Table of Contents — Privacy Policy
- 1. Introduction and Our Role
- 2. What Data We Collect
- 3. How We Collect Your Data
- 4. Legal Basis for Processing Your Data
- 5. How We Use Your Data
- 6. Data Security: How We Protect Your Information
- 7. Data Retention: How Long We Keep Your Records
- 8. Your Data Protection Rights Under GDPR
- 9. Third-Party Services & Data Processors
- 10. International Data Transfers
- 11. Children's Privacy
- 12. Data Protection Officer & Governance
- 13. Cookies & Website Technologies
- 14. Changes to This Privacy Policy
- 15. Professional Confidentiality & Legal Compliance
- 16. How to Contact Us & Lodge a Complaint
- 17. Accountability & Documentation
- 18. Multilingual Availability & Legal Precedence
1. Introduction and Our Role
This Privacy Policy describes how your personal information is collected, used, and protected when you visit the website https://diaeta.be or use the professional healthcare services of Diaeta.
Data Controller
Under the EU General Data Protection Regulation (GDPR) and Belgian data protection law, the "Data Controller" responsible for your personal data is:
| Business Name | Diaeta |
| Legal Entity | Natural person (sole proprietorship) |
| Enterprise Number (BCE) | 0540.714.226 |
| NIHDI Number | 5-63187-92-601 |
| Data Controller | Pierre Abou-Zeid, dietitian |
| Address | Ouden Heirweg 58, 9340 Lede, Belgium |
| info@diaeta.be | |
| Phone | +32 479 35 55 51 |
| Website | https://diaeta.be |
As a licensed dietitian, I am a healthcare professional bound by professional secrecy (Article 352 of the Penal Code). I treat the personal data you share confidentially, in accordance with the GDPR and Belgian law.
2. What Data We Collect
We collect personal data necessary to provide you with safe, effective, and personalized dietetic care. The types of data we process include:
A. Identity & Contact Data
- Full name
- Date of birth
- Email address
- Phone number
- Preferred language of communication
B. Health & Clinical Data (Special Category Data)
This is sensitive health information processed specifically for your healthcare treatment:
Pre-consultation Questionnaire and Initial Consultation Information:
- Medical history and past health diagnoses (e.g., Type 2 Diabetes, Irritable Bowel Syndrome, high cholesterol)
- Current medications and supplements
- Food allergies and intolerances
- Family health history
- Lifestyle information (sleep, stress, physical activity)
- Details of your primary care physician or referring healthcare provider
Ongoing Clinical Monitoring:
- Food diaries and meal evaluations (recorded via our professional nutrition software)
- Fluid intake tracking
- Symptom journals (especially for IBS patients following low-FODMAP protocols)
- Weight measurements and body composition analysis (fat mass, muscle mass, hydration percentage) obtained via our professional clinical equipment
- Relevant blood test results provided by you (e.g., blood glucose, cholesterol levels, triglycerides)
- Progress notes and clinical observations from your dietitian
C. Financial Data
- Payment information related to consultation fees
- Billing details of business clients (name, billing address)
- Payment method (cash, Wero QR code or bank transfer)
- Insurance reimbursement documentation when requested by you
Note: We do not store credit card numbers. QR code payments are processed directly via Wero without any transaction data retention by our practice. For a bank transfer, your name, account number and payment reference appear on our bank statements, which we keep with the accounts.
D. Website Technical Data
- IP address (technical server logs)
- Browser type and operating system
- Pages visited
- Time spent on website
- Geographic location (city-level, not precise)
- Technical errors encountered while browsing
- Session replay and performance measurements, only if you consent
Vercel Analytics and Vercel Speed Insights measure the site's audience and speed. They place no cookies and store nothing on your device. Vercel counts visitors using a hash calculated from the request, which is deleted after 24 hours. Sentry records technical errors.
3. How We Collect Your Data
Personal data is collected through multiple pathways:
- Direct Communication: When you provide information during in-person or virtual consultations via Google Meet
- Website Contact Form: When you submit inquiries using the contact form at diaeta.be. Form data is sent via secure email to info@diaeta.be. We delete these emails after processing, or copy their content into our patient management software if you become a patient.
