Privacy Policy

Privacy Policy

Last updated: 23 August 2026

This Privacy Policy describes how MintClinic Lda (“Mint Clinic”, “we” or “our”) collects, uses, stores and protects the personal data of its patients, website users and other data subjects, in accordance with Regulation (EU) 2016/679 (GDPR) and the remaining legislation applicable in Portugal.

By using our website mint.pt, by contacting us or by using our clinical services, you accept the terms of this Privacy Policy.

1. Data Controller

Controller: MintClinic Lda

Tax number (NIF): 516 838 598

Address: Avenida Marquês de Tomar 5B, 1050-152 Lisbon, Portugal

Telephone: +351 211 552 308

General e-mail: clinica@mint.pt

Website: mint.pt

Data controller / privacy contact: Sofia Martiniano (General Manager of the Clinic)

For any question relating to the protection of personal data or to this Privacy Policy, you may contact us at clinica@mint.pt.

2. What personal data we collect

We may collect and process the following categories of personal data, depending on the relationship you have with us:

2.1. Identification and contact data

  • Full name
  • Telephone
  • E-mail
  • Address (where necessary for invoicing or administrative management)

2.2. Clinical data

  • Dental and medical history relevant to the treatment
  • Results of complementary diagnostic examinations
  • Clinical images (e.g. radiographs, intraoral and extraoral photographs)
  • Treatment plan, procedures carried out and clinical notes

2.3. Appointment data and relationship with the clinic

  • Data on the booking, rescheduling and cancellation of appointments
  • Records of communications relating to appointments and treatments
  • Invoicing and payment data, where applicable

2.4. Website browsing data

  • Access IP address (anonymised or pseudonymised wherever possible)
  • Technical data on the device and browser used
  • Website usage information (pages visited, time spent, etc.), collected through functional cookies and anonymous analytical cookies

2.5. Contact forms and requests for information

  • Name
  • E-mail
  • Telephone
  • Content of the message you send us (reason for contact, questions, appointment requests, etc.)

2.6. Online appointment booking

First name and surname, telephone, e-mail, service and practitioner selected, date and time chosen, area to be assessed, tax number (NIF) (optional, for invoicing purposes) and data relating to payment of the booking fee.

2.7. Newsletter and marketing communications

  • Name
  • E-mail
  • Communication preferences, where applicable

2.8. Images for Clinical Cases

  • Before and after photographs
  • Other clinical images relating to the treatment

Patient images used in clinical cases and communication materials are only processed and disclosed with specific, informed and written consent, and the data subject may withdraw that consent at any time, without prejudice to the lawfulness of the processing carried out until then.

3. Purposes and legal bases for the processing

We process your personal data for the following purposes, on the legal bases indicated:

3.1. Provision of healthcare

  • Scheduling, managing and carrying out appointments and treatments;
  • Preparation of diagnoses, treatment plans and clinical follow-up;
  • Issuing of reports, certificates or statements where necessary.

Legal basis: performance of a contract (provision of healthcare services) and compliance with legal obligations in the area of health.

3.2. Administrative and accounting management

  • Management of invoicing and payments;
  • Management of schedules and communication relating to appointments;
  • Response to requests, complaints or queries.

Legal basis: performance of a contract and compliance with legal obligations of a tax and accounting nature.

3.3. Communication with patients

  • Confirmation of and reminders for appointments;
  • Relevant information on treatments or clinical follow-up.

Legal basis: performance of a contract and the legitimate interest of the clinic in managing the relationship with its patients.

3.4. Marketing and newsletter

  • Sending of informative communications about the services, campaigns or content of the clinic;
  • Sending of a newsletter by e-mail, where applicable.

Legal basis: consent of the data subject and, in certain cases, legitimate interest, always with the possibility of objection.

3.5. Management of the website and improvement of the user experience

  • Ensuring the technical functioning of the website;
  • Use of functional cookies and anonymous analytical cookies to improve performance and content.

Legal basis: the legitimate interest of the clinic in managing the website, and consent where required by the applicable legislation.

3.6. Publication of clinical cases

  • Presentation of clinical cases illustrating the treatments carried out;
  • Use of images and testimonials in digital or physical media.

Legal basis: the specific, freely given and informed consent of the data subject.

4. Cookies and browsing data

The Mint Clinic website uses cookies essentially to ensure its correct functioning and to collect anonymous statistical data on usage, so as to continuously improve the experience of users.

We use functional cookies (necessary for the basic functioning of the site) and anonymous analytical cookies (for aggregated statistics, without direct identification of users).

You may, at any time, configure your browser to block or delete cookies. However, some website features may not work correctly without certain essential cookies.

Our website may use Google services, such as Google Analytics or Google Ads, which use cookies and similar technologies to collect information about the use of the website, measure the effectiveness of campaigns and display personalised or non-personalised advertising. You can find out more about how Google uses data collected on sites and applications that use its services at: https://business.safety.google/privacy/

5. Sharing of personal data with third parties

Your personal data may be shared with third parties only where this is necessary, proportionate and duly protected. In particular, we may share data with:

5.1. Dental laboratories

We share strictly necessary data (e.g. patient name or code, relevant clinical data, examinations, moulds or images) with dental laboratories that work with us in the manufacture of prostheses, aligners or other devices required for the treatment.

