English
Privacy Statement HealthEmove Pilot
Privacy matters when you use the HealthEmove app. In this statement we explain how the HealthEmove app handles your personal data.
The HealthEmove app
The HealthEmove app (the “App”) helps you keep an overview of your own health. This is important because you may change healthcare providers and because your information is currently held by different healthcare providers in the Netherlands or in other EU countries. With the App you can keep your information with you in a secure way and show it to your (new) healthcare or support provider. This helps a new healthcare provider to help you better.
You store your information in your “Data Vault”: a personal storage space that you can access through the App and that is protected with encryption. You are the only person who has access to your Data Vault; not even ahti can see its contents. You fill the Data Vault yourself: you add documents and photos and your own notes, and you can make and save audio recordings. With the App you can translate documents and audio recordings that you have added and add these translations to your Data Vault. In the App you can also find information about your rights to healthcare and where you can get care.
The App is still under development and is continuously being tested for further development.
Who is responsible for processing your personal data?
The App is offered by the Amsterdam health & technology institute (“ahti”). ahti is responsible for processing your personal data when you use the App.
Our contact details are:
ahti (Stichting Amsterdam Health & Technology Institute)
Paasheuvelweg 25
1105BP Amsterdam, the Netherlands.
App for ages 16 and over
The App is intended for users aged 16 and over. When you use the App for the first time, you will be asked to confirm that you are over 16.
For your own personal use only
The App is for your own personal use only. You should only put information in the App that is relevant to your personal situation and use. You should not put information about other people in the App, unless it is relevant to your use of the App. Sometimes documents you upload will contain information about third parties, such as the names of treating doctors or contact persons.
This is permitted to the extent that you use the App for your own personal purposes under the so-called ‘household exemption’ in Article 2(2)(c) of the GDPR, provided that you:
- Use the information for private purposes only, so not, for example, for business or commercial purposes;
- Share the information only within a limited circle (such as with family and support providers); and
- Do not make the information publicly available (which is not possible through the App).
What personal data do we process?
You do not need an identity document or a fixed address to use the App. When you use the App, the following data may be processed:
- Account and contact details, such as the email address and phone number you use to create your account and the PIN you choose;
- Documents from third parties that you add to the App, for example photos or PDFs of documents from healthcare and welfare organisations, municipalities, schools, etc.
- Other information and documents you enter yourself in the App, such as health measurements, your name, your emergency contact, notes, audio messages or, for example, photos of medicine boxes;
- Information you generate through the App, such as translations of Documents.
- Usage and research information: We anonymise information about how the App is used (for example, which button you click) and statistical information (how often a feature is used) for research and to further develop the App.
On what legal basis do we process your data?
We process the personal data listed above because this is necessary to provide you with the App’s features (Article 6(1)(b) GDPR). The legal basis for anonymising the Usage and research information is legitimate interest (Article 6(1)(f) GDPR). We use this anonymous information to improve the App.
Where is your personal data stored?
Documents from third parties and other information and documents that you add to the App are stored in your personal Data Vault. This is hosted on servers in the European Union. ahti has no access to this information.
When you are logged in to the App, a limited amount of information may be temporarily available locally on your mobile device, for example certain notes and file names. ahti has no access to this locally stored information. This information is deleted as soon as you log out or your session ends.
How do we protect your personal data?
When you create an account, you provide your email address and phone number and choose a five-digit PIN. You will then receive an email to confirm your email address, so that we know that you really created the account yourself.
Once you have created an account, you can log in to the App using two-factor authentication. The App offers two login methods for this:
- An email code in combination with your PIN; or
- A passkey on your mobile device. A passkey is a digital login key that lets you use your device’s unlock method, for example your fingerprint, face recognition or device passcode.
Information you store in the Data Vault is protected with encryption, both when the information is stored (‘at rest’) and when it is sent from the servers to your mobile device or the other way round (‘in transit’). The contents of your Data Vault are only temporarily decrypted when this is necessary for a feature you are using yourself, for example to translate information with AI. The information is encrypted again immediately after the AI feature has been carried out and is not used to train AI models.
Who has access to your personal data?
You are in control of your personal data in the App. This means that you decide which data you store and what you show to others (such as a support provider).
Service providers
ahti uses AWS for hosting and for identity verification and authentication for the App. These services for HealthEmove are provided within the European Union. For the AI features, ahti uses Microsoft Azure Foundry within the European Union.
ahti has made agreements with AWS and Microsoft on the protection of personal data that meet the applicable requirements of the GDPR.
Requests from authorities
Border control
You can take steps yourself to prevent authorities from gaining access to the information (for example at the border). For instance, you can temporarily delete the App from your phone before you cross the border. The information will then remain stored in your Data Vault and will be available again when you reinstall the App. In any case, make sure you are logged out when you cross the border, so that no information is temporarily available locally on your mobile device (see “Where is your personal data stored?”).
Requests to ahti
Because ahti has no access to the encrypted contents stored in your Data Vault, ahti cannot provide those contents to an authority itself. ahti only has access to your account and contact details. ahti only provides this information when there is a valid legal obligation to do so. We assess every request legally and reject requests that have no valid legal basis.
Requests from authorities
Border control
You can take steps yourself to prevent authorities from gaining access to the information (for example at the border). For instance, you can temporarily delete the App from your phone before you cross the border. The information will then remain stored in your Data Vault and will be available again when you reinstall the App. In any case, make sure you are logged out when you cross the border, so that no information is temporarily available locally on your mobile device (see “Where is your personal data stored?”).
Requests to ahti
Because ahti has no access to the encrypted contents stored in your Data Vault, ahti cannot provide those contents to an authority itself. ahti only has access to your account and contact details. ahti only provides this information when there is a valid legal obligation to do so. We assess every request legally and reject requests that have no valid legal basis.
How long is my personal data kept?
You can close your account at any time. You can do this yourself in the App under ‘More’, ‘Delete my account’.
From that moment on, your account and Data Vault are no longer accessible. A copy of your data may remain in backups for up to 30 days and is then permanently deleted.
In addition, your account and data are automatically deleted after 2 years and 30 days of inactivity. Every six months you will receive a reminder to log in to your account. After 2 years, you have another 30 days to log in to your account before your account and data are deleted.
The anonymised Usage and research information collected up to that point is retained; this information can no longer be traced back to you.
What rights do I have regarding my personal data?
Under the GDPR you have various rights regarding your personal data. For example, you can ask for access to, correction or deletion of your personal data and, in certain cases, you have the right to object to the processing of your personal data based on our legitimate interest, the right to restriction of processing and the right to data portability.
You can exercise many of these rights directly in the App. For example, you can view, change or delete information you have added yourself and download documents from your Data Vault. You cannot change the content of documents you have received from a healthcare or support provider; for that, you need to contact that healthcare or support provider. You can, however, delete such Documents from your Data Vault or add your own note to them.
To exercise rights that you cannot exercise yourself through the App, you can contact us using the contact details below.
Where can I go with questions, complaints or comments?
If you have questions about the App or this privacy statement, you can contact us at info@healthemove.org. You can also contact our Data Protection Officer at m.suijs@ahti.nl. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
What if I have forgotten my PIN or lost access to my email address and phone number?
In that case, you can contact HealthEmove at info@healthemove.org or send a WhatsApp message to +316 173 70 554. We will then contact you within 24 hours on working days to help you further. For this, we do need to have your phone number and/or your recovery email address on file.
Have you lost both your PIN and access to your email? Then ahti cannot help you regain access to your account, and you will lose your data in HealthEmove.
Last updated: [28-09-2026]