Meeting team Ontzorgd

At Ontzorgd, we develop software for mental health care. In doing so, we process highly sensitive data. Privacy and Data Security are therefore pivotal in everything we design, build and implement.

Healthcare providers must be able to trust that their data is safe, and that Ontzorgd deals with personal data in an honest and transparent way. That is why we comply with the strictest security standards in the healthcare sector, such as ISO27001 and NEN7510.

When using Ontzorgd, you, as a healthcare provider, are the controller. We act on your behalf. The following principles apply:

Your data remains confidential

We do not use client data to train AI models. We only train our models with datasets that are intended for research and with fictitious data.

Processing for the right purpose

All data processed via Ontzorgd remains the property of the healthcare organization or therapist. We only use this data to support reporting and administration.

Complies with the GDPR and AI Act

Ontzorgd fully complies with the GDPR and the AI Act, and also demonstrate this through our ISO27001 and NEN7510 certification. We closely follow legal developments and work with legal experts to continuously remain compliant.

Transparent agreements

We conclude a processing agreement with each organization, which clearly states how we deal with privacy, security and data processing. We also support the preparation or implementation of a DPIA (Data Protection Impact Assessment).

Data deleted automatically

  • During a conversation, the healthcare provider starts recording via Ontzorgd.
  • Our software listens and transcribes the audio every 30 seconds.
  • Those audio clips are deleted immediately after processing.
  • Based on the transcript, a report is generated automatically.

So no raw audio remains on our servers unless the healthcare provider consciously chooses to do so. The report and transcript are also automatically deleted at the time you want.

Encryption & Data Transfer

  • Transit encryption: All communications are encrypted via TLS 1.2 or 1.3 (A+ SSL Labs Score).
  • Encryption at rest: All stored data is minimally encrypted with AES-128.

Infrastructure & Access

  • Our infrastructure runs within the EU, specifically in the Azure region of Germany West Central.
  • Access to systems is protected by MFA, the zero-trust model and the principle of least privilege.

Collaborate securely

At Ontzorgd, security is not a check mark on a checklist — it's an integral part of how we develop software, make choices and collaborate with healthcare providers. Do you have questions about our policy, would you like to view our certifications or set up a DPIA together? Feel free to contact us.

Bottom Arrow Icon