Privacy Policy
Version 1.1 – last updated: 24 July 2026
This policy explains how Apolline Clinique Dentaire processes your personal data when you visit https://apolline.be, use its forms or contact the clinic to request information or an appointment. It should be read together with the information displayed in our cookie manager.
We do not sell your personal data. We restrict its use to specified purposes and access to those individuals and service providers who need it.
1. Data controller and contact details
For the processing activities relating to the Website described in this policy, the data controller is DENTALUX, a Belgian private limited company trading as Apolline Clinique Dentaire, registered with the Crossroads Bank for Enterprises under number 0640.672.627 and having its registered office at Avenue des Gloires Nationales 65-66, 1083 Ganshoren, Belgium. The Apolline Clinique Dentaire establishment unit and clinic are located at Avenue Brugmann 577, 1180 Uccle, Belgium.
You can contact us:
- by email: info@apolline.be;
- by telephone: +32 2 203 77 21;
- at the clinic: Apolline Clinique Dentaire, Avenue Brugmann 577, 1180 Uccle, Belgium;
- by post to the registered office: DENTALUX SRL, Avenue des Gloires Nationales 65-66, 1083 Ganshoren, Belgium.
Where a request results in care and data is added to a patient record, the identity of the controller responsible for that record and the information specific to clinical processing are provided to you in a separate notice supplied or made accessible as part of your care. This Website policy does not describe such clinical processing and does not replace that notice.
2. Scope
This policy covers browsing the Website, contact and appointment request forms, email or telephone communications, cookie choices, audience measurement and online advertising. If a request results in care being provided, certain information may be added to the patient record and will then be processed in accordance with the rules applicable to healthcare, patients’ rights and professional secrecy.
The Website and its forms are not intended for emergencies. Do not send X-rays, medical documents or detailed health information through them unless an authorised member of the clinic expressly asks you to do so through an appropriate channel.
3. Data we may process and its sources
Depending on how you use the Website and the information you choose to provide, we may process:
- your identification and contact details, such as your name, email address and telephone number;
- the subject matter, content and follow-up of your request, as well as the information needed to arrange an appointment;
- health data that you provide voluntarily or that is strictly necessary to handle your request or arrange your appointment;
- technical data, including the IP address, date and time, requested pages, referring URL, language, browser and device type, HTTP headers and security logs;
- your choices and identifiers relating to cookie consent;
- with your consent, audience measurement and advertising attribution data.
This data mainly comes from you, your browser or your device. To process a request submitted through the Website, certain information may also be provided to us by your legal representative or, at your request and where permitted by law, by a healthcare professional. If data is collected from another source, the required information will be provided to you in accordance with applicable law.
Health data that is clearly unrelated to your request is not used for other purposes: its processing is restricted and it is deleted as soon as its retention is no longer necessary or legally required.
4. Purposes and legal bases
We process data only where a legal basis permits us to do so:
- answering your questions and arranging an appointment: steps taken at your request prior to entering into a contract and, where the request does not relate to a contract, the legitimate interest in responding and managing communications;
- ensuring operation, security and the prevention of misuse: the legitimate interest in operating and protecting the Website, as well as compliance with a legal obligation where applicable;
- processing health information strictly necessary to organise your request and forwarding it to the relevant professional: steps taken at your request, legal obligations and, for necessary health data, Article 9(2)(h) of the GDPR, under the responsibility of professionals who are subject to professional secrecy. The provision of care and maintenance of the patient record are described in the separate clinical notice;
- handling requests concerning your rights, complaints and disputes: a legal obligation, the legitimate interest in establishing, exercising or defending legal claims and, where necessary, Article 9(2)(f) of the GDPR;
- recording and demonstrating your cookie choices: compliance with the rules applicable to trackers and the legitimate interest in retaining appropriate evidence of your choices;
- measuring audiences, measuring conversions or personalising advertising: your prior consent to non-essential cookies and other trackers;
Where processing is based on our legitimate interest, we balance that interest against your rights and freedoms. You may request further information about this assessment.
5. Health data and patient records
Health data benefits from enhanced protection. It is accessible only to authorised persons and, where necessary for care, is processed by or under the responsibility of professionals who are bound by professional secrecy.
Separate and tailored information is provided or made accessible when care is provided to explain in greater detail the patient record, its controller, recipients involved in care, billing, exchanges with health insurance funds or insurers and any clinical tools. Where a patient record is maintained by a healthcare professional, that professional retains it for at least thirty years and no more than fifty years from the patient’s last contact, in accordance with applicable Belgian law.
6. Mandatory or optional nature of the data
Fields marked as mandatory are required in order to process your request or arrange the appointment. If you do not provide them, we may be unable to respond to you or arrange the requested appointment. Other information is optional.
Refusing non-essential cookies has no effect on access to care or on the essential features of the Website.
7. Cookies and Google tools
Strictly necessary cookies may be used without consent where they are essential to the operation or security of the Website or to recording your preferences. Statistical, advertising and other non-essential trackers are activated only after you have given your consent.
