Privacy Policy

Dental Studio Den Haag B.V.

This is the Privacy Policy of Dental Studio Den Haag B.V., located in The Hague and registered with the Dutch Chamber of Commerce under number 96861754.

Article 1. General

Dental Studio Den Haag ensures that the personal and sensitive data of patients is handled with the utmost care and confidentiality. We comply with applicable laws and regulations, including the General Data Protection Regulation (GDPR). Through this Privacy Policy, we aim to inform you about our data processing practices.

Article 2. Definitions

For clarity, the following terms are used throughout this document:

  1. Personal Data: Any information relating to an identified or identifiable individual.
  2. Data Controller: The entity responsible for the processing of personal data, in this case, Dental Studio Den Haag.
  3. Processing: Any operation performed on personal data, whether automated or not, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction.
  4. Processor: A third party that processes personal data on behalf of the Data Controller, without being under its direct authority.
  5. Data Subject: The individual whose personal data is being processed, generally the patient.
  6. Implementation Act: The Dutch GDPR Implementation Act.
  7. Regulation: EU Regulation 2016/679 (GDPR) on the protection of personal data.
  8. Privacy Policy: This document.
  9. Pseudonymized Data: Data that cannot be attributed to a specific individual without the use of additional information, which is kept separately and securely.

Article 3. Source of Data

Personal data is obtained either directly from the Data Subject or their legal representative, or indirectly via general practitioners, healthcare providers, specialists, insurers, or other authorized entities.

Article 4. Purpose and Legal Basis of Processing

  1. Processing is lawful, fair, and transparent with specific and legitimate purposes.
  2. Processing for archival, scientific, or statistical purposes is not considered incompatible with the original purpose.
  3. Processing is lawful if it meets at least one of the following conditions:
    • Explicit consent from the Data Subject;
    • Necessity for the performance of a treatment agreement;
    • Protection of vital interests (e.g., medical emergencies);
    • Legitimate interest of the Data Controller or third party;
    • Compliance with a legal obligation.
  4. Personal data is only processed as necessary and relevant for the defined purposes.
  5. Purposes include:
    • Patient care and treatment;
    • Communication with patients;
    • Financial administration;
    • Proper functioning of the website.

Article 5. Consent Conditions

  1. The Data Controller must be able to demonstrate that the Data Subject has consented.
  2. Consent can be withdrawn at any time by the Data Subject.

Article 6. Anonymized Data

Anonymized data is not subject to this Privacy Policy.

Article 7. Categories of Personal Data Processed

Processing may involve the following data categories:

  • Identification and contact details;
  • Administrative numbers;
  • Details of legal guardians (for minors);
  • Family or emergency contact information;
  • Health and hereditary condition data;
  • Data necessary for proper treatment;
  • Treatment records and prescriptions;
  • Billing and insurance information;
  • Any other necessary data for treatment.

Article 8. Duty to Inform

The Data Controller must inform the Data Subject (or legal guardian) about:

  • Identity and contact details of the Data Controller;
  • The purpose of the processing;
  • Data Protection Officer contact details (if applicable);
  • Method of processing;
  • Data retention period;
  • Any other relevant information.

If data is collected from or shared with third parties, the same information must be provided unless this requires disproportionate effort.

Article 9. Right of Access

The Data Subject has the right to access their personal data and receive information regarding:

  • Purpose of the processing;
  • Source of data;
  • Categories of data processed;
  • Recipients or categories of recipients;
  • Data retention period or criteria for retention;
  • Rights to rectification, erasure, and restriction of processing.

Requests may be denied if:

  • The requester is not the Data Subject;
  • The Data Subject is under 16 or under guardianship (only legal representatives may apply);
  • The request was recently fulfilled;
  • There are overriding rights or interests of others;
  • There are legal grounds for denial (e.g., state security or criminal investigation).

Article 10. Other Rights

The Data Subject also has the right to:

  1. Object to processing;
  2. Request correction of incorrect data;
  3. Request deletion of data if no longer necessary or upon withdrawal of consent;
  4. Request restriction of processing during disputes;
  5. Receive personal data in a structured, commonly used, machine-readable format.

Article 11. Exercising Data Subject Rights

The Data Controller must provide concise, transparent, and accessible communication regarding the rights of the Data Subject.

Article 12. Access to Personal Data

  1. Access is granted only to those directly involved in patient care, as required for their work.
  2. Processors are engaged only if they guarantee GDPR-compliant data handling.
  3. Data may also be shared with:
    • Authorized researchers;
    • Health insurers;
    • Debt collection agencies (non-medical data only);
    • Others, based on consent, legal obligations, or vital interests;
    • Statistical or scientific institutions, under strict safeguards.

Article 13. Processing Register

The Data Controller maintains a register of all processing activities including:

  • Controller’s contact details;
  • Processing purposes;
  • Data categories;
  • Recipient categories;
  • Retention periods;
  • Technical and organizational safeguards.

Article 14. Data Breach Notification

In the event of a data breach:

  1. The Data Subject and the Dutch Data Protection Authority will be informed promptly, if legally required.
  2. The notification includes:
    • Nature of the breach;
    • Likely consequences;
    • Measures taken;
    • Contact details for further information.

Article 15. Data Retention

  1. Medical data is retained for 20 years per Dutch Civil Code.
  2. Other personal data is kept no longer than necessary for its intended purpose.

Article 16. Confidentiality

  1. The Data Controller, Processors, and any individuals with access to personal data are bound by confidentiality.
  2. Health data is considered sensitive personal data and is subject to a stricter confidentiality obligation under law or contract.

Article 17. Data Security

  1. The Data Controller ensures appropriate technical and organizational security measures.
  2. Measures are risk-based and ensure:
    • Access only by authorized personnel;
    • Data integrity and availability;
    • Continuous compliance with internal data protection policies.

Article 18. Website and Cookies

  1. Our website uses:
    • Technical Cookies: Essential for proper website functionality.
    • Analytical Cookies: Help us improve user experience; no personal data is collected.
    • Marketing Cookies: Used with consent to deliver personalized offers and promotions. Consent is obtained via a cookie banner and can be adjusted at any time.
  2. Data collected via the website is retained for a maximum of two years.
  3. Only authorized personnel involved in data processing or site management have access to personal data.

Third-party tools used:

  • Hotjar
  • Facebook
  • LiveZilla
  • Google Analytics
  • Mailchimp
  • Vimeo

These tools are used for user behavior analysis, newsletter distribution, and traffic reporting. Each of these providers has its own privacy policy and is responsible for its data handling.

 

Use of Online Tools and Final Provisions

Various online tools are used on this website to analyze visitor browsing behavior, collect website statistics, and distribute newsletters. Please note that external parties, such as Facebook, maintain their own privacy policies and bear responsibility for compliance with their respective terms.

Article 19. Final Provisions

  1. The Controller shall not assume any obligations beyond those required by law, unless otherwise agreed upon in writing with the Data Subject.
  2. The Data Subject reserves the right to lodge a complaint with the appropriate supervisory authority.
  3. This Privacy Policy may be amended by the Controller. Any amendments shall become effective with respect to the Data Subject(s) once they have been notified of such changes.
  4. This Privacy Policy entered into force on May 25, 2018, and is available for review at the dental practice.

For questions or to exercise your rights as a Data Subject, you may contact us at:
Address: Laan van Nieuw-Oost Indië 42C
Phone: +31 (70) 221 08 87
Email: info@dentalstudio-denhaag.nl