PRIVACY POLICY OF THE MVZ FÜR DIAGNOSTIK, PRÄVENTION, ONKOLOGIE UND GASTROENTEROLOGIE TÜBINGEN GMBH
MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH takes your legitimate data protection concerns very seriously and complies with the provisions of the General Data Protection Regulation (GDPR), the Federal Data Protection Act (Bundesdatenschutzgesetz (BDSG)), the Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG)) and, where applicable, the provisions of other applicable data protection regulations such as the Genetic Diagnostics Act (Gendiagnostikgesetz).
The MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH handles the data you provide carefully and conscientiously. Insofar as data of any kind is collected, processed or used, these processes are always carried out in accordance with the statutory provisions or with your express consent.
The protection of privacy is of crucial importance for the future of Internet-based business models and for the development of an Internet-based economy. MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH emphasises its commitment to the protection of privacy with this data protection declaration. Below you will find information on how MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH handles personal data on this website.
This privacy policy applies to this and all other websites that refer to this privacy policy.
The data controller pursuant to Art. 4 (7) of the General Data Protection Regulation (GDPR) is
MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH
Represented by:
Dr. Dirk Biskup
Authorised Managing Director
Paul-Ehrlich-Str. 23
72076 Tübingen, Germany
info(at)mvz-tuebingen.de
www.mvz-tuebingen.de
Phone +49 (0)7071 565 44 990
Fax. +49 (0)7071 565 44 999
You can contact our data protection officer for MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH at
Auxillium Managementberatung
Thomas Fletschinger
E-mail: dsb(at)mvz-tuebingen.de
Global data protection standards
Our handling of personal data has been aligned with global principles and standards relating to transparency in the use of personal data, the observance and granting of rights of choice, access regulations, rules on data integrity, data security, data transfer and monitoring the lawfulness of processing. The MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH complies in particular with the General Data Protection Regulation (GDPR) and the German Genetic Diagnostics Act.
Consent
By using this website, you consent to the electronic storage and use of your data as described below. Changes to this privacy policy will always be announced on this page so that you are always informed about what data the MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH stores and how it is used.
Where required by applicable data protection law, we will also expressly request your consent for the further processing of the personal data collected on this website or provided by you.
This consent can be revoked at any time by sending an e-mail to info(at)mvz-tuebingen.de. In any case, MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH undertakes to treat all personal data provided confidentially and not to pass on any data to third parties.
Collection and processing of personal data
MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH would like to better understand your wishes and interests and offer you the best possible service. Therefore, MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH collects and uses personal information in the manner described below and in accordance with applicable data protection law.
When you visit our website, we collect your IP address and use cookies and other Internet technologies (hereinafter referred to as “automated tools” and “integrated web links”) to collect general information about visitors to our website. Below we explain which technologies are used and what type of information is collected.
We also collect and process data that you provide to us voluntarily, for example when you contact us by means of the contact form.
What data do we collect and why?
The MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH would like to use the collected data to offer you consistent personalised care. MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH will only use your data as described in this privacy policy. Any subsequent change in the purpose of use is subject to your express consent unless the change is otherwise legitimised by applicable legal provisions.
We always process your personal data for a specific purpose
In particular, we may process your personal data for the following purposes:
- To process orders
- To inform you about our diagnostic services, the procedure, costs and payment, and other information. In some cases, this may also include information from other companies and business partners, insofar as their products complement the products of MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH in a beneficial way
- To contact you, answer customer enquiries and provide information on dispatch and billing issues
- To process job enquiries
- To fulfil contractual obligations
- To answer your enquiries and provide you with efficient support
- For archiving and logging
- For invoicing and accounting
- For other purposes required by law and authorities
- In certain cases, we are legally obliged to transmit data to a requesting government body (institution or authority). The legal basis for processing is Art. 6 (1) c GDPR or Section 24 (2) (1) BDSG.
- In some cases, business partners require personal data from our customers, usually in the context of order fulfilment (e.g. in the event of complaints). This request for personal data is expressly provided for by law. The MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH remains responsible for the protection of your data even in this case – in addition to the data processor, if applicable. The respective business partner works in accordance with our instructions, which MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH ensures through strict contractual regulations.
IP addresses
IP addresses are used to analyse malfunctions, administer the website and obtain demographic information. MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH only collects such data in anonymised form and does not link it to a registered user’s profile without their consent. When you visit our website, only the domain name is recorded by default.
MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH only collects data in connection with your visit to our website. We do not collect any personal data in connection with your visits to the websites of other companies or organisations that do not belong to us.
Cookie Tool – CCM19
This website uses the cookie consent tool “CCM19” from Papoo Software & Media GmbH, Auguststr. 4, 53229 Bonn (“CCM19”) to obtain user consent for cookies and cookie-based applications that require consent.
