Privacy Statement Harai Massagetherapie & Rolfing
Harai Massagetherapie & Rolfing handles personal data with care. In this privacy statement, you can read which data I process, why I do so, how long I retain data, with whom data may be shared, and what rights you have.
This privacy statement applies to visitors to the website, clients, people who contact us, people who make an appointment online or directly, people who leave a comment on the website, and people who buy or use a gift card or voucher.
1. Who is responsible for your data?
Harai Massagetherapie & Rolfing is responsible for the processing of personal data.
Practice name: Harai Massagetherapie & Rolfing
Website: staging.harai.nl
Email address: paul@harai.nl
Visiting and postal address: Utrechtsedwarsstraat 89 sous, 1017 WD Amsterdam
Chamber of Commerce number: 28095253
In this statement, Harai also referred to as “I”, “me” or “the practice”.
2. Which personal data do I process?
I only process personal data that is necessary for contact, appointments, treatment, administration, and the proper functioning of the website.
This may involve:
name;
email address;
phone number;
appointment details;
details you enter when booking online;
data that you enter yourself in a contact form, intake form, response form, or email;
payment and invoice details;
details about gift cards and vouchers;
relevant information about your health, symptoms, medication use, treatments, injuries, pregnancy, contraindications, or other circumstances that are important for safe treatment;
notes on intake and treatment;
technical data during website visits, such as IP address, browser information, cookie data, and data for spam detection.
3. Why am I processing this data?
I process personal data for the following purposes:
contact and answer questions;
make, change or cancel appointments;
process online bookings;
conduct an intake;
assess whether a massage or treatment is safe and appropriate;
tailor the treatment to your situation;
keep track of what was discussed or done during previous treatments;
invoicing and administration;
processing of payments, gift cards and credit vouchers;
respond to public comments on the website;
limit spam and abuse of forms or comments;
comply with legal obligations;
improving, securing, and managing the website.
4. Health data
For massage, massage therapy, and Rolfing, it may be necessary to process health data. This constitutes special personal data. Therefore, I handle this with extra care.
I only request health data that is relevant for safe and appropriate treatment. This includes information about complaints, injuries, medication use, medical treatments, pregnancy, surgeries, allergies, skin problems, or other conditions that may affect the treatment.
Health data is not used for marketing.
Health data is not shared with third parties, except when:
you give explicit permission for that;
it is necessary to comply with a legal obligation;
it is necessary for anonymous or non-traceable consultation with a fellow practitioner;
there is an exceptional situation in which safety or a legal duty outweighs this.
Anonymous consultation means that your name and directly identifiable details are not shared. If information could nevertheless be traced back to you, I will ask for your permission in advance.
5. Grounds for processing
I process personal data only when there is a valid reason for doing so. Depending on the situation, this may be:
execution of an agreement or contract;
consent;
legal obligation, such as tax administration;
legitimate interest, such as normal business operations, security, communication and protection against abuse;
necessary processing of health data for safe and responsible treatment, to the extent permitted by law.
When processing is based on consent, you may withdraw that consent later. Withdrawal of consent has no retroactive effect.
6. Contact forms, email and messages
If you contact me via the website, email, telephone, WhatsApp, or another communication channel, I process the data that you provide yourself.
I use this data to answer your question, make an appointment, or handle the communication carefully.
Preferably do not send extensive medical information via unsecured email, contact forms, or messaging apps, unless it is necessary and you choose to do so yourself.
7. Online booking
When you make an appointment online, the data necessary to complete the booking is processed. This may include name, contact details, chosen treatment, date, time, any comments, and technical data required for the functioning and security of the booking system.
Data from online booking is used for:
booking the appointment;
confirmation and communication regarding the appointment;
change or cancel the appointment;
preparation of the treatment;
administration;
preventing abuse or double bookings.
When booking online, only provide health information when necessary for the appointment. More extensive health information can be discussed during the intake or treatment.
If an external provider or plug-in is used for online booking, this provider may have technical access to data processed via the booking system. Where necessary, appropriate agreements regarding security and processing are made with such parties.
8. Appointments and intake
Before or during a treatment, I may ask questions about your health, complaints, boundaries, wishes, and previous experiences with massage, massage therapy, Rolfing, or other body-oriented work.
I use this information to carry out the treatment safely, professionally, and appropriately.
You are personally responsible for correctly and fully informing the practice about relevant circumstances. This is also stated in the general terms and conditions.
9. Payment and administration
For payments and administration, I process data such as name, amount paid, date of payment, invoice number, and possibly address details.
Financial data is retained for as long as necessary for administration and statutory retention obligations.
10. Gift cards and credit vouchers
Upon purchase or use of a gift card or voucher, I may process data such as name, contact details, purchase date, value of the card, validity period, and usage status.
This data is used to issue, verify, and administratively process the receipt.
