2.1 Who we are (Controller)
The controller responsible for processing personal data on this website is:
Vital20 B.V., trading as Swiss Point of Care
Registered seat: IJsselstein, The Netherlands
Office and postal address: Tuinderij 15, 2451 GG Leimuiden, The Netherlands
KvK: 55.936.091
VAT (NL): NL851914603B01
Contact: contact
2.2 Data Protection Officer (DPO)
We have not appointed a Data Protection Officer because we are not required to do so under GDPR Article 37.
2.3 Personal data we process
Depending on how you use the website, we may process:
- Name and contact details (name, email address, phone number)
- Company details (company name, job title) if you contact us in a professional capacity
- Communication data (messages submitted via forms and related correspondence)
- Newsletter subscription data (email address, consent status, subscription preferences)
- Technical and usage data (IP address, device/browser type, pages viewed, timestamps, referrer URL)
- Cookie and consent data (your cookie choices and consent log)
We do not intend to collect data from children under 16 without parental consent. If you believe we have collected such data, please contact us and we will delete it.
2.4 Why we process data (purposes)
We process personal data for:
- Responding to requests submitted via the contact page (B2C and B2B)
- Managing business relationships and communication with professional contacts (e.g., pharmacies, occupational health providers, distributors, and other partners)
- Sending newsletters and updates (via Omnisend), where you have subscribed
- Measuring and improving website performance (analytics), subject to your cookie choices
- Ensuring website security and preventing abuse
- Complying with legal obligations where applicable
2.5 Legal bases (GDPR Article 6)
We rely on one or more of the following legal bases:
- Consent(e.g., newsletter subscription, analytics and marketing cookies where required)
- Legitimate interests(e.g., responding to inquiries, business communication, website security, improving our services)
- Legal obligation(where we must retain or disclose information under applicable law)
2.6 Service providers (processors)
We use trusted service providers to operate this website, including:
Consent management
- Cookiebot(cookie consent management and consent logging)
Email and newsletter
- Omnisend(newsletter distribution and subscription management)
Analytics
- Google Analytics(Google LLC) (only where permitted based on your cookie choices)
Marketing and measurement
- Meta Pixel(Meta Platforms Ireland Ltd.) (only where permitted based on your cookie choices)
- LinkedIn Insight Tag(LinkedIn Ireland Unlimited Company) (only where permitted based on your cookie choices)
Hosting
- Current hosting provider: Savvii (Netherlands)
- From April 2026: Infomaniak (Switzerland)
We require our processors to protect personal data and process it only on our instructions.
2.7 International transfers
Some providers may process data outside the EEA, including the United States (for example, Google services). Where this happens, we apply appropriate safeguards such as EU Standard Contractual Clauses and, where required, additional measures.
From April 2026, our hosting provider will be Infomaniak, which is based in Switzerland. Switzerland benefits from an EU adequacy decision under GDPR Article 45, meaning transfers to Switzerland are recognised as providing an adequate level of data protection.
2.8 How long we keep data (retention)
We retain personal data only as long as necessary:
- Contact requests and correspondence: typically up to 24 months
- B2B relationship communications: typically up to 24 months after last contact (unless a longer retention is necessary for contractual or legal reasons)
- Newsletter subscription data: until you unsubscribe (plus a minimal suppression record to respect your opt-out)
- Security logs: typically up to 180 days
- Cookie consent logs (Cookiebot): typically up to 24 months
Where legal retention obligations apply, we retain data for the required period.
2.9 Your rights
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Request deletion of your data (where applicable)
- Restrict processing
- Data portability (where applicable)
- Object to processing based on legitimate interests
- Withdraw consent at any time (without affecting prior processing)
To exercise your rights, please contact us via contact.
We may ask for verification of identity to protect your data. If you provide an ID copy, please redact sensitive fields (document number, BSN, MRZ).
2.10 Automated decision-making and profiling (Article 22 GDPR)
We do not use automated decision-making or profiling as referred to in Article 22 GDPR.
2.11 Complaints
You can lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.
2.12 Security
We implement appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access.