Privacy Policy

Last updated: 30 October 2025

1. Introduction

Medscio respects your privacy and is committed to protecting your personal data. This privacy policy explains how we handle your personal data when you visit our website. For our website, marketing, recruitment, and internal administration, we act as the data controller.

 

Contact details:

Company name: Medscio
Address: Paasheuvelweg 25, 1105 BP, Amsterdam, The Netherlands

KvK: 98107496
Email: privacy@medscio.nl

 

2. What data do we collect?

We may collect the following personal data from you:

 

2.1 Data you provide to us

  • Contact details: name, email address, phone number, organization name

  • Communication: correspondence when you contact us

  • Other information: any additional data you voluntarily share with us via contact forms, emails, or conversations

 

2.2 Data collected automatically

  • Technical data: IP address, browser type and version, time zone settings, operating system

  • Usage data: information about how you use our website

  • Cookies and similar technologies: see our Cookie Policy

 

3. How do we use your data?

We use your personal data for the following purposes:

 

3.1 Legal basis: Performance of a contract

  • Providing our services

  • Communicating about your account or our services

  • Technical support

 

3.2 Legal basis: Legitimate interest

  • Responding to your questions and requests

  • Improving our website and services

  • Sending relevant information about our services (you may opt out at any time)

  • Analyzing website usage

 

3.3 Legal basis: Legal obligation

  • Complying with legal requirements, such as tax laws

 

3.4 Legal basis: Consent

  • Marketing communication (only with your consent)

  • Placement of certain cookies

 

4. Who do we share your data with?

We only share your personal data when necessary:

 

4.1 Service providers

We use third-party service providers to support our operations, such as:

  • Hosting providers

  • Email service providers

  • Analytics services

  • CRM systems

These parties process data only on our behalf and are contractually obligated to protect your data.

 

4.2 Legal obligations

We may share your data when required by law or when necessary to:

  • Comply with legal obligations

  • Protect our rights

  • Prevent fraud

 

4.3 Business transfer

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new owner.

 

5. International data transfers

Your data is primarily processed within the European Economic Area (EEA).
If we process data outside the EEA, we ensure that appropriate safeguards are in place, such as:

  • EU Standard Contractual Clauses

  • Adequate protection measures as recognized by the European Commission

 

6. Data retention

We do not retain your personal data longer than necessary for the purposes for which it was collected:

  • Prospect contact data: up to 2 years after last contact

  • Customer data: for the duration of the agreement and 7 years thereafter (legal retention requirement)

  • Financial data: 7 years (legal retention requirement)

  • Website analytics: 26 months

 

7. Data security

We take appropriate technical and organizational measures to protect your personal data against loss, misuse, unauthorized access, and disclosure, including:

  • Encrypted connections

  • Access control and authorization

  • Regular security updates

  • Secure backups

  • Confidentiality obligations for employees

 

8. Your rights

Under the General Data Protection Regulation (GDPR), you have the following rights:

 

8.1 Right of access

You have the right to know what personal data we process about you.

 

8.2 Right to rectification

You have the right to have inaccurate or incomplete data corrected.

 

8.3 Right to erasure (‘right to be forgotten’)

You can request deletion of your personal data when:

  • The data is no longer needed for its original purpose

  • You withdraw your consent and no other legal basis applies

  • You object to processing and there are no overriding legitimate grounds

  • The data has been unlawfully processed

 

8.4 Right to restriction of processing

You may request limitation of processing in certain situations.

 

8.5 Right to data portability

You have the right to receive your data in a structured, commonly used, and machine-readable format.

 

8.6 Right to object

You have the right to object to the processing of your personal data based on legitimate interest.

 

8.7 Right to withdraw consent

If processing is based on consent, you may withdraw your consent at any time.

To exercise your rights, please contact us at privacy@medscio.nl. We will respond within 30 days.

 

9. Complaints

If you have a complaint about how we handle your personal data, please contact us first.
You also have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
www.autoriteitpersoonsgegevens.nl

 

10. Cookies

10.1 What are cookies?

Cookies are small text files placed on your computer, tablet, or mobile device when you visit our website.
They help websites remember your preferences and improve your user experience.

Types of cookies:

  • Session cookies: deleted when you close your browser

  • Persistent cookies: remain on your device until expired or deleted

  • First-party cookies: placed by the website you visit (medscio.nl)

  • Third-party cookies: placed by external services (e.g., analytics providers)

 

10.2 Why do we use cookies?

Medscio uses cookies to:

  • Ensure our website functions properly

  • Remember your preferences

  • Understand how visitors use our website

  • Improve and optimize our website

  • Display relevant information

 

10.3 Which cookies do we use?

10.3.1 Strictly necessary cookies

Essential for the website’s core functionality.
These do not require consent.

10.3.2 Functional cookies

Provide additional functionality and personalization (e.g., remembering preferences).
Improve the user experience without infringing privacy.

10.3.3 Analytical cookies

Help us understand how visitors use our website to improve it.

10.3.4 Marketing cookies

Used to track visitors across websites to show relevant advertisements.
Currently, we do not use marketing cookies.
If this changes, we will inform you and request consent again.

 

10.4 Third-party cookies

Some cookies are set by external providers. We have no control over these cookies.
Please refer to their privacy policies:

 

10.5 Managing your cookie preferences

10.5.1 Giving or withdrawing consent

When you first visit our website, we ask for your consent (except for strictly necessary cookies).
You can withdraw or change consent anytime by:

  • Clicking the cookie settings link at the bottom of each page

  • Contacting us at privacy@medscio.nl

 

10.5.2 Deleting cookies via your browser

You can manage and delete cookies in your browser settings:

  • Google Chrome: Settings → Privacy & Security → Cookies and other site data

  • Mozilla Firefox: Settings → Privacy & Security → Cookies and site data

  • Safari: Preferences → Privacy → Cookies and website data

  • Microsoft Edge: Settings → Cookies and site data

Note: Disabling cookies may affect some website functionality.

 

10.5.3 Do Not Track

Some browsers offer a “Do Not Track” feature.
Currently, there is no universal standard for responding to these signals.
We respect your privacy and recommend using our cookie settings.

 

10.6 Google Analytics

Google Analytics collects information such as:

  • Pages you visit

  • Time spent on the website

  • Browser and device used

  • How you reached our website

  • Your general location (country/city level)

Google Analytics data is automatically deleted after 26 months.

 

10.7 Changes to cookie usage

If we start using new types of cookies (e.g., marketing cookies):

  • We will clearly inform you

  • Request your consent again

  • Update this policy

 

11. Links to external websites

Our website may contain links to external websites.
We are not responsible for their privacy practices and encourage you to read their privacy policies.

 

12. Children

Our services are not intended for persons under 16 years of age.
We do not knowingly collect data from children under 16.
If you believe we have done so, please contact us immediately.

 

13. Changes to this privacy policy

We reserve the right to update this privacy policy.
The latest version will always be available on our website.
We recommend reviewing it regularly.
If major changes occur, we will notify you.

 

14. Contact

For any questions regarding this privacy policy or how we handle your data, please contact us at: privacy@medscio.nl