Privacy Policy
Status: October 2026
The protection of your personal data is important to us. Below, we inform you about how we process personal data.
This Privacy Policy covers both the use of our website and the processing of personal data within the scope of medical treatment in our practice, as well as in connection with applications.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Dr. med. Corinna Mann
Owner of the Medical Practice
Practice Name: Private Center ‘Die Kinderwunschärztin’
Herzogspitalstraße 5
80331 München
Phone: (089) 123 595 65
E‑mail: hallo@kinderwunschaerztin.de
For general data protection inquiries, you can also contact datenschutz@kinderwunschaerztin.de.
2. Data Protection Officer
We have appointed an external data protection officer:
kraussfirmengruppe GmbH & Co. KG
Haldenloh E 10
86465 Welden
Phone: +49 8293 950 80–0
E‑mail: info@kraussakademie.de
I. Data Protection when using our Website
3. General Data Processing when visiting our Website
When you visit our website, technically necessary information is processed. This may include, in particular, your IP address, time and duration of the page view, pages or files accessed, browser type and browser version, operating system, referrer URL, and other technical information.
Processing is carried out, insofar as it is necessary for the operation and secure provision of our website, on the basis of Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the secure, stable, and technically error-free operation of our online offering.
4. Hosting
Our website is hosted by an external hosting service provider: HostPress GmbH, Bahnhofstraße 34, 66571 Eppelborn. The servers are located in a data center in Germany. In particular, server log data and other technically necessary data may be processed.
Where necessary, an agreement on commissioned processing exists with the hosting provider in accordance with Art. 28 GDPR.
5. SSL or TLS Encryption
Our website uses SSL or TLS encryption. This means that data transmitted between your browser and our website is encrypted.
6. Cookies and Consent Management
Our website uses cookies and similar technologies.
Technically necessary cookies and technologies are used insofar as this is required for the secure and functional provision of our website, e.g., for storing your cookie settings and your language setting. The legal basis for this is Art. 6 para. 1 lit. f GDPR in conjunction with Section 25 para. 2 no. 2 TDDDG.
Non-essential technologies, particularly for statistics, analysis, or marketing, are only used after your prior consent. The legal basis for this is Art. 6 para. 1 lit. a GDPR in conjunction with Section 25 para. 1 TDDDG.
To manage and document your consents, we use the Borlabs Cookie consent management system from Borlabs GmbH, Rübenkamp 32, 22305 Hamburg. Your consent decision is stored in a cookie in your browser and not passed on to Borlabs. You can change or revoke a given consent at any time with effect for the future via the settings offered there. The legal basis for the use of the consent management system is Art. 6 para. 1 lit. c GDPR.
7. Contact via Email or Phone
If you contact us by email or phone, we process the information you provide to handle your request.
If your inquiry relates to the initiation or execution of a treatment relationship, processing is generally based on Art. 6 para. 1 lit. b GDPR. Insofar as health data is concerned, processing is carried out in particular on the basis of Art. 9 para. 2 lit. h GDPR in conjunction with Section 22 para. 1 no. 1 lit. b BDSG.
In other cases, processing may be based in particular on our legitimate interest in the proper handling of your inquiry in accordance with Art. 6 para. 1 lit. f GDPR.
8. External Appointment Booking via arzt-direkt
On our website, we provide links for online appointment booking and online forms via arzt-direkt, a service of zollsoft GmbH, Ernst-Haeckel-Platz 5/6, 07745 Jena.
arzt-direkt is not directly embedded in our website. Only when you click the corresponding link do you leave our website and access the arzt-direkt service.
For data processing taking place there, the data protection information of the respective provider additionally applies.
Regardless, we also use arzt-direkt for our patient communication and other treatment processes. We will inform you about this in more detail in the section “Data Protection Information for Patients.”
9. External Payment Page by Stripe
For certain services, particularly the at-home fertility test, we link to an external payment page of the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland).
Stripe is not embedded as a payment module on our website. Only when you click the corresponding link do you leave our website and proceed to Stripe’s checkout.
