These are the privacy regulations of Team Tandartsen in Amsterdam, registered in the trade register of the Chamber of Commerce under number 97225428.
Team Tandartsen ensures that (special) Personal Data of patients is handled with care. We comply with applicable laws and regulations, including the General Data Protection Regulation. With this Privacy Policy we want to inform you in more detail about our policy.
For clarity, we briefly state what we mean by certain terms:
Personal data: any data through which the patient can be identified.
Controller: the processing Controller, as referred to in Article 4 paragraph 7 of the Regulation. For this privacy regulation the dental practice.
Processing/Processing: a processing of Personal Data, whether or not carried out through automated processes, such as collecting, recording, organizing, storing, updating, modifying, retrieving, consulting, using, providing by means of transmission, dissemination or any other form of making available, bringing together, correlating, as well as blocking, erasing or destroying Personal Data.
Processor: the person who takes care of the Processing of Personal Data on behalf of the dental practice, without being subject to its direct authority, such as auxiliary persons hired by the Controller.
Data Subject: the person to whom the Personal Data relates, generally the patient.
Implementation Act: the General Data Protection Regulation Implementation Act.
Regulation:Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (OJEU 2016, L 119).
Privacy Regulations: this document.
Pseudonymized data:Personal data that can no longer be linked to a specific data subject without the use of additional data. This additional data is kept in such a way that it cannot be linked to an identifiable person.
Personal data are derived or derived from data provided orally and in writing by the person concerned or their legal representative. Personal data may additionally be provided by the health insurance company, the general practitioner, other practitioners, specialists, social workers or other persons or agencies other than the aforementioned.
1. Processing shall be carried out in a manner that is lawful, proper and transparent with respect to the data subject. In addition, the collection of personal data is done for specified, explicitly defined and legitimate purposes. It shall not be processed in a manner incompatible with those purposes.
2. Processing for archiving in the public interest, scientific or historical research or statistical purposes shall not be considered incompatible with the original purposes.
3. The Processing is lawful only if and to the extent that at least one of the following conditions is met:
a. Consent of data subject;
b. Entering into and performing a treatment agreement);
c. Safeguarding a vital interest of the Data Subject, such as emergencies;
d. Serving a legitimate interest of the Respondent or a third party (e.g., business continuity);
e. Need to fulfill a legal obligation or a contract with the data subject.
4. Personal data shall be processed only insofar as they are adequate, relevant and limited to what is necessary in view of the purposes for which they are processed.
5. The dental practice processes Personal Data for the following purposes:
a. Treatment of the Data Subject;
b. Informing and contacting Data Subject(s);
c. Financial records;
d. Proper operation of the website.
1. The Controller can demonstrate that the Data Subject has given consent to the processing.
2. The Data Subject may withdraw a given consent at any time.
Anonymized data is not subject to the effect of these privacy regulations.
Processing may see the following data categories:
a. Name, first names, initials, title, gender, date of birth, address, zip code, place of residence, telephone number and similar data necessary for communication, as well as payment data of the Data Subject;
b. An administration number that contains no information other than under a;
c. Data referred to in a. from the parents, guardians or caregivers of minor Data Subjects;
d. Data referred to in point a of the Data Subject's family or relatives as well as others who are informed about the wellbeing and health of the Data Subject;
e. Information on the health status of the Data Subject and, in the case of hereditary conditions, his family and relatives;
f. Other special Personal Data for the purpose of the proper treatment or care of the Data Subject;
g. Information about the treatment followed and to be followed by the Data Subject as well as the medications or facilities provided;
h. Information on calculating, recording and collecting the fee;
i. Information about the Data Subject's insurance;
j. Other data necessary for treatment.
