Privacy policy
Version 2.2 — last amended on 4 August 2026
Homediq Europe B.V. ("Homediq", "we", "us") offers self-collection tests that are analysed by independent, accredited medical laboratories. We handle the order, the test kit, the logistics and the secure portal in which you view your result. The laboratory analysis, and the medical responsibility attached to it, rests with the laboratory.
To deliver this service we process personal data, including data concerning health. We do so with the care that this requires. This statement sets out which data we process, why, on what legal basis, for how long, and with whom we share it.
For cookies and similar techniques on our websites, please see our cookie statement. That is a separate document.
1. Who is responsible for your data?
Homediq Europe B.V. is the controller for the processing described in this statement, unless stated otherwise below.
Contact details
Homediq Europe B.V.
Mensinge 2, 1083 HA Amsterdam, the Netherlands
Chamber of Commerce 77050444
privacy@homediq.com
Data Protection Officer (DPO)
We have appointed a Data Protection Officer. You can reach the DPO directly and confidentially at fg@homediq.com.
2. Who does this statement apply to?
This statement applies when you:
- order a test from us through one of our webshops or through a sales partner;
- activate a test and send in a sample or have one collected;
- create or use an account at account.homediq.com;
- visit our websites;
- contact us;
- use our portals on behalf of a business or healthcare partner.
We operate in the Netherlands, Germany, Austria and Belgium, and are expanding into other EU countries. The same European privacy legislation (GDPR) applies across all EU markets. Where national rules differ, for example on retention periods for medical data, we follow the strictest applicable standard.
3. When are we controller and when are we processor?
If you order a test from Homediq yourself (consumer), we are the controller. This statement then applies to you in full.
If you receive a test through your GP, clinic, pharmacy, healthcare platform or employer, that organisation determines the purpose of the processing and we act as processor or joint controller. That organisation's privacy statement then governs why your data is processed. In that situation we process your data solely in accordance with the data processing agreement we have with that party. The sections of this statement on security, retention periods and sub-processors remain relevant, because they describe how we actually handle your data.
The laboratory that analyses your sample is an independent controller for the laboratory analysis and the associated medical record, on the basis of its own accreditation and statutory retention obligation.
4. What data do we process and why?
4.1 Account and order
Data: name, email address, telephone number, delivery address, billing address, date of birth, sex, password (stored encrypted), order history. For business customers additionally: company name, Chamber of Commerce number, VAT number.
Purpose: creating and securing your account, processing your order, sending the test kit, keeping you informed about its status.
Legal basis: performance of the contract (Article 6(1)(b) GDPR).
Retention period: 5 years after the last activity on your account. Data appearing on invoices is retained for 7 years under the statutory tax retention obligation.
4.2 Payment
Data: payment method, transaction details, amount, name of the payment service provider. We do not receive or store full card or bank account details ourselves; these are entered directly with the payment service provider.
Purpose: processing the payment, handling refunds, preventing fraud.
Legal basis: performance of the contract and legal obligation (Article 6(1)(b) and (c) GDPR).
Retention period: 7 years (statutory tax retention obligation).
4.3 Shipping and return of the test kit
Data: name, address, postcode, country, email address, telephone number, track and trace data.
Purpose: sending the test kit to you and returning the sample to the laboratory.
Legal basis: performance of the contract.
Retention period: 2 years after delivery, except for data covered by the statutory tax retention obligation.
4.4 Activating the test and collecting the sample
Data: test kit number or sample ID, date of birth, sex, and depending on the test additional data such as height, weight, symptoms, medication use, pregnancy, lifestyle and relevant medical history.
Purpose: linking the sample to the right person, giving the laboratory the context needed for correct interpretation, and presenting your result to you correctly.
Legal basis: your explicit consent for the processing of health data (Article 9(2)(a) GDPR), together with performance of the contract. You give this consent actively when activating the test. You can withdraw your consent at any time; this does not have retroactive effect, and it does mean we can no longer deliver the service.
Please note: the person who activates the test may be someone other than the person who ordered it. This processing concerns the person who provides the sample.
4.5 Blood collection at a collection point
We currently offer this service in the Netherlands only.
If you choose collection at a collection point rather than at home, we share your name, address details, date of birth, the requested parameters and the sample ID with our fulfilment partner and with the collection location. The fulfilment partner sends you the required collection materials in advance. The collection location records for itself that and when collection took place.
Legal basis: performance of the contract and explicit consent for health data.
4.6 Test results
Data: the values determined by the laboratory, the reference values, the date of analysis and the explanation that follows from these in your account.
How it works: the laboratory receives your sample under a sample ID, together with the data that is medically necessary for the analysis (as a rule date of birth and sex). The laboratory does not hold your name, address or email address. We then link the result back to your account.
