Privacy Policy
Privacy Policy
This Privacy Policy explains how Algarve Pain Centre may collect, use, retain, disclose, and protect personal data when you use this website or contact the clinic. It is designed as a practical GDPR-aligned transparency notice.
Who we are
Algarve Pain Centre is a multidisciplinary healthcare provider based in the Algarve, Portugal. For the purposes of applicable data protection law, Algarve Pain Centre is the controller of personal data processed through this website unless a different role is stated for a specific service.
Information we collect
Depending on how you interact with the website, we may collect:
- contact details you submit, such as name, email address, phone number, or message content;
- appointment or enquiry details you voluntarily provide through forms or direct communication;
- technical information such as IP address, browser type, device characteristics, and referring page;
- consent preferences relating to cookies and privacy-sensitive embedded services.
We ask that you do not submit unnecessary special-category health data through general website forms unless specifically requested by a clinician or secure patient process.
How we use information
We may use personal data to:
- respond to enquiries and appointment requests;
- manage communications about services, availability, or follow-up actions you requested;
- maintain website functionality, security, and accessibility;
- document and honour cookie-consent choices;
- comply with legal, regulatory, or professional obligations.
Legal bases for processing
Under GDPR, our legal bases may include one or more of the following:
- your consent, for example where optional cookies or third-party embeds require it;
- taking steps at your request before entering into a service relationship;
- our legitimate interests in operating, securing, and improving the website, provided those interests do not override your rights;
- compliance with legal obligations applicable to healthcare, accounting, or regulatory record-keeping.
Retention and security
We retain personal data only for as long as reasonably necessary for the purpose it was collected, including legal, clinical, administrative, and security obligations. Retention periods may differ depending on the type of enquiry or service involved.
We apply proportionate technical and organisational measures to protect personal data, including access controls, secure transport measures, and privacy controls for optional embedded services. No website can guarantee absolute security, but we work to reduce risk appropriately.
Your rights
Subject to legal conditions and exceptions, you may have the right to:
- request access to personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request erasure where continued processing is not required;
- object to certain processing or request restriction of processing;
- withdraw consent where processing depends on consent;
- request data portability where applicable.