Shopping cart
ALWAYS
FREE SHIPPING
Your basket is empty.
Skincare product mockup
Hair Growth Shampoo
Delivery every month
€35.00
Subtotal
€00.00
Shipping costs
gratuitous
Paying
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Fellos B.V.

Privacy Policy

Version: 1.0

Last updated: 29 May 2024

Identity and contact details

Fellos B.V.

Company registration number: 93317336

VAT number: NL866352077B01

Website: www.fellos.nl

‍Email: care@fellos.nl

Introduction

  • Fellos B.V. (“Fellos”, “we”, “us” or “our”) is responsible for this website; its details can be found under the heading “Identity and contact details”.
  • Fellos is committed to protecting the privacy and personal data of our users. Fellos handles the personal data of customers and visitors with the utmost care and in compliance with relevant laws and regulations, including the General Data Protection Regulation (GDPR) and other applicable laws and regulations. This Privacy Policy describes how we collect, use, store and share personal data when you use our website www.fellos.nl (the “Platform”).
  • The Platform connects customers with independent doctors with whom we collaborate (the “Healthcare Providers”). If you choose to have your orders delivered via our partner pharmacy (the “Partner Pharmacy”), the Platform also connects customers with the relevant Partner Pharmacy. Please note that the Healthcare Providers and the Partner Pharmacy are jointly responsible for the processing of your personal data.
  • By using the Platform and agreeing to the terms of this Privacy Policy, you consent to the processing of your personal data as described herein. If you do not (or no longer) consent to the processing of your personal data as described in this Privacy Policy, this automatically means that you will no longer be able to use the products and services on the Platform.

Personal data we process

Fellos processes your personal data because you use our services and/or because you provide this data to us yourself. Each time you use the platform, Fellos may collect personal data about you through the following activities:

  • Online account registration process;
  • Registration form for medical consultation;
  • Online contact or consultation with your doctor via chat, audio or video call;
  • purchase of medicines or other goods or services;
  • navigating and using the website; or
  • contacting us by telephone, text message, post or email.

We collect and process the following categories of personal data:

  • Identification data: first name and surname, date of birth and gender.
  • Contact details: address details, email address and telephone number.
  • Account data: Username, password, login details.
  • Communication data: Emails, messages via the platform or other data provided via the platform or in correspondence.
  • Health data: Health data, medical history, treatments, medication data, test results.
  • Citizen Service Number: if our partner pharmacy claims the cost of your medicines from your insurer, the Citizen Service Number (BSN).
  • Transaction data: data relating to your purchases, including purchase history. We do not process payment data; this is securely collected and processed by our payment service provider.
  • Technical data: IP address, location data, browser type, device type and identifier, log files, cookies.
  • Information about your visit: Information about which pages you visit and which links you click on, the path you follow on the website, and what information you view or download.
  • Additional information: Information relating to your use of the website and access to our services, such as marketing preferences, survey results and feedback.

You must be at least 18 years old to use our website. We do not intentionally collect information from minors.

Special and/or sensitive personal data that we process

We are aware of the particular sensitivity of health-related information (referred to as ‘special categories’ of personal data). We take additional measures to ensure that this sensitive data is treated securely and confidentially. This information is only stored for as long as is necessary for the purposes for which it was collected. Fellos processes the following special categories of special and/or sensitive personal data from you:

  • Sexual life
  • Health
  • Personal Identification Number (BSN)

The purposes for which we process personal data

We process your personal data for the following purposes:

