Version August 2026
Privacy policy
Genus Care values your privacy, and all our data processing activities are fully compliant with data protection legislation. Genus Care does not, for example, sell your personal data to third parties. In this privacy statement, we explain how Genus Care further uses and protects your personal data.
Contact information
Genus Care BV
Assendorperdijk 1
8012 EG Zwolle
KVK 70992363
E-mail: info@genus.care
What is Genus
Genus Care is a (communication) platform for remote care for formal and informal healthcare professionals and informal caregivers. The Genus Care platform consists of several components: Genus Device (Genus), Connected Peripherals, Genus Apps, Genus Portal, Genus PAL, and Genus Backend.
1. Our Role in Data Processing
Genus Care operates as either a Data Controller or a Data Processor depending on how our hardware, portal services, and sensor monitoring are acquired:
Institutional Care (Data Processor): When our services are provided through Healthcare Organisations, Genus Care acts as a Data Processor on behalf of the Healthcare Organisation, which acts as the Data Controller. Institutional care recipients must submit primary data subject rights requests directly to their care provider.
Direct & Distributor Consumer Sales (Data Controller): When our products and services are purchased directly by consumers or through authorized distributors, Genus Care acts as the Data Controller for the personal data collected to operate the devices and portal. Consumer account holders may exercise their data subject rights directly with Genus Care.
2. Processing Operations
2.1. Institutional Deployment (Data Processor)
When the Genus Care platform is deployed within a Healthcare Organisation, Genus Care acts as a Data Processor. In order to deliver our services, execute platform functionality, and facilitate care coordination, Genus Care processes end-user identity attributes, device telemetry, and personnel data on behalf of and under the documented instructions of the Healthcare Organisation (the Data Controller). The Healthcare Organisation retains full statutory responsibility as Data Controller pursuant to Articles 6 and 9 GDPR.
2.2. Direct & Distributor Consumer Sales (Data Controller)
When our hardware, portal services, or apps are acquired directly or through authorized distributors without an institutional care provider, Genus Care acts as an independent Data Controller. In this capacity, we process identity data, account attributes, and device sensor telemetry directly to deliver platform functionality, secure infrastructure, and fulfill our contractual obligations to the end user
2.3. Distribution of Legal Responsibilities
Processing conducted on behalf of a Healthcare Organisation is performed under the direct authority and instructions of that institution. The Healthcare Organisation retains full statutory responsibility as the Data Controller to ensure that its instructions to Genus Care, as well as its overall data processing activities, have a lawful basis (pursuant to Articles 6 and 9 GDPR) and fully comply with all applicable privacy, data protection, and healthcare regulations.
3. What data do we use and for what purposes?
3.1. User provided Information
Before communication between Genus Device and Genus Family App can be set up, permission must be given to the Family App on the Genus Device. This permission is stored in the Genus Backend. The users of Genus Device and Genus Family App utilize pseudonymized storage, meaning communication relies on cryptographic separation of personal identity databases from device and sensor telemetry. With the Genus Portal, Genus Care offers the possibility to communicate with multiple Genus devices.
However, in order to communicate with the correct Genus it is necessary that each Genus in the portal can be uniquely (and recognisably) identified. Genus Portal was developed especially for Healthcare Organisations, which is why it was decided to identify a Genus by means of: linking it to a client, so that the care provider immediately knows which client he/she is communicating with.
Genus Care only uses client information from the Genus Portal to set up the communication. All stored communications and telemetry data are managed using isolated media servers and secure TLS 1.3 transit encryption.
In addition to managing communications, Genus includes sensors to monitor Genus' environment. The data from the sensors utilises pseudonymized storage in the Genus backend every minute. The Genus backend uses this data to automatically generate messages if an unexpected situation occurs.
3.2. Automatically Collected Information
In addition, the Genus Apps and Portals may collect certain information automatically, including, but not limited to, the type of mobile device you use, your mobile devices unique device ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browsers you use, and information about the way you use the Genus apps and portals.
3.3. Real time location information
The Genus apps do not gather precise information about the location of your mobile device.
