This privacy policy explains how Sima Clinic (referred to as “we”, “us” and “our”), the operator of yoursima.com, collects, uses and protects information about visitors to this website and the people who contact us through it. We are committed to protecting your privacy and to complying with the data protection laws that apply to us, including the EU and UK General Data Protection Regulation (GDPR) where it applies.
Data controller
- Operator Sima Clinic
- Registered address Al-Sabil district, Aleppo, Syria, beside Al-Kalimah Hospital
- Privacy contact [email protected]
- Data protection officer No data protection officer has been appointed. Please use the contact above.
For data subject requests, use the contact above or our contact page.
Information we collect
When you visit our website or submit a form, we may collect the following information.
- Information you provide Your first name, surname, email address, telephone number and any free-text message you include in a consultation or contact request, or your email address when you subscribe to our newsletter. Our forms also capture the position of the form on our website (for example the footer or the contact page) and your country, which is determined automatically from your IP address at the time of submission.
- Information our server collects automatically Your IP address, browser type and version, operating system, referring website, the pages you visited, and the date and time of your visit.
- Information collected by analytics and advertising tools See the section “Third-party services we use” below.
How we use your information
- To respond to your consultation or contact request.
- To send the newsletter you subscribed to and related service updates.
- To improve our website, our services and the user experience.
- To measure the performance of our marketing and advertising.
- To comply with legal obligations.
Cookies and tracking technologies
Our website uses cookies and similar technologies to recognise visitors, remember preferences, measure traffic and support advertising. The cookies set on or through our website include the following.
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
_ga, _ga_* |
Google Analytics 4 | Distinguishes visitors, measures sessions | Up to 2 years |
_fbp |
Meta Pixel | Distinguishes visitors for advertising attribution | 3 months |
_fbc |
Meta Pixel | Attributes the last click on a Meta advert (set when you arrive through a link containing fbclid) |
2 years |
_onyx_visitor_id |
Our website (first party) | A persistent visitor identifier used to de-duplicate browser pixel events against server-side Meta events, sent to Meta in hashed form | 2 years |
You can clear or block these cookies through your browser settings. Disabling them may affect the functionality of the website and our ability to measure performance.
Third-party services we use
Google Analytics 4 (GA4) Provided by Google LLC (United States). GA4 receives your IP address, browser and device identifiers (including the client_id stored in the _ga cookie), the pages you view, the referring page and an approximate estimate of your location derived from your IP address. Google truncates the IP address before storing it. Reports are aggregated, but the underlying data sent to Google identifies your device. Learn more in the Google Privacy Policy. You can stop the tracking by installing the Google Analytics opt-out browser add-on.
Meta Pixel and Meta Conversions API Provided by Meta Platforms Inc. (United States). We use two complementary tools.
- Meta Pixel A JavaScript snippet loaded on every page of our website. On every page view it sends to Meta the page URL, the referring page, your IP address, your browser’s user-agent string and the
_fbp/_fbccookies described above. The pixel runs on every page view. - Meta Conversions API (server-side) We use it to send a server-side event to Meta in two cases.
- When you submit a form (contact, consultation or newsletter). Submitting any of our forms requires you to tick the privacy policy consent box first; without it the form is not sent. When the event fires, we send to Meta hashed identifiers (SHA-256, a one-way hash) of your email address, telephone number, first name, surname and country, together with your IP address, user-agent, the
_fbp/_fbccookies (where present) and a hashed first-party visitor identifier. Meta uses this data to match the event to a Meta account and to de-duplicate it against the browser pixel. - When you click a contact link on our website (telephone, WhatsApp or email). We send to Meta your IP address, user-agent, the
_fbp/_fbccookies (where present) and a hashed visitor identifier. Because a link click collects no contact details, no personal identifiers are included in this event.
- When you submit a form (contact, consultation or newsletter). Submitting any of our forms requires you to tick the privacy policy consent box first; without it the form is not sent. When the event fires, we send to Meta hashed identifiers (SHA-256, a one-way hash) of your email address, telephone number, first name, surname and country, together with your IP address, user-agent, the
We never send the free-text message from the contact form to Meta. Event labels are limited to generic position codes (for example consultation, subscription, footer_phone) and never contain procedure names, medical conditions or any other sensitive description.
