Rondom Privacy Statement
Last updated: 1 September 2026
Last updated: 1 September 2026
Email: fg@rondomlopengroep.nl
Telephone: 088-1180500
Correspondence address:
Rondom
Hooge Zijde 17
5626 DC Eindhoven
The personal data we process depends on the reason why you are using our website, healthcare or services.
This may include, amongst other things:
Health data
When you receive care from us or register for certain types of care, we may also process your health data.
This could, for example, refer to:
Health data is a special category of personal data. Additional legal requirements apply to this data, and we handle it with extra care.
We ask that you only provide medical or other sensitive information when specifically requested to do so in a designated form or secure healthcare process.
For general contact forms and free-text fields, we ask that you do not include your BSN, a copy of your ID or any unnecessary medical or other sensitive information.
Make an appointment
When you book an appointment online, we use the information required for this purpose to:
When our appointment scheduler forwards data directly to the designated system, the website does not also store it as a separate form submission.
Ordering insoles
When you order insoles via our website, we use your details to:
Health pathways, treatment groups and other healthcare registrations
When you register for or express an interest in a Health Programme, treatment group or other form of care or support, we use your personal data to:
Where this actually results in healthcare being provided, the necessary details are recorded in the relevant healthcare record.
Contact forms
When you fill in a general enquiry form, we use your details to:
Complaints
When you submit a complaint via our website, we use your details to:
As a complaint may contain medical or other sensitive information, the information is only made available to those who need it to deal with the complaint.
Medically relevant information from a complaint is only included in the patient’s medical record if this is necessary for the provision of care or record-keeping. In principle, the complaints file itself is kept separately from the medical record.
Rondom app
When you sign up for or cancel a Rondom app or a similar online service via our website, we use your data to process your registration or cancellation and, where applicable, to manage your account.
Webinars, activities and meetings
When you register for a webinar, meeting or other activity, we use your details to:
Registering for an activity does not automatically mean that you are also signing up for future newsletters or commercial communications.
Newsletters and marketing
When you voluntarily subscribe to a newsletter or other marketing communications, we use your contact details to send you this information.
If we use your consent for this purpose, you may withdraw this consent at any time.
We do not use data from patient records or medical information for general commercial marketing purposes.
Apply for a job
When you apply via our website, we use your details to:
If, following the recruitment process, we wish to retain your application details for a longer period in order to potentially contact you regarding a future vacancy, we will seek your separate consent for this.
Website and search feedback
When we ask you whether the information on our website was helpful, or when you provide feedback on search results via a simple function, we use this information to improve our website and the information we provide.
We aim to process as little personal data as possible for this purpose. Where possible, we use only aggregated or anonymised information.
We process personal data only where there is a valid legal basis for doing so under the General Data Protection Regulation (GDPR).
Depending on the situation, the processing may be based on:
Performance of a contract or steps leading up to a contract
For example, when you:
A legal obligation
As a healthcare provider and a business, we are required by law to process and retain certain data. This may apply, for example, to medical records and our financial records.
A legitimate interest
In certain cases, we process data because this is necessary for a legitimate interest of Rondom or another party, and your privacy interests do not override this.
This may apply, for example, in the following cases:
Permission
We require your consent for certain processing activities.
This may apply, for example, to:
When we process personal data on the basis of consent, you may withdraw that consent at any time.
Health data and other special categories of personal data
For health data, in addition to a standard legal basis under the GDPR, a statutory exception to the prohibition on processing special categories of personal data is also required.
In the context of healthcare provision, for example, data processing may be necessary for the provision, organisation and administration of healthcare, whereby the data is processed by, or under the responsibility of, persons bound by a professional duty of confidentiality.
Virtually everything we know about illness, health and effective care has been partly developed through medical and scientific research.
Within certain healthcare organisations belonging to Rondom, we can therefore contribute to scientific research aimed at improving healthcare, treatments and knowledge about symptoms, conditions and treatment outcomes.
Data collected during routine care may be used for this purpose, such as:
Research for which we are seeking separate consent
For some studies, we expressly ask for your consent in advance.
This applies, for example, when:
In that case, you will receive information about the specific study before you decide whether you wish to take part.
Participation is voluntary. Not taking part will not affect your treatment.
Reuse of existing medical data
In certain cases, medical data and imaging material collected during your treatment may be reused for statistical or medical-scientific research in the field of public health without separate consent being sought again for that specific reuse.
