Trust Centre

The ArboNed Absence Portal is an innovative portal for case management and absence management. This platform was developed in collaboration with BlueVi. B.V. In choosing this new medical file system, we are taking an important step towards improved, modern service provision, while also maintaining our high standards of security and privacy. The ArboNed Absence Portal was developed according to the principle of privacy and security by design, ensuring that your confidential (personal) data enjoys optimum protection. 

Privacy and data protection 

The ArboNed Absence Portal handles with sensitive personal data. We apply high standards of security, care and transparency.

To give you, our customer, a clear understanding of how we handle your data, we have created a comprehensive FAQ section on this page, where we answer the most frequently asked questions. Do you have a different question? Please feel free to contact your regular contact person at ArboNed.

Frequently asked questions privacy and security

  • Who processes my data when I use the ArboNed Absence Portal and what are their roles?

    You are the data controller for your own data. This means that, as an employer, you determine which data is processed and for what purpose, for example in the context of case management. If you use this absence portal, you have appointed IT&Care as a processor. In introducing the new absence portal, IT&Care is using the software and services of BlueVi B.V. (the supplier of the absence portal) as a sub-processor. A sub-processor agreement has been concluded with BlueVi B.V., which stipulates that they may only process your data in accordance with the instructions of the controller and that they must take appropriate security measures. IT&Care and BlueVi B.V. therefore work together to keep your data secure and confidential, each within their own role and responsibility.

  • Where is my data hosted and stored?

    All data processed in the ArboNed Absence Portal is stored in the Microsoft Azure cloud environment. These cloud servers are located physically in the Netherlands, which means that your data remains within the Netherlands and the European Economic Area (EEA). Microsoft Azure meets strict requirements for data residency and compliance. The Azure data centres offer a robust, modern infrastructure with high availability, security and disaster recovery capabilities. The Azure environment for IT&Care is designed in such a way that only authorised parties (IT&Care and BlueVi B.V.) have access. This guarantees that your customer data is securely hosted under the supervision of IT&Care in the Dutch Azure region, in accordance with all relevant laws and regulations.

  • What information security and privacy certifications do IT&Care and its partners hold?

    Both IT&Care and BlueVi B.V. have leading certifications that demonstrate their compliance with high standards for information security and privacy:

    IT&Care B.V.: ISO/IEC 27001 and NEN 7510 certified. This means that IT&Care meets the highest requirements for process control and protection of medical and personal data. IT&Care is also registered with the Personal Data Authority as a processor.


    BlueVi B.V.: ISO/IEC 27001 and NEN 7510 certified for the ArboNed Absence Portal. In addition, BlueVi B.V. has an ISAE 3000 Type II assurance statement, in which the most important privacy controls are independently assessed on an annual basis. 
    These certifications are verified annually by external auditors, confirming that all parties continuously work according to strict security standards and legislation.


     Here are the links to our certifications:

     

     

     

     


     

  • Who has access to my data?

    Access to your data is strictly limited to authorised persons and is done on a need-to-know basis. In practice, this means that only authorised users can access your data:
     

    IT administrators (IT&Care): A limited number of IT administrators at IT&Care have access to the systems for maintenance and support. This access is strictly regulated and logged in accordance with the NEN 7510 and NEN 7513 standards. These IT&Care employees treat all personal data, including medical data, as confidential. These IT&Care employees have signed a confidentiality agreement.
     

    BlueVi B.V. support: Employees of BlueVi B.V. do not have standard access to customer data. In exceptional cases, such as for technical support or incident handling, temporary access may be required. This only happens with the consent of IT&Care and under strict conditions in accordance with the processing agreement.
     

    No external party or unauthorised person can access your data. The roles and rights within the ArboNed Absence Portal are designed so that each user only sees the information relevant to his/her role. This ensures that privacy and confidentiality are maintained.

  • How is the privacy legislation (GDPR) complied with?

    IT&Care and its partners are fully compliant with the General Data Protection Regulation, known internationally as the GDPR. This includes:
     

    Processing agreements: Legally binding agreements have been concluded between IT&Care and BlueVi B.V., in which the agreements regarding data processing, confidentiality and security are stipulated in accordance with the GDPR. 
     

    Purpose limitation and minimal data: Your personal data will only be processed for the specific purpose for which it was collected (e.g. guidance in the event of absence). Moreover, no more data is collected than is necessary.
     

    Rights of data subjects: IT&Care places great importance on the protection of personal data and respects the privacy rights of your employees. This means that employees always have the right to access their data, the right to have incorrect data amended, and the right to have data deleted when justified. According to the GDPR, a data subject must exercise his or her rights with the controller. In the case of employee administration in the absence portal, you yourself, as the employer, are the controller. If your employee wishes to exercise his or her rights, IT&Care will provide all reasonable assistance to ensure that you, as an employer, are able to comply with the obligations associated with your requests. The manner in which your employee can exercise his or her rights with you must be included in your own applicable privacy regulations. Your employees can read about this division of roles in our privacy regulations:
     

    Supervision by the data protection officer: Within ArboNed, of which IT&Care is a part, a data protection officer (DPO) has been appointed to supervise compliance with privacy laws and regulations. The DPO's contact details are included in the privacy regulations.
     

    Annual privacy audit: The most important privacy measures from BlueVi B.V. are independently assessed annually as part of an ISAE 3000 Type II audit. IT&Care is also periodically audited for its GDPR compliance. This demonstrates that the processing of personal data complies with laws and regulations.