1. Before processing personal data, the Controller shall notify the Data Subject and/or the Data Subject's legal representative:
a. Who is responsible for processing with contact information;
b. Why certain, specific Personal Data will be Processed;
c. If applicable, the contact information of the data protection officer;
d. In what manner the Personal Data is processed;
e. The period for which the personal data will be stored or, if that is not possible, the criteria for determining that period;
f. Any other information that must be provided for the purpose of due diligence. This also means: The more sensitive the Personal Data the Controller intends to process, the more thorough the information must be.
2. If personal data is obtained through a third party, or delivered to a third party, the information requirement shall be met in the same manner before the personal data is obtained or delivered, unless it can only be done with disproportionate effort.
1. The Data Subject has the right to inspect his/her personal data and may request the following information:
a. A description of the purpose or purposes of processing Personal Data;
b. Any available information regarding the origin of the personal data;
c. The categories of data covered by the processing;
d. A list of recipients or categories of recipients who received the personal data;
e. If possible, the period for which the personal data is expected to be stored, or if not possible, the criteria for determining that period;
f. That the Data Subject has the right to rectification, the right to data erasure and the right to restriction of processing.
2. A request for inspection may be denied for the following reasons:
a. The requester is not a Data Subject or his/her request does not involve data that relates only to the requester;
b. The applicant has not yet reached the age of 16 years and/or is under guardianship. In this case, only the legal representative can make the request;
c. Respondent has already recently complied with a similar request from the same requester;
d. Protection of the Data Subject or the rights and freedoms of others;
e. Because of the security of the state, and/or the prevention, detection and prosecution of crimes.
1. The Data Subject has the right to object at any time to the processing of personal data concerning him/her. In the event of an objection, the processing shall be stopped by the Controller.
2. The Data Subject has the right to obtain from the Controller without delay rectification of inaccurate Personal Data concerning him.
3. The Data Subject shall have the right to obtain from the Controller the erasure of Personal Data concerning him without unreasonable delay. In addition, the Controller shall be obliged to erase data without unreasonable delay when the Data Subject has withdrawn his consent or the Controller no longer needs the Personal Data for the purposes for which they were collected.
4. The Data Subject, if the accuracy of the Personal Data is disputed by him, has the right from the Controller to obtain restriction of the processing.
5. The Data Subject shall have the right to obtain the Personal Data concerning him that he has provided to the Controller in a structured, common and machine-readable form.
The Controller shall take appropriate measures so that the Data Subject receives the communication or information regarding the rights described in these privacy regulations in a concise, transparent and accessible manner and in clear terms.
1. Access to Personal Data shall in principle only have those directly involved in carrying out the treatment of the Data Subject, insofar as such access is necessary for their work.
2. When a Processing is carried out on behalf of the Controller, the Controller shall only use Processors who provide adequate guarantees that the Personal Data will be Processed in accordance with the Regulation, the Implementing Act or regulations based thereon.
3. Access/Personal Data may otherwise be granted to the following persons and entities:
a. Investigators referred to in Article 7:458 of the Civil Code;
b. Health insurance companies to the extent necessary for the purpose of the obligations under the insurance contract;
c. Third parties in charge of debt collection to the extent that access/disclosure is necessary and does not involve medical data;
d. Others, when the basis of the Data Processed is:
(i) Consent of the Data Subject;
(ii) A need to fulfill a legal obligation;
(iii) Safeguarding a vital interest of the Data Subject.
e. Others, where the further processing is for historical, statistical or scientific purposes, if the Controller has taken the necessary measures to ensure that further processing is carried out only for these purposes.
The Responsible Party shall keep a register of the processing activities carried out under its responsibility. This register shall contain the following information:
a. The name and contact information of the Responsible Party and, if applicable, the Data Protection Officer;
b. The processing purposes;
c. The categories of data covered by the Processing;
d. The categories of recipients to whom Personal Data is provided;
e. If possible, the intended time period within which the Personal Data must be deleted;
f. If possible, a description of the technical and organizational measures taken.
