Privacy Policy

Patient Information on Data Protection

Dear patient, protecting your personal data is important to us. Under the EU General Data Protection Regulation (GDPR), we are required to inform you why data is collected, stored or shared. This information also explains the rights you have in relation to data protection.

You can access the full text of the General Data Protection Regulation (“GDPR”) here.

Contents

  • Definitions

  • Controller under Article 4 No. 7 GDPR
  • Legal basis for processing
  • Storage and deletion of data
  • Sharing of personal data
  • Webflow
    7.1 Hosting
    7.1.1 Fastly
    7.1.2 Amazon CloudFront
    7.2 Cloudflare
    7.3 website-files.com
    7.4 Legal basis

    6.1 Ausschließliche informatorische Nutzung unserer
    Website

    6.2 Kontaktaufnahme per E-Mail

  • Webflow

    7.1 Hosting

    7.1.1 Fastly

    7.1.2 Amazon CloudFront

    7.2 Cloudflare

    7.3 website-files.com

    7.4 Rechtsgrundlage

  • Your rights
  • Right to object
  • Data security

1. Definitions

The terms used in this Privacy Policy are defined in Article 4 GDPR. The following is only an extract from Article 4 GDPR. You can view all definitions in the GDPR.

Personal Data

Personal data means any information relating to an identified or identifiable natural person, referred to below as the “data subject”. A natural person is considered identifiable if they can be identified directly or indirectly, for example by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific factors relating to their physical, physiological, genetic, mental, economic, cultural or social identity.

Processing

Processing means any operation or set of operations performed on personal data, whether or not by automated means. This includes collecting, recording, organising, structuring, storing, adapting or altering, retrieving, consulting, using, disclosing by transmission, dissemination or otherwise making available, aligning or combining, restricting, erasing or destroying personal data.

Pseudonymisation

Pseudonymisation means processing personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional information, provided that this additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data cannot be attributed to an identified or identifiable natural person.

Controller

The controller is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

Processor

A processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Third Party

A third party is a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Consent

Consent means any freely given, specific, informed and unambiguous indication of the data subject’s wishes, given by a statement or by a clear affirmative action, by which the data subject agrees to the processing of personal data relating to them.

2. Controller

Dr. med. Stefan Ollig

Postfach 10 01 31
01071 Dresden
Germany

hallo[at]stefanollig.de
www.stefanollig.de

Our full legal notice can be accessed here.

3. Legal Basis for Processing

For each type of processing described in this Privacy Policy, we inform you of the legal basis on which it is carried out. Processing is lawful in the following cases:

  • You have given us consent to process your personal data for one or more specific purposes (Article 6(1)(a) GDPR).
  • There is a contract between you and us, and processing is necessary for the performance of that contract, or processing is necessary in order to take steps at your request before entering into a contract (Article 6(1)(b) GDPR).
  • Processing is necessary for compliance with a legal obligation to which we are subject (Article 6(1)(c) GDPR).
  • Processing is necessary to protect your vital interests or those of another natural person (Article 6(1)(d) GDPR).
  • Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us (Article 6(1)(e) GDPR).
  • Processing is necessary for the purposes of our legitimate interests or the legitimate interests of a third party, unless your interests or fundamental rights and freedoms requiring the protection of personal data override those interests (Article 6(1)(f) GDPR).

4. Storage and Deletion

For each type of processing described in this Privacy Policy, we inform you of the relevant storage period and the intended time limits for deletion or restriction of the data. If no specific storage period is stated, the data will be deleted or restricted as soon as the purpose or legal basis for storing it no longer applies.

Storage beyond the specified periods may be necessary where statutory rules to which we are subject require a different retention period, for example under Section 147 of the German Fiscal Code or Section 257 of the German Commercial Code.

After the storage period has expired, the personal data will be deleted or restricted, unless further storage is required on another legal basis. Storage beyond the stated period may also be possible in the event of a legal dispute with you or other legal proceedings.

5. Sharing of Data

If your personal data is shared, you will be informed of this in the relevant section of this Privacy Policy. This also applies to transfers outside the European Economic Area to socalled third countries. We generally transfer personal data to third countries only if the European Commission has confirmed an adequate level of protection there, or if we can ensure careful handling of the personal data through contractual agreements or other suitable safeguards.

6. Collection of Personal Data

Below we explain how personal data is collected, for example your name, email address, postal address or user behaviour.

