Privacy Policy
Last updated: 24 June 2026
This Privacy Policy explains how HeidelBridge processes personal data when you visit this website, contact us, or submit a Snapshot request.
HeidelBridge provides non-clinical Patient Trust Intelligence services for dental clinics targeting German-speaking patients across inquiry, booking communication, and commitment.
This Privacy Policy applies to the website:
1. Controller
The controller responsible for data processing on this website is:
Volkan Samur
operating under the trade name HeidelBridge
Formanekgasse 12-14/1/4
1190 Vienna
Austria
Email: contact@heidelbridge.com
HeidelBridge is operated as a registered trade / sole proprietorship.
2. General information
We process personal data only where this is necessary to operate this website, respond to business inquiries, process Snapshot requests, communicate with prospective clients, improve the website, measure marketing performance, and comply with legal obligations.
Personal data means any information relating to an identified or identifiable natural person. This may include, for example, your name, email address, phone number, clinic name, clinic website, location, IP address, website usage data, and information you voluntarily submit through the website form or by email.
HeidelBridge does not provide medical, clinical, or legal services through this website. The Snapshot request form is intended for business inquiries from clinics or clinic representatives.
Please do not submit patient-identifiable medical data, patient names, treatment records, diagnostic files, health information, or other sensitive patient data through the website, form, or email.
3. Data collected when you visit the website
When you visit this website, technical data may be processed automatically to display the website, maintain security, prevent misuse, and ensure proper website functionality.
This may include:
-
IP address
-
Date and time of access
-
Browser type and version
-
Device type
-
Operating system
-
Referrer URL
-
Pages visited
-
Technical log data
-
Interaction data
-
Approximate location derived from technical data
-
Cookie and consent preferences
This data is processed to operate the website securely and reliably.
Legal basis: Art. 6(1)(f) GDPR, legitimate interest in operating a secure, functional, and reliable website.
4. Website hosting and Wix services
This website is created and hosted using Wix.
We use Wix services including:
-
Wix hosting
-
Wix Forms
-
Wix Analytics
-
Wix Automations
-
Wix CRM
Wix may process technical, usage, form, communication, and CRM-related data on our behalf or as otherwise described in Wix’s own privacy documentation. This may include information you provide through forms, technical website usage information, device and browser information, IP address, interaction data, and information required to operate the website and related business functions.
We use Wix Forms to collect Snapshot requests and business inquiries. We use Wix CRM and Wix Automations to organize submitted inquiries, store contact details, and support follow-up communication related to the submitted request.
Legal basis:
Art. 6(1)(b) GDPR, where processing is necessary for pre-contractual communication or responding to a request submitted by you.
Art. 6(1)(f) GDPR, legitimate interest in operating the website, managing business inquiries, maintaining website security, and organizing communication.
5. Snapshot request form
If you submit a Snapshot request through the website, we process the information you provide in order to review the request, assess whether the submitted clinic context appears suitable for a Snapshot Review, and communicate with you about possible next steps.
The form currently collects the following fields:
-
First name
-
Last name
-
Email address
-
Phone number
-
Clinic name
-
Clinic website
-
Country
-
City
-
Current challenge selection
-
Optional message field
-
Consent confirmation
The “Current challenge” field may include one or more of the following options:
-
German wording may feel unclear or translated
-
Aftercare, guarantee, or support information may be unclear
-
Pricing, costs, or treatment value may not feel clear enough
-
The clinic may not feel premium enough online
-
Treatment steps may be difficult to understand
-
Visitors view the website but do not send inquiries
-
Trust signals, proof, or reassurance may be missing
-
Unsure what German-speaking patients notice
-
We are not sure. We would like an outside-in view
-
Other
The optional message field may contain any additional information you choose to provide.
We process this data only for purposes connected with the business inquiry, including reviewing the submitted information, responding to your request, assessing suitability for a Snapshot Review, and managing related communication.
Submitting the Snapshot request does not create an obligation to purchase a full audit or any additional service.
Legal basis:
Art. 6(1)(b) GDPR, steps taken prior to entering into a potential contract.
