Privacy Policy
How Previon Nordic handles personal information through the public website previonnordic.dk.
This policy applies to the public website previonnordic.dk. It does not describe the processing of personal data inside the SafeMind app, platform, dashboard or customer environments. Those activities are handled through separate customer agreements, data processing agreements and platform privacy/security documentation.
Who is responsible for your data?
Previon Nordic ApS is responsible for the processing of personal data described in this policy.
Previon Nordic ApSCVR: 46406621
Jernbanegade 4, 2. th
5000 Odense C
Denmark
mm@previonnordic.dk
+45 51 60 04 98
What this policy covers
This policy covers personal data processed when you visit previonnordic.dk, use the website's cookie settings, contact Previon Nordic by email or phone, or use the seafarer-doctor service page to book an appointment through the embedded Microsoft Bookings interface.
This includes booking-related processing carried out through Microsoft Bookings, appointment-related processing in Microsoft Power Automate, and the booking confirmations, reminders and internal control emails connected to the seafarer-doctor service.
For the seafarer-doctor service, this policy covers booking and pre-appointment administration. Clinical examination records and the patient journal are handled separately, under applicable healthcare and confidentiality rules, and are not described in full in this policy.
This policy does not cover the SafeMind app, platform, dashboard, or customer administration. It also does not cover employee/end-user health data processed within SafeMind products, customer environments, or under customer agreements. Those activities require separate documentation and agreements, and are also not described in full in this policy.
Personal data we may process
Depending on how you use the website, we may process the following categories of information:
- Technical information such as IP address, browser information, language settings, operating system and device-related information.
- Website interaction and performance data, such as page views, route information, loading performance and interaction events.
- Cookie and consent preferences stored locally in your browser.
- Contact information that you choose to provide, such as name, email address, phone number, organisation, role and message content.
- Information needed to manage security, prevent misuse, document requests or comply with legal obligations.
Please do not send sensitive health information or other special category data through the public website or by general email enquiry unless specifically requested through an appropriate and secure process.
Why we process personal data and our legal basis
We process personal data for the following purposes:
- To operate, display and secure the website. Legal basis: our legitimate interest in running a secure and functional website.
- To remember your cookie and consent preferences. Legal basis: our legitimate interest in respecting your choices and, where applicable, compliance with legal obligations.
- To respond to enquiries sent by email or phone. Legal basis: our legitimate interest in responding to business enquiries and, where relevant, steps prior to entering into a business relationship.
- To understand website performance and improve the website through analytics, where analytics consent has been given. Legal basis: consent.
- To protect the website against misuse, spam, technical errors or security incidents. Legal basis: our legitimate interest in security and risk management.
- To comply with legal obligations and handle requests related to data protection rights. Legal basis: compliance with legal obligations.
- To take steps requested by you and administer the seafarer-doctor service you have booked. Legal basis: performance of steps taken at your request prior to and in connection with the service, and our legitimate interest in administering bookings.
- To manage appointment communication, confirmations, reminders, changes, cancellations and availability through Microsoft Bookings. Legal basis: performance of the requested service and our legitimate interest in reliable appointment administration.
- To document booking choices and agreed conditions, such as the no-show condition and consent responses. Legal basis: our legitimate interest in accurate administration and, where applicable, compliance with legal and healthcare documentation obligations.
- To comply with healthcare, accounting, legal and documentation obligations that apply to the seafarer-doctor service. Legal basis: compliance with legal obligations.
- To process health-related information connected with the seafarer-doctor service, only where necessary and only under the applicable healthcare-law, confidentiality and data-protection basis for that specific processing.
Contact by email or phone
If you contact us by email or phone, we process the information you choose to provide so that we can respond to your enquiry, arrange a conversation, follow up on your request or manage a potential business relationship.
The website's email flow opens your own email application. The website itself does not submit or store a contact form message.
Booking a seafarer-doctor appointment
When you book an appointment for the seafarer-doctor service through the embedded Microsoft Bookings interface on the seafarer-doctor service page, Previon Nordic may process the following information as part of managing your booking:
- Name.
- Email address.
- Telephone number.
- The service you have selected.
- Appointment date and time.
- Booking status, including updates and cancellations.
- Your answers to service-specific booking questions.
- Your acceptance or rejection of the no-show condition.
- Your consent response concerning access to relevant health-record information for the health examination.
Please do not enter your CPR number, a diagnosis, a detailed medical history or other unnecessary health information in free-text booking fields or in general email correspondence.
Microsoft Bookings is used to manage availability, reservations, confirmations, reminders, changes and cancellations for the seafarer-doctor service.