The processing of personal data and payment information there is carried out in accordance with the payment service provider’s data protection information.
10. Analysis and Online Marketing
We use the services listed below for statistical analysis and for measuring and optimizing our online advertising. These services are only activated after your prior consent.
Google Tag Manager
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The Google Tag Manager serves for the technical administration and delivery of other website services. It is only loaded on our website after your consent.
Use is exclusively based on prior consent in accordance with Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG.
Google Analytics
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics is used for the statistical analysis of our website’s usage.
This may involve processing information about page views, duration of use, devices and browsers used, approximate geographical origin, and interactions with our website.
Use is exclusively based on prior consent in accordance with Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG.
Google Ads and Conversion Tracking
The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
We use Google Ads and corresponding conversion technologies to measure the effectiveness of our online advertising and optimize advertising measures.
Use is exclusively based on prior consent in accordance with Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG.
Meta Pixel
The provider is Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.
We use the Meta Pixel to measure the effectiveness of advertising measures on Meta platforms.
This allows us to track, in particular, whether users have performed certain actions on our website after interacting with an advertisement.
Insofar as personal data is collected on our website and forwarded to Meta, we and Meta Platforms Ireland Limited are jointly responsible for the collection and transmission (Art. 26 GDPR). Further information can be found at https://www.facebook.com/legal/controller_addendum.
Use is exclusively based on prior consent in accordance with Art. 6 para. 1 lit. a GDPR and Section 25 para. 1 TDDDG.
11. Review Display via Trustindex
On our website, we integrate reviews via the Trustindex service. The provider is Trustindex Ltd., Nyári Pál utca 15, 2724 Újlengyel, Hungary.
When accessing corresponding content, a connection is established with Trustindex servers. In particular, the IP address and technical information about the device used may be processed.
The integration is based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in an appealing presentation of testimonials from our patients.
12. Google Maps
On individual pages of our website, we integrate maps from Google Maps. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The maps are only loaded after your corresponding consent.
When loading Google Maps, your IP address and other technical information may be transmitted to Google.
The legal basis for activation in this case is Art. 6 para. 1 lit. a GDPR in conjunction with Section 25 para. 1 TDDDG.
13. Fonts and Icons
The fonts (Google Fonts) and icons (Font Awesome) used on our website are provided locally on our own web server. No connection to the servers of the respective external providers is established solely for retrieving these resources.
14. Transfer to Third Countries in connection with Website Services
For some of the service providers we use, particularly Google and Meta, personal data may be processed outside the European Union or the European Economic Area, especially in the USA.
Insofar as data is transferred to a country for which an adequacy decision by the European Commission exists, the transfer can be based on this. For the USA, this applies to companies certified under the EU-US Data Privacy Framework; this is the case for Google and Meta.
Otherwise, where necessary, appropriate safeguards are used, in particular the standard contractual clauses of the European Commission.
II. Data Protection Information for Patients
15. What Data We Process in connection with Treatment
In connection with your contact, consultation, diagnostics, and treatment, we process the personal data required for this purpose.
This includes, in particular:
- Name, date of birth, address, and other master data
- Phone number and email address
- Insurance and billing information
- Medical history
- Diagnoses and findings
- Laboratory values
- Medication data
- Information on pre-existing conditions and previous treatments
- Information on reproductive health and, where relevant to treatment, sexual and family history
- Genetic data, insofar as corresponding examinations are carried out
- Treatment and progress data
- Appointment and communication data.
Depending on the treatment, we also process medical image and laboratory data, in particular ultrasound images and, where applicable in the respective treatment procedure, microscopic, embryo- and laboratory-related image data and documentation.
16. Purposes and Legal Bases of Processing
We process your personal data in particular:
- for the initiation and execution of the treatment relationship
- for medical diagnostics and therapy
- for the performance of reproductive medical and laboratory medical measures
- for documenting your treatment
- for appointment and treatment organization
- for communication with you
- for billing
- for quality assurance
- for fulfilling legal documentation, reporting, and retention obligations
- for asserting, exercising, or defending legal claims.
