Pri­va­cy Poli­cy

Sta­tus: Octo­ber 2026

The pro­tec­tion of your per­so­nal data is important to us. Below, we inform you about how we pro­cess per­so­nal data.

This Pri­va­cy Poli­cy covers both the use of our web­site and the pro­ces­sing of per­so­nal data within the scope of medi­cal tre­at­ment in our prac­ti­ce, as well as in con­nec­tion with appli­ca­ti­ons.

1. Con­trol­ler

The con­trol­ler within the mea­ning of the Gene­ral Data Pro­tec­tion Regu­la­ti­on (GDPR) is:

Dr. med. Corin­na Mann
Owner of the Medi­cal Prac­ti­ce
Prac­ti­ce Name: Pri­va­te Cen­ter ‘Die Kin­der­wunsch­ärz­tin’
Her­zog­s­pi­tal­stra­ße 5
80331 Mün­chen

Pho­ne: (089) 123 595 65
E‑mail: hallo@kinderwunschaerztin.de

For gene­ral data pro­tec­tion inqui­ries, you can also cont­act datenschutz@kinderwunschaerztin.de.

2. Data Pro­tec­tion Offi­cer

We have appoin­ted an exter­nal data pro­tec­tion offi­cer:

kraussfir­men­grup­pe GmbH & Co. KG
Hal­den­loh E 10
86465 Wel­den
Pho­ne: +49 8293 950 80–0
E‑mail: info@kraussakademie.de

I. Data Pro­tec­tion when using our Web­site

3. Gene­ral Data Pro­ces­sing when visi­ting our Web­site

When you visit our web­site, tech­ni­cal­ly neces­sa­ry infor­ma­ti­on is pro­ces­sed. This may include, in par­ti­cu­lar, your IP address, time and dura­ti­on of the page view, pages or files acces­sed, brow­ser type and brow­ser ver­si­on, ope­ra­ting sys­tem, refer­rer URL, and other tech­ni­cal infor­ma­ti­on.

Pro­ces­sing is car­ri­ed out, inso­far as it is neces­sa­ry for the ope­ra­ti­on and secu­re pro­vi­si­on of our web­site, on the basis of Art. 6 para. 1 lit. f GDPR. Our legi­ti­ma­te inte­rest lies in the secu­re, sta­ble, and tech­ni­cal­ly error-free ope­ra­ti­on of our online offe­ring.

4. Hos­ting

Our web­site is hos­ted by an exter­nal hos­ting ser­vice pro­vi­der: Host­Press GmbH, Bahn­hof­stra­ße 34, 66571 Eppel­born. The ser­vers are loca­ted in a data cen­ter in Ger­ma­ny. In par­ti­cu­lar, ser­ver log data and other tech­ni­cal­ly neces­sa­ry data may be pro­ces­sed.

Whe­re neces­sa­ry, an agree­ment on com­mis­sio­ned pro­ces­sing exists with the hos­ting pro­vi­der in accordance with Art. 28 GDPR.

5. SSL or TLS Encryp­ti­on

Our web­site uses SSL or TLS encryp­ti­on. This means that data trans­mit­ted bet­ween your brow­ser and our web­site is encrypt­ed.

6. Coo­kies and Con­sent Manage­ment

Our web­site uses coo­kies and simi­lar tech­no­lo­gies.

Tech­ni­cal­ly neces­sa­ry coo­kies and tech­no­lo­gies are used inso­far as this is requi­red for the secu­re and func­tion­al pro­vi­si­on of our web­site, e.g., for sto­ring your coo­kie set­tings and your lan­guage set­ting. The legal basis for this is Art. 6 para. 1 lit. f GDPR in con­junc­tion with Sec­tion 25 para. 2 no. 2 TDDDG.

Non-essen­ti­al tech­no­lo­gies, par­ti­cu­lar­ly for sta­tis­tics, ana­ly­sis, or mar­ke­ting, are only used after your pri­or con­sent. The legal basis for this is Art. 6 para. 1 lit. a GDPR in con­junc­tion with Sec­tion 25 para. 1 TDDDG.

To mana­ge and docu­ment your cons­ents, we use the Borlabs Coo­kie con­sent manage­ment sys­tem from Borlabs GmbH, Rüben­kamp 32, 22305 Ham­burg. Your con­sent decis­i­on is stored in a coo­kie in your brow­ser and not pas­sed on to Borlabs. You can chan­ge or revo­ke a given con­sent at any time with effect for the future via the set­tings offe­red the­re. The legal basis for the use of the con­sent manage­ment sys­tem is Art. 6 para. 1 lit. c GDPR.

7. Cont­act via Email or Pho­ne

If you cont­act us by email or pho­ne, we pro­cess the infor­ma­ti­on you pro­vi­de to hand­le your request.