When visiting our site, users are shown a banner, which is embedded on the page using JavaScript code. In this banner, they can give their consent for certain cookies and/or cookie-based applications by checking a box. The tool blocks all cookies requiring consent until the respective consent has been given by checking the box. This ensures that such cookies are only stored on the respective end device with the user’s explicit consent.
In order to assign page views to unique users and to be able to individually record, log, and store the consent settings made by the user for the duration of a session, the cookie consent tool collects certain user information (including the IP address) when our website is accessed. This information is transmitted to CCM19 servers and stored there.
CCM19 is used to obtain the legally required consent for the use of cookies. The legal basis for this is Art. 6 (1) (c) GDPR. Further information on data use by CCM19 can be found at https://www.ccm19.de/datenschutzerklaerung.html.
E-mail Addresses
If you enter your e-mail address in the contact form, we will also contact you by e-mail. We will not pass on your e-mail address to third parties outside the MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH. You can decide at any time that you no longer wish to receive e-mails from us.
Depending on the settings of your e-mail programme, information may be automatically transmitted to us when you send an e-mail to MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH.
Use of external service providers
We work together with service providers who process certain data on our behalf exclusively in accordance with the applicable data protection law. In particular, we have concluded agreements with our service providers on data processing on our behalf that meet the requirements of Article 28 GDPR.
Use of Microsoft 365
We would like to provide you with the following information regarding the processing of personal data in connection with the use of Microsoft 365 products.
Purpose of Processing
The MVZ Tübingen uses the Microsoft 365 suite of applications as a work tool. Microsoft 365 consists of various applications (e.g., Microsoft Office, Microsoft SharePoint, Microsoft Forms, Microsoft OneDrive), all of which are hosted in the cloud.
We also use the Microsoft 365 tool to communicate with you and to conduct telephone conferences, online meetings, video conferences, and surveys, as well as to gather information from our clients, cooperation partners, service providers, suppliers, customers, and participants.
Information about the Microsoft 365 software
We use the Microsoft 365 software from Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA (hereinafter “Microsoft”). This is operated as a cloud application. In some cases, a user account must be created to use the individual components. To the extent that this user account was not created by us and made available to you, Microsoft is the responsible entity or the entity that provided you with the access credentials.
In addition, Microsoft reserves the right to process user data for its own business purposes. In this context, Microsoft is the data controller. We have only limited control over Microsoft’s use of your usage data. We take all possible measures to minimize the transfer of your usage data to Microsoft as much as possible, but we cannot prevent it entirely.
For details and contact information, particularly regarding your rights vis-à-vis Microsoft, please refer to the links below if you have any questions about this aspect:
General: https://privacy.microsoft.com/de-de/privacystatement
Use of Microsoft Forms
We use “Microsoft Forms” for our contact forms, as well as for internal and external surveys and inquiries, such as evaluating completed campaigns, registering for events, etc.
Microsoft Forms is a tool within the Microsoft 365 suite we use and is a service provided by the third-party provider Microsoft Ireland Operations Limited.
When using Microsoft Forms, personal data is processed. This privacy notice provides information exclusively about our processing of your personal data. Information regarding Microsoft’s processing of personal data can be found at the following link:
https://privacy.microsoft.com/de-de/privacystatement
Data from users in the European Union is processed in data centers within the European Economic Area (EEA). However, it may be necessary for the provision of the service and for support purposes that data be processed at Microsoft Inc.’s headquarters in the United States. Regarding the conclusion of a data processing agreement: To fully comply with strict legal data protection requirements, we have entered into a data processing agreement with Microsoft under the “Online Service Terms” (OST). In this respect, Microsoft acts solely as a data processor. To the extent that the Microsoft website www.Office.com or “Microsoft Forms” processes personal data or uses cookies, Microsoft is responsible for the data processing. For the provision of the Microsoft Forms service, Microsoft cookies are used on the survey page.
In addition, the EU Standard Contractual Clauses have been contractually agreed upon for data transfers to third countries. The EU Standard Contractual Clauses provide a guarantee of an adequate level of data protection in the EU. We would like to point out that, according to the case law of the European Court of Justice, the United States is currently not a safe third country within the meaning of EU data protection law. Due to surveillance laws in the U.S., U.S. service providers may be required to disclose personal data to security authorities without data subjects having the right to appeal this. It cannot therefore be ruled out that U.S. authorities, such as intelligence agencies, will process, analyze, and permanently store your data located on the servers of U.S. service providers for surveillance purposes. We have no influence over these processing activities.
Therefore, Microsoft has implemented additional technical and organizational measures to protect personal data. In particular, personal data is transmitted via Forms only in encrypted form. Furthermore, Microsoft has contractually committed to challenging disclosure requests from U.S. authorities in court to the extent possible. Consequently, it can generally be assumed that an adequate level of protection is provided when Microsoft processes personal data.