  • Services: To offer you services and products in the field of sexual and dermatological health; to put you in touch with healthcare providers for consultations; and for the processing of your medical data by healthcare providers.
    • Legal basis for processing: Performance of a contract (Art. 6(1)(b) GDPR) in relation to standard personal data; healthcare (Art. 9(2)(h) GDPR) in relation to the processing of medical data by our healthcare providers, as well as explicit consent (Art. 9(2)(a) GDPR) in relation to special categories of personal data, provided these do not fall under Art. 9(2)(h) GDPR.
  • Account management: To create and manage user accounts; to provide customer service.
    • Legal basis for processing: Performance of a contract (Art. 6(1)(b) GDPR) and consent (Art. 6(1)(a) GDPR).
  • Purchase and dispatch: The processing of purchases and the delivery of goods and services. To process your orders, fulfil your prescription and (at your request) deliver your medicines to you from our partner pharmacy.
    • Legal basis for processing: Performance of a contract (Art. 6(1)(b) GDPR) in relation to general personal data, health data (Art. 9(2)(h) GDPR) in relation to the processing of medical data by our partner pharmacy, as well as explicit consent (Art. 9(2)(a) GDPR) in relation to special categories of personal data, provided these do not fall under Art. 9(2)(h) GDPR.
  • Communication: To communicate with you regarding the Fellos services or products you have purchased (including notifying you when you have received a new message from your healthcare provider, and sending reminders regarding this), to provide you with dispatch and tracking information, to provide customer service and/or to answer questions you have asked us or your healthcare provider. To call you or contact you by email if this is necessary for the provision of our services.
    • Legal basis for processing: Performance of a contract (Art. 6(1)(b) GDPR) and legitimate interest (Art. 6(1)(f) GDPR) in relation to general personal data, as well as explicit consent (Art. 9(2)(a) GDPR) in relation to special categories of personal data.
  • Marketing: To send you marketing or promotional material; to send you reminders about services or products in which you have shown an interest. If you have consented to this, we may also use your medical data to send you marketing information that is tailored to you or which we believe may be of interest to you.
    • Legal basis for processing: Explicit consent (Art. 9(2)(a) GDPR) in relation to special categories of personal data, consent (Art. 6(1)(a) GDPR) in relation to general personal data and legitimate interest (Art. 6(1)(f) GDPR) when informing existing customers about similar products or services following a purchase.
  • Online advertising: We use online advertising to keep you up to date with our offerings and to help you view and find our products and services.
    • Legal basis for processing: Legitimate interest (Art. 6(1)(f) GDPR) in using your personal data to help us display relevant advertising, provided we are entitled to do so.
  • Improvement of services: Conducting customer satisfaction surveys; analysing usage data to improve our services and advertising activities.
    • Legal basis for processing: Legitimate interest (Art. 6(1)(f) GDPR) or consent (Art. 6(1)(a) GDPR) when improving our services.
  • Legal obligations: Compliance with legal obligations, such as retention requirements and reporting to authorities.
    • Legal basis for processing: Legal obligation (Art. 6(1)(c) GDPR).

On what legal basis do we process personal data?

Below you will find an explanation of the legal bases on which we process your personal data:

  • Consent (Art. 6(1)(a) GDPR): Where you have consented to the processing of your personal data for specific purposes.
  • Explicit consent (Art. 9(2)(a) GDPR): Where special categories of personal data are concerned, if you have explicitly consented to the processing of such data.
  • Healthcare (Art. 9(2)(h) GDPR): The processing of your data is necessary for medical diagnosis or the provision of healthcare services or treatment carried out by a healthcare professional or under their responsibility, including healthcare providers and (staff of) the partner pharmacy. We rely on this legal basis when your data is processed by the partner pharmacy or one of the healthcare providers, or under their responsibility.
  • Performance of a contract (Art. 6(1)(b) GDPR): The processing of your personal data is necessary for the performance of a contract to which you are a party, or because we have asked you to take certain steps prior to entering into such a contract.
  • Legal obligation (Art. 6(1)(c) GDPR): To comply with legal obligations to which we are subject.
  • Legitimate interest (Art. 6(1)(f) GDPR): For our legitimate interests, such as improving our services, provided that your fundamental rights and freedoms do not override these.

Consent

We seek your explicit consent to the processing of your data, in particular to the collection and disclosure (including to healthcare providers and the partner pharmacy) of your medical data, which you provide in the registration form, via the chat function or in any other way. You give this consent when you start the registration process and agree to this privacy policy. If you decide not to have your order fulfilled by the partner pharmacy, we will not pass on your medical data to them.