If your inquiry rela­tes to the initia­ti­on or exe­cu­ti­on of a tre­at­ment rela­ti­onship, pro­ces­sing is gene­ral­ly based on Art. 6 para. 1 lit. b GDPR. Inso­far as health data is con­cer­ned, pro­ces­sing is car­ri­ed out in par­ti­cu­lar on the basis of Art. 9 para. 2 lit. h GDPR in con­junc­tion with Sec­tion 22 para. 1 no. 1 lit. b BDSG.

In other cases, pro­ces­sing may be based in par­ti­cu­lar on our legi­ti­ma­te inte­rest in the pro­per hand­ling of your inquiry in accordance with Art. 6 para. 1 lit. f GDPR.

8. Exter­nal Appoint­ment Boo­king via arzt-direkt

On our web­site, we pro­vi­de links for online appoint­ment boo­king and online forms via arzt-direkt, a ser­vice of zoll­soft GmbH, Ernst-Hae­ckel-Platz 5/6, 07745 Jena.

arzt-direkt is not direct­ly embedded in our web­site. Only when you click the cor­re­spon­ding link do you lea­ve our web­site and access the arzt-direkt ser­vice.

For data pro­ces­sing taking place the­re, the data pro­tec­tion infor­ma­ti­on of the respec­ti­ve pro­vi­der addi­tio­nal­ly appli­es.

Regard­less, we also use arzt-direkt for our pati­ent com­mu­ni­ca­ti­on and other tre­at­ment pro­ces­ses. We will inform you about this in more detail in the sec­tion “Data Pro­tec­tion Infor­ma­ti­on for Pati­ents.”

9. Exter­nal Pay­ment Page by Stri­pe

For cer­tain ser­vices, par­ti­cu­lar­ly the at-home fer­ti­li­ty test, we link to an exter­nal pay­ment page of the pay­ment ser­vice pro­vi­der Stri­pe (Stri­pe Pay­ments Euro­pe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dub­lin, Ire­land).

Stri­pe is not embedded as a pay­ment modu­le on our web­site. Only when you click the cor­re­spon­ding link do you lea­ve our web­site and pro­ceed to Stri­pe’s check­out.

The pro­ces­sing of per­so­nal data and pay­ment infor­ma­ti­on the­re is car­ri­ed out in accordance with the pay­ment ser­vice pro­vi­der’s data pro­tec­tion infor­ma­ti­on.

10. Ana­ly­sis and Online Mar­ke­ting

We use the ser­vices lis­ted below for sta­tis­ti­cal ana­ly­sis and for mea­su­ring and opti­mi­zing our online adver­ti­sing. The­se ser­vices are only acti­va­ted after your pri­or con­sent.

Goog­le Tag Mana­ger

The pro­vi­der is Goog­le Ire­land Limi­t­ed, Gor­don House, Bar­row Street, Dub­lin 4, Ire­land.

The Goog­le Tag Mana­ger ser­ves for the tech­ni­cal admi­nis­tra­ti­on and deli­very of other web­site ser­vices. It is only loa­ded on our web­site after your con­sent.

Use is exclu­si­ve­ly based on pri­or con­sent in accordance with Art. 6 para. 1 lit. a GDPR and Sec­tion 25 para. 1 TDDDG.

Goog­le Ana­ly­tics

The pro­vi­der is Goog­le Ire­land Limi­t­ed, Gor­don House, Bar­row Street, Dub­lin 4, Ire­land.

Goog­le Ana­ly­tics is used for the sta­tis­ti­cal ana­ly­sis of our web­site’s usa­ge.

This may invol­ve pro­ces­sing infor­ma­ti­on about page views, dura­ti­on of use, devices and brow­sers used, appro­xi­ma­te geo­gra­phi­cal ori­gin, and inter­ac­tions with our web­site.

Use is exclu­si­ve­ly based on pri­or con­sent in accordance with Art. 6 para. 1 lit. a GDPR and Sec­tion 25 para. 1 TDDDG.

Goog­le Ads and Con­ver­si­on Track­ing

The pro­vi­der is Goog­le Ire­land Limi­t­ed, Gor­don House, Bar­row Street, Dub­lin 4, Ire­land.

We use Goog­le Ads and cor­re­spon­ding con­ver­si­on tech­no­lo­gies to mea­su­re the effec­ti­ve­ness of our online adver­ti­sing and opti­mi­ze adver­ti­sing mea­su­res.

Use is exclu­si­ve­ly based on pri­or con­sent in accordance with Art. 6 para. 1 lit. a GDPR and Sec­tion 25 para. 1 TDDDG.

Meta Pixel

The pro­vi­der is Meta Plat­forms Ire­land Limi­t­ed, 4 Grand Canal Squa­re, Dub­lin 2, Ire­land.

We use the Meta Pixel to mea­su­re the effec­ti­ve­ness of adver­ti­sing mea­su­res on Meta plat­forms.

This allows us to track, in par­ti­cu­lar, whe­ther users have per­for­med cer­tain actions on our web­site after inter­ac­ting with an adver­ti­se­ment.

