Privacy

Privacy policy

Last updated: 7 June 2026

1. Data controller

The controller responsible for the processing of your personal data via this website and at the practice is:

Dr. Isabel Pinxten BV
Henry Van de Veldelaan 1
8300 Knokke-Heist
België

Phone: 050 62 00 00 · Email:

2. Which data do we process?

We only process data that you provide to us or that is necessary for your care:

  • Identification data: last name, first name, date of birth, national registry number (medical file).
  • Contact details: address, phone, email.
  • Health data: medical history, examination results, prescriptions, imaging, only at the practice.
  • Form data: name, email, phone, message, and where applicable the appointment date or time.
  • Technical data: IP address and browser information, kept for a limited period for security and anti-spam purposes.

3. Purposes and legal basis

  • Provision of medical care: art. 9(2)(h) GDPR and art. 6(1)(b) GDPR.
  • Appointment management and communication with the secretariat: art. 6(1)(b) GDPR and art. 6(1)(a) (your consent) for the forms.
  • Statutory obligations (medical record keeping, INAMI/RIZIV, accounting): art. 6(1)(c) GDPR.
  • Security and abuse prevention on the forms: art. 6(1)(f) GDPR (legitimate interest).

4. Retention periods

  • Medical file: 30 years after the last patient contact (art. 24 RD of 3 May 1999 and the Quality Act).
  • Form messages: maximum 12 months after the last exchange, unless added to the medical file.
  • Accounting data: 7 years.
  • Technical logs: maximum 90 days.

5. Recipients and processors

Your data are only shared with parties needed for our services:

  • Our hosting provider and email delivery service (servers within the EEA).
  • The online booking platform Progenda (Belgian company, servers within the EEA), if you book an appointment online.
  • The hospital or surgical centre when a procedure is scheduled there.
  • Legally competent authorities (INAMI/RIZIV, health insurance funds) in the context of third-party payment or statutory obligations.

We never sell or rent your data and we do not transfer it outside the European Economic Area.

6. Cookies and external services

On your first visit, we display a cookie banner that lets you explicitly accept or decline cookies and external services. Strictly necessary functional storage (language preference, your cookie choice itself) is always used. The ePrivacy law does not require consent for these.

If you accept the banner, we load:

  • Google Tag Manager (Google Ireland Ltd.): a container we use to measure website usage anonymously. Cookies are set and your IP address and browser data are sent to Google. Legal basis: your consent (art. 6(1)(a) GDPR).
  • Google Maps (Google Ireland Ltd.): the map on the contact page is loaded automatically and your IP address and browser data are sent to Google. Legal basis: your consent (art. 6(1)(a) GDPR).

If you decline the banner, Google Tag Manager is not loaded and the Google Maps map is replaced by a placeholder. The map is then only loaded when you actively click the button "Click to load the map". Only at that moment is your data sent to Google.

You can withdraw your consent at any time by clearing this website's cookies in your browser. The cookie banner will reappear on your next visit.

More information about Google's processing is available in the Google privacy policy. Google may transfer data to the United States on the basis of the EU-US Data Privacy Framework.

7. Your rights

Under the GDPR you have the following rights:

  • Right of access.
  • Right to rectification.
  • Right to erasure, subject to statutory retention obligations.
  • Right to restriction of processing.
  • Right to object.
  • Right to data portability.
  • Right to withdraw consent at any time.

Please send your request in writing to the address above or by . We reply within 30 days.

8. Complaints

If you have a complaint about how we process your data, please contact us first. You also always have the right to lodge a complaint with the Belgian Data Protection Authority:

Data Protection Authority
Drukpersstraat 35, 1000 Brussels
Phone: +32 (0)2 274 48 00
www.dataprotectionauthority.be

9. Security

We take appropriate technical and organisational measures to protect your data against loss, unauthorised access or misuse: encrypted connections (HTTPS), access control, regular backups and strict confidentiality (medical secrecy).

10. Changes

This privacy statement may be updated. The latest version is always available on this page.