Our privacy policy

At Menovia, we protect your personal data with the utmost care and transparency. If you have any questions, you can always contact us.

Personal data protection

Last updated: 11 August 2026

Menovia values your privacy. As a digital clinic we process health data, handled with care and confidentiality. This policy explains what we process, why, on what legal basis, with whom we share it, and your rights.

1. Who we are

Menovia BV is the controller. Address: Regentesselaan 2C, 3762DS Soest · CoC: 98160834 · Contact: contact@menovia.nl · 085 212 9706.

2. What data we process

Identity & contact details (name, date of birth, address, email, phone); health data (special category): intake questionnaires, symptoms, medical history, blood test results, treatment plan and notes; appointment & treatment data; payment data (no full card details); website & cookie data.

3. Purposes

Providing care (intake, diagnostics, treatment, guidance), scheduling, invoicing, meeting legal obligations, and — only with your consent — sending information and newsletters.

4. Legal basis

Performance of the treatment agreement and Article 9(2)(h) GDPR (provision of healthcare), together with the Dutch Medical Treatment Act (WGBO), for health data; legal obligation for administrative/ fiscal retention; consent for marketing, newsletter and non-necessary cookies (always withdrawable); legitimate interest for security and service improvement.

5. Medical confidentiality & WGBO

Our BIG-registered clinicians are bound by medical confidentiality. Your medical data is not shared with third parties without your consent, except where required or permitted by law. The WGBO applies.

6. Who we share data with

We use carefully selected providers and sign a data processing agreement with each. We never sell your data. These include: our electronic patient record hosted within the EU; forms, CRM, invoicing and support (within the EU); video consultation (Meet) and email — with data at rest stored within the EU — and general file storage; scheduling and payments; newsletter and email delivery; website hosting, analytics and — only with your cookie consent — advertising partners.

7. Transfers outside the EU

Your data stays within the EU where possible. For Google Workspace (email and video consultation via Meet) we have configured data at rest to be stored within the European Union. For providers outside the EU, appropriate safeguards apply, such as the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

8. Retention

Medical record: at least 20 years after the last change (WGBO); administration: 7 years (fiscal); marketing data: until you unsubscribe or withdraw consent.

9. Security

We take appropriate technical and organisational measures, including encryption, access control and logging, and EU hosting. For healthcare information security we align with the NEN 7510 standard.

10. Your rights

Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. Note: erasure of your medical record is limited by the statutory retention duty. Requests: contact@menovia.nl. You may also complain to the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

11. Cookies

See our Cookie Statement.

12. Complaints & data protection officer

Menovia has not appointed a separate data protection officer. For questions or requests about your data, contact contact@menovia.nl. Please raise any complaint with us first; for care-related complaints see our Complaints Committee. You may also complain to the Dutch Data Protection Authority.

13. Changes · 14. Contact

We may update this policy; the date above reflects the latest version. Menovia BV · Regentesselaan 2C, 3762DS Soest · CoC 98160834 · contact@menovia.nl · 085 212 9706.