Arrow Left Home

Privacy statement

Privacy statement of Health-RI as of 1 December 2025 

This is the privacy statement of Stichting Health-RI (Chamber of Commerce number: 77193415), located at Jaarbeursplein 6, 3521 AL Utrecht, the Netherlands. Health-RI processes personal data to fulfil itspublic mission and does so in accordance with the General Data Protection Regulation (GDPR). 

In this privacy statement we explain for which purposes we process personal data and on which legal bases. 

Roles: controller and processor 

Health-RI acts as a controller for some services (when we determine the purposes and means of the processing) and as a processor for others (when we process personal data solely on instructions of anotherorganisation). 

Health-RI is the controller for the processing activities described in this privacy statement. 

No patient data and no research data 

Health-RI does not process health data of patients or citizens for its own purposes. 

We do provide services to hospitals and researchers and may process personal data for those services. In such cases, Health-RI acts only on the documented instructions of another controller and is thereforea processor. 

The relevant privacy information for those services is provided by the controller, for example the hospital or the research group. 

No automated decision-making 

Health-RI does not take decisions based solely on automated processing that produce legal effects concerning individuals or similarly significantly affect them (article 22 GDPR). 

Contact 

Beatrix Building Jaarbeurs, 5th floor, room HI-FIVE 

Jaarbeursplein 6, 3521 AL Utrecht 

Email: privacy@health-ri.nl 

Telephone: +31 88 116 7500 

Website: www.health-ri.nl 

2. Personal data we process as controller 

2.1 When you visit our website or read our newsletter 

Purpose Categories of personal data Legal basis 
Providing a functioning website Technical data such as (shortened) IP address, device, browser, time zone, necessary cookies Legitimate interests of Health-RI to provide a secure and functional website (article6(1)(f) GDPR) 
Website analytics using Google Analytics and Matomo Device and usage data, cookie identifiers Legitimate interests of Health-RI to obtain limited usage insights with low privacy impact (article 6(1)(f) GDPR) 
Sending newsletters Name, email address, preferences Consent (article 6(1)(a) GDPR) 
Managing unsubscribe requests Email address on suppression list Legitimate interests of Health-RI to comply with your objection (article 6(1)(f) GDPR) 

More information on cookies can be found in our cookie statement. 

2.2 When you are a customer or user of our services 

Purpose Categories of personal data Legal basis 
Creating and managing anaccount Name, email address, username, password Performance of a contract (article 6(1)(b) GDPR) 
Communicating about ourservices Contact details, information you provide Performance of a contract (article 6(1)(b) GDPR) 
Invoicing and tax compliance Name, organisation name, address, payment details, Chamber of Commerce number, VAT number Legal obligation (article 6(1)(c) GDPR) 
Improving our services Contact and usage data, feedback Legitimate interests of Health-RI to improve its services (article 6(1)(f) GDPR) 

2.3 When you contact our service desk 

Purpose Categories of personal data Legal basis 
Handling questions andrequests Name, organisation name, email address, telephone number, content of your message Legitimate interests of Health-RI and the data subject to handle enquiries effectively (article6(1)(f) GDPR) 
Handling data subject rightsrequests Identification data for verification, information you provide Legal obligation (article 6(1)(c) GDPR) 

2.4 When you receive an assignment from us or provide goods or services 

Purpose Categories of personal data Legal basis 
Procurement and contract management Contact details, role, communication, publicly available traderegister data Performance of a contract (article 6(1)(b) GDPR) 
Payments and audits Payment and bank details, tax data Legal obligation (article 6(1)(c) GDPR) 
Supplier management and risk management Contact and contract data Legitimate interests of Health-RI to manage risks (article 6(1)(f) GDPR) 

2.5 When you attend an event or webinar 

Purpose Categories of personal data Legal basis 
Planning and delivering events andwebinars Contact details, correspondence, registration status, preferences, payment information Performance of a contract (article 6(1)(b) GDPR) 
Reporting and internalcommunication Photos and videos Legitimate interests of Health-RI to document and communicate internally about events (article 6(1)(f) GDPR) 
Use of photos on social media Photos and videos Consent (article 6(1)(a) GDPR) 

