Privacyverklaring Dahlina

In this document, I (Sanja Zijlstra) will inform you about how my company (Dahlina) handles your personal data, which I will receive in the course of my work. Due to the sensitivity of this data, I highly value your privacy.  

My company is the controller for the collection and use of your data. This privacy statement explains which personal data I process and for what purpose. It also describes your rights. If you have any questions or wish to exercise your rights, please contact me using the contact details below. Dahlina has not appointed a Data Protection Officer (DPO), as this is not mandatory for a small healthcare provider, but you can always contact me directly as the controller.  

Contact details: You can reach me by phone at +31 681 661 536. You can email me at info@dahlina.nl. You can find further (contact) information about my business on my website (https://leden.solopartners.nl/lid/143000).  

Who does this privacy statement apply to? This privacy statement applies to all my clients. It also applies if you visit my website, are a former client, want to become a client or wanted to become one but ultimately didn’t, or if I act as a substitute for your healthcare provider.  

Your personal data: To provide the care that best suits your situation, I will speak with you. During this conversation, I will ask you several questions. These questions relate to your health, medication use, care needs, and wishes, as necessary for the indicated or desired care, and your own capabilities. You may also be asked for other personal data, including: your name, address, date of birth, account number, telephone number, and email address.  

If you are being treated, this information will be recorded in your medical file.  

Consent I cannot simply process your personal data; I require a legitimate basis for doing so. This often stems from the treatment agreement or a legal obligation. Sometimes it is based on your explicit consent. You can withdraw your consent at any time. For minors under the age of 12, I request permission from a parent/guardian/legal representative. For minors aged 12 to 16, I request permission from both the minor and the parent/guardian/legal representative. 

 If you do not agree or withdraw your consent, I cannot provide you with proper service. Providing good care depends on having all necessary and/or relevant information. Furthermore, I am required to maintain a medical record to ensure the quality of (future) care. If I do not have sufficient information to provide responsible care, I will inform you.  

I handle your data with care. I handle the information I receive from you with care. I have implemented technical and organizational measures to prevent unauthorized access to this data.  

As a healthcare provider, I am bound by professional secrecy, which essentially means that nothing may be shared with third parties. Furthermore, I do not transfer personal data to countries outside the European Economic Area (EEA). In exceptional circumstances, other healthcare providers may need quick access to your medical records, for example, in emergencies.  

To meet my accountability obligations, I keep registers of processing and any data leaks.  

How do I use the information I receive from you? I use the information I receive from you to form an overview of your health situation and to provide you with the best possible care you want or need. I only share the personal data I receive from you with third parties in the context of the assignment you have given me to perform certain care tasks for you. I only share the data with these third parties if you have given permission or if they are directly involved in your treatment and truly need this data to provide the necessary or requested care. Specifically, I may process your personal data in the following situations, among others.  

Beginning of Care Before starting care, you must provide your Citizen Service Number (BSN). I will need to verify this against your ID. I will not make a copy or scan of it. I will also ask you for your file with your previous healthcare provider.  

Referral: Sometimes it may be necessary to refer you to another specialist. I will only provide this specialist with the necessary personal data. I require your explicit consent to share other personal data and medical information.  

Payment:  I use your information to send an invoice for your treatment to your insurer or to you. This can also be done through a factoring company or accounting firm. The invoice will include your name and address and a breakdown of the treatment. I keep these invoices for my accounts receivable administration. If an invoice remains unpaid after several reminders, information may be shared with third parties for collection purposes.  

Health insurer: If you are insured, I will exchange your personal data with your health insurer. I will only exchange the necessary information. The health insurer may also request information from insured persons for a check-up. Depending on the type of check-up, I will be required to provide the requested information. Your privacy will always be my top priority.  
Incident reporting: If, unexpectedly, something has gone wrong with the protection of your personal data (or I suspect it has) and this potentially poses a high risk to your rights and freedoms, I will inform you as soon as possible. In some situations, an incident must be reported to the Dutch Data Protection Authority. If such a situation exists, a report will be made.  

Processor: It may be necessary to share data with third parties, such as an IT provider or an administrative office. If this third party qualifies as a processor, I will enter into a data processing agreement with them to ensure your privacy is protected.  