The use of our contact forms and participation in our surveys is voluntary. To the extent that consent is given by participating in the survey, the legal basis is Article 6(1)(a) of the GDPR (consent of the data subject). Consent that has been given may be revoked at any time with future effect. Revoking consent or refusing to give consent will not result in any disadvantages.
If the use of contact forms and surveys is necessary for the initiation and/or performance of contracts, the processing of personal data is carried out in accordance with Article 6(1)(b) of the GDPR.
If no contractual relationship exists, the use of the contact form may be based on our legitimate business interest in providing you with efficient, cost-effective, and user-friendly services,
or, in the case of surveys, on our legitimate interest in the effective planning and implementation of projects and processes, etc., in accordance with Article 6(1)(f) of the GDPR.
Form owners have access to Microsoft Forms and can create and distribute surveys, forms, and questionnaires directly, either alone or with other owners. They are also the sole recipients of the responses.
These are presented graphically in Microsoft Forms and are available to the form owners.
When using “Microsoft Forms,” various types of data are processed. The scope of the data depends on the questions asked and answered, as well as any additional files that may be uploaded.
Generally, this includes the following personal data:
Last name, first name, email address
Profile picture (optional, if stored in Microsoft 365)
Preferred language
Status (optional, if stored in Microsoft 365)
Date and time the questionnaire was opened
Date and time the response was submitted
If you participate in an anonymous survey, the response contains no contact information and cannot be traced back to you.
The service provider for “Microsoft Forms” necessarily gains access to this data as a data processor in the course of providing its services.The processing of this information serves our legitimate interest in the effective provision and security of the services used, as well as for legal proceedings. The legal basis is Article 6(1)(f) of the GDPR.
Use of Cisco Webex
This privacy notice provides information about the processing of your personal data in connection with our use of video conferencing systems and the rights you are entitled to under the European General Data Protection Regulation (GDPR) and other data protection regulations.
We use “Webex” to conduct video conferences. “Webex” is software provided by Cisco Systems, Inc.
In general, we consider video conferencing systems to be telecommunications services in which the participant’s email address is typically used as the connection identifier. Furthermore, however, the respective video conferences may also be recorded. While we advise against this, if this feature is nevertheless used, it constitutes data processing on behalf of a controller. Where necessary, the MVZ Tübingen has entered into a data processing agreement with the relevant service providers.
The data controller is the respective employer of the person issuing the invitation. Our external data protection officer serves as the contact person. You can reach our external data protection officer via the relevant privacy notices on our website.
Why do we process your data (purpose of processing)?
We use the tools listed above to conduct video conferences. Chat content is logged when these tools are used. We store the chat content for a period of 70 days. Automated decision-making within the meaning of Art. 22 GDPR is not used. Legal basis for data processing: To the extent that personal data of employees is processed, § 26 BDSG serves as the legal basis for data processing.
If, in connection with the use of the specified tools, personal data is not required for the establishment, performance, or termination of the employment relationship, but is nonetheless an essential component of using the tools, then Article 6(1)(f) of the GDPR is the legal basis for data processing. In these cases, our interest lies in the effective conduct of video conferences.
Otherwise, the legal basis for data processing when conducting video conferences is Article 6(1)(b) of the GDPR, provided that the video conferences are conducted within the framework of contractual relationships. If no contractual relationship exists, the legal basis is Article 6(1)(f) of the GDPR. Here, too, our interest lies in the effective conduct of video conferences.
What data is processed?
When using video conferencing, various categories of data are processed. The scope of the data also depends on what data you provide
before or during your participation in a video conference. The following personal data, which is purely connection data, is subject to processing:
User information: e.g., display name, email address (if applicable), profile picture (optional), preferred language Meeting metadata:
e.g., date, time, meeting ID, phone numbers, location Text, audio, and video data:
You may have the option to use the chat function in an “online meeting.” In this regard, the text you enter is processed in order to display it in the “online meeting.” To enable video display and audio playback, data from your device’s microphone and any video camera on the device is processed for the duration of the meeting. You can turn off the camera or mute the microphone yourself at any time using the respective tool.
Recipients / Disclosure of Data?
Personal data processed in connection with participation in video conferences is generally not disclosed to third parties, unless it is specifically intended for disclosure. Please note that, as with in-person meetings, content from video conferences is often intended precisely to communicate information to customers, prospects, or third parties and is therefore intended for disclosure.
Other recipients: The providers of the tools necessarily gain access to the aforementioned data,
to the extent provided for in the respective data processing agreement.
Cisco Webex Privacy Policy: https://www.cisco.com/c/de_de/about/legal/privacy-full.html
How long will my data be stored?
