We have taken technical and organisational measures to adequately secure your personal data against loss or any other form of unlawful processing.
Your personal data is stored encrypted. Reports and other static files are protected separately according to current encryption standards (AES-256).
Access to the App is fully protected. Your identity is first verified using OAuth 2.0 with proof key for code exchange ("PKCE"), after which your data can only be accessed using biometric authentication (such as Face ID or Touch ID) or a personal access code.
We also apply data minimisation, data repair and pseudonymisation. Sensitive medical data is stored in separate, highly secure databases and can only be linked to users indirectly, without directly traceable personal data being used.
We apply the principles of privacy by design and privacy by default when developing and maintaining the App. Our technical and organisational security measures are aligned with current best practices and recognised standards, including ISO/IEC 27001 (information security), the OWASP Mobile Security Guidelines and the principles and recommendations of the Dutch Data Protection Authority.