Privacy Policy
Who we are
Vima is a Belgian software company that provides planning and care administration software to care organisations and independent care providers. This policy explains how we process personal data and which rights you have.
Our two roles under the GDPR: read this first
For data of website visitors, prospects and customer contacts, Vima acts as the controller. For data that customers enter into the software, such as data about care users, Vima acts as a processor and follows the customer’s instructions only.
Processing for which we are the controller
As controller, we process data to answer enquiries, perform contracts, invoice and improve our services. The legal bases are the performance of a contract, legal obligations, our legitimate interest and, where required, your consent. We keep this data no longer than necessary for the purpose, taking statutory retention duties into account, such as the accounting retention period.
Processing for which your care provider is responsible (we act as processor)
Care data entered into the software remains the responsibility of the customer as controller. The customer decides which data is processed and informs the individuals concerned. The customer may use eID or national-register data only where legally authorised to do so and remains responsible for that use. When the trial period expires, we send an email stating the exact deletion date together with links to export or activate. The data remains exportable until exactly 60 calendar days after the end of the trial period. After that, we delete the data from our active systems.
Minors and representatives
Our website and commercial services are not directed at minors. A parent or representative may book an appointment, and a minor may also book themselves. The care practice decides on representation, capacity and the applicable legal basis; Vima processes this data solely on the customer’s instructions.
Recipients of your data
We share personal data only with carefully selected service providers, such as hosting and email providers, and with authorities where the law requires it. Where a provider acts as a processor, we conclude a data processing agreement with them. We never sell personal data.
Transfers outside the EEA
Personal data is in principle processed within the European Economic Area. If a transfer outside the EEA is necessary, it only takes place with appropriate safeguards, such as an adequacy decision or the European Commission’s standard contractual clauses, supplemented with additional measures where needed.
Security
We take appropriate technical and organisational measures, including encrypted data transmission, restricted access to data and backups. Our staff are bound by confidentiality.
Your rights
You have the rights of access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on consent, you may withdraw it at any time. You exercise your rights by contacting us; we respond within the statutory deadlines.
Complaints
If you are unhappy with how we handle your data, please contact us first. You may also lodge a complaint with the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels.
No automated decision-making
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
Changes, applicable law and contact
We may update this policy when our services or regulations change. The current version is always available on this page; we inform our customers of significant changes.