Please contact us by phone on 070-200 20 70
Monday to Friday 10:00 to 18:00
Privacy Statement SkinSurgery Clinics
SkinSurgery Clinics processes personal and medical data of clients carefully, securely, and confidentially. We do this in compliance with the General Data Protection Regulation, the GDPR Implementation Act, the Medical Treatment Agreement Act, and other applicable laws and regulations.
SkinSurgery Clinics is responsible for the processing of personal data as described in this privacy statement.
SkinSurgery Clinics
Laan van Meerdervoort 677
2564 Den Haag
E-mail: info@skin-surgery.nl
Website: www.skin-surgery.nl
For questions about privacy or the processing of personal data, please contact us via info@skin-surgery.nl.
What data do we process?
SkinSurgery Clinics may process the following personal data, among others:
Name, address, place of residence, telephone number, email address, date of birth, gender, appointment details, payment details, correspondence, medical history, medication use, allergies, previous treatments, treatment details, medical photographs, consent forms, aftercare details, complication details, and other data necessary for good and safe healthcare.
Medical data constitutes special categories of personal data. This data is processed only where necessary for medical treatment, the medical record, the performance of the treatment agreement, legal obligations, or where you have given your explicit consent.
What do we use your data for?
We process personal data and medical data for the following purposes:
- Planning, confirming, and changing appointments.
- Conducting a medical assessment, taking a medical history and determining suitability.
- Assessing contraindications and medical risks.
- Performing cosmetic medical treatments.
- Providing aftercare and check-ups.
- Maintaining the medical record.
- Recording consent for treatments.
- Processing payments and administration.
- Handling enquiries, complaints and requests.
- Communicating about the treatment path, including preparation, recovery and aftercare.
- Compliance with legal obligations.
- Improving our care, services and internal processes.
We do not process more data than is necessary for these purposes.
Medical record
As a healthcare provider, SkinSurgery Clinics is required to maintain a medical record. In this record, we document relevant medical information that is necessary for good, safe, and responsible care.
The medical record may include, amongst other things: your reason for seeking care, medical history, medication use, allergies, diagnosis, treatment plan, information provided, consent, medical images, treatment carried out, products or materials used, aftercare instructions, follow-up appointments and any complications.
The medical records are stored in a secure electronic patient record system. Access to the records is restricted to healthcare professionals and staff who require this information for their work.
Medical photographs
During the consultation, treatment, or check-up, medical photographs may be taken. These photographs might be necessary for diagnosis, treatment planning, record-keeping, assessing the outcome, aftercare, and follow-up.
Medical photographs form part of the medical record and are treated confidentially.
Medical photographs will not be used for marketing, social media, websites, advertisements, ‘before and after’ publications or any other commercial purposes without your separate and explicit consent. This consent will be requested and recorded separately.
You can withdraw your consent for marketing purposes at any time. Withdrawing your consent will not affect your treatment.
SkinSurgery App in partnership with Caro
SkinSurgery Clinics can use the SkinSurgery App in collaboration with Caro for surgical treatments. This app is used for secure communication throughout the treatment process.
The app can be used for preoperative information, preparation for the procedure, postoperative care instructions, communication about recovery, sending or receiving photos, and answering questions about the treatment pathway.
Personal data and medical data necessary for the relevant care pathway can be processed via the SkinSurgery App. This may include, among other things, name, contact details, treatment data, appointment data, medical questionnaires, recovery information, messages, and photos relevant to the treatment or aftercare.
The SkinSurgery App, in collaboration with Caro, is NEN 7510 and ISO 27001 certified. This means it operates in accordance with recognised standards for information security in the healthcare sector and for the secure processing of sensitive personal and medical data.
The app is used exclusively for content-related communication and guidance regarding treatment. Data from the app will not be used for marketing purposes without separate and explicit consent.
To the extent that Caro processes personal data on behalf of SkinSurgery Clinics, processor agreements will be drawn up. These agreements will cover security, confidentiality, data access, retention periods, and processing in accordance with the GDPR and applicable healthcare-specific security standards.
Basis for processing
SkinSurgery Clinics processes personal data on the basis of one or more of the following grounds:
- Performance of the treatment agreement.
- Statutory obligation.
- Legitimate interest, for example for security, administration, quality improvement, or the protection of property and persons.
- Express consent, for example for marketing use of medical photos.
- The need for high-quality medical care.
When processing is based on consent, you can always withdraw this consent. Processing that took place before the withdrawal remains lawful.
Who do we share data with?
SkinSurgery Clinics will only share personal and medical data when it is necessary for healthcare provision, administration, security, legal obligations, or when you have given consent.