4. Lawful Grounds for Processing Your Personal Data
We process your personal data only when we have a valid legal ground under European data protection legislation (GDPR). The legal grounds we rely upon include:
4.1. Contractual Necessity
What we process: Account details, device pairing keys, active alarm status, user profiles, and real-time social alarming signal telemetry.
Why we process it: To fulfill our contractual agreement to deliver care coordination services, enable app navigation, route social alarms, and ensure hardware devices function properly.
4.2. Legitimate Interests
What we process: Operational telemetry, system diagnostic event logs, IP addresses, crash reports, and security access logs.
Why we process it: To pursue our legitimate interest in securing our infrastructure against cyber threats, guaranteeing continuous system availability, debugging software errors, and optimizing platform performance. We balance our business interests against your fundamental privacy rights to ensure our telemetry processing is proportionate and secure.
4.3. Legal Obligations
What we process: Financial billing records, tax documentation, and regulatory audit records.
Why we process it: To comply with statutory accounting, administrative, and data protection reporting duties under applicable Dutch and EU law.
4.4. Explicit Consent
What we process: Non-essential analytical telemetry, direct marketing preferences, or user-uploaded media containing health or special category data where applicable.
Why we process it: Where explicitly requested by you. Consent is never bundled into platform terms and can be revoked at any time via app settings without affecting your core service access.
5. Access from the Genus Apps
The Genus Apps need access to the photos, camera and microphone. These are only used for the following functions:
Photo access: To share photos with the Genus Device
Camera and microphone: Call only during the video
6. Automated decision making
Genus Care utilizes automated decision-making processes to enhance the efficiency and effectiveness of our services. These processes include the following.
6.1. Anomaly Detection
Sensor data is automatically analysed to detect unexpected situations in the environment of the Genus device. If an anomaly is detected, an automatic alert can be generated (if enabled) and sent utilising cryptographic separation to ensure privacy.
6.2. Communication Management
Automated systems help manage communication between Genus devices and the portal to ensure seamless and secure interactions.
6.3. Legal Basis
The basis for processing end-user data, including automated decision-making and anomaly detection, is Explicit Consent (GDPR Article 6(1)(a) and Article 9(2)(a)). For institutional users, consent is obtained and managed by the Healthcare Organisation. For direct and distributor consumer sales, Explicit Consent is obtained directly by Genus Care during activation of the Genus Device and can be managed or revoked at any time via the Genus Device.
7. How long we keep personal data
7.1. Retention schedules
Genus Care maintains explicit retention schedules for all processed data:
Active Subscription Processing: Data is retained for the duration of an active service subscription.
Soft-Delete Buffer: Following subscription termination, data enters a 12-month soft-delete buffer period.
Automated Hard-Delete: After the 12-month buffer, automated scripts permanently hard-delete by anonymizing the data.
Statutory Financial Records: Financial records are retained for the statutory period of 7 years.
7.2. Notice on Healthcare Record Retention
The obligation to export clinically relevant alarm records into primary Electronic Health Record (EHR) systems to satisfy statutory medical retention requirements (such as the Dutch WGBO 20-year requirement) applies strictly to Healthcare Organisations acting as Data Controllers. For consumers who purchase products directly or through authorized distributors, personal data and telemetry are governed exclusively by Genus Care’s standard retention schedule outlined in Section 7.1.
8. Data Sharing, Subprocessors, and International Transfers
8.1. General Principles on Third-Party Data Sharing
Genus Care does not sell, rent, or trade your personal data to any third parties. We only disclose or share personal data under the following conditions:
Service Execution: With technical service providers and subprocessors strictly necessary to operate the Software Platform, route social alarms, and perform our contract with you.
Legal Compliance: With judicial, regulatory, or law enforcement authorities when required by applicable law, court order, or mandatory statutory obligations.
8.2. Dynamic Subprocessor Roster
To deliver high-availability infrastructure, real-time social alarming, and platform stability, Genus Care engages specialized external vendors (subprocessors). All subprocessors are vetted and bound by data processing agreements pursuant to Article 28 of the GDPR, ensuring they process personal data strictly on our documented instructions.
