Legal

Privacy Policy

DERMATOO SRL — Last updated: October 2021

1. Introduction

This privacy policy concerns all data collected and used by DERMATOO SRL, with BCE number 0755.523.201 and registered office at 4053 EMBOURG, Avenue du centenaire 61, in connection with the use of the DERMATOO application.

This privacy policy only concerns data processing carried out by DERMATOO for doctors and healthcare professionals authorized to use the application.

This policy does not concern data processing carried out on the data of "patients" of said doctors and healthcare professionals.

2. Definitions

  • Supervisory Authority: A supervisory authority designated by the Member State pursuant to Article 51 of the GDPR. In Belgium, this is the Data Protection Authority.
  • Application: A program created by the Data Controller, directly used by the Data Subject (the Professional or User) to process Patient Data and communicate with Colleagues.
  • Colleague: A natural person who is a healthcare professional such as a doctor or other healthcare professional and who is not part of the Professional's or User's practice.
  • Personal Data (or Data): Any information relating to an identified or identifiable natural person (hereinafter referred to as "Data Subject"). An "identifiable natural person" is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.
  • Sensitive Data: Personal data relating to sensitive aspects such as racial identity or ethnic origin, political opinions, religion or any other beliefs, health or any pathological condition, criminal history, trade union membership, or sexual orientation.
  • Notification: Information provided to the Authority by the Data Controller, in accordance with Article 33 of the GDPR, in the event of a Personal Data Breach.
  • Patient: The natural person for whom the Professional or User provides a service related to the medical field.
  • Professional: The legal entity or self-employed natural person, healthcare professional, who uses the Data Controller's Application to provide services to Patients. The Professional may also be referred to as a "direct client" of the Data Controller.
  • Privacy Policy: This policy concerning the protection of Personal Data of Professionals and Users.
  • Data Controller: The natural or legal person, public authority, agency, or other body which determines the purposes and means of the Processing. In this case, it is DERMATOO SRL, with BCE number 0755.523.201 and registered office at 4053 EMBOURG, Avenue du centenaire 61.
  • Processor: The natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Data Controller.
  • Processing: Any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
  • User: The natural person, healthcare professional, who uses the Data Controller's Application without being a direct client. The User may be a doctor or other medical professional working in a hospital setting.
  • Breach: A security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.

3. What Data is collected and why does the Data Controller retain this Data?

Principle

In accordance with the GDPR, Data is collected for specific purposes. Data collection must also be based on one of the legal grounds provided for in Article 6 of the GDPR.

If the Data Controller decides to use the Data for a purpose other than that stated in the Policy, it will provide prior information to the Data Subject about this other purpose.

The Data Subject is a Professional

Professional Data is collected during account creation on the application and during the processing of Patient files.

The Data collected includes:

  • Personal identification data: name, surname, address, telephone, email address, etc.
  • Data issued by public services: INAMI number
  • Current employment data
  • Electronic identification data: IP address, operating system, connection location, preferred language, date and time of consultation, actions performed, identifier, etc.
  • Audio recording data
  • Other data that may be collected during exchanges between professionals

The Data Subject is a User

User Data is collected during account creation on the Application and during the processing of Patient files. User Data is processed even if they are not direct clients of the Data Controller.

The Data collected is similar to that of Professionals, also including the National Registry number.

4. How long is Data retained?

The Data Controller retains Data for as long as necessary to achieve the purpose of the processing and to comply with its legal obligations.

Retention periods are determined based on several criteria such as the legal obligations to which the profession is subject, the type of processing, its purpose, where the Data is stored, the type of Data Subject, and the type of Data collected. The retention period for a particular Data processing may be communicated to the Data Subject upon request.

In any event, the Data Controller retains Data in accordance with legal retention periods.

5. Who collects the Data?

Data may be collected by the Data Controller or through the Application host or through the Data Controller's processors. The Data is then transmitted to the Data Controller.

The list of Processors may be communicated upon request.

Some intermediaries may be established in a third country outside the European Economic Area that guarantees an adequate level of protection of Personal Data, as determined by the European Commission.

When intermediaries are established in countries that do not provide an equivalent level of privacy protection, the Data Controller declares that it takes specific measures, in accordance with data protection legislation in force in the EEA, to protect Personal Data.

6. How is Data collected?

Data is collected during exchanges with the Data Controller during registration on the Application.