Both tools are used to measure advertising performance, understand the actions taken on our website and show more relevant adverts on Meta platforms (Facebook, Instagram, WhatsApp). Learn more in the Meta Privacy Policy. You can manage how Meta uses your data through Facebook ad preferences and review your activity off Meta through Off-Facebook Activity.
International data transfers
Google LLC and Meta Platforms Inc. are both located in the United States. When you visit our website, personal data (including your IP address, browser identifiers, cookies and, where applicable, the hashed identifiers described above) is transferred to the United States.
Where the GDPR applies, these transfers rely on the EU-US Data Privacy Framework (Google LLC and Meta Platforms Inc. are both self-certified participants) and, where applicable, on the Standard Contractual Clauses (SCCs) issued by the European Commission as additional safeguards. You can verify the recipients’ certifications at www.dataprivacyframework.gov.
Legal basis for processing (GDPR)
Where the GDPR applies, we process your personal data on the following legal bases.
- Consent When you tick a consent box on a form (contact, consultation or newsletter) or take another clear affirmative action. You can withdraw consent at any time by contacting us.
- Contract When processing is necessary to respond to your request for a service or consultation.
- Legitimate interest For website security, fraud prevention and aggregated measurement of how our website is used. You have the right to object to processing on this basis at any time.
- Legal obligation For record-keeping, tax and similar regulatory requirements.
If you are a visitor from the European Economic Area or the United Kingdom and would prefer that the analytics and advertising cookies above are not set, please use the opt-out links in the third-party services section or your browser’s cookie settings before continuing to browse. We will continue to honour any direct request to delete previously collected data.
Health and sensitive information
We work in medical and aesthetic care, which means the messages you send us through our website may contain information about your health. We treat any information of this kind as a “special category” of personal data under Article 9 of the GDPR and process it only on the basis of your explicit consent, given when you tick the consent box before submitting the form. The following applies when you provide such information.
- It is used only to respond to your request and to provide the consultation or service you asked for.
- It is not shared with our advertising or analytics providers. The free-text message field is never sent to Meta or Google.
- It is stored on our servers and shared only with our affiliated medical specialists responsible for handling your request.
If you would rather not share health information, please limit your message to general contact details and we will follow up with you by telephone or email.
Sharing your information
We do not sell your personal information. We may share data with the following parties.
- Our affiliated medical specialists For the purpose of fulfilling your consultation or treatment request.
- Service providers That we use to operate the website (hosting, email delivery, analytics, advertising measurement), all of whom are bound by data processing agreements. Our main sub-processors include the following.
- Hosting by Veridyen (Türkiye)
- Email and newsletter delivery by an external transactional email provider (such as Resend or SendGrid)
- Web analytics by Google LLC (GA4)
- Advertising measurement by Meta Platforms Inc. (Pixel and Conversions API)
- Authorities Where required by law or to defend our legal rights.
Data retention
- Enquiry submissions Kept for as long as necessary to respond to you and for the duration of any subsequent relationship, plus any retention period required by law.
- Newsletter subscriptions Kept until you unsubscribe.
- Analytics data Kept according to the default GA4 settings (currently 14 months for event-level data).
- Meta advertising data Kept according to Meta’s own policy.
- Server access logs Kept for short-term security and diagnostic purposes (typically up to 30 days) and then deleted or rotated.
Your rights
Under applicable law, and under the GDPR where it applies, you have the following rights.
- To access the personal data we hold about you.
- To request the correction of inaccurate or incomplete data.
- To request the deletion of your data (the “right to be forgotten”).
- To object to or restrict the processing of your data.
- To receive your data in a portable format.
- To withdraw consent at any time (this does not affect the lawfulness of processing carried out before the withdrawal).
- To lodge a complaint with a competent supervisory authority, such as the national data protection authority in your EEA country or the Information Commissioner’s Office (ICO) in the United Kingdom.
To exercise these rights, contact us using the contact details listed in the data controller section above.
Children’s privacy
Our services are intended for adults. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, please contact us so that we can remove it.
Security
We implement reasonable technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure or destruction. However, no method of transmitting data over the internet is 100% secure.
Updates to this privacy policy
We may update this privacy policy from time to time. The date below reflects the most recent revision. Material changes will be highlighted on this page. We encourage you to review this page regularly.
Contact
If you have questions about this privacy policy or your personal data, please contact us through our contact page or the contact details listed in the data controller section above.
Last updated 26 May 2026.