Skip to content
Leading Medicine Guide logo

Privacy Policy

As of July 31, 2026

1. Privacy Policy at a Glance

General Information

The following information provides an overview of what happens to your personal data when you visit our website. Personal data refers to any information that can be used to personally identify you, such as your name, email address, phone number, IP address, or information you submit to us via contact forms.

For detailed information, please refer to the privacy policy below.

Data Controller

The entity responsible for data processing on this website is:

Deutscher Verlag für Gesundheitsinformation GmbH
Vangerowstraße 14/1
69115 Heidelberg
Germany

Email: [email protected]
Phone: +49 (0) 6221 / 5 02 97 - 0

To whom does this policy apply?

This privacy policy is intended for:

  • Visitors to our website, in particular patients and their relatives
  • Doctors, clinics, and medical facilities that are featured on our portal with a profile or request admission
  • Expert authors and individuals appointed by the editorial team
  • Business partners, prospective clients, and job applicants

How do we collect your data?

Your data is collected, on the one hand, when you provide it to us—for example, through entries in contact and inquiry forms, via email, by phone, or in connection with other inquiries.

Other data is collected automatically or with your consent when you visit the website by our IT systems or the services we use. This includes, in particular, technical data such as IP address, browser, operating system, referrer URL, time of page view, pages visited, as well as cookie and usage data.

How do we use your data?

We process personal data primarily for the following purposes:

  • Provision, stability, and security of the website
  • Processing contact, patient, and appointment requests
  • Forwarding inquiries to the doctors, clinics, or medical contacts you have selected
  • Displaying the profiles of listed doctors, clinics, and expert authors
  • Compiling usage and performance statistics for our partners
  • Communication with users, doctors, clinics, and business partners
  • Technical administration and translation of our content
  • Analysis and optimization of our online offerings
  • Integration of external content and services
  • Marketing and audience measurement, provided consent has been obtained
  • Compliance with legal obligations

Special Categories of Personal Data

If you provide us with information regarding your health status, symptoms, diagnoses, treatments, or medical concerns via a form or message, health data as defined in Article 9(1) of the GDPR may be processed.

We process this data only if we have your explicit consent or if there is another legal basis for doing so. Health data is processed exclusively for the purpose for which it was provided, in particular to handle your inquiry and, if necessary, to forward it to the doctor or medical contact person you have selected.

We ask that you provide only the health information in the free-text fields that is actually necessary for your inquiry.

What rights do you have?

In accordance with statutory provisions, you have the following rights in particular:

  • Right of Access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to Object to Certain Processing Activities
  • Right to Withdraw Consent
  • Right to File a Complaint with a Data Protection Supervisory Authority

2. General Information and Mandatory Disclosures

Data Protection

We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG), and the Telecommunications and Digital Services Data Protection Act (TDDDG).

This Privacy Policy explains what personal data we collect, for what purposes we process it, on what legal basis this is done, and what rights you have.

Data Controller

The data controller is:

Deutscher Verlag für Gesundheitsinformation GmbH
Vangerowstraße 14/1
69115 Heidelberg
Germany

Email: [email protected]
Phone: +49 (0) 6221 / 5 02 97 - 0

The data controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

Data Protection Officer

We have appointed an external Data Protection Officer:

dacuro GmbH
Heinrich-Hertz-Straße 11
69190 Walldorf
Germany

For all questions regarding data protection and the exercise of your rights as a data subject, you can contact our Data Protection Officer at:

Email: [email protected]

Legal Bases for Processing

We process personal data based on the following legal grounds:

  • Art. 6(1)(a) GDPR, if you have given us your consent
  • Article 6(1)(b) of the GDPR, if processing is necessary for the performance of a contract or for the implementation of pre-contractual measures
  • Article 6(1)(c) of the GDPR, if we are legally required to process the data
  • Article 6(1)(f) of the GDPR, if the processing is necessary to protect our legitimate interests or the interests of a third party
  • Article 9(2)(a) of the GDPR, if you have expressly consented to the processing of special categories of personal data, in particular health data

Where cookies or similar technologies are used, the storage of information on your device or access to information already stored is governed by § 25 TDDDG. Technically necessary processes are based on Section 25(2) of the TDDDG. For non-essential cookies and services, we obtain your consent in accordance with Section 25(1) of the TDDDG and Article 6(1)(a) of the GDPR.

