Dear patient, protecting your personal data is important to us. Under the EU General Data Protection Regulation (GDPR), we are required to inform you why data is collected, stored or shared. This information also explains the rights you have in relation to data protection.
You can access the full text of the General Data Protection Regulation (“GDPR”) here.
Contents
Definitions
Webflow
7.1 Hosting
7.1.1 Fastly
7.1.2 Amazon CloudFront
7.2 Cloudflare
7.3 website-files.com
7.4 Legal basis
6.1 Ausschließliche informatorische Nutzung unserer
Website
6.2 Kontaktaufnahme per E-Mail
Webflow
7.1 Hosting
7.1.1 Fastly
7.1.2 Amazon CloudFront
7.2 Cloudflare
7.3 website-files.com
7.4 Rechtsgrundlage
The terms used in this Privacy Policy are defined in Article 4 GDPR. The following is only an extract from Article 4 GDPR. You can view all definitions in the GDPR.
Personal Data
Personal data means any information relating to an identified or identifiable natural person, referred to below as the “data subject”. A natural person is considered identifiable if they can be identified directly or indirectly, for example by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific factors relating to their physical, physiological, genetic, mental, economic, cultural or social identity.
Processing
Processing means any operation or set of operations performed on personal data, whether or not by automated means. This includes collecting, recording, organising, structuring, storing, adapting or altering, retrieving, consulting, using, disclosing by transmission, dissemination or otherwise making available, aligning or combining, restricting, erasing or destroying personal data.
Pseudonymisation
Pseudonymisation means processing personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional information, provided that this additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data cannot be attributed to an identified or identifiable natural person.
Controller
The controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Processor
A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Third Party
A third party is a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
Consent
Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, given by a statement or by a clear affirmative action, by which the data subject agrees to the processing of personal data relating to them.
Dr. med. Stefan Ollig
Postfach 10 01 31
01071 Dresden
Germany
hallo[at]stefanollig.de
www.stefanollig.de
Our full legal notice can be accessed here.
For each type of processing described in this Privacy Policy, we inform you of the legal basis on which it is carried out. Processing is lawful in the following cases:
For each type of processing described in this Privacy Policy, we inform you of the relevant storage period and the intended time limits for deletion or restriction of the data. If no specific storage period is stated, the data will be deleted or restricted as soon as the purpose or legal basis for storing it no longer applies.
Storage beyond the specified periods may be necessary where statutory rules to which we are subject require a different retention period, for example under Section 147 of the German Fiscal Code or Section 257 of the German Commercial Code.
After the storage period has expired, the personal data will be deleted or restricted, unless further storage is required on another legal basis. Storage beyond the stated period may also be possible in the event of a legal dispute with you or other legal proceedings.
If your personal data is shared, you will be informed of this in the relevant section of this Privacy Policy. This also applies to transfers outside the European Economic Area to socalled third countries. We generally transfer personal data to third countries only if the European Commission has confirmed an adequate level of protection there, or if we can ensure careful handling of the personal data through contractual agreements or other suitable safeguards.
Below we explain how personal data is collected, for example your name, email address, postal address or user behaviour.
6.1 Use of Our Website for Information Purposes Only
If you do not register on our website, for example for a newsletter, and do not otherwise provide us with data, for example via a contact form, the collection of personal data is limited to information that your browser automatically transmits to our server. This is technically necessary data which we need in order to display the website to you securely and reliably. Specifically, this includes the following information contained in a log file entry:
The legal basis for collecting this data is Article 6(1)(f) GDPR. We have a legitimate interest in ensuring a technically error-free connection to our website, making the website convenient to use, analysing system stability and security, and using the data for further administrative purposes.
6.2 Contact by Email
If you contact us using the email address stated in Section 2 or any other email address published on our website, we will store your email address and any other contact details contained in your message, such as your name or telephone number, in order to process your enquiry. This data will be deleted without delay once further storage is no longer necessary. If statutory retention periods apply, processing will be restricted instead of deletion. The legal basis for processing depends on the reason for the email. It is either Article 6(1) (b) GDPR, where processing is necessary for handling a contract concluded with you or for fulfilling pre-contractual or contractual obligations, or Article 6(1)(f) GDPR, where processing is based on our legitimate interest in communicating with people interested in our services.
Our website is hosted by Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA, referred to below as “Webflow”. Webflow also provides the content management system for our website. We have concluded a data processing agreement with Webflow. This agreement includes the standard contractual clauses for the transfer of personal data to third countries in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council. Webflow’s global Privacy Policy can be accessed here, and the Privacy Policy for the EU and Switzerland can be accessed here. Data may be processed in the USA. As the USA is considered a so-called third country under the GDPR, data transfers there require a specific legal basis. In this case, the legal basis is provided by Articles 44 and 45 GDPR, as Webflow is an active participant in the EU-US Data Privacy Framework. Under this data protection agreement between the EU and the USA, the level of data protection for certified companies in the USA has been recognised as adequate by an adequacy decision.
7.1 Hosting
Webflow hosts our website using the content delivery networks of the US companies Fastly Inc. and Amazon Web Services, Inc. A content delivery network is a network of geographically distributed and, where applicable, interconnected servers. The server closest to the respective user is used wherever possible. The CDN used here includes servers in North America and parts of Europe. Further information can be found here.