Inso­far as per­so­nal data is coll­ec­ted on our web­site and for­ward­ed to Meta, we and Meta Plat­forms Ire­land Limi­t­ed are joint­ly respon­si­ble for the coll­ec­tion and trans­mis­si­on (Art. 26 GDPR). Fur­ther infor­ma­ti­on can be found at https://www.facebook.com/legal/controller_addendum.

Use is exclu­si­ve­ly based on pri­or con­sent in accordance with Art. 6 para. 1 lit. a GDPR and Sec­tion 25 para. 1 TDDDG.

11. Review Dis­play via Trust­in­dex

On our web­site, we inte­gra­te reviews via the Trust­in­dex ser­vice. The pro­vi­der is Trust­in­dex Ltd., Nyá­ri Pál utca 15, 2724 Újlen­gyel, Hun­ga­ry.

When acces­sing cor­re­spon­ding con­tent, a con­nec­tion is estab­lished with Trust­in­dex ser­vers. In par­ti­cu­lar, the IP address and tech­ni­cal infor­ma­ti­on about the device used may be pro­ces­sed.

The inte­gra­ti­on is based on Art. 6 para. 1 lit. f GDPR. Our legi­ti­ma­te inte­rest lies in an appe­al­ing pre­sen­ta­ti­on of tes­ti­mo­ni­als from our pati­ents.

12. Goog­le Maps

On indi­vi­du­al pages of our web­site, we inte­gra­te maps from Goog­le Maps. The pro­vi­der is Goog­le Ire­land Limi­t­ed, Gor­don House, Bar­row Street, Dub­lin 4, Ire­land. The maps are only loa­ded after your cor­re­spon­ding con­sent.

When loa­ding Goog­le Maps, your IP address and other tech­ni­cal infor­ma­ti­on may be trans­mit­ted to Goog­le.

The legal basis for acti­va­ti­on in this case is Art. 6 para. 1 lit. a GDPR in con­junc­tion with Sec­tion 25 para. 1 TDDDG.

13. Fonts and Icons

The fonts (Goog­le Fonts) and icons (Font Awe­so­me) used on our web­site are pro­vi­ded local­ly on our own web ser­ver. No con­nec­tion to the ser­vers of the respec­ti­ve exter­nal pro­vi­ders is estab­lished sole­ly for retrie­ving the­se resour­ces.

14. Trans­fer to Third Count­ries in con­nec­tion with Web­site Ser­vices

For some of the ser­vice pro­vi­ders we use, par­ti­cu­lar­ly Goog­le and Meta, per­so­nal data may be pro­ces­sed out­side the Euro­pean Uni­on or the Euro­pean Eco­no­mic Area, espe­ci­al­ly in the USA.

Inso­far as data is trans­fer­red to a coun­try for which an ade­quacy decis­i­on by the Euro­pean Com­mis­si­on exists, the trans­fer can be based on this. For the USA, this appli­es to com­pa­nies cer­ti­fied under the EU-US Data Pri­va­cy Frame­work; this is the case for Goog­le and Meta.

Other­wi­se, whe­re neces­sa­ry, appro­pria­te safe­guards are used, in par­ti­cu­lar the stan­dard con­trac­tu­al clau­ses of the Euro­pean Com­mis­si­on.

II. Data Pro­tec­tion Infor­ma­ti­on for Pati­ents

15. What Data We Pro­cess in con­nec­tion with Tre­at­ment

In con­nec­tion with your cont­act, con­sul­ta­ti­on, dia­gno­stics, and tre­at­ment, we pro­cess the per­so­nal data requi­red for this pur­po­se.

This includes, in par­ti­cu­lar:

  • Name, date of birth, address, and other mas­ter data
  • Pho­ne num­ber and email address
  • Insu­rance and bil­ling infor­ma­ti­on
  • Medi­cal histo­ry
  • Dia­gno­ses and fin­dings
  • Labo­ra­to­ry values
  • Medi­ca­ti­on data
  • Infor­ma­ti­on on pre-exis­ting con­di­ti­ons and pre­vious tre­at­ments
  • Infor­ma­ti­on on repro­duc­ti­ve health and, whe­re rele­vant to tre­at­ment, sexu­al and fami­ly histo­ry
  • Gene­tic data, inso­far as cor­re­spon­ding exami­na­ti­ons are car­ri­ed out
  • Tre­at­ment and pro­gress data
  • Appoint­ment and com­mu­ni­ca­ti­on data.

Depen­ding on the tre­at­ment, we also pro­cess medi­cal image and labo­ra­to­ry data, in par­ti­cu­lar ultra­sound images and, whe­re appli­ca­ble in the respec­ti­ve tre­at­ment pro­ce­du­re, micro­sco­pic, embryo- and labo­ra­to­ry-rela­ted image data and docu­men­ta­ti­on.