Art. 6(1)(f) GDPR, legitimate interest in reviewing and responding to business inquiries.
6. Consent statement in the form
The form includes the following consent confirmation:
“I agree that HeidelBridge may process my submitted information to respond to this business inquiry. This is not a medical, clinical, or legal consultation. I have read the Privacy Policy, Imprint, and Terms of Use.”
This confirmation is used to ensure that users understand the business nature of the inquiry and the non-clinical, non-legal scope of the request.
Where processing is necessary to respond to the inquiry, the primary legal basis is Art. 6(1)(b) GDPR. Where the confirmation relates to acknowledgement of scope and documentation of consent or transparency, we may also process it based on Art. 6(1)(f) GDPR, legitimate interest in documenting submitted requests and user acknowledgements.
7. Processing of clinic websites and patient-facing touchpoints
If you provide a clinic website, webpage, form, communication example, or other patient-facing touchpoint, we may review the submitted material from a non-clinical, outside-in trust perspective.
This may include analysis of visible trust signals, patient-facing clarity, communication gaps, hesitation points, perceived reassurance, treatment explanation, pricing clarity, aftercare explanation, proof signals, and the quality of inquiry or booking communication.
This analysis does not constitute:
-
medical evaluation
-
clinical evaluation
-
legal review
-
regulatory assessment
-
treatment outcome evaluation
-
patient volume guarantee
If submitted materials contain personal data, we process such data only to the extent necessary for the requested review or pre-review assessment.
Please anonymize or remove patient-identifiable information before submitting any communication examples.
Legal basis:
Art. 6(1)(b) GDPR, where the processing relates to a submitted service request.
Art. 6(1)(f) GDPR, legitimate interest in assessing business materials submitted by the requesting clinic or representative.
8. What we do not request
We do not request the submission of:
-
patient names
-
patient medical histories
-
treatment records
-
diagnostic images
-
health insurance information
-
patient correspondence containing identifiable health information
-
other patient-identifiable sensitive data
-
If such data is submitted inadvertently, we may delete it, ask you to resubmit anonymized information, or decline to process the request.
9. Contact by email
If you contact us by email, we process the information you provide in order to respond to your inquiry.
This may include:
-
name
-
email address
-
phone number, if provided
-
clinic or organization name
-
role or professional position, if provided
-
message content
-
any information voluntarily included in the communication
We use this data only to respond to your message, process your inquiry, and manage the communication.
Legal basis:
Art. 6(1)(b) GDPR, where the communication relates to a potential or existing contractual relationship.
Art. 6(1)(f) GDPR, legitimate interest in general business communication.
10. Cookies and similar technologies
This website uses cookies and similar technologies.
Cookies are small files stored on your device. Similar technologies may include pixels, tags, scripts, local storage, and other tracking or measurement technologies.
Cookies and similar technologies may be used for:
-
website functionality
-
security
-
form operation
-
consent management
-
analytics
-
website performance measurement
-
marketing and advertising measurement
-
campaign attribution
Some cookies are necessary for the website to function. Others are optional and are used only where legally permitted and, where required, after you have given consent.
You can manage your cookie preferences through the cookie banner or cookie settings tool, where available. You can also adjust cookie settings in your browser.
11. Necessary cookies
Necessary cookies are required for basic website functions, security, page loading, consent settings, and form functionality.
These cookies cannot usually be disabled through the website without affecting website functionality.
Legal basis: Art. 6(1)(f) GDPR, legitimate interest in operating a secure and functional website.
12. Analytics and performance cookies
We use analytics tools to understand how visitors use the website and to improve website performance, content structure, and user experience.
Analytics tools may process information such as:
-
pages visited
-
time spent on pages
-
clicks and interactions
-
device type
-
browser type
-
approximate location
-
referrer information
-
session data
-
technical identifiers
-
cookie identifiers
Where analytics tools use non-essential cookies or similar technologies, they are used only with your consent where required.
Legal basis: Art. 6(1)(a) GDPR, consent, where required for analytics cookies or tracking technologies.