11. Comments on the website
If you leave a comment on the website, I collect the data shown in the comment form. Your IP address and browser information may also be processed to detect spam and limit abuse.
Comments may be publicly visible on the website after approval. Therefore, do not include information in a comment that you do not wish to make public, such as medical data, private information, or information about others.
An anonymized string, generated based on your email address, may be shared with the Gravatar service if this feature is active. This allows verification that you are using a Gravatar profile. After approval of your comment, your profile picture may be publicly visible alongside your comment.
Gravatar's privacy statement is part of Automattic and can be found on the Automattic website.
12. Upload media
Visitors are normally unable to upload images or other media to the website.
If uploading is possible, please note that images may contain location data, such as EXIF GPS data. Visitors can download images and potentially view this location data.
13. Cookies
The website uses cookies. Cookies are small text files that are placed on your device.
When you leave a comment on the website, you may be able to indicate whether your name, email address, and website should be stored in a cookie. This is intended for convenience, so that you do not have to re-enter this information for a subsequent comment. These cookies may be valid for up to 1 year.
The website may also use necessary cookies for security, spam detection, technical functioning, session management, and online booking.
If the website uses analytical or other non-essential cookies, these are only placed when consent is required and that consent has been given.
You can delete or block cookies via your browser settings. Some parts of the website, such as online booking or contact forms, may then not function as well.
14. Embedded content from other websites
The website may contain embedded content, such as videos, images, maps, booking modules, or posts from other websites.
Embedded content from other websites behaves as if you are visiting that other website directly. These external websites may collect data about you, place cookies, use tracking, and monitor your interaction with the content.
Harai has no control over the processing of data by these external parties. For this, please consult the privacy statement of the relevant party.
15. Data storage
In principle, data is kept within the practice.
I do not use cloud storage for practice or client data. Except for encrypted backups, I do not store practice or client data outside the practice.
Backups are intended to enable data recovery in the event of loss, damage, technical failure, or security incident. These backups are encrypted and not intended for daily use.
Paper records are stored in a location that is not freely accessible to unauthorized persons. Digital data is protected by appropriate technical and organizational measures.
16. With whom do I share data?
I only share personal data when necessary.
Possible recipients are:
bookkeeper or administration office, to the extent necessary for financial administration;
payment provider or bank, to the extent necessary for payments;
website administrator or hosting provider, to the extent necessary for the technical management of the website;
provider or plug-in of online booking, to the extent necessary for processing appointments;
spam detection service, to the extent necessary for public comments or forms;
colleague practitioner during anonymous or consent-based consultations;
government agencies, when legally required.
With parties acting on behalf of Harai When processing personal data, appropriate agreements regarding security and confidentiality are made where necessary.
I never sell personal data to third parties.
17. Security
I take appropriate measures to protect personal data against loss, misuse, unauthorized access, and unwanted disclosure.
Only persons who require access for their work activities are granted access to data. Health data is treated confidentially.
Security measures may include local storage, restricted access, password protection, encrypted backups, careful handling of paper files, and regular review of data that is no longer needed.
No system is completely risk-free. If a data breach occurs, I handle it in accordance with applicable legal regulations.
18. How long do I retain data?
I do not retain personal data longer than necessary for the purpose for which it was collected, unless a statutory retention period applies.
Broadly speaking, the following retention periods apply:
public comments on the website: as long as the comment remains relevant to the website, unless removal is requested and there is no reason to retain the comment;
metadata for comments: as long as necessary for moderation, spam detection, and security;
contact details and correspondence: for as long as necessary for answering, handling appointments, or follow-up contact;
online booking details: as long as necessary for appointment management, administration, and potential follow-up;
intake data and treatment data: for as long as necessary for careful guidance, follow-up, accountability, or handling of any questions or complaints;
financial records: in principle 7 years due to the tax retention obligation;
data regarding gift cards and credit vouchers: for as long as necessary for use, verification and administration;
technical website details: as short as possible, depending on security, spam detection and website management;
Encrypted backups: as long as necessary for recovery and security, after which they are overwritten or deleted according to the backup process.
When data is no longer needed, it is deleted or anonymized.
19. What rights do you have?
You have various rights under privacy legislation. You can request:
access to your personal data;
correction of incorrect data;
deletion of data;
restriction of processing;
transfer of data;
objection to processing;
withdrawal of previously given consent.
For public comments, you may request the removal or anonymization of your comment, unless there is a compelling reason to retain the comment.
Sometimes I am unable to fully comply with a request, for example when data is required for administration, legal obligations, substantiation of rights, or protection against legal claims.
I may ask to confirm your identity before I process a request.
20. Privacy complaint
If you have a question or complaint about the processing of your personal data, you can contact Harai via:
E-mail: paul@harai.nl
You also have the right to file a complaint with the Dutch Data Protection Authority.
21. Amendments
This privacy statement may be amended when the practice, website, systems used, or legislation changes.
The most recent version is on the website.
Last updated: June 3, 2026