We never send medical results by email. At most you will receive a notification that a result is available; you view the result itself after logging in to the secure portal.
Messages via WhatsApp. When activating your test you can choose to receive status notifications via WhatsApp as well. If you do, we pass your telephone number to WhatsApp, part of Meta, through our messaging service. These messages never contain a result or any other health data, only a notification about the progress of your test. We rely on your consent for this (Article 6(1)(a) GDPR). You can withdraw that consent at any time through your account or at support@homediq.com; you will then continue to receive the notifications by email.
Legal basis: explicit consent (Article 9(2)(a) GDPR).
Retention period: your results remain available in your account for as long as your account exists, and are deleted 5 years after the last activity or earlier at your request. The laboratory separately applies its own statutory retention period for the medical record, which in the Netherlands is in principle 20 years. That period falls under the responsibility of the laboratory and we cannot shorten it.
4.7 Customer service
Data: your name, contact details, the content of your message and the associated order or test data. Only at your request, and only where necessary to answer your question, may trained staff view your test result.
Purpose: handling your question or complaint.
Legal basis: performance of the contract and our legitimate interest in providing a proper service (Article 6(1)(b) and (f) GDPR). For access to health data: your explicit consent.
Retention period: 2 years after the contact is closed.
4.8 Email marketing and customer communication
Data: name, email address, language and country preference, order history, and whether you open or click our emails.
Purpose: sending you newsletters, offers and reminders, and making these more relevant.
Legal basis: your consent (Article 6(1)(a) GDPR). If you are already a customer, we may inform you about similar products on the basis of our legitimate interest. In both cases every email contains an unsubscribe link.
We do not use your health data or test results to target marketing at you.
Retention period: until you unsubscribe, and thereafter a maximum of 1 year in order to demonstrate that you unsubscribed.
4.9 Reviews
After your order is completed we may invite you to leave a review. For this we share your name, email address and order number with our review platform. We never share which test you took or what the result was.
Legal basis: legitimate interest (Article 6(1)(f) GDPR). You can object to this at privacy@homediq.com.
4.10 Surveys and research
We may ask you to complete a survey to improve our service. Participation is always voluntary.
In addition, we use test results in anonymised form to improve our tests and for scientific research. Anonymised means the data can no longer be traced back to you, not even by us: your name, address, contact details and account number are removed before the data enters the research dataset, and we keep no key to link it back. We do not sell data.
Because this data is no longer personal data, the GDPR does not apply to it and we cannot remove it from the dataset afterwards. If you would rather not take part, tell us before activating your test at privacy@homediq.com; your test will still be carried out.
4.11 Website visits, security and analytics
Data: IP address, device and browser data, pages visited, referring website, and data from cookies and similar techniques.
Purpose: making our websites work, countering misuse and fraud, and improving our websites and advertising.
Legal basis: legitimate interest for strictly necessary and security purposes; your consent for all analytics and marketing cookies. Without consent we place no non-essential cookies and share no data with advertising platforms.
On our login and form pages we use Google reCAPTCHA to prevent automated misuse. Google processes the data collected in this context solely on our instructions, as a processor, under the Cloud Data Processing Addendum. Google's privacy policy for its own services does not apply to this processing.
Retention period: see the cookie statement. Security logs are retained for a maximum of 12 months.
4.12 Business contacts
For contact persons at healthcare institutions, partners and suppliers we process name, job title, business email address and telephone number, and the correspondence we conduct.
Legal basis: performance of the contract and legitimate interest.
Retention period: 2 years after the last contact, or longer where there is an ongoing agreement.
5. Minors
Placing an order and creating an account is only possible if you are 18 or over.
For a number of tests, the person the test relates to may be under 18. In that case the following applies:
- the test is ordered and activated by a parent or legal representative;
- that parent or representative gives the explicit consent for the processing of the child's health data;
- from the age of 16 the young person gives that consent themselves;
- the result is made available to the person who activated the test.
We do not knowingly process children's data outside this situation. If you believe we are doing so, please contact privacy@homediq.com and we will delete that data.
6. Who do we share your data with?
We never sell your data. We share it only with parties that need it in order to deliver our service, and always on the basis of a data processing agreement or another appropriate legal basis.
6.1 Laboratories
The laboratory that analyses your sample. Which laboratory this is depends on the test. We work with, among others:
| Laboratory | Country |
|---|---|
| Medische laboratoria Dr. Stein & Collegae | Netherlands and Germany |
| Labor Krone | Germany |
| BioDiagnostics (ALEX allergy tests) | Germany |
| MyMicroZoo (microbiome) | Netherlands |
| NiFGO (pharmacogenetics), with analysis by Eurofins Genomics | Netherlands and Denmark |
| Eurofins Clinical Testing Netherlands | Netherlands |
Laboratories receive only the data that is medically necessary, and not your name and address details.