The processing of personal data required for the execution of the treatment contract is carried out in particular on the basis of Art. 6 para. 1 lit. b GDPR.
We process health data and other special categories of personal data in particular on the basis of Art. 9 para. 2 lit. h GDPR in conjunction with Section 22 para. 1 no. 1 lit. b BDSG.
Insofar as we are legally obliged to process data, processing is carried out on the basis of Art. 6 para. 1 lit. c GDPR in conjunction with the respective applicable legal provisions.
Insofar as processing is not already permissible on the basis of the treatment relationship or a legal basis, we will obtain consent in accordance with Art. 6 para. 1 lit. a or Art. 9 para. 2 lit. a GDPR, if necessary.
A given consent can be revoked at any time with effect for the future.
17. Origin of Data
Most personal data is received directly from you.
Insofar as this is necessary for your treatment and legally permissible, we may also receive data from referring or co-treating physicians, medical facilities, laboratories, or other service providers.
18. Electronic Patient File and Practice and Laboratory Systems
We document treatment in an electronic patient file and primarily use the tomedo® practice management system from zollsoft GmbH for this purpose.
In addition, we use specialized electronic practice, laboratory, documentation, identification, and quality assurance systems.
These include, among others, locally operated systems for the IVF laboratory and electronic identity and process control.
A complete list of all internally used software products is not provided in this Privacy Policy.
Insofar as manufacturers, IT service providers, or support companies can access systems containing personal data for maintenance, remote maintenance, or support, this is done exclusively to the extent required for this purpose and in compliance with applicable data protection requirements.
19. Communication with Patients
Email and Google Workspace
We use Google Workspace for our business email communication and some other organizational applications.
This may involve processing contact, appointment, and communication data, as well as health and treatment data depending on the content of the communication.
Insofar as we send confidential documents by email, these can be additionally protected, for example, by password-protected attachments.
United Domains
For individual email inboxes and technical communication channels, through which fax and telephone mailbox messages can be received, among other things, we use services from United Domains.
Since such messages may originate from patients, personal data and, depending on the content of the message, health data may be processed.
Telephony via STARFACE
We use a cloud telephone system from STARFACE for our telephone communication.
This involves processing telephone numbers, connection, and communication data in particular.
When using our mailbox, voice recordings left by callers may also be stored and processed.
Normal phone calls with our practice are not recorded.
Communication via arzt-direkt
We use services from arzt-direkt / zollsoft GmbH for online appointment booking, patient forms, anamneses, video consultations, and electronic communication functions, among other things.
Depending on the respective function, master and contact data, appointment data, communication data, as well as health and treatment data may be processed.
Processing is carried out, insofar as it serves the treatment, in particular on the basis of Art. 6 para. 1 lit. b GDPR and Art. 9 para. 2 lit. h GDPR.
SMS via ClickSend
We use the ClickSend SMS service for transmitting certain organizational information.
We use it in particular to send decryption codes for separately transmitted protected documents and occasionally neutral appointment reminders.
This involves processing the mobile phone number and the respective message text in particular.
Diagnoses, findings, or other medical content are not sent by us via SMS.
Automated Transmission via Zapier
For individual technical processes, we use Zapier as an interface service.
In particular, data from designated Google forms can be automatically forwarded to ClickSend.
Only the information required for the respective process is processed, in particular the mobile phone number and decryption code or message text.
The corresponding data records are deleted promptly after successful transmission.
20. AI-supported Assistance Systems
We use AI-supported assistance systems in selected administrative, organizational, and technical work processes.
These serve in particular to support research, structuring, and linguistic processing of information, as well as the development and maintenance of internal technical applications.
Insofar as external general AI services are used for case discussions or comparable tasks, information is generally anonymized or reduced to such an extent that direct identification of the data subject is avoided.
In individual approved work processes, we use business services from OpenAI, including in connection with approved corporate applications such as our business email communication.
