Data Protection

Privacy Policy

Name and contact details of the controller

Your contact person as the controller within the meaning of the European General Data Protection Regulation (“EU GDPR”) and other national data protection laws of the Member States, as well as other data protection provisions, is:

MedVital GmbH & Co. KG

Stefanie-von-Strechine-Str. 6

83646 Bad Tölz

Phone: +49 (0)8022 / 925 41-00

Email: info@medvital-residenz.de

www.medvital-residenz.de

(hereinafter referred to as “we”, “us” or “our”).

Contact details of the Data Protection Officer

The protection of your personal data is of great importance to us. To reflect this importance, we have commissioned a consulting company specialising in data protection and data security to take on these key topics. Our Data Protection Officer also comes from this highly experienced group of experts.

MAGELLAN Säugling Rechtsanwaltsgesellschaft mbH, Raiffeisenallee 9, 82041 Oberhaching / www.magellan-legal.de

Please contact our Data Protection Officer at MAGELLAN Rechtsanwälte directly with any questions regarding data protection and data security.

Email: datenschutz_medvital@magellan-legal.de / Tel.: +49 (0)8022 / 925 41-00

General information on data processing

1. Scope

As a rule, we process your personal data only to the extent necessary to provide a functional website and our content and services.

2. Legal basis

Where we obtain your consent for the processing of your personal data, the legal basis for processing is Art. 6(1) sentence 1 lit. a) EU GDPR.

If your personal data is processed to perform a contract with you or in the context of initiating a contractual relationship, the legal basis for processing is Art. 6(1) sentence 1 lit. b) EU GDPR.

Where processing of personal data is necessary to comply with a legal obligation to which we are subject, the legal basis for processing is Art. 6(1) sentence 1 lit. c) EU GDPR.

If your personal data is processed to safeguard the legitimate interests of us or a third party, and your interests, fundamental rights and freedoms do not override the aforementioned interest, the legal basis for processing is Art. 6(1) sentence 1 lit. f) EU GDPR.

3. Storage period

Your personal data will be deleted as soon as the purpose for storage no longer applies or, if you have a right of withdrawal, you declare the withdrawal of your consent. Storage may also take place if this has been stipulated by the European or national legislator in EU regulations, laws or other provisions to which we are subject. In this case, however, your personal data will be blocked.

4. External links

If we provide links to external websites, this Privacy Policy does not apply to the processing of your personal data by the controller of the linked website. We therefore recommend that you read the privacy notices on the external website you visit. If this link requires a legal basis for the resulting processing of your personal data, this is your consent pursuant to Art. 6(1) sentence 1 lit. a) EU GDPR, which you give by clicking the link.

As a rule, clicking the link (hyperlink) results in the processing of the following personal data of yours:

  • IP address
  • Screen resolution
  • Browser used
  • Bandwidth
  • Language settings

Data processing on our website

1. Website functions

a. Provision of the website and creation of log files

(1) Description and scope

As part of providing our website, we process your personal data to enable error-free delivery of our website to your PC or mobile device. In some cases, your personal data must be stored for the duration of a session.

We also temporarily store your personal data in log files to ensure the functionality of our website and the security of our IT systems. Your personal data is not otherwise processed in log files.

The following personal data of yours is processed:

  • IP address
  • Date of access
  • Time of access
  • Previously visited website
  • Browser used
  • Operating system used

(2) Legal basis

Legitimate interest, Art. 6(1) sentence 1 lit. f) EU GDPR.

Purpose

The purpose of data processing is to provide the website, ensure the functionality of the website, and ensure the security of the IT systems used for this purpose. This purpose also constitutes our legitimate interest.

Storage period

Your personal data is stored in log files for a period of 7 days. In addition, your personal data is stored only for the duration of the session as part of providing the website.

Right to object and possibility of removal

The processing of your personal data and the storage of your personal data in log files is strictly necessary for providing the website, ensuring the functionality of the website, and ensuring the security of the IT systems used. You therefore have no right to object.

Technically necessary cookies

Description and scope

As part of technically necessary cookies, we process your personal data because many functions and services on our website that make it easier for you to use our website, or enable its use in the first place, do not function properly without cookies (so-called “technically necessary cookies”).

By means of these technically necessary cookies, we sometimes store personal data about you, but this is used only for the use of these functions and services. Your personal data is not otherwise processed.

The following personal data is processed:

  • IP address
  • Your browser’s language settings
  • Browser used
  • Shopping cart information

Legal basis

Legitimate interest, Section 25(2) TDDDG in conjunction with Art. 6(1) sentence 1 lit. f) EU GDPR.

