Privacy Policy
Reveal Health attaches great importance to the protection of your personal data. As we are a medical practice, we also process health data. This is particularly sensitive information, and we handle it with the utmost care.
In this policy, we explain what data we collect, why we do so, how long we keep it, and what your rights are.
1. Who is responsible for your data?
The data controller is Reveal Health, Naamsesteenweg 210, 3001 Heverlee, Belgium.
Email: info@revealhealth.be Phone: +32 (0)16 18 58 52
2. What data do we process?
Depending on your contact with us, we process the following data.
Identification and contact details. Name, date of birth, gender, address, phone number, email address, national registry number, and health insurance information.
Health data. Your medical history, symptoms and reason for consultation, results from questionnaires such as the Reveal QuickScan, laboratory results, imaging and ultrasound, body composition and function measurements, treatment plans, reports of consultations and interventions, prescribed medication and supplements, and correspondence with other healthcare providers.
Administrative and financial data. Appointments, invoices, payments, and payment details.
Technical data from this website. IP address, device and browser information, pages visited, and the time of your visit. See also our cookie policy.
3. Why do we process this data?
To examine, advise, and treat you, and to maintain your patient file. This is done on the basis of Article 9.2.h GDPR: processing necessary for healthcare, by or under the responsibility of a professional bound by professional secrecy.
To manage appointments and communicate with you. This is necessary for the performance of our agreement with you, based on Article 6.1.b GDPR.
For invoicing, accounting, and our tax obligations. This is a legal obligation, based on Article 6.1.c GDPR.
For the quality assurance of our care. This is done on the basis of Article 9.2.h GDPR and the Quality of Practice Act of 22 April 2019.
To defend ourselves in the event of complaints or disputes. This is done on the basis of our legitimate interest, Article 6.1.f GDPR.
To send you newsletters and information about our services. This is only done with your consent, which you can withdraw at any time.
We never use your health data for commercial purposes and never sell your data to third parties.
4. Who gets access to your data?
Within Reveal Health, only the healthcare providers and staff involved in your care have access to your file. They are all bound by professional secrecy (Article 458 of the Penal Code) or an equivalent contractual duty of confidentiality.
Outside of Reveal Health, we only share data when necessary:
- with other healthcare providers involved in your treatment, such as your GP or a specialist to whom we refer you, and only with your consent
- with laboratories and medical imaging centers for the performance of examinations
- with your health insurance fund or insurer, when necessary for reimbursement or coverage
- with our IT suppliers, who act as processors and only act according to our instructions, based on a data processing agreement
- with our accountant, and with government authorities when required by law
We process your data within the European Economic Area. [If applicable: When a supplier processes data outside the EEA, this is done on the basis of an adequacy decision or standard contractual clauses from the European Commission.]
5. How long do we keep your data?
Your patient file is kept for a minimum of 30 years and a maximum of 50 years after the last contact, as prescribed by the Quality of Practice Act.
Invoices and accounting documents are kept for 7 years, as required by tax law.
Data of non-patients, for example if you only asked a question via the contact form, is kept for a maximum of [1 year] after the last contact.
Your newsletter subscription is kept until you unsubscribe.
6. How do we secure your data?
We take appropriate technical and organizational measures, including role-based access control, encrypted storage and transmission, secure backups, and periodic evaluation of our systems and procedures.
Standard email is not a fully secure channel. We therefore ask that you preferably do not send medical information via standard email, but rather via [secure channel / during your consultation].
7. What are your rights?
Under the GDPR and the Patient Rights Act of 22 August 2002, you have the right to:
- access your file and receive a copy of it
- have your data corrected if it is inaccurate or incomplete
- have your data erased, within the limits of our legal retention obligations — we cannot simply delete your medical file
- restrict the processing of your data or object to it
- receive your data in a standard format or have it transferred to another healthcare provider
- withdraw your consent when processing is based on it
- designate a trusted person to assist you when reviewing your file
You can exercise your rights via info@revealhealth.be. We may ask you to verify your identity and will respond within 30 days.
If you are dissatisfied with how we handle your data, please contact us first. You also have the right to file a complaint with the Data Protection Authority, Drukpersstraat 35, 1000 Brussels, contact@apd-gba.be.
8. Changes
We may update this privacy policy. The date at the top indicates when it was last modified. We will actively notify you of any significant changes.