Data protection declaration of Frauenklinik an der Elbe
-
General information
We take data protection very seriously and your data security is important to us, therefore we describe below how we handle your data in detail.
Unless you have given us separate consent, personal data will only be processed on the pages of this website to the extent technically necessary and required for the provision of individual services and offers. If the use of individual offers and services found within this website requires the entry of personal data (e.g., processing inquiries via contact forms), we will only process this data for the purpose for which you provided it to us.
In any case where you transmit personal data to us via the internet, we would like to point out that there is always a risk of security vulnerabilities. Complete protection of data against access by third parties is not possible. If you do not wish to accept this risk, please do not communicate with us via the internet.
In this privacy policy, we inform you about the processing of personal data when using our website www.frauenklinik-elbe.de (hereinafter also referred to as "this website").
Data protection generally applies to all information relating to an identified or identifiable person that can be directly or indirectly attributed to that person (so-called personal data). This includes, in particular, information such as name, address, date of birth, etc., or combinations thereof. Pseudonymized data, i.e., information that can, in principle, be attributed to a natural person via an identifier (e.g., number, IP address, etc.), also falls under data protection requirements. However, if the information is altered to such an extent that neither direct nor indirect attribution to a natural person is possible, then it is considered anonymized data. Such data (e.g., aggregated datasets or truncated IP addresses) is no longer subject to data protection regulations.
The following information explains how we process your personal data on this website. The term "processing" encompasses the entire process from collection, storage, editing, and/or transfer to deletion of the data.
-
Name and contact details of the controller and their data protection officer
This privacy information applies to data processing by us, the following joint controllers:
Sonnemann/Strelecki GbR
Kronenstrasse 77
D-44139 Dortmund
Telephone: +49 (0) 231 97 86 9 -51/52
The company's data protection officer can be contacted at the above address, c/o Data Protection Officer, or at datenschutz@frauenklinik-elbe.de reachable.
-
Data processing on our website
When you simply use our website for informational purposes, i.e., when you otherwise transmit information to us, we only collect the personal data that your browser transmits to our server. If you wish to view our website, we collect the following data:
- IP address of the requesting device,
- Date and time of the request,
- Time Zone Difference to Greenwich Mean Time (GMT)
- Content of the requirement (concrete page)
- Access Status / HTTP status code
- each transmitted amount of data
- Website from which the request originates; browser
- Operating system and its interface of the requesting device,
- Language and version of the browser software.
The processing of this access data is necessary to enable the visit to the website and to ensure the stability, continued functionality and security of our systems.
The access data is also temporarily stored in internal log files for the purposes described above, in order to compile statistical information about the use of our website, to further develop our website with regard to the usage patterns of our visitors, and for general administrative maintenance of our website. The legal basis for this is Article 6(1)(f) GDPR, whereby our "legitimate interest" within the meaning of this provision is our legitimate interest in providing this website and in ensuring the stability, long-term functionality, and security of our systems.
The information stored in the log files does not allow any direct conclusions to be drawn about your identity – in particular, we only store IP addresses in a shortened, anonymized form. The log files are stored for 60 days and then archived after anonymization.
-
Processing of personal data and the nature and purpose of its use
Personal data will be deleted immediately as soon as its retention is no longer necessary for fulfilling the purpose for which it was stored, and provided that no legal or statutory retention obligation prevents its deletion or the destruction of the corresponding documents. Specifically, we process your data as follows:
- When visiting the website
When you visit our website, our web servers automatically and temporarily store the connection data of the requesting computer, the web pages you visit on our site, the date and duration of your visit, the identification data of the browser and operating system you are using, and the website from which you accessed our site (so-called server log data). This is done for system security purposes. No further personal data, such as your name, address, telephone number, or email address, is collected. Furthermore, the server log data is not linked to any personally identifiable information. We process this data for the following purposes:
- Ensuring a smooth connection to the website,
- Ensuring the proper use of our website,
- Evaluation of system security and stability as well
- for further administrative purposes.
The legal basis for data processing is Art. 6 para. 1 p. 1 lit. f DSGVO. Our legitimate interest follows from the data collection purposes listed above. In no case we use the collected data for the purpose of drawing conclusions about you.