- Booking Platforms: When you schedule appointments through Doctoranytime.be or our Google Business profile. Basic information (first name, last name, phone, email, date of birth) is transmitted to our practice for appointment management.
- Online Pre-consultation Questionnaire: Before your first consultation, you receive a link to an online questionnaire (reason for consultation, medical history, medications, eating habits and lifestyle). Our professional nutrition software hosts this questionnaire on servers located in the EU. Your answers are saved directly in your patient record and follow its retention period. No third-party form tool keeps a copy.
- Patient Management App: When you actively log food, symptoms, fluid intake, or communicate with your dietitian via our secure nutrition platform
- Clinical Measurements: When body composition is measured during consultation using our professional clinical equipment
- Automatic Collection: When you visit our website (technical server logs, browser data, cookie-free audience measurement, technical error reports)
Video Consultation Policy
Virtual consultations via Google Meet are conducted in real-time and are NOT recorded. No video or audio recordings are created or stored unless you explicitly request recording for clinical documentation purposes and provide clear written consent beforehand. In such cases, recordings are treated as part of your patient record and subject to the same retention period and security measures.
4. Legal Basis for Processing Your Data
The processing of your personal data is lawful only when we have a valid legal basis under GDPR. Here's how we justify our data processing:
A. To Provide You with Healthcare Services
General Data (Identity, Contact, Financial)
- Legal Basis: GDPR Article 6(1)(b) — Performance of a Contract
- Purpose: We process your contact and financial data to schedule appointments, manage your patient file, send appointment reminders, and process payments. This is necessary to fulfill our service agreement with you.
Health Data (Clinical Information)
- Legal Basis: GDPR Article 9(2)(h) — Provision of Health Care
- Purpose: As a licensed dietitian, I am a healthcare professional legally bound by professional secrecy. The processing of your health data is necessary for the purposes of medical diagnosis and the provision of health care, under a contract with a health professional subject to professional secrecy (Articles 9(2)(h) and 9(3) GDPR). This is our primary legal basis for maintaining your clinical file.
B. To Comply with Legal Obligations
- Legal Basis: GDPR Article 6(1)(c) — Legal Obligation
- Purpose: Article 35 of the Act of 22 April 2019 on quality practice in healthcare requires the healthcare professional to keep the patient record for at least 30 years and at most 50 years from the last contact with the patient
- Purpose: Belgian tax and accounting legislation requires invoices and accounting records to be kept for 7 years (Article 315 of the Income Tax Code 1992 (CIR 92), Article 60 of the VAT Code, Articles III.86 and III.88 of the Code of Economic Law)
C. For Sharing with Your Doctor or Your Insurer
- Legal Basis: For transmission to your doctor or to another healthcare professional: your consent (Articles 19 and 36 of the Act of 22 April 2019) and Article 9(2)(h) GDPR. For transmission to your insurer: your explicit consent (Articles 6(1)(a) and 9(2)(a) GDPR)
- Purpose: With your consent, we may share clinical progress reports, treatment summaries, or relevant health information with:
- Your referring doctor or another healthcare professional you designate, to ensure coordinated care
- Your insurance company when you request documentation for reimbursement purposes (limited clinical information such as diagnosis, treatment dates, and invoice details)
We transmit this data only at your request or with your consent. You may withdraw this consent at any time.
D. For Website Analytics
- Legal Basis: GDPR Article 6(1)(f) — Legitimate Interest
- Purpose: Vercel Analytics and Vercel Speed Insights measure the site's audience and speed. These tools place no cookies and store nothing on your device. Vercel counts visitors using a hash calculated from the request, which is deleted after 24 hours. Sentry records technical errors. Our legitimate interest: improving the site, its speed and its reliability.
