Fellos B.V.
Privacy Policy
Version: 1.0
Last updated: May 29, 2024
Identity and contact details
Fellos B.V.
Chamber of Commerce number: 93317336
VAT number: NL866352077B01
Website: www.fellos.nl
E-mail: [email protected]
Introduction
- The person responsible for this website is Fellos B.V. (”Fellos“,”we“,”us“or”our“), whose details can be found under the heading “identity and contact information”.
- Fellos is committed to protecting the privacy and personal information of our users. Fellos treats the personal data of customers and visitors with the utmost care and in compliance with relevant laws and regulations, including the General Data Protection Regulation (GDPR) and other applicable laws and regulations. This privacy policy describes how we collect, use, store and share personal information when you use our website www.fellos.nl (the”Platform“).
- The Platform connects customers with independent doctors with whom we work (the”Caregivers“). If you choose to place your orders through our partner pharmacy (the”Partner pharmacy“) to have it delivered, the Platform also connects customers to the relevant Partner Pharmacy. Please note that the Healthcare Providers and the Partner Pharmacy are jointly responsible for processing your personal data.
- By using the Platform and agreeing to the terms of this privacy policy, you consent to the processing of your personal data as described herein. If you no longer agree to the processing of your personal data as described in this privacy policy, this automatically means that you cannot (anymore) use the products and services on the Platform.
Personal data that we process
Fellos processes your personal data because you use our services and/or because you provide this information to us yourself. Each time you use the Platform, Fellos may collect personal data about you through the following activities:
- Registration process for the online account;
- Intake form for medical consultation;
- Online contact or consultation with your doctor via chat, audio or video calls;
- Purchasing medicines or other goods or services;
- Navigating and using the website; or
- Contact us by phone, text message, letter post or email.
We collect and process the following categories of personal data:
- Identification information: first and last name, date of birth and gender.
- Contact details: address details, email address and telephone number.
- Account details: username, password, login details.
- Communication data: emails, messages via the Platform or other data provided via the Platform or in correspondence.
- Health Information: health information, medical history, treatments, medication data, test results.
- Social Security Number: if our partner pharmacy declares the costs for your medicines from your insurer, the Social Security Number (BSN).
- Transaction details: information about your purchases, including purchase history. We do not process payment information, it is securely collected and processed by our payment processor.
- Technical data: IP address, location data, browser type, device type and identifier, log files, cookies.
- Information about your visit: information about which pages you view and which links you click, what route you take around the website, and what information you view or download.
- Additional information: information related to your use of the website and access to our services, such as marketing preferences, survey results, and feedback.
You must be 18 or older to use our website. We do not intentionally collect information from minors.
Special and/or sensitive personal data that we process
We recognize the particularly sensitive nature of health-related information (referred to as “special categories” of personal data). We take extra measures to ensure that this sensitive data is treated securely and confidentially. This information is only kept for the period necessary for the purposes for which it was collected. Fellos processes the following special categories of special and/or sensitive personal data about you:
- Sexual life
- health
- Social Security Number (BSN)
For what purpose do we process personal data
We process your personal data for the following purposes:
- Services: To provide you with sexual and dermatological health services and products; to connect you with Healthcare Providers for consultations and for Healthcare Providers to process your medical information.
- Basis for processing: Execution of an agreement (art. 6 paragraph 1 sub b GDPR) with regard to regular personal data, healthcare (art. 9 paragraph 2 sub h GDPR) with regard to the processing of medical data by our Healthcare Providers and explicit consent (art. 9 paragraph 2 sub a GDPR) with regard to special categories of personal data, unless covered by art. 9 paragraph 2 sub h GDPR.
- Account Management: To create and manage user accounts; provide customer service.
- Basis for processing: Performance of a contract (Art. 6 (1) (b) GDPR) and consent (Art. 6 (1) (a) GDPR).
- Purchase and Shipping: Managing purchases and delivering goods and services. To process your orders, fill your prescription and (at your request) deliver your medication to you from our Partner Pharmacy.
- Basis for processing: Execution of an agreement (art. 6 paragraph 1 sub b GDPR) with regard to regular personal data, healthcare (art. 9 paragraph 2 sub h GDPR) with regard to the processing of medical data by our Partner Pharmacy and explicit consent (art. 9 paragraph 2 sub a GDPR) with regard to special categories of personal data, unless covered by art. 9 paragraph 2 sub h GDPR.
- Communication: To communicate with you about the Fellos services or products that you have purchased (including notifying you when you receive a new message from your Healthcare Provider and sending you reminders), to provide you with shipping and tracking information, to provide customer service and/or to answer questions you have asked us or your Healthcare Provider. To call or email you if this is necessary to provide our services.