This is not automatically permitted simply because the data already exists.
Use or disclosure without separate authorisation is only permitted if the applicable legal conditions are met.
In this regard, the following applies, amongst other things:
We assess on a case-by-case basis whether these conditions are met and what legal basis and additional safeguards are required.
Where the law stipulates that a note must be made in the medical record regarding a service provided for research purposes, we do so.
Data protection in research
We do not process more personal data for research purposes than is necessary.
Where possible:
Pseudonymised data Personal data is retained for as long as it is still possible to trace it back using additional information.
Data is only considered anonymous when it can no longer, within reason, be traced back to an individual. The GDPR no longer applies to data that has been effectively and irreversibly anonymised.
When research results are published, we ensure that individual patients cannot be identified in them.
Objection to reuse for scientific research
Do you not wish your medical data already collected and, where applicable, medical imaging to be reused or disclosed for medical-scientific research without your separate consent, where the law grants you a right to object?
In that case, you may object to this.
You can submit your objection via: wetenschap@rondomlopengroep.nl
For Rondom Podotherapeuten, you can also use the objection form available on our website for this purpose.
Your objection will be recorded so that it can be taken into account in future investigations. Where appropriate, this objection will be noted in your medical records.
Objecting to clinical research will not affect your treatment or your relationship with your healthcare provider.
Previously given consent for a specific study
If you have previously given separate consent to take part in a specific study, that consent is not automatically withdrawn simply because you later raise a general objection to the reuse of your data.
You can, however, withdraw your consent for a specific study.
Withdrawal does not affect the lawfulness of the processing that took place before you withdrew your consent.
If research data has already been effectively and irreversibly anonymised at the time of your request, we can no longer link it to you and are therefore unable to remove it from the research data as your individual data.
On our online forms, we explain why we need the personal data requested.
For example, the following mandatory tick box can be used on forms:
☐ I have read the privacy policy.
This tick is intended to confirm that you have been able to read the information regarding the use of your personal data.
It does not automatically mean that consent is the legal basis for the processing.
Where we actually require your consent for a specific and voluntary purpose, we will ask for it via a separate tick box or other distinct option.
This may apply, for example, to:
A consent box is not pre-ticked for you.
Not every form submission received via our website is automatically saved in the EPD.
Only forms for which this is necessary and for which a specific procedure or technical link has been set up are transferred to the EPD or another healthcare system.
This applies, for example, to:
When data becomes part of the patient record, the legal regulations governing medical records apply from that moment onwards.
General contact forms, newsletter subscriptions, webinar registrations, job applications and other data are not automatically stored in a patient record simply because they are submitted via our website.
We only share personal data when this is necessary for the purpose for which the data was collected, for the provision of our services or healthcare, or when we are legally obliged to do so.
This may include, amongst other things:
The fact that various organisations are part of the same group does not mean that every employee or every limited company automatically has access to all personal data.
Access is restricted as far as possible to those who require the data for their work.
Our website and the associated platform are technically managed in collaboration with Stofloos.
Stofloos processes personal data on our behalf and acts as a data processor for Rondom in relation to this work.
For parts of its technical infrastructure, Stofloos uses, amongst other things:
The primary storage of personal data from our website environment and the regular backups thereof take place within the European Union.
Agreements with Stofloos regarding the processing and security of personal data are set out in a data processing agreement. The relevant infrastructure providers are engaged by Stofloos as sub-processors.
Mailchimp
We can use Mailchimp for newsletters and other email communications intended for this purpose.
For example, your:
are processed.
We will only use your data for such marketing communications where there is a valid legal basis for doing so.
MultiSafepay
For online payments, we can use MultiSafepay.
We will provide the details necessary to process the payment.
MultiSafepay processes personal data in connection with its payment services and its own legal obligations, and acts as the data controller for these processing operations.
CookieYes
We use CookieYes to manage our cookie banner, cookie preferences and to record the choices visitors make regarding cookies.
CookieYes processes this data on our behalf and acts as a data processor in doing so.
Other suppliers
Depending on the service you use, other providers may also be involved in, for example:
We do not provide suppliers with any more personal data than is necessary for them to carry out their work.
Where required, we enter into agreements on privacy and security with parties that process personal data on our behalf as data processors.
Our website uses cookies and similar technologies.
We use CookieYes to manage our cookie banner and your cookie preferences.
