Your employer thinks it is important that you feel vital and especially that you stay that way, and has called in our help to realise that goal. We offer various services that all contribute to the vitality of working people in the Netherlands.
When you make use of our services, in most cases this means that we process your personal data. In this Privacy Statement, we want to provide you with clear information on how we handle your data. After all, you want to be sure that your data is in good hands.
We do everything we can to guarantee your privacy and are therefore very careful with your data. In doing so, we comply with the applicable laws and regulations, including the General Data Protection Regulation (AVG).
We do not have access to the personal data that you have shared with your employer and your personal data is never shared between HC Health and your employer.
1.WHAT PERSONAL DATA DO WE PROCESS FROM YOU?
HC Health provides various types of services, the Hello services. By using these services you enter into a contract with us. Which data of yours we process depends on the service(s) you make use of. Below is an overview of our services and the data we request from you and process for them.
- If you make use of our so-called ‘Self starter modules’ (step 1), we do not request or process any personal data from you.
- If you use HelloFysio (online physiotherapy and/or physiotherapy on location), we process your data on the basis of a so-called treatment agreement. Personal data of physiotherapy clients are processed for the purpose of the treatment process. The physical therapy treatment agreement is the basis for recording this personal data. The following data is requested in this case:
– First name
– Surname;
– Date of birth; E-mail address
– E-mail address;
– Telephone number;
– BSN-number;
– Medical data;
– Insurance details.
We are legally obliged to retain the above details for a period of 20 years. This is laid down in the Medical Treatment Agreement Act (WGBO).
If you use HelloEnergy, we process the following data from you:
– First name;
– Last name;
– E-mail address;
– Telephone number;
– Information about your lifestyle that you share with the coach.
If you make use of [email protected], we will process the following data from you:
– First name;
– Last name; E-mail address
– E-mail address;
– Information about the (home) workplace.
If you make use of HelloFit, we will process the following data from you:
– First name; Last name
– Last name;
– Business e-mail address.
In addition to offering Hello services, HC Health makes it possible to request information about various topics via its websites. You can also subscribe to our newsletters, for example. In these cases we process your data on the basis of your consent.
The following data is processed:
– First name;
– Last name;
– Business e-mail address.
2. PROCESSING PRINCIPLES FOR PROCESSING PERSONAL DATA
The processing of personal data requires a legal basis. As you have read above, we process your personal data on the basis of executing a contract with you and in some cases we specifically ask your permission to process your data. It is also possible that we have to process your personal data on the basis of a legal obligation.
In addition, HC Health processes personal data on the basis of the so-called legitimate interest. This may include marketing, security, IT management, market research, analysis of products or services, business administration, legal affairs and internal management.
3. PURPOSES OF PROCESSING PERSONAL DATA
HC Health processes your personal data for the purposes set out below:
- Execution of a contract;
- To inform customers and interested parties about products and services;
- Informing customers and interested parties about relevant news, actions, events, surveys and similar activities;
- To comply with legal obligations;
- To analyse the use and functionality of our website and apps (types of use, click behaviour, etc.);
- Discovering trends in order to develop new products and services or optimise our existing products and services (whether or not based on these trends).
4. PROVISION OF PERSONAL DATA TO THIRD PARTIES
The data that you supply to HC Health can be provided to third parties if this is necessary for the execution of the service.
We have made the necessary agreements with these parties (processors) to ensure the security of your personal data. These agreements have been laid down in processing agreements.
We never give personal data to other parties with whom no processing agreement or confidentiality agreement has been made. An exception to this is when it is legally permitted to share personal data (e.g. for police investigations). We may also share personal data with third parties if you give us written permission to do so.
5. SECURITY MEASURES
HC Health has set up an Information Security Management System (ISMS) with technical and organisational measures to protect your personal data. The ISMS of HC Health is ISO27001 and NEN7510 certified and therefore meets the highest standards in the field of information security.
6. RIGHTS CONCERNING YOUR DATA
You have the right to access, correct or delete personal data that we have received from you. You can also object to the processing of (part of) your personal data by us or one of our processors. You also have the right to have the data you have provided us with transferred to yourself or on your behalf directly to another party. We may ask you to identify yourself before we can comply with the aforementioned requests.
Should we process your personal data on the basis of permission granted by you, you always have the right to withdraw this permission.
If you have a complaint about the processing of your personal data, please contact us directly. The contact person for handling complaints is Amber Wolters ([email protected] or 020 412 3006).
Should we not be able to resolve the matter together, you also have the right to submit a complaint to the Dutch Data Protection Authority. This is the supervisory authority in the field of privacy protection.
7. RETENTION PERIODS
HC Health stores your personal data for as long as there is a customer relationship with HC Health or you continue to show interest in HC Health’s products and services. In addition, your data will be retained in accordance with mandatory statutory retention periods or for as long as the retention of your data is necessary due to circumstances.
8. TRANSFER OF PERSONAL DATA OUTSIDE THE EU
In principle, your personal data is processed within Europe and therefore falls under the scope of the AVG.
If personal data is sent to a recipient in a so-called third country, this only takes place if that country offers an appropriate level of protection for personal data according to the European Commission. If personal data is sent to a country that does not provide an adequate level of protection, HC Health will ensure that the legal requirements safeguards are put in place as stated in the AVG.
9. COOKIES
HC Health points out that use is made of Google Analytics to track how visitors use the website. Google Analytics recognises your (temporary) IP address and possibly the website you came from when visiting our website. Google uses this information to track how our website is used, to provide us with reports on the website and to provide its advertisers with information on the effectiveness of their campaigns. We use this data to analyse the navigation flow of our visitors in order to be able to offer a better user experience. Google will never have access to personal or medical data.
10. VISITING AND POSTAL ADDRESS
HC Health
Grote Bickersstraat
50A 1013 KS
Amsterdam
www.hchealth.nl
020-4123006
Please feel free to contact our Privacy Officer if you have any questions or comments about this Privacy Statement. Contact details: Dirk Wisman ([email protected]/020 412 3006).
This Privacy Statement was last amended on: 25 August 2021