15% launch discount with code LIVE15

    Your data, handled with care.

    Explanation of roles, legal bases and (sub)processors.

    Explanation of how LiveLong B.V. processes personal data, the roles we fulfil, the legal bases we rely on, and which parties are involved in the processing. This page provides further detail to our general Privacy Statement.

    Version 21 August 2026

    Data Controller & Processors

    LiveLong B.V. as data controller

    For personal data relating to the use of our platform, such as account data, billing, and platform usage data, LiveLong B.V. acts as data controller within the meaning of Article 4(7) GDPR.

    LiveLong B.V. as processor

    For medical records maintained under the responsibility of a healthcare provider affiliated with our platform, LiveLong acts as a processor to the extent that LiveLong processes this personal data solely on behalf of, and in accordance with the instructions of, that healthcare provider. In that situation, the healthcare provider is the data controller and bears legal responsibility for the medical record. For other processing of health data, an assessment is made on a case-by-case basis as to which party determines the purpose and means, and therefore which GDPR role applies.

    Healthcare providers

    The healthcare providers affiliated with LiveLong are independently BIG and AGB registered physicians. They are the data controller for their patients' medical records and act entirely independently in that capacity.

    Legal bases

    For the processing of ordinary personal data, LiveLong relies on the following legal bases:

    • Consent (Art. 6(1)(a) GDPR), for processing for which the user has given prior consent.
    • Performance of a contract (Art. 6(1)(b) GDPR), for processing necessary to provide our services to the client.
    • Legal obligation (Art. 6(1)(c) GDPR), for processing arising from a statutory requirement.

    For the processing of health data (special category data within the meaning of Article 9 GDPR), additional legal bases apply:

    • Explicit consent (Art. 9(2)(a) GDPR), the client gives prior explicit consent to the processing of their health data.
    • Necessary for medical care (Art. 9(2)(h) GDPR), to the extent that the processing is necessary for the provision of healthcare by the relevant healthcare provider.

    Service providers and other recipients

    LiveLong uses various categories of service providers and other recipients of personal data to carry out its services. Where a party processes personal data on behalf of LiveLong, a data processing agreement is concluded that complies with Article 28 GDPR. Other parties may, depending on their services, have their own role as data controller.

    Personal data is processed within the European Economic Area (EEA) wherever possible. Where personal data is transferred outside the EEA, LiveLong applies a valid transfer mechanism, such as an adequacy decision of the European Commission, certification under the EU-U.S. Data Privacy Framework, or EU Standard Contractual Clauses (SCCs), depending on the service provider and processing concerned.

    LiveLong periodically assesses whether the categories of service providers, purposes and transfer mechanisms used still reflect actual data processing, and updates this page where this is materially relevant to transparency towards users.

    Payment processing

    Payments are processed by an external payment service provider. This payment service provider acts as an independent data controller for its own payment processing. The privacy policy of the relevant payment service provider applies to that processing.

    Retention periods

    LiveLong does not retain personal data for longer than necessary for the purposes for which it was collected, in accordance with Article 5(1)(e) GDPR.

    After deletion from production systems, data may remain present in back-ups for up to a maximum of 35 days; this is a normal part of our security and continuity measures.

    Security

    LiveLong implements appropriate technical and organisational measures to protect personal data against loss, unauthorised access or unlawful processing, in accordance with Article 32 GDPR. In doing so, we apply NEN 7510 as a guideline for information security in the healthcare sector.

    In the event of a data breach affecting your personal data, we will notify you without undue delay, to the extent required by law.

    Your rights

    As a data subject, you have the following rights with respect to your personal data:

    • Access, you can request which data we process about you.
    • Rectification, you can have inaccurate data corrected.
    • Erasure, you can request deletion of your data, to the extent that the law does not require retention.
    • Objection, you can object to certain processing.
    • Data portability, you can obtain your data in a commonly used format.
    • Withdrawal of consent, you can withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

    Requests can be sent to: support@livelong.nl

    You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).

    Last updated: 21 August 2026

    LiveLong

    Preventive blood tests without GP referral. Analyses by an ISO 15189:2022-accredited laboratory in the Netherlands.

    LiveLong B.V.
    Prinses Marijkestraat 21
    1077XB Amsterdam
    Chamber of Commerce 95606572
    VAT no. NL867201794B01
    ISO 15189:2022
    GDPR Compliant

    Newsletter

    Stay updated with health insights and promotional emails.

    Follow Us:

    © 2026 LiveLong. All rights reserved.

    Version 1.0