Automated processing: When a decision is made automatically based on personal data without the intervention of a real person, this is considered automated decision-making. If I use this method (for example, for technical support based on your personal data), I will ask your permission, unless it is legally permitted or this processing is necessary for the provision of healthcare.  

How long do I retain your data? Your personal data will not be retained longer than necessary under applicable laws and regulations. Healthcare providers are required under the Dutch Medical Treatment Contracts Act (WGBO) to retain medical records for 20 years, starting from the date of the last modification, or for as long as reasonably follows from the care of a good healthcare provider (or if this is in the interest of another party). After this period has expired, your data will be destroyed. For data not covered by the WGBO, your data will generally not be retained longer than necessary, unless a different statutory retention period applies (e.g., 7 years for tax data).  

What are your rights? As a client, you decide which data I do and do not receive from you. The rights you may also be entitled to are summarized below. If you wish to exercise any of your rights, please submit a request in writing. You will find my contact details at the top of this statement. I aim to respond to your request within one month (extendable to three months for complex requests).  

Right to access and copy: You have the right to inspect the data in your file. You can inspect your file by appointment. Personal notes and information from third parties in the file are not covered by the right to access. You may also request a copy of your personal data at any time. I will provide this copy free of charge once.  

Right to rectification: If you believe I have incorrectly processed certain information about you in my records, you can request a rectification. You can also supplement your client file. Please also ensure you report any changes to your situation so that the information on which I base my care is correct.  

Right to erasure: If you no longer want me to retain certain data in my records, you can request that I erase it. I will comply with this request in most cases. In some cases, erasure may not be possible. Consideration must be given to the interests of another party in retaining the data or to legal requirements that prevent erasure.  

Right to restriction: I have indicated above how I use the data I receive from you. If at any time you wish to restrict this use, for example, if you do not want me to share certain data with a specific organization, please let me know. I will comply with this request.  

Right to object:
If you do not want me to process certain data, you can request me not to do so before processing. I will comply with this request if the data is not necessary for fulfilling the agreement/contract.  

Source data If I receive personal information from you from third parties, I will inform you about the source from which I received this information.  

Other rights: You also have the right to information (this document) and the right to data portability. This entitles you to obtain your data in a commonly used and readable format. You also have the right to request information about who made certain information available to others via the electronic exchange system, and when others have accessed or requested certain information.  

Electronic communications

Website If you fill out the contact form on my website or send me an email, the data you send will be retained for as long as the nature of the form or the content of your email requires for a complete response and handling thereof.  

Third-party websites: This privacy statement does not apply to third-party websites that are linked to my website. I cannot guarantee that these third parties will handle your personal data reliably or securely. I recommend that you read the privacy statements of these websites before using them.  

Cookies: I use cookies on my website. Cookies are small text files that are placed on your PC, tablet, or mobile phone by a website. This happens immediately when you visit my website. I use essential cookies to make the website function (e.g., for navigation) and analytical cookies to analyze usage (e.g., via Google Analytics, anonymized without IP storage). For analytical cookies, I ask your permission via a cookie banner. You can refuse or delete cookies through your browser settings. When I ask you for your information on my website, it is to be able to properly answer a question or because you are registering for a specific service. I use this information only internally and it is not shared with third parties. This includes the following data: the browser used (such as Internet Explorer, Chrome, or Firefox), the time and duration of your visit, the pages visited, and any error messages that visitors have received.  

Changes to this privacy statement. I reserve the right to make changes to this statement. Regularly reviewing this privacy statement will keep you informed of any changes.  

Do you have any questions or complaints? Do you have any questions about how I handle your personal data? Please don’t hesitate to contact me. I will do my best to answer your questions as best as possible.  

If you have any complaints about how I have handled your personal data, please contact me. I promise to address this complaint. If you continue to believe I have not handled your personal data with sufficient care, you can file a complaint with the Dutch Data Protection Authority: www.autoriteitpersoonsgegevens.nl.  

Obligations for you as a client In order to be able to carry out the treatment agreement (as well as possible), you as a client also have obligations when it comes to providing information:  

– You inform your doctor as best you can.  

– You cooperate with your treatment as much as possible.  

– You pay your care provider or healthcare institution.  

Failure to comply with patient duties may have consequences for the treatment agreement.  

Dahlina Privacy Statement – ​​version February 2026

Dahlina 2026