Our privacy policy
At Menovia, we protect your personal data with the utmost care and transparency. If you have any questions, you can always contact us.
Personal data protection
Last updated: 11 August 2026
Menovia values your privacy. As a digital clinic we process health data, handled with care and confidentiality. This policy explains what we process, why, on what legal basis, with whom we share it, and your rights.
1. Who we are
Menovia BV is the controller. Address: Regentesselaan 2C, 3762DS Soest · CoC: 98160834 · Contact: contact@menovia.nl · 085 212 9706.
2. What data we process
Identity & contact details (name, date of birth, address, email, phone); health data (special category): intake questionnaires, symptoms, medical history, blood test results, treatment plan and notes; appointment & treatment data; payment data (no full card details); website & cookie data.
3. Purposes
Providing care (intake, diagnostics, treatment, guidance), scheduling, invoicing, meeting legal obligations, and — only with your consent — sending information and newsletters.
4. Legal basis
Performance of the treatment agreement and Article 9(2)(h) GDPR (provision of healthcare), together with the Dutch Medical Treatment Act (WGBO), for health data; legal obligation for administrative/ fiscal retention; consent for marketing, newsletter and non-necessary cookies (always withdrawable); legitimate interest for security and service improvement.
5. Medical confidentiality & WGBO
Our BIG-registered clinicians are bound by medical confidentiality. Your medical data is not shared with third parties without your consent, except where required or permitted by law. The WGBO applies.
6. Who we share data with
We use carefully selected providers and sign a data processing agreement with each. We never sell your data. These include: our electronic patient record hosted within the EU; forms, CRM, invoicing and support (within the EU); video consultation (Meet) and email — with data at rest stored within the EU — and general file storage; scheduling and payments; newsletter and email delivery; website hosting, analytics and — only with your cookie consent — advertising partners.
7. Transfers outside the EU
Your data stays within the EU where possible. For Google Workspace (email and video consultation via Meet) we have configured data at rest to be stored within the European Union. For providers outside the EU, appropriate safeguards apply, such as the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
8. Retention
Medical record: at least 20 years after the last change (WGBO); administration: 7 years (fiscal); marketing data: until you unsubscribe or withdraw consent.
9. Security
We take appropriate technical and organisational measures, including encryption, access control and logging, and EU hosting. For healthcare information security we align with the NEN 7510 standard.
10. Your rights
Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. Note: erasure of your medical record is limited by the statutory retention duty. Requests: contact@menovia.nl. You may also complain to the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).
11. Cookies
See our Cookie Statement.
12. Complaints & data protection officer
Menovia has not appointed a separate data protection officer. For questions or requests about your data, contact contact@menovia.nl. Please raise any complaint with us first; for care-related complaints see our Complaints Committee. You may also complain to the Dutch Data Protection Authority.
13. Changes · 14. Contact
We may update this policy; the date above reflects the latest version. Menovia BV · Regentesselaan 2C, 3762DS Soest · CoC 98160834 · contact@menovia.nl · 085 212 9706.