Analytics Tools Used:
- Vercel Analytics: audience measurement, no cookies
- Vercel Speed Insights: real-user speed measurements (Core Web Vitals), no cookies
- Sentry: technical error tracking for all visitors, error data stored in Germany (EU)
E. For Other Website-Related Processing
- Requests via the contact form: GDPR Article 6(1)(b), pre-contractual steps taken at your request
- Sentry session replay and performance measurements: GDPR Article 6(1)(a), your consent (analytics category)
- Display of the DoctorAnytime modules: GDPR Article 6(1)(a), your consent ("Third-party content" category)
- Server logs and uptime monitoring: GDPR Article 6(1)(f), our legitimate interest in the security and availability of the site
F. Whether Providing Data Is Mandatory
Keeping a patient record is a legal obligation (Articles 33 to 35 of the Act of 22 April 2019). Your identity and health data are necessary for the performance of the care contract. Without this data, we cannot provide your dietetic follow-up. Tax legislation requires the invoicing data. In the contact form, only the fields needed to reply to you are mandatory.
5. How We Use Your Data
We use your personal data for these specific, legitimate purposes:
- Healthcare Assessment & Diagnosis: To conduct a comprehensive evaluation of your nutritional status, health condition, and treatment needs
- Treatment Planning & Delivery: To create, manage, and deliver your personalized dietetic plan and nutritional therapy
- Progress Monitoring: To track your clinical progress through food diary analysis via our professional nutrition software, body composition measurements via our professional equipment, and symptom tracking
- Patient Communication: To communicate with you between appointments, provide feedback on your meals, answer your questions, and share clinical insights (primarily via our secure nutrition platform)
- Appointment Management: To manage your appointment schedule, send appointment reminders via SMS (without mentioning your name or personal data in the message, only phone number for delivery), and handle booking logistics
- Billing & Administration: To process payments by cash, Wero QR code or bank transfer, issue a certificate of care provided with its receipt, invoice business clients via Accountable.eu, manage financial records, and keep the accounts.
- Healthcare Coordination: To share relevant clinical information with your referring physician or insurance provider (only with your explicit consent or at your request)
- Legal Compliance: To keep your patient record for the period required by Belgian law (at least 30 years and at most 50 years from the last contact, Article 35 of the Act of 22 April 2019)
- Website Analytics: To measure the site's audience and speed via Vercel Analytics and Vercel Speed Insights, without cookies and without storing anything on your device, and to fix technical errors via Sentry
Data Minimization Principle: We adhere to the data minimization principle under GDPR Article 5(1)(c). We collect only the personal data that is adequate, relevant, and strictly necessary for providing your healthcare services. We do not collect excessive or unnecessary information.
6. Data Security: How We Protect Your Information
The security of your personal data, particularly your sensitive health information, is a paramount priority. We implement robust technical and organizational measures to protect your data from unauthorized access, loss, alteration, or misuse.
Security Measures
Secure Software Systems:
- Clinical data is processed in professional software dedicated to patient follow-up
- Patient management takes place exclusively through this software
- No patient data is stored on general office computers, personal laptops or unencrypted local devices
EU Data Hosting:
- Your clinical data is stored on servers located in the European Union
- Professional nutrition software (patient management, food diaries, clinical notes): hosted in the European Union by the software publisher and its cloud infrastructure providers
- Body composition analysis system: hosted in France with an HDS-certified host (Hébergeur de Données de Santé), according to the manufacturer
- Google Cloud Platform (Backups & Long-Term Archives): patient records archived and backed up on Google Cloud servers in Belgium (one region). These backups serve the legal retention of patient records (at least 30 years and at most 50 years from the last contact).