2.6 When you are a contact person of a partner or data holder 

Purpose Categories of personal data Legal basis 
Relationship management andcollaboration Name, role, organisation, business email address and phone number, correspondence, communication preferences Legitimate interests of Health-RI and partners to maintain and coordinatecollaboration (article 6(1)(f) GDPR) 

2.7 When you participate in discussion groups 

Purpose Categories of personal data Legal basis 
Facilitating participation in discussiongroups Name, contact details, contributions Legitimate interests of Health-RI and participants to facilitate discussions (article 6(1)(f) GDPR) 

2.8 When you apply for a job 

Purpose Categories of personal data Legal basis 
Assessing candidates andconducting the recruitment process Name, contact details, CV (education, work experience), motivation letter, anyreferences, correspondence, other information provided by the applicant Performance of a contract (pre-contractual phase) (article 6(1)(b) GDPR) andlegitimate interests of Health-RI to select suitable candidates (article 6(1)(f) GDPR) 

3. Recipients of personal data 

We share personal data only where necessary with the following categories of recipients. 

Processors 

Hosting and cloud service providers, analytics providers, email and newsletter providers, service desk providers, security and maintenance providers. 

We conclude processing agreements with our processors (article 28 GDPR). 

Independent controllers 

Payment service providers, banks, accountants, the Tax Authority, and other competent authorities. 

Authorities 

Health-RI may disclose personal data to competent authorities such as courts or supervisory authorities. 

In all other cases, we only share personal data with third parties when you have given consent, when required to comply with a legal obligation, or when necessary for legal claims or to protect legitimateinterests. 

4. Transfers outside the European Economic Area 

Personal data will only be stored or otherwise processed outside the EEA by Health-RI or by third parties engaged by Health-RI if this complies with the GDPR rules on international data transfers. 

We only transfer your personal data to countries outside the EEA: 

  • if the European Commission has issued an adequacy decision, or
  • if appropriate safeguards are in place, or
  • if a derogation for specific situations applies. 

For more information, you may contact privacy@health-ri.nl

5. Retention periods 

We do not retain personal data longer than necessary for the purposes for which they were collected or for as long as a legal retention obligation applies. Examples include: 

  • Account and service data: as long as your account is active. After deletion, we retain necessary log and contract data for up to 24 months for security, evidence and complaint handling, or longer if requiredby law.
  • Invoice and tax data: retained for 7 years under tax legislation.
  • Newsletter consent and suppression list: consent records are retained for 5 years after the last message sent. Suppression list entries are retained for as long as your objection applies. 

6. Security 

We implement appropriate technical and organisational measures to prevent misuse, loss, unauthorised access, unauthorised disclosure and unauthorised alteration of personal data. 

Processors are assessed on security measures appropriate to the nature and risks of the processing. 

If you suspect a security issue or data breach, we ask that you report it by sending an email with your findings to servicedesk@health-ri.nl. More details can be found on the Coordinated Vulnerability Disclosure page.

7. Your rights 

Under the GDPR you have the following rights: 

  • Right to withdraw consent
  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing based on legitimate interests 

How to exercise your rights 

You may send your request to privacy@health-ri.nl

We respond within one month. To prevent misuse, we may request additional information to verify your identity. We only ask for what is necessary and process as little of this information as possible. 

We may not be able to comply fully with certain requests, for example due to legal retention obligations or to protect the rights and freedoms of others. 

If you have a complaint about our processing of your personal data, you may contact us via privacy@health-ri.nl or by post. You may also submit a complaint to the Dutch Data Protection Authority via www.autoriteitpersoonsgegevens.nl

8. Changes 

We may amend this privacy statement when necessary. The most recent version is available at www.health-ri.nl

In the event of substantial changes, we aim to inform you proactively. 

Share this page…