6.2 Processors and service providers
We engage service providers that process data on our behalf. We have concluded a data processing agreement with each of them. They fall into the following categories:
| Category | Purpose | Where data is processed |
|---|---|---|
| Hosting and cloud infrastructure | Our customer portal, our API and our databases | EU (Frankfurt) |
| E-commerce platform | Webshop, order and customer administration | EU, with appropriate safeguards |
| Customer service and office software | Handling enquiries, business email, internal reporting | EU data centres |
| Email marketing platform | Sending newsletters and customer emails | EU and US, with appropriate safeguards |
| Messaging services | Sending status notifications about your test by email, text message or WhatsApp | EU and US, with appropriate safeguards |
| Review platform | Invitations to leave a review | EU |
| Analytics and advertising services | Website analytics, advertising, protection against misuse. Only after your cookie consent, with the exception of strictly necessary security | EU and US, with appropriate safeguards |
| Fulfilment partners | Production, assembly and dispatch of test kits, and dispatch to collection locations | EU |
| Carriers | Delivery of test kits and return shipment of samples | EU |
| Payment service providers | Processing payments and refunds | EU and US, with appropriate safeguards |
| IT development and maintenance | Building and maintaining our software | EU |
| Online marketing service providers | Managing our campaigns and webshop | EU |
| Accountant and bookkeeping firm | Financial administration | Netherlands |
If you would like to know which specific parties sit behind these categories, we will send you that list. Email privacy@homediq.com to request it.
The services for which you give consent yourself, such as analytics and advertising cookies, are named individually. You will find these in our cookie statement.
6.3 Healthcare providers and partners
If you come to us through a GP, clinic, pharmacy or healthcare platform, we share the result with that healthcare provider. That is the core of the service you took out there.
6.4 Authorities
We provide data to competent authorities where we are legally obliged to do so, or where necessary to defend our rights.
7. Transfers outside the EEA
We prefer to store your data within the European Economic Area. Our core infrastructure and our medical data are held in the EU.
With a number of service providers, processing may take place outside the EEA, in particular in the United States. In that case we base the transfer on the EU-US Data Privacy Framework, or on the European Commission's standard contractual clauses combined with supplementary technical and organisational measures.
We do not transfer health data or test results outside the EEA.
8. Automated decision-making
We do not take decisions producing legal effects or similarly significant effects based solely on automated processing.
The presentation of your result in your account is automated: your values are compared with the reference values applied by the laboratory and shown as within or outside the reference range on that basis. This is a presentation of the laboratory result and not a diagnosis. For a medical assessment of your result, please consult your GP or treating physician.
9. Security
We take appropriate technical and organisational measures, including:
- encryption of data in transit and at rest;
- access on a need-to-know basis, with mandatory two-factor authentication for staff;
- separation of identifying data and health data, with samples going to the laboratory pseudonymised;
- logging and monitoring of access to systems;
- data processing agreements with all parties that process data on our behalf;
- a procedure for reporting and handling data breaches.
Our test kits are shipped in neutral packaging, with no reference to the contents or the test.
10. Your rights
You have the right to:
- request access to the data we process about you;
- request rectification of inaccurate data;
- request erasure of your data;
- request restriction of processing;
- object to processing based on legitimate interest, and at any time to direct marketing;
- request portability of data you provided yourself;
- withdraw your consent, without this affecting processing that has already taken place.
You can exercise these rights at privacy@homediq.com. We respond within one month. For a complex request we may extend that period by two months; we will tell you within one month if we do. To prevent misuse, we may ask you to verify your identity.
We cannot always carry out an erasure request in full, for example because invoice data is subject to a 7-year statutory tax retention obligation. In that case we will explain which part we can and cannot delete.
If you wish to access or delete your medical record held by the laboratory, please address that request to the laboratory. On request, we will help you find the right point of contact.
11. Complaints
If we cannot resolve matters together, you may lodge a complaint with a supervisory authority. Our lead supervisory authority is the Dutch Autoriteit Persoonsgegevens. You may also lodge your complaint with the authority in your country of residence:
- Netherlands: Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl
- Belgium: Gegevensbeschermingsautoriteit, gegevensbeschermingsautoriteit.be
- Germany: the supervisory authority of your federal state, bfdi.bund.de
- Austria: Datenschutzbehörde, dsb.gv.at
12. Changes
We may amend this privacy statement, for example when we add new services or service providers. The current version is always available on this page. In the event of significant changes we will inform you actively.
Version 2.2, 4 August 2026