Privacy Policy
PRIVACY POLICY
Last Updated: 02/09/2026
This Privacy Policy explains how VisReed collects, uses, and protects information when you use our website and the VisReed Practice area.
It covers two different situations, and our role is not the same in each:
- For your own account, and for anything you send us through the site, VisReed is the data controller.
- For patient records you enter into VisReed Practice, you are the data controller and VisReed is your processor. We hold that data on your behalf and act only on your instructions.
INFORMATION WE COLLECT
Information you provide: your name, email address, password and, optionally, your profession when you create an account. The content of any message you send through the contact form. Your email address if you subscribe to the Journal.
Patient records you enter: first name, last name and date of birth, stored against your account. See PATIENT RECORDS below.
Information collected automatically: request logs kept by our infrastructure provider, including IP address, for security and reliability. We do not run analytics or advertising cookies. See our Cookie Policy for details.
PATIENT RECORDS
VisReed Practice lets you save a patient's first name, last name and date of birth so that a test can be labelled and repeated. This is personal data concerning health under Article 9 of the GDPR.
Our role. You, the clinician, decide what to enter and why. You are the controller. VisReed stores it for you and is your processor. We do not use patient records for any purpose of our own, we do not analyse them, and we never sell or share them.
Legal basis. You are responsible for the basis on which you process your patients' data, normally Article 9(2)(h), health care provided by a professional bound by professional secrecy. Our processing rests on your instructions under Article 28.
What we do not collect. VisReed does not store test results, images, clinical notes or any diagnosis against a patient record. Test output stays on the device running the test unless you export it yourself. The nine-position gaze tool keeps captured photographs in the browser and does not transmit them.
Who can see it. A patient record is readable only by the account that created it. Every query is restricted to that account. VisReed staff do not access patient records in the course of normal operation.
Where it is stored. In Cloudflare's Western Europe region, inside the European Union. Cloudflare acts as our sub-processor under its Data Processing Addendum and Standard Contractual Clauses.
How long we keep it. For as long as your account holds it. A patient record is deleted when you delete it, and all of your patient records are deleted when your account is deleted. We apply no separate retention period of our own, because the record is yours.
Your own obligations. You remain responsible for telling your patients that you use VisReed, for your own statutory record keeping, and for entering no more than you need. Do not put clinical notes, identifiers or free text into the name fields.
HOW WE USE YOUR INFORMATION
We use account and contact information to:
- Give you access to VisReed Practice and keep you signed in
- Reply to messages you send us
- Send the Journal, if you have subscribed
- Keep the service secure and prevent abuse
Our legal basis is performance of a contract for your account, your consent for the Journal, and our legitimate interest in keeping the service secure.
INFORMATION SHARING
We share information only with:
- Service providers who operate the platform for us, currently Cloudflare, under a data processing agreement
- Legal authorities when the law requires it
- Successor entities in case of a business transfer
We do not sell personal information.
DATA SECURITY
Access to VisReed Practice requires a verified email address and a password of at least twelve characters. Patient records are scoped to the account that created them. Traffic is encrypted in transit. No system is completely secure, and we will tell you and the supervisory authority if a breach occurs that is likely to present a risk.
YOUR PRIVACY RIGHTS
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to processing, and to receive it in a portable form. Where processing rests on consent, you may withdraw that consent at any time.
To exercise a right over your own account, contact us. For a right over a patient record, the request belongs to the clinician who holds it, and we will refer the patient to them.
You may also lodge a complaint with the Belgian Data Protection Authority, the Autorité de protection des données / Gegevensbeschermingsautoriteit, Rue de la Presse 35, 1000 Brussels, contact@apd-gba.be.
YOUR CHOICES
You can:
- Update or delete your account information
- Delete any patient record you have created
- Unsubscribe from the Journal in one click
- Request access to information we hold about you
CHILDREN'S PRIVACY
The website is intended for eye care professionals and is not directed to children. We do not knowingly collect information from a child about themselves. A patient record entered by a clinician may of course concern a child, and that record is the clinician's responsibility as controller.
CHANGES TO THIS POLICY
We may update this policy periodically. The date at the top indicates when it was last updated.
CONTACT US
If you have questions about this Privacy Policy, contact us at contact@visreed.com.
Visreed