Privacy policy
What this website collects, why it collects it, how long it is kept and how to get it removed. Last updated September 4, 2026.
Who is responsible
MammoLoop is published by MLJ, SASU, a company registered in Paris, France, with SIREN 934 769 837. The publication director is Jimenez Julien. For anything in this policy, write to jimenezjulien42@gmail.com. This policy covers the mammoloop.com website only. Patient data processed inside the MammoLoop application on behalf of a customer center is governed by the business associate agreement and the service contract signed with that center, not by this policy, and we act there as a service provider to the center rather than as the party deciding how that data is used.
What the contact form collects
The contact form on the home page collects exactly these fields, and nothing else: name, email, company, role, request, size, message and consent. A hidden field named bot-field exists to catch automated spam and is expected to stay empty. Two further hidden fields, subject and recipient, simply route your message to the correct inbox. We do not ask for and do not want patient information in the message field. Please describe your situation in general terms, for example your monthly exam volume, and never include a patient name, a date of birth or a medical record number.
Why we collect it and on what legal basis
We collect this information for one purpose: to answer your request and, if you go on to become a customer, to prepare a quote and an onboarding plan. Under the EU General Data Protection Regulation the legal basis is your consent, given by ticking the consent box, together with our legitimate interest in responding to a business enquiry addressed to us. For visitors in the United States, submitting the form is a request for a business communication that you initiated. You are never added to a marketing list because you asked a question. We do not send newsletters, we do not sell contact data, we do not share it with partners, and we do not use it for advertising of any kind.
Who processes and stores your submission
This site is hosted by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, United States. Form submissions are processed and stored by Netlify Forms, and a notification containing your message is sent to the publisher by email. Netlify acts as our processor for that storage. Our email provider stores the notification message in the ordinary course of delivering email. No other company receives your submission.
How long it is kept
Enquiries that do not lead to a commercial relationship are deleted from Netlify Forms and from the publisher inbox within twenty four months of the last message exchanged. Enquiries that become customer relationships are kept for the life of the contract and then for the retention period required by French commercial and accounting law, which is ten years for accounting records. You can ask for earlier deletion at any point and we will act on it unless a legal obligation requires us to keep a specific record.
Cookies and tracking
This website sets no advertising cookies, no third party analytics cookies and no cross site tracking pixels. There is no Google Analytics tag, no advertising network tag and no social media tracking script on any page. The only third party requests the pages make are to Google Fonts for the two typefaces used in the design, which involves your browser requesting font files, and to Netlify when you submit the form. Server access logs kept by the host include IP addresses for security and abuse prevention and are retained by the host under its own policy.
Your rights under US state privacy laws
If you are a resident of California, Colorado, Connecticut, Utah or Virginia, you have the right to know what personal information we hold about you, to obtain a copy of it, to have it corrected if it is wrong and to have it deleted. You also have the right to opt out of the sale or sharing of personal information and of targeted advertising, and to be free from discrimination for exercising any of these rights. We do not sell or share personal information and we do not carry out targeted advertising or profiling, so there is nothing to opt out of, but the right stands and the request will be honored. California residents may also request the categories of sources and recipients of the information. You may use an authorized agent to make a request on your behalf, with proof of authorization.
Your rights under the GDPR
If you are in the European Union, the United Kingdom or the European Economic Area, you have the right of access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You also have the right to lodge a complaint with a supervisory authority, which in France is the Commission Nationale de l'Informatique et des Libertes.
How to exercise your rights
Write to jimenezjulien42@gmail.com from the email address you used on the form, or from an address you can prove is yours, and say plainly what you want: a copy, a correction or a deletion. We acknowledge every request within five business days and complete it within thirty calendar days. There is no charge. If we cannot act on a request, we explain why in writing and tell you how to appeal that decision, which you may do by replying to the same address with the word appeal in the subject line.
Children's privacy
This website and the MammoLoop product are business tools intended for adults working at imaging centers and healthcare practices. The site is not directed at children, and we do not knowingly collect personal information from anyone under sixteen years of age. If you believe a child has submitted information through this site, write to us and we will delete it promptly.
International transfers
Because the site is hosted in the United States and the publisher is established in France, information you submit crosses borders. Transfers from the European Economic Area to our United States processors rely on the standard contractual clauses adopted by the European Commission, together with the additional measures agreed with those processors. Data in transit is encrypted with current transport security, and data at rest is encrypted by the host.
Security
The site is served over HTTPS with security headers that block content type sniffing and restrict framing. Access to form submissions is limited to the publication director. We use multi factor authentication on the accounts that hold this data. No system is perfect, and if a breach affecting your information occurred we would notify you and the competent authorities within the deadlines set by applicable law.
Changes to this policy
If this policy changes, the revised version is published on this page with a new last updated date. Material changes affecting how existing enquiries are handled are communicated by email to the people concerned. This version was last updated on September 4, 2026.