Privacy Policy

1. Identity of the provider

Aevita BV

Koningsweg 38-10

3762 EC Soest

Nederland

KvK-nummer: 98141139

Email: info@aevita.com

Phone: 085 40150 35

Website: https://aevita.com/en/

Aevita has its own pharmacy and collaborates with BIG-registered healthcare professionals.

2. To whom does this privacy statement apply?

This privacy statement applies to:

  • visitors to our website;
  • users of our digital care platform and the app;
  • (potential) patients/clients of Aevita;
  • persons who contact us (for example by email or telephone).

3. What data do we process?

We process the following categories of personal data, among others:

A. Basic Data

  • Name, address, city
  • Date of birth and gender
  • BSN number or equivalent
  • Contact details (email, phone number)
  • Login details (username, password – encrypted)

B. Medical and care-related data

  • Medical history, current complaints and symptoms
  • Medication use, allergies and contraindications
  • Measurement values ​​and health data that you enter yourself or share with us
  • Reports of (video) consultations and contact moments
  • Prescriptions and dispensing of medicines
  • Details regarding treatment plan and progress

C. Identification and verification data

  • Data from digital identification (e.g. via eID / video identification)
  • Login attempt log data

D. Financial and administrative data

  • Bank account number (for SEPA direct debit)
  • Payment details and invoice details
  • Subscription type and payment status

E. Technical data

  • IP address
  • Device and browser data
  • Usage data of the app/platform (log files, session information)

F. Communication details

  • Correspondence via email, chat, or messages within the platform
  • Complaints, requests and feedback

We only process data that is necessary for the purposes described below.

4. For what purposes do we use your data?

We use your personal data for, among other things:

Provision of care and medical assessment

  • Assessing your complaints and medical situation;
  • Conducting (video) consultations and digital intakes;
  • decide whether or not to prescribe medication;
  • monitoring the progress and your health within the chosen indication.

Pharmacy care and medication dispensing

  • processing recipes;
  • dispensing and (arranging for) the delivery of medicines;
  • Check for contraindications, interactions, and dosages.

Account management and use of the platform

  • creating and managing your account;
  • securing access to your file;
  • logging usage (for example for security and audit trail).

Administration and payment

  • invoicing and payment processing;
  • executing subscriptions and SEPA direct debits;
  • comply with fiscal and administrative retention obligations.

Quality, safety and improvement of care

  • internal quality control and incident recording;
  • analyzing anonymized/aggregated data to improve our services;
  • training and peer supervision within the care team (anonymized where possible).

Legal obligations and supervision

  • comply with obligations under laws and regulations (including WGBO, Wkkgz, Medicines Act, GDPR);
  • notifications to supervisory authorities (e.g. IGJ) when required.

Communication

  • answering questions and requests;
  • sending important service messages (e.g. about your medication, changes to appointments, or system updates).

Marketing (only with your consent)

  • sending newsletters or targeted information about our services, if you have signed up for this. You can easily unsubscribe at any time.

5. On what grounds do we do that (GDPR)?

We process your data based on the following legal grounds under the GDPR:

For healthcare provision and medical data

  • Uitvoering van de behandel-/zorgovereenkomst (art. 6 lid 1 sub b AVG);
  • Provision of healthcare by a professional, with appropriate confidentiality (Art. 9, paragraph 2, subparagraph h GDPR).

For pharmacy care and medication dispensing

  • Performance of the contract and/or substantial public interest in public health (Art. 6(1)(b) and Art. 9(2)(h)/i GDPR).

For administration and invoicing

  • Statutory obligation (for example, tax retention obligation) (Art. 6 paragraph 1 sub c GDPR).

For security, quality and improvement

  • Legitimate interest of Aevita to provide safe and high-quality care (Art. 6 para. 1 sub f GDPR).

Where possible, we use anonymized or aggregated data.

For newsletters and marketing, we use your consent (Art. 6 para. 1 sub a GDPR). You can withdraw this consent at any time.

6. Who has access to your data?

Within Aevita, only those employees who need access to your data for their work have access to it, such as:

  • doctors;
  • nurses;
  • pharmacist and pharmacy team;
  • customer service employees;
  • administrators of the digital systems (for technical maintenance).

All these individuals are bound by (medical) professional secrecy, confidentiality agreements, and internal privacy and security rules.

In addition, we may share data with:

Healthcare providers outside Aevita, but only:

  • if this is necessary for your treatment, and with your consent or in accordance with the applicable exchange rules (e.g., GP, other pharmacy, specialist).

External processors (service providers), such as:

  • hosting- en cloudproviders;
  • video identification/eID providers;
  • IT maintenance parties;
  • email and SMS service providers;
  • Transport and courier companies;
  • payment providers (for example iDEAL/SEPA via a third party).

We enter into a data processing agreement with these parties, which stipulates that they process your data only according to our instructions and with appropriate security.

We do not sell your personal data to third parties.

7. Transfer outside the EU/EEA

In principle, we process your personal data within the European Economic Area (EEA). If data is nevertheless transferred to a country outside the EEA, we ensure appropriate safeguards, for example: a European Commission decision stating that the country concerned offers adequate protection, or by using Standard Contractual Clauses (SCCs) approved by the European Commission.

Where applicable, this is recorded in the data processing agreements and, if relevant, in additional information provided to you.