Skip to main content
Diaeta

Privacy Policy

Last Updated: 6 October 2026

1. Introduction and Our Role

This Privacy Policy describes how your personal information is collected, used, and protected when you visit the website https://diaeta.be or use the professional healthcare services of Diaeta.

Data Controller

Under the EU General Data Protection Regulation (GDPR) and Belgian data protection law, the "Data Controller" responsible for your personal data is:

Business NameDiaeta
Legal EntityNatural person (sole proprietorship)
Enterprise Number (BCE)0540.714.226
NIHDI Number5-63187-92-601
Data ControllerPierre Abou-Zeid, dietitian
AddressOuden Heirweg 58, 9340 Lede, Belgium
Emailinfo@diaeta.be
Phone+32 479 35 55 51
Websitehttps://diaeta.be

As a licensed dietitian, I am a healthcare professional bound by professional secrecy (Article 352 of the Penal Code). I treat the personal data you share confidentially, in accordance with the GDPR and Belgian law.

2. What Data We Collect

We collect personal data necessary to provide you with safe, effective, and personalized dietetic care. The types of data we process include:

A. Identity & Contact Data

  • Full name
  • Date of birth
  • Email address
  • Phone number
  • Preferred language of communication

B. Health & Clinical Data (Special Category Data)

This is sensitive health information processed specifically for your healthcare treatment:

Pre-consultation Questionnaire and Initial Consultation Information:

  • Medical history and past health diagnoses (e.g., Type 2 Diabetes, Irritable Bowel Syndrome, high cholesterol)
  • Current medications and supplements
  • Food allergies and intolerances
  • Family health history
  • Lifestyle information (sleep, stress, physical activity)
  • Details of your primary care physician or referring healthcare provider

Ongoing Clinical Monitoring:

  • Food diaries and meal evaluations (recorded via our professional nutrition software)
  • Fluid intake tracking
  • Symptom journals (especially for IBS patients following low-FODMAP protocols)
  • Weight measurements and body composition analysis (fat mass, muscle mass, hydration percentage) obtained via our professional clinical equipment
  • Relevant blood test results provided by you (e.g., blood glucose, cholesterol levels, triglycerides)
  • Progress notes and clinical observations from your dietitian

C. Financial Data

  • Payment information related to consultation fees
  • Billing details of business clients (name, billing address)
  • Payment method (cash, Wero QR code or bank transfer)
  • Insurance reimbursement documentation when requested by you

Note: We do not store credit card numbers. QR code payments are processed directly via Wero without any transaction data retention by our practice. For a bank transfer, your name, account number and payment reference appear on our bank statements, which we keep with the accounts.

D. Website Technical Data

  • IP address (technical server logs)
  • Browser type and operating system
  • Pages visited
  • Time spent on website
  • Geographic location (city-level, not precise)
  • Technical errors encountered while browsing
  • Session replay and performance measurements, only if you consent

Vercel Analytics and Vercel Speed Insights measure the site's audience and speed. They place no cookies and store nothing on your device. Vercel counts visitors using a hash calculated from the request, which is deleted after 24 hours. Sentry records technical errors.

3. How We Collect Your Data

Personal data is collected through multiple pathways:

  • Direct Communication: When you provide information during in-person or virtual consultations via Google Meet
  • Website Contact Form: When you submit inquiries using the contact form at diaeta.be. Form data is sent via secure email to info@diaeta.be. We delete these emails after processing, or copy their content into our patient management software if you become a patient.
  • Booking Platforms: When you schedule appointments through Doctoranytime.be or our Google Business profile. Basic information (first name, last name, phone, email, date of birth) is transmitted to our practice for appointment management.
  • Online Pre-consultation Questionnaire: Before your first consultation, you receive a link to an online questionnaire (reason for consultation, medical history, medications, eating habits and lifestyle). Our professional nutrition software hosts this questionnaire on servers located in the EU. Your answers are saved directly in your patient record and follow its retention period. No third-party form tool keeps a copy.
  • Patient Management App: When you actively log food, symptoms, fluid intake, or communicate with your dietitian via our secure nutrition platform
  • Clinical Measurements: When body composition is measured during consultation using our professional clinical equipment
  • Automatic Collection: When you visit our website (technical server logs, browser data, cookie-free audience measurement, technical error reports)

