Privacy Policy
Version 1.0
Date: 18th September 2023
1. Identity and Contact Information of the Data Controller
This privacy policy applies to all personal data processed by the Vision Healthcare Group, with its registered office at Grote Markt 41, 8500 Kortrijk, with enterprise number BE 0685.849.188, as well as to Remark Groep, part of the Vision Healthcare Group and with its registered office at Rogat, the Netherlands, and enterprise number O4047609, acting as conjoint data controllers under the GDPR (hereafter called ‘Data Controller’).
The Data Controller places great importance on your privacy and processes your personal data in accordance with the European Regulation 2016/679 of April 27, 2016, regarding the protection of natural persons concerning the processisng of personal data (hereinafter referred to as "GDPR"), as well as any future or additional legislation implementing it, where applicable.
For further questions or comments regarding how we handle your personal data, you can always contact us, either by email at privacy@visionhealthcare.eu or by mail to the aforementioned postal address.
Our Data Protection Officer (DPO), Mr. Franklin BV – www.misterfranklin.be, can also be reached using the same contact information (please specify "Attention: DPO").
2. What does ‘processing of personal data’ mean?
The processing of personal data (hereinafter referred to as ‘data’) includes any handling of data that can identify you as a natural person. You can find information about the specific data involved in this Privacy Policy. The term ‘processing’ is very broad and encompasses activities such as collecting, storing, using your data, or sharing it with third parties.
3. What data do we process?
Below, we clarify the types of data that we may process from you. We may receive the following data either directly or indirectly from you.
We receive personal data directly from you when you make a purchase from one of the companies belonging to the Vision Healthcare group, when you contact one of these
companies, or when you contract as a service provider/supplier with one of the companies within the group.
It is also possible that we receive your personal data indirectly, through third parties. In such cases, these personal data are not provided directly by you to one of the companies belonging to the Vision Healthcare group. You may have given a third-party permission to further disclose your personal data to other parties, including one of the companies within the Vision Healthcare group.
3.1. Customer data
3.1.1. Data customer account
It is possible to create a personal customer account through this website, which allows for placing orders, making purchases, and keeping track of purchase history. By creating such a customer account, you provide the data controller with the following information:
- General identification data (name, first name, date of birth);
- Contact information (name, first name, email address, address, telephone number);
- Payment card details (account number, expiration date, cardholder name);
- Order history;
- Company number and other company-related data insofar as they can lead to identification of a natural person;
- Delivery addresses (in case they differ from the provided residential address);
- Shopping cart;
- Gender (optional);
- Account details (username, password).
3.1.2. Data when placing an order without an account
However, it is not required to create an account to place an order. When such an order is placed, the following customer data is processed:
- General identification data (name, first name);
- Contact information (name, first name, email address, and address);
- Payment card details;
- Delivery address (in case it differs from the billing address).
3.1.3. Data when contacting customer service
For inquiries, complaints, comments, etc., you can always contact the customer service of the company. When you contact our customer service, we process the following data:
- General identification data (name, first name);
- Contact information (name, first name, email address, and address if the reason for contacting customer service is related to it);
- Payment card details (to the extent that the reason for contacting customer service is related to it);
- Ordered products/services and order number/customer number.
3.1.4. Data in the context of after-sales services, contests, and other promotional activities
Customer friendliness, optimal customer experience, and service are highly valued by Vision Healthcare NV. In the context of these activities, the data controller processes the following data:
- General identification data (name, first name);
- Contact information (name, first name, email address, and address if relevant);
- Ordered products/services and order number/customer number;
- Feedback on the products sold and, more generally, on the services provided.
3.2. Suppliers’ data
The Vision Healthcare group and all companies belonging to this group engage external service providers and suppliers for various services/products. In this context, the data controller processes the following personal data from these suppliers/service providers:
- Contact information of the contact person within the supplier/service provider's company (name, first name, email address, telephone number);
- Company number and other company-related data insofar as they can lead to identification of a natural person;
- Contractual data (e.g., company name, address, VAT number, agreement, etc.);
- Payment and billing data (e.g., payment card information, invoices, etc.);
- Account information for the platform (e.g., account registration data);
- Feedback, testimonials, quotes, promotional content such as photos and videos (e.g., reviews and experiences related to our collaboration, testimonials, quotes, presence at events, etc.).
