Responsibility for Your Personal Data
Prescan B.V.
Hermesweg 15
3741 GP Baarn
The Netherlands
Telephone: +31 (0)74 255 9255
Email: info@prescan.nl
Chamber of Commerce (KvK): 08100923
Data Protection Officer (DPO)
Marc Wiertz
Email: dpo@prescan.nl
Telephone: +31 (0)74 255 9255
Categories of Personal Data
By using the website and the services available on it, you leave certain data with us. This also applies in the context of the performance of a mediation agreement and/or a medical treatment agreement. Such data may include personal data. Depending on the service you use, we may collect the following data, for which we act as the data controller within the meaning of the General Data Protection Regulation (GDPR):
- Name, address and place of residence details
- Gender
- Email address
- Telephone number
- Contact preferences
- Insurance partners
- Partner’s name
- Information about your appointment
- IP address
- Payment details
- Healthcare providers (general practitioner, specialist, etc.)
- Medical history (conditions, surgeries, weight, height, lifestyle)
- Health-related data
Results of blood and urine analyses, including in relation to:
- Indications of conditions (including cholesterol, glucose, kidney function, liver function)
- Specific blood tests based on existing complaints (including hormones, allergies and vitamins)
- Results of imaging examinations (including X-ray images, CT scans, ultrasound and MRI scans)
- Reports and advice from treating physicians, including any translations thereof
- Results and images from dermatological examinations
- Results of cardiological examinations (including ECG recordings)
Legal Basis for Data Processing
We process, store and retain your medical personal data solely on the basis of your explicit consent (Article 9(2)(a) GDPR), unless otherwise provided in this document, such as where processing is necessary for the performance of a medical treatment agreement pursuant to Article 9(2)(h) GDPR in conjunction with Article 7:457(2) of the Dutch Civil Code.
We also process personal data insofar as this is necessary for the performance of the service agreement between you and us, as referred to in Article 6(1)(b) GDPR. This includes name and address details, contact preferences and financial data.
In addition, we may process your personal data on the basis of a legitimate interest, such as informing our clients about updates or changes to our services. This legal basis is laid down in Article 6(1)(f) GDPR. In such cases, we process only the personal data that is strictly necessary for this purpose, such as your contact details.
Purposes of Data Processing
The personal data collected by us are used for the following purposes:
- Creating your account for registration with the Prescan Group
- Logging into your account
- Maintaining your medical record
- Scheduling appointments
- Mediating the performance of diagnostic treatments
- Recording your stated preferences
- Improving our services to you
- Performing or arranging other services requested by you
- Providing translations of medical findings reports from treating physicians
- Maintaining results from previous examinations
- Referring you to your general practitioner and/or an external specialist not employed by Prescan (via ZorgDomein)
- Sending newsletters (with information about examinations and developments, webinars, promotions and client stories)
Disclosure of Personal Data to Third Parties
We disclose your medical personal data to third parties only if there is a legal basis for doing so. Disclosure without your consent occurs only if this is necessary for the performance of the agreement between you and us, for the execution of the medical treatment agreement, or to comply with a legal obligation.
In relation to our services (imaging techniques, cardiological and dermatological examinations), the following categories of third parties may be involved:
Laboratories
- External medical service providers
- Financial service providers
- Hosting providers
- IT service providers
- Retention Periods
We do not retain personal data longer than necessary. Below is an overview of retention periods per category.
Personal Data
- Name and address details
- Contact details
- Contact preferences
- Medical data, including:
- Medical history (anamnesis)
- Reports
- Findings
- Imaging material
Where personal data are processed in the context of a medical treatment agreement, such data are retained for 20 years, in accordance with statutory requirements under the Medical Treatment Contracts Act (WGBO).
Financial Data
- Invoices
- Financial transactions (bank transfers)
Financial data are retained for 7 years, in accordance with statutory tax obligations.
Where personal data are processed for the purpose of sending newsletters, such data are retained for 2 years after you have used a service with us or 2 years after you have given consent for this purpose.
Security Measures
- To protect your data as effectively as possible, we have implemented appropriate security measures. These include, among others:
- Access to personal data is protected by a username, password and a visual login token; data are stored in a separate, secured system after receipt
- Physical security measures to protect systems in which personal data are stored
- Use of secure connections (Secure Socket Layer – SSL) to protect all information exchanged between you and our website when you enter personal data
- Logging of all data access and retrieval activities
- Biennial security testing of critical systems
Links to Third-Party Websites
To provide you with optimal service, our website contains links to third-party websites. Please note that when you visit these websites, the privacy statements of these third parties apply. We recommend that you read their privacy statements before making further use of such websites.
Google Analytics
We use Google Analytics to track how visitors use the website. The information obtained, including your computer’s IP address, is transferred to and stored by Google on its servers. Please read Google’s privacy policy and the specific Google Analytics privacy policy for more information.
Newsletter
If you have subscribed to our newsletter, you will regularly receive emails from us containing information about Prescan (based on Article 6(1)(a) GDPR). This includes newsletters with information about products, webinars, promotions and client stories. Newsletter content may be personalised based on the information you provide to us, such as stated topic preferences.
You have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before it was withdrawn.
If you have purchased an examination from Prescan, you may also receive emails from us with information about Prescan based on Article 6(1)(f) GDPR and Article 11.7(4) of the Dutch Telecommunications Act. This includes newsletters with information about products, webinars and promotions.
You may unsubscribe from newsletters at any time by clicking the “Unsubscribe” link included in each newsletter. If you wish to object to the processing of your personal data, you may email privacy@prescan.nl.
Your Rights
You have several rights regarding the personal data you have provided to us, including the right of access, rectification and erasure. You may also request data portability, restriction of processing, or object to the processing of your data.
Requests may be submitted by email to dpo@prescan.nl. Prescan Group will respond as soon as possible, and no later than within four weeks.
You may also withdraw your consent for data processing at any time, without affecting the lawfulness of processing prior to withdrawal.
Filing a Complaint with the Dutch Data Protection Authority
If you are not satisfied with the way we handle your personal data, you may file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Contact details can be found on the Authority’s website.
Changes to This Privacy Statement
We reserve the right to amend this Privacy Statement. Any changes will be published on our website. We therefore recommend that you review this statement regularly to stay informed of any changes.
Contact Details
If you have any questions or comments after reading this Privacy Statement, please contact us at dpo@prescan.nl.
Prescan B.V.
Hermesweg 15
3741 GP Baarn
The Netherlands
Email: info@prescan.nl
Telephone: +31 (0)74 255 9255
Chamber of Commerce (KvK): 08100923
Data Protection Officer
Marc Wiertz
Email: dpo@prescan.nl
Telephone: +31 (0)74 255 9255
Cookies
Cookies and similar technologies are very small text files or pieces of code that often contain a unique identification code. When you visit a website or use a mobile application, a computer asks your computer or mobile device for permission to store this file and access information. Information collected through cookies and similar technologies may include the date and time of the visit and how you use a particular website or mobile application.