Video Consultation Policy

Virtual consultations via Google Meet are conducted in real-time and are NOT recorded. No video or audio recordings are created or stored unless you explicitly request recording for clinical documentation purposes and provide clear written consent beforehand. In such cases, recordings are treated as part of your patient record and subject to the same retention period and security measures.

4. Legal Basis for Processing Your Data

The processing of your personal data is lawful only when we have a valid legal basis under GDPR. Here's how we justify our data processing:

A. To Provide You with Healthcare Services

General Data (Identity, Contact, Financial)

  • Legal Basis: GDPR Article 6(1)(b) — Performance of a Contract
  • Purpose: We process your contact and financial data to schedule appointments, manage your patient file, send appointment reminders, and process payments. This is necessary to fulfill our service agreement with you.

Health Data (Clinical Information)

  • Legal Basis: GDPR Article 9(2)(h) — Provision of Health Care
  • Purpose: As a licensed dietitian, I am a healthcare professional legally bound by professional secrecy. The processing of your health data is necessary for the purposes of medical diagnosis and the provision of health care, under a contract with a health professional subject to professional secrecy (Articles 9(2)(h) and 9(3) GDPR). This is our primary legal basis for maintaining your clinical file.

B. To Comply with Legal Obligations

  • Legal Basis: GDPR Article 6(1)(c) — Legal Obligation
  • Purpose: Article 35 of the Act of 22 April 2019 on quality practice in healthcare requires the healthcare professional to keep the patient record for at least 30 years and at most 50 years from the last contact with the patient
  • Purpose: Belgian tax and accounting legislation requires invoices and accounting records to be kept for 7 years (Article 315 of the Income Tax Code 1992 (CIR 92), Article 60 of the VAT Code, Articles III.86 and III.88 of the Code of Economic Law)

C. For Sharing with Your Doctor or Your Insurer

  • Legal Basis: For transmission to your doctor or to another healthcare professional: your consent (Articles 19 and 36 of the Act of 22 April 2019) and Article 9(2)(h) GDPR. For transmission to your insurer: your explicit consent (Articles 6(1)(a) and 9(2)(a) GDPR)
  • Purpose: With your consent, we may share clinical progress reports, treatment summaries, or relevant health information with:
    • Your referring doctor or another healthcare professional you designate, to ensure coordinated care
    • Your insurance company when you request documentation for reimbursement purposes (limited clinical information such as diagnosis, treatment dates, and invoice details)

We transmit this data only at your request or with your consent. You may withdraw this consent at any time.

D. For Website Analytics

  • Legal Basis: GDPR Article 6(1)(f) — Legitimate Interest
  • Purpose: Vercel Analytics and Vercel Speed Insights measure the site's audience and speed. These tools place no cookies and store nothing on your device. Vercel counts visitors using a hash calculated from the request, which is deleted after 24 hours. Sentry records technical errors. Our legitimate interest: improving the site, its speed and its reliability.

Analytics Tools Used:

  • Vercel Analytics: audience measurement, no cookies
  • Vercel Speed Insights: real-user speed measurements (Core Web Vitals), no cookies
  • Sentry: technical error tracking for all visitors, error data stored in Germany (EU)

E. For Other Website-Related Processing

  • Requests via the contact form: GDPR Article 6(1)(b), pre-contractual steps taken at your request
  • Sentry session replay and performance measurements: GDPR Article 6(1)(a), your consent (analytics category)
  • Display of the DoctorAnytime modules: GDPR Article 6(1)(a), your consent ("Third-party content" category)
  • Server logs and uptime monitoring: GDPR Article 6(1)(f), our legitimate interest in the security and availability of the site

F. Whether Providing Data Is Mandatory

Keeping a patient record is a legal obligation (Articles 33 to 35 of the Act of 22 April 2019). Your identity and health data are necessary for the performance of the care contract. Without this data, we cannot provide your dietetic follow-up. Tax legislation requires the invoicing data. In the contact form, only the fields needed to reply to you are mandatory.