Backup & Archiving Infrastructure:
Our backup system ensures continuity of care and legal compliance:
- Purpose: Long-term retention of patient records (legal obligation: at least 30 years and at most 50 years) and security backup for service continuity
- Infrastructure: Google Cloud Platform (GCP), encrypted storage buckets with restricted access
- Location: Google Cloud servers in Belgium, one region (data remains in the EU)
- Encryption: Data encrypted at rest and in transit via Google Cloud security protocols
- Access Control: Access strictly limited to the Data Controller (Pierre Abou-Zeid)
Access Control:
- Access to your identifiable patient file is strictly limited to Pierre Abou-Zeid (the treating dietitian)
- Future staff members (if applicable) will only access patient files necessary for patient care and will be bound by professional confidentiality obligations
Encryption:
- All patient data transmitted between devices and servers is encrypted in transit using industry-standard TLS/SSL encryption
- Data at rest on servers (nutrition software, body composition analysis system, GCP) is encrypted
- Communication via our nutrition platform is encrypted in transit
Physical Security:
- Paper records (if any) are stored in locked filing cabinets in secure office spaces
- Access to consultation rooms is controlled and limited to authorized personnel
- All consultation practices implement appropriate physical security measures
- Documents are disposed of securely through cross-cut shredding when permitted by retention requirements
Incident Response & Data Breach Notification:
- Despite preventive measures, if a data security incident is suspected, we will investigate immediately to determine scope and impact
- Your Right to Notification (GDPR Article 34): In the unlikely event of a confirmed personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. The notification will describe the nature of the breach, likely consequences, and measures taken or proposed to address it.
- Supervisory Authority Notification (GDPR Article 33): We will notify the Belgian Data Protection Authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to your rights and freedoms.
- Identity Verification: For your protection, when you exercise your data subject rights (such as requesting access to your data), we may need to verify your identity through secure means (e.g., matching your request details against information we hold, or requesting a copy of identification document). This prevents unauthorized access to your personal data.
Regular Security Review:
- Our main infrastructure providers (Google, Vercel, Sentry) publish ISO 27001 certifications and SOC 2 reports
- We maintain up-to-date vendor security assessments
7. Data Retention: How Long We Keep Your Records
We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, or to comply with legal and regulatory requirements.
Retention Periods
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Medical & Clinical Records | At least 30 years and at most 50 years from the last contact with the patient | Article 35 of the Act of 22 April 2019 on quality practice in healthcare |
| Pre-consultation Questionnaire Answers | Same period as patient records (the answers are part of the record) | Article 35 of the Act of 22 April 2019 |
| GCP Backups (Medical Archives) | Same period as patient records | Article 35 of the Act of 22 April 2019 |
| Financial Documents & Invoices | 7 years | Belgian tax and accounting legislation (Article 315 of the Income Tax Code 1992 (CIR 92), Article 60 of the VAT Code, Articles III.86 and III.88 of the Code of Economic Law) |
| Contact Requests (Non-Patients) | Deletion after processing | Art. 5(1)(e) GDPR (storage limitation) |
| Website Analytics Data | Vercel: 12 months (guaranteed window, the provider may keep data longer). Sentry: 30 days | Art. 5(1)(e) GDPR |
| Cookie Consents | 180 days (then new consent requested) | Art. 10/2 of the Act of 30 July 2018 |
| GDPR Consent Records | 5 years after the end of the processing | Art. 5(2) and 7(1) GDPR |
Secure Deletion
When data is no longer needed and legal retention periods have expired, we securely delete or anonymize your personal data in such a way that it can no longer be recovered or reconstructed.
Special Note on Patient Records: Article 35 of the Act of 22 April 2019 requires the patient record to be kept for at least 30 years and at most 50 years from the last contact. We therefore cannot delete your clinical data before this legal period ends, even if you request deletion. You retain other rights, such as data portability and rectification. If the practice ceases its activity, your record is transferred, with your agreement, to another healthcare professional (Article 20 of the Act of 22 April 2019).
8. Your Data Protection Rights Under GDPR
Under GDPR, you have comprehensive rights concerning your personal data. You can exercise these rights at any time by contacting us.
Your Rights
1. Right of Access (Article 15)
You have the right to request a copy of all personal data we hold about you. This includes:
- Confirmation that we process your data
- Access to your personal data
- Information on how we use your data
Response Timeline: 1 month (may be extended by 2 months depending on the complexity and number of requests). For consulting or obtaining a copy of your patient record, we respond within 15 days (Article 9 of the Act of 22 August 2002 on patient rights). The first copy is free of charge.