13. Wix Analytics
We use Wix Analytics to understand website performance and visitor behavior.
Wix Analytics may process usage information, traffic information, device and browser data, page visits, interaction data, and other website analytics information.
This helps us understand which pages are visited, how visitors interact with the website, and how the website can be improved.
Legal basis: Art. 6(1)(a) GDPR, consent, where non-essential analytics cookies or similar technologies are used.
14. Google Analytics
We use Google Analytics to measure website usage and understand how visitors interact with the website.
Google Analytics may process data such as:
-
pages visited
-
session duration
-
device and browser information
-
approximate location
-
referrer URL
-
interactions with the website
-
cookie identifiers
-
technical usage data
Google may process data on servers outside the European Union or European Economic Area. Google may also use data according to its own privacy documentation and settings.
Google Analytics is used only where legally permitted and, where required, after consent has been given.
Legal basis: Art. 6(1)(a) GDPR, consent.
15. Google Ads
We may use Google Ads for advertising, conversion measurement, campaign attribution, and performance analysis.
Google Ads may process information such as:
-
ad interactions
-
website visits after ad clicks
-
conversion events
-
cookie identifiers
-
device and browser data
-
approximate location
-
technical interaction data
-
This helps us understand whether advertising campaigns lead to relevant website interactions or form submissions.
Google Ads tracking is used only where legally permitted and, where required, after consent has been given.
Legal basis: Art. 6(1)(a) GDPR, consent.
16. LinkedIn Insight Tag
We use the LinkedIn Insight Tag to measure LinkedIn campaign performance, website visits, and conversions.
LinkedIn may process information such as:
-
page visits
-
URL
-
referrer
-
IP address
-
device and browser information
-
timestamp
-
cookie identifiers
-
interaction and conversion data
This helps us understand whether LinkedIn campaigns lead to relevant website visits or inquiries.
The LinkedIn Insight Tag is used only where legally permitted and, where required, after consent has been given.
Legal basis: Art. 6(1)(a) GDPR, consent.
17. TWIPLA Website Intelligence
We use TWIPLA Website Intelligence to analyze website traffic, visitor behavior, and website performance.
TWIPLA may process information such as:
-
page visits
-
session data
-
device and browser information
-
approximate location
-
referrer information
-
visitor interactions
-
technical identifiers
-
analytics data
Depending on the configuration, TWIPLA may use cookies or similar technologies.
TWIPLA is used only where legally permitted and, where required, after consent has been given.
Legal basis: Art. 6(1)(a) GDPR, consent, where non-essential analytics or tracking technologies are used.
18. Additional third-party apps from the Wix App Market
This website may use third-party apps or integrations offered through the Wix App Market if they are activated for website functionality, analytics, form handling, automation, security, communication, or other website-related features.
Third-party apps may process personal data according to their function and their own privacy documentation. This may include technical data, interaction data, form data, communication data, analytics data, or other information necessary for the app to operate.
Only apps that are actually activated on the website should process personal data.
If additional third-party apps are added in the future, this Privacy Policy should be updated where necessary to reflect the new processing activity.
Legal basis: Depending on the app and purpose, Art. 6(1)(a), Art. 6(1)(b), or Art. 6(1)(f) GDPR.
19. No newsletter or marketing email subscription
We do not currently operate a newsletter through this website.
We do not use submitted Snapshot request data to send newsletter emails or unrelated marketing emails.
We may, however, respond to your submitted business inquiry and communicate with you about the request you submitted.
20. Wix Automations and CRM
We use Wix Automations and Wix CRM to manage submitted inquiries, store contact details, organize communication, and support operational follow-up.
This may include:
-
storing form submissions
-
creating or updating contact records
-
sending automated confirmation messages
-
organizing inquiry status
-
supporting manual follow-up communication
Automated messages, if used, are related to the submitted request and are not newsletter marketing emails.
Legal basis:
Art. 6(1)(b) GDPR, pre-contractual communication and response to submitted requests.
Art. 6(1)(f) GDPR, legitimate interest in organizing business inquiries and communication.