5. How We Use Your Data

We use your personal data for these specific, legitimate purposes:

  1. Healthcare Assessment & Diagnosis: To conduct a comprehensive evaluation of your nutritional status, health condition, and treatment needs
  2. Treatment Planning & Delivery: To create, manage, and deliver your personalized dietetic plan and nutritional therapy
  3. Progress Monitoring: To track your clinical progress through food diary analysis via our professional nutrition software, body composition measurements via our professional equipment, and symptom tracking
  4. Patient Communication: To communicate with you between appointments, provide feedback on your meals, answer your questions, and share clinical insights (primarily via our secure nutrition platform)
  5. Appointment Management: To manage your appointment schedule, send appointment reminders via SMS (without mentioning your name or personal data in the message, only phone number for delivery), and handle booking logistics
  6. Billing & Administration: To process payments by cash, Wero QR code or bank transfer, issue a certificate of care provided with its receipt, invoice business clients via Accountable.eu, manage financial records, and keep the accounts.
  7. Healthcare Coordination: To share relevant clinical information with your referring physician or insurance provider (only with your explicit consent or at your request)
  8. Legal Compliance: To keep your patient record for the period required by Belgian law (at least 30 years and at most 50 years from the last contact, Article 35 of the Act of 22 April 2019)
  9. Website Analytics: To measure the site's audience and speed via Vercel Analytics and Vercel Speed Insights, without cookies and without storing anything on your device, and to fix technical errors via Sentry

Data Minimization Principle: We adhere to the data minimization principle under GDPR Article 5(1)(c). We collect only the personal data that is adequate, relevant, and strictly necessary for providing your healthcare services. We do not collect excessive or unnecessary information.

6. Data Security: How We Protect Your Information

The security of your personal data, particularly your sensitive health information, is a paramount priority. We implement robust technical and organizational measures to protect your data from unauthorized access, loss, alteration, or misuse.

Security Measures

Secure Software Systems:

  • Clinical data is processed in professional software dedicated to patient follow-up
  • Patient management takes place exclusively through this software
  • No patient data is stored on general office computers, personal laptops or unencrypted local devices

EU Data Hosting:

  • Your clinical data is stored on servers located in the European Union
  • Professional nutrition software (patient management, food diaries, clinical notes): hosted in the European Union by the software publisher and its cloud infrastructure providers
  • Body composition analysis system: hosted in France with an HDS-certified host (Hébergeur de Données de Santé), according to the manufacturer
  • Google Cloud Platform (Backups & Long-Term Archives): patient records archived and backed up on Google Cloud servers in Belgium (one region). These backups serve the legal retention of patient records (at least 30 years and at most 50 years from the last contact).

Backup & Archiving Infrastructure:

Our backup system ensures continuity of care and legal compliance:

  • Purpose: Long-term retention of patient records (legal obligation: at least 30 years and at most 50 years) and security backup for service continuity
  • Infrastructure: Google Cloud Platform (GCP), encrypted storage buckets with restricted access
  • Location: Google Cloud servers in Belgium, one region (data remains in the EU)
  • Encryption: Data encrypted at rest and in transit via Google Cloud security protocols
  • Access Control: Access strictly limited to the Data Controller (Pierre Abou-Zeid)

Access Control:

  • Access to your identifiable patient file is strictly limited to Pierre Abou-Zeid (the treating dietitian)
  • Future staff members (if applicable) will only access patient files necessary for patient care and will be bound by professional confidentiality obligations

Encryption:

  • All patient data transmitted between devices and servers is encrypted in transit using industry-standard TLS/SSL encryption
  • Data at rest on servers (nutrition software, body composition analysis system, GCP) is encrypted
  • Communication via our nutrition platform is encrypted in transit

Physical Security:

  • Paper records (if any) are stored in locked filing cabinets in secure office spaces
  • Access to consultation rooms is controlled and limited to authorized personnel
  • All consultation practices implement appropriate physical security measures
  • Documents are disposed of securely through cross-cut shredding when permitted by retention requirements

Incident Response & Data Breach Notification:

  • Despite preventive measures, if a data security incident is suspected, we will investigate immediately to determine scope and impact
  • Your Right to Notification (GDPR Article 34): In the unlikely event of a confirmed personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay. The notification will describe the nature of the breach, likely consequences, and measures taken or proposed to address it.
  • Supervisory Authority Notification (GDPR Article 33): We will notify the Belgian Data Protection Authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to your rights and freedoms.
  • Identity Verification: For your protection, when you exercise your data subject rights (such as requesting access to your data), we may need to verify your identity through secure means (e.g., matching your request details against information we hold, or requesting a copy of identification document). This prevents unauthorized access to your personal data.

Regular Security Review:

  • Our main infrastructure providers (Google, Vercel, Sentry) publish ISO 27001 certifications and SOC 2 reports
  • We maintain up-to-date vendor security assessments

7. Data Retention: How Long We Keep Your Records

We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, or to comply with legal and regulatory requirements.

Retention Periods

Data TypeRetention PeriodLegal Basis
Medical & Clinical RecordsAt least 30 years and at most 50 years from the last contact with the patientArticle 35 of the Act of 22 April 2019 on quality practice in healthcare
Pre-consultation Questionnaire AnswersSame period as patient records (the answers are part of the record)Article 35 of the Act of 22 April 2019
GCP Backups (Medical Archives)Same period as patient recordsArticle 35 of the Act of 22 April 2019
Financial Documents & Invoices7 yearsBelgian tax and accounting legislation (Article 315 of the Income Tax Code 1992 (CIR 92), Article 60 of the VAT Code, Articles III.86 and III.88 of the Code of Economic Law)
Contact Requests (Non-Patients)Deletion after processingArt. 5(1)(e) GDPR (storage limitation)
Website Analytics DataVercel: 12 months (guaranteed window, the provider may keep data longer). Sentry: 30 daysArt. 5(1)(e) GDPR
Cookie Consents180 days (then new consent requested)Art. 10/2 of the Act of 30 July 2018
GDPR Consent Records5 years after the end of the processingArt. 5(2) and 7(1) GDPR

Secure Deletion

When data is no longer needed and legal retention periods have expired, we securely delete or anonymize your personal data in such a way that it can no longer be recovered or reconstructed.

Special Note on Patient Records: Article 35 of the Act of 22 April 2019 requires the patient record to be kept for at least 30 years and at most 50 years from the last contact. We therefore cannot delete your clinical data before this legal period ends, even if you request deletion. You retain other rights, such as data portability and rectification. If the practice ceases its activity, your record is transferred, with your agreement, to another healthcare professional (Article 20 of the Act of 22 April 2019).

8. Your Data Protection Rights Under GDPR

Under GDPR, you have comprehensive rights concerning your personal data. You can exercise these rights at any time by contacting us.

Your Rights

1. Right of Access (Article 15)

You have the right to request a copy of all personal data we hold about you. This includes:

  • Confirmation that we process your data
  • Access to your personal data
  • Information on how we use your data

Response Timeline: 1 month (may be extended by 2 months depending on the complexity and number of requests). For consulting or obtaining a copy of your patient record, we respond within 15 days (Article 9 of the Act of 22 August 2002 on patient rights). The first copy is free of charge.

2. Right to Rectification (Article 16)

You have the right to correct inaccurate or incomplete personal data.

Example: If your email address, phone number, or medical information has changed, you can request an update.

