Cookie Policy

Patient App B.V. (Caro Health) Cookie Policy

Last updated: 18-09-2026

1. Introduction

This is the Cookie Policy (the "Policy") of Patient App B.V., also registered as Caro Health, with registered office at H.J.E. Wenckebachweg 123 in Amsterdam, registered with the Chamber of Commerce under number 71943765 ("we", "us" or "Caro Health"), accessible via https://www.caro.health. To ensure this site functions properly, we and third parties engaged by us place small data files, called cookies, on your device. These cookies improve your user experience and serve other purposes as described below. Caro Health is the data controller (Article 4, sub 7, GDPR) for the processing of personal data via cookies on this website.

2. What are cookies?

Cookies are small text files that are stored on your device. They remember, for example, login details, preferences or language settings. There are two types of cookies:

  • Session cookies: expire as soon as you close your browser.

  • Persistent cookies: remain active until they expire or are deleted.

In addition to cookies, we also use similar techniques, such as tracking pixels and local (HTML/browser) storage. Where "cookies" are mentioned in this Policy, this also refers to these types of similar techniques.

3. How we use cookies

We use cookies to:

  • Allow essential functions to work (Necessary cookies; in the cookie banner: “Necessary”)

  • Remember your preferences (Preference cookies; in the cookie banner: “Preferences”)

  • Analyse visitor behaviour (Statistics cookies; in the cookie banner: “Statistics”)

  • Enable lead generation (Marketing cookies; in the cookie banner: "Marketing")

Cookies are managed by us and, in some cases, by trusted third parties. The category names above correspond to the categories you see in the cookie banner on our website. The banner currently displays these in English (Necessary, Preferences, Marketing, Statistics); when the banner language in Cookiebot is set to Dutch, we show the Dutch names here (Noodzakelijk, Voorkeuren, Marketing, Statistieken).

4. Legal basis for the use of cookies

The following legal bases apply to the placement of cookies and similar techniques:

  • Necessary cookies: exempt from the consent requirement under Article 11.7a paragraph 3 of the Telecommunications Act, as they are strictly necessary for the functioning of the website or for a service explicitly requested by you (such as remembering your cookie preferences).

  • Preference and statistics cookies: we request your prior consent for these based on Article 6 paragraph 1 sub a GDPR, in combination with Article 11.7a paragraph 1 of the Telecommunications Act. These cookies are only placed if you have given consent via the cookie banner. You can withdraw your consent at any time (see chapter 5). For Google Analytics cookies, this is not yet fully configured in this way (see chapter 6); this is being resolved.

  • Marketing cookies: your consent is required based on Article 6 paragraph 1 sub a GDPR, in combination with Article 11.7a paragraph 1 of the Telecommunications Act. For Leadfeeder cookies, this is not yet fully configured in this way (see chapter 6); this is being resolved.

5. Your choice and cookie management

You can manage or delete cookies through your browser settings. In addition, we use a cookie banner (powered by Cookiebot/Usercentrics) that allows you to make a choice upon your first visit via the buttons “Allow all”, “Allow selection” or “Deny”. Please bear in mind the following:

  • Necessary cookies cannot be disabled.

  • You can give consent and change your settings via the cookie banner during your first visit.

  • You can withdraw or change your consent at any time via the black round button at the bottom left of the website. After consent is withdrawn, previously placed cookies and similar identifiers (including local storage) of the relevant category are also deleted.

6. Types of cookies we use

The overview below shows the cookies and similar techniques actually placed or executed on caro.health. The “Retention period” column indicates the lifespan of the cookie itself on your device; this is not in all cases identical to the period for which the underlying data is kept by the provider — for this, please see the privacy policy of the respective provider (chapter 7). This overview is updated periodically; the most recent version is always available on this page.

Necessary cookies

Cookie

CookieConsent

Provider

caro.health

Type

HTTP

Retention period

1 year

Purpose

Stores your consent status (cookie preferences) for this domain.

Preference cookies

Cookie

intercom.intercom-state-#

Provider

caro.health / js.intercomcdn.com

Type

HTML

Retention period

Permanent

Purpose

Temporarily stores chat function data and visitor data in your browser’s web storage so the chat (Intercom Messenger) continues to load correctly after you navigate to another page.

Cookie

intercom-device-id-#, intercom-id-#, intercom-session-#

Provider

caro.health / Intercom

Type

HTTP

Retention period

9 months (device-id-#, id-#) / 1 week (session-#)

Purpose

Identify you and your device for the chat function (Intercom): intercom-id-# links you to your conversations in the chat, intercom-session-# keeps you, as a logged-in user, able to access your previous conversations, and intercom-device-id-# identifies your device for security reasons.

Statistics cookies

Cookie

_ga, _ga_#

Provider

caro.health (Google Analytics)

Type

HTTP

Retention period

2 years

Purpose

Send data to Google Analytics about your device and behaviour and track you across multiple devices (_ga_# is a property-specific variant of _ga).

Even if you refuse, Google may receive a limited, cookieless signal via “Consent Mode” (without a cookie or client ID) for aggregated measurements. This is a technical signal for which no consent is required.

Marketing cookies

Cookie

_lfa, _lfa_expiry, _lfa_test_cookie_stored and two unnamed tracking pixels (tr.lfeeder.com and tr-rc.lfeeder.com)

Provider

caro.health, sc.lfeeder.com, tr.lfeeder.com and tr-rc.lfeeder.com (Leadfeeder / Dealfront)

Type

HTTP, HTML (local storage) and pixel

Retention period

_lfa: 1 year (HTTP) and permanent (local storage); _lfa_expiry: permanent; _lfa_test_cookie_stored: session; pixels: session

Purpose

Account-Based Marketing (ABM): records, among other things, your IP address, the time you spend on the website and the pages you request, in order to recognise visiting organisations, compile statistics about them and use these data for B2B marketing and retargeting.

Similar techniques without a cookie

Cookie

— (no cookie)

Provider

Framer, Inc. (events.framer.com)

Type

HTTP pixel/POST

Retention period

N/A (no cookie or local storage; one-time server registration per page view)

Purpose

Website hosting and website analytics by our provider Framer: records that a page has been viewed, both before a choice in the cookie banner and after an explicit refusal. No cookie is placed and no lasting identifier is created. Your IP address and browser details (user agent) are read, but immediately converted into an irreversible code using a key that changes daily and is deleted at the end of each day. According to Framer, the data are thereby fully anonymised and cannot be traced back to you. Framer uses this to measure, among other things, page views, unique visitors per day, visit duration, bounce rate and the origin of your visit. We include this here because it falls under tracking pixels as defined in chapter 2 of this Policy.

7. Third-party cookies

We use cookies and similar techniques from the following third parties, among other things for chat and analytics.

  • Google Analytics (statistics) – Google cookie policy

  • Cookiebot / Usercentrics (cookie banner and consent registration) – Cookiebot privacy policy

  • Intercom (chat function) – Intercom cookie policy (visible and active once you accept cookies for the Preferences/Statistics category; if you refuse or before a choice is made, the chat function does not load)

  • Framer, Inc. (website hosting and website analytics via events.framer.com) – Framer privacy policy (see framer.com)

  • Leadfeeder / Dealfront (marketing and lead generation) – Dealfront privacy policy

These parties process these data solely as a processor for Caro Health, on the basis of a data processing agreement concluded with them. They may not use the data for their own purposes. Leadfeeder/Dealfront combines your IP address with company data from its own database. That is done on our instructions and solely for the purpose of establishing which organisation visits our website.

Which data are collected via which cookie, for what purpose and how long they are retained, can be found in chapter 6. More about transfers of personal data outside the EEA is set out in chapter 8.

8. Transfer of personal data outside the EEA

Some of the providers mentioned above are (also) established outside the European Economic Area (EEA). When personal data are transferred to the United States via cookies, we ensure that this takes place on the basis of a valid transfer mechanism under the GDPR, such as the recipient’s participation in the EU-US Data Privacy Framework (DPF) or the use of Standard Contractual Clauses, supplemented where necessary with additional technical and organisational measures.

We periodically check the certifications listed below, at least annually, against the official DPF list. Last checked on: 18 September 2026, by: Data Protection Officer (DPO). At that time the following applied:

  • Google (statistics): the data are transferred to the United States. Google LLC is certified under the EU-US Data Privacy Framework.

  • Intercom (chat function): the data are transferred to the United States. Intercom, Inc. is certified under the EU-US Data Privacy Framework.

  • Leadfeeder / Dealfront (marketing): the data are transferred to the United States. Dealfront is not certified under the Data Privacy Framework; this transfer takes place on the basis of Standard Contractual Clauses.

  • Cookiebot / Usercentrics (cookie banner): consent data are stored within the European Union. For the performance of the service, Usercentrics also engages one party in the United States; that party is certified under the EU-US Data Privacy Framework.

  • Framer (website hosting and website analytics): insofar as personal data are processed outside the EEA in connection with this service, this takes place on the basis of a valid transfer mechanism as set out in the data processing agreement with Framer.

You can request a copy of the Standard Contractual Clauses used via privacy@caro.health.

9. Changes to this policy

We may change this policy in the event of legal or technical changes. You can find the latest version on this page, with the date of the last update at the top.

10. Acceptance of this policy

Necessary cookies are always placed, because the website cannot function without them. For all other (non-necessary) cookies we request your prior active consent via the cookie banner. By clicking “Allow all” or “Allow selection”, you give consent for the placement of the cookie categories you selected, as described in this Policy. If you click “Deny” or close the cookie banner without making a choice, we only place necessary cookies. You can also use the website if you refuse non-necessary cookies. This may affect certain functionalities, such as the chat function.

11. Your rights

For more information about how we handle your personal data, including your rights as a data subject (such as the right of access, rectification, erasure and objection), we kindly refer you to our privacy statement. It contains detailed information about how we process personal data, the legal bases we rely on and how you can contact us with privacy-related questions.

You can view the privacy statement here: https://www.caro.health/en/veiligheid/privacy-statement.

Specifically with regard to cookies, you have at least the following rights:

  • You can withdraw your consent for non-necessary cookies at any time, in the same simple way as you gave it. Withdrawing your consent does not affect the lawfulness of processing before the withdrawal.

  • You have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), if you believe that the processing of your personal data via cookies is contrary to the GDPR.

  • In addition, you have the rights described in our privacy statement, including the right of access, rectification, erasure, restriction, portability and objection.

12. Contact

For questions you can contact our Data Protection Officer by sending an email to privacy@caro.health.

Want to know more about how Caro can work for you?

Effective care requires innovative solutions. Discover what we can achieve together.