16. Pur­po­ses and Legal Bases of Pro­ces­sing

We pro­cess your per­so­nal data in par­ti­cu­lar:

  • for the initia­ti­on and exe­cu­ti­on of the tre­at­ment rela­ti­onship
  • for medi­cal dia­gno­stics and the­ra­py
  • for the per­for­mance of repro­duc­ti­ve medi­cal and labo­ra­to­ry medi­cal mea­su­res
  • for docu­men­ting your tre­at­ment
  • for appoint­ment and tre­at­ment orga­niza­ti­on
  • for com­mu­ni­ca­ti­on with you
  • for bil­ling
  • for qua­li­ty assu­rance
  • for ful­fil­ling legal docu­men­ta­ti­on, report­ing, and reten­ti­on obli­ga­ti­ons
  • for asser­ting, exer­cis­ing, or defen­ding legal claims.

The pro­ces­sing of per­so­nal data requi­red for the exe­cu­ti­on of the tre­at­ment con­tract is car­ri­ed out in par­ti­cu­lar on the basis of Art. 6 para. 1 lit. b GDPR.

We pro­cess health data and other spe­cial cate­go­ries of per­so­nal data in par­ti­cu­lar on the basis of Art. 9 para. 2 lit. h GDPR in con­junc­tion with Sec­tion 22 para. 1 no. 1 lit. b BDSG.

Inso­far as we are legal­ly obli­ged to pro­cess data, pro­ces­sing is car­ri­ed out on the basis of Art. 6 para. 1 lit. c GDPR in con­junc­tion with the respec­ti­ve appli­ca­ble legal pro­vi­si­ons.

Inso­far as pro­ces­sing is not alre­a­dy per­mis­si­ble on the basis of the tre­at­ment rela­ti­onship or a legal basis, we will obtain con­sent in accordance with Art. 6 para. 1 lit. a or Art. 9 para. 2 lit. a GDPR, if neces­sa­ry.

A given con­sent can be revo­ked at any time with effect for the future.

17. Ori­gin of Data

Most per­so­nal data is recei­ved direct­ly from you.

Inso­far as this is neces­sa­ry for your tre­at­ment and legal­ly per­mis­si­ble, we may also recei­ve data from refer­ring or co-trea­ting phy­si­ci­ans, medi­cal faci­li­ties, labo­ra­to­ries, or other ser­vice pro­vi­ders.

18. Elec­tro­nic Pati­ent File and Prac­ti­ce and Labo­ra­to­ry Sys­tems

We docu­ment tre­at­ment in an elec­tro­nic pati­ent file and pri­ma­ri­ly use the tome­do® prac­ti­ce manage­ment sys­tem from zoll­soft GmbH for this pur­po­se.

In addi­ti­on, we use spe­cia­li­zed elec­tro­nic prac­ti­ce, labo­ra­to­ry, docu­men­ta­ti­on, iden­ti­fi­ca­ti­on, and qua­li­ty assu­rance sys­tems.

The­se include, among others, local­ly ope­ra­ted sys­tems for the IVF labo­ra­to­ry and elec­tro­nic iden­ti­ty and pro­cess con­trol.

A com­ple­te list of all intern­al­ly used soft­ware pro­ducts is not pro­vi­ded in this Pri­va­cy Poli­cy.

Inso­far as manu­fac­tu­r­ers, IT ser­vice pro­vi­ders, or sup­port com­pa­nies can access sys­tems con­tai­ning per­so­nal data for main­ten­an­ce, remo­te main­ten­an­ce, or sup­port, this is done exclu­si­ve­ly to the ext­ent requi­red for this pur­po­se and in com­pli­ance with appli­ca­ble data pro­tec­tion requi­re­ments.

19. Com­mu­ni­ca­ti­on with Pati­ents

Email and Goog­le Workspace

We use Goog­le Workspace for our busi­ness email com­mu­ni­ca­ti­on and some other orga­niza­tio­nal appli­ca­ti­ons.

This may invol­ve pro­ces­sing cont­act, appoint­ment, and com­mu­ni­ca­ti­on data, as well as health and tre­at­ment data depen­ding on the con­tent of the com­mu­ni­ca­ti­on.

Inso­far as we send con­fi­den­ti­al docu­ments by email, the­se can be addi­tio­nal­ly pro­tec­ted, for exam­p­le, by pass­word-pro­tec­ted attach­ments.

United Domains

For indi­vi­du­al email inbo­xes and tech­ni­cal com­mu­ni­ca­ti­on chan­nels, through which fax and tele­pho­ne mail­box mes­sa­ges can be recei­ved, among other things, we use ser­vices from United Domains.

Sin­ce such mes­sa­ges may ori­gi­na­te from pati­ents, per­so­nal data and, depen­ding on the con­tent of the mes­sa­ge, health data may be pro­ces­sed.

Tele­pho­ny via STARFACE

We use a cloud tele­pho­ne sys­tem from STARFACE for our tele­pho­ne com­mu­ni­ca­ti­on.

