Skip to main content
VisioConsult

Legal

Privacy policy

Last updated: 1 September 2026

This policy describes the data VisioConsult processes, why, for how long, and the rights available to you.

1. Controller

The controller is [[SRL_DENOMINATION]], with its registered office at [[SRL_SIEGE]], registered with the Crossroads Bank for Enterprises under number [[SRL_BCE]].

For any question about this policy, or to exercise your rights: privacy@visioconsult.be.

2. Data we process

We process three categories of data, and nothing else.

  • Account data: surname, first name, email address, profession, language, password stored as a hash.
  • Billing data: plan chosen, payment history. Card data is processed directly by Stripe and is never stored by us.
  • Technical session data: session identifier, start and end timestamps, duration, connection IP address, browser type.

3. Data we do not process

No audio or video content is recorded, stored or analysed. The stream is end-to-end encrypted between participants.

We host no patient record, no clinical note and no medical document. That content stays with the practitioner, in their own tools.

4. Purposes and legal bases

  • Providing the service: performance of the contract with the practitioner.
  • Invoicing and accounting: legal obligation.
  • Security, abuse prevention and technical logging: legitimate interest.
  • Waiting list registration and notice of accounts opening: consent, withdrawable at any time.

5. Respective roles of the practitioner and VisioConsult

The practitioner is the controller for their patients' data. They decide who is invited, for what reason, and for how long.

VisioConsult acts as processor for the session data processed on their behalf. A data processing agreement is available on request.

6. Recipients and processors

We sell no data and share none for advertising purposes. Two processors are involved.

  • Amazon Web Services: hosting of the application and the databases, in European Union regions.
  • Stripe: payment processing and invoicing.

7. Transfers outside the European Union

Hosting stays in the European Union. Where processing by Stripe involves a transfer outside the Union, it is covered by the standard contractual clauses adopted by the European Commission.

8. Retention periods

  • Account data: for the duration of the subscription, then twelve months.
  • Session metadata: twelve months, then automatic deletion.
  • Invoices and accounting records: seven years, a period required by Belgian accounting law.
  • Waiting list registrations: until accounts open, then twelve months.

9. Security

The session stream is end-to-end encrypted. Traffic with the application runs over TLS. Administrative access is named and logged. Backups are encrypted.

10. Your rights

You have a right of access, rectification, erasure, restriction, objection and portability. Where processing rests on your consent, you may withdraw it at any time.

Write to privacy@visioconsult.be. We answer within one month.

You may lodge a complaint with the Data Protection Authority, Rue de la Presse 35, 1000 Brussels.

11. Changes

Any substantial change to this policy is announced by email to account holders, thirty days before it takes effect.