21. Recipients of personal data
We may share or make personal data accessible to service providers where necessary for the purposes described in this Privacy Policy.
Recipients may include:
-
website hosting providers
-
Wix and Wix-related service providers
-
form and CRM providers
-
automation providers
-
email and communication providers
-
analytics providers
-
advertising and campaign measurement providers
-
cookie consent and tracking management providers
-
IT support providers
-
legal, tax, or accounting advisors, where necessary
-
public authorities, where legally required
Service providers are used only where required for the relevant processing activity and, where necessary, based on appropriate contractual arrangements.
22. International data transfers
Some service providers may process personal data outside the European Union or European Economic Area.
This may apply, for example, to providers such as Wix, Google, LinkedIn, TWIPLA, and other third-party technology providers, depending on their infrastructure, affiliates, subprocessors, and service configuration.
Where personal data is transferred to countries outside the EU or EEA, we aim to ensure that appropriate safeguards are in place, such as:
-
an adequacy decision by the European Commission
-
standard contractual clauses
-
additional technical or organizational safeguards
-
other legally recognized transfer mechanisms
Despite these safeguards, data processing in third countries may involve privacy risks depending on the laws of the destination country.
23. Data retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy.
For Snapshot requests and business inquiries, we generally retain submitted information for up to 12 months after the last communication, unless a longer retention period is required by law or necessary for the establishment, exercise, or defense of legal claims.
Typical retention periods may include:
-
Website technical logs: retained for a limited technical and security period.
-
Form submissions and Snapshot requests: up to 12 months after the last communication.
-
Email inquiries: up to 12 months after the last communication, unless a longer period is legally required or necessary for business documentation.
-
Contract-related communication: retained for the duration of the business relationship and applicable statutory retention periods.
-
Accounting and tax-related records: retained according to applicable legal retention obligations.
-
Cookie consent records: retained as long as necessary to document consent and compliance.
-
Analytics data: retained according to the settings and retention periods of the relevant analytics provider.
If personal data is no longer required, it will be deleted or anonymized unless legal obligations require further retention.
24. Data security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.
These measures may include access controls, secure account settings, careful handling of submitted information, and the use of reputable website and service providers.
No online transmission or storage system can be guaranteed to be completely secure.
25. Your rights
Subject to the conditions of the GDPR, you may have the following rights:
-
Right of access to your personal data
-
Right to rectification of inaccurate personal data
-
Right to erasure of personal data
-
Right to restriction of processing
-
Right to data portability
-
Right to object to processing based on legitimate interests
-
Right to withdraw consent at any time, where processing is based on consent
-
Right to lodge a complaint with a supervisory authority
To exercise your rights, please contact:
If you withdraw consent, this does not affect the lawfulness of processing carried out before withdrawal.
26. Right to object
Where we process personal data based on legitimate interests under Art. 6(1)(f) GDPR, you have the right to object to such processing on grounds relating to your particular situation.
If you object, we will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing serves the establishment, exercise, or defense of legal claims.
27. Cookie consent withdrawal
Where processing is based on cookie consent or consent for similar technologies, you may withdraw or change your consent through the cookie settings tool, where available.
You can also restrict or delete cookies through your browser settings.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
28. Supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority.
For Austria, the competent authority is:
Austrian Data Protection Authority
Datenschutzbehörde
Barichgasse 40-42
1030 Vienna
Austria
Website: www.dsb.gv.at
You may also contact the supervisory authority in your usual place of residence, place of work, or place of the alleged infringement.
29. Children’s data
This website and HeidelBridge services are intended for business users and clinic representatives.
We do not knowingly collect personal data from children.
30. Automated decision-making
We do not use personal data submitted through this website for automated decision-making that produces legal effects or similarly significant effects.
31. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, website functionality, service providers, tracking tools, or data processing practices.
The current version published on this website applies.
32. Contact
For questions about this Privacy Policy or the processing of personal data, please contact:
Volkan Samur
operating under the trade name HeidelBridge
Formanekgasse 12-14/1/4
1190 Vienna
Austria
Email: contact@heidelbridge.com