6.1 Use of Our Website for Information Purposes Only

If you do not register on our website, for example for a newsletter, and do not otherwise provide us with data, for example via a contact form, the collection of personal data is limited to information that your browser automatically transmits to our server. This is technically necessary data which we need in order to display the website to you securely and reliably. Specifically, this includes the following information contained in a log file entry:

  • Internet protocol address (IP address)
  • Time and date of access
  • Time zone difference from Greenwich Mean Time (GMT
  • The specific page accessed
  • Access status / Hypertext Transfer Protocol (HTTP)
  • Amount of data transferred
  • Website from which access to our website took place (referrer URL)
  • Internet browser used, including language and version
  • Operating system used

The legal basis for collecting this data is Article 6(1)(f) GDPR. We have a legitimate interest in ensuring a technically error-free connection to our website, making the website convenient to use, analysing system stability and security, and using the data for further administrative purposes.

6.2 Contact by Email

If you contact us using the email address stated in Section 2 or any other email address published on our website, we will store your email address and any other contact details contained in your message, such as your name or telephone number, in order to process your enquiry. This data will be deleted without delay once further storage is no longer necessary. If statutory retention periods apply, processing will be restricted instead of deletion. The legal basis for processing depends on the reason for the email. It is either Article 6(1) (b) GDPR, where processing is necessary for handling a contract concluded with you or for fulfilling pre-contractual or contractual obligations, or Article 6(1)(f) GDPR, where processing is based on our legitimate interest in communicating with people interested in our services.

7. Webflow

Our website is hosted by Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA, referred to below as “Webflow”. Webflow also provides the content management system for our website. We have concluded a data processing agreement with Webflow. This agreement includes the standard contractual clauses for the transfer of personal data to third countries in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council. Webflow’s global Privacy Policy can be accessed here, and the Privacy Policy for the EU and Switzerland can be accessed here. Data may be processed in the USA. As the USA is considered a so-called third country under the GDPR, data transfers there require a specific legal basis. In this case, the legal basis is provided by Articles 44 and 45 GDPR, as Webflow is an active participant in the EU-US Data Privacy Framework. Under this data protection agreement between the EU and the USA, the level of data protection for certified companies in the USA has been recognised as adequate by an adequacy decision.

7.1 Hosting

Webflow hosts our website using the content delivery networks of the US companies Fastly Inc. and Amazon Web Services, Inc. A content delivery network is a network of geographically distributed and, where applicable, interconnected servers. The server closest to the respective user is used wherever possible. The CDN used here includes servers in North America and parts of Europe. Further information can be found here.

7.1.1 Fastly

Webflow hosts our website using the content delivery network of the US company Fastly Inc., 475 Brannan St. #300, San Francisco, CA 94107, USA, referred to below as “Fastly”. Fastly’s Privacy Policy can be accessed here. Data may be processed in the USA. As the USA is considered a third country under the GDPR, data transfers there require a specific legal basis. In this case, the legal basis is provided by Articles 44 and 45 GDPR, as Fastly is an active participant in the EU-US Data Privacy Framework. Under this data protection agreement between the EU and the USA, the level of data protection for certified companies in the USA has been recognised as adequate by an adequacy decision.

7.1.2 Amazon CloudFront

Webflow hosts our website using the content delivery network of the US company Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA, referred to below as “AWS”. This CDN is called Amazon CloudFront. The company’s legal notice can be accessed here. The company’s privacy information can be accessed here. Data may be processed in the USA. As the USA is considered a third country under the GDPR, data transfers there require a specific legal basis. In this case, the legal basis is provided by Articles 44 and 45 GDPR, as AWS is an active participant in the EU-US Data Privacy Framework. Under this data protection agreement between the EU and the USA, the level of data protection for certified companies in the USA has been recognised as adequate by an adequacy decision.

7.2 Cloudflare

To ensure cross-browser compatibility and to make the modern functionality of Webflow pages available even in older browsers without native support, Webflow includes JavaScript via Cloudflare’s content delivery network. This CDN is operated by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, referred to below as “Cloudflare”. Cloudflare’s Privacy Policy can be accessed here. Data may be processed in the USA. As the USA is considered a third country under the GDPR, data transfers there require a specific legal basis. In this case, the legal basis is provided by Articles 44 and 45 GDPR, as Cloudflare is an active participant in the EU-US Data Privacy Framework. Under this data protection agreement between the EU and the USA, the level of data protection for certified companies in the USA has been recognised as adequate by an adequacy decision.