Retention Period

We store personal data only for as long as is necessary for the respective processing purposes. Afterward, the data is deleted unless there are statutory retention obligations, obligations to provide evidence, or legitimate interests in further storage.

Unless a more specific retention period is stated in this Privacy Policy, we store personal data in particular until:

  • the purpose of the processing no longer applies,
  • you withdraw your consent,
  • you lawfully request erasure,
  • statutory retention periods expire,
  • legal claims have been asserted, exercised, or defended.

Please note that personal data may also be contained in encrypted backups. These are overwritten on a regular basis; therefore, deletion from the production system will not affect the backups until the respective backup cycle has ended.

Recipients of Personal Data

In the course of our business activities, personal data may be transferred to the following recipients or categories of recipients:

  • IT and hosting service providers
  • Technical service providers for the website, maintenance, delivery, and security
  • Providers of analytics, marketing, and consent management services
  • CRM, newsletter, and communication service providers
  • Translation service providers
  • Doctors, clinics, or medical contacts, provided you submit a corresponding request
  • Tax advisors, legal advisors, or government agencies, to the extent required by law
  • Other service providers we engage to provide our services

To the extent that service providers process personal data on our behalf, we enter into data processing agreements with them in accordance with Article 28 of the GDPR.

Data Transfers to Third Countries

Some of the services we use may transfer personal data to countries outside the European Union or the European Economic Area, in particular to the United States and Singapore.

A transfer will only take place if the legal requirements are met, in particular if:

  • there is an adequacy decision by the European Commission,
  • the recipient is certified under the EU-U.S. Data Privacy Framework,
  • standard contractual clauses issued by the European Commission have been concluded,
  • additional safeguards are in place, or
  • you have expressly consented.

In the case of transfers to third countries, it cannot be ruled out that authorities in the respective third country may access personal data without you having the same rights as you would within the EU.

Withdrawal of Your Consent

Many processing operations are only possible with your consent. You may withdraw your consent at any time with future effect. The lawfulness of the processing carried out prior to the withdrawal remains unaffected.

You can withdraw or change your consent to cookies and external services at any time via the cookie settings on our website.

Right to Object under Article 21 of the GDPR

If the processing of your personal data is based on Article 6(1)(e) or (f) of the GDPR, you have the right at any time to object to the processing on grounds relating to your particular situation.

If your personal data is processed for the purpose of direct marketing, you have the right to object to this processing at any time.

Right to File a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. In particular, the supervisory authority responsible is the one in your usual place of residence, your place of work, or the location of the alleged data protection violation.

The supervisory authority responsible for us is the State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart.

Right of Access, Rectification, and Erasure

You have the right to request information about your personal data stored by us. You also have the right to have inaccurate data corrected and, under the conditions set forth by law, to have your personal data erased.

Right to Restriction of Processing

You have the right, under the conditions set forth by law, to request the restriction of the processing of your personal data, in particular if:

  • you contest the accuracy of the data,
  • the processing is unlawful,
  • we no longer need the data, but you need it for the establishment, exercise, or defense of legal claims,
  • you have objected to the processing.

Right to Data Portability

You have the right to receive data that we process automatically based on your consent or to fulfill a contract in a commonly used, machine-readable format, or to have it transferred to another data controller, to the extent that this is technically feasible.

SSL or TLS Encryption

For security reasons, our website uses SSL or TLS encryption. You can recognize an encrypted connection by “https://” in your browser’s address bar and by the padlock icon.

Objection to Marketing Emails

We object to the use of contact information published in accordance with our legal notice requirements for the purpose of sending unsolicited advertising.

3. Hosting, Content Delivery, and Security

Hosting

Our website is hosted by an external hosting provider in Germany.

The provider is:

Hetzner Online GmbH
Industriestraße 25
91710 Gunzenhausen
Germany

When you visit our website, the hosting provider processes personal data, in particular technical access data, which is necessary for the operation, security, and delivery of the website. This may include, in particular:

  • IP address
  • Date and time of access
  • URL accessed
  • Referrer URL
  • Browser type and version
  • Operating system
  • Hostname of the accessing computer
  • Amount of data transferred
  • Status codes
  • Technical log data

Processing is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure, stable, and efficient provision of our website.

We have a contract with the hosting provider for data processing on our behalf in accordance with Article 28 of the GDPR.