Depending on the specific work order, personal data and, if applicable, health data may be processed as a result.
We use business accounts for this and only employ the services within the scope of use approved for the practice.
Other external AI services are only used with identifiable patient data if this has been reviewed under data protection law and approved for the respective processing purpose.
AI systems do not make independent medical treatment decisions in our practice. Diagnostic and therapeutic decisions are made by our treating physicians.
21. AI-supported Documentation of Consultations
To support medical documentation, we may use the tomedo® Consultation Assistant from zollsoft GmbH.
In this process, a doctor-patient conversation is recorded and automatically transcribed exclusively after prior explicit consent from all recorded persons.
The transcript can then be structured with the help of an AI-supported language model and summarized into a documentation proposal.
The generated content is reviewed by medical professionals before being transferred to the patient file.
The system serves exclusively to support documentation. It does not make independent diagnostic or therapeutic decisions.
The use of the Consultation Assistant is voluntary. Refusal has no impact on your treatment.
The audio recording is only stored for as long as necessary for transcription, review, and creation of the medical documentation, and is then deleted as quickly as possible.
The medical documentation transferred to the patient file, however, is subject to statutory retention periods.
22. External Medical Diagnostics and Laboratories
Insofar as it is necessary for diagnostics and treatment, we transmit the required personal data, health data, and, if applicable, examination material to external medical laboratories and specialized diagnostic facilities.
This concerns in particular:
- Special hormone analyses
- Infection diagnostics
- Genetic examinations
- Other special examinations that we do not perform ourselves.
For genetic examinations, we collaborate with, among others, the Medical Genetic Center (MGZ) Munich.
For genetic examinations, we observe the special legal requirements, in particular the provisions of the Genetic Diagnostics Act, including the necessary information and consent.
23. German IVF Register
We participate in the German IVF Register (D·I·R).
A pseudonymized transmission of treatment data to the D·I·R takes place with us after a separately obtained consent for this purpose.
For this, we use a separate consent form.
Patient master data is not transmitted to the D·I·R.
The transmitted data serves in particular for quality assurance and scientific evaluation of reproductive medical treatments.
24. Cryopreservation and FERTILA GmbH
If you decide on cryopreservation and subsequent storage, the personal data and health data required for this purpose may be transmitted to FERTILA GmbH.
FERTILA GmbH concludes its own contract with you for storage, bills its services itself, and processes the data required for this under its own data protection responsibility.
You will receive separate data protection information regarding the processing of your data by FERTILA GmbH.
25. Sperm Banks and other Medical Facilities
The selection and commissioning of external sperm banks is generally done by the patients themselves.
Insofar as you expressly commission us with communication or processing with a sperm bank or another reproductive medical facility, we transmit the personal and, if applicable, medical data required for this to the necessary extent.
The same applies if, at your request, samples, treatment documents, or other medical information are to be transmitted to another medical facility.
26. Billing
As a private practice, we generally bill our medical services directly to our patients.
Transmission of billing, treatment, or other personal data to private health insurance companies or other cost bearers is generally only carried out by us at your request or with your corresponding approval, or if another legal basis exists for this.
We do not use an external private medical billing service provider.
27. Payment Service Providers
Depending on the chosen payment method, payment data may be processed by external payment service providers.
These currently include, in particular:
- Stripe
- PayPal
- SumUp
- the payment service provider used for payments via arzt-direkt.Pay.
The processing of data required for payment processing is carried out according to the respective applicable data protection information of the payment service providers.
PayPal and SumUp are used by us in particular for on-site payments.
28. Tax Consulting and Accounting
To fulfill our legal tax, commercial, and accounting obligations, we transmit necessary data to tax consulting and accounting service providers commissioned by us.
This may also involve processing individual outgoing invoices with the patient’s name and service items.
The transmission is limited to the extent necessary for the respective purpose.
29. Authorities and Legally Designated Recipients
Insofar as we are obliged to report, document, or transmit personal data due to legal, supervisory, or professional regulations, data may be transmitted to the competent authorities or other legally designated bodies to the extent required.
