Privacy Policy
Privacy Statement
Version 2.0 — April 2026
1. Who Is Responsible for Your Data?
ZIZ Foundation (AGB code: 22227884), Spijkermakersstraat 101a, 2512 ET The Hague, Chamber of Commerce (KvK) No. 82825327, is responsible for the processing of your personal data. This applies to all information you share with us through www.ziz.nl.
Questions about privacy? Email us at klantenservice@ziz.nl.
Data Protection Officer: bas.mourik@ziz.nl.
Product information about the eHealth consultation: www.ziz.nl/over-deze-software.
2. Why Do We Process Your Data?
We process your data because it is necessary to provide you with appropriate healthcare:
To perform the eHealth consultation and provide you with personalized triage advice
To carry out the appropriate diagnostic tests and report the results to you
To facilitate a dermatological photo consultation, where applicable
To monitor and improve the quality and safety of our services
To comply with our legal obligations (such as medical record retention and incident reporting requirements)
3. On What Legal Basis Do We Process Your Data?
We process your data on the basis of:
Your explicit consent
The healthcare agreement — without your data we cannot provide our services.
Legal obligations — such as medical record retention requirements (WGBO) and reporting obligations for medical devices.
Our legitimate interests — namely improving software quality and monitoring safety.
4. What Data Do We Process?
Identification data: first and last name, address, date of birth, gender, email address, telephone number, Dutch citizen service number (BSN), identity document details, and health insurance number
Health data: your questionnaire responses, symptoms, testing history, and test results
Information about sexual behaviour: details about sexual contacts and risk factors
Photographs: only if you use the photo consultation service
Technical data: IP address, browser type, and session information
5. Machine Learning
In addition to guideline-based advice, the eHealth consultation displays an estimated probability of a positive test result. This estimate is calculated using a machine learning model trained on anonymized historical consultation data. It is important to note that:
The estimate is provided for informational purposes only and never changes which tests are offered to you.
You will never be excluded from testing based on the machine learning model.
6. How Long Do We Retain Your Data?
Your medical record (questionnaire responses and test results): 20 years after your most recent consultation, as required by law (WGBO).
Administrative and financial records: 7 years, in accordance with Dutch tax legislation.
Registration without completing testing: 3 months, after which your data are deleted (see also the Terms and Conditions).
Other data: no longer than necessary. After that, they are deleted or irreversibly anonymized.
7. Who Has Access to Your Data?
Your data are protected by medical confidentiality. Only your healthcare providers within ZIZ have access to your patient record. In addition, we work with a limited number of trusted service providers that help us deliver our services:
Software developers and technical administrators (located in the Netherlands)
Our hosting provider (located in the Netherlands)
Dermatologists (only for photo consultations)
We have concluded appropriate agreements with all these parties to protect your personal data. Your data are stored within the European Union. For two technical services hosted in the United States (error monitoring and password management), additional safeguards have been implemented. We disclose your data only where legally required, for example to regulatory authorities or the Municipal Public Health Service (GGD).
8. How Do We Protect Your Data?
We take the security of your data seriously and operate in accordance with NEN 7510, the Dutch standard for information security in healthcare. Our systems are regularly tested by independent cybersecurity experts.
9. What Happens If Something Goes Wrong?
If a personal data breach occurs, we will report it to the Dutch Data Protection Authority within 72 hours. If the breach poses a high risk to your rights and freedoms, we will also inform you personally.
10. What Are Your Rights?
You have the right to:
Access your personal data
Have inaccurate data corrected
Request the deletion of your data (unless we are legally required to retain them)
Restrict or object to the processing of your data
Receive your data in a portable format and transfer them to another organization (data portability)
Withdraw your consent at any time
You can submit a request by emailing klantenservice@ziz.nl. We will respond within one month.
11. Complaints
If you are dissatisfied with how we process your personal data, please contact us via klantenservice@ziz.nl. You may also lodge a complaint with the Dutch Data Protection Authority (www.autoriteitpersoonsgegevens.nl).
12. Minors
Our services are available to users aged 12 years and older. Under the Dutch Medical Treatment Contracts Act (WGBO), STI care is regarded as healthcare intended to prevent serious harm. Therefore, young people aged 12 and older may independently consent to the processing of their personal data in this context; parental or guardian consent is not required.
13. Cookies
The website uses cookies that are necessary for its operation. We ask for your consent before placing analytical cookies. More information is available at www.ziz.nl.
14. Changes
We may update this Privacy Statement from time to time. The most current version is always available at www.ziz.nl. If we make significant changes, we will actively inform you.
Contact
ZIZ Foundation
Spijkermakersstraat 101a
2512 ET The Hague
Customer Service / Privacy: klantenservice@ziz.nl