At the same time, you consent to the use of your medical or sensitive data to personalise the marketing communications we send you in accordance with this privacy policy.

You have the right to withdraw your consent at any time.

Cookies or similar technologies we use

At Fellos, we use cookies and similar technologies to enhance your experience on our website, analyse the performance and functionality of our website, and provide personalised advertising and content. This section describes our use of cookies and explains how you can manage your cookie settings.

Fellos uses essential, analytics, personalisation and marketing cookies. A cookie is a small text file that is stored in the browser of your computer, tablet or smartphone when you first visit this website. Fellos uses cookies with purely technical functionality. These ensure that the website functions properly and that, for example, your preferred settings are saved. These cookies are also used to keep the website operational and to optimise it. In addition, we use cookies that track your browsing behaviour so that we can offer you tailored content and advertising. When you first visited our website, we already informed you about these cookies and asked for your consent to their use. You can disable cookies by setting your internet browser so that it no longer stores cookies. You can also delete all previously stored information via your browser settings. For an explanation, please see: https://veiliginternetten.nl/themes/situatie/cookies-wat-zijn-het-en-wat-doe-ik-ermee/. Third-party cookies are also set on this website. These include, for example, social media companies.

What are cookies?

Cookies are small text files that are stored on your device when you visit our website. They help us to recognise your device on return visits, save your preferences and analyse the use of Fellos for optimisation purposes.

How do we use cookies?

  • Essential cookies: These cookies are essential for the functioning of our website and cannot be disabled. They ensure basic functions such as page navigation and access to secure areas of the website.
  • Analytics cookies: These cookies collect information about how visitors use our website, which pages are accessed most frequently and whether error messages occur. All information collected by these cookies is aggregated and therefore anonymous.
  • Personalisation cookies: These cookies enable our website to offer enhanced features and personalisation. They may be set by us or by third-party providers whose services we have integrated into our pages.
  • Marketing cookies: These cookies are used to display adverts that are more relevant to you and your interests. They also serve to limit the frequency of adverts and to measure the effectiveness of advertising campaigns.

Managing cookie settings

You have control over the use of cookies on our website. You can set your browser to refuse all cookies or to notify you when a cookie is sent. However, disabling cookies may affect the functionality of our website and prevent you from making full use of our services.

Sharing personal data with third parties

We rely on third parties to provide our services and carry out our activities. Fellos does not sell your data to third parties and only shares it where necessary to provide our services or to comply with a legal obligation. Where personal data is processed in this context, this is done on the basis of a data processing agreement setting out our principles for the protection and security of personal data. Below, we explain to whom we disclose your data, why this is necessary and under what conditions this takes place:

  • Partner pharmacy: To ensure that you receive the medicines you need, we disclose relevant personal data to our partner pharmacy. This includes the disclosure of your prescriptions and any other necessary medical information. In addition, we may use this data to carry out a check for interactions with other medicines via the national clearing house (LSP). This ensures that the medicines can be used safely in combination with other medicines you may be taking.
  • Healthcare providers: To ensure optimal treatment, it is sometimes necessary to share your medical data with your treating doctor. This enables your doctor to gain a complete picture of your health and adjust your treatment accordingly. This also includes sharing your patient data from the online questionnaire, provided you have consented to this.
  • Payment processor: To process your payments securely and efficiently, Fellos works with Stripe. When you make a purchase on our website, your payment details (such as credit card or bank details) are processed directly by Stripe. Fellos does not have access to this payment data. Stripe processes your data in accordance with its own privacy policy and the highest security standards.
  • Authorities: Where we are legally obliged to disclose personal data to government bodies or regulatory authorities.
  • Third-party advertising services: We may share your personal data with third parties with whom we collaborate to provide you with tailored advertising services.
  • Service providers: We share your personal data with various third parties on whom we rely to perform a range of services on our behalf and to develop and improve Fellos’s activities, such as: IT service providers (including cloud IT service providers such as Amazon Web Services), payment system operators (such as Stripe), courier services for the delivery of your orders (such as PostNL), and any other organisations that provide us with technical and support services.