You can accept, refuse or customise these trackers with comparable ease and then change your choice at any time using the permanent “Manage my cookie preferences” link or button. Continuing to browse does not constitute consent. The current list of cookies and technologies, including their provider, purpose and duration, is available in the Website’s CookieYes manager.
The Website uses Google Tag Manager to manage the firing of tags. Depending on your choices, these may include Google Analytics 4 for audience measurement and Google Ads for conversion measurement or advertising. Google Tag Manager does not, by itself, constitute authorisation to load these services: their activation must comply with your preferences.
8. Recipients and service providers
To the extent necessary for each purpose, your data may be accessible:
- to authorised members of DENTALUX and professionals involved in your care;
- to our hosting, security, IT maintenance, messaging and backup service providers, including WP Engine for hosting the Website;
- to CookieYes for managing your cookie choices;
- to Google Ireland Limited and its group entities for Google Tag Manager, Google Analytics 4 and Google Ads, only to the extent authorised by your choices and in accordance with the terms applicable to those services;
- to our advisers, insurers, accounting service providers or competent authorities where justified by a legal obligation or the defence of our rights.
Depending on the service, these recipients may act as processors, independent controllers or joint controllers. We restrict access on a need-to-know basis and impose appropriate contractual commitments where a service provider acts on our behalf.
9. Transfers outside the European Economic Area
Certain international service providers may process data, or make it accessible, outside the European Economic Area. Where required by the GDPR, these transfers are based on an adequacy decision by the European Commission, standard contractual clauses or another appropriate safeguard, supplemented by additional measures where necessary.
You may contact us for information about the applicable mechanism and, where permitted by law, a copy of the relevant safeguards.
10. Retention periods
We retain data only for as long as necessary for the relevant purpose and subsequently for the periods required by law or necessary for establishing, exercising or defending legal claims. In particular:
- a contact or appointment request that is not added to a patient record is deleted or anonymised no later than twenty-four months after the last relevant exchange, unless a legal obligation or dispute requires otherwise;
- data added to the patient record is subject to the statutory retention periods referred to in Section 5;
- automatic Website backups made by WP Engine are retained for thirty days; technical and security logs are deleted or anonymised at the end of the period documented by the hosting provider, unless a specific incident requires their isolation for the duration of its analysis or a dispute;
- user-level and event-level data recorded in Google Analytics 4 is retained for no more than fourteen months; certain aggregated statistics may remain available for longer. Data processed by Google Ads is retained in accordance with the account settings and the periods specified by Google, to the extent authorised by your consent;
- evidence of your choices and consent is retained for up to five years after the consent is withdrawn or expires, solely to demonstrate its validity and comply with the applicable statutory time limits.
11. Your rights
Subject to the conditions set out in the GDPR, you may request access to and a copy of your data, its rectification or erasure, restriction of its processing or its portability. You may also object to processing based on a legitimate interest.
Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before that withdrawal. You may object to direct marketing, including related profiling, free of charge and at any time. Some rights are not absolute: erasure or objection may, in particular, be restricted by a legal or professional retention obligation, the continuity and safety of care or the need to establish, exercise or defend legal claims.
To exercise a right, contact us at info@apolline.be or at the postal address indicated in Section 1. Where there are reasonable doubts about your identity, we may request only the proportionate additional information necessary to verify it; a complete copy of your identity card is not systematically required.
We normally respond within one month of receiving the request. This period may be extended by two months where justified by the complexity or number of requests; in that event, we will inform you within the first month.
You may also lodge a complaint with the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, +32 (0)2 274 48 00, contact@apd-gba.be, https://www.dataprotectionauthority.be. You may contact us beforehand so that we can review your request, but doing so is not a condition for exercising your right to lodge a complaint.
12. Security and confidentiality
We implement technical and organisational measures appropriate to the risk, including access restrictions, authorisation management, security of systems and communications, backups and incident-management procedures. Persons who access data are subject to a duty of confidentiality and, where applicable, professional secrecy.
No system offers absolute security. If you believe that your data has been compromised or sent to the wrong recipient, please contact us without delay.
13. Minors
The clinic also treats patients who are minors. Their data may be disclosed and processed by their legal representatives or under the other conditions laid down by patient-rights legislation, taking account of the minor’s age and capacity for discernment. Optional consents relating to cookies, marketing or the publication of images are managed separately from care.
14. Automated decision-making
We do not make any decision based solely on automated processing using data collected through the Website that produces legal effects concerning you or similarly significantly affects you. Subject to your consent, advertising service providers may carry out measurement, attribution or personalisation activities; Apolline Clinique Dentaire does not use them to make a medical decision or determine your access to care.
15. Updates to this policy
We may update this policy to reflect changes to the Website, our practices or the law. The version in force is the one published on the Website. If a material change is made, we will inform you by an appropriate means. We will not reuse your data for an incompatible purpose without providing the required information and having a valid legal basis.