The connection data mentioned above will be deleted by the respective service provider in accordance with the statutory retention periods.
Is data transferred to a third country or to an international organization?
Video conferencing services are provided by the respective tool providers. Consequently, the processing of personal data depends on the tool used.
In the event of a transfer to a third country, data protection requirements are met through standard contractual clauses and additional safeguards.
What data protection rights do I have?
Every data subject has the right of access under Article 15 of the GDPR, the right to rectification under Article 16 of the GDPR, the right to erasure under Article 17 of the GDPR, the right to restriction of processing under Article 18 of the GDPR, and the right to data portability under Article 20 of the GDPR.
The right of access and the right to erasure are subject to the restrictions set forth in Sections 34 and 35 of the Federal Data Protection Act (BDSG). In addition, you have the right to lodge a complaint with a data protection supervisory authority (Article 77 of the GDPR).
Information Regarding Your Right to Object Under Article 21 of the General Data Protection Regulation (GDPR) You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is carried out pursuant to Article 6(1)(f) of the GDPR (data processing based on a balancing of interests).
If you object, participation in a “web conference” is not possible. The objection may be made in any form and should be addressed to the respective controller.
Adobe Fonts
Our texts use fonts from Adobe Fonts, a service provided by Adobe Inc, 345 Park Avenue, San Jose, CA 95110-2704 (“Adobe”).
When you access one of our pages, your browser loads the required web fonts into your browser cache so that texts and fonts are displayed correctly. To do so, your browser connects to the Adobe server. For this purpose, information such as the fonts provided, JavaScript version, IP address, etc. is collected.
You can find more detailed information on Adobe’s privacy policy here: https://www.adobe.com/de/privacy/policies/adobe-fonts.html
Use of the “One Click Accessibility” (OneTap) Plugin
To improve the accessibility of our website, we use the “One Click Accessibility” plugin from the provider OneTap (wponetap.com). The plugin lets visitors customise the display of the website to their individual needs – for example, by enlarging the font or increasing the contrast. The plugin does not process any personal data and does not transfer any data to OneTap servers. Cookies are not set by OneTap. All settings made are stored locally in the user’s browser to retain the selected configuration during a subsequent visit. The use is based on Art. 6 (1) f GDPR (legitimate interest). Our interest lies in improving the user-friendliness and accessibility of our website.
Further information about the provider: https://wponetap.com/
Privacy Notice for the Use of Microsoft Exchange Online
1. Nature and Scope of Data Processing
We use the Microsoft Exchange Online service, part of the Microsoft 365 suite provided by Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland), to handle our email communications as well as for calendar and contact management. The following categories of data are processed in this context:
2. Purpose of Processing
-
- Communication Content: Subject lines, email texts, file attachments.
- Metadata: Sender and recipient information, date/time, IP addresses of the sending systems.
- Master data: Last name, first name, business email address, phone number (if stored in the profile).
- Calendar data: Appointment details, attendee lists, location information.
Processing is carried out to provide a modern and secure communication infrastructure, for efficient scheduling, and to ensure IT security (e.g., spam and phishing filters).
3.Legal basis or the performance of a contract pursuant to Art. 6(1)(b) GDPR.
-
- Employees: Data processing is based on Art. 88(1) GDPR in conjunction with § 26 BDSG for the purpose of carrying out the employment relationship.
- Business partners/external parties: If you communicate with us via email, the legal basis is our legitimate interest in effective communication pursuant to Article 6(1)(f) of the GDPR.
4.Recipients and transfer to third countries
Your data is processed on Microsoft servers. We have entered into a Data Processing Agreement (DPA) with Microsoft. Microsoft uses data centers in the European Union (Germany/Europe region). However, access by the U.S. parent company (Microsoft Corporation) cannot be completely ruled out. In this case, the EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses apply to ensure an adequate level of data protection.
5.Retention Period
The data will be deleted as soon as it is no longer necessary to achieve the purpose for which it was collected. For emails, statutory retention requirements (e.g., under the German Fiscal Code (AO) or the German Commercial Code (HGB)) also apply, which may require archiving for up to 10 years.
Use of Google Tools
The tracking measures listed below and used by us are carried out on the basis of Art. 6 para. 1 sentence 1 lit. f) GDPR. With the tracking measures used, we aim to ensure a demand-oriented design and the continuous optimization of our website. On the other hand, we use the tracking measures to statistically record the use of our website and to evaluate it for the purpose of optimizing our offer for you. These interests are to be regarded as legitimate within the meaning of the aforementioned provision. The respective data processing purposes and data categories can be found in the tracking tools described in more detail below.