This invol­ves pro­ces­sing tele­pho­ne num­bers, con­nec­tion, and com­mu­ni­ca­ti­on data in par­ti­cu­lar.

When using our mail­box, voice recor­dings left by cal­lers may also be stored and pro­ces­sed.

Nor­mal pho­ne calls with our prac­ti­ce are not recor­ded.

Com­mu­ni­ca­ti­on via arzt-direkt

We use ser­vices from arzt-direkt / zoll­soft GmbH for online appoint­ment boo­king, pati­ent forms, ana­mne­ses, video con­sul­ta­ti­ons, and elec­tro­nic com­mu­ni­ca­ti­on func­tions, among other things.

Depen­ding on the respec­ti­ve func­tion, mas­ter and cont­act data, appoint­ment data, com­mu­ni­ca­ti­on data, as well as health and tre­at­ment data may be pro­ces­sed.

Pro­ces­sing is car­ri­ed out, inso­far as it ser­ves the tre­at­ment, in par­ti­cu­lar on the basis of Art. 6 para. 1 lit. b GDPR and Art. 9 para. 2 lit. h GDPR.

SMS via Click­Send

We use the Click­Send SMS ser­vice for trans­mit­ting cer­tain orga­niza­tio­nal infor­ma­ti­on.

We use it in par­ti­cu­lar to send decryp­ti­on codes for sepa­ra­te­ly trans­mit­ted pro­tec­ted docu­ments and occa­sio­nal­ly neu­tral appoint­ment remin­ders.

This invol­ves pro­ces­sing the mobi­le pho­ne num­ber and the respec­ti­ve mes­sa­ge text in par­ti­cu­lar.

Dia­gno­ses, fin­dings, or other medi­cal con­tent are not sent by us via SMS.

Auto­ma­ted Trans­mis­si­on via Zapier

For indi­vi­du­al tech­ni­cal pro­ces­ses, we use Zapier as an inter­face ser­vice.

In par­ti­cu­lar, data from desi­gna­ted Goog­le forms can be auto­ma­ti­cal­ly for­ward­ed to Click­Send.

Only the infor­ma­ti­on requi­red for the respec­ti­ve pro­cess is pro­ces­sed, in par­ti­cu­lar the mobi­le pho­ne num­ber and decryp­ti­on code or mes­sa­ge text.

The cor­re­spon­ding data records are dele­ted prompt­ly after suc­cessful trans­mis­si­on.

20. AI-sup­port­ed Assis­tance Sys­tems

We use AI-sup­port­ed assis­tance sys­tems in sel­ec­ted admi­nis­tra­ti­ve, orga­niza­tio­nal, and tech­ni­cal work pro­ces­ses.

The­se ser­ve in par­ti­cu­lar to sup­port rese­arch, struc­tu­ring, and lin­gu­i­stic pro­ces­sing of infor­ma­ti­on, as well as the deve­lo­p­ment and main­ten­an­ce of inter­nal tech­ni­cal appli­ca­ti­ons.

Inso­far as exter­nal gene­ral AI ser­vices are used for case dis­cus­sions or com­pa­ra­ble tasks, infor­ma­ti­on is gene­ral­ly anony­mi­zed or redu­ced to such an ext­ent that direct iden­ti­fi­ca­ti­on of the data sub­ject is avo­ided.

In indi­vi­du­al appro­ved work pro­ces­ses, we use busi­ness ser­vices from Ope­nAI, inclu­ding in con­nec­tion with appro­ved cor­po­ra­te appli­ca­ti­ons such as our busi­ness email com­mu­ni­ca­ti­on.

Depen­ding on the spe­ci­fic work order, per­so­nal data and, if appli­ca­ble, health data may be pro­ces­sed as a result.

We use busi­ness accounts for this and only employ the ser­vices within the scope of use appro­ved for the prac­ti­ce.

Other exter­nal AI ser­vices are only used with iden­ti­fia­ble pati­ent data if this has been review­ed under data pro­tec­tion law and appro­ved for the respec­ti­ve pro­ces­sing pur­po­se.

AI sys­tems do not make inde­pen­dent medi­cal tre­at­ment decis­i­ons in our prac­ti­ce. Dia­gno­stic and the­ra­peu­tic decis­i­ons are made by our trea­ting phy­si­ci­ans.

21. AI-sup­port­ed Docu­men­ta­ti­on of Con­sul­ta­ti­ons

To sup­port medi­cal docu­men­ta­ti­on, we may use the tome­do® Con­sul­ta­ti­on Assistant from zoll­soft GmbH.

In this pro­cess, a doc­tor-pati­ent con­ver­sa­ti­on is recor­ded and auto­ma­ti­cal­ly tran­scri­bed exclu­si­ve­ly after pri­or expli­cit con­sent from all recor­ded per­sons.

The tran­script can then be struc­tu­red with the help of an AI-sup­port­ed lan­guage model and sum­ma­ri­zed into a docu­men­ta­ti­on pro­po­sal.