Purpose

The purpose of data processing is to provide the functions and services of our website. This purpose also constitutes our legitimate interest.

Storage period

Generally for the duration of the respective session, unless otherwise stated in the detailed information in the list of technically necessary cookies we use.

Right to object and possibility of removal

Technically necessary cookies are stored on your PC or mobile device and transmitted from there to our website. You therefore have full control over the use of technically necessary cookies. You can deactivate or restrict the transmission of cookies by changing your browser settings. Cookies that have already been stored can be deleted at any time. If cookies are disabled for our website, it may no longer be possible to use all functions of the website to their full extent.

Technically non-essential cookies

If technically non-essential cookies are used as part of the functions and services of our website, you will find a list of these cookies, their purpose, storage period and further information in our cookie banner.

2. eCommerce

Contact form and email contact

Description and scope

As part of the contact form and when contacting us by email, the following personal data is processed:

  • Salutation
  • First name
  • Last name
  • Email address
  • Interest in private practice/spa treatment/residence
  • Interest in receiving information material by email/by post
  • Postal address
  • Message content

Legal basis

Legitimate interest, Art. 6(1) sentence 1 lit. f) EU GDPR.

Purpose

The purpose of data processing is to handle your enquiry.

Storage period

Your personal data will be stored until the purpose no longer applies. This usually occurs once your enquiry has been processed, unless longer retention periods apply.

Right to object and possibility of removal

You have the option at any time to object to the processing of your personal data in the context of contacting us for the future. In this case, however, we will not be able to process your enquiry further. All personal data stored in the course of contacting us will be deleted in this case, unless statutory retention periods prevent deletion.

3. Marketing

1. Direct marketing

Description and scope

As part of direct marketing activities, we process your personal data if the narrow scope of application of special laws allows us to contact you for advertising purposes without your consent. We also process your personal data if you have consented to being contacted for advertising purposes.

As part of direct marketing, the following personal data is processed:

  • Salutation
  • First name
  • Last name
  • Postal address
  • Email address
  • Phone number

Legal basis

Legitimate interest, Art. 6(1) sentence 1 lit. f) EU GDPR (post).

Consent, Art. 6(1) sentence 1 lit. a) EU GDPR (post, email, phone).

Legitimate interest, Section 7(3) UWG (email).

Purpose

The purpose of data processing is to carry out direct marketing activities and to send offers and supplementary information.

Storage period

Your personal data will be stored until you object to the processing.

Right to object and possibility of removal

You may object to the processing of your personal data in the context of direct marketing activities at any time with effect for the future.

Web analysis using Google Analytics

Description and scope

As part of web analysis, we use the Google Analytics platform to collect metrics for our website and to analyse your browsing behaviour.

When individual pages of our website are accessed, the following data is stored:

  • IP address
  • Browser used
  • Operating system used
  • Screen resolution
  • Mouse and keyboard behaviour

Legal basis

Consent, Section 25(1) TDDDG in conjunction with Art. 6(1) sentence 1 lit. a) EU GDPR.

Purpose

The purpose of data processing is to analyse your browsing behaviour. By evaluating the data obtained, we are able to compile information about the use of the individual components of our website. This helps us to continuously improve our website and its user-friendliness.

Storage period

You can find a detailed list of the storage period of each “tracking cookie” we use in our cookie banner.

Right to object and possibility of removal

You may revoke your consent at any time with effect for the future by changing the consent settings on our website or adjusting your browser settings.

Alternatively, you can install the browser add-on to deactivate Google Analytics.

Further information on terms of use and data protection can be found at:

http://www.google.com/analytics/terms/de.html

https://support.google.com/analytics/answer/6004245?hl=de

IP anonymisation is also activated on our website.

4. Data protection and legal matters

Exercising your data subject rights pursuant to Art. 12 et seq. EU GDPR

Description and scope

As part of processing data subject rights, we process your personal data. In doing so, we process the contact details you provide in this context exclusively for processing and responding to your message and the subsequent documentation.

Data processed: first name, last name, postal address, email address.

Legal basis

Legal obligation, Art. 6(1) sentence 1 lit. c) in conjunction with Art. 12 et seq. EU GDPR. Legitimate interest for subsequent documentation, Art. 6(1) sentence 1 lit. f) EU GDPR.

Storage period

3 years after completion of the processing of the respective matter, Section 41 BDSG in conjunction with Section 31(2) no. 1 OWiG.