3. Right to Erasure / "Right to be Forgotten" (Article 17)

You can request the deletion of your personal data in certain circumstances:

  • The data is no longer necessary
  • You withdraw your consent (where consent was the legal basis)
  • You object to the processing and there are no overriding legitimate grounds
  • The data was processed unlawfully

IMPORTANT LIMITATION: This right does NOT apply to patient records that we are legally required to keep for at least 30 years and at most 50 years (Article 35 of the Act of 22 April 2019, Article 17(3)(b) GDPR). However, we can restrict access to your data if you no longer wish to receive services.

4. Right to Restriction of Processing (Article 18)

You can ask us to temporarily "freeze" the processing of your data in certain situations:

  • You contest the accuracy of the data (while we verify it)
  • The processing is unlawful but you do not want the data erased
  • We no longer need the data but you need it for legal claims
  • You have objected to the processing (pending verification)

5. Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.

Applies to: Data you have provided on the basis of consent or a contract, and that is processed by automated means.

Format: We will provide the data in PDF or CSV format, as appropriate.

6. Right to Object (Article 21)

You have the right to object to the processing of your personal data in certain circumstances:

  • Processing based on legitimate interest
  • Direct marketing (you can unsubscribe at any time)
  • Profiling for marketing purposes

LIMITATION: You cannot object to processing that is necessary to provide healthcare services or to comply with legal obligations.

7. Rights Related to Automated Decision-Making and Profiling (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

Current Status: We do not currently use any automated decision-making or profiling in our practice. All clinical decisions are made by your dietitian.

8. Right to Withdraw Consent (Article 7(3))

Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Applies to:

  • Session replay and performance measurements (analytics category)
  • Display of the DoctorAnytime modules ("Third-party content" category)
  • Marketing communications (currently not used)
  • Sharing data with your doctor or your insurer

How to Exercise Your Rights

To exercise any of these rights, please contact us:

  • Email: info@diaeta.be
  • Phone: +32 479 35 55 51
  • Mail: Ouden Heirweg 58, 9340 Lede, Belgium

We will respond to your request within 1 month. Depending on the complexity and number of requests, we may extend this period by 2 months. We will inform you of this, with the reasons, within one month of your request.

Patient record: For consulting or obtaining a copy of your patient record, we respond no later than 15 days after receiving your request (Article 9 of the Act of 22 August 2002 on patient rights). This period cannot be extended. The first copy is free of charge. For an additional copy, we may charge an administrative fee that is reasonable, justified and limited to the actual cost.

No fee is charged for exercising your other rights. However, we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive, in particular because of its repetitive character (Article 12(5) GDPR).

9. Third-Party Services & Data Processors

We use two types of service providers. Processors process personal data on our behalf and according to our instructions. The other recipients receive data and process it under their own responsibility, as separate controllers.

Data Processors

ServiceProviderPurposeData LocationRole and Safeguards
Patient Management & Food DiariesProfessional nutrition softwarePatient records, food diaries, patient-dietitian communicationEuropean UnionProcessor (Article 28 GDPR)
Body Composition AnalysisBody composition analysis systemBody composition measurements, weight trackingFrance (EU), HDS-certified host (Hébergeur de Données de Santé) according to the manufacturerProcessor (Article 28 GDPR)
Patient Record Backups & ArchivesGoogle Cloud Platform (GCP)Backup and archiving of patient records (at least 30 years and at most 50 years)Belgium (EU), Google Cloud servers, one regionProcessor (Article 28 GDPR)
Video ConsultationsGoogle MeetReal-time virtual consultations (not recorded)Google data centers (EU and non-EU, including the United States)Processor; EU-U.S. Data Privacy Framework, Standard Contractual Clauses
EmailGoogle WorkspaceReceiving contact form requests, email exchanges with patientsGoogle data centers (EU and non-EU, including the United States)Processor; EU-U.S. Data Privacy Framework, Standard Contractual Clauses
Website HostingVercelHosting of the website diaeta.be, technical server logsServer functions in Frankfurt (EU); global delivery network; United StatesProcessor; EU-U.S. Data Privacy Framework
Audience and Speed MeasurementVercel Analytics & Speed InsightsMeasurement of the site's audience and speed (Core Web Vitals), without cookiesEU/United StatesProcessor; EU-U.S. Data Privacy Framework
Error TrackingSentryDetection and correction of technical errors on the website. Session replay and performance measurements only with your consentGermany (EU) for error data; United States for account data and exchanges with supportProcessor; EU-U.S. Data Privacy Framework
Infrastructure MonitoringUptimeRobot s.r.o. (Slovakia)Monitoring of website availability (response time, HTTP status). No patient dataEuropean Union; some servers of its own sub-processors in the United StatesProcessor; Standard Contractual Clauses