We may share data with the following categories of parties:
- Electronic patient record, such as Clinicminds.
- Secure communication providers, such as Zivver.
- Digital care platforms for surgical communication, aftercare, questionnaires, and photos, including the SkinSurgery App in collaboration with Caro.
- Payment providers.
- Bookkeeper, accountant or accountancy firm.
- IT suppliers and hosting providers.
- Pharmacy or supervising pharmacist.
- Healthcare professionals involved in medical care.
- Legal advisors or insurers, if necessary.
- Governmental bodies, supervisory authorities or law enforcement agencies when we are legally obliged to do so.
We enter into data processing agreements with parties that process personal data on our behalf. These agreements contain arrangements on confidentiality, security, and the use of personal data.
Security and confidentiality
SkinSurgery Clinics takes appropriate technical and organisational measures to protect personal and medical data from loss, unauthorised access, misuse, modification, or unwanted disclosure.
We work with secure systems, limited access rights, secure communication and internal confidentiality agreements. Employees and healthcare providers are bound by secrecy.
Medical data is exclusively accessed by individuals who require this data for their work.
CCTV
Security cameras may be present on and around our premises. These cameras are used exclusively for the security of clients, visitors, employees, property and the building, and for the prevention or recording of incidents such as theft, vandalism, aggression or unauthorised access.
There are no cameras in treatment rooms, toilets, changing rooms, or other areas where clients have a heightened expectation of privacy. Our cameras do not record sound.
We inform clients, visitors and staff about CCTV surveillance by means of visible signs at the entrance and/or in the relevant areas.
Camera footage is only viewed when there is a concrete reason to do so, such as an incident or safety risk. Footage is not used for medical assessment, marketing purposes, or continuous staff monitoring.
CCTV footage is not stored for longer than necessary. In principle, we adhere to a retention period of a maximum of 4 weeks, unless an incident occurs. In that case, relevant footage may be stored for longer as long as it is necessary for the handling of the incident, claims settlement, legal proceedings or a request from the police or judiciary.
Access to camera footage is restricted to authorised personnel. Footage will not be shared with third parties unless necessary for security, claims handling, legal proceedings, or when legally required to do so.
Retention periods
SkinSurgery Clinics does not retain personal data for longer than is necessary for the purpose for which the data was collected, unless there is a statutory retention period or longer retention is necessary.
Medical records are, in principle, kept for at least 20 years under the WGBO (Medical Treatment Contracts Act), calculated from the last amendment to the record. In some situations, data may be kept for longer, for example, when this is necessary for proper patient care or due to a legal interest.
Administrative and fiscal data are kept for as long as legally required.
CCTV footage is generally kept for a maximum of 4 weeks, unless there is an incident or another specific reason to retain the footage for longer.
Data that is no longer required will be deleted or anonymised.
Your rights
You have the right to access, rectify, supplement, restrict, transfer, or, where possible, have your personal data deleted. You can also object to certain processing or withdraw previously given consent.
For medical records, removal or destruction is not always possible. SkinSurgery Clinics may refuse a request in the event of a statutory retention obligation, when retention is necessary for proper care, or when another overriding interest exists.
You can send a request to info@skin-surgery.nl.
To protect your privacy, we may ask you to verify your identity. In principle, we will respond within one month of receiving your request. If a request is complex, this period may be extended in accordance with the GDPR. In that case, we will inform you.
Data breaches
If there is a potential data breach, we assess it carefully. If necessary, we will report the data breach to the Data Protection Authority and/or the individuals concerned.
SkinSurgery Clinics registers data breaches internally and takes measures to prevent recurrence where necessary.
Cookies and website usage
Our website uses cookies and similar technologies. Functional cookies are necessary for the website to work properly. Analytical cookies can be used to gain insight into the use of the website and to improve it.
When we use marketing cookies, tracking cookies, or similar techniques, we ask for your consent when legally required.
Further information about this can be included in a separate cookie policy.
Newsletters and marketing
SkinSurgery Clinics can inform clients about treatments, news, or promotions when there is a valid basis for doing so, for example, consent or an existing client relationship.
You can always unsubscribe from commercial communications.
Medical data will not be used for commercial purposes without your express consent.
Complaints about privacy
If you have any questions or complaints regarding the processing of your personal data, please contact us via info@skin-surgery.nl.
You also have the right to lodge a complaint with the Data Protection Authority.
Changes
SkinSurgery Clinics may amend this privacy statement when legislation, our services, or internal processes change. The most current version is always available on our website.
Last updated: May 2026