Google Tag Manager
Use Google Tag Manager: Google Tag Manager is a solution that allows marketers to manage website tags through a single interface. The Tag Manager tool itself (which implements the tags) is a cookie-loose domain and does not collect any personal information. The tool is responsible for triggering other tags, which in turn may collect data. Google Tag Manager has no access to this data. When disabled at the domain or cookie level, all tracking tags implemented with the Google Tag Manager will continue to be disabled. https://marketingplatform.google.com/about/analytics/tag-manager/use-policy/
Google Analytics 4 (with cookies, with UserID)
Google Universal Analytics has been replaced by the new Google Analytics 4 service, which is also provided by Google Ireland Limited, Gordon House, 4 Barrow St, Dublin, D04 E5W5, Ireland (“Google”). This tool is also used to analyze website usage.
Google Analytics 4 uses “cookies” by default. Cookies are text files that are stored on your device and allow analysis of your use of a website. The information collected by cookies about your use of this website (including the IP address sent by your device, shortened by the last few digits, see below) is usually sent to a Google server, where it is stored and processed. This information may also be transferred to and processed on servers of Google LLC in United States.
When using Google Analytics 4, the IP address transmitted by your terminal device when you use the website is always automatically and anonymously collected and processed by default, so that a direct personal reference of the collected information is excluded. This automatic anonymization is carried out by Google within the member states of the European Union (EU) or other contractual states of the European Economic Area (EEA) by shortening the IP address transmitted by your terminal device by the last digits.
Google will use this and other information on our behalf to evaluate your use of the website, compiling reports on website activity for us and providing other services relating to website activity and internet usage. Google will not associate the IP address transmitted by your device and shortened by Google Analytics 4 with any other data held by Google. The data collected through the use of Google Analytics 4 will be stored for two months and then deleted.
Google Analytics 4 also has a special feature called “demographic characteristics” that allows you to create statistics that include information about age, interest-based advertising, and third-party information. This makes it possible to identify and distinguish groups of users of the website for the purpose of targeted marketing. However, the information collected through the “demographic characteristics” cannot be linked to any specific individual and is therefore not personally identifiable. The data collected through the “demographic characteristics” function will be kept for two months and then deleted.
All the aforementioned processing, particularly the setting of Google Analytics cookies for the storage and reading of information on the terminal device you use to use the site, will only be carried out if you give explicit consent pursuant to art. 6 (1) lit. a GDPR. Without your consent, Google Analytics 4 will not be used during your use of the website. You can revoke your consent at any time with effect for the future. To exercise your opt-out, please disable this service using the “Cookie Consent Tool” provided on the website. In connection with this website, the “UserIDs” feature is also used as an extension of Google Analytics 4. By assigning individual UserIDs, we can have Google generate cross-device reports (so-called “cross-device tracking”). This means that your usage behavior can also be analyzed across devices if you have given your consent to the use of Google Analytics 4 in accordance with Art. 6 (1) lit. a GDPR, if you have set up a personal account by registering on this website.
For our use of Google Analytics 4, we have entered into an order processing agreement with Google, which obligates Google to protect the data of our website users and not to pass it on to third parties. To ensure compliance with European data protection standards, Google refers to the European Commission’s Standard Contractual Clauses, which we have contractually agreed with Google, even if data is transferred from the EU or EEA to the U.S. for further processing.
Further legal information on Google Analytics 4, including a copy of the aforementioned standard contractual clauses, can be found at the following link: https://policies.google.com/privacy?hl=de&gl=de
Details on the processing triggered by Google Analytics 4 and Google’s handling of data from websites can be found here: https://policies.google.com/technologies/partner-sites
Further notes on Google UA can be found here: https://policies.google.com/privacy?hl=de&gl=de
For the transfer of data from the EU to the USA, the provider has signed up to the EU-US Data Privacy Framework, which ensures compliance with the European level of data protection on the basis of an adequacy decision by the European Commission.
Transfer of data, transfer to third countries
Your personal data will not be transferred to third parties for purposes other than those listed below. We only pass on your personal data to third parties if
- You have given your express consent in accordance with Art. 6 (1) (1) a GDPR and/or Section 26 (2) German Federal Data Protection Act (BDSG).
- The disclosure pursuant to Art. 6 (1) (1) f) GDPR is necessary for the assertion, exercise or defence of legal claims. There is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data.
- There is a legal obligation for the disclosure pursuant to Art. 6 (1) (1) c GDPR.
- Diese gesetzlich zulässig und nach Art. 6 Abs. 1 S. 1 lit. b) DSGVO, § 26 Abs. 1 BDSG für die Abwicklung eines Vertragsverhältnisses mit Ihnen oder für vorvertragliche Maßnahmen auf Ihre Veranlassung erforderlich ist.
A transfer to a third country or an international organisation is not intended and no automated decision-making takes place, unless otherwise provided for in this data protection declaration.