- Cookie policy
This website uses "cookies" to ensure its proper functioning and to make browsing easier.
Cookies are small files that are stored on your device and save certain settings and data for exchange with our system via your browser. They serve to make the overall internet experience more user-friendly and efficient.
Cookies that are not strictly necessary for the operation of the website may only be used with your consent.
You can withdraw your consent for the future via our Borlabs Cookies.
We use Borlabs Cookies, Borlabs GmbH, Hamburger Str. 11, 22083 Hamburg, Germany. In this context, IP address, date and time of visit, browser information, consent information and device information of the requesting device are processed.
The legal basis is Article 6(1)(f) GDPR (legitimate interest). Obtaining and managing legally required consents is considered a legitimate interest within the meaning of Article 6(1)(f) GDPR. The provider processes consents and revocations exclusively on our behalf and according to our instructions.
- Use of contact forms
When you contact us via the contact form, the data you enter will be transmitted to the responsible staff members and processed accordingly. The specific data to be collected is indicated in the respective input form.
The data will be deleted as soon as it is no longer required for the purpose for which it was collected, provided there are no legal retention obligations to the contrary. This is generally the case when the respective conversation with you has ended. A conversation is considered ended when it is clear from the circumstances that the matter in question has been conclusively resolved. The legal basis for processing the data is Article 6(1)(a) GDPR.
- Email address: info@frauenklinik-elbe.de, aerzte@frauenklinik-elbe.de and anaesthesie@frauenklinik-elbe.de
If you contact us using the email address: info@frauenklinik-elbe.de, aerzte@frauenklinik-elbe.de and anaesthesie@frauenklinik-elbe.de If you contact us, our staff will process your request.
Personal data is processed within the framework of commissioned data processing in accordance with Art. 28 GDPR.
- online applications
We appreciate your interest in our company. We are aware of the necessary sensitivity regarding the processing of your personal data during the application process. The legal basis for processing your application documents is Article 6 Paragraph 1 Sentence 1 Letter b and Article 88 Paragraph 1 GDPR in conjunction with Section 26 Paragraph 1 Sentence 1 BDSG.
- Online Reception 321MED
This website uses the online reception service 321 MED for digital, online-based communication and interaction between patients and healthcare facilities and/or medical practices. The service provider is 321 MED GmbH, Wernerwerkstraße 4, 93049 Regensburg, Germany.
321 MED enables us to provide immediate online care to our patients and to communicate with them quickly and easily. When you enter data, such as your contact details, on our website via our online reception for the purpose of communicating with us, this data is stored on 321 MED's servers in Germany. Depending on the individual configuration and input, personal data and/or health data may be collected when using our online reception service.
321 MED is used in the interest of an appealing presentation of our online offers and the provision of a direct and fast service. This represents a legitimate interest; the legal basis is Art. 6 Para. 1 lit. f GDPR. Data processing using 321 MED is carried out using the data you provide/enter on the basis of your consent, Art. 6 Para. 1 lit. a GDPR. If you provide optional data such as gender or health data, data processing is carried out on the basis of your consent in accordance with Art. 9 Para. 2 lit. a GDPR.
If you do not want your data to be transferred to 321 MED, you can revoke your consent to the processing of your personal data or health data at any time by sending us a message. If you revoke your consent, your data will be deleted by us or 321 MED. Please note that in this case, you may not be able to fully use all the functions of our online reception service. Data that has been stored by us or 321 MED for other purposes remains unaffected. The legality of data processing operations that have already taken place remains unaffected by the revocation.
We have concluded a data processing agreement (AVV) with the provider 321 MED, which is required by data protection law. This is a contract that guarantees that the respective provider only processes personal data of the users of our website in accordance with our instructions and in compliance with the GDPR.
Further information about the data processed via 321 MED, as well as which cookies we use and how you can manage your cookie settings, can be found in the 321 MED privacy policy at https://321med.com/de/dataprotection..
-
Transfer of data to third parties
We only transfer your personal data to third parties if:
- You have expressly consented to the transfer in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR;
- the transfer is necessary for the performance of a contract with you (Art. 6 para. 1 sentence 1 lit. b GDPR) or
- There is a legal obligation to transmit the data (Art. 6 para. 1 sentence 1 lit. c GDPR).