Server Log Files

The website provider automatically collects and stores information in so-called server log files that your browser automatically transmits. These include, in particular:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address
  • Requested file or URL
  • HTTP status code
  • Amount of data transferred

This data is not combined with other data sources under any circumstances. However, an analysis may be conducted if there are concrete indications of unlawful use, attacks on our systems, or other security incidents.

The processing of server log files is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring the technically flawless display, stability, and security of our website, as well as in investigating and defending against misuse and attacks.

Server log files are stored only for as long as necessary for the aforementioned purposes. They may be stored for a longer period if this is necessary to investigate security incidents, to assert, exercise, or defend legal claims, or to comply with legal obligations.

Cloudflare

We use Cloudflare services to ensure the secure and efficient delivery of our website.

The provider is:

Cloudflare, Inc.
, 101 Townsend Street
, San Francisco, CA 94107
, USA

Cloudflare provides a globally distributed network and acts as a reverse proxy for our website. All requests to our website are therefore routed through Cloudflare’s servers. In particular, Cloudflare is used to deliver content, improve loading times, provide caching, offer DNS services, operate a web application firewall, provide DDoS and bot protection, and detect unauthorized access.

In particular, the following data may be processed:

  • IP address
  • URL accessed
  • Date and time of the request
  • Referrer URL
  • Browser type and version
  • Operating system used
  • Device information
  • HTTP headers
  • DNS requests
  • Security events
  • Log data
  • Information on detecting and preventing unauthorized access

The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the secure, fast, and reliable provision of our website, as well as in protecting our systems from attacks, misuse, and outages.

We have a data processing agreement with Cloudflare in accordance with Article 28 of the GDPR. The transfer of personal data to the United States or other third countries cannot be ruled out. Such transfers will only take place if the legal requirements are met, in particular based on appropriate safeguards such as EU Standard Contractual Clauses.

For more information on data processing by Cloudflare, please visit:
https://www.cloudflare.com/privacypolicy/
and see Cloudflare’s Data Processing Addendum:
https://www.cloudflare.com/cloudflare-customer-dpa/

Cloudflare Web Analytics

The Cloudflare Web Analytics script (also known as “Cloudflare Insights”) is also integrated into our website. It is loaded from the domain `static.cloudflareinsights.com`.

Cloudflare Web Analytics is used to measure page views and technical performance metrics of our website, such as load times and Web Vitals metrics. According to the provider, the service operates without cookies or fingerprinting and does not create cross-page user profiles. The data processed includes, in particular, the page accessed, the referrer URL, browser and device information, approximate location information at the country level, and technical performance metrics.

The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in the data-minimal, cookie-free measurement of the technical performance and usage of our website.

5. Contact, Patient Inquiries, and Appointment Requests

General Contact Forms

If you contact us via a contact form, we process the data you enter to handle your inquiry. This may include:

  • Name
  • Email address
  • Phone number
  • Message text
  • Company or organization, if applicable
  • Technical metadata
  • Time of the request

Depending on the content of the inquiry, processing is carried out on the basis of Article 6(1)(b) of the GDPR, Article 6(1)(f) of the GDPR, or, if you provide consent, Article 6(1)(a) of the GDPR.

Medical Inquiries and Health Data

If you submit an inquiry via our website to a doctor, a clinic, or a medical contact person, health data may be processed. This includes, in particular, information regarding symptoms, diagnoses, treatments, medical concerns, or other health-related information, as well as documents you have uploaded.

The processing of such data is based on your explicit consent pursuant to Article 9(2)(a) of the GDPR and Article 6(1)(a) of the GDPR.

We use the data you provide exclusively to process your inquiry and, if you so request, to forward it to the doctor, clinic, or medical contact person you have selected.

This data will not be used for advertising purposes or for any other purposes of our own unless you have given separate consent for such use.

Appointment Requests, Callback Requests, and Voice Messages

Through our partners’ profile pages, you can submit appointment requests and callback requests, as well as—where available—leave a voice message.

In doing so, we process, in particular, your name, your contact information, your appointment request, the doctor or clinic you have selected, the voice message you recorded (if applicable), as well as technical metadata and the time of the request. If your request or voice message contains health-related information, the provisions regarding medical inquiries apply accordingly.

The legal basis is Article 6(1)(b) of the GDPR for the implementation of pre-contractual measures and, to the extent that health data is involved, your explicit consent pursuant to Article 9(2)(a) of the GDPR.

Forwarding to Doctors or Clinics

If you contact a doctor or clinic through our website, we will forward your inquiry and the personal data it contains to the recipient you have selected.

This transfer is made for the purpose of processing your medical inquiry and is based on your consent.

Please note that once the respective doctor or clinic receives your inquiry, they are solely responsible for the further processing of your data. The privacy policy of the respective recipient applies to this processing.

Inquiries via Email, Phone, or Fax

If you contact us via email, phone, or fax, we will process your information to handle your inquiry.

Processing is based on Article 6(1)(b) of the GDPR if your inquiry relates to a contract or pre-contractual measures. In all other cases, processing is based on Article 6(1)(f) of the GDPR or your consent pursuant to Article 6(1)(a) of the GDPR.

Retention Period for Inquiries

We store the data you provide until the purpose of the processing no longer applies, you withdraw your consent, or you request its deletion. Statutory retention requirements remain unaffected.

For medical inquiries, we regularly review whether further storage is necessary. Longer storage may be necessary, in particular, if there are interests related to evidence, documentation, or legal defense.

6. Registration and Membership Inquiries from Physicians and Clinics

Doctors, clinics, and medical facilities can request admission to our portal or inquire about membership via our website. The forms provided for this purpose are made available in part via our own form subdomains and via Zoho services.

In doing so, we process the following information in particular:

  • Name, title, and specialty
  • Practice, clinic, or company information
  • Professional contact information
  • Information on qualifications, areas of expertise, certifications, and admission criteria
  • Voluntary additional information and free-text fields
  • Technical metadata and time of the request

Data processing is carried out to review and process your inquiry, as well as to take pre-contractual measures, based on Article 6(1)(b) of the GDPR. To the extent that you voluntarily provide us with additional information, processing is based on Article 6(1)(a) of the GDPR.

Inquiries from physicians and clinics are processed in our CRM system (see the “Zoho CRM” section).

7. Profiles of Listed Physicians, Clinics, and Expert Authors

On our portal, we publish editorially prepared profiles of physicians, clinics, and expert authors. These profiles contain personal data of the individuals featured.

In particular, the following may be published:

  • Name, title, and academic degrees
  • Specialty, areas of focus, and treatments offered
  • Professional background, qualifications, memberships, and awards
  • Practice or clinic address and professional contact information
  • Portrait photos and other images
  • Interviews, professional articles, and author information
  • Location information for display on a map

The legal basis is Article 6(1)(b) of the GDPR, to the extent that publication is based on a contractual agreement with the respective physician, clinic, or author. Additionally, we base the publication of editorial content on Article 6(1)(f) of the GDPR; our legitimate interest and the public interest lie in providing information about medical services and areas of treatment specialization. To the extent that you provide us with visual material or voluntary information for publication, processing is additionally based on your consent pursuant to Article 6(1)(a) of the GDPR.

The profiles remain published as long as the underlying contractual relationship exists or a legitimate interest in their display continues to exist. Data subjects may at any time request the correction, supplementation, blocking of individual details, or deletion of their profile.

Please note that our content may be indexed by search engines and temporarily stored there. We have no direct influence over storage in search engine caches or third-party archives.

8. Usage Statistics and Reporting for Our Partners

We analyze the use of our portal to provide our partners—in particular listed doctors and clinics—with statistics on the visibility of their profiles and to further develop our services.

The following data is collected at the level of each profile:

  • Profile page views
  • Clicks on listed phone numbers
  • Views and submissions of the contact form
  • Clicks on the partner’s website
  • Views of the appointment booking page
  • Voice message plays
  • the respective language version, as well as the date and time

This analysis is conducted using our own systems. The results are aggregated into daily and monthly figures for each profile and language version and made available to our partners exclusively in aggregated form. Our partners cannot identify individual users; user profiles are not created.

The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in fulfilling our documentation and reporting obligations to our partners, as well as in tailoring our services to meet user needs. To the extent that information is stored on or read from your device for the purpose of data collection that is not technically necessary, this is done only with your consent in accordance with Section 25(1) of the German Telemedia Act (TDDDG).

We store the aggregated statistical data for the duration of the partnership and, beyond that, for the duration of the statutory retention and statute of limitations periods.

9. Physician Login and Customer Portal

We provide our partners with a password-protected login area where they can manage their profile data and view their statistics. The login area is hosted on a separate subdomain.

For this purpose, we process the following in particular:

  • Name and contact information
  • Username and email address
  • Password in encrypted form
  • Login times and session information
  • IP address and technical log data
  • Master, contract, and profile data

This data is processed to provide the user account, for authentication, to manage access, and to secure the portal, based on Article 6(1)(b) and Article 6(1)(f) of the GDPR.

We generally store access data for as long as the user account exists. Statutory retention requirements remain unaffected.

10. CRM System and Internal Administration

Zoho CRM

We use Zoho CRM services to process, manage, and document inquiries, contacts, communications, and business processes.

The provider is:

Zoho Corporation B.V.
, Beneluxlaan 4B
, 3527 HT Utrecht
, Netherlands

Zoho CRM is used in particular to process inquiries received via our website in a structured manner, manage contacts, document communication, and organize internal workflows. In particular, the following data may be processed:

  • Name
  • Contact information, specifically email address and phone number
  • Company or organization details
  • Communication content and inquiry content
  • Assignment to doctors, clinics, contacts, or business partners
  • Processing status
  • Technical metadata and time of contact
  • Internal notes and case histories

If you provide us with medical information or other health-related information via the website, this information may also be processed in Zoho CRM, provided that this is necessary to handle your inquiry.

The legal bases are Article 6(1)(b) of the GDPR, to the extent that processing is necessary for the implementation of pre-contractual measures or for the performance of a contract, as well as Article 6(1)(f) of the GDPR based on our legitimate interest in the efficient processing and management of inquiries and business processes.

To the extent that health data or other special categories of personal data within the meaning of Article 9(1) of the GDPR are processed, this is done on the basis of your explicit consent pursuant to Article 9(2)(a) of the GDPR as well as Article 6(1)(a) of the GDPR, provided that no other legal basis applies.

We have a data processing agreement with Zoho in accordance with Article 28 of the GDPR. A transfer of personal data to companies within the Zoho Group or to service providers outside the European Union or the European Economic Area cannot be ruled out. In this case, the transfer takes place only on the basis of an adequacy decision, appropriate safeguards such as EU Standard Contractual Clauses, or explicit consent.

Personal data in Zoho CRM is deleted as soon as it is no longer necessary for the respective purposes and no statutory retention periods, obligations to provide evidence, or legitimate interests preclude deletion.

11. Analytics, Statistics, and Marketing

The services mentioned in this section—with the exception of Google Tag Manager itself—are loaded exclusively with your consent. You can revoke your consent at any time via the cookie settings.

Google Tag Manager

We use Google Tag Manager.

The provider is:

Google Ireland Limited
, Gordon House, Barrow Street
, Dublin 4
, Ireland

Google Tag Manager is used to manage website tags. Google Tag Manager itself does not create user profiles or store its own analytics cookies. However, it loads the services listed below, which in turn process personal data. The loading of these services is linked to the selection you made in the consent banner.

The use of Google Tag Manager is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in the efficient and consent-compliant management of services on our website.

Google Analytics 4

We use Google Analytics 4, a web analytics service provided by Google Ireland Limited (address as above).

Google Analytics enables us to analyze the use of our website. In particular, the following data may be processed:

  • IP address
  • Usage and interaction data
  • Device and browser information
  • Referrer URL and pages visited
  • Approximate location data
  • Cookie IDs or similar identifiers

Google Analytics 4 truncates IP addresses within the EU or the EEA before they are further processed. Data transfer to Google LLC in the U.S. cannot be ruled out. Google LLC is certified under the EU-U.S. Data Privacy Framework; in addition, EU Standard Contractual Clauses are used.

The legal basis is Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG.

Google Ads and Conversion Tracking

We use Google Ads, including conversion tracking and remarketing. The provider is Google Ireland Limited (address as above).

We use Google Ads to place ads in Google Search and the Google Display Network. Conversion tracking helps us determine whether users perform specific actions on our website after clicking on an ad. Through remarketing features, ads can be displayed again to users who have visited our website within the Google Display Network.

In particular, the following data may be processed:

  • IP address
  • Cookie IDs and advertising identifiers
  • Ad interactions
  • Pages visited and conversion data
  • Device and browser information

The legal basis is Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG.

Meta Pixel

We use the Meta Pixel to measure and optimize our advertising campaigns.

The provider is:

Meta Platforms Ireland Limited
, Merrion Road
, Dublin 4, D04 X2K5
, Ireland

The Meta Pixel tracks which pages you visit and what actions you take on our website. This allows us to evaluate advertising efforts, measure conversions, and create target audiences for ad delivery.

A transfer of data to Meta Platforms, Inc. in the United States cannot be ruled out. With regard to the processing of your data by Meta for its own purposes, we and Meta are joint controllers within the meaning of Article 26 of the GDPR.

The legal basis is Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG.

Mouseflow

We use Mouseflow to analyze user behavior on our website.

The provider is:

Mouseflow ApS
Flæsketorvet 68
1711 Copenhagen
Denmark

Mouseflow collects session recordings, heat maps, clicks, scroll and mouse movements, as well as other interactions and technical usage data. Entries in form fields are anonymized by the service before transmission; password fields are generally not recorded.

The legal basis is Art. 6(1)(a) of the GDPR in conjunction with § 25(1) of the TDDDG.

Matomo

We use Matomo to analyze the use of our online offering. We operate Matomo on our own infrastructure within the European Union; the analysis data is not transferred to the manufacturer of Matomo.

Matomo processes the following data in particular:

  • truncated IP address
  • pages visited and referrers
  • Date, time, and duration of visit
  • Browser, operating system, and screen resolution
  • Interactions on the website

Matomo is loaded via Google Tag Manager and uses cookies. Processing therefore takes place solely on the basis of your consent pursuant to Art. 6(1)(a) of the GDPR and § 25(1) of the TDDDG.

Ahrefs Web Analytics

We use Ahrefs Web Analytics for statistical analysis and search engine optimization of our website. It is integrated via Google Tag Manager.

The provider is:

Ahrefs Pte. Ltd.
, 16 Raffles Quay, #33-03 Hong Leong Building
, Singapore 048581

According to the provider, Ahrefs Web Analytics operates without cookies and does not create cross-user profiles. The data processed may include, in particular, pages visited, date and time, referrer URL and traffic source, device, browser, and operating system information, approximate location information, technical event data, and a truncated or otherwise technically processed IP address.

The transfer of personal data to Singapore or other third countries cannot be ruled out. Such transfers are made only on the basis of appropriate safeguards, in particular EU Standard Contractual Clauses.

The legal basis is Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG.

Further information:
https://ahrefs.com/legal/privacy-policy
https://ahrefs.com/legal/data-processing-addendum

12. External Content, Maps, and Security Features

OpenStreetMap and OpenLayers

On our partners’ profile pages, we embed maps to display their locations. The maps are rendered using the OpenLayers JavaScript library; the map data is loaded from OpenStreetMap’s servers.

The provider of the map data is:

OpenStreetMap Foundation
St John’s Innovation Centre, Cowley Road
Cambridge CB4 0WS
United Kingdom

When the map tiles are loaded, your IP address is transmitted to the OpenStreetMap Foundation’s servers. Additionally, browser and device information, the page you are viewing, and the selected map section may be processed.

The legal basis is Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG; the maps are loaded only with your consent.

An adequacy decision by the European Commission is in place for the United Kingdom.

Friendly Captcha

We use Friendly Captcha to protect our forms from misuse, spam, and automated submissions.

The provider is:

Friendly Captcha GmbH
Am Anger 3-5
82237 Wörthsee
Germany

The widget is hosted on our own servers. However, to perform the verification, it retrieves a computational task from the provider’s servers and transmits the result back there for verification. In particular, the IP address, browser and device information, technical verification data, the time of the request, and form-related metadata may be processed. Friendly Captcha operates without cookies and without analyzing user behavior.

The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in protecting our website and our forms from automated access and misuse.

YouTube

We embed YouTube videos on certain pages. The provider is Google Ireland Limited (address as above).

When an embedded YouTube video is played, data may be transmitted to Google, including, in particular, your IP address, device and browser information, the page you visited, and user interactions. If you are signed in to Google through your browser, Google may associate the view with your account.

YouTube content is loaded only with your consent. The legal basis is Article 6(1)(a) of the GDPR in conjunction with Section 25(1) of the TDDDG.