The gene­ra­ted con­tent is review­ed by medi­cal pro­fes­sio­nals befo­re being trans­fer­red to the pati­ent file.

The sys­tem ser­ves exclu­si­ve­ly to sup­port docu­men­ta­ti­on. It does not make inde­pen­dent dia­gno­stic or the­ra­peu­tic decis­i­ons.

The use of the Con­sul­ta­ti­on Assistant is vol­un­t­a­ry. Refu­sal has no impact on your tre­at­ment.

The audio recor­ding is only stored for as long as neces­sa­ry for tran­scrip­ti­on, review, and crea­ti­on of the medi­cal docu­men­ta­ti­on, and is then dele­ted as quick­ly as pos­si­ble.

The medi­cal docu­men­ta­ti­on trans­fer­red to the pati­ent file, howe­ver, is sub­ject to sta­tu­to­ry reten­ti­on peri­ods.

22. Exter­nal Medi­cal Dia­gno­stics and Labo­ra­to­ries

Inso­far as it is neces­sa­ry for dia­gno­stics and tre­at­ment, we trans­mit the requi­red per­so­nal data, health data, and, if appli­ca­ble, exami­na­ti­on mate­ri­al to exter­nal medi­cal labo­ra­to­ries and spe­cia­li­zed dia­gno­stic faci­li­ties.

This con­cerns in par­ti­cu­lar:

  • Spe­cial hor­mo­ne ana­ly­ses
  • Infec­tion dia­gno­stics
  • Gene­tic exami­na­ti­ons
  • Other spe­cial exami­na­ti­ons that we do not per­form our­sel­ves.

For gene­tic exami­na­ti­ons, we col­la­bo­ra­te with, among others, the Medi­cal Gene­tic Cen­ter (MGZ) Munich.

For gene­tic exami­na­ti­ons, we obser­ve the spe­cial legal requi­re­ments, in par­ti­cu­lar the pro­vi­si­ons of the Gene­tic Dia­gno­stics Act, inclu­ding the neces­sa­ry infor­ma­ti­on and con­sent.

23. Ger­man IVF Regis­ter

We par­ti­ci­pa­te in the Ger­man IVF Regis­ter (D·I·R).

A pseud­ony­mi­zed trans­mis­si­on of tre­at­ment data to the D·I·R takes place with us after a sepa­ra­te­ly obtai­ned con­sent for this pur­po­se.

For this, we use a sepa­ra­te con­sent form.

Pati­ent mas­ter data is not trans­mit­ted to the D·I·R.

The trans­mit­ted data ser­ves in par­ti­cu­lar for qua­li­ty assu­rance and sci­en­ti­fic eva­lua­ti­on of repro­duc­ti­ve medi­cal tre­at­ments.

24. Cryo­p­re­ser­va­ti­on and FERTILA GmbH

If you deci­de on cryo­p­re­ser­va­ti­on and sub­se­quent sto­rage, the per­so­nal data and health data requi­red for this pur­po­se may be trans­mit­ted to FERTILA GmbH.

FERTILA GmbH con­cludes its own con­tract with you for sto­rage, bills its ser­vices its­elf, and pro­ces­ses the data requi­red for this under its own data pro­tec­tion respon­si­bi­li­ty.

You will recei­ve sepa­ra­te data pro­tec­tion infor­ma­ti­on regar­ding the pro­ces­sing of your data by FERTILA GmbH.

25. Sperm Banks and other Medi­cal Faci­li­ties

The sel­ec­tion and com­mis­sio­ning of exter­nal sperm banks is gene­ral­ly done by the pati­ents them­sel­ves.

Inso­far as you express­ly com­mis­si­on us with com­mu­ni­ca­ti­on or pro­ces­sing with a sperm bank or ano­ther repro­duc­ti­ve medi­cal faci­li­ty, we trans­mit the per­so­nal and, if appli­ca­ble, medi­cal data requi­red for this to the neces­sa­ry ext­ent.

The same appli­es if, at your request, samples, tre­at­ment docu­ments, or other medi­cal infor­ma­ti­on are to be trans­mit­ted to ano­ther medi­cal faci­li­ty.

26. Bil­ling

As a pri­va­te prac­ti­ce, we gene­ral­ly bill our medi­cal ser­vices direct­ly to our pati­ents.

Trans­mis­si­on of bil­ling, tre­at­ment, or other per­so­nal data to pri­va­te health insu­rance com­pa­nies or other cost bea­rers is gene­ral­ly only car­ri­ed out by us at your request or with your cor­re­spon­ding appr­oval, or if ano­ther legal basis exists for this.

We do not use an exter­nal pri­va­te medi­cal bil­ling ser­vice pro­vi­der.

27. Pay­ment Ser­vice Pro­vi­ders

Depen­ding on the cho­sen pay­ment method, pay­ment data may be pro­ces­sed by exter­nal pay­ment ser­vice pro­vi­ders.