When you make a selection via the cookie banner, CookieYes may, amongst other things, record:
We use this registration to respect your preferences and, where necessary, to be able to demonstrate which cookie choices have been made.
We may retain evidence of your cookie preferences via CookieYes for up to 5 years.
CookieYes Limited is based in the United Kingdom and processes this data on our behalf.
Non-essential external scripts and tracking techniques are blocked until you have given your consent, where such consent is required by law.
You can review and change your preferences at any time via the Cookie settings on our website.
Further information on:
can be found in our Cookie policy.
Depending on your cookie preferences, we may use services provided by, for example:
These techniques can be used to analyse our website and, where you have given your consent, to measure the results of campaigns or to carry out online marketing.
We do not use information from your patient record, medical forms or other health-related data for general commercial advertising purposes.
You can find out which tracking techniques are actually in use and for how long they are used in the current cookie overview in our Cookie Policy.
We endeavour to process personal data within the European Economic Area as far as possible.
The personal data stored by Stofloos via our website environment is hosted within the European Union.
Some other suppliers may process personal data outside the EEA.
This allows Mailchimp to process data in the United States. CookieYes Limited is based in the United Kingdom.
When personal data is processed outside the EEA, we ensure that a valid legal framework is in place for this.
This could be, for example:
We do not retain personal data for longer than is necessary for the purpose for which it was collected, unless we are required by law to retain the data for longer or there is another legitimate reason for retaining it for a longer period.
We apply the following principles to our website and the associated processes:
General contact form
Up to 12 months after the enquiry has been dealt with. Simple enquiries will be removed sooner where possible.
Online appointment
The website does not save the appointment as a separate form submission when it is sent directly to the scheduler. Data that becomes part of the medical record is subject to the retention period for that medical record.
Medical file
In principle, at least 20 years from the date of the last change to the file. Longer where this is required by law or is reasonably necessary for the provision of proper care or for another compelling interest.
Youth support file, where applicable
In principle, at least 20 years after the end of youth care, or longer if this is necessary for the provision of care.
Temporary website/CMS copy of healthcare data following successful transfer to the EPD
Up to 30 days.
Signing up for or unsubscribing from the Rondom app
Form data is retained for a maximum of 3 months after the registration or deregistration has been fully processed. Account data is retained for as long as the account is active and, in principle, for a maximum of 3 months thereafter, unless a different retention period applies.
Healthcare pathway, treatment group or pre-registration for care
Following successful transfer to the care record, the CMS copy is retained for a maximum of 30 days. If no care is provided: for a maximum of 12 months after the last substantive contact or the intake.
Sole order
Website/CMS content must be transferred within a maximum of 30 days following successful handover. Healthcare-related data in the medical record is subject to the retention period applicable to the medical record. Relevant financial records are, in principle, retained for 7 years.
Complaint via the website
CMS submissions must be transferred to the complaints file no later than three months after the information has been verified. In principle, we retain the individual complaints file for five years after final resolution. Retention for a longer period may be necessary in the event of an ongoing or reasonably foreseeable dispute or claim.
Webinar, activity or meeting
No later than 3 months after the end of the activity and any necessary follow-up. Financial data forming part of the accounts may be retained for 7 years.
Newsletter
A copy will be retained in the mailing system for a maximum of 30 days following successful processing. It will remain in the mailing system for as long as you remain registered. Once you have unsubscribed, your data will no longer be used for active marketing purposes. A minimum record of your unsubscription or previously given consent may be retained to the extent necessary.
Job application
Up to 4 weeks after the end of the recruitment process. With your separate consent, we may retain your data for up to 1 year for potential future vacancies.
Website feedback
A maximum of 3 months. After that, data will be deleted or effectively anonymised or aggregated.
Search feedback
In principle, 30 to 90 days and up to 3 months, unless the information is anonymised or deleted earlier.
Cookie preferences via CookieYes
Proof of your cookie preferences may be retained for up to 5 years.
Core financial administration
In principle, 7 years where the statutory tax retention obligation applies.
Personal data for scientific research
Provided this is necessary and lawful for the research in question. The specific retention period is determined on a case-by-case basis for each research project, taking into account the research objective, research protocol, applicable legislation and required safeguards. Data that has been effectively and irreversibly anonymised is no longer personal data.
Where the same information is used for different purposes, different retention periods may apply.
For example, when relevant information is entered into the EPD via a website form, the separate copy in the CMS does not need to be retained for the same period as the medical record.