If necessary, information from MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH will also be passed on to business partners, service providers, third parties or subcontractors. Such transfer may be necessary in order to provide a service or transaction requested by you, e.g., for order processing or customer service purposes.
MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH may be obliged to disclose your data and related information in response to a court or official order. We also reserve the right to use your data for the assertion of or defence against legal claims.
In the event of a takeover or merger with another company, it may be necessary to disclose or pass on personal data to potential or actual buyers. In such a case, MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH will endeavour to protect the data as far as possible.
In accordance with applicable law, we reserve the right to store and pass on personal and other data to detect and combat illegal activities and attempted fraud or a breach of the terms of use of MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH.
Links to other websites
Our website may contain links to third-party websites. The MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH is not responsible for the data protection precautions or the content of websites outside the MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH.
Data retention
We only retain personal data for as long as required by the purpose or legal provisions for which it was collected.
Google Maps
On our website, we use Google Maps (API) provided by Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland (“Google”).
Google Maps is a web service that displays interactive (map) images to visually present geographic information. By using this service, our location is displayed to you, making it easier for you to find us.
As soon as you access the subpages on which the Google Maps map is embedded, information about your use of our website (such as your IP address) is transmitted to Google’s servers in the United States and stored there.
This occurs regardless of whether Google provides a user account through which you are logged in or whether no user account exists.
If you are signed in to Google, your data will be directly associated with your account. If you do not want your data to be associated with your Google profile, you must sign out before clicking the button. If you do not consent to the future transmission of your data to Google in connection with the use of Google Maps, you also have the option to completely disable the Google Maps web service by turning off JavaScript in your browser. Google Maps and, consequently, the map display on this website will then not be available.
The processing of this information serves our legitimate interest in the effective provision and security of the services used.
The legal basis is Article 6(1)(f) of the GDPR.
You can view Google’s Terms of Service at http://www.google.de/intl/de/policies/terms/regional.html; the additional Terms of Service for Google Maps can be found at https://www.google.com/intl/de_US/help/terms_maps.html.
For detailed information on data protection in connection with the use of Google Maps, please refer to Google’s Privacy Policy: http://www.google.de/intl/de/policies/privacy/
Software T2med and the APP PatMed
§ 1 Collection of personal data
(1) T2med GmbH & Co KG (“T2med”) collects and processes the personal data of its customers, business partners and employees in compliance with the applicable statutory data protection regulations, in particular, in compliance with the requirements of the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
(2) The party responsible for data collection and processing is T2med GmbH & Co: Bismarckallee 15, 24105 Kiel, Germany, fax: +49 431 – 55 680 690, e-mail:info@t2med.de . You can contact the data protection officer (Niels Köhrer, specialist lawyer for IT law, www.koehrer.de) by e-mail at dsb@t2med.de or by post at our address with the addition “Data Protection Officer”.
§ 2 Purposes, scope and duration of data collection and processing; legal bases
(1) T2med collects and processes personal data of customers who have purchased software licences from T2med or who have concluded a software licence agreement and maintenance contract with T2med. In particular, the customer’s contact data (name, practice name, address, telephone and fax numbers, e-mail address, homepage, operating site numbers, KV region, practice type, previous practice programme), the physician data of the physicians covered by the licence (title, name, HZV, LANR, BSNR) and the customer’s account data are collected and processed. Data is collected and processed on the basis of Art. 6 (1) b GDPR to fulfil the mutual obligations arising from the licence and software maintenance agreements concluded. The data is processed for the duration of the contractual relationship and beyond that only to the extent necessary to fulfil the contractual and legal obligations.