The transmitted data may only be used by third parties for the stated purposes.
-
Data transfer to third countries
Personal data will only be transferred outside the European Union or the European Economic Area (EEA) to an unsafe third country if you are informed in advance and the requirements of Art. 44 et seq. GDPR are met.
A third country is considered unsafe if the EU Commission has not issued an adequacy decision for that country pursuant to Article 45(1) GDPR, confirming that the country provides an adequate level of protection for personal data.
In unsafe third countries, there is a risk that personal data may be processed by US authorities, possibly without any legal recourse.
Under the EU-US Data Privacy Framework, the European Commission has recognized the level of data protection for certain US companies as adequate in its adequacy decision of July 10, 2023. The Framework is an agreement between the European Union and the US designed to ensure compliance with European data protection standards for data processing in the US. Every company certified under the Framework commits to adhering to these data protection standards. The list of certified companies can be found on the US Department of Commerce website under Participant Search (dataprivacyframework.gov).
In our privacy policy, we inform you which of our service providers are certified under the Data Privacy Framework.
We only transfer your personal data to insecure third countries if:
- You have expressly consented to the transfer in accordance with Art. 49 para. 1 lit. a GDPR,
- The recipients must provide sufficient guarantees in accordance with Article 46 GDPR (e.g., standard contractual clauses) for the protection of personal data.
- the transfer is necessary for the fulfillment of contractual obligations between you and us or
- another exception under Article 49 GDPR applies.
-
Embedded YouTube videos
We have embedded YouTube videos on our websites, which can be played directly from the websites. The operator is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, a Google company.
The implementation is based on your consent pursuant to Art. 6 para. 1 sentence 1 lit. a GDPR. By loading the videos on our website, data is transmitted to Google. In particular, information about which of our web pages you have visited, as well as device-specific information including the IP address, is transmitted to Google.
The YouTube videos are embedded using the so-called "enhanced privacy mode," which, according to the provider, only initiates data storage when the videos are played. When you visit a page with an embedded video, a connection to the YouTube servers is only established, and the content is only displayed on the website by sending a message to your browser if you actually watch the video.
If you are logged into your YouTube account, you are allowing YouTube to directly associate your browsing behavior with your personal profile. You can prevent this by logging out of your YouTube account before activating the play button.
Further information on the purpose and scope of data collection and processing by YouTube can be found in Google's privacy policy. There you will also find further information on your rights and settings options to protect your privacy: [https://www.google.de/intl/de/policies/privacy].
We will only transfer your data if you expressly consent to its processing by Google. In this case, you acknowledge the risks described in section 5 and simultaneously consent to your data being transferred to the USA in accordance with Article 49(1)(a) GDPR.
As described above, you can configure your browser to reject cookies, or you can prevent the collection of data generated by cookies relating to your use of this website and the processing of this data by Google by disabling the "Personalized ads on the web" option in Google's advertising settings. In this case, Google will only display non-personalized ads.
Further information on the purpose and scope of data collection and processing by YouTube can be found in Google's privacy policy, which also applies to YouTube. There you will also find further information on
Your rights and privacy settings can be found at: www.google.de/intl/de/policies/privacy. Google also processes your personal data in the USA and has committed to the EU-US Privacy Shield, www.privacyshield.gov/EU-US-Framework.
-
Integration of Google Maps
Our website uses the Google Maps service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). This allows us to display interactive maps directly on the website and enables you to conveniently use the map function.
The legal basis is Art. 6 para. 1 sentence 1 lit. f GDPR, based on our legitimate interest in integrating a map service for contact purposes.
In order for the Google Maps data we use to be integrated and displayed in your web browser, your browser must establish a connection to a Google server, which may also be located in the USA, when you access the contact page. In the event that personal data is transferred to the USA, Google has committed to the EU-US Privacy Shield . Google thereby receives the information that the contact page of our website was accessed from your device's IP address. In addition, the following data is transmitted: the IP address, the date and time of the request; the time zone difference to Greenwich Mean Time; the content of the request (specific page); the access status/HTTP status code; the amount of data transferred; the website from which the request originated; the browser; the operating system and its interface, language, and version of the browser software. This occurs regardless of whether Google provides a user account that you are logged into or whether no user account exists. If you are logged into Google, your data will be directly associated with your account. If you do not wish to have your activity associated with your Google profile, you must log out before activating the button. Google stores your data as user profiles and uses it for advertising, market research, and/or to tailor its website to user needs. This analysis is carried out in particular (even for users who are not logged in) to provide targeted advertising and to inform other users of the social network about your activities on our website. You have the right to object to the creation of these user profiles, and to exercise this right, you must contact Google.
