and Article 9(2)(h) where health information is involved, because the processing is necessary for the provision of healthcare.
- To keep a record of enquiries. Our legal basis is our legitimate interest in being able to demonstrate what was asked and what we responded, under Article 6(1)(f).
- To protect the website from abuse. Our legal basis is our legitimate interest in keeping the service secure, under Article 6(1)(f).
Who sees your information
Enquiries are read by clinic staff. Your details are held on our web hosting and email infrastructure, both located within the European Union. We do not sell your information, and we do not use it for advertising.
Separately from anything you send us, and only if you accept it in the cookie banner, the Meta (Facebook) Pixel reports the pages you view on this website to Meta so that we can measure our advertising. It never sees your enquiry, your name or anything you type. It is off until you accept, and our cookie policy explains what it collects and how to switch it off again. Meta is a United States company, so that information leaves the EEA under Meta's own transfer safeguards.
If you book through the online calendar instead of the enquiry form, that booking is handled by Cliniko, our practice management and scheduling provider, and the details you give it are held by them as well as by us. Using the calendar is entirely optional: the enquiry form and the telephone reach us without any third party.
[TO CONFIRM] The final list of processors, once hosting and email providers are contracted. Each requires a written data processing agreement.
Where your information is stored
Anything you send through the enquiry form stays within the European Economic Area. Our website hosting, database and email are all inside the EU.
Bookings made through the online calendar are held by Cliniko on its European Union data region, which is where our account is hosted. Cliniko itself is run by Red Guava Pty Ltd, an Australian company, and its support staff and some of its suppliers are outside the EEA, so limited access from outside the EEA is possible under the EU Standard Contractual Clauses in Cliniko's data processing agreement. If you would rather your details did not touch a third party at all, use the enquiry form or telephone the clinic instead.
[TO CONFIRM] That the clinic has signed Cliniko's EU Data Processing Addendum (cliniko.com/policies/eu_dpa), and that Cliniko has confirmed in writing where the EU region's data is physically stored. Both must be in place before launch.
How long we keep it
Website enquiries that do not lead to an appointment are deleted after [TO CONFIRM: proposed 12 months]. Where you go on to attend the clinic, your enquiry becomes part of your clinical record and is retained under the clinic's clinical retention schedule.
How we protect it
- The website is served over an encrypted HTTPS connection.
- Your name, phone number and message are encrypted in our database.
- Access to enquiries is limited to staff who need it.
- The site loads no analytics and no third-party fonts, and the one advertising tool it uses stays off until you accept it.
Your rights
Under the GDPR you have the right to:
- ask for a copy of the information we hold about you;
- have inaccurate information corrected;
- ask us to erase your information, where no legal obligation requires us to keep it;
- ask us to restrict how we use it, or object to our use of it;
- withdraw consent at any time, without affecting anything done before you withdrew it;
- receive your information in a portable format.
To exercise any of these rights, contact info@sanfidiagnostics.com. We will respond within one month.
Complaints
If you are unhappy with how we have handled your information, please tell us first so we can put it right. You also have the right to complain to the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963. See dataprotection.ie.
Changes to this policy
If we change how we use your information we will update this page and change the date at the top.