Privacy Policy

We, SeaDent Mallorca (hereinafter “we” or “SeaDent”), take the protection of your personal data very seriously. This privacy policy informs you about how we collect, process, and protect your data when you visit our website or use our services. It complies with the General Data Protection Regulation (GDPR) and applicable Spanish data protection law (LOPDGDD).

1. Controller

The controller within the meaning of the GDPR is:

Jan D. Heiringhoff

SeaDent Mallorca

Avenida de Jaime III, № 3, 07012 Palma de Mallorca, Illes Balears, España

Tel.: +34 603 31 96 48

E-Mail: info@seadent.es

2. Data Collected, Purposes and Legal Bases

We process personal data in the following cases:

  • Usage data when visiting the website (IP address, browser type, operating system, pages visited, date and duration) – legal basis: legitimate interest in the secure operation of the website (Art. 6(1)(f) GDPR), or your consent for analytics services (Art. 6(1)(a) GDPR).
  • Contact data for inquiries via form, email or phone (name, email, phone number, message) – legal basis: initiation/performance of a contract or legitimate interest (Art. 6(1)(b) and (f) GDPR).
  • Appointment and treatment data for scheduling and treatment – legal basis: contract (Art. 6(1)(b) GDPR) and provision of health care (Art. 9(2)(h) GDPR).

3. Server Log Files and Hosting

When you access our website, information is automatically collected in so-called server log files transmitted by your browser (e.g., IP address, date and time, requested file). This data is used for the technical provision, security, and stability of the website and is not merged with other data sources.

4. Cookies and Consent

Our website uses cookies. Necessary cookies are required for operation. Analytics and marketing cookies are only set after you have given explicit consent via our cookie banner (Consent Mode). You can withdraw or adjust your consent at any time via the cookie settings.

5. Google Services

Provided you have given consent, we use services of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Data may be transferred to servers in the USA; Google is certified under the EU-US Data Privacy Framework.

  • Google Analytics / Google Tag Manager – reach and usage analysis (with IP anonymization).
  • Google Maps – display of our location.
  • Google reCAPTCHA – protection of our forms against abuse.
  • Google Fonts – display of fonts.

6. Contact Form and Appointment Booking

When you contact us via the contact form or online appointment booking, we process the data you provide to handle your request and organize appointments. The data is treated confidentially and not shared with third parties without your consent, unless necessary to provide the service.

7. Digital reception (SmartAI)

Our website offers a digital reception („SmartAI"). It answers questions about the practice and takes requests. Using it is entirely optional — phone, WhatsApp, email and the contact form remain available as before.

Structured requests (booking, call-back, prescription and document requests, appointment management) are processed exclusively on our own systems. The contact details you provide there — name, phone number, email address — are never transmitted to an AI service provider.

Only freely worded questions are transmitted to an AI service provider in order to answer them. Before transmission our system automatically removes recognisable personal details from the text (email addresses, phone numbers, IBAN, DNI/NIE, dates of birth, web addresses). Even so, please do not enter health data or personal details into the free-text field; for anything personal please use the phone or the contact form.

The service provider is currently Fireworks AI, Inc., 541 Jefferson Ave, Redwood City, CA 94063, USA. This constitutes a transfer to a third country. It is based on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) together with an assessment of the legal situation in the recipient country; the legal basis for the processing is our legitimate interest in providing prompt information (Art. 6(1)(f) GDPR). The transmitted texts are not used by the provider to train AI models.

The conversation is not stored on our servers; it exists only in your browser's memory and ends when you close the window. If a question could not be answered and you choose to forward it to the practice team, we store only the redacted version of your question in our inbox so that we can reply to it.

If you want to reschedule or cancel an existing appointment online, we can send a confirmation code to your email address. Address and code are held only transiently in our server's memory and expire after ten minutes at the latest. We need this proof because appointment data is health data, which we may not disclose on the mere mention of an email address.

You are communicating with a digital assistant, not with a human being. It gives no medical advice and makes no diagnoses. In an emergency, please call us directly.

8. Health Data

In the context of dental treatments, we process special categories of personal data (health data) pursuant to Art. 9 GDPR. This processing is carried out exclusively for the purpose of health care (Art. 9(2)(h) GDPR) by medical or dental staff bound by professional secrecy, or on the basis of your explicit consent.

9. Data Sharing and International Transfers

Your data will only be shared if:

  • it is necessary to provide our services (e.g., to dental laboratories),
  • there is a legal obligation,
  • you have given explicit consent.
  • When using Google services, data may be transferred to the USA (see section 5).

10. Storage Period

We store personal data only as long as necessary for the stated purposes or as required by statutory retention periods (in particular for medical documentation). Analytics data is subsequently deleted or anonymized.

11. Your Rights

Under the GDPR, you have the following rights:

  • Access to the data stored about you (Art. 15),
  • Rectification of inaccurate data (Art. 16),
  • Erasure (“right to be forgotten”, Art. 17),
  • Restriction of processing (Art. 18),
  • Data portability (Art. 20),
  • Objection to processing (Art. 21),
  • Withdrawal of consent with future effect (Art. 7(3)).

12. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority in Spain is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid – www.aepd.es. You may also contact the supervisory authority of your habitual residence.

13. Data Security

We implement technical and organizational measures to protect your data against unauthorized access, loss, or misuse, including SSL/TLS encryption of the website.

14. Changes to this Privacy Policy

We reserve the right to adapt this privacy policy, e.g., due to legal or technical changes. The current version is always available on this website.

15. Privacy Contact

For questions about data protection or to exercise your rights, contact us at: SeaDent Mallorca · Jan D. Heiringhoff · Avenida de Jaime III, № 3, 07012 Palma de Mallorca, Illes Balears, España · +34 603 31 96 48 · info@seadent.es.

Last updated: August 2026

Cookie Settings

We use cookies to improve your experience on our website. By using our website, you agree to our cookie policy.