Privacy policy
Nollie runs on trust: you trust us with your practice, and your patients trust you with their health. That is why we explain here, without beating about the bush, which personal data we process, why we do so and what say you have in it.
On this page
Nollie’s two hats
Almost every privacy policy starts with a single role. With us there are two, and that difference determines who decides what. Read this part first: the rest of this page builds on it.
For your data as a physiotherapist
Do you visit our website, request access or become a customer? Then Nollie itself determines why and how that data is processed. For that part, we are accountable, and this policy applies in full.
For your patients’ data
Everything you enter in Nollie about your patients remains your practice’s. You are the controller for it; we are merely the processor that stores and processes it on your behalf. See section 03.
The controller for role 1 is Soluxion BV, Steenbruggestraat 11, 8570 Anzegem, Belgium, company number 0607.888.607. You can reach us about anything privacy-related at [email protected].
What we process and why
We collect nothing “just in case”. Each category of data below belongs to a specific purpose and a legal basis under the GDPR. If you do not see it in this table, we do not process it.
| What | What for | Legal basis |
|---|---|---|
| Request to get started (name, e-mail address, practice name, your optional comment) |
Contacting you to set up your practice and get your account ready. | Your consent, which you can withdraw at any time. |
| Contact and practice details (name, e-mail, phone, practice name, RIZIV/INAMI number) |
Creating your account, setting up your practice, providing support and guiding your switch to Nollie. | Performance of the contract we have with your practice. |
| Billing details (address, VAT number, payment details) |
Invoicing your subscription and keeping our accounts properly. | Contract and our legal obligation as a company. |
| Account data (username, encrypted password, sign-in times) |
Letting you sign in securely and detecting account misuse. | Contract and our legitimate interest in a secure platform. |
| Technical log data (IP address, timestamp, errors) |
Resolving outages, keeping the software stable and fending off attacks. | Our legitimate interest in a working, secure service. |
| Your questions and messages to support | Answering you, following up on your case and improving our explanations. | Contract or our legitimate interest in providing good help. |
Should we ever process data for a new purpose not listed here, we will inform you in advance and ask for your consent where required.
Patient data in the software
This is the most sensitive part, so we will put it plainly: the patient records in Nollie belong to your practice, not to us. We store and process them on your behalf and in accordance with your instructions. You decide what goes into them, who may see them and when they may be deleted.
- We do not look. Our staff have no access to medical records, except when you expressly ask us to in the event of a technical problem, and then only for as long and as far as necessary.
- We do not use them for anything else. Patient data is never sold, rented out, used for advertising, or used to build models or statistics outside your practice.
- We put it in writing. Your subscription comes with a data processing agreement that sets out exactly what we may do with that data, how we secure it and what happens to it when your contract ends.
- Professional secrecy remains professional secrecy. Health data is a special category under the GDPR. The technical and organisational measures in section 07 are designed accordingly.
Does a patient have questions about their record, or wish to exercise their rights? Then you, as the practice acting as controller, are the right point of contact. We help you behind the scenes with everything you need technically to do so.
How long we keep data
We do not keep data that has served its purpose. In practice, this means:
| Data | Retention period |
|---|---|
| Requests to get started | Until your practice has been set up, or until you ask us to stop. If you do not become a customer, we delete your request. |
| Customer and account data | For as long as you are a customer, plus the period in which legal claims may still arise. |
| Invoices and accounts | Seven years, because Belgian law requires us to. |
| Technical logs | Short-term, usually a few months, and only for security and troubleshooting. |
| Patient records in the software | For as long as your practice keeps them. You set the period; we carry out what you ask. |
Is your subscription ending? You will first be given the opportunity to export your data. Only then do we delete it permanently from our systems, except for what we are legally required to keep.
Who gets to see your data
We do not sell your data. Full stop. There are only three situations in which it leaves our systems:
1. Suppliers who work for us
To keep Nollie running, we work with a limited number of service providers, such as our hosting partner, our payment provider and the tools we use for support and e-mail. They act solely on our instructions, are contractually bound by the same obligations, and may not use your data for anything else.
2. The Belgian healthcare network, when you ask for it
When you send an eAttest, an eFact batch statement or an eAgreement, that data travels via the secure eHealth and MyCareNet channels to the bodies and health insurance funds concerned. This always happens on your initiative, within the legal framework that applies to those services.
3. When the law requires us to
For example, on a valid order from a court or a competent authority. In that case, we pass on no more than is strictly requested.
If you connect Nollie to your Google Calendar, data also goes to Google itself. Exactly what happens there, and with whom that data is and is not shared, is set out separately in section 06.
Google Calendar integration
Nollie can synchronise your calendar in both directions with Google Calendar. This integration is switched off by default: you turn it on yourself via Google’s sign-in screen. You never give us your Google password, only the permissions shown on that screen, and you can revoke them at any time. Because this concerns data from your Google account, we set out separately below what we request, what for, who we share it with, how we secure it and when it is deleted.
Which Google data we request
| What | What for |
|---|---|
| Basic details of your Google account (name, e-mail address, profile photo) |
Linking the integration to the right Nollie account and showing you which Google account is connected. |
| The list of your calendars (names and identifiers) |
Letting you choose which calendar is synchronised, so that the rest are left untouched. |
| The appointments in the chosen calendar (title, description, start and end time, location, status, invitees) |
Keeping appointments in step in both directions and avoiding double bookings. |
| The integration’s access keys (OAuth tokens) |
Keeping the synchronisation running without you having to sign in again each time. |
We only request the permissions the calendar integration genuinely needs. We do not touch other Google services, such as your Gmail messages, your contacts or your files in Drive.