(2) When the Internet domain www.patmed.de, www.t2med.de or its subpages operated by T2med are called, data is automatically sent to the T2med server by the browser and stored for a limited period of time. The storage serves internal system-related and statistical purposes. The following are logged: the name of the retrieved file, date and time of retrieval, amount of data transferred, notification of successful retrieval, web browser and requesting domain. The IP addresses of the requesting computers are also logged. Further personal data is only collected if the user of the website and/or customer provides information voluntarily, for example, as part of an enquiry or registration, in particular, to register for the T2med forum or conclude a contract or by means of the settings of their browser. Data is collected and processed in accordance with Art. (6) (1) (1) f GDPR. When making entries in the online contact form on the website, contacting T2med electronically, registering for the forum or otherwise placing orders with T2med through the website, consent is given to the collection and processing of the personal data transmitted. Data processing is carried out exclusively for the purpose of processing and responding on the basis of consent pursuant to Art. 6 (1) (1) a GDPR. The personal data collected in this way will be automatically deleted as soon as the enquiry has been completed and there are no reasons for further storage (e.g. subsequent commissioning of T2med). The PatMed and T2med websites use cookies. A cookie is a text file that is sent when a website is visited and stored temporarily on the hard drive of the website user and/or customer. If the corresponding T2med server is called again by the user of the website and/or customer, the browser of the user of the website and/or customer sends the previously received cookie back to the server. The server can then analyse the information received through this procedure in various ways. Cookies can be used, for example, to control the display of adverts or make it easier to navigate a website. If the user of the website and/or customer wishes to prevent the use of cookies, they can do so by making local changes to their settings in the Internet browser used on their computer, i.e. the programme for opening and displaying Internet pages (e.g. Internet Explorer, Mozilla Firefox, Opera or Safari). The data collection and processing associated with cookies for the abovementioned purposes is justified to safeguard the legitimate interests of T2med in accordance with Art. 6 (1) (1) f GDPR. Plugins from the following social networks are integrated into the T2med website: Facebook, Twitter, Instagram. The legal basis for the use of social media plugins is Art. 6 (1) (1) f GDPR. A legitimate interest and purpose of the use of plugins is to publicise T2med’s services more widely. The social networks are responsible for handling their users’ data in compliance with data protection regulations.
(3) The collection and processing of personal data of T2med employees is carried out on the basis of Art. 6 (1)b GDPR for the fulfilment of mutual obligations arising from employment relationships and for the fulfilment of legal obligations by T2med in accordance with Art. 6 (1) c GDPR, in particular for tax and social security reasons. Personal data of applicants for employee positions are collected and processed for the purpose of the application procedure on the basis of the consent associated with the sending of application documents on the basis of Art. 6 (1) a GDPR. Employee data will be processed for the duration of the employment relationship and subsequently to the extent necessary for the settlement of existing reciprocal claims or to fulfil T2med’s legal obligations. Applicant data will be stored for the duration of the application process and then deleted.
(4) The collection and processing of personal data of business partners (in particular, suppliers and service providers) is carried out in accordance with Art. 6 (1) b GDPR for the initiation, implementation and follow-up of the respective contractual relationships to the extent necessary. In particular, contact details of business partners and their employees are collected and processed. Data will be processed for as long as required to safeguard the legitimate interests of T2med, in particular to enforce any claims. Beyond this use, data will only be collected and processed with the consent of the business partner concerned.
(5) The PatMed app uses push services from Firebase Cloud Messaging. If the push service is used, a device token from Apple or a registration ID from Google is assigned. These are encrypted, anonymised device IDs. The sole purpose of their use is to provide the push services. It is not possible for T2med to identify the individual user. The push service can be customised or deactivated on the user’s operating system if required. The push messages are end-to-end encrypted.
Other Firebase services are not used.
Further information on the terms of use of Firebase Cloud Messaging can be found on the Firebase website: https://firebase.google.com/terms/.
§ 3 Rights of data subjects affected by data collection and processing
The data subjects affected by the collection and processing of personal data by T2med have the rights listed below with regard to data collection and processing:
(1) Right to information in accordance with Art. 15 GDPR
Data subjects may request information from T2med as to whether personal data is processed by T2med. However, there is no right to information if the provision of the requested information must be kept secret for legitimate reasons, in particular, due to an overriding legitimate interest of a third party. In this case, a balance must be struck between the data subject’s interest in information and the third party’s interest in confidentiality. A right to information is also excluded if the personal data must not be deleted only due to statutory retention periods or serve exclusively for data backup or data protection control, provided that the provision of the requested information would require a disproportionately high effort and the processing for other purposes is excluded by suitable technical and organisational measures. If the right to information is not excluded, T2med may be requested to provide the following information:
- Purpose of data collection and processing;
- Categories of personal data processed;
- Recipients or categories of recipients to whom personal data is disclosed;
- Duration of storage of the personal data or, if this is not possible, criteria for determining the storage period
- The existence of a right to rectification or erasure or restriction of processing of personal data or a right to object to such processing
- The existence of a right to lodge a complaint with a supervisory authority;
- If personal data was not collected from the data subject: available information on the origin of the data
- Where applicable, the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and envisaged consequences of automated decision-making
- Where applicable, in the case of transfer to recipients in third countries, unless the EU Commission has decided on the adequacy of the level of protection pursuant to Art. 45 (3) GDPR, information on the appropriate safeguards pursuant to Art. 46 (2) GDPR for the protection of personal data.
(2) Right to receive a copy pursuant to Art. 15 (3) GDPR and right to data portability pursuant to Art. 20 GDPR
Data subjects have the right to receive a copy of the personal data concerning them and, in this context, to data portability if the processing is based on the consent of the data subject (Art. 6 (1) (1) a or Art. 9 (2) a GDPR) or on a contract with the data subject and the processing is carried out using automated procedures. The right to data portability includes the right to data portability, provided that it does not adversely affect the rights and freedoms of third parties: the personal data must be receivedin a structured, commonly used and machine-readable format, and the data subject must be able to transmit those data to another controller without hindrance from T2med in any form. Where technically feasible, the data subject may request that T2med transmit the personal data directly to another data controller.