- Basis for processing: Performance of an agreement (Art. 6 (1) (b) GDPR) and legitimate interest (Art. 6 (1) (f) GDPR) with regard to regular personal data and explicit consent (Art. 9 (2) (a) GDPR) with regard to special categories of personal data.
- Marketing: To send you marketing or promotional material; to send you reminders about services or products in which you have expressed interest. If you have agreed, we may also use your medical information to send you marketing information that is tailored to you or that we think may be of interest to you.
- Basis for processing: Explicit consent (Art. 9 (2) (a) GDPR) with regard to special categories of personal data, consent (Art. 6 (1) (a) GDPR) with regard to regular personal data and legitimate interest (Art. 6 (1) (f) GDPR) in informing existing customers about similar, own products or services after a purchase.
- Online ads: We use online ads to keep you up to date with what we have to offer and help you see and find our products and services.
- Basis for processing: Legitimate interest (Art. 6 (1) (f) GDPR) in using your personal data to help us display relevant advertisements, provided that we have the right to do so.
- Improving services: Conducting customer satisfaction surveys; analyzing usage data to improve our services and promotional activities.
- Basis for processing: Legitimate interest (Art. 6 (1) (f) GDPR) or consent (Art. 6 (1) (a) GDPR) in improving our services.
- Legal obligations: Complying with legal obligations, such as data retention and reporting to government agencies.
- Basis for processing: Legal obligation (Art. 6 (1) (c) GDPR).
On what basis do we process personal data
Below is an explanation of the legal grounds on which we process your personal data:
- Consent (Art. 6 (1) (a) GDPR): When you have given your consent to the processing of your personal data for specific purposes.
- Explicit consent (Art. 9 (2) (a) GDPR): As far as special categories of personal data are concerned, if you have given explicit consent to their processing.
- Health care (Art. 9 (2) (h) GDPR): The processing of your data is necessary for medical diagnoses or the provision of health care or treatments that are processed by or under the responsibility of a healthcare professional, including the Healthcare Providers and (employees of) the Partner Pharmacy. We rely on this legal basis when your data is processed by or under the responsibility of the Partner Pharmacy or one of the Healthcare Providers.
- Execution of an agreement (Art. 6 (1) (b) GDPR): The processing of your personal data is necessary for the execution of an agreement you have with us or because we have asked you to take certain steps before entering into this agreement.
- Legal obligation (Article 6 (1) (c) GDPR): To comply with legal obligations to which we are subject.
- Legitimate interest (Art. 6 (1) (f) GDPR): For our legitimate interests, such as improving our services, unless your fundamental rights and freedoms outweigh.
consent
We obtain your explicit consent to the processing, in particular to collect and transfer (including to Healthcare Providers and the Partner Pharmacy) your medical information that you provide in the intake form, via the chat functionality or otherwise. You give this permission when you start the intake and agree to this privacy policy. If you decide not to let the Partner Pharmacy carry out your order, we will not share your medical information with them.
At the same time, you consent to the use of your medical or sensitive information to personalize the marketing that we send you in accordance with this Privacy Policy.
You have the right to withdraw your consent at any time.
Cookies, or similar techniques, that we use
At Fellos, we use cookies and similar technologies to improve your experience on our website, analyze the performance and functionality of our site, and provide personalized ads and content. This section describes our use of cookies and how to manage your cookie preferences.
Fellos uses essential, analytics, personalization, and marketing cookies. A cookie is a small text file that is stored in the browser of your computer, tablet or smartphone when you first visit this website. Fellos uses cookies with a purely technical functionality. These ensure that the website works properly and that, for example, your preferred settings are remembered. These cookies are also used to make the website work properly and to optimize it. In addition, we place cookies that track your surfing behavior so that we can offer customized content and advertisements. On your first visit to our website, we already informed you about these cookies and asked for your permission to place them. You can opt out of cookies by setting your internet browser so that it no longer stores cookies. In addition, you can also delete all information that was previously stored via your browser settings. For an explanation, see: https://veiliginternetten.nl/themes/situatie/cookies-wat-zijn-het-en-wat-doe-ik-ermee/. Cookies are also placed on this website by third parties. These include, for example, the social media companies.
What are cookies?
Cookies are small text files that are stored on your device when you visit our website. They help us recognize your device on recurring visits, remember your preferences, and analyze the use of Fellos for optimization purposes.
How do we use cookies?
- Essential Cookies: These cookies are essential for the functioning of our website and cannot be disabled. They provide basic functions such as page navigation and access to secure parts of the website.
- Analysis Cookies: These cookies collect information about how visitors use our website, which pages are visited most often, and whether there are any error messages. All information collected by these cookies is aggregated and therefore anonymous.
- Personalization Cookies: These cookies enable our website to provide improved functionality and personalization. They can be set by us or by third party providers whose services we have added to our pages.