3.3. Candidate-employees
We may process the following additional data from prospective employees, which will largely depend on the data you choose to provide to us in the context of your job application:
- Personal particulars (motivation letter, CV, diplomas);
- Work-related data (previous professional experience, CV, ...);
- Personality data;
- Photos.
3.4. Visitors of the website
When you visit our website as a customer or non-customer, the following personal data may be processed, depending on your own personal preferences:
- IP address, browser type, location data, how the individual arrived at the website, interests, and the way the individual navigates the web page (through strictly necessary, analytical, and marketing cookies);
- Name, first name, email address, telephone number, subject of contact, and contact message (via the online contact form);
- Email address (via the online newsletter subscription form).
4. For what purposes do we process your data?
Personal data is processed exclusively within the framework of the company, specifically for the following purposes:
- Within the scope of our main activities and webshops;
- Aftersales service;
- Marketing and promotional activities;
- Compliance with administrative and tax obligations;
- Communication with customers and prospects;
- Employee recruitment procedures.
5. On what legal grounds do we process your data?
We process your data for the purposes described below and collect and process no more or no other types of data than those necessary for these purposes. We process your data only to the extent based on one of the legal grounds listed in the GDPR, as outlined below.
Legal obligation
Certain data is processed by us to comply with legal or regulatory obligations imposed on us. For example, within the scope of tax and accounting obligations or data protection.
Necessary for the Performance of the Contract:
Certain data is processed by us because it is necessary for entering into, performing, or terminating a contract with you as the data subject. For example, for contacting, scheduling, responding to a request, or obtaining information in the context of entering into a contractual relationship, as well as for the actual execution of the contractual task within the framework of our main activity, in order to provide you with our services or receive services from you.
Legitimate interest
Certain data is processed by us based on our legitimate interest, which, in specific cases, outweighs any potential detriment to your rights. For example, for the following purposes:
- Marketing activities to our customers;
- Improving the quality of our services;
- Training employees and evaluating and maintaining data and statistics related to our activities in the broad sense.
- Preserving and using evidence in the context of liability, procedures, or disputes, with a view to archiving activities.
- Ensuring security, both online on our websites and in our company premises.
Consent
Certain data is processed by us based on your consent. For example, for the following purposes:
- Marketing activities that don’t fall under legitimate interest;
- Using certain analytical or marketing cookies;
- Using media on our website and social media channels.
- Data of job applicants will only be retained after the recruitment process with their consent.
6. Data source
Most of the data we process from you has been obtained directly from you. Within the scope of our services. It is possible that we obtain data from you through external service providers or public sources. You can always contact us for more information about the sources of our data about you.
7. Who do we share your data with?
We do not share your data with third parties unless it is strictly necessary for the purposes mentioned above or if we are legally obliged to do so.
The company Vision Healthcare NV and each individual enterprise that is part of the Vision Healthcare group act as conjoint data controllers. Personal data processed by the enterprises that are part of the Vision Healthcare Group may be shared within the Group to the extent that the sharing of such personal data is based on a legal processing basis provided for in Article 6 of the GDPR and to the extent that such sharing aligns with one of the processing purposes as indicated in this privacy policy.
Where necessary, we rely on external service providers (processors) to support our operational purposes such as the management of our websites and IT systems. These external service providers may, where applicable, perform certain data processing on our behalf. We will only share your data with these external service providers to the extent necessary for the respective purpose. They are not allowed to use the data for other purposes. Furthermore,
these service providers are contractually bound to ensure the confidentiality of your data through a 'data processing agreement' concluded with these parties."