Fonts

The fonts used on our website are hosted locally on our servers. When the fonts are loaded, no connection is established to third-party servers, and no data is transferred to third parties.

External Images, Logos, and Quality Seals

On certain pages, images, logos, or seals from external domains are loaded, including the quality seal of the Aktionsforum Gesundheitsinformationssystem (afgis) as well as media from domains of affiliated services within our corporate group.

When loading external media, the following data in particular may be transmitted to the respective provider:

  • IP address
  • Browser and device information
  • Referrer URL and page accessed
  • Time of access

The legal basis is Article 6(1)(f) of the GDPR; our legitimate interest lies in presenting quality certifications and editorial content. To the extent that external media are not technically necessary, they will only be embedded with your consent.

13. Translation of Our Content

Our portal is available in multiple languages. We use machine translation to translate editorial content and profile texts.

The provider is:

DeepL SE
, Maarweg 165
, 50825 Cologne
, Germany

Translation takes place exclusively on the server side within our editorial system. The content to be translated is transmitted; this may contain personal data of the individuals mentioned in the texts, in particular doctors and authors. Data from website visitors is not transmitted in this process. Proper nouns, such as names of individuals, practices, and clinics, are excluded from the machine translation.

According to the provider, the transmitted texts are deleted once the translation is complete and are not used to train the translation models.

The legal basis is Article 6(1)(f) of the GDPR. Our legitimate interest lies in making our content available in multiple languages. We have a contract with the provider for data processing on our behalf in accordance with Article 28 of the GDPR.

14. Social Media and External Profiles

We maintain an online presence and profiles on social networks and external platforms to provide information about our offerings, communicate with users, and make our content accessible.

Our website includes links, buttons, or QR codes to our social media profiles. Simply visiting our website does not establish a connection to the servers of the respective providers via these links or QR codes. Data is only transmitted when you click the link, scan the QR code, or visit the respective platform.

In particular, we link to the following platforms: Facebook, Instagram, Threads, LinkedIn, Reddit, YouTube, Google Business Profile, Pinterest, Bluesky, TikTok, X, and Mastodon.

When you visit our profiles on these platforms, the privacy policies of the respective platform providers also apply. The platform providers may process personal data, such as your IP address, device information, usage data, interactions, profile information, and communication content. In doing so, data may also be processed outside the European Union or the European Economic Area. We do not have full control over the nature, scope, and purposes of this processing.

When you communicate with us via social media—for example, through messages, comments, likes, or sharing content—we process the data you provide to handle your inquiry and to communicate with you.

The legal basis for this is Article 6(1)(f) of the GDPR. Our legitimate interest lies in public relations, communication, providing information about our offerings, and maintaining our online presence. To the extent that you have given your consent to a platform provider, Article 6(1)(a) of the GDPR serves as the legal basis for processing by the respective provider.

Platform Providers

PlatformProvider
Facebook, Instagram, Threads Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
LinkedIn LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
Reddit Reddit Netherlands B.V. or an affiliate of the Reddit Group
YouTube, Google Company Profile Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Pinterest Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland
Bluesky Bluesky Social, PBC, USA
TikTok TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland
X Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, Ireland
Mastodon Operator of the respective Mastodon instance

Joint Responsibility for Page Insights

We are jointly responsible with Meta Platforms Ireland Limited, within the meaning of Article 26 of the GDPR, for the collection and processing of statistical data regarding our Facebook and Instagram presences (“Page Insights”). Meta provides the key terms of the agreement as well as information on how to exercise your data subject rights. You may exercise your data subject rights with either us or Meta.

15. Newsletter

Newsletter Subscription

If you subscribe to our newsletter, we will process the personal data required for this purpose. This includes, in particular, your email address. Depending on the subscription form, additional information may also be processed, such as your name, title, company, or interests.

A sign-up form may also appear as a pop-up window when you attempt to leave our website. The pop-up appears on the client side; personal data is not transmitted until you fill out and submit the form.

Registration is based on your consent pursuant to Article 6(1)(a) of the GDPR. We use a double opt-in procedure: After signing up, you will receive an email in which you must confirm your registration. This ensures that no one can sign up using someone else’s email address.