- Marketing Cookies: These cookies are used to show ads that are more relevant to you and your interests. They are also used to limit the number of times you see an ad and to measure the effectiveness of advertising campaigns.
Managing cookie preferences
You have control over the use of cookies on our website. You can set your browser to refuse all cookies or to indicate when a cookie is being sent. However, disabling cookies may affect the functionality of our site and may prevent you from making full use of our services.
Sharing personal data with third parties
We use third parties to carry out our services and activities. Fellos does not sell your information to third parties and will only provide it if this is necessary for the execution of our services or to comply with a legal obligation. If personal data is processed here, this is based on a processing agreement, which sets out our principles for the protection and security of personal data. Below, we explain who we share your data with, why it is necessary and under what conditions this happens:
- Partner pharmacy: To ensure that you can receive the medication you need, we share relevant personal data with our partner pharmacy. This includes sharing your prescriptions and any other necessary medical information. In addition, we can use this data to check for countermedication via the national switching point (LSP). This ensures that the medication is safe to use in combination with other medications you may be taking.
- Caregivers: For optimal treatment, it is sometimes necessary to share your medical data with your treating doctor. This enables your doctor to get a complete picture of your health situation and to adapt the treatment accordingly. This includes providing your patient data as part of the online questionnaire, if you have given your consent.
- Payment processor: To handle your payments securely and efficiently, Fellos works with Stripe. When you make a purchase on our website, your payment information (such as credit card or bank details) is processed directly by Stripe. Fellos does not have access to these payment details. Stripe processes your information in accordance with their own privacy policy and the highest security standards.
- Statutory bodies: If we are legally obliged to provide personal data to government agencies or supervisory authorities.
- Third-party advertising services: We may share your personal information with third parties that we work with to provide us with customized advertising services.
- Service Providers: We share your personal information with various third parties that we depend on to perform a variety of services on our behalf and to grow and improve Fellos' business, including: IT service providers (including cloud IT service providers, such as Amazon Web Services), payment system operators (such as Stripe), courier companies to deliver your orders (such as PostNL), and any other organizations that provide us with technical and support services.
Transfer of data to a third country
Fellos strives to minimize the transfer of personal data outside the EU. From time to time, we may transfer your personal data to parties outside the EU.
In particular, we may transfer your personal information to third party service providers with servers in the United States for the purposes set out above, namely:
- Webflow, based on standard contractual clauses approved by the European Commission for the transfer of personal data to third countries, a copy of which we can provide you with upon request. We only share technical data and information about your visit with Webflow.
When we transfer personal data outside the EU, we ensure that it is adequately protected. We do this by transferring your information to countries that the EU believes offer substantially equivalent protection, or by entering into EU-approved standard contractual clauses with the relevant party.
Comply with personal data processing principles
Fellos processes personal data in accordance with the six basic principles of the General Data Protection Regulation (GDPR). These principles are at the core of our data processing practices and ensure that we handle personal data carefully and responsibly.
1. Legality, Fairness and Transparency
Legality: We process personal data only on a valid legal basis, such as consent from the person concerned, the execution of an agreement, a legal obligation, or our legitimate interest.
Fairness: We treat personal data fairly and transparently. This means that we communicate clearly about how we collect, use and share data.
Transparency: We inform data subjects in an understandable and accessible way about the processing of their personal data through our privacy policy and other communication channels.
2. Purpose limitation
We collect and process personal data only for specific, explicit and legitimate purposes that have been clearly communicated to the person concerned. Personal data will not be further processed in a way that is incompatible with these purposes.
Examples of these purposes include: facilitating medical care, managing user accounts and improving our services.
3. Data minimization
We do not process more personal data than is necessary for the purposes for which it is collected and processed. This means that we only collect data that is relevant and limited to what is necessary for the purposes in question.
We regularly review our data collection practices to ensure that we do not collect redundant or irrelevant data.
4. Accuracy
We ensure that the personal data that we process is accurate and up to date. Inaccurate or outdated data will be corrected or deleted immediately.
Data subjects have the right to have inaccurate personal data corrected and we have procedures in place to effectively ensure this right.
5. Storage limitation
We do not keep personal data longer than necessary for the purposes for which it was collected, or as required by laws and regulations.
For example, medical data is stored in accordance with the legal retention periods for medical records. As soon as personal data is no longer required, it is securely deleted or anonymized.
6. Confidentiality and Integrity
We take appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, and against accidental loss, destruction or damage.
These measures include encryption, access restrictions and secure communication channels.
How we protect personal data
Fellos takes the protection of your data very seriously and takes appropriate measures to prevent misuse, loss, unauthorized access, unwanted disclosure and unauthorized modification or destruction. If you feel that your data is not properly secured or there are indications of abuse, please contact our customer service or via [email protected]. Fellos has taken, but is not limited to, the following organizational and technical measures to protect your personal data:
Access control:
Access to personal data is limited to authorized employees and third parties who need this information to perform their tasks.