The­se curr­ent­ly include, in par­ti­cu­lar:

  • Stri­pe
  • Pay­Pal
  • SumUp
  • the pay­ment ser­vice pro­vi­der used for pay­ments via arzt-direkt.Pay.

The pro­ces­sing of data requi­red for pay­ment pro­ces­sing is car­ri­ed out accor­ding to the respec­ti­ve appli­ca­ble data pro­tec­tion infor­ma­ti­on of the pay­ment ser­vice pro­vi­ders.

Pay­Pal and SumUp are used by us in par­ti­cu­lar for on-site pay­ments.

28. Tax Con­sul­ting and Accoun­ting

To ful­fill our legal tax, com­mer­cial, and accoun­ting obli­ga­ti­ons, we trans­mit neces­sa­ry data to tax con­sul­ting and accoun­ting ser­vice pro­vi­ders com­mis­sio­ned by us.

This may also invol­ve pro­ces­sing indi­vi­du­al out­go­ing invoices with the pati­en­t’s name and ser­vice items.

The trans­mis­si­on is limi­t­ed to the ext­ent neces­sa­ry for the respec­ti­ve pur­po­se.

29. Aut­ho­ri­ties and Legal­ly Desi­gna­ted Reci­pi­ents

Inso­far as we are obli­ged to report, docu­ment, or trans­mit per­so­nal data due to legal, super­vi­so­ry, or pro­fes­sio­nal regu­la­ti­ons, data may be trans­mit­ted to the com­pe­tent aut­ho­ri­ties or other legal­ly desi­gna­ted bodies to the ext­ent requi­red.

30. Reten­ti­on of Tre­at­ment Data

Pati­ent files and tre­at­ment docu­ments are retai­ned in accordance with legal regu­la­ti­ons.

For medi­cal pati­ent files, the sta­tu­to­ry basic reten­ti­on peri­od is gene­ral­ly ten years after the com­ple­ti­on of tre­at­ment.

For indi­vi­du­al data, samples, docu­men­ta­ti­on, and records, dif­fe­rent and lon­ger reten­ti­on peri­ods may app­ly, par­ti­cu­lar­ly due to repro­duc­ti­ve medi­cal, phar­maceu­ti­cal, tis­sue, labo­ra­to­ry, or other spe­cial legal regu­la­ti­ons.

Inso­far as fur­ther sto­rage is neces­sa­ry and legal­ly per­mis­si­ble for the asser­ti­on, exer­cise, or defen­se of legal claims, the cor­re­spon­ding data may be stored for this pur­po­se for a lon­ger peri­od.

31. Data Back­up

We pro­tect prac­ti­ce and pati­ent data through tech­ni­cal and orga­niza­tio­nal mea­su­res against loss, unaut­ho­ri­zed access, and other risks.

Data back­ups are encrypt­ed and stored under our own respon­si­bi­li­ty.

32. Reci­pi­ents of Pati­ent Data

Per­so­nal data is only pas­sed on if this is neces­sa­ry for the exe­cu­ti­on of the tre­at­ment rela­ti­onship, legal­ly requi­red, cover­ed by con­sent, or per­mis­si­ble on ano­ther data pro­tec­tion legal basis.

Pos­si­ble reci­pi­ents include, in par­ti­cu­lar:

  • Co-trea­ting or refer­ring phy­si­ci­ans
  • Medi­cal and gene­tic labo­ra­to­ries
  • Other medi­cal or repro­duc­ti­ve medi­cal faci­li­ties
  • FERTILA GmbH
  • Sperm banks at your request
  • The Ger­man IVF Regis­ter after sepa­ra­te con­sent
  • Pay­ment ser­vice pro­vi­ders
  • Tax con­sul­ting and accoun­ting ser­vice pro­vi­ders
  • IT, soft­ware, main­ten­an­ce, and sup­port ser­vice pro­vi­ders
  • Com­mu­ni­ca­ti­on and cloud ser­vice pro­vi­ders
  • Com­pe­tent aut­ho­ri­ties and other legal­ly desi­gna­ted bodies.

33. Pro­ces­sing out­side the Euro­pean Eco­no­mic Area

Some of the IT, cloud, com­mu­ni­ca­ti­on, auto­ma­ti­on, or AI ser­vice pro­vi­ders we use may pro­cess per­so­nal data out­side Ger­ma­ny or the Euro­pean Eco­no­mic Area.

Inso­far as data is trans­fer­red to third count­ries, we use the trans­fer mecha­nisms pro­vi­ded for by the GDPR.

The­se may include, in par­ti­cu­lar, ade­quacy decis­i­ons by the Euro­pean Com­mis­si­on, cer­ti­fi­ca­ti­on of the respec­ti­ve com­pa­ny under the EU-US Data Pri­va­cy Frame­work, or the stan­dard con­trac­tu­al clau­ses of the Euro­pean Com­mis­si­on.