(3) Right to rectification and restriction of processing pursuant to Art. 16 GDPR and Art. 18 GDPR
a) If a data subject discovers that T2med has incorrect personal data relating to the data subject, the data subject may request that T2med rectify this incorrect data without delay. In the case of incomplete personal data, completion may be requested.
b) A data subject may request the restriction of processing if
- the accuracy of the personal data is contested, for the duration of the verification of accuracy by T2med;
- the processing is unlawful and the restriction of the use of the personal data is requested instead of erasure;
- the personal data are no longer necessary for the purposes of the processing by T2med, but are required by the data subject for the establishment, exercise or defence of legal claims;
- an objection has been lodged pursuant to Art. 21 (1) GDPR pending the verification as to whether the legitimate grounds of T2med override those for the restriction.
Restriction of processing means that personal data will only be processed with the consent of the data subject or for the establishment, exercise or defence of legal claims or for the protection of the rights of a third party or for reasons of important public interest. T2med will inform the data subject before cancelling a restriction.
(4) Right to erasure pursuant to Art. 17 GDPR
The data subject has the right to erasure of personal data (“right to be forgotten”), unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation or for the performance of a task carried out in the public interest, and one of the following reasons applies
- the personal data is no longer necessary in relation to the purposes for which it was processed;
- the justification for the processing was solely the consent of the data subject, which has since been withdrawn
- an objection has been lodged against the processing of personal data that T2med has made public;
- an objection has been lodged to the processing of personal data not made public by T2med and there are no overriding legitimate grounds for the processing
- the personal data has not been processed unlawfully;
- the erasure of the personal data is no longer necessary for compliance with a legal obligation to which T2med is subject.
There is no right to erasure if, in the case of lawful non-automated data processing, erasure is not possible or only possible with disproportionate effort due to the special type of storage and the interest in erasure is low. In this case, the restriction of processing may be requested instead of erasure.
(5) Objection and revocation of consent
If the processing of personal data is based on Art. 6 (1) (1) f GDPR (legitimate interest of the controller or a third party), the data subject has the right to object to the processing of personal data concerning them at any time for reasons arising from their particular situation. This also applies to profiling based on Art. 6 (1) (1) e or f GDPR. After exercising the right to object, T2med will no longer process the personal data concerned unless T2med can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject. The same applies in the case of processing for the establishment, exercise or defence of legal claims by T2med.
The data subject may object at any time to the processing of personal data concerning them for direct marketing purposes. This also applies to profiling in connection with such direct marketing. After exercising the right to object, T2med will no longer use the personal data concerned for direct marketing purposes. The data subject has the option of informing T2med of the objection informally by telephone, e-mail, fax or post.
The person affected by the collection and storage of data has the right to revoke their consent at any time with effect for the future. The revocation of consent can be communicated informally to T2med by telephone, e-mail, fax or post. The revocation does not affect the legality of the data processing until receipt of the revocation. If the data processing is carried out exclusively on the basis of the consent given in advance, T2med shall cease the data processing immediately after revocation of the consent.
§ 4 Data transfer; organisational measures
(1) Forwarding of data
T2med will only disclose or otherwise transfer personal data to third parties if required for the purpose of contract fulfilment or billing purposes or if the data subject has given their prior consent. Any consent given can be revoked at any time with effect for the future.
(2) Technical measures for data protection
For the processing of personal data by T2med, suitable technical and organisational measures are taken to ensure that the personal data is protected. These measures include, in particular, the pseudonymisation and encryption of personal data, data backup and the evaluation of technical and organisational measures.
§ 5 Processors of personal data
On the basis of the software utilisation and maintenance contracts, T2med also offers its customers remote maintenance and servicing of the software products. In this way, T2med is enabled to access and process the personal data collected and processed by its customers. This processing of personal data is inextricably linked to the services provided by T2med to its customers. T2med guarantees to its customers that all data protection provisions under the GDPR and BDSG are also observed with regard to this data in accordance with this data protection notice.
§ 6 Right of complaint in relation to T2med
Data subjects affected by the collection and processing of personal data have the right to lodge a complaint with the supervisory authority responsible for T2med in accordance with Art. 77 GDPR: State Data Protection Officer Marit Hansen, Independent State Centre for Data Protection Schleswig-Holstein, P.O. Box 7116, 24171 Kiel, Germany. A complaint may also be lodged with the supervisory authority responsible for the data subject’s usual place of residence or workplace.
Data