Privacy Policy
Introduction and Overview
We have drawn up this privacy policy (version 21.10.2024-322893869) to explain to you, in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 and applicable national laws, which personal data (hereinafter ‘data’) we, as the data controller – and the data processors commissioned by us (e.g. service providers) – process, will process in future, and what legal options you have. The terms used are to be understood as gender-neutral.
In short: we provide you with comprehensive information about the data we process about you.
Privacy policies usually sound very technical and use legal jargon. This privacy policy, however, aims to describe the most important points to you as simply and transparently as possible. Where it aids transparency, technical terms are explained in a reader-friendly manner, links to further information are provided, and diagrams are used. We therefore explain in clear and simple language that, in the course of our business activities, we only process personal data where there is a corresponding legal basis for doing so. This is certainly not possible if one provides explanations that are as brief, unclear and legally technical as those often found online when it comes to data protection. I hope you find the following explanations interesting and informative, and perhaps you will find one or two useful pieces of information here.
Scope
This privacy policy applies to all personal data processed by us within the company and to all personal data processed by companies we have commissioned (data processors). By ‘personal data’, we mean information as defined in Article 4(1) of the GDPR, such as a person’s name, email address and postal address. The processing of personal data enables us to offer and invoice our services and products, whether online or offline. The scope of this privacy policy covers:
all online platforms (websites, online shops) that we operate
social media platforms and email communications
mobile apps for smartphones and other devices
In short: the privacy policy applies to all areas within the company where personal data is processed via the
Legal Basis
In the following privacy policy, we provide you with transparent information on the legal principles and regulations—that is, the legal basis under the General Data Protection Regulation—which enable us to process personal data.
With regard to EU law, we refer to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016. You can, of course, read this EU General Data Protection Regulation online on EUR-Lex, the portal for EU law, at https://eur-lex.europa.eu/legal-content/DE/ALL/?uri=celex%3A32016R0679.
We process your data only if at least one of the following conditions applies:
- Consent (Article 6(1)(a) of the GDPR): You have given us your consent to process data for a specific purpose. An example would be the storage of the data you entered in a contact form.
- Contract (Article 6(1)(b) of the GDPR): We process your data in order to fulfil a contract or pre-contractual obligations with you. For example, if we enter into a sales contract with you, we require personal information in advance.
- Legal obligation (Article 6(1)(c) GDPR): We process your data where we are subject to a legal obligation. For example, we are legally obliged to retain invoices for accounting purposes. These usually contain personal data.
- Legitimate interests (Article 6(1)(f) GDPR): Where there are legitimate interests that do not restrict your fundamental rights, we reserve the right to process personal data. For example, we need to process certain data in order to operate our website securely and economically efficiently. This processing therefore constitutes a legitimate interest.
Other conditions, such as processing for reasons of public interest, the exercise of official authority, or the protection of vital interests, do not generally apply in our case. Should such a legal basis nevertheless be relevant, it will be indicated in the appropriate section.
In addition to the EU Regulation, national laws also apply:
In Austria, this is the Federal Act on the Protection of Natural Persons with regard to the Processing of Personal Data (Data Protection Act), or DSG for short.
In Germany, the Federal Data Protection Act, or BDSG for short, applies.
Where further regional or national laws apply, we will inform you of this in the following sections.
Contact details of the data controller
If you have any questions regarding data protection or the processing of personal data, please find the contact details of the data controller below:
Association Executive Committee
1. Chairperson:
Anja Yakovleva
2. Chairperson:
Sara-Una Hujic
Zentmarkweg 19,
60489 Frankfurt,
Deutschland
info@poliklinik-frankfurt.de
Retention period
It is our general policy to store personal data only for as long as is strictly necessary for the provision of our services and products. This means that we delete personal data as soon as the reason for processing it no longer applies. In some cases, we are legally obliged to store certain data even after the original purpose has ceased to apply, for example for accounting purposes.
Should you wish to have your data deleted or withdraw your consent to data processing, the data will be deleted as soon as possible, provided there is no legal obligation to retain it.
We provide further details on the specific duration of the respective data processing below, where we have further information on this.
Rights under the General Data Protection Regulation
In accordance with Articles 13 and 14 of the GDPR, we hereby inform you of the following rights to which you are entitled, to ensure that your data is processed fairly and transparently:
- Under Article 15 of the GDPR, you have the right to be informed as to whether we are processing your data. If this is the case, you are entitled to receive a copy of the data and to be informed of the following:
- the purpose for which we are processing the data;
- the categories, i.e. the types of data, being processed;
- who receives this data and, if the data is transferred to third countries, how security is guaranteed;
- how long the data will be stored;
- the existence of the right to rectification, erasure or restriction of processing, and the right to object to processing;
- that you may lodge a complaint with a supervisory authority (links to these authorities can be found below);
- the source of the data, if we did not collect it from you;
- whether profiling is carried out, i.e. whether data is automatically analysed to create a personal profile of you.
- Under Article 16 of the GDPR, you have the right to have your data rectified, which means that we must correct any data if you find any errors.
- Under Article 17 of the GDPR, you have the right to erasure (‘right to be forgotten’), which specifically means that you may request the erasure of your data.
- Under Article 18 of the GDPR, you have the right to restriction of processing, which means that we may only store the data but may not use it further.
- Under Article 20 of the GDPR, you have the right to data portability, which means that, upon request, we will provide you with your data in a commonly used format.
- Under Article 21 of the GDPR, you have the right to object, which, if upheld, will result in a change to the processing of your data.
- If the processing of your data is based on Article 6(1)(e) (public interest, exercise of official authority) or Article 6(1)(f) (legitimate interest), you may object to the processing. We will then assess as soon as possible whether we can legally comply with this objection.
- If data is used for direct marketing purposes, you may object to this type of data processing at any time. We may no longer use your data for direct marketing purposes thereafter.
- If data is used for profiling purposes, you may object to this type of data processing at any time. We may no longer use your data for profiling purposes thereafter.
- Under Article 22 of the GDPR, you may have the right not to be subject to a decision based solely on automated processing (such as profiling).
- Under Article 77 of the GDPR, you have the right to lodge a complaint. This means that you may lodge a complaint with the data protection authority at any time if you believe that the processing of personal data infringes the GDPR.
In short: you have rights – please do not hesitate to contact the data controller listed above!
If you believe that the processing of your data violates data protection law or that your data protection rights have been infringed in any other way, you can lodge a complaint with the supervisory authority. In Austria, this is the Data Protection Authority, whose website can be found at https://www.dsb.gv.at/. In Germany, there is a data protection officer for each federal state. For further information, you can contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI). The following local data protection authority is responsible for our company:
All texts are protected by copyright.
Source: Created using the Data Protection Generator Germany by AdSimple