2. Right to Rectification (Article 16)
You have the right to correct inaccurate or incomplete personal data.
Example: If your email address, phone number, or medical information has changed, you can request an update.
3. Right to Erasure / "Right to be Forgotten" (Article 17)
You can request the deletion of your personal data in certain circumstances:
- The data is no longer necessary
- You withdraw your consent (where consent was the legal basis)
- You object to the processing and there are no overriding legitimate grounds
- The data was processed unlawfully
IMPORTANT LIMITATION: This right does NOT apply to patient records that we are legally required to keep for at least 30 years and at most 50 years (Article 35 of the Act of 22 April 2019, Article 17(3)(b) GDPR). However, we can restrict access to your data if you no longer wish to receive services.
4. Right to Restriction of Processing (Article 18)
You can ask us to temporarily "freeze" the processing of your data in certain situations:
- You contest the accuracy of the data (while we verify it)
- The processing is unlawful but you do not want the data erased
- We no longer need the data but you need it for legal claims
- You have objected to the processing (pending verification)
5. Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
Applies to: Data you have provided on the basis of consent or a contract, and that is processed by automated means.
Format: We will provide the data in PDF or CSV format, as appropriate.
6. Right to Object (Article 21)
You have the right to object to the processing of your personal data in certain circumstances:
- Processing based on legitimate interest
- Direct marketing (you can unsubscribe at any time)
- Profiling for marketing purposes
LIMITATION: You cannot object to processing that is necessary to provide healthcare services or to comply with legal obligations.
7. Rights Related to Automated Decision-Making and Profiling (Article 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
Current Status: We do not currently use any automated decision-making or profiling in our practice. All clinical decisions are made by your dietitian.
8. Right to Withdraw Consent (Article 7(3))
Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Applies to:
- Session replay and performance measurements (analytics category)
- Display of the DoctorAnytime modules ("Third-party content" category)
- Marketing communications (currently not used)
- Sharing data with your doctor or your insurer
How to Exercise Your Rights
To exercise any of these rights, please contact us:
- Email: info@diaeta.be
- Phone: +32 479 35 55 51
- Mail: Ouden Heirweg 58, 9340 Lede, Belgium
We will respond to your request within 1 month. Depending on the complexity and number of requests, we may extend this period by 2 months. We will inform you of this, with the reasons, within one month of your request.
Patient record: For consulting or obtaining a copy of your patient record, we respond no later than 15 days after receiving your request (Article 9 of the Act of 22 August 2002 on patient rights). This period cannot be extended. The first copy is free of charge. For an additional copy, we may charge an administrative fee that is reasonable, justified and limited to the actual cost.
No fee is charged for exercising your other rights. However, we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive, in particular because of its repetitive character (Article 12(5) GDPR).
9. Third-Party Services & Data Processors
We use two types of service providers. Processors process personal data on our behalf and according to our instructions. The other recipients receive data and process it under their own responsibility, as separate controllers.