Strict access control measures, such as role-based access rights and two-factor authentication, to prevent unauthorized access.
Encryption:
Data is encrypted both during transmission and at rest to ensure the confidentiality and integrity of the personal data.
Use of strong encryption protocols to protect data.
Secure connections:
We send your data via a secure TLS internet connection. You can see this in the 'https' address bar and the padlock in the address bar.
DNSSEC is an extra security (additional to DNS) for converting a domain name (www.fellos.nl) to the associated IP address; it is provided with a digital signature. You can have that signature checked automatically. This way, we prevent you from being redirected to a false IP address.
Safe application development:
Applying safe development practices to design and build our software and applications.
Regular security tests and code reviews to identify and address potential vulnerabilities.
Backups and recovery:
Regular data backups to prevent loss of personal data in the event of an incident.
Implemented recovery procedures to ensure the continuity of our services in the event of a failure or data breach.
Secure communication channels:
Use of secure communication channels for the transfer of personal data. Communication with our partner pharmacy takes place via secure portals and/or via the secure Enovation ZorgMail network.
Protecting our network infrastructure from external threats using advanced security technologies.
DKIM, SPF and DMARC are three internet standards that we use to prevent you from receiving emails on our behalf that contain viruses, are spam or are intended to obtain personal (login) data.
Monitoring and logging:
Active monitoring of our systems and networks to detect suspicious activity and respond to potential security incidents.
Logging access to personal data to enable accountability and supervision.
Fellos is constantly reviewing and improving our security measures to ensure that your personal data is protected in the best possible way.
Patient and Consumer Rights
1. Right to view
You have the right to request access to the personal data that Fellos processes about you. This includes information about the purposes of the processing, the categories of personal data involved, and the recipients or categories of recipients to whom the personal data has been or will be provided.
2. Right to rectification
If you discover that the information we hold about you is inaccurate or incomplete, you have the right to request that we correct or supplement this information.
3. Right to be forgotten
In certain circumstances, you have the right to request Fellos to erase your personal data. This right applies when the data is no longer necessary for the purposes for which it was collected, you withdraw your consent, you object to the processing, or when the data has been processed unlawfully.
4. Right to restrict processing
You have the right to request that the processing of your personal data be restricted. This right applies in specific cases, such as when you dispute the accuracy of the data, the processing is unlawful, or you have objected to the processing.
5. Right to data portability
You have the right to receive the personal data that you have provided to Fellos in a structured, commonly used and machine-readable form. You also have the right to transfer this information to another person responsible, without hindering Fellos.
6. Right to object
You have the right to object to the processing of your personal data at any time on grounds related to your specific situation. This right applies in particular to data processing based on legitimate interests or the performance of a task in the public interest.
7. Right to withdraw consent
Where the processing of your personal data is based on consent, you have the right to withdraw this consent at any time. Withdrawing consent does not affect the lawfulness of processing based on consent prior to its withdrawal.
Exercising your rights
To exercise any of these rights, you can contact us using the contact details provided in this Privacy Policy or on our website. To ensure that the request for inspection has been made by you, we ask you to send a copy of your ID with the request. In this copy, make your passport photo, MRZ (machine readable zone, the strip with numbers at the bottom of the passport), passport number and social security number (BSN) black. This is to protect your privacy. We will respond to your request within a reasonable time and in accordance with applicable law.
Fellos would also like to point out that you have the opportunity to file a complaint with the national supervisory authority, the Data Protection Authority. This can be done via the following link: https://autoriteitpersoonsgegevens.nl/nl/contact-met-de-autoriteit-persoonsgegevens/tip-ons
At Fellos, we are committed to protecting your privacy and respecting your rights. If you have any questions or concerns about the processing of your personal data, please do not hesitate to contact us.
How long we keep personal data
We do not keep your personal data longer than is strictly necessary for the purposes for which it was collected or as required by applicable law. The personal data collected will be kept as long as you have registered to use (among other things) the Platform. Thereafter, the collected data may be stored for historical, statistical or scientific purposes, in which case Fellos will endeavor to keep it in a form that no longer allows you to be identified. Medical data is stored in accordance with the legal retention periods for medical records.
Privacy Policy Changes
We reserve the right to change this privacy policy. We will notify you of any material changes via the Platform or by email. It is recommended that you review this privacy policy regularly to stay informed about how we process your personal data.
Contact
For questions, comments, or complaints regarding this Privacy Policy or our data processing activities, please contact us at: [email protected].
We strive to answer and resolve your questions and complaints within a reasonable period of time.


.svg.png)