Privacy policy
Version 2025 – Compliant with GDPR & WGBO
Joya Nutrition is committed to protecting your privacy and handling your personal data with care, integrity, and transparency.
1. Data controller
Joya Nutrition
Email: info@joyanutrition.com
2. Personal data I process
To provide personalised dietary guidance, I may collect:
Full name
Contact details (email, phone number)
Date of birth
Address
Citizen Service Number (BSN) only when legally required
Insurance details (if relevant)
Health information needed for treatment
Notes related to your nutritional assessment and progress
Because nutrition care is part of healthcare, some of this information falls under special (sensitive) personal data.
3. Why I collect your data
Your data is used to:
Provide personalised nutrition and lifestyle guidance
Maintain a legally required health record (WGBO)
Communicate with you regarding your appointments
Fulfil administrative and legal obligations
I do not use your data for marketing.
4. Legal basis for processing
I process your data based on:
The treatment agreement between you and the Service Provider
Legal requirements under Dutch healthcare law
Your explicit consent (for specific or digital communications)
5. Digital communication
I use secure systems where possible.
If you choose to communicate via regular email, you acknowledge that this method may be less secure. You may withdraw this consent at any time.
6. Data Retention (WGBO)
Medical and treatment-related information is stored for 15 years after your last consultation, as required by Dutch healthcare law.
7. Sharing your data
I only share your data when necessary and with your explicit consent, for example:
With your GP, medical specialist, or other healthcare providers
With IT service providers who offer secure hosting
With health insurers (only when relevant)
I never sell or distribute your data for commercial use.
8. Complaints about your data
If you have concerns about how your data is used, contact: info@joyanutrition.com
You also have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
9. Complaints procedure
As a healthcare provider, Joya Nutrition complies with the Dutch Quality, Complaints and Disputes in Healthcare Act (Wkkgz).
The service provider is personally affiliated as a dietitian/healthcare provider with the Dutch Association of Dietitians (NVD) and is registered with the Klachtenloket Paramedici, which provides access to an independent complaints officer and a Wkkgz-recognised disputes committee.
In the event of a complaint, the client is encouraged to first discuss this with the service provider. If the complaint cannot be resolved by mutual agreement, the client may submit the complaint to the Klachtenloket Paramedici.
10. Your data rights under GDPR
You have the right to:
Request access to your data
Request correction
Request deletion (where legally allowed)
Request data restriction
Withdraw consent
To protect your privacy, identity verification may be required before processing requests.
11. Data security
I take appropriate technical and organisational measures to protect your data against loss, misuse, and unauthorised access.