What we use it for
Solely to make the calendar integration you switched on work. In practice: putting appointments from Nollie into your Google Calendar and vice versa, carrying changes and cancellations through to both calendars, reading your busy times so that nothing is double-booked, and detecting faults in the integration.
To be equally clear about what we do not do with it: we never use Google user data for advertising or targeted ads, never to build or sell profiles, never for credit assessment, and never to build or train AI or machine learning models. Our staff do not read your calendar data, except when you expressly ask us to in the event of a technical problem, when it is necessary to deal with a security issue or abuse, or when the law requires us to.
Who we share, transfer or disclose it to
We do not sell, rent or trade Google user data, to anyone. We do not transfer your data to third parties and do not disclose it for purposes other than those described above. There are only three exceptions, and they are listed here:
- Google itself. This is inherent to the integration: appointments you create in Nollie are written to your Google Calendar.
- Our hosting partner, which stores the data solely on our instructions on servers within the European Economic Area. That party is contractually bound, may not use the data for anything else and has no access rights of its own.
- A competent authority or court, when a valid order requires us to. In that case, we pass on no more than is strictly requested.
Under no circumstances do we pass Google user data on to advertisers, data brokers, analytics companies or parties that train AI models.
How we secure it
- ✓Encrypted in transit and at rest. All traffic with Google runs over TLS; the retrieved data and the access keys are stored encrypted, including in backups.
- ✓Keys stored separately. Your OAuth tokens are stored in isolation and are not visible to our team.
- ✓As few permissions as possible. We only request access to the calendars you select yourself.
- ✓Need-to-know access, and traceable. Access to the integration is restricted; what happens is logged.
The measures in section 07 apply in full to this data as well.
How long we keep it, and how to erase it
We keep Google user data for as long as the integration is active, and no longer than needed to make it work. You have three ways to put an end to it:
- Disconnect the integration in Nollie. We then delete your access keys and the calendar data retrieved from Google from our active systems within 30 days at the latest, and from backups as soon as they have completed their normal retention cycle.
- Revoke access at Google itself, via myaccount.google.com/permissions. The integration then stops immediately on Google’s side, and we clean up as described above.
- Ask us. A single e-mail to [email protected] is enough to have your Google data erased. And when your account with us ends, we delete it without you having to ask.
Appointments that the synchronisation has already put into your Google Calendar stay there: they are in your Google account and you continue to manage them yourself.
Limited Use: the commitment Google requires of us, and one we are glad to make
Nollie’s use and transfer of information received via Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Furthermore, we do not use Google Workspace APIs to develop, improve or train generalised or non-personalised AI or machine learning models.
Connecting your Microsoft or Outlook calendar instead of Google? The same rules and the same restrictions then apply, with the data from your Microsoft account instead of your Google account.
How we secure your data
Security is not a box we tick afterwards, but the way Nollie is built. The main measures:
- ✓Encrypted in transit and at rest. All traffic runs over TLS, and stored data is encrypted, including in backups.
- ✓Need-to-know access. Within your practice, you decide who sees what. Within our team, nobody gets access they do not need for their work.
- ✓Logging of sensitive actions. Who requested or changed what remains traceable.
- ✓Backups that are tested. Not only taken, but actually restored to make sure they work.
- ✓European data centres. Your records stay within the European Economic Area.
Perfect security does not exist, and you should not believe anyone who claims otherwise. If, despite everything, something does go wrong that poses a real risk to the people concerned, we will notify you and, where the law requires it, the Data Protection Authority within the prescribed period.
Cookies and analytics
Our website deliberately keeps things simple. We use the cookies that are strictly necessary for the site to work: remembering your sign-in session and protecting forms against abuse. No consent is required for these, because the site does not work without them.
In addition, only with your consent, we anonymously measure how visitors use the site, through our own analytics service at analytics.nollie.be. We ask for this consent on your first visit, and you can change or withdraw it at any time via cookie settings. You can also always refuse or delete cookies yourself in your browser.
Our pages sometimes contain links to other people’s websites. Once you click through, their rules apply, not ours: so it is best to read their privacy policy separately.
Your rights
The GDPR gives you a range of rights over your own data. At Nollie, you do not need to fill in a form in triplicate to use them: one e-mail is enough.
Send your request to [email protected]. We reply within one month. If your request is exceptionally complex, we will let you know within that month how much extra time we need. To prevent someone else from requesting your data, we may ask you to identify yourself.
Not happy? Lodge a complaint
Do you feel we are handling your data carelessly? Tell us first: nine times out of ten it is a misunderstanding we can quickly put right. E-mail us at [email protected].
If we cannot resolve it together, you always have the right to lodge a complaint with the supervisory authority:
Changes to this policy
Nollie is growing, and this policy grows with it. Each version carries a date at the top, so you can see straight away which is the most recent. In the case of a material change, such as a new purpose or a new category of data, we will actively notify you by e-mail or in the software. So we do not expect you to keep an eye on this page of your own accord.
This version dates from August 2026 and replaces all previous versions. This policy and our services are governed by Belgian law.