Privacy Statement

Patient App B.V. (Caro Health) · Version 2.0, June 2026 · replaces version 1.0 (6 June 2024)

Caro Health makes digital healthcare easier for patients and healthcare providers. Do you use our website caro.health, contact us or apply for a job with us? Then we process some of your personal data. Below we explain in plain language which data that is, why we use it, how long we keep it and what rights you have.

This statement is about our website, our business contacts and job applications. Do you use the Caro app as a patient, or the healthcare provider portal as a healthcare provider? Separate privacy statements apply to those.

Who are we?

We are Patient App B.V., better known as Caro Health. We determine which of your data is processed and why — in law this is called the "data controller". You can reach us here:

Patient App B.V. · H.J.E. Wenckebachweg 123, 1096 AM Amsterdam · KvK (Chamber of Commerce) 71943765 · info@caro.health · +31 (0)20 244 0361

Which group do we belong to? Caro Health is part of the HOPCo group, based in the United States. This does not affect the storage of or access to your data. Your data remains with Caro in the European Union. We do not share it with our parent companies in the United Kingdom or the United States, and they do not have access to it.

Our Data Protection Officer monitors on our behalf that we comply with privacy laws. Do you have a question about your data or do you want to exercise a right? Feel free to email her at privacy@caro.health.

Who does this statement apply to?

For:

  • visitors to caro.health;

  • business contacts at (potential) clients and partners;

  • people who contact us or request a demo;

  • job applicants.

Patients who use the Caro app and healthcare providers who use the portal can find their information in separate statements.

What data do we use, and why?

Per situation you can see which data we use and on what ground.

What for

Answering your question or arranging a demo (Cal)

Which data

Name*, email*, company*, your message

Ground

To carry out your request or make a quotation (lead-up to an agreement); or our legitimate interest to respond

What for

Maintaining contact with (potential) clients (Pipedrive)

Which data

Name*, email*, phone number, company, job title, conversation history

Ground

Execution of the agreement with your organisation; or our legitimate interest in customer management

What for

Sending you our newsletter or product updates (Intercom)

Which data

Name*, email*

Ground

Your consent; for existing clients our legitimate interest — you can unsubscribe at any time

What for

Making our website work, securing and improving it (Framer)

Which data

IP address, anonymised usage statistics

Ground

Our legitimate interest in a secure, well-functioning website

What for

Analysing and improving website visits (Google Analytics 4)

Which data

Cookie and device IDs, usage data (page views, clicks), anonymised location data

Ground

Your consent via the cookie banner for cookies and tracking; limited legitimate interest in performance and website analysis

What for

Helping you via the chat (Intercom)

Which data

Name, email, chat content, technical data

Ground

To help you at your request; or our legitimate interest in good support

What for

Processing your job application (Homerun)

Which data

Name*, email*, CV*, cover letter, work experience, education, interview notes

Ground

Your consent to process your application data; our legitimate interest in managing the recruitment procedure. With your consent, we keep your data for up to 12 months; without consent, we keep it for up to 1 month

What for

Invoicing (WeFact)

Which data

Name*, company name*, address*, Chamber of Commerce number*, VAT number*, type of subscription* and amount*

Ground

Legal obligation (including tax legislation)

What for

Signing contracts (PandaDoc)

Which data

Name*, email*

Ground

Execution of the agreement (signing contracts); or our legitimate interest in managing contractual documents

*This is mandatory information: without this data we cannot process your request, application or job application.

Do we rely on a "legitimate interest"? Then we always weigh that interest against the privacy of the person concerned, and we only use business contact details. We do not process special category data (such as health data) through this website.

Who processes your data — us or someone else?

We are responsible for everything in this statement. We do engage suppliers who process data on our behalf (for example for our CRM, hosting and statistics). We have a data processing agreement with each of them. Our patient platform is different: if we deliver it to a healthcare institution, that institution is responsible and we are their processor. That is stated in the privacy statement of that healthcare provider, not here.

Who do we share your data with?

Only where necessary, with:

  • our suppliers: Pipedrive (CRM), Intercom (chat/email), Google (Google Workspace — email, documents, calendar; Google Analytics — website statistics), Framer (website hosting), Homerun (recruitment), Cal (demo requests), WeFact (billing) and PandaDoc (signing contracts);

  • advisers, independent auditors and authorities, if required or permitted.

We do not sell your data and we do not use it for advertisements.

Does your data go outside the EU?

As much as possible, we keep your data within the European Economic Area (EEA). Pipedrive (CRM) and Homerun (recruitment) store your data within the EU. A few suppliers are based in the United States: Google (Workspace, Analytics), Intercom (chat), Framer (hosting) and PandaDoc (signing). For that transfer we use the EU-US Data Privacy Framework if the supplier is certified for it, and otherwise the standard contractual clauses (SCCs) of the European Commission — with extra safeguards. Want to know more? Email privacy@caro.health.

How long do we keep your data?

No longer than necessary. Specifically:

  • Business contact and CRM data: as long as we are in contact, and up to 180 days after a lead is closed. After that, we delete or anonymise it.

  • Contracts and invoices: 7 years. This is required by tax law (Art. 52 AWR).

  • Application data: with your consent, we keep your data for up to 12 months after the application (for example for a later vacancy); without consent, we keep your data for up to 1 month. After that, we ask for consent again or we delete your data.

  • Website statistics (Google Analytics 4): 2 or 14 months from your first visit to the website, depending on the retention setting we have chosen in Google Analytics.

  • Newsletter: until you unsubscribe. After that, we only remember that you no longer want emails.

Do we use cookies?

Only where really necessary.

  • Strictly necessary cookies make the website work properly (security, remembering your choices). No consent is required for these (Art. 11.7a Telecommunications Act).

  • Do you start a chat? Then Intercom places cookies to conduct that conversation. These are only placed once you open the chat yourself — so we do not need to ask for consent for that either.

  • For our website statistics we use Google Analytics 4. This tool places cookies and collects, for example, device IDs and anonymised location data. We ask for your consent for this first via our cookie banner (Cookiebot).

  • We do not use cookies for advertisements. You can withdraw or adjust your consent for cookies at any time — see our cookie statement for how that works.

Do we make automated decisions about you?

No. We do not make decisions about you that are made solely by a computer and affect you significantly. Your job application is assessed by people, not by an algorithm.

What rights do you have?

Your data remains yours. You can always ask us to:

  • see what data we have of yours (access);

  • correct errors or delete data;

  • restrict processing or object to it;

  • receive your data in a convenient file (portability);

  • withdraw your consent (what happened before that remains valid).

Email privacy@caro.health and we will respond within one month. If your question is complex, we may take an extra two months; we will let you know within the first month.

Not satisfied with how we handle your data?

Please let us know first via privacy@caro.health — we will gladly resolve it. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (autoriteitpersoonsgegevens.nl).

Data of children

caro.health is not intended for children aged 16 or under. If we do receive data from a child, we will delete it as soon as we know.

Changes

We may adjust this statement. We will announce important changes in good time. The latest version is always on caro.health.

Want to know more about how Caro can work for you?

Effective care requires innovative solutions. Discover what we can achieve together.