7.1.1 Fastly
Webflow hosts our website using the content delivery network of the US company Fastly Inc., 475 Brannan St. #300, San Francisco, CA 94107, USA, referred to below as “Fastly”. Fastly’s Privacy Policy can be accessed here. Data may be processed in the USA. As the USA is considered a third country under the GDPR, data transfers there require a specific legal basis. In this case, the legal basis is provided by Articles 44 and 45 GDPR, as Fastly is an active participant in the EU-US Data Privacy Framework. Under this data protection agreement between the EU and the USA, the level of data protection for certified companies in the USA has been recognised as adequate by an adequacy decision.
7.1.2 Amazon CloudFront
Webflow hosts our website using the content delivery network of the US company Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA, referred to below as “AWS”. This CDN is called Amazon CloudFront. The company’s legal notice can be accessed here. The company’s privacy information can be accessed here. Data may be processed in the USA. As the USA is considered a third country under the GDPR, data transfers there require a specific legal basis. In this case, the legal basis is provided by Articles 44 and 45 GDPR, as AWS is an active participant in the EU-US Data Privacy Framework. Under this data protection agreement between the EU and the USA, the level of data protection for certified companies in the USA has been recognised as adequate by an adequacy decision.
7.2 Cloudflare
To ensure cross-browser compatibility and to make the modern functionality of Webflow pages available even in older browsers without native support, Webflow includes JavaScript via Cloudflare’s content delivery network. This CDN is operated by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, referred to below as “Cloudflare”. Cloudflare’s Privacy Policy can be accessed here. Data may be processed in the USA. As the USA is considered a third country under the GDPR, data transfers there require a specific legal basis. In this case, the legal basis is provided by Articles 44 and 45 GDPR, as Cloudflare is an active participant in the EU-US Data Privacy Framework. Under this data protection agreement between the EU and the USA, the level of data protection for certified companies in the USA has been recognised as adequate by an adequacy decision.
7.3 website-files.com
In addition, a connection is established to the domain website-files.com, which belongs to Webflow. Images, fonts and other assets embedded in our website are hosted via this domain. This domain is also hosted by Webflow using the Fastly and Amazon CloudFront CDNs.
7.4 Legal Basis
The legal basis for the data processing described above is Article 6(1)(f) GDPR and is based on our interest in providing you with a fast, secure and user-friendly website. With regard to data processing in the third country USA, the legal basis is, as described above, Articles 44 and 45 GDPR, because all companies involved are active participants in the EU-US Data Privacy Framework. In addition, the legal basis is Article 46(1) and Article 46(2)(c) GDPR, relating to standard contractual clauses.
Below we inform you about your rights under the GDPR. You can access the full text of the GDPR here.
Right of Access under Article 15(1) GDPR
You have the right to request confirmation from us as to whether personal data concerning you is being processed by us. If this is the case, you have the right to access this personal data and to receive information about:
Right to Rectification under Article 16 GDPR
You have the right to request that we correct inaccurate personal data concerning you without undue delay and complete incomplete personal data.
Right to Erasure (“Right to Be Forgotten”) under Article 17(1) GDPR
You have the right to request that we erase personal data concerning you without undue delay.
However, under Article 17(3) GDPR, this right does not apply where processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest in the area of public health, for archiving purposes in the public interest, or for the establishment, exercise or defence of legal claims.
Right to Restriction of Processing under Article 18(1) GDPR
You have the right to request that we restrict the processing of your personal data if:
Right to Data Portability under Article 20 GDPR
You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format and to transmit that data to another controller without hindrance from us. You may also request that we transmit the data directly to another controller, where technically feasible, provided that the processing was based on consent or a contract and was carried out by automated means.
Right to Withdraw Consent under Article 7(3) GDPR
You have the right to withdraw any consent you have given to us at any time with effect for the future. In this case, processing based on that consent may no longer continue. The lawfulness of processing carried out before withdrawal remains unaffected.
Right to Lodge a Complaint under Article 77 GDPR
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of personal data concerning you infringes the GDPR. As a rule, you may contact the supervisory authority of your usual place of residence, your place of work or the place of the alleged infringement. Further information can be found on the website of the German Federal Commissioner for Data Protection and Freedom of Information.
You also have the right to object at any time, with effect for the future, to the processing of your personal data where that processing is based on the performance of a task carried out in the public interest or in the exercise of official authority under Article 6(1)(e) GDPR, or on our legitimate interests under Article 6(1)(f) GDPR, provided there are reasons arising from your particular situation.
If you object, we will stop processing your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.
If your personal data is processed for direct marketing purposes or related profiling, you have a general right to object without having to give reasons relating to your particular situation. If you object, we will stop processing your personal data for these purposes without delay.
To exercise your right to withdraw consent or object, simply send an email to:
hallo[at]stefanollig.de
Our website uses the TLS 1.3 encryption and communication protocol, Transport Layer Security.
Using a TLS certificate issued by a certification authority, we enable encrypted data exchange between your web browser and our web server. This helps ensure that sensitive data cannot be read by third parties.
We always use the highest level of encryption supported by your browser, usually 256-bit encryption. The higher the number of bits, the longer the key and the stronger the protection against access by third parties.