Tiro.health logoTiro.health
Legal

Privacy policy

How Tiro.health handles personal data on this website, inside the product, and during recruitment. Written in plain language, and complete: this is the single privacy notice for tiro.health.

Last updated: 28 August 2026

Who we are

Tiro.health BV, Voskenslaan 95 A, 9000 Ghent, Belgium, company number BE 0768.912.565, is the controller for the personal data described on this page. We build clinical documentation software for outpatient specialists.

For data inside the product, the healthcare practice is the controller and Tiro.health acts as processor under a Data Processing Agreement.

Our Data Protection Officer is Mister Franklin BV. You can reach the DPO at privacy@tiro.health, marked "For the attention of the DPO".

Data we process on this website

On tiro.health we process a limited set of data:

  • Contact details you submit in a form or when booking a demo, such as name, email, phone, practice and specialty
  • Technical data collected automatically: IP address, device and browser, pages visited and referring page
  • Preference data such as your language choice and your cookie consent

Cookies and analytics

Nothing beyond the strictly necessary is loaded until you choose in the cookie banner. Google Analytics 4 is only downloaded after you accept the analytics category, and we use it in aggregate, never to build advertising profiles. We do not use session replay or heatmap tools on this site. The details are in our cookie policy, and you can change your choice at any time through the Manage preferences link in the footer.

Patient data in the product

Patient data is stored and processed inside the European Union, encrypted in transit and at rest. Access is role-based and logged. We do not use patient data to train foundation models, and we do not sell or share it with third parties for their own purposes.

If you apply for a job with us

When you apply we process your CV, cover letter and application details, your employment history and qualifications, references you provide, and our interview notes and assessment results.

We use this only to assess your application, contact you, run interviews, verify what you told us, and onboard you if we make an offer. Applicant data is never used for marketing.

It may be shared with recruitment service providers assisting us, and with legal advisors or authorities where the law requires it. We keep it for the duration of the procedure and, if you agree, for up to two years afterwards so we can come back to you for a future opening.

Processors we use

HubSpot is our CRM, form and meeting-scheduling provider for this website. HubSpot hosts that data in its United States East region under a Data Processing Agreement including the European Commission's standard contractual clauses.

Google Analytics 4 provides aggregate website statistics, loaded only after you accept analytics cookies.

Product and patient data are hosted in the European Union and are not transferred outside the EEA. Where a website or CRM tool processes data outside the EEA, we rely on an adequacy decision or on standard contractual clauses with additional safeguards.

Legal bases

We rely on your consent for marketing communication, non-essential cookies and keeping applicant data after a procedure closes. We rely on the performance of a contract for product access, onboarding, support and invoicing. We rely on our legitimate interest in securing and improving the platform, website statistics, fraud prevention and defending legal claims. We rely on legal obligations for accounting, tax and data protection records. Where processing is based on consent, you can withdraw it at any time without affecting what was done before.

Retention

Website contact data is retained for up to 24 months after the last interaction. Product data is retained for the term of the agreement with the practice and deleted or returned according to that agreement. Applicant data follows the periods above. Once a retention period expires, data is deleted or anonymised.

Security

We apply technical and organisational measures against loss, alteration, unauthorised access and unlawful disclosure, and we require the same of the processors we engage. Our security page describes the controls in more detail.

Your rights

You can request access, correction, deletion, restriction or portability, and you can object to processing. Write to privacy@tiro.health and we will respond within the periods set by law. For data held inside a practice's record, contact that practice, and we will support them in responding.

You also have the right to lodge a complaint with the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels, contact@apd-gba.be.

Children

This website and our commercial services are not directed at people under 18, and we do not knowingly collect their personal data as controller.

Changes to this policy

We update this policy when our practices, tooling or legal obligations change. The date at the top always reflects the current version, and the new version applies from the moment it is published here.

Questions about this document? Write to privacy@tiro.health and we will come back to you.