Transfer of data to a third country

Fellos endeavours to keep the transfer of personal data outside the EU to a minimum. From time to time, we may share your personal data with parties outside the EU.

In particular, we may transfer your personal data for the purposes mentioned above to external service providers with servers in the United States, namely:

  • Webflow, based on standard contractual clauses approved by the European Commission for the transfer of personal data to third countries, a copy of which we can provide to you on request. We only share technical data and information about your visit with Webflow.

When we transfer personal data outside the EU, we ensure that it is adequately protected. We do this by transferring your data to countries which the EU considers to offer a substantially equivalent level of protection, or by agreeing to EU-approved standard contractual clauses with the relevant party.

Compliance with the principles of personal data processing

Fellos processes personal data in accordance with the six core principles of the General Data Protection Regulation (GDPR). These principles form the core of our data processing practices and ensure that we handle personal data carefully and responsibly.

1. Lawfulness, fairness and transparency

Lawfulness: We process personal data exclusively on the basis of a valid legal basis, such as the data subject’s consent, the performance of a contract, a legal obligation or our legitimate interest.

Fairness: We handle personal data in a fair and transparent manner. This means that we clearly communicate how we collect, use and share data.

Transparency: We inform data subjects in a clear and accessible manner about the processing of their personal data via our privacy policy and other communication channels.

2. Purpose limitation

We collect and process personal data only for specific, explicit and legitimate purposes that have been clearly communicated to the data subject. Personal data shall not be further processed in a manner incompatible with these purposes.

Examples of these purposes include: facilitating medical care, managing user accounts and improving our services.

3. Data minimisation

We do not process more personal data than is necessary for the purposes for which it is collected and processed. This means that we only collect data that is relevant and limited to what is necessary for the respective purposes.

We regularly review our data collection procedures to ensure that we do not collect superfluous or irrelevant data.

4. Accuracy

We ensure that the personal data we process is accurate and up to date. Incorrect or out-of-date data is rectified or erased without delay.

Data subjects have the right to have inaccurate personal data rectified, and we have established procedures to effectively guarantee this right.

5. Storage limitation

We do not store personal data for longer than is necessary for the purposes for which it was collected or as required by law.

Medical data, for example, is stored in accordance with the statutory retention periods for medical records. As soon as personal data is no longer required, it is securely deleted or anonymised.

6. Confidentiality and integrity

We take appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, as well as against accidental loss, destruction or damage.

These measures include, amongst other things, encryption, access restrictions and secure communication channels.

How we protect personal data

Fellos takes the protection of your data extremely seriously and takes appropriate measures to prevent misuse, loss, unauthorised access, unwanted disclosure, and unauthorised alteration or destruction. If you feel that your data is still not adequately protected or there are signs of misuse, please contact our customer service team or write to care@fellos.nl. Fellos has implemented, amongst other things but not limited to, the following organisational and technical measures to protect your personal data:

Access control:

Access to personal data is restricted to authorised staff and third parties who require this data to perform their duties.

Strict access control measures, such as role-based access rights and two-factor authentication, to prevent unauthorised access.

Encryption:

Data is encrypted both during transmission and at rest to ensure the confidentiality and integrity of personal data.

Use of strong encryption protocols to protect the data.

Secure connections:

We transmit your data via a secure TLS internet connection. You can recognise this by the ‘https’ in the address bar and the padlock icon.

DNSSEC is an additional security measure (complementary to DNS) for converting a domain name (www.fellos.nl) into the associated IP address; it is provided with a digital signature. You can have this signature verified automatically. In this way, we prevent you from being redirected to a false IP address.

Secure application development:

Application of secure development practices when designing and building our software and applications.

