Privacy statement
Tandarts West Rotterdam takes your privacy seriously. In this statement you can read which personal data we collect, why we need it, how long we keep it and what rights you have.
Last updated: 13 May 20261. Who are we?
Tandarts West, located at Taandersstraat 121, 3026 XS Rotterdam, is the data controller for the processing of personal data described in this privacy statement.
Contact: 010 846 6539 · info@tandarts-west.nl
2. Which data do we collect?
In order to provide you with good oral healthcare, we process the following categories of data:
Identification and contact details
- First and last name, gender, date of birth
- Address, postcode and place of residence
- Phone number and email address
- Citizen Service Number (BSN), required for healthcare under the Dutch Additional Provisions on the Processing of Personal Data in Healthcare Act
- Identity document (we only record the type and number, no copy)
Health insurance details
- Name of health insurer and policy number
- Type of supplementary dental insurance
Medical data
- Treatment history, X-rays and scans
- Medication, allergies and relevant medical history
- Treatment plan and notes from the dentist or dental hygienist
Financial data
- Invoice and payment details (processed by Infomedics, our billing partner)
Visits to our website
- Anonymised data via cookies (see our cookie statement)
- IP address (only for security and for a short period)
- Content of contact forms that you submit yourself
3. What do we use your data for?
We process your data solely for the following purposes:
- Performing the dental treatment agreement (WGBO, the Dutch Medical Treatment Contracts Act)
- Keeping a medical record as required by law
- Scheduling and confirming appointments
- Sending invoices via Infomedics
- Communication about your treatment (phone, email, SMS)
- Referral to a specialist or hospital when medically necessary
- Answering questions you submit via our contact form or by phone
- Improving our services and website (on an anonymised basis)
We never sell your data to third parties and we do not use it for commercial profiling.
4. On what legal basis do we process?
We process your data exclusively on the basis of one of the legal grounds set out in the GDPR:
- Performance of a contract, for the dental treatment and billing
- Legal obligation, for maintaining the medical record (under the WGBO) and for tax administration
- Vital interests, in the case of medical emergencies or allergies
- Consent, for optional communication (for example SMS reminders) and for certain cookies
5. Who do we share your data with?
We only share your data when this is necessary. The external parties we work with are:
- Infomedics, for sending invoices and managing payments
- Your health insurer, for claims of reimbursed treatments
- Referral specialists, such as an orthodontist, oral surgeon or hospital, only when medically necessary and with your consent
- IT suppliers and our hosting provider, for the secure storage of the medical record (with a data processing agreement in place)
- Government authorities, only when legally required (for example the tax authorities or the Healthcare and Youth Inspectorate (IGJ))
We have concluded data processing agreements with all of these parties. Your data is stored within the European Economic Area (EEA).
6. How long do we keep your data?
For other data we apply the following retention periods:
- Financial administration: 7 years (statutory tax retention obligation)
- Patient registration form: for as long as you are a patient with us, plus 20 years thereafter (it becomes part of your record)
- Contact forms (non-patients): a maximum of 1 year
- Job application data: 4 weeks after the application process is completed, or 1 year with your consent
- Website cookies: see our cookie statement
7. How do we secure your data?
We take the protection of your data very seriously and apply appropriate measures to prevent misuse, loss and unauthorised access:
- Access to the medical record is limited to healthcare staff with a treatment relationship
- Encrypted connections (HTTPS) for our website and patient portal
- Strong passwords and two-factor authentication for staff
- Regular back-ups on secure servers within the EEA
- Data processing agreements with all external parties
- Periodic security audits and staff training
8. What are your rights?
Under the GDPR you have a number of data subject rights regarding your personal data:
- Right of access, you can ask which data we hold about you
- Right to rectification, to have incorrect data corrected
- Right to restriction, to temporarily halt processing
- Right to object, against specific processing activities
- Right to data portability, a copy of your data in a structured format
- Right to be forgotten, to have data deleted, with the exception of the medical record which we are legally required to keep for 20 years
Would you like to exercise one of these rights? Send a request together with proof of identity to info@tandarts-west.nl or visit us at reception. We will respond within 4 weeks.
10. Complaints and contact
Do you have a question about this privacy statement or about how we handle your data? Please get in touch. We are happy to help.
If you disagree with how we handle your data and we cannot resolve it together, you can file a complaint with the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority).
Questions about your privacy?
We are ready to help. Call or email us directly.