Privacy Policy

Preamble

With this Privacy Policy, we would like to inform you about the type, scope, and purpose of the processing of personal data (hereinafter referred to as "data") within our practice's online services and associated websites, applications, and external online presences (such as our social media profiles, collectively referred to as "online services").

The terms used herein are gender-neutral.

Last updated: September 29, 2025

Contents Overview

Data Controller

Katharina Rübsam / Dermatology Practice Burgstrasse

Burgstrasse 7

80331 Munich, Germany

Email: info@derma-burgstrasse.de

Overview of Processing Activities

The following summary provides an overview of the types of data processed, the purposes of processing, and the categories of data subjects involved.

Types of Data Processed

Categories of Data Subjects

Purposes of Processing

Applicable Legal Bases

Relevant Legal Bases under the GDPR

Below is an overview of the primary legal bases under the General Data Protection Regulation (GDPR / DSGVO) upon which we process personal data:

National Data Protection Regulations in Germany

In addition to the GDPR, national data protection laws in Germany apply, specifically the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). The BDSG includes specific provisions regarding the right of access, right to erasure, right to object, processing of special categories of personal data (such as health data under § 22 BDSG), and automated individual decision-making/profiling.

Security Measures

In accordance with statutory requirements and taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the varying risk of likelihood and severity for the rights and freedoms of natural persons, we implement appropriate technical and organizational measures (TOMs) to ensure a level of security appropriate to the risk.

These measures include protecting the confidentiality, integrity, and availability of data by controlling physical and electronic access, input, disclosure, availability, and separation of data. Furthermore, we maintain procedures to ensure the exercise of data subject rights, data deletion, and responses to data security threats. Data protection principles are also integrated into hardware and software selection (privacy by design and privacy by default).

Encryption (SSL/TLS via HTTPS)

To protect user data transmitted via our online services against unauthorized access, we utilize Transport Layer Security (TLS) / Secure Sockets Layer (SSL) encryption. Secured pages are indicated by the https:// prefix in your browser's address bar.

Transfer of Personal Data

In the course of our processing activities, personal data may be transferred to or disclosed to third parties, independent organizational units, or external service providers (e.g., IT hosting providers, medical administrative services, or embedded content providers). In all such cases, we comply with strict legal requirements and enter into Data Processing Agreements (DPAs / Auftragsverarbeitungsverträge) pursuant to Art. 28 GDPR to safeguard your data.

International Data Transfers

Data Processing in Third Countries

If data is processed in a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)), or in the context of using third-party services, transfers occur strictly in accordance with statutory requirements.

For transfers to the USA, we rely primarily on the EU-U.S. Data Privacy Framework (DPF), recognized as an adequate level of protection by the European Commission as of July 10, 2023. Additionally, we implement Standard Contractual Clauses (SCCs) issued by the European Commission as a secondary contractual safeguard.

Information on the DPF and certified companies can be found on the U.S. Department of Commerce website: https://www.dataprivacyframework.gov/.

General Information on Data Retention and Erasure

We erase personal data as soon as the underlying consent is withdrawn or the purpose for processing ceases to exist, provided no legal retention obligations apply.

In Germany, statutory retention periods include:

Rights of Data Subjects

Under the GDPR, data subjects possess the following rights:

Business and Practice Services

We process personal data of our contractual and practice partners (e.g., patients, clients, prospective patients) to fulfill contractual, pre-contractual, and medical service duties.

Provision of Online Services and Web Hosting

To deliver our website reliably, we process technical access data necessary to render site content to your device.

Use of Cookies

Cookies are small text files stored on your device that retain user settings or analytics data.

Contact and Inquiry Management

When contacting our practice (via email, contact form, or phone), we process your submitted information strictly to handle and respond to your inquiry.

Web Analytics: Google Analytics

Our website uses Google Analytics, a web analytics service provided by Google Ireland Limited ("Google").

Online Marketing & Social Media

We maintain online presences on platforms such as Instagram (Meta Platforms Ireland Ltd.) and LinkedIn (LinkedIn Ireland Unlimited Company) to communicate with prospective patients and present our clinical services. Processing on these platforms occurs under the privacy policies of the respective network providers.

Plugins and Embedded Content

To enhance user experience, we integrate third-party services and content elements:

Please also take a look at the German Privacy Policy

Erstellt mit kostenlosem Datenschutz-Generator.de von Dr. Thomas Schwenke