Privacy Policy
Preamble
With this Privacy Policy, we would like to inform you about the type, scope, and purpose of the processing of personal data (hereinafter referred to as "data") within our practice's online services and associated websites, applications, and external online presences (such as our social media profiles, collectively referred to as "online services").
The terms used herein are gender-neutral.
Last updated: September 29, 2025
Contents Overview
Preamble
Data Controller
Overview of Processing Activities
Applicable Legal Bases
Security Measures
Transfer of Personal Data
International Data Transfers
General Information on Data Retention and Erasure
Rights of Data Subjects
Business and Practice Services
Provision of Online Services and Web Hosting
Use of Cookies
Contact and Inquiry Management
Web Analytics, Monitoring, and Optimization
Online Marketing
Customer Reviews and Rating Procedures
Social Media Presences
Plugins, Embedded Content, and External Functions
Data Controller
Katharina Rübsam / Dermatology Practice Burgstrasse
Burgstrasse 7
80331 Munich, Germany
Email: info@derma-burgstrasse.de
Overview of Processing Activities
The following summary provides an overview of the types of data processed, the purposes of processing, and the categories of data subjects involved.
Types of Data Processed
Master data (e.g., full name, address, contact details, patient/customer ID).
Payment data (e.g., bank details, invoices, payment history).
Location data.
Contact details (e.g., email address, phone number, postal address).
Content data (e.g., text entries, photographs, uploaded files).
Contractual data (e.g., service scope, duration, patient category).
Usage data (e.g., page visits, access times, interaction with site elements).
Meta, communication, and technical process data (e.g., IP addresses, device information, browser details).
Server log files.
Categories of Data Subjects
Patients, clients, and service recipients.
Prospective patients and inquiring individuals.
Communication partners.
Website users and visitors.
Business and contractual partners.
Purposes of Processing
Provision of contractual and medical practice services.
Communication and handling inquiries.
Security measures and system stability.
Reach measurement and traffic analysis.
User tracking and performance optimization.
Administrative and organizational procedures.
Audience group segmentation.
Feedback collection.
Practice marketing and public relations.
User profiling (pseudonymized).
Delivery and user-friendliness of online services.
IT infrastructure management.
Applicable Legal Bases
Relevant Legal Bases under the GDPR
Below is an overview of the primary legal bases under the General Data Protection Regulation (GDPR / DSGVO) upon which we process personal data:
Consent (Art. 6(1)(a) GDPR): The data subject has given consent to the processing of their personal data for one or more specific purposes.
Performance of a Contract and Pre-contractual Inquiries (Art. 6(1)(b) GDPR): Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Legal Obligation (Art. 6(1)(c) GDPR): Processing is necessary for compliance with a legal obligation to which the controller is subject.
Legitimate Interests (Art. 6(1)(f) GDPR): Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
National Data Protection Regulations in Germany
In addition to the GDPR, national data protection laws in Germany apply, specifically the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG includes specific provisions regarding the right of access, right to erasure, right to object, processing of special categories of personal data (such as health data under § 22 BDSG), and automated individual decision-making/profiling.
Security Measures
In accordance with statutory requirements and taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the varying risk of likelihood and severity for the rights and freedoms of natural persons, we implement appropriate technical and organizational measures (TOMs) to ensure a level of security appropriate to the risk.
These measures include protecting the confidentiality, integrity, and availability of data by controlling physical and electronic access, input, disclosure, availability, and separation of data. Furthermore, we maintain procedures to ensure the exercise of data subject rights, data deletion, and responses to data security threats. Data protection principles are also integrated into hardware and software selection (privacy by design and privacy by default).
Encryption (SSL/TLS via HTTPS)
To protect user data transmitted via our online services against unauthorized access, we utilize Transport Layer Security (TLS) / Secure Sockets Layer (SSL) encryption. Secured pages are indicated by the https:// prefix in your browser's address bar.
Transfer of Personal Data
In the course of our processing activities, personal data may be transferred to or disclosed to third parties, independent organizational units, or external service providers (e.g., IT hosting providers, medical administrative services, or embedded content providers). In all such cases, we comply with strict legal requirements and enter into Data Processing Agreements (DPAs / Auftragsverarbeitungsverträge) pursuant to Art. 28 GDPR to safeguard your data.
International Data Transfers
Data Processing in Third Countries
If data is processed in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or in the context of using third-party services, transfers occur strictly in accordance with statutory requirements.
For transfers to the USA, we rely primarily on the EU-U.S. Data Privacy Framework (DPF), recognized as an adequate level of protection by the European Commission as of July 10, 2023. Additionally, we implement Standard Contractual Clauses (SCCs) issued by the European Commission as a secondary contractual safeguard.
Information on the DPF and certified companies can be found on the U.S. Department of Commerce website: https://www.dataprivacyframework.gov/.
General Information on Data Retention and Erasure
We erase personal data as soon as the underlying consent is withdrawn or the purpose for processing ceases to exist, provided no legal retention obligations apply.