Specifically, this means that we share your data, as relevant in your situation, with the following third parties for the following purposes, where these third parties, in certain cases, act as processors on our behalf:
- Postal companies, transport and delivery companies if we need to send you something by mail;
- Payment service providers if we receive payments from you, or vice versa;
- External representatives and consultants or any other parties involved in the context of our main or ancillary activities;
- Processors who assist us in the field of IT in operating our organization, with a view to secure and efficient digital data management within our organization;
- Government authorities, judicial bodies, and practitioners of regulated professions such as accountants and lawyers, in order to comply with our legal obligations and defend our interests, as required.
8. For how long do we store your data?
We do not retain your data for longer than necessary for the purpose for which the data was collected or processed. Since the duration for which data may be retained depends on the purposes for which the data was collected, the storage period may vary in each situation. Sometimes, specific legislation may require us to retain data for a certain period. Our retention periods are always based on legal requirements and a balance of your rights and expectations with what is useful and necessary for fulfilling the purposes. After the retention period expires, your data will be deleted or anonymized."
9. Where do we store your data and how is your data protected?
We implement appropriate security measures on a technical and organizational level to prevent, within the scope of our activities, the destruction, loss, falsification, alteration, unauthorized access, or unlawful disclosure to third parties, as well as any other unauthorized processing of this data.
Furthermore, we also ensure that the processors we engage with also implement appropriate security measures to minimize the risks of incidents as much as possible.
If your data, when using specific services or software tools, is processed outside the European Economic Area (EEA), this will only occur in/to countries for which the European Commission has confirmed that they guarantee an adequate level of protection for your data, or measures will be taken to ensure the lawful processing of your data in these third countries.
10.What are your rights?
You have various rights concerning the data we process about you. If you wish to exercise any of the following rights, please contact our GDPR representative using the contact details provided in the first section of this Privacy Policy.
Right of Access and Copy:
You have the right to access your data and obtain a copy of it. This right also includes the ability to request further information about the processing of your data, including the categories of data processed about you and the purposes for which this is done.
Right of Rectification: You have the right to have your data rectified if you believe that we hold inaccurate data.
Right to Erasure (Right to Be Forgotten):
You have the right to request that we erase your data without undue delay. However, we may not always be able to fulfill such a request, particularly when we still need the data for an ongoing contract or when keeping certain data for a specified period is legally required.
Right to Restriction of Processing:
You have the right to restrict the processing of your data. This temporarily suspends the processing until, for example, its accuracy is confirmed.
Right to Withdraw Your Consent:
When processing is based on your consent, you have the right to withdraw this consent at any time by contacting us. For marketing messages you receive from us via email based on your consent, you can easily withdraw this consent by clicking on the unsubscribe link at the bottom of such a message.
Right to Object:
You have the right to object to the processing of your data based on legitimate interest. This must be done based on specific reasons related to your situation. You can also object to the use of your data for direct marketing. In marketing emails, there will always be an opt-out option provided.
Right to Data Portability:
You have the right to obtain your data, which you provided to us with your consent or in the performance of a contract, in electronic form. This allows them to be easily
transferred to another organization. You also have the right to request us to transmit your data directly to another organization, where technically feasible.
Right to Lodge a Complaint with Your Supervisory Authority:
If you believe that we are processing your data in an incorrect manner, you always have the right to lodge a complaint with your data protection supervisory authority.
Autoriteit Persoonsgegevens
Hoge nieuwstraat 8
2514 EL Den Haag https://www.autoriteitpersoonsgegevens.nl/contact
11.How to exercise your rights
You can exercise your rights by contacting us, either by email at privacy@visionhealthcare.eu or by mail at Grote Markt 41, 8500 Kortrijk (Belgium). It is possible that we will ask you to provide us some documentation to prove your identity. Those documents will only be used to comply to your request in accordance with the GDPR.
12.Adaptations
We reserve the right to change this Privacy Policy. The most recent version is always available on our websites. You can find the date on which this Privacy Policy was last modified at the top. In the event of a substantial change to the Privacy Policy, we will inform those affected, if possible, directly.