Data may also be collected via cookies (see specific information on this subject).

7. Why do we collect your Data?

Data is primarily collected to enable Users and Professionals to use the Application and process their Patients' Data.

Data may also be collected by the Data Controller for the purpose of proper contract performance with Professionals or used for managing contracts related to services provided to/for them.

  • Respond to information requests and ensure follow-up.
  • Inform about possible changes in the services offered and/or applicable regulations.

Data is also collected to meet legal obligations, particularly in terms of ethics, accounting, compliance with court decisions, responding to requests from public authorities, protecting the interests of the Data Controller as well as those of its partners and the Patients of Professionals and Users, protecting its services, enforcing the general terms and conditions, privacy policy, and any applicable text, formulating any recourse, or limiting any damage that the Data Controller may suffer.

Finally, Data may be collected in the legitimate interest of the Data Controller or a third party.

8. With whom will Data be shared?

Data may be communicated to third parties directly related to the Data Controller, when necessary, including the entities listed below:

  • Certain colleagues of Professionals and Users, also healthcare professionals, in order to provide the best possible care to their Patients;
  • Service providers chosen by the Data Controller, who are responsible for hosting the application, providing infrastructure, IT services, email services, audit services, and any other similar service to enable them to provide said services;
  • A potential acquirer, in the event of a (total or partial) transfer of the Data Controller's activities (merger, sale, asset transfer, judicial reorganization, etc.);
  • In the event of a dispute, Data may be transmitted to a third party responsible for managing disputes (law firm, debt collection company, etc.), who will also ensure compliance with applicable legislation regarding this information;
  • Accountant, public authority, etc., in order to comply with the Data Controller's legal obligations.

The list of service providers may be communicated upon request.

9. Patient Data

As part of the services it offers, the Data Controller allows Professionals and Users to process their Patients' Data.

In this context, Professionals and Users are considered joint data controllers with the Data Controller (DERMATOO) within the meaning of the Data Protection Regulation.

Professionals and Users agree to sign, for the processing of Patient Data, a contract under Article 26 of the GDPR and to inform Patients of the processing carried out.

They also agree to comply with all legal provisions applicable to personal data processing and privacy, including provisions on image rights.

10. How do we secure Data?

Appropriate technical and organizational measures have been implemented to ensure a level of security appropriate to the risks, including, among others, as needed:

  • Means to ensure the confidentiality, integrity, availability, and ongoing resilience of processing systems and services;
  • Means to restore the availability of Personal Data and access to it within appropriate timeframes in the event of a physical or technical incident;
  • Limited retention periods;
  • Access to the information system limited to authorized personnel who are aware of personal data protection requirements.

Details of these security measures may be communicated upon request.

11. What rights do you have?

Depending on the type of Processing carried out on Personal Data, the Data Subject, whether Professional or User, may exercise several of the following rights:

A. Right to Information

Any Data Subject has a right to information concerning the Data collected. It is notably through this Privacy Policy that the Data Controller wishes to fulfill this information requirement.

B. Right of Access

Any Data Subject has a right of access to their Personal Data. To do so, the Data Subject must make a request to the relevant department of the Data Controller.

C. Right to Rectification

Any Data Subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate Personal Data concerning them.

D. Right to Erasure

The Data Subject may claim the right to erasure of their Data when one of the following grounds applies:

  • The Data is no longer necessary for the purposes for which it was collected;
  • The Data Subject wishes to withdraw their consent;
  • The Data Subject objects to the processing;
  • The Data has been unlawfully processed;
  • The Data must be erased to comply with a legal obligation.

E. Right to Restriction of Processing

The Data Subject has the right to obtain from the Data Controller restriction of processing in certain circumstances provided for by the GDPR.

F. Right to Data Portability

When the processing of Personal Data is based on consent or a contract, and that processing is carried out by automated means, the Data Subject may request to receive such data in a structured, commonly used, and machine-readable format.

G. Right to Object

The Data Subject has the right to object at any time, on grounds relating to their particular situation, to the processing of Personal Data concerning them based on public interest or the legitimate interest of the Data Controller.

12. How can you exercise your rights?

An information request can be submitted internally via email: data@dermatoo.com.

If the response to your request is unsatisfactory, you may still exercise any of the rights provided above, or file a complaint with the Data Protection Authority.

You can contact them as follows: