Caro App Privacy Statement

For patients · Patient App B.V. (Caro Health) · Version 2.0, August 2026

Caro is an app that supports you during your treatment or recovery. You use Caro because your hospital or clinic offers it to you. Below we explain in plain language what happens with your data and how we protect it.

Important: your healthcare provider decides which data is used in Caro and why. They are the “controller”. Caro only processes your data on your provider’s instructions. For the full picture, also read your own healthcare provider’s privacy notice.

Who is responsible for your data?

Your healthcare provider — the hospital or clinic treating you — decides which data is used in Caro and why. Through your arrangements with your provider, they engage Caro to process your data. So Caro (Patient App B.V.) processes your data on your provider’s instructions, under a data processing agreement. A few things Caro decides itself; you can read those further on.

Caro: Patient App B.V. · H.J.E. Wenckebachweg 123, 1096 AM Amsterdam, The Netherlands · privacy@caro.health. Our Data Protection Officer oversees this and can be reached at privacy@caro.health.

What data does Caro process?

  • Who you are: name, date of birth (optional), contact details.

  • Your treatment: type and location of treatment, appointments, symptoms, pain scores, questionnaires and recovery progress.

  • Messages between you and your care team.

  • How you use the app: which parts you view and complete.

  • Technical data needed to run the app and send you notifications.

Some of this is health data. It is extra sensitive, so we handle it with extra care.

What does Caro use your data for, and on what ground?

For your care, Caro processes your data on your provider’s instructions. Your provider has a legal ground for this — usually the provision of care (Art. 9(2)(h) GDPR). Caro adds no purpose of its own.

A few things Caro does decide itself. Caro is responsible for those:

  • keeping the app secure and preventing misuse (legitimate interest);

  • analytical purposes using anonymised data that can no longer be traced to you (legitimate interest);

Does Caro use artificial intelligence (AI)?

Yes. Caro uses AI to support your care team, for example to prepare information or content. A human — your healthcare professional — is always involved. Caro makes no automated decisions about your treatment or care. Decisions about your care are always made by your healthcare professionals.

Who might Caro share your data with?

With your care team, through your healthcare provider. And with suppliers Caro engages to run the app — all under a data processing agreement:

  • storage and hosting: AWS and MongoDB Atlas (within the EU);

  • push notifications on your phone: Google Firebase;

  • text messages: Spryng (within the EU);

  • AI features: Orq.

Caro never sells your data and does not use it for advertising.

Does your data stay in Europe?

Your health data is processed and stored within the European Economic Area (EEA). For push notifications we use Google Firebase; limited technical information may go to the United States, with appropriate safeguards (Standard Contractual Clauses). For AI features that involve your data, we use European (Azure) models.

How does Caro protect your data?

Caro is ISO 27001 and NEN 7510 certified — recognised standards for information security in healthcare. We encrypt your data, give access only to those who genuinely need it, and have our security tested regularly.

How long is your data kept?

Your healthcare provider decides how long your health data is kept; they follow the statutory retention periods for medical records. Caro keeps your data for as long as needed to provide the app and for as long as your provider instructs. At your provider’s request we delete or anonymise your data.

Cookies and statistics in the app

Caro uses only technical data needed to run the app and send you notifications. For statistics we use a privacy-friendly method that builds no profile of you and does not track you across other apps or websites. You do not need to accept anything for this.

Children’s data

Is the patient under 16, or under legal guardianship? Then a parent or legal representative acts on the patient’s behalf. Your healthcare provider arranges the necessary consent.

What rights do you have?

Your data stays yours. You may access, correct or delete your data, and you may object to or restrict the processing. Because your healthcare provider is responsible for your health data, you exercise these rights through your provider. If you send your request to Caro anyway, we will help you and pass it on to your provider.

A question or complaint?

For questions about your health data, contact your healthcare provider. For questions about Caro itself, email privacy@caro.health. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).

Changes

We may update this statement. The latest version is available in the app.

Want to know more about how Caro can work for you?

Effective care requires innovative solutions. Discover what we can achieve together.