In this comprehensive privacy statement, you will find more information about how AssurCard processes your personal data.
Who are we?
AssurCard NV is a service company that facilitates communication between insurers and hospitals. We ensure that your hospital invoice is sent directly to your insurer, so you don’t have to worry about advance payments. Our computerised third-party payer system makes the process simple and reliable: insurers and medical service providers work through one uniform procedure, saving time and effort for all parties.
Contact details
Address: Nieuwlandlaan 111 bus 103, 3200 Aarschot
Email: privacy@assurcard.be
AssurCard fulfils two different roles in the processing of personal data:
Controller: For certain processes, such as recruitment, account and asset management, internal IT support, web application management and hosting, we determine the purpose and means of processing ourselves. In these cases, we are responsible for compliance with the GDPR.
Processor: For other processes, such as helpdesk, card creation, insurance administration (claims, invoicing, payment follow-up) and access management of web applications, we process personal data solely on behalf of a controller. This may be a hospital or insurer.
Important: For processing activities where AssurCard acts as a processor, you must exercise your rights with your controller. We support them in handling your request correctly. More information on how these data are processed can be found in their Privacy Policy.
Why do we process your personal data?
AssurCard as Processor
We process your personal data because we have been instructed to do so by the controller, usually a hospital or insurer.
AssurCard as Controller
Staff-related processing
AssurCard is the controller for several processes related to managing our staff, such as personnel administration, evaluations, training and internal IT support. These are not included in this privacy statement, as they are only relevant to our employees. Once you join AssurCard, you will receive a separate privacy statement explaining these processes and your rights in detail.
Which data do we process as controller and why?
In addition to staff-related processing (explained in a separate privacy statement), AssurCard also processes data as controller for the following processes:
Recruitment
- Data: Identification details (name, contact information), CV, cover letter, education and work experience.
- Purpose: Assessing suitability for a role and communication during the application process.
Account management
- Data: Identification details of stakeholders (hospitals, medical service providers and insurers).
- Purpose: Managing accounts and relationships with AssurCard stakeholders.
Web application management
- Data: Technical and security logs, user and access data.
- Purpose: Managing, supporting and securing the AssurCard application, including access control, monitoring and troubleshooting.
Hosting
- Data: Identification details.
- Purpose: Hosting the web application and ensuring availability and security.
Legal basis for processing
For each processing activity described above, the legal basis is legitimate interest. This interest lies in providing our services correctly and efficiently, such as facilitating communication between insurers and hospitals, managing accounts and maintaining our web applications.
Source of the data
The personal data we process come from the data subject themselves, via direct communication, use of our applications or in the context of cooperation with hospitals and insurers.
Sharing with third parties
We do not share your personal data with third parties unless strictly necessary to achieve the purposes described above. If data is transferred to third parties, we ensure appropriate safeguards.
Data retention
We do not process your personal data longer than necessary for the purposes set out in this policy.
We keep your data as long as you are an active contact (customer, lead, etc.) and actively delete your data three years after you become inactive, except for legally required minimum retention periods.
Security of your data
AssurCard takes appropriate technical and organisational measures to protect your personal data against loss, misuse, unauthorised access or disclosure. These measures include:
- Encryption of data during transmission and, where appropriate, at rest.
- Strict access control and authentication.
- Logging and monitoring of systems.
- Regular security audits and updates.
Transfers to third countries
We generally process your personal data within the European Economic Area (EEA). If transfer outside the EEA is necessary, we ensure appropriate safeguards, such as:
- EU Standard Contractual Clauses.
- Additional technical and organisational measures to protect your data.
We inform our customers and data subjects in advance when such transfers occur.
What are your rights and how can you exercise them?
If you have a complaint, question or issue regarding how we use your personal data, please contact our DPO via privacy@assurcard.be.
If you contact us to exercise your rights, we will respond within one month. In exceptional cases, this may take longer (up to a maximum of three months), but we will inform you within one month why. Whether you can exercise your rights depends on the processing and the legal basis.
Make sure it is clear which right you want to exercise and how you wish to receive the information (e.g., by email, post, orally). Note that we may need more information to ensure we are helping the correct person.
Your rights include:
- Right of access: You can ask us about the personal data we hold about you. We can provide a free copy, but not for all documents, as we must respect the rights and freedoms of others.
- Right to rectification: If you believe your data is incorrect or outdated, you can ask us to correct it.
- Right to object: You can ask us to stop processing your personal data.
- Right to restriction: You can ask us to limit processing, for example, while we verify the accuracy of your data.
- Right to erasure: You can ask us to delete your personal data. If we are legally required to keep certain data, we cannot comply.
- Right to withdraw consent: For processing based on your consent, you can withdraw it at any time.
- Right to lodge a complaint: If you believe the processing of your personal data violates applicable data protection regulations, you have the right to lodge a complaint with the Data Protection Authority (GBA):
Data Protection Authority
Drukpersstraat 35
1000 Brussels
contact@apd-gba.be