Recipients Acting as Separate Controllers

ServiceRecipientPurposeData LocationRole
Appointment BookingsDoctoranytime (Doctor Anytime Belgium SRL, Auderghem)Appointment booking, transmission of contact data to the practiceBelgium; according to its privacy policy, some data may be transferred to the United StatesSeparate controller. Its privacy policy applies
Business ProfileGoogle Business ProfileInformation about the practice, reviews and requests received via the profileGoogle data centers (EU and non-EU)Separate controller. Google's privacy policy applies
QR Code PaymentWeroQR code payments executed by your bank and ours. Our practice does not keep the transaction dataBelgium/EUSeparate controller (payment scheme)
Invoicing & Tax ManagementAccountable.euInvoices to business clients (name, address, amounts), tax complianceEuropean UnionSeparate controller (invoicing software)

Data Protection Guarantees

For our processors:

  • Data Processing Agreements: We conclude a data processing agreement compliant with Article 28 GDPR with each processor
  • Security Measures: Processors must implement appropriate technical and organizational measures
  • Confidentiality: Processor staff are bound by confidentiality obligations
  • Breach Notification: Processors must notify us of any data breach without delay

The booking platform, the Google Business Profile, the payment scheme and the invoicing software act as separate controllers. Article 28 GDPR does not apply to them. They process your data according to their own privacy policies.

No Unauthorized Third-Party Sharing

We never sell, rent, or share your personal data with third parties for marketing or commercial purposes. Your health data is shared only:

  • With our processors, for the delivery of our services
  • With your doctor or another healthcare professional you designate (with your consent)
  • With your insurance company (at your request and with your explicit consent)
  • When required by law

Emergency Data Sharing

Emergency Situations: If your life or health is in immediate danger and you are physically or legally incapable of giving your consent, we may disclose the necessary health information to the emergency services (Article 9(2)(c) GDPR; Article 39 of the Act of 22 April 2019).

10. International Data Transfers

Your clinical record stays hosted in the European Union. Some technical tools involve data transfers outside the European Economic Area (EEA). This section describes them.

Current Status of Data Transfers

Services hosted in the EU:

  • ✅ Professional nutrition software: hosted in the European Union
  • ✅ Body composition analysis system: hosted in France with an HDS-certified host, according to the manufacturer
  • ✅ Google Cloud Platform (backups and archives): Google Cloud servers in Belgium (one region)
  • ✅ Accountable: European Union
  • ✅ Wero: Belgium/EU

Services with Potential Non-EU Transfers

Some services involve limited data transfers outside the EU:

Google Services (Google Workspace, Google Meet, Google Business Profile)

  • Location: Google data centers in the EU and outside the EU
  • Potential Transfers: Google may process data in the United States
  • Data Concerned: Meeting metadata, emails exchanged with the practice, reviews and requests received via the Business Profile
  • Safeguards:
    • Google adheres to the EU-U.S. Data Privacy Framework
    • Google's data processing terms contain the European Commission's Standard Contractual Clauses
  • Business Profile: For Google Business Profile, Google acts as a separate controller