Data Processors
| Service | Provider | Purpose | Data Location | Role and Safeguards |
|---|---|---|---|---|
| Patient Management & Food Diaries | Professional nutrition software | Patient records, food diaries, patient-dietitian communication | European Union | Processor (Article 28 GDPR) |
| Body Composition Analysis | Body composition analysis system | Body composition measurements, weight tracking | France (EU), HDS-certified host (Hébergeur de Données de Santé) according to the manufacturer | Processor (Article 28 GDPR) |
| Patient Record Backups & Archives | Google Cloud Platform (GCP) | Backup and archiving of patient records (at least 30 years and at most 50 years) | Belgium (EU), Google Cloud servers, one region | Processor (Article 28 GDPR) |
| Video Consultations | Google Meet | Real-time virtual consultations (not recorded) | Google data centers (EU and non-EU, including the United States) | Processor; EU-U.S. Data Privacy Framework, Standard Contractual Clauses |
| Google Workspace | Receiving contact form requests, email exchanges with patients | Google data centers (EU and non-EU, including the United States) | Processor; EU-U.S. Data Privacy Framework, Standard Contractual Clauses | |
| Website Hosting | Vercel | Hosting of the website diaeta.be, technical server logs | Server functions in Frankfurt (EU); global delivery network; United States | Processor; EU-U.S. Data Privacy Framework |
| Audience and Speed Measurement | Vercel Analytics & Speed Insights | Measurement of the site's audience and speed (Core Web Vitals), without cookies | EU/United States | Processor; EU-U.S. Data Privacy Framework |
| Error Tracking | Sentry | Detection and correction of technical errors on the website. Session replay and performance measurements only with your consent | Germany (EU) for error data; United States for account data and exchanges with support | Processor; EU-U.S. Data Privacy Framework |
| Infrastructure Monitoring | UptimeRobot s.r.o. (Slovakia) | Monitoring of website availability (response time, HTTP status). No patient data | European Union; some servers of its own sub-processors in the United States | Processor; Standard Contractual Clauses |
Recipients Acting as Separate Controllers
| Service | Recipient | Purpose | Data Location | Role |
|---|---|---|---|---|
| Appointment Bookings | Doctoranytime (Doctor Anytime Belgium SRL, Auderghem) | Appointment booking, transmission of contact data to the practice | Belgium; according to its privacy policy, some data may be transferred to the United States | Separate controller. Its privacy policy applies |
| Business Profile | Google Business Profile | Information about the practice, reviews and requests received via the profile | Google data centers (EU and non-EU) | Separate controller. Google's privacy policy applies |
| QR Code Payment | Wero | QR code payments executed by your bank and ours. Our practice does not keep the transaction data | Belgium/EU | Separate controller (payment scheme) |
| Invoicing & Tax Management | Accountable.eu | Invoices to business clients (name, address, amounts), tax compliance | European Union | Separate controller (invoicing software) |
Data Protection Guarantees
For our processors:
- Data Processing Agreements: We conclude a data processing agreement compliant with Article 28 GDPR with each processor
- Security Measures: Processors must implement appropriate technical and organizational measures
- Confidentiality: Processor staff are bound by confidentiality obligations
- Breach Notification: Processors must notify us of any data breach without delay
The booking platform, the Google Business Profile, the payment scheme and the invoicing software act as separate controllers. Article 28 GDPR does not apply to them. They process your data according to their own privacy policies.
No Unauthorized Third-Party Sharing
We never sell, rent, or share your personal data with third parties for marketing or commercial purposes. Your health data is shared only:
- With our processors, for the delivery of our services
- With your doctor or another healthcare professional you designate (with your consent)
- With your insurance company (at your request and with your explicit consent)
- When required by law
Emergency Data Sharing
Emergency Situations: If your life or health is in immediate danger and you are physically or legally incapable of giving your consent, we may disclose the necessary health information to the emergency services (Article 9(2)(c) GDPR; Article 39 of the Act of 22 April 2019).
10. International Data Transfers
Your clinical record stays hosted in the European Union. Some technical tools involve data transfers outside the European Economic Area (EEA). This section describes them.