III. Data Pro­tec­tion Infor­ma­ti­on for Appli­cants

34. Appli­ca­ti­ons

If you app­ly to us, we pro­cess the appli­ca­ti­on data you sub­mit to deci­de on the estab­lish­ment of an employ­ment rela­ti­onship.

This may include, in par­ti­cu­lar:

  • Name and cont­act details
  • Cur­ri­cu­lum vitae
  • Cer­ti­fi­ca­tes
  • Qua­li­fi­ca­ti­ons
  • Infor­ma­ti­on on pro­fes­sio­nal care­er
  • Other infor­ma­ti­on vol­un­t­a­ri­ly sub­mit­ted by you.

Appli­ca­ti­ons are gene­ral­ly accept­ed by email.

Appli­cants may reach us via job adver­ti­se­ments on exter­nal plat­forms, such as Inde­ed. The respec­ti­ve plat­form pro­vi­der is initi­al­ly respon­si­ble for data pro­ces­sing the­re.

The legal basis for pro­ces­sing in the appli­ca­ti­on pro­ce­du­re is, in par­ti­cu­lar, Sec­tion 26 BDSG.

If an employ­ment rela­ti­onship is not estab­lished, we gene­ral­ly dele­te the appli­ca­ti­on docu­ments no later than six months after the con­clu­si­on of the appli­ca­ti­on pro­cess, unless lon­ger sto­rage is requi­red due to con­sent, a legal dis­pu­te, or ano­ther legal basis.

If an employ­ment rela­ti­onship is estab­lished, the data requi­red for the employ­ment rela­ti­onship is trans­fer­red to our per­son­nel admi­nis­tra­ti­on.

IV. Your Rights

35. Infor­ma­ti­on, Rec­ti­fi­ca­ti­on, Era­su­re, and Rest­ric­tion

In accordance with legal requi­re­ments, you have the right to infor­ma­ti­on about the per­so­nal data stored about you and to rec­ti­fi­ca­ti­on of inac­cu­ra­te data.

You can also request the era­su­re of your data or the rest­ric­tion of pro­ces­sing, pro­vi­ded that the legal requi­re­ments for this are met.

A right to era­su­re does not exist, in par­ti­cu­lar, inso­far as we are legal­ly obli­ged to fur­ther store data, for exam­p­le, due to medi­cal docu­men­ta­ti­on and reten­ti­on obli­ga­ti­ons.

36. Data Por­ta­bi­li­ty

Inso­far as the legal requi­re­ments are met, you have the right to recei­ve per­so­nal data that you have pro­vi­ded to us in a struc­tu­red, com­mon­ly used, and machi­ne-rea­da­ble for­mat or to request its trans­mis­si­on to ano­ther con­trol­ler.

37. With­dra­wal of Cons­ents

Inso­far as pro­ces­sing is based on your con­sent, you can revo­ke this con­sent at any time with effect for the future.

The lawful­ness of pro­ces­sing car­ri­ed out until the time of with­dra­wal remains unaf­fec­ted by this.

38. Right to Object

Inso­far as we pro­cess per­so­nal data based on a legi­ti­ma­te inte­rest in accordance with Art. 6 para. 1 lit. f GDPR, you can object to this pro­ces­sing for reasons ari­sing from your par­ti­cu­lar situa­ti­on.

Inso­far as per­so­nal data is pro­ces­sed for the pur­po­se of direct mar­ke­ting, you have the right to object to this pro­ces­sing at any time.

39. Right to Lodge a Com­plaint with a Super­vi­so­ry Aut­ho­ri­ty

You have the right to lodge a com­plaint with a data pro­tec­tion super­vi­so­ry aut­ho­ri­ty if you belie­ve that the pro­ces­sing of your per­so­nal data vio­la­tes data pro­tec­tion regu­la­ti­ons.

The super­vi­so­ry aut­ho­ri­ty respon­si­ble for us is:

Bava­ri­an Sta­te Office for Data Pro­tec­tion Super­vi­si­on (BayL­DA)
Pro­me­na­de 18
91522 Ans­bach

Pho­ne: +49 981 180093–0
E‑mail: poststelle@lda.bayern.de
www.lda.bayern.de

40. No Exclu­si­ve­ly Auto­ma­ted Medi­cal Decis­i­ons

We do not use exclu­si­ve­ly auto­ma­ted decis­i­on-making within the mea­ning of Art. 22 GDPR that pro­du­ces legal effects con­cer­ning you or simi­lar­ly signi­fi­cant­ly affects you.

In par­ti­cu­lar, medi­cal dia­gno­ses and the­ra­py decis­i­ons are not made exclu­si­ve­ly auto­ma­ti­cal­ly.

41. Updating this Pri­va­cy Poli­cy

We will adapt this Pri­va­cy Poli­cy if our data pro­ces­sing pro­ce­du­res, the ser­vices we use, or the legal frame­work con­di­ti­ons chan­ge.