HealthCodesAPI

Privacy policy

Last updated 23 September 2026

HealthCodes API is a developer API operated from Belgium. This notice describes what personal data the service holds, why, and what you can ask us to do with it. It is written to be read, not to be survived.

Who the controller is

The controller is the operator of HealthCodes API, reachable at hello@healthcodesapi.be. Postal and company details are shown on the invoice issued for any paid subscription.

What we hold, and why

  • Account details — your email address, and a name if you give one. Needed to create the account, to sign you in, and to contact you about the service. Lawful basis: performance of a contract.
  • A password hash, or a Google account identifier. If you sign in with Google we store the identifier Google assigns you and the address it confirms — never a Google password, and no other Google data. Lawful basis: performance of a contract.
  • API keys — stored only as a SHA-256 hash plus the first characters, so a key cannot be recovered from our records, only recognised.
  • Usage records — per day and per endpoint, the number of requests made by your account. Needed to enforce the quota you agreed to and to bill correctly. Lawful basis: performance of a contract and legitimate interest in preventing abuse. We do not log the content of your queries against your identity.
  • Billing records — a Stripe customer and subscription identifier, and the status of your subscription. Card details are handled by Stripe and never reach our servers. Lawful basis: contract and legal obligation (invoicing, tax).

What we do not hold

The reference data this API serves is public administrative data. It contains no patient information, no practitioner-identifying information, and nothing about the people whose care the codes describe. Nothing you look up here is personal data about a patient, because no such data exists in the source.

We do not use advertising trackers, we do not sell or share personal data, and we do not profile you.

Processors

Personal data is processed on our behalf by:

  • Stripe — payments and invoicing.
  • Resend — transactional email (address confirmation, password reset, quota notices). Sending region: Ireland.
  • Google — only if you choose to sign in with Google.
  • Our hosting provider — the servers on which the service runs, located in the EU.

How long we keep it

Account and usage records are kept while the account exists, and for as long afterwards as invoicing and tax law requires us to keep the billing records they relate to. Ask us to delete the account and we will delete everything not held under that obligation.

Your rights

Under the GDPR you may ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable form. Write to hello@healthcodesapi.be. You also have the right to complain to the Belgian Data Protection Authority (dataprotectionauthority.be).

Cookies

One cookie, holding your sign-in session, plus two short-lived cookies during a Google sign-in that exist only to prove the response belongs to the request. All are strictly necessary, so no consent banner is shown. There are no analytics or advertising cookies.

Source of the data

The reference data originates from RIZIV/INAMI. HealthCodes API is an independent developer service and is not affiliated with or endorsed by RIZIV/INAMI. Official publications remain authoritative.

This notice is published in good faith and describes what the service actually does. It has not been reviewed by a lawyer; if you need a warranty to that effect, ask us before relying on it. Canonical address: https://healthcodesapi.be/legal/privacy