Hosting, Audience Measurement, Monitoring and Booking

  • Sentry: Error data stored in Germany (EU). Sentry is a U.S. company: account data and exchanges with its support may be processed in the United States. Sentry adheres to the EU-U.S. Data Privacy Framework
  • Vercel (hosting and audience measurement): The site's server functions run in the Frankfurt (EU) region. Vercel's delivery network receives requests at the point of presence closest to the visitor. Vercel is a U.S. company: technical logs (IP address, pages requested) and audience measurement data may be transferred to the United States. Vercel adheres to the EU-U.S. Data Privacy Framework
  • UptimeRobot: Slovak company (UptimeRobot s.r.o., Bratislava). Main processing in the EU. Some servers of its own sub-processors are located in the United States. These transfers rely on the European Commission's Standard Contractual Clauses
  • Doctoranytime: Belgian company (Doctor Anytime Belgium SRL, Auderghem), separate controller for appointment booking. According to its privacy policy, some data may be transferred to the United States under Standard Contractual Clauses or the EU-U.S. Data Privacy Framework

Important: Your clinical record (nutrition software, body composition analysis, archives) stays hosted in the EU. Vercel and UptimeRobot process only technical data.

Safeguards for Non-EU Transfers

Data transfers outside the EU rely on the following safeguards:

  • Transfers to the United States rely on the European Commission's adequacy decision of 10 July 2023 (Implementing Decision (EU) 2023/1795, EU-U.S. Data Privacy Framework) for certified companies. Google, Vercel and Sentry adhere to this framework
  • Failing that, transfers rely on the European Commission's Standard Contractual Clauses
  • You can obtain a copy of these safeguards by writing to info@diaeta.be

11. Children's Privacy

Our consultations are in principle intended for adults. When we see a patient who is a minor, their parents or guardian exercise their patient rights. We involve the minor in decisions according to their age and maturity. A minor who is able to reasonably assess their interests exercises their rights themselves (Article 12 of the Act of 22 August 2002 on patient rights).

For online services, a child can consent alone to the processing of their data from the age of 13 in Belgium (Article 7 of the Act of 30 July 2018). Below that age, the consent of their legal representative is required.

If you believe we hold data of a minor without the required agreement, write to us at info@diaeta.be.

12. Data Protection Officer & Governance

We have assessed the obligation to appoint a Data Protection Officer (DPO) under Article 37 GDPR. As a dietitian practising individually, we do not process health data on a large scale within the meaning of Article 37(1)(c) GDPR (recital 91; guidelines WP 243 of the Article 29 Working Party). Appointing a DPO is therefore not mandatory. We will reassess this conclusion if the scope of our processing changes.

13. Cookies & Website Technologies

Cookie Consent

Diaeta.be sets no first-party cookies. The site uses your browser's local storage, a technology similar to cookies. Our Cookie Policy gives the details.

1. Strictly Necessary Storage

Stores your consent choice and the settings you switch on yourself (reading-mode theme and text size, saved articles). These items are exempt from consent (Article 10/2 of the Act of 30 July 2018).

2. Cookieless Audience Measurement and Error Tracking

Vercel Analytics and Vercel Speed Insights measure the site's audience and speed. They place no cookies and store nothing on your device. Vercel counts visitors using a hash calculated from the request, which is deleted after 24 hours. Sentry records technical errors for all visitors. Legal basis: our legitimate interest (Article 6(1)(f) GDPR).

3. Analytics Subject to Consent

If you accept the analytics category, Sentry records session replays, with text masked and media blocked, as well as performance measurements (tracing). Without your agreement, these two functions stay switched off. You can withdraw this consent at any time in the cookie settings.

4. Third-Party Content

The DoctorAnytime modules (rating in the footer, booking calendar) load only after you accept the "Third-party content" category in the consent window, or when you click to display the module in its place. DoctorAnytime then sets the cookie DA.ABTests (domain doctoranytime.be, duration 1 year). We use no marketing or tracking cookies.

