Data protection
Privacy policy
This policy explains how personal data sent through the contact form on www.martalopezdental.com is processed.
Personal data collected
When the contact form is used, the following data may be processed:
- Name.
- Email address.
- Subject of the enquiry.
- Message sent by the user.
- Short-lived technical security data, such as the IP address and form timing metadata, used to limit spam and abuse.
This form is not intended to collect health data. Do not include symptoms, diagnoses, medical history, medication or treatment details. For clinical questions, contact the clinic where you receive care directly.
Purpose of processing
The data is used only to respond to a general enquiry. If a question requires clinical assessment, the user is asked to contact the relevant clinic directly; information submitted through this form is not automatically forwarded. The data is not used for marketing or profiling.
Legal basis
Responding to general enquiries is based on the legitimate interest in handling professional communications and, where an enquiry concerns possible services, on taking steps at the user’s request before a potential professional relationship. Consent is used only where it is genuinely required for a specific processing activity.
Data processors
Limited technical providers are used to operate the site and receive enquiries:
- Netlify, as hosting and deployment provider for the website.
- Resend, as technical provider for sending emails generated by the contact form.
- Google (Gmail), as the mailbox provider where messages delivered by Resend are received and stored.
- Cloudflare, as provider of DNS, security and CDN services.
The website does not store enquiries in its own database; messages are sent through Resend and received in a Gmail mailbox.
International transfers
Some technical providers may process data outside the European Economic Area. Where this occurs, processing must rely on appropriate safeguards under the GDPR, such as standard contractual clauses or other mechanisms recognised by applicable law.
Data retention
The website does not store enquiries in its own database. Messages are kept only for the time necessary to respond and manage reasonable professional follow-up, unless an applicable legal obligation requires otherwise. Application-level anti-abuse records, such as a temporary IP address record, are kept in volatile memory for up to approximately 10 minutes. This application-level retention window does not determine how long technical request logs may be retained by infrastructure providers such as Netlify, Cloudflare or Google under their own settings and policies.
User rights
The user may exercise the rights recognised by the GDPR, including:
- Access to their personal data.
- Correction of inaccurate data.
- Erasure of their data where applicable.
- Objection to processing.
- Restriction of processing.
- Data portability, where applicable.
- Withdrawal of consent, without affecting the lawfulness of previous processing.
How to exercise rights
The user may exercise their rights through the contact form available on the website. The request must allow the applicant and the right they wish to exercise to be reasonably identified.
If the user considers that the processing of their data does not comply with the rules, they may lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch data protection authority.
Security
Basic technical and organisational measures are applied to protect data sent through the form, including secure transmission via HTTPS, limitation of the data requested and the use of specialised technical providers for hosting and email delivery.
Cookies and tracking
This website does not use advertising cookies, profiling cookies, remarketing cookies, or analytics cookies based on personal identifiers.
The website uses a functional preference cookie to remember the user's selected language. It is not used for advertising tracking or profiling.
The selected light or dark theme may be stored locally in the browser. This preference is not used for tracking or profiling.
The website does not set consent-based advertising or marketing cookies, so no cookie banner is shown.
Aggregated web analytics
When Cloudflare Web Analytics is enabled for the production domain, it is used to obtain aggregated statistics such as visited pages, number of visits, approximate country, device type, browser, traffic sources/referrers and performance metrics.
These aggregated statistics are used only to understand general website usage, improve performance and detect technical issues. They are not used for advertising, remarketing or individual user profiling.
Data controller
- Controller
- Marta Lopez B.V.
- Trading name
- Marta López Dental
- Country
- Netherlands
- KVK
- 97552143
- Registered office location
- Zwolle, Netherlands
- Contact
- The user may exercise their rights through the contact form available on the website.
Last updated
7 August 2026.