30. Retention of Treatment Data
Patient files and treatment documents are retained in accordance with legal regulations.
For medical patient files, the statutory basic retention period is generally ten years after the completion of treatment.
For individual data, samples, documentation, and records, different and longer retention periods may apply, particularly due to reproductive medical, pharmaceutical, tissue, laboratory, or other special legal regulations.
Insofar as further storage is necessary and legally permissible for the assertion, exercise, or defense of legal claims, the corresponding data may be stored for this purpose for a longer period.
31. Data Backup
We protect practice and patient data through technical and organizational measures against loss, unauthorized access, and other risks.
Data backups are encrypted and stored under our own responsibility.
32. Recipients of Patient Data
Personal data is only passed on if this is necessary for the execution of the treatment relationship, legally required, covered by consent, or permissible on another data protection legal basis.
Possible recipients include, in particular:
- Co-treating or referring physicians
- Medical and genetic laboratories
- Other medical or reproductive medical facilities
- FERTILA GmbH
- Sperm banks at your request
- The German IVF Register after separate consent
- Payment service providers
- Tax consulting and accounting service providers
- IT, software, maintenance, and support service providers
- Communication and cloud service providers
- Competent authorities and other legally designated bodies.
33. Processing outside the European Economic Area
Some of the IT, cloud, communication, automation, or AI service providers we use may process personal data outside Germany or the European Economic Area.
Insofar as data is transferred to third countries, we use the transfer mechanisms provided for by the GDPR.
These may include, in particular, adequacy decisions by the European Commission, certification of the respective company under the EU-US Data Privacy Framework, or the standard contractual clauses of the European Commission.
III. Data Protection Information for Applicants
34. Applications
If you apply to us, we process the application data you submit to decide on the establishment of an employment relationship.
This may include, in particular:
- Name and contact details
- Curriculum vitae
- Certificates
- Qualifications
- Information on professional career
- Other information voluntarily submitted by you.
Applications are generally accepted by email.
Applicants may reach us via job advertisements on external platforms, such as Indeed. The respective platform provider is initially responsible for data processing there.
The legal basis for processing in the application procedure is, in particular, Section 26 BDSG.
If an employment relationship is not established, we generally delete the application documents no later than six months after the conclusion of the application process, unless longer storage is required due to consent, a legal dispute, or another legal basis.
If an employment relationship is established, the data required for the employment relationship is transferred to our personnel administration.
IV. Your Rights
35. Information, Rectification, Erasure, and Restriction
In accordance with legal requirements, you have the right to information about the personal data stored about you and to rectification of inaccurate data.
You can also request the erasure of your data or the restriction of processing, provided that the legal requirements for this are met.
A right to erasure does not exist, in particular, insofar as we are legally obliged to further store data, for example, due to medical documentation and retention obligations.
36. Data Portability
Insofar as the legal requirements are met, you have the right to receive personal data that you have provided to us in a structured, commonly used, and machine-readable format or to request its transmission to another controller.
37. Withdrawal of Consents
Insofar as processing is based on your consent, you can revoke this consent at any time with effect for the future.
The lawfulness of processing carried out until the time of withdrawal remains unaffected by this.
38. Right to Object
Insofar as we process personal data based on a legitimate interest in accordance with Art. 6 para. 1 lit. f GDPR, you can object to this processing for reasons arising from your particular situation.
Insofar as personal data is processed for the purpose of direct marketing, you have the right to object to this processing at any time.
39. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection regulations.
The supervisory authority responsible for us is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Phone: +49 981 180093–0
E‑mail: poststelle@lda.bayern.de
www.lda.bayern.de
40. No Exclusively Automated Medical Decisions
We do not use exclusively automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
In particular, medical diagnoses and therapy decisions are not made exclusively automatically.
41. Updating this Privacy Policy
We will adapt this Privacy Policy if our data processing procedures, the services we use, or the legal framework conditions change.