Regular security tests and code reviews to identify and rectify potential vulnerabilities.

Backups and recovery:

Regular data backups to prevent the loss of personal data in the event of an incident.

Implemented recovery procedures to ensure the continuity of our services in the event of a disruption or data breach.

Secure communication channels:

Use of secure communication channels for the transmission of personal data. Communication with our partner pharmacy takes place via secure portals and/or via the secure Enovation ZorgMail network.

Protection of our network infrastructure against external threats through advanced security technologies.

DKIM, SPF and DMARC are three internet standards we use to prevent you from receiving emails in our name that contain viruses, are spam, or are designed to obtain personal (login) details.

Monitoring and logging:

Active monitoring of our systems and networks to detect suspicious activity and respond to potential security incidents.

Logging of access to personal data to enable accountability and control.

Fellos is constantly evaluating and improving our security measures to ensure that your personal data is protected as effectively as possible.

Rights of patients and consumers

1. Right of access

You have the right to request information about the personal data that Fellos processes about you. This includes information regarding the purposes of the processing, the categories of personal data concerned, and the recipients or categories of recipients to whom the personal data has been or will be disclosed.

2. Right to rectification

If you find that the information we hold about you is inaccurate or incomplete, you have the right to request that we rectify or supplement this information.

3. Right to erasure

In certain circumstances, you have the right to request that Fellos erases your personal data. This right applies if the data is no longer necessary for the purposes for which it was collected, if you withdraw your consent, if you object to the processing, or if the data has been processed unlawfully.

4. Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. This right applies in certain cases, for example if you contest the accuracy of the data, the processing is unlawful, or you have objected to the processing.

5. Right to data portability

You have the right to receive the personal data you have provided to Fellos in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without Fellos hindering this.

6. Right to object

You have the right to object at any time to the processing of your personal data on grounds relating to your particular situation. This right applies in particular to data processing based on legitimate interests or the performance of a task carried out in the public interest.

7. Right to withdraw consent

Where the processing of your personal data is based on consent, you have the right to withdraw this consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent prior to its withdrawal.

Exercising your rights

To exercise any of these rights, you may contact us using the contact details provided in this privacy policy or on our website. To ensure that the request for access originates from you, we ask you to enclose a copy of your ID with the request. In this copy, please black out your passport photo, the MRZ (machine-readable zone, the strip of numbers at the bottom of the passport), the passport number and the citizen service number (BSN). This is to protect your privacy. We will respond to your request within a reasonable period of time and in accordance with the applicable legislation.

Fellos would also like to inform you that you have the option to lodge a complaint with the national supervisory authority, the Autoriteit Persoonsgegevens. This can be done via the following link: https://autoriteitpersoonsgegevens.nl/nl/contact-met-de-autoriteit-persoonsgegevens/tip-ons

At Fellos, we are committed to protecting your privacy and respecting your rights. If you have any questions or concerns regarding the processing of your personal data, please do not hesitate to contact us.

How long we store personal data

We do not store your personal data for longer than is strictly necessary for the purposes for which it was collected or as required by applicable legislation. The personal data collected will be stored for as long as you are registered to use (among other things) the platform. After that, the data collected may be retained for historical, statistical or scientific purposes; in this case, Fellos endeavours to store it in a form that no longer allows you to be identified. Medical data is stored in accordance with the statutory retention periods for medical records.

Changes to the Privacy Policy

We reserve the right to amend this Privacy Policy. We will inform you of any significant changes via the platform or by email. It is advisable to consult this Privacy Policy regularly to stay informed about how we process your personal data.

Contact

If you have any questions, comments or complaints regarding this Privacy Policy or our data processing activities, you can contact us at the following address: care@fellos.nl.

We will endeavour to respond to and resolve your questions and complaints within a reasonable timeframe.

This website uses cookies

By op “Accept” By clicking, you agree to the storage of cookies on your device to improve site navigation, analyze site use and assist with our marketing efforts. Watch us Privacy Policy for more information.