7.3 website-files.com

In addition, a connection is established to the domain website-files.com, which belongs to Webflow. Images, fonts and other assets embedded in our website are hosted via this domain. This domain is also hosted by Webflow using the Fastly and Amazon CloudFront CDNs.

7.4 Legal Basis

The legal basis for the data processing described above is Article 6(1)(f) GDPR and is based on our interest in providing you with a fast, secure and user-friendly website. With regard to data processing in the third country USA, the legal basis is, as described above, Articles 44 and 45 GDPR, because all companies involved are active participants in the EU-US Data Privacy Framework. In addition, the legal basis is Article 46(1) and Article 46(2)(c) GDPR, relating to standard contractual clauses.

8. Ihre Rechte

Below we inform you about your rights under the GDPR. You can access the full text of the GDPR here.

Right of Access under Article 15(1) GDPR

You have the right to request confirmation from us as to whether personal data concerning you is being processed by us. If this is the case, you have the right to access this personal data and to receive information about:

  • the purposes of processing,
  • the recipients or categories of recipients to whom your personal data has been or will be
  • the recipients or categories of recipients to whom your personal data has been or will be disclosed, especially recipients in third countries or international organisations,
  • the storage period or the criteria used to determine that period,
  • the existence of a right to rectification or erasure of your personal data or restriction of processing by us, as well as the existence of a right to object to such processing,
  • the existence of a right to lodge a complaint with a supervisory authority,
  • all available information about the source of the data if it was not collected from you,
  • the existence of automated decision-making, including profiling, and, where applicable, meaningful information about the logic involved, as well as the significance and intended consequences of such processing.

Right to Rectification under Article 16 GDPR

You have the right to request that we correct inaccurate personal data concerning you without undue delay and complete incomplete personal data.

Right to Erasure (“Right to Be Forgotten”) under Article 17(1) GDPR

You have the right to request that we erase personal data concerning you without undue delay.

However, under Article 17(3) GDPR, this right does not apply where processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest in the area of public health, for archiving purposes in the public interest, or for the establishment, exercise or defence of legal claims.

Right to Restriction of Processing under Article 18(1) GDPR

You have the right to request that we restrict the processing of your personal data if:

  • you contest the accuracy of your personal data, in which case the restriction applies for the period needed for us to verify its accuracy,
  • the processing of your personal data is unlawful and you request restriction of processing instead of erasure,
  • we no longer need your personal data for the purposes of processing, but you need it for the establishment, exercise or defence of legal claims, or
  • you have objected to processing under Article 21(1) GDPR, in which case the restriction applies until it has been determined whether our legitimate grounds override yours.

Right to Data Portability under Article 20 GDPR

You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format and to transmit that data to another controller without hindrance from us. You may also request that we transmit the data directly to another controller, where technically feasible, provided that the processing was based on consent or a contract and was carried out by automated means.

Right to Withdraw Consent under Article 7(3) GDPR

You have the right to withdraw any consent you have given to us at any time with effect for the future. In this case, processing based on that consent may no longer continue. The lawfulness of processing carried out before withdrawal remains unaffected.

Right to Lodge a Complaint under Article 77 GDPR

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of personal data concerning you infringes the GDPR. As a rule, you may contact the supervisory authority of your usual place of residence, your place of work or the place of the alleged infringement. Further information can be found on the website of the German Federal Commissioner for Data Protection and Freedom of Information.

9. Right to Object

You also have the right to object at any time, with effect for the future, to the processing of your personal data where that processing is based on the performance of a task carried out in the public interest or in the exercise of official authority under Article 6(1)(e) GDPR, or on our legitimate interests under Article 6(1)(f) GDPR, provided there are reasons arising from your particular situation.

If you object, we will stop processing your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or unless the processing serves the establishment, exercise or defence of legal claims.

If your personal data is processed for direct marketing purposes or related profiling, you have a general right to object without having to give reasons relating to your particular situation. If you object, we will stop processing your personal data for these purposes without delay.

To exercise your right to withdraw consent or object, simply send an email to:

hallo[at]stefanollig.de

10. Data Security

Our website uses the TLS 1.3 encryption and communication protocol, Transport Layer Security.

Using a TLS certificate issued by a certification authority, we enable encrypted data exchange between your web browser and our web server. This helps ensure that sensitive data cannot be read by third parties.

We always use the highest level of encryption supported by your browser, usually 256-bit encryption. The higher the number of bits, the longer the key and the stronger the protection against access by third parties.