Rather than maintaining a static vendor schedule within this policy document, Genus Care maintains a complete, up-to-date, and dynamic schedule of all engaged subprocessors—including their legal entity names, functional roles, processing locations, and applicable transfer mechanisms—published at: Genus Care Subprocessors
Registered controllers and account holders are notified of any intended additions or replacements to our subprocessor roster at least 14 calendar days prior to authorizing a new subprocessor, in accordance with our Terms of Service and Data Processing Agreements
8.3. International Data Transfers
Where personal data is processed by or transferred to a subprocessor located outside the European Economic Area (EEA) in a country that does not benefit from an adequacy decision by the European Commission, Genus Care implements statutory safeguards pursuant to Article 46 of the GDPR. We rely on European Commission Standard Contractual Clauses (SCCs), supplemented by technical security measures including TLS 1.3 transit encryption and cryptographic data separation.
The specific processing locations and international transfer tools applicable to each subprocessor are detailed on our public subprocessor webpage at: Genus Care Subprocessors
8.4. Direct Marketing Communications
We do not share personal data with third parties for marketing or promotional purposes. You will only receive news or marketing updates directly from Genus Care if you explicitly select unbundled opt-in checkboxes during account registration or within your account settings. You may withdraw your consent for marketing communications at any time without affecting your core service access.
9. Cookies, or similar techniques that we use
9.1 What is a cookie?
A cookie is a small piece of information that a website can send to your browser, which is how it is stored on the system. These ensure that the website works properly and that, for example, your preference settings are remembered. These cookies are also used to ensure that the website works properly and to optimize it.
Cookies expire after closing your browser (session cookie) or cookies in the browser (persistent cookies). For example, cookies allow you to identify your device by a session ID so that you can maintain access to our site. Cookies can also be used to store language settings or to analyze visitor behavior.
9.2 The cookies we use
We use cookies from Marketing and Google Analytics to find out the behavior of visitors and analyze our performance. This helps us improve our website, for example by ensuring that visitors can easily find what they are looking for.
9.3 Delete cookies
You can unsubscribe from cookies by setting your internet browser so that it no longer stores cookies. In addition, you can also delete all information previously stored via the settings of your browser.
10. View, adjust or delete data
You have the right to view, correct, or delete your personal data. You also have the right to withdraw any consent to data processing, object to processing, and request data portability pursuant to the GDPR.
Institutional Care Recipients: Please submit your primary data subject rights requests directly to your healthcare provider (the Data Controller).
Direct & Distributor Account Holders: Consumers who purchase Genus Care products directly or through authorized distributors hold direct account relationships with us and may submit rights requests directly to info@genus.care.
11. Policy regarding Genus Care website contact form
When you contact us, data is stored and sent to Genus Care. This data is only used to contact you. You have the right to be forgotten, which means you have the right to have the data deleted at any time. If you wish, please send an email to info@genus.care and we will process your request.
12. Identity Verification, Rights Requests, and Filing a Complaint
12.1. Identity Verification and Response Timelines
To ensure that a request to exercise your data subject rights (such as access, rectification, or erasure) is made by you, Genus Care may ask you to enclose a copy of your proof of identity with your request. To protect your privacy, you must black out your passport photo, MRZ (Machine Readable Zone—the strip with numbers at the bottom of the passport), passport number, and Citizen Service Number (BSN) in this copy. Genus Care will respond to your request as quickly as possible, and in any case within four (4) weeks of receipt.
12.2. Right to Lodge a Complaint with a Supervisory Authority
If you believe that Genus Care’s processing of your personal data infringes applicable data protection legislation (including the GDPR), you have the statutory right under Article 77 GDPR to lodge a complaint with a supervisory authority.
In the Netherlands, the competent lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens – AP). You can contact the AP or submit a complaint directly via their website at:
https://autoriteitpersoonsgege...
13. How we protect personal data
Genus Care takes the protection of your data seriously and takes appropriate measures to prevent misuse, loss, unauthorized access, unwanted disclosure and unauthorized modification. We publicly cite our compliance with ISO/IEC 27001:2022 and NEN 7510-1:2024+A1:2026 frameworks to ensure the highest standards of data security.
If you have the impression that your data is not properly secured or there are indications of misuse, please contact us at info@genus.care
