Skip to content Skip to sidebar Skip to footer

Customer Privacy Statement

Organization: Autism Academy
Date: February 24, 2026

Processing Customer Personal Data
Your privacy is very important to our organization. We comply with the European General Data Protection Regulation (GDPR). This regulation governs how your personal data should be processed. It also states that we must be able to demonstrate that we comply with the law. In this statement, we briefly explain our organization’s obligations and the rights of customers (or their representatives).

What does a privacy statement mean?

In short, we are obliged to explain what happens to your personal data. We explain which personal data we request, what we use it for, who uses it, and to whom we may provide the data. Our fundamental principle is to use personal data only when necessary and, of course, securely.

What (standard) data do we need from you and for what purpose?  General personal data (name, date of birth, marital status, etc.), contact information (including information of parents and/or legal guardians), insurance information, care products provided, social profile/network, medical and behavioral data, to the extent that it relates to determining the necessary care and services. We use this data for our business operations, correspondence and personal communication; in particular for maintaining services and ensuring external accountability for the care provided (billing to the healthcare provider, health insurance company and/or municipality), as well as for social networking and parent involvement.

 Customer/Relationship Number: We assign this number to each customer, and this number is unique to our care relationship with the customer.

 Citizen Service Number (BSN): We need this number to share customer-related data with healthcare providers, health insurance companies, municipalities and/or government and other care providers; in such cases, the use of this number is mandatory.

 Medical/specialist, behavioral, social, and nursing/support data. We use this data to identify, evaluate, monitor, and implement individual care and services.  The nature, date/duration, reason, and, if applicable, responsibility, or whether it is an emergency measure, of any restrictions or measures applied to the client. Recording this data is necessary to justify the restrictions or measures.  Description and nature of events affecting clients, measures taken, and injuries/harms. This data is necessary to maintain and optimize the quality of care provided to clients.  Definition and circumstances of (sexual) abuse related to a client, and measures taken against abuse. We need this information to establish our policy regarding (sexual) abuse (treatment, post-care, and prevention).  We may use the information mentioned above without requesting your specific consent, based on our agreement with you. Other personal data Data must always be collected for a defined purpose. We are not permitted to collect other private, particularly sensitive personal data (e.g., religion, sexual orientation, political preference, and race). In some cases, such as when a particular diet is involved, consent may be an exception. Passport photographs may also provide information about a person’s race, culture, or religion. If we wish to collect photographs for our own records or for publication elsewhere, consent may be used to facilitate this. Our institution also uses this method. You can withdraw your consent at any time. When our institution has a legitimate interest in collecting and recording data, this may be done without obtaining consent. For example, let’s consider aggressive behavior that our employees need to be aware of. How does our institution obtain personal data? A customer’s data may be obtained through digital messaging, other care providers, and/or customer/parents. The file/care plan is completed for the duration of the customer’s care at our institution.

Internal Use of Data
To protect your privacy as much as possible, we limit the internal use of personal data as much as possible. Only employees whose positions require them to use your data are permitted to do so. We ensure this by granting these employees specific authorizations for access to automated systems. Which functions are authorized is specified in our processing record in accordance with GDPR.

Confidentiality Obligation
All employees are subject to a strict confidentiality obligation and sign a confidentiality agreement upon joining our organization.

Data Security
Our organization takes appropriate technical and organizational measures to securely store your personal data and prevent unwanted actions with personal data. These measures comply with the security standards applicable to the healthcare sector, as specified in the NEN7510 standard.

Data Breach
Any data breach, regardless of its size, must be reported to the Dutch Data Protection Authority (www.autoriteitpersoonsgegevens.nl).

External Use of Data
Mandatory Transfer
Our institution is obligated to share data about necessary and provided care with healthcare organizations, health insurers and/or municipalities (declarations). This sharing takes place via secure connections. In exceptional circumstances, for example in the case of a criminal investigation, we may also need to provide data about you to other organizations.

Access by Software/Computer Program Suppliers
Our institution uses many computer programs for its business operations. Program suppliers support and maintain these programs; therefore, employees of these suppliers may also have access to personal data in these programs. For this purpose, we sign a data processing agreement obliging the supplier to process personal data with the same care as our institution itself.

Other Transfers Therefore, we only share data with third parties when it is necessary for the execution of the healthcare contract and compliance with any legal obligations. When we provide data to others, we do so only after obtaining your consent. How long do we keep your personal data? In accordance with the Medical Contracts Act (WGBO), our organization complies with the following retention periods: After the termination of the care relationship, unless changes are made (see last paragraph), the patient file is kept for 20 years. For data relating to restrictive measures, precautions, compulsion or obligations under the Care and Obligation Act (Wzd), a statutory retention period of 5 years applies. We do not retain other data for longer than necessary. We then delete the data as soon as possible. The retention period begins from the date of the last change made to the file. Your rights regarding your personal data As an organization, we are obliged to use the personal data of our customers. However, this personal data relates to the customer themselves. Therefore, the customer has the following rights: The right to access their personal data The right to have their data corrected if it is incorrect The right to transfer their data to other individuals or organizations Also, the right to request the deletion of data or to object to its processing, if legally possible The right to give consent for access rights to their surviving relatives during their lifetime To access your data, you can primarily use the customer portal in our digital system. If the customer portal does not provide complete information or the data appears incorrect, please contact your support representative or maintenance manager. They can help you access your data and, if necessary, ensure the file is completed or updated. For other questions, you can also contact your maintenance manager, the central maintenance administration office, or the help desk.

Right of Surviving Relatives to Access Surviving relatives have a legal right to access the file of a deceased client. Surviving relatives may access the file under the following circumstances: When the client gave permission while alive; When an incident notification is received under the Healthcare Quality, Complaints and Disputes Act (Wkkgz); On a compelling interest basis ‘for everyone’; Special access arrangements apply for the parents and guardians of a deceased child under the age of 16; 5. Obligation to Provide Information. Changes to the Privacy Statement Changes may be necessary to the Privacy Statement. Therefore, please always note the date above and check regularly for new versions. Our organization will also announce changes separately. Questions or Criticisms If you have any questions about your rights, are not satisfied with how we implement them, or have specific questions regarding the processing of your personal data, you may always contact us via our public email address or public number found on our website. Please clearly state who you are so that we do not alter or delete data belonging to the wrong person. We may also ask you to identify yourself and fill out a form. Reporting a Complaint If you believe that our organization has not processed your personal data correctly, you have the right to complain to us. How this works is explained in our complaint procedure, which you can find on our website. You can also always complain to the supervisory authority. This is the Dutch Data Protection Authority (www.autoriteitpersoonsgegevens.nl).