Back to Home
    Preventa Health®
    Legal

    Privacy Statement Preventa Health

    Last updated: April 2026

    Preventa Health is an organization that provides preventive medical screening for employees across all sectors.

    In the course of our activities, we process personal data. Below we explain in which situations we process personal data and for what purposes.

    We attach great importance to protecting your privacy when processing personal data. Personal data is processed in accordance with the General Data Protection Regulation (hereinafter: GDPR).

    This privacy statement explains how we handle the processing of your personal data and what your rights are.

    1. Data Controller

    Preventa Health acts as an independent data controller for all personal data related to health that is collected via our platform, within the meaning of Article 4 GDPR.

    The employer purchasing our services (the "Organization") acts solely as a data controller for employee contact details and data relating to participation/logistics. Preventa and the Organization are not joint controllers.

    2. What Data We Collect

    We collect the following categories of personal data:

    Identity data:

    Name, email address provided by you or (with your consent) by your employer.

    Health screening data:

    Biomarker test results, pre-test measurements (blood pressure, glucose, body measurements), responses to health questionnaires, and derived health insights. These are special categories of personal data as defined in Article 9 GDPR.

    Engagement survey data:

    Responses to the Preventa Work Engagement Survey (P-PRI), domain scores, and composite risk scores.

    Technical data:

    Authentication session tokens and language preferences stored in your browser's localStorage.

    If you have questions about how we use this data to generate the recommendations sent to you, you can contact us at contact@preventa-health.com.

    3. Whose Personal Data Do We Process?

    We process personal data of the following groups:

    • Participants in our preventive medical screenings
    • Individuals requesting information about our services
    • External parties (such as medical professionals supporting service delivery)

    4. Legal Basis for Processing

    We process your personal data based on the following legal grounds:

    Explicit consent:

    For all health screening data, biomarker results, and responses to health questionnaires. Participation in our services is entirely voluntary.

    You may withdraw your consent at any time without adverse consequences via the Consent Management section of your employee dashboard. Withdrawal does not affect the lawfulness of processing prior to withdrawal. You can withdraw consent by emailing privacy@preventa-health.com.

    Legitimate interest:

    For platform security, fraud prevention, and service improvement using non-medical technical data.

    Personal data collected in the context of our services is never shared with third parties, including your employer. This also applies if the employer terminates its cooperation with us.

    5. Purposes of Processing

    We use your data for the following purposes:

    • Contacting individuals who have shown interest in our services
    • Providing personalized health screening results and scientifically grounded recommendations
    • Generating anonymized, aggregated health reports for your employer (minimum group sizes are applied to prevent re-identification)
    • Complying with applicable laws and regulations

    6. Retention Periods

    We do not retain your data longer than necessary for the purposes of processing and comply with applicable laws and regulations.

    We retain your data for the following periods:

    • Biomarker test results: 2 years
    • Health insights & survey responses: 2 years
    • Audit logs: 7 years
    • Expired survey tokens: 30 days
    • Account data: duration of the contract + 2 years

    Automated retention policies ensure timely deletion. Upon withdrawal of consent, your health data will be deleted as soon as possible, unless retention is legally required.

    7. Security

    We have implemented appropriate organizational and technical measures to protect your data. Our servers are protected by a firewall and regularly scanned for malware. Access to personal data is restricted to individuals who require it. Access is logged. These measures aim to prevent unauthorized access to personal data.

    8. Reporting a Data Breach

    We handle your personal data with care. However, a data breach may occur, for example if data reaches the wrong person or is lost due to an error.

    Do you suspect a data breach? Please report it as soon as possible by emailing privacy@preventa-health.com. If necessary, we will contact you within 24 hours.

    9. Service Providers

    As an independent data controller, Preventa uses the following service providers:

    • Cloud infrastructure provider — Database hosting, authentication, and edge computing (EU, Ireland)
    • Email provider — Transactional emails (US, with EU Standard Contractual Clauses)

    All service providers are bound by data processing agreements in accordance with Articles 28 and 32 GDPR.

    10. Your Privacy Rights

    When we process your personal data, you have rights under the GDPR. You can exercise these rights by submitting a request via privacy@preventa-health.com. More information can be found on the website of the Autoriteit Persoonsgegevens.

    Right of access

    You have the right to access the personal data we process about you.

    Right to rectification

    You have the right to have your personal data corrected if it is inaccurate or incomplete.

    Right to erasure (right to be forgotten)

    Under certain circumstances, you have the right to have your data deleted.

    Right to restriction of processing

    You have the right to temporarily restrict the processing of your personal data.

    Right to object

    You may object to further processing of your data. We must then cease processing.

    Right to data portability

    You have the right to receive a copy of your data in a structured, commonly used, machine-readable format.

    Complaints

    If you have questions or complaints, you can contact the privacy advisor at privacy@preventa-health.com. If your complaint is not satisfactorily resolved, you can contact the supervisory authority.

    11. Supervisory Authority

    You have the right to lodge a complaint with a supervisory authority (Art. 13(2)(d) GDPR). Since Preventa Health B.V. is established in the Netherlands, the lead supervisory authority is:

    Autoriteit Persoonsgegevens
    Bezuidenhoutseweg 30
    2594 AV The Hague
    autoriteitpersoonsgegevens.nl

    12. Contact

    For questions about this privacy statement or other privacy-related matters, please contact our privacy advisor via:

    privacy@preventa-health.com