Legal defence and enforcement

We process your personal data if you assert legal claims against us or if we assert claims and rights against you.

Legal basis

Legitimate interest, Art. 6(1) sentence 1 lit. f) EU GDPR.

Purpose

Defence against unjustified claims and the legal enforcement and assertion of claims and rights.

Storage period

Your personal data will be stored until the purpose no longer applies. This is generally the case once the respective decision becomes final and binding.

Further data processing in addition to our website

Facebook fan page

As part of operating our Facebook fan page, we process your personal data in order to get in touch and interact with users and visitors of the social network “Facebook”.

With regard to Facebook Insights data, we are jointly responsible for data processing with Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

Further information: facebook.com/legal/controller_addendum

Legal basis:

Legitimate interest, Art. 6(1) sentence 1 lit. f) EU GDPR.

Instagram channel

As part of operating our Instagram channel, we process your personal data in order to get in touch and interact with users and visitors of the social network “Instagram”.

With regard to Instagram Insights data, we are jointly responsible for data processing with Meta Platforms Ireland Limited.

Further information: privacycenter.instagram.com/policy

Legal basis:

Legitimate interest, Art. 6(1) sentence 1 lit. f) EU GDPR.

LinkedIn page

As part of operating our LinkedIn page, we process your personal data in order to get in touch and interact with users and visitors of the social job network “LinkedIn”.

With regard to Page Insights data, we are jointly responsible for data processing with LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.

Further information: linkedin.com/legal/privacy-policy

Legal basis:

Legitimate interest, Art. 6(1) sentence 1 lit. f) EU GDPR.

Xing page

As part of operating our Xing page, we process your personal data in order to get in touch and interact with users and visitors of the social network “Xing”.

Further information: privacy.xing.com/de/datenschutzerklaerung

Legal basis:

Legitimate interest, Art. 6(1) sentence 1 lit. f) EU GDPR.

Doctolib appointment scheduling

When scheduling doctor’s appointments via Doctolib, we process the following personal data: appointment type, date, first name, last name, previous visit.

Legal basis:

Performance of a contract, Art. 6(1) sentence 1 lit. b) EU GDPR.

Purpose:

Scheduling your doctor’s appointment.

Telephone appointment scheduling

When scheduling doctor’s appointments by phone, we process the following personal data: appointment type, date, first name, last name, reason for the visit.

Legal basis:

Performance of a contract, Art. 6(1) sentence 1 lit. b) EU GDPR.

Categories of recipients

Within our company, those offices and departments receive personal data that require it to fulfil the purposes stated above. In addition, we sometimes use various service providers:

  • Printing companies
  • Mailing houses
  • Scanning service
  • Banks
  • IT service providers
  • Cooperation partners
  • Lawyers, tax advisors and courts

Transfer to third countries

In the course of processing your personal data, it may happen that we transfer your personal data to trusted service providers in third countries. Third countries are countries outside the European Union (EU) or the European Economic Area (EEA).

In doing so, we work only with service providers that can provide us with appropriate safeguards for the security of your personal data.

If we transfer personal data to third countries, this is done on the basis of an adequacy decision by the European Commission, or on the basis of so-called standard contractual clauses for data protection.

Your rights

You have the following rights vis-à-vis us:

Right of access

You have the right to obtain information as to whether and which personal data relating to you is processed by us.

Right to rectification

You have the right to rectification and/or completion if the personal data relating to you that we process is inaccurate or incomplete.

Right to restriction of processing

You have the right to restriction of processing under certain conditions (e.g. if we are verifying the accuracy of your data or if the processing is unlawful).

Right to erasure

You have the right to erasure if the data is no longer needed for its original purpose, you withdraw your consent, or the processing is unlawful.

Right to be informed

If you have asserted your right to rectification, erasure or restriction, we will notify all recipients of your data of these changes.

Right to data portability

You have the right to receive the personal data relating to you that we process on the basis of consent or for the performance of a contract in a structured, commonly used and machine-readable format.

Right to object

If there are specific reasons, you have the right to object to the processing of your personal data. In the case of direct marketing, you have the right to object at any time.

Right to withdraw consent

You have the right to withdraw any consent you have given to us at any time. The withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

Right to lodge a complaint with a supervisory authority

Competent supervisory authority:

Bavarian State Office for Data Protection Supervision (BayLDA)

Promenade 18

91522 Ansbach

Phone: +49 (0) 981 180093-0

Email: poststelle@lda.bayern.de