Further information on the purpose and scope of data collection and its processing by the plug-in provider can be found in the provider's privacy policy. There you will also find further information on your rights and settings options to protect your privacy: http://www.google.de/intl/de/policies/privacy.
Google also processes your personal data in the USA and has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.
-
Links on social media
We link to offers from Facebook, YouTube, Google+, and Google Maps on our websites. These links are integrated via corresponding graphics. Clicking on such a link redirects you to the respective provider's website. We do not process any personal data in this process. However, when you access the linked page via the link, data is processed by the respective website operator. The respective provider is responsible for ensuring data protection compliance.
How each provider handles this data can be found in their respective privacy policy:
- Facebook - Meta Privacy Policy
- Youtube - Privacy Policy – Privacy Policy & Terms of Service – Google
- Google+ – Privacy Policy – Privacy Policy & Terms of Service – Google
- Google Maps - Privacy Policy – Privacy Policy & Terms of Service – Google
We maintain a fan page on the Facebook network (operator: Meta Platforms Ireland Limited, 4 Grand Canal Square Grand Canal Harbour, Dublin 2, Ireland).
As operators of the Facebook fan page, we are jointly responsible with Meta within the meaning of Article 4 No. 7 of the General Data Protection Regulation (GDPR) and have concluded an agreement with Meta pursuant to Article 26 GDPR, according to which we acknowledge our joint data protection responsibility. You can access and view the relevant agreement between Meta and us here: www.facebook.com/legal/terms/page_controller_addendum.
When you visit the fan page, your personal data is processed, such as the content you view or interact with, as well as information about the devices you use (IP addresses, browser type, cookie data, etc.).
In connection with the operation of the fan page, we also use the analysis functions provided there, such as Facebook Insights, to obtain statistical evaluations of the visitors to our fan page.
For information about Page Insights, please see Facebook's Privacy Policy: Meta Privacy Policy – How Meta collects and uses user data | Privacy Center | Manage your privacy on Facebook, Instagram and Messenger | Facebook Privacy.
When you contact us via the messaging function, the like buttons and the option to comment on posts on our fan page, we process your personal data, in particular your Facebook username, profile URL, profile picture, the content of the comments you submit or information about your reaction and the related metadata (e.g. time of submission of the comment).
Your data will remain accessible to us via the fan page until your user account or just the data itself, for example the individual comment, is deleted.
Facebook provides information about data processing through the use of cookies and similar technologies in its Cookie Policy: Cookie Policy (facebook.com).
Your personal data may also be processed by Meta outside the European Union. According to Meta, your data is transferred to its parent company, Meta Platforms, Inc., in the USA based on standard contractual clauses. Meta Platforms Ireland Limited is solely responsible for this transfer. Meta Platforms, Inc. is certified under the Data Privacy Framework. We ourselves do not transfer any personal data that we receive via our fan page.
10. Disclosure of Data
We only share the data we collect if:
- You have given your explicit consent in accordance with Art. 6 para. 1 sentence 1 lit. a GDPR,
- the transfer is necessary pursuant to Art. 6 para. 1 sentence 1 lit. f GDPR for the establishment, exercise or defense of legal claims and there is no reason to assume that you have an overriding legitimate interest in preventing the transfer of your data,
- we are legally obliged to disclose the data pursuant to Art. 6 para. 1 sentence 1 lit. c GDPR or
- This is legally permissible and necessary according to Art. 6 para. 1 sentence 1 lit. b GDPR for the processing of contractual relationships with you or for the implementation of pre-contractual measures which are carried out at your request.