1. If a Personal Data breach has occurred, the Controller shall -if and to the extent required by law- notify the Data Subject and the Personal Data Authority as soon as possible after becoming aware of it.
2. The notification referred to in the first paragraph shall contain at least:
a. The nature of the breach;
b. The likely impact of the breach;
c. The measures taken by the Respondent as a result of the breach;
d. A point of contact for more information.
1. Medical data obtained to enter into or fulfill a treatment agreement shall be kept for 20 years. The Responsible Party shall not be bound to longer retention periods than required by law, in particular article 7:454 paragraph 3 of the Civil Code.
2. Other Personal Data shall not be kept longer than necessary for the purposes for which it was processed. If such Personal Data is no longer needed, it will be deleted.
1. The Controller, the Processor and anyone who has access to Personal Data under the authority of the Controller are obliged to maintain the confidentiality of the Personal Data.
2. Data relating to the health of Data Subject(s) are considered ‘special Personal Data’. The Processing of special Personal Data is subject to a duty of confidentiality for anyone processing it. This arises from that person's office, profession or employment contract.
1. The Responsible Party must ensure appropriate technical and organizational measures to secure personal data.
Appropriate‘ means that the security measures taken are appropriate to the risk that the Personal Data will be (further) processed carelessly or unlawfully and the damage that would result. The measures taken must ensure that:
a. Only authorized persons have access to Personal Data;
b. The Personal Data is accurate and not lost;
c. The Personal Data are available without hindrance for lawful processing according to the arrangements within the organization.
3. In all cases, the Responsible Party shall ensure the information security policy and shall propagate this policy within the dental practice.
1. The Team Tandartsen website uses cookies. Cookies are small text files sent by a website to the browser, after which the browser stores this data. On a subsequent visit to the website, the browser sends the stored data back to the website. Cookies come in all shapes and sizes. Team Tandartsen uses technical cookies, analytical cookies and marketing cookies. Below we explain what these cookies are used for.
Technical cookies
Technical cookies are necessary for the website to function properly. These cookies are necessary to ensure that you have an optimal user experience. No personal data is processed with the use of technical cookies.
Analytical cookies
Analytical cookies are used to collect information about how website visitors use and experience our website. This information allows us to optimize the website, monitor its performance and improve the user experience. No personal data is processed with the use of analytical cookies.
Marketing cookies
Marketing cookies, also known as tracking cookies, are used to track the browsing habits of website visitors across the Internet. If you have given your consent, we place tracking cookies to present personalized offers and discount promotions through various online channels.
You consent to this processing when you check the box using the cookie notice. At any time you can change the preference through the cookie settings on the website. Team Tandartsen takes appropriate technical and organizational security measures to secure personal data against loss or against any form of unlawful processing. These measures are aimed at achieving an appropriate level of protection, given the risks involved in the processing and the nature of the data to be protected.
2. Data retention period through the website
Team Tandartsen retains your data for no longer than is necessary for the purposes for which the data was collected with a maximum duration of 2 years.
3. Management and access to third-party personal data
Subject to any legal requirements in laws and regulations to that effect, only those entrusted with the management of the customer database and/or those associated with or necessarily involved in the processing of personal data, including employees and processors of Team Tandartsen, shall have access to the personal data.
Team Tandartsen uses the following online tools.
* Google Analytics
These online tools are used, among other things, to analyze the surfing behavior of website visitors, to collect website statistics and to send newsletters. The above party has its own privacy statement and bears its own responsibility for it.
1. The Respondent accepts no more obligations than those to which it is bound by law, unless otherwise agreed in writing with the Data Subject.
2. The Data Subject has the right to file a complaint with the supervisory authority.
3. Amendments to these privacy regulations shall be made by the Respondent. The amendments to the privacy regulations are effective with respect to Data Subject(s) after Data Subject(s) have been notified of the amendment.
4. These Privacy Regulations are effective as of 25-06-2025 and are available for inspection at the dental office.