5.2. Clinical management platform

We use the Novigest (Tactis) clinical management platform for the recording and management of patients’ clinical and administrative data, in a controlled environment and with appropriate security measures.

5.3. Cloud services and e-mail server

We may use hosting and e-mail services for the management of our communications and data (for example, the clinic’s e-mail server), ensuring that these providers offer appropriate guarantees of security and confidentiality.

5.4. Payment service provider

Payments made through the website, namely the appointment booking fee, are processed by Ifthenpay, Lda., which acts as a processor for that purpose. Mint Clinic does not store payment card data.

5.5. External marketing services

In certain situations, we use marketing service providers who assist us in the management of campaigns, communication and digital presence. These providers process only the data necessary for the purposes contracted and are subject to obligations of confidentiality and data protection. These providers may include digital advertising and analytics platforms, such as Google (for example, Google Ads or Google Analytics) and Meta (for example, Facebook or Instagram), which may use cookies or similar technologies to measure the performance of campaigns and display relevant content or advertisements.

5.6. Legal obligations and authorities

We may also transmit personal data to judicial, administrative or regulatory authorities, where this is required by law or necessary for the exercise or defence of rights in judicial proceedings.

6. Transfers of data outside the European Union

In certain cases, some of the service providers we use may be established outside the European Economic Area (EEA) or use infrastructure located in third countries, namely Google and Meta.

In those situations, we seek to ensure that appropriate data protection mechanisms are in place, namely:

  • Adequacy decisions of the European Commission, where applicable;
  • Standard contractual clauses approved by the European Commission;
  • Additional technical and organisational measures that reinforce the protection of the data.

Whenever international transfers are carried out, they will take place in accordance with the GDPR and with the guidelines of the data protection authorities.

7. Data retention periods

We retain your personal data only for the period strictly necessary to fulfil the purposes for which it was collected, respecting the legal periods applicable to the area of health, to taxation and to other legal obligations.

  • Clinical data: for the period required by the legislation applicable to health records and in accordance with the guidelines of the competent authorities.
  • Administrative and invoicing data: for the mandatory period laid down in tax and accounting law.
  • Contact data for marketing and the newsletter: until the data subject withdraws consent or exercises the right to object.
  • Data collected via contact forms: for the time necessary to manage the request and, if it results in a clinical relationship, for the period applicable to that relationship.

After the retention periods have elapsed, the data will be securely deleted or anonymised.

8. Rights of data subjects

As a data subject, you have the following rights, under the law:

  • Right of access: to obtain confirmation as to whether or not we process your data and, if so, to access it.
  • Right to rectification: to request the correction of personal data that is inaccurate or incomplete.
  • Right to erasure: to request the erasure of your personal data, where one of the grounds provided for by law applies.
  • Right to restriction of processing: to request the restriction of processing in certain situations.
  • Right to data portability: to receive the personal data you have provided to us, in a structured, commonly used and machine-readable format, or to request its transmission to another entity, where technically possible.
  • Right to object: to object to the processing of your personal data based on legitimate interests, including for direct marketing purposes.
  • Right to withdraw consent: where the processing is based on consent, you have the right to withdraw it at any time, without affecting the lawfulness of the processing carried out until then.
  • Right to lodge a complaint with the supervisory authority: you have the right to lodge a complaint with the Portuguese Data Protection Authority (Comissão Nacional de Proteção de Dados – CNPD) or with another competent supervisory authority.

To exercise any of these rights, you may contact us at clinica@mint.pt or by letter to the address of the clinic.

9. Security of personal data

We adopt appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction. These measures include:

  • Access control and user profiles;
  • Logging of access to clinical information in protected systems;
  • Use of up-to-date IT security solutions;
  • Training and awareness-raising of the team on confidentiality and data protection.

Despite all efforts, no information system is completely invulnerable. Should a personal data breach occur involving a risk to your rights and freedoms, the applicable legal procedures will be followed, including, where necessary, notification of the data subjects and of the competent authorities.

10. Data of minors

We do not knowingly collect or process personal data of minors under 16 years of age without the express and verifiable consent of their parents or legal representatives.

If you become aware that a minor has provided us with personal data without the appropriate consent, we ask that you contact us immediately at clinica@mint.pt, so that we can act accordingly.

11. Changes to this Privacy Policy

This Privacy Policy may be updated periodically, to reflect legislative changes or changes in our internal processes.

Whenever relevant changes are made, the updated version will be published on the website mint.pt, indicating the date of the last update.

We recommend that you consult this page regularly to keep yourself informed about how we process your personal data.

12. Contacts

For any question relating to this Privacy Policy or to the processing of your personal data, you may contact us through:

Should you consider it necessary, you may also lodge a complaint with the Portuguese Data Protection Authority (Comissão Nacional de Proteção de Dados – CNPD), through the contact details available on the official CNPD website.

Note: This text is informative in nature and does not remove the need to seek specialised legal advice for specific situations.