Privacy Policy
Last updated:
1. Who is responsible for your data?
ARRISE – Academy for Research & Orthopaedic Rehabilitation, Innovation and Sports Medicine Excellence ("ARRISE") is responsible for personal data processed through this website and the ARRISE platform in connection with its services.
2. What data do we process?
- Identity, contact and account information.
- Appointment and service-related information.
- Health, rehabilitation, assessment and session-report information where required for patient care.
- Files and measurements added to a clinical record by authorised staff.
- Academy registrations and related communications.
- Charity-shop reservations and enquiries.
- Contact-form messages and service correspondence.
- Technical and security information such as IP address, login/security events, and necessary cookies.
3. Why do we process it?
We process personal data only where there is an appropriate legal basis under the GDPR. Depending on the activity, this may include performing a contract or taking steps requested before a contract, complying with a legal obligation, protecting legitimate interests such as platform security, or consent where consent is required.
Health information is special-category personal data. Where ARRISE processes health data for physiotherapy, rehabilitation or related care, it is processed only where an applicable Article 9 GDPR condition permits it, including where processing is necessary for healthcare by or under the responsibility of professionals subject to confidentiality obligations.
4. Access to clinical information
Clinical information is not public. Access is limited through role-based controls to the patient, authorised ARRISE staff, therapists involved in that patient's care, and authorised clinical/administrative leadership where access is required for care or clinic operations. Clinical reports and attachments are stored outside the website's public file area and are served only after authentication and authorisation.
5. Service providers and recipients
ARRISE may use trusted providers for hosting, database infrastructure, email delivery, appointment/practice-management services and other operational functions. We disclose only the data needed for the relevant service and use appropriate contractual and security safeguards where required. We may also disclose information to healthcare professionals involved in care, or to public authorities where disclosure is required by law.
If ARRISE introduces integrations such as connected rehabilitation or measurement platforms, this notice will be updated before personal or health data is exchanged through that integration.
6. Retention
We keep personal data only for as long as needed for the purpose for which it was collected and for any applicable healthcare, accounting, contractual, evidential or other legal retention requirements. Different categories therefore have different retention periods. When data is no longer required, it is deleted, anonymised or securely archived as appropriate.
7. Security
ARRISE uses measures appropriate to the sensitivity of the information, including encrypted connections, hashed passwords, access controls, authenticated clinical-file delivery, private storage for clinical documents, data minimisation, and logging/review of relevant system events. No internet service can guarantee absolute security, so safeguards are reviewed as the platform evolves.
8. Cookies
Necessary cookies support security, authentication and core website functions. Optional preference, analytics or marketing technologies are used only in accordance with the choices presented in the cookie settings and applicable consent requirements. You can reopen the cookie settings from the website footer and change optional choices.
9. Your data-protection rights
Subject to the conditions and exceptions in applicable law, you may have rights to access, correct, erase or restrict processing of your personal data, receive portable data, object to certain processing, and withdraw consent where processing relies on consent. Some requests may be limited where ARRISE must retain clinical or other records by law.
To make a request, contact info@arrise.be. We may need to verify your identity before disclosing or changing personal information.
10. Complaints and changes
If you have a privacy concern, please contact ARRISE first so it can be addressed. You also have the right to lodge a complaint with the Belgian Data Protection Authority. We may update this notice when our services, integrations or legal obligations change; the date above identifies the current version.