When you sign up, we specifically store:

  • Email address
  • Date and time of registration
  • IP address at the time of registration
  • Date and time of confirmation
  • IP address at the time of confirmation
  • Registration form used
  • Consent text
  • Voluntary information, if provided

The registration is logged in order to be able to verify your consent. The legal basis for this is Article 6(1)(c) of the GDPR in conjunction with Article 7(1) of the GDPR and Article 6(1)(f) of the GDPR.

Distribution via Zoho

Our newsletter is sent and managed using Zoho services.

The provider is:

Zoho Corporation B.V.
, Beneluxlaan 4B
, 3527 HT Utrecht
, Netherlands

We use Zoho to send newsletters, manage recipient lists, document subscriptions and unsubscriptions, and organize communication with prospects, customers, physicians, clinics, or other recipients.

We have a data processing agreement with Zoho in accordance with Article 28 of the GDPR. The transfer of personal data to companies within the Zoho Group or to service providers outside the European Union or the European Economic Area cannot be ruled out. In such cases, the transfer will only take place on the basis of an adequacy decision, appropriate safeguards such as EU Standard Contractual Clauses, or explicit consent.

Newsletter Analytics

Our newsletters contain features that allow us to analyze how the newsletter is used. In particular, we track whether a newsletter has been opened and which links have been clicked. This may involve processing open rates, click behavior, time of access, device used, browser information, IP address, and technical delivery data.

This analysis serves to improve our newsletters and make their content more relevant. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR, which you provide when you subscribe to the newsletter. It is not possible to revoke consent for performance measurement alone; this is done by unsubscribing from the newsletter.

Unsubscription and Withdrawal

You can unsubscribe from the newsletter at any time. To do so, you can use the unsubscribe link included in every newsletter or contact us directly.

By unsubscribing, you withdraw your consent to receive the newsletter with future effect. The lawfulness of the processing carried out up to the time of withdrawal remains unaffected.

After you unsubscribe, your data will be deleted from the active newsletter distribution list or blocked for newsletter distribution. We may store your email address in a block list to ensure that you do not receive any further newsletters in the future. Storage in the block list is based on Art. 6(1)(f) of the GDPR; our legitimate interest lies in permanently honoring your revocation.

Retention Period

The data stored for the purpose of receiving the newsletter will be processed for as long as you remain subscribed to the newsletter. After you unsubscribe, your data will be deleted from the active mailing list, provided that no legal retention obligations, obligations to provide evidence, or legitimate interests prevent this. Data required to prove your consent may be stored for the duration of the statutory limitation periods.

16. Job Applications

If you apply for a position with us, we process your application data exclusively for the purpose of conducting the application process. This may include:

  • Name and contact information
  • Application materials, resume, and certificates
  • Qualifications
  • Communication during the application process
  • Other data you have provided

The legal basis is Section 26(1) of the German Federal Data Protection Act (BDSG), Article 6(1)(b) of the General Data Protection Regulation (GDPR), and, if you have given your consent, Article 6(1)(a) of the GDPR.

Application data is generally deleted six months after the conclusion of the application process, unless there are statutory retention requirements or legitimate interests—in particular, to defend against claims under the General Equal Treatment Act—that preclude such deletion. If you have consented to being included in our applicant pool, we will store your data for the agreed-upon period.

17. Obligation to Provide Personal Data

You are generally not required to provide personal data. However, certain information is required for specific functions of our website, particularly contact forms, medical inquiries, appointment requests, or login areas. These required fields are marked on the forms. Without this information, we cannot provide the respective function or service.

18. Automated Decision-Making

Automated decision-making, including profiling as defined in Article 22 of the GDPR, does not take place.

19. Security of Processing

We implement technical and organizational measures in accordance with Article 32 of the GDPR to protect personal data against loss, manipulation, unauthorized access, and misuse. These include, in particular:

  • Transport encryption using TLS
  • Role-based access controls and password protection for internal systems
  • Securing the website with a web application firewall, bot protection, and DDoS protection
  • Protection of forms against automated submissions
  • Logging of security-related events and administrative changes
  • Regular, monitored data backups with a limited retention period
  • Regular updates and testing of the systems in use
  • Configuration of services in compliance with data protection regulations

20. Multilingual Versions

Our website is available in several languages. We provide this Privacy Policy in the respective language versions. In case of doubt, the German version shall prevail, to the extent permitted by law.

21. Changes to This Privacy Policy

We reserve the right to amend this Privacy Policy in the event of technical, legal, or organizational changes. The most current version is available on our website.