Some data processing may be carried out by our service providers. In addition to the service providers mentioned in this privacy policy, these may include, in particular, data centers that host our website and databases, IT service providers that maintain our systems, and consulting firms. If we transfer data to our service providers, they may only use the data to fulfill their tasks. These service providers have been carefully selected and commissioned by us. They are contractually bound to our instructions, have implemented appropriate technical and organizational measures to protect the rights of data subjects, and are regularly audited by us.
Furthermore, disclosure may occur in connection with official inquiries, court orders and legal proceedings if necessary for the prosecution or enforcement of legal claims.
11. Storage duration
Unless otherwise specified in this privacy policy regarding the duration of the storage of your data, the following applies:
As a general rule, we only store personal data for as long as necessary to fulfill contractual or legal obligations for which we collected the data. Afterwards, we delete the data immediately, unless we still need the data for evidentiary purposes in civil claims until the expiry of the statutory limitation period or due to statutory retention obligations.
For evidentiary purposes, we are required to retain contract data for three years from the end of the year in which our business relationship with you terminates. Any claims will become time-barred according to the statutory limitation period, at the earliest at this point.
Even after that, we are required to retain some of your data for accounting purposes. We are obligated to do so due to legal documentation requirements arising from the German Commercial Code, the German Fiscal Code, the German Banking Act, the German Money Laundering Act, and the German Securities Trading Act. The retention periods stipulated therein range from two to ten years.
12. Rights of data subjects
a. Fundamental rights of data subjects
You have the right:
- in accordance with Art. 15 GDPR to request information about your personal data processed by us. In particular, you can request information about the processing purposes, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right of complaint, the origin of your data if it has not been collected by us, as well as the existence of automated decision-making including profiling and, if applicable, meaningful information about its details;
- in accordance with Art. 16 GDPR to immediately demand the correction of incorrect or completion of your personal data stored by us;
- pursuant to Art. 17 GDPR to request the erasure of your personal data stored by us, unless the processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defense of legal claims;
- to request the restriction of the processing of your personal data in accordance with Art. 18 GDPR, insofar as the accuracy of the data is disputed by you, the processing is unlawful, but you object to its erasure and we no longer require the data, but you need it for the assertion, exercise or defense of legal claims or you have objected to the processing in accordance with Art. 21 GDPR;
- pursuant to Art. 20 GDPR to receive your personal data that you have provided to us in a structured, common and machine-readable format or to request the transfer to another controller;
- to revoke your consent at any time in accordance with Art. 7 (3) GDPR. This has the consequence that we may no longer continue the data processing based on this consent for the future, and
- to lodge a complaint with a supervisory authority in accordance with Article 77 GDPR.
b. Right of withdrawal
If you wish to revoke the consent you gave at the beginning of your use of the website regarding the use of cookies and the associated processing, you have the following options available:
- You can clear your browser cache, reload the page, and make a different selection regarding cookie usage.
- You can change or withdraw your consent via the consent management tool. You can access the consent management tool via the link at the bottom of the website.
- If you wish to exercise your right of withdrawal or objection in another way, please contact us by email at: datenschutz@frauenklinik-elbe.de
c. Right to object to data processing based on legitimate interests
If your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) p. 1 lit. f GDPR, you have the right to object to the processing of your personal data pursuant to Art. 21 GDPR, provided that there are grounds for doing so that arise from your particular situation or the objection is directed against direct advertising. In the latter case, you have a general right of objection, which is implemented by us without specifying a particular situation.
If you wish to exercise your right of withdrawal or objection, please contact us by email at datenschutz@frauenklinik-elbe.de.
13. Data security
We take all necessary technical and organizational security measures to protect your personal data from loss and misuse. Your data is stored in a secure operating environment that is not accessible to the public.
In certain cases, your personal data is encrypted during transmission using Transport Layer Security (TLS). This means that communication between your computer and our servers takes place using a recognized encryption method, provided your browser supports TLS.
14. Up-to-dateness and change of this data protection explanation
This privacy policy is currently valid and has the status of Mai 2024.
Due to the ongoing development of our website and related services, or due to changes in legal or regulatory requirements, it may become necessary to amend this privacy policy. The current privacy policy can be viewed at any time on the website at https://frauenklinik-elbe.de/datenschutz/ can be accessed and printed by you.