Deletion and backups
When a form submission needs to be removed from the CMS, the recycle bin is also emptied so that the information is actually deleted from the active database.
Due to our technical backup procedures, deleted data may still be temporarily present in a backup.
Personal data removed from our website environment will also have been removed from the regular backup chain no later than 7 days after its final removal from the live environment.
Where personal data has also been transferred to another system, such as the EPD, Mailchimp, a complaints file or the financial records, the retention period applicable to that system is the one associated with the relevant purpose.
We take appropriate technical and organisational measures to protect personal data against:
Measures have been put in place for our website environment in areas including:
We review our security measures periodically and adapt them whenever changes in technology, services or risks give cause to do so.
Various organisations within Rondom also provide care or services to children and young people.
When we process personal data relating to minors, we take into account the additional legal requirements that apply to children, parents and legal representatives.
Exactly which rules apply depends, amongst other things, on:
Under the GDPR, you have various rights regarding your personal data.
Depending on the situation, you can ask us to:
Access
You may ask what personal data we process about you and what we use it for.
A copy
You may be entitled to a copy of the personal data we process about you and, if you are a patient, to access or obtain a copy of your medical records in accordance with the applicable rules.
Correction and addition
Is your information incorrect or incomplete? If so, you can ask us to correct or complete it.
Erasure – the right to be forgotten
In certain circumstances, you may ask us to delete your personal data. This is also known as the right to erasure or the right to be forgotten.
This right is not unlimited.
For example, we cannot always delete data when:
Destruction of your medical records
There are also specific patients’ rights relating to medical records.
You may request that we destroy your medical records or part thereof.
In principle, such a request will be complied with, unless there is a legal or other compelling reason why we are not permitted or unable to destroy the file or certain data.
Restriction of processing
In certain situations, you may ask us to temporarily restrict the use of your personal data.
Data portability
Where the legal conditions are met, you may request to receive personal data that you have provided to us in a structured and machine-readable format, or to have it transferred to another organisation.
Objection
In certain cases, you may object to the processing of your personal data.
If we use your personal data for direct marketing purposes, you may object to this at any time. We will then stop using your personal data for that purpose.
Withdraw consent
Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of any processing that took place before you withdrew your consent.
When we process personal data for scientific or statistical research, the privacy rights under the GDPR also apply in principle.
However, there are a few special rules and exceptions for research.
Objection to investigation
If existing medical data is used for scientific research without separate consent, on the basis of a statutory provision that grants you a right to object, you may lodge an objection as described above.
In addition, under the GDPR, for certain processing operations carried out for scientific or statistical research purposes, you have the right to object on grounds relating to your specific situation.
Which option applies depends on the legal basis and the type of research.
Right to erasure in the context of an investigation
The right to erasure may also apply in the context of scientific research.
However, this right may be restricted under certain conditions if the deletion of personal data threatens to make it impossible to achieve the research objective or would seriously jeopardise it, and the processing complies with the legal requirements for scientific research.
We assess this on a case-by-case basis for each request and each study.
Anonymised research data
Once research data has been effectively and irreversibly anonymised, we can no longer determine which data originally came from you.
Consequently, it is no longer possible to retrieve, correct or delete your personal data from such a fully anonymised dataset.
Would you like to exercise a data protection right, or do you have a question about the processing of your personal data?
Please contact us via: fg@rondomlopengroep.nl
Please state as clearly as possible which organisation, service or processing operation your request relates to.
To prevent us from disclosing personal data to the wrong person, we may ask you to provide additional information so that we can verify your identity.
We do not ask for any more information than is necessary.
If you have a specific objection to the reuse of medical data for medical research, you can also contact us via: wetenschap@rondomlopengroep.nl
Do you have a complaint about the way in which we process your personal data? If so, we would like to hear from you. Please contact our Data Protection Officer via: fg@rondomlopengroep.nl
You also have the right to lodge a complaint with the Dutch Data Protection Authority.
We do not use this website to make decisions that have legal consequences for you or significantly affect you in a similar way based solely on automated processing, unless we specifically inform you of this in advance and it is permitted by law.
Our organisations, services, websites, systems and suppliers may change. Legislation and regulations may also change.
We therefore review this privacy statement periodically and amend it where necessary.
You will always find the most up-to-date version on our website. At the top of this privacy notice, we state when it was last updated.