Privacy Policy
Last updated: July 2026
1. Who we are
VeryPatient is the online private clinic service of Clinique de la Brisée, Clinique de la Brisée, Rue Brisée 281, 7020 Maisières (Mons), Belgium. We are the data controller for the personal data described in this policy. You can reach our privacy contact at privacy@verypatient.com.
2. What data we process
Identity and contact data (name, email, phone, WhatsApp number); family membership details (family members covered by your plan); billing and subscription data (plan, billing period, payment status — card details are processed by our payment provider and never touch our servers); and, when you use our care services, health data you or your practitioners share with us (consultation notes, symptoms, reports). Health data is special-category data under Article 9 GDPR and is processed for the purpose of providing you with healthcare, under the responsibility of licensed healthcare professionals bound by medical secrecy.
3. Why and on what legal basis
We process your data to provide the membership and care coordination services you subscribe to (performance of a contract; provision of healthcare under Art. 9(2)(h) GDPR); to invoice and administer your subscription (contract, legal obligations); to respond to your messages (legitimate interest); and, with your consent, to send you service updates. AI-assisted features are always subject to validation by qualified human caregivers, and we clearly disclose when you are interacting with an AI system.
Cookies and analytics
We use one analytics tool, Google Analytics, to see which pages people find useful. It is switched OFF until you accept it: when you first arrive it loads in a denied state in which it sets no analytics cookie and sends no identifier. It runs only if you press Accept on the banner. If you decline — or simply ignore the banner — nothing is measured, and nothing about your care changes. We do not advertise, we do not build profiles, and we share nothing with advertisers. To change your mind, clear this site's data in your browser and the banner returns.
4. Who receives your data
Payment processing: Stripe (payment card data is handled entirely by Stripe). Messaging: WhatsApp Business via our messaging platform, when you choose to contact us there. Clinical partners involved in your care (e.g. dermatology, mental-health and women's-health partners) receive only the data needed for the service you subscribed to. We never sell your data and never use your health data for advertising.
5. International transfers
Where a service provider processes data outside the EEA, we rely on adequacy decisions or Standard Contractual Clauses. Health data is hosted within the EEA.
6. How long we keep it
Medical records are retained for 30 years after the last patient contact, as required by Belgian law. Billing records are kept for 7 years (accounting law). Other data is kept no longer than needed for the purposes above.
7. Your rights
You have the right of access, rectification, erasure (within the limits of medical record-keeping law), restriction, portability, and objection, plus all rights under the Belgian Patient Rights Act, including access to your patient file. Write to privacy@verypatient.com. You may also lodge a complaint with the Belgian Data Protection Authority (autoriteprotectiondonnees.be).
8. Security
Data is encrypted in transit and at rest; access to health data is restricted to the care team involved in your treatment and logged. In case of a breach affecting your rights, we will notify you and the supervisory authority as required by law.
This policy may be updated as our services evolve; material changes are announced on this page at least 30 days in advance.