ClinicPeek · Privacy policy
Privacy policy
How ClinicPeek uses your data: storage, privacy and your rights.
Controller and contact
The operator is responsible for processing personal data on this website. The full operator details appear below. Send privacy requests through the contact form using the Privacy topic. Identify the relevant account or request without sending unnecessary sensitive information.
Agency.one LimitedUnit 1603, 16th Floor
The L. Plaza
367–375 Queen’s Road Central
Sheung Wan
Hong KongContact us
Technical operation and security
Serving this website requires connection information such as your IP address, request time, requested address and browser information. This information is processed to deliver content and detect faults or abuse. Private data is available only to authorised people. Where the GDPR applies, necessary security processing relies on Article 6(1)(f); the legitimate interest is operating a secure and functioning website.
Contact requests
We process the name, email address, topic and message you supply to answer your request. Required fields are necessary for a response; the form cannot be submitted without them. Processing relies on the consent given in the form (Article 6(1)(a) GDPR where applicable), which you may withdraw for the future. Requests to prepare or perform a contract may rely on Article 6(1)(b). Sending a message does not subscribe you to marketing.
Accounts and access
Accounts contain names, email addresses, protected credentials and roles. Session cookies support sign-in. Organisation and team permissions control access. Processing provides and secures the requested account (Articles 6(1)(b) and (f) GDPR where applicable).
Retention
Closed general contact and support records are scheduled for deletion 90 days after their last update. Delivered email texts are removed after 30 days. Open requests are retained for handling. Account, organisation and published profile records are retained while needed for their purpose. Legal retention obligations or the necessary protection of legal claims may require longer retention.
Recipients and transfers
General contact requests go to the responsible operator team. The website stores requests with the operator. Technical suppliers may process information only for their assigned services and agreed access permissions. External links lead to independent websites with their own privacy information.
Your rights
Subject to the applicable legal conditions, you may request access, correction, erasure, restriction and portability. You may object to processing based on legitimate interests for reasons relating to your particular situation. You may withdraw consent for future processing; earlier lawful processing remains unaffected. You may complain to a competent supervisory authority, particularly where you live, work or believe an infringement occurred. A proportionate identity check may be needed to handle a request.
Automated decisions and changes
The general contact form and site search do not make decisions producing legal or similarly significant effects. Search ranks relevant public information using your search terms. This notice is updated when features or services change.
Uploaded media
Files and rights confirmations are stored with their project, organisation and profile or property. Approved images and property videos can be accessed through their published listing; PDF documents remain within the authorised portal. Removing media from a profile detaches it but does not immediately delete the stored file. There is currently no automatic deletion routine for these files.
Clinic profiles and enquiries
Published profiles contain public professional information and authorised submissions. Sources and research dates are retained internally. Your selected clinic organisation and the operator receive a clinic enquiry. Do not send medical documents or detailed medical history. Clinics are responsible for their own processing.
Optional analytics
Analytics starts only with permission and respects Do Not Track. Page and profile views, contact actions, sessions and successful clinic enquiries are counted without names, emails, message contents or IP addresses in analytics. Pseudonymous browser and session identifiers support counts; no session recordings. The browser identifier lasts 90 days, your privacy choice 180 days, and sessions end after 30 minutes of inactivity. Reports include path, market, language, device, resolution, browser information and referring domain. Events are removed after 180 days. Withdraw permission through footer Privacy preferences.
Saved items and site search
Saved items and comparison lists are stored on your device and can be cleared there. Site search processes your search term to find published pages. Terms appear in the page address, so do not enter confidential information.
Interactive maps
Opening a map fetches content from OpenStreetMap, which receives your IP address and technical request information. Consult its privacy information as well. You can use the website without opening a map.
Email delivery with Brevo
We send the recipient address, sender, subject and message, including personal confirmation or recovery links where applicable, to Brevo through an encrypted API connection for delivery. This covers account messages, requested notifications and newsletters after consent. Brevo also processes technical sending and delivery information. Our application does not transfer the full project database or visit analytics to Brevo. Recipient records remain separated per project in our shared system.
Brevo currently adds opening pixels and may rewrite links to measure clicks. Loading a pixel or following a measurement link sends Brevo the associated recipient identifier, time and technical connection information, including IP address and browser details. Tracking is currently not anonymised in the Brevo account. Confirmation emails respond to a requested newsletter subscription; the subscription becomes active only after confirmation.
Hosting with Hetzner
Hetzner hosts the application server and database. Account, profile and request data and necessary technical connection information are processed there. Backups also contain stored project data.
Delivery and protection through Cloudflare
Website requests pass through Cloudflare to our server. Cloudflare processes your IP address, requested address, technical connection information and submitted requests, including forms and sign-ins. Cloudflare provides HTTPS and delivery and security functions. Processing may take place across its worldwide network. Website access protection does not replace application sign-in and permission checks.