In Germany, statutory retention periods include:
10 Years: Financial records, tax records, accounting vouchers, invoices, and general balance sheets (§ 147 AO, § 257 HGB).
10 Years: Medical patient records and documentation pursuant to § 630f BGB (German Civil Code) and professional medical regulations (Musterberufsordnung).
6 Years: General commercial correspondence and tax-relevant documentation (§ 147 AO, § 257 HGB).
3 Years: Data subject to standard civil limitation periods (§§ 195, 199 BGB) for defending or asserting legal claims.
Rights of Data Subjects
Under the GDPR, data subjects possess the following rights:
Right to Object (Art. 21 GDPR): Right to object at any time, on grounds relating to your particular situation, to the processing of personal data based on Art. 6(1)(e) or (f) GDPR. You may also object to direct marketing processing at any time.
Right to Withdraw Consent (Art. 7(3) GDPR): Right to revoke granted consent at any time with future effect.
Right of Access (Art. 15 GDPR): Right to obtain confirmation as to whether personal data is being processed and receive a copy of that data.
Right to Rectification (Art. 16 GDPR): Right to request correction of inaccurate data or completion of incomplete data.
Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): Right to request immediate deletion of personal data where legal conditions are met.
Right to Restriction of Processing (Art. 18 GDPR): Right to request restriction of data processing under specific statutory criteria.
Right to Data Portability (Art. 20 GDPR): Right to receive your personal data in a structured, commonly used, and machine-readable format or request transmission to another controller.
Right to Lodge a Complaint (Art. 77 GDPR): Right to file a complaint with a competent Data Protection Supervisory Authority (e.g., Bayerisches Landesamt für Datenschutzaufsicht - BayLDA).
Business and Practice Services
We process personal data of our contractual and practice partners (e.g., patients, clients, prospective patients) to fulfill contractual, pre-contractual, and medical service duties.
Processed Data Types: Master data, payment details, contact details, contractual details.
Data Subjects: Patients, practice partners, prospective clients.
Legal Bases: Contract performance and pre-contractual inquiries (Art. 6(1)(b) GDPR), Legal obligation (Art. 6(1)(c) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
Provision of Online Services and Web Hosting
To deliver our website reliably, we process technical access data necessary to render site content to your device.
Processed Data Types: Usage data (e.g., page visits), technical log files (IP address, timestamp, browser type, referrer URL).
Storage Period: Server log files are stored for a maximum of 30 days for security and DDoS protection, after which they are erased or anonymized.
Legal Basis: Legitimate interests (Art. 6(1)(f) GDPR).
Use of Cookies
Cookies are small text files stored on your device that retain user settings or analytics data.
Session Cookies: Automatically deleted when you close your browser.
Persistent Cookies: Remain stored for a defined duration (up to 2 years) to save preferences or track return visits.
Consent Management: Where legally required, cookies are set strictly based on user opt-in consent (Art. 6(1)(a) GDPR) managed via our consent banner. Essential technical cookies are set based on legitimate interest (Art. 6(1)(f) GDPR).
Contact and Inquiry Management
When contacting our practice (via email, contact form, or phone), we process your submitted information strictly to handle and respond to your inquiry.
Processed Data Types: Name, contact details, message content.
Legal Bases: Pre-contractual or contractual requests (Art. 6(1)(b) GDPR), Legitimate interests (Art. 6(1)(f) GDPR).
Web Analytics: Google Analytics
Our website uses Google Analytics, a web analytics service provided by Google Ireland Limited ("Google").
Scope & Anonymization: Google Analytics uses cookies to evaluate website usage. We have activated IP masking/anonymization, ensuring user IP addresses within the EU/EEA are truncated before processing. No raw IP addresses are permanently stored.
Third Country Transfer: Safeguarded under the EU-U.S. Data Privacy Framework (DPF) and Standard Contractual Clauses.
Opt-Out: Users can prevent data collection by installing the Google Browser Plugin: https://tools.google.com/dlpage/gaoptout.
Legal Basis: Consent (Art. 6(1)(a) GDPR).
Online Marketing & Social Media
We maintain online presences on platforms such as Instagram (Meta Platforms Ireland Ltd.) and LinkedIn (LinkedIn Ireland Unlimited Company) to communicate with prospective patients and present our clinical services. Processing on these platforms occurs under the privacy policies of the respective network providers.
Plugins and Embedded Content
To enhance user experience, we integrate third-party services and content elements:
Google Fonts (Server Hosted): Delivers standardized typography. IP addresses are processed transiently to serve font files. (Legal Basis: Legitimate Interests / Art. 6(1)(f) GDPR).
Google Maps: Interactive mapping service for finding practice location and directions. (Legal Basis: Consent / Art. 6(1)(a) GDPR).
YouTube Videos: Embedded video content. (Legal Basis: Consent / Art. 6(1)(a) GDPR).
Please also take a look at the German Privacy Policy
Erstellt mit kostenlosem Datenschutz-Generator.de von Dr. Thomas Schwenke