Current Status of Data Transfers
Services hosted in the EU:
- ✅ Professional nutrition software: hosted in the European Union
- ✅ Body composition analysis system: hosted in France with an HDS-certified host, according to the manufacturer
- ✅ Google Cloud Platform (backups and archives): Google Cloud servers in Belgium (one region)
- ✅ Accountable: European Union
- ✅ Wero: Belgium/EU
Services with Potential Non-EU Transfers
Some services involve limited data transfers outside the EU:
Google Services (Google Workspace, Google Meet, Google Business Profile)
- Location: Google data centers in the EU and outside the EU
- Potential Transfers: Google may process data in the United States
- Data Concerned: Meeting metadata, emails exchanged with the practice, reviews and requests received via the Business Profile
- Safeguards:
- Google adheres to the EU-U.S. Data Privacy Framework
- Google's data processing terms contain the European Commission's Standard Contractual Clauses
- Business Profile: For Google Business Profile, Google acts as a separate controller
Hosting, Audience Measurement, Monitoring and Booking
- Sentry: Error data stored in Germany (EU). Sentry is a U.S. company: account data and exchanges with its support may be processed in the United States. Sentry adheres to the EU-U.S. Data Privacy Framework
- Vercel (hosting and audience measurement): The site's server functions run in the Frankfurt (EU) region. Vercel's delivery network receives requests at the point of presence closest to the visitor. Vercel is a U.S. company: technical logs (IP address, pages requested) and audience measurement data may be transferred to the United States. Vercel adheres to the EU-U.S. Data Privacy Framework
- UptimeRobot: Slovak company (UptimeRobot s.r.o., Bratislava). Main processing in the EU. Some servers of its own sub-processors are located in the United States. These transfers rely on the European Commission's Standard Contractual Clauses
- Doctoranytime: Belgian company (Doctor Anytime Belgium SRL, Auderghem), separate controller for appointment booking. According to its privacy policy, some data may be transferred to the United States under Standard Contractual Clauses or the EU-U.S. Data Privacy Framework
Important: Your clinical record (nutrition software, body composition analysis, archives) stays hosted in the EU. Vercel and UptimeRobot process only technical data.
Safeguards for Non-EU Transfers
Data transfers outside the EU rely on the following safeguards:
- Transfers to the United States rely on the European Commission's adequacy decision of 10 July 2023 (Implementing Decision (EU) 2023/1795, EU-U.S. Data Privacy Framework) for certified companies. Google, Vercel and Sentry adhere to this framework
- Failing that, transfers rely on the European Commission's Standard Contractual Clauses
- You can obtain a copy of these safeguards by writing to info@diaeta.be
11. Children's Privacy
Our consultations are in principle intended for adults. When we see a patient who is a minor, their parents or guardian exercise their patient rights. We involve the minor in decisions according to their age and maturity. A minor who is able to reasonably assess their interests exercises their rights themselves (Article 12 of the Act of 22 August 2002 on patient rights).
For online services, a child can consent alone to the processing of their data from the age of 13 in Belgium (Article 7 of the Act of 30 July 2018). Below that age, the consent of their legal representative is required.
If you believe we hold data of a minor without the required agreement, write to us at info@diaeta.be.
12. Data Protection Officer & Governance
We have assessed the obligation to appoint a Data Protection Officer (DPO) under Article 37 GDPR. As a dietitian practising individually, we do not process health data on a large scale within the meaning of Article 37(1)(c) GDPR (recital 91; guidelines WP 243 of the Article 29 Working Party). Appointing a DPO is therefore not mandatory. We will reassess this conclusion if the scope of our processing changes.
13. Cookies & Website Technologies
Cookie Consent
Diaeta.be sets no first-party cookies. The site uses your browser's local storage, a technology similar to cookies. Our Cookie Policy gives the details.
1. Strictly Necessary Storage
Stores your consent choice and the settings you switch on yourself (reading-mode theme and text size, saved articles). These items are exempt from consent (Article 10/2 of the Act of 30 July 2018).
2. Cookieless Audience Measurement and Error Tracking
Vercel Analytics and Vercel Speed Insights measure the site's audience and speed. They place no cookies and store nothing on your device. Vercel counts visitors using a hash calculated from the request, which is deleted after 24 hours. Sentry records technical errors for all visitors. Legal basis: our legitimate interest (Article 6(1)(f) GDPR).
3. Analytics Subject to Consent
If you accept the analytics category, Sentry records session replays, with text masked and media blocked, as well as performance measurements (tracing). Without your agreement, these two functions stay switched off. You can withdraw this consent at any time in the cookie settings.
4. Third-Party Content
The DoctorAnytime modules (rating in the footer, booking calendar) load only after you accept the "Third-party content" category in the consent window, or when you click to display the module in its place. DoctorAnytime then sets the cookie DA.ABTests (domain doctoranytime.be, duration 1 year). We use no marketing or tracking cookies.