Managing Your Cookie Preferences

When you first visit our website, a consent window appears. You can change your preferences at any time through the "Cookie settings" link in the footer, or by contacting us.

14. Changes to This Privacy Policy

We may update this privacy policy from time to time to reflect changes in our data practices, new technologies, legal requirements, or regulatory guidance. Any material changes will be posted on this page with an updated "Last Updated" date.

If changes significantly affect your rights or our data processing practices, we will notify you by email if you are a patient.

Annual Review Commitment: We conduct an annual review of this privacy policy to ensure continued compliance with evolving data protection standards and legal requirements.

15. Professional Confidentiality & Legal Compliance

As a licensed healthcare professional in Belgium, I am bound by:

  • Professional Secrecy: Article 352 of the Penal Code prohibits me from revealing what you confide to me, unless I testify in court or before a parliamentary commission of inquiry, or the law obliges or authorises me to do so
  • GDPR and Act of 30 July 2018: I process your personal data in accordance with these two texts
  • Act of 22 August 2002 on patient rights, as amended by the Act of 6 February 2024: It protects your rights to quality services, to information, to consent and to access to your patient record
  • Act of 22 April 2019 on quality practice in healthcare: It requires me to keep and retain your record (Articles 33 to 35) and makes the sharing of your data with another healthcare professional subject to your consent (Articles 19 and 36)

16. How to Contact Us & Lodge a Complaint

Data Protection Rights Requests

For any questions, concerns, or to exercise your data protection rights, please contact:

Pierre Abou-Zeid

Email: info@diaeta.be

Phone: +32 479 35 55 51

Address: Ouden Heirweg 58, 9340 Lede, Belgium

Preferred Contact: Email (please include "Data Protection Request" in the subject line)

Response Timeline: We will acknowledge your request within 5 business days and respond to it within one month. Depending on the complexity and number of requests, we may extend this period by two months. We will inform you of this, with the reasons, within one month of your request. Requests to consult or obtain a copy of the patient record receive a response within 15 days.

Lodge a Complaint with the Data Protection Authority

If you believe we have not handled your personal data in accordance with GDPR or Belgian data protection law, you have the right to lodge a complaint with the Belgian Data Protection Authority:

Autorité de protection des données / Gegevensbeschermingsautoriteit

Website: autoriteprotectiondonnees.be

Address: Rue de la Presse 35, 1000 Brussels, Belgium

Phone: +32 (0)2 274 48 00

Email: contact@apd-gba.be

17. Accountability & Documentation

We maintain comprehensive documentation of our data protection practices, including:

  • Record of processing activities (Article 30 GDPR) documenting all data processing operations
  • Data processing agreements with our processors
  • Records of data security assessments and incident response procedures
  • Consent records for website visitors
  • Regular compliance reviews and updates

This documentation is maintained for supervisory authority review if requested.

Data Protection Impact Assessment (DPIA)

Article 35 GDPR requires a data protection impact assessment (DPIA) when processing is likely to result in a high risk, in particular in the case of large-scale processing of health data. According to recital 91 GDPR, the processing of patient data by a health professional practising individually is not large-scale processing. Our processing operations also do not appear on the list of the Data Protection Authority (decision no. 01/2019). A DPIA is therefore not mandatory. We nevertheless assess the risks of our processing and apply safeguards: hosting of body composition measurements with an HDS-certified host according to the manufacturer, encryption, access controls and regular security reviews.

18. Multilingual Availability & Legal Precedence

The French version of this privacy policy prevails. Translations in English, Dutch and German are published on this site.

Legal Precedence: In case of any discrepancy or conflict between language versions, the French version shall take legal precedence and be considered the authoritative version for interpretation and enforcement purposes.

All language versions are maintained with the same "Last Updated" date to ensure consistency across translations. For any question about this policy, please contact info@diaeta.be.

Your privacy and the confidentiality of your health information are fundamental to our practice.

END OF PRIVACY POLICY