Microsoft Power Automate may inspect the service-specific answers you provide and automatically send an internal email to Mette Molberg when consent to access health-record information, or the no-show condition, has been rejected. Mette Molberg may then contact you directly or manually cancel the appointment.
The information recorded in Microsoft Bookings does not replace any documentation that must be made in your patient record under applicable healthcare rules.
Cookies, local storage, external content and analytics
The website uses a consent manager that allows you to accept, reject or customise optional categories. Your consent choices may be stored locally in your browser so the website can remember your preferences.
Necessary storage is used to make the website and consent settings work correctly.
Analytics is used only if you give analytics consent. When analytics consent is given, Vercel Speed Insights may be used to understand website performance and usage at an aggregated level.
We do not currently use Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, Google Ads or advertising/targeting cookies on this website. If such tools are added later, this policy and the cookie information must be updated, and consent will be requested where required.
The embedded Microsoft Bookings interface on the seafarer-doctor service page is optional external content. It is not loaded until you give external content consent in the cookie settings. You can instead open the booking service directly in a new window at any time. If you withdraw external content consent through the cookie settings, the embedded booking interface is removed.
You can change your cookie preferences at any time by using the cookie settings link on the website.
Service providers and processors
We may use trusted service providers to operate, secure and improve the website and to communicate with people who contact us.
These may include:
- Website hosting and deployment providers, including Vercel.
- Website performance and analytics providers, including Vercel Speed Insights where analytics consent has been given.
- Email and communication providers used to receive and respond to enquiries.
- IT, security and operational service providers that help us run and protect the website.
- Microsoft 365, including Microsoft Bookings, Exchange Online, Microsoft Power Automate and Outlook email, used to manage seafarer-doctor bookings, appointment communication and related internal control emails.
Booking, service and appointment information collected through Microsoft Bookings is stored within Previon Nordic's Microsoft 365 and Exchange environment. Loading the embedded Microsoft Bookings interface on the seafarer-doctor service page may also transmit technical information, such as IP address, browser and device information, to Microsoft.
We do not sell personal data. Service providers may only process personal data for the purposes for which they are engaged and must protect the data appropriately.
International transfers
Some service providers may process or access personal data outside the EU/EEA. Where this happens, we rely on appropriate safeguards where required, such as adequacy decisions, Standard Contractual Clauses or other legally recognised transfer mechanisms.
How long we keep personal data
We keep personal data only for as long as necessary for the purpose for which it was collected or as required by law.
- Cookie and consent preferences are kept until you change your settings, withdraw consent, clear your browser storage, or the consent setup is reset.
- Website technical and security data is kept for as long as necessary for operation, security, troubleshooting and service-provider logging.
- Email enquiries are kept for as long as necessary to respond, follow up and document the relationship. General enquiries are normally deleted or archived when they are no longer relevant, unless a longer period is required for legal, contractual or business documentation purposes.
- Information related to legal requests, disputes or compliance may be kept for as long as necessary to document and handle the matter.
- Booking and appointment data connected to the seafarer-doctor service is retained only as long as needed to administer the service, document the relationship, and comply with applicable healthcare, accounting and legal obligations.
- Internal Power Automate notification emails are deleted or archived when no longer required for appointment handling or documentation.
- Retention of booking-related data may also follow the Microsoft 365 and Exchange retention settings configured by Previon Nordic.
Security
We use technical and organisational measures intended to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
These measures may include access control, encryption, secure hosting, monitoring, supplier management and internal review procedures.
Your rights
Depending on the circumstances, you may have the right to:
- request access to the personal data we process about you;
- request correction of inaccurate information;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain data in a portable format;
- withdraw consent where processing is based on consent;
- complain to a data protection authority.
To exercise your rights, contact us at mm@previonnordic.dk. We may need to verify your identity before responding to a request.
Requests concerning Microsoft Bookings data can be sent to the same address, subject to identity verification and any legal restrictions that apply to clinical documentation.
Complaints
You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data does not comply with applicable data protection law.
For Denmark, the relevant supervisory authority is Datatilsynet.
Data breaches
If a personal data breach occurs, we will assess the incident and take appropriate steps to limit its impact. Where required by law, we will notify the relevant supervisory authority without undue delay and, where required, no later than 72 hours after becoming aware of the breach. If a breach is likely to result in a high risk to affected individuals, we will also notify those individuals where required.
Children
This website is not directed at children. We do not knowingly collect personal data from children through the public website.
Changes to this policy
We may update this policy when our website, use of service providers, cookies, analytics setup or legal obligations change. The latest version will be available on this page.
Last updated: July 2026