Managing Your Cookie Preferences
When you first visit our website, a consent window appears. You can change your preferences at any time through the "Cookie settings" link in the footer, or by contacting us.
14. Changes to This Privacy Policy
We may update this privacy policy from time to time to reflect changes in our data practices, new technologies, legal requirements, or regulatory guidance. Any material changes will be posted on this page with an updated "Last Updated" date.
If changes significantly affect your rights or our data processing practices, we will notify you by email if you are a patient.
Annual Review Commitment: We conduct an annual review of this privacy policy to ensure continued compliance with evolving data protection standards and legal requirements.
15. Professional Confidentiality & Legal Compliance
As a licensed healthcare professional in Belgium, I am bound by:
- Professional Secrecy: Article 352 of the Penal Code prohibits me from revealing what you confide to me, unless I testify in court or before a parliamentary commission of inquiry, or the law obliges or authorises me to do so
- GDPR and Act of 30 July 2018: I process your personal data in accordance with these two texts
- Act of 22 August 2002 on patient rights, as amended by the Act of 6 February 2024: It protects your rights to quality services, to information, to consent and to access to your patient record
- Act of 22 April 2019 on quality practice in healthcare: It requires me to keep and retain your record (Articles 33 to 35) and makes the sharing of your data with another healthcare professional subject to your consent (Articles 19 and 36)
16. How to Contact Us & Lodge a Complaint
Data Protection Rights Requests
For any questions, concerns, or to exercise your data protection rights, please contact:
Pierre Abou-Zeid
Email: info@diaeta.be
Phone: +32 479 35 55 51
Address: Ouden Heirweg 58, 9340 Lede, Belgium
Preferred Contact: Email (please include "Data Protection Request" in the subject line)
Response Timeline: We will acknowledge your request within 5 business days and respond to it within one month. Depending on the complexity and number of requests, we may extend this period by two months. We will inform you of this, with the reasons, within one month of your request. Requests to consult or obtain a copy of the patient record receive a response within 15 days.
Lodge a Complaint with the Data Protection Authority
If you believe we have not handled your personal data in accordance with GDPR or Belgian data protection law, you have the right to lodge a complaint with the Belgian Data Protection Authority:
Autorité de protection des données / Gegevensbeschermingsautoriteit
Website: autoriteprotectiondonnees.be
Address: Rue de la Presse 35, 1000 Brussels, Belgium
Phone: +32 (0)2 274 48 00
Email: contact@apd-gba.be
17. Accountability & Documentation
We maintain comprehensive documentation of our data protection practices, including:
- Record of processing activities (Article 30 GDPR) documenting all data processing operations
- Data processing agreements with our processors
- Records of data security assessments and incident response procedures
- Consent records for website visitors
- Regular compliance reviews and updates
This documentation is maintained for supervisory authority review if requested.
Data Protection Impact Assessment (DPIA)
Article 35 GDPR requires a data protection impact assessment (DPIA) when processing is likely to result in a high risk, in particular in the case of large-scale processing of health data. According to recital 91 GDPR, the processing of patient data by a health professional practising individually is not large-scale processing. Our processing operations also do not appear on the list of the Data Protection Authority (decision no. 01/2019). A DPIA is therefore not mandatory. We nevertheless assess the risks of our processing and apply safeguards: hosting of body composition measurements with an HDS-certified host according to the manufacturer, encryption, access controls and regular security reviews.
18. Multilingual Availability & Legal Precedence
The French version of this privacy policy prevails. Translations in English, Dutch and German are published on this site.
Legal Precedence: In case of any discrepancy or conflict between language versions, the French version shall take legal precedence and be considered the authoritative version for interpretation and enforcement purposes.
All language versions are maintained with the same "Last Updated" date to ensure consistency across translations. For any question about this policy, please contact info@diaeta.be.
Your privacy and the confidentiality of your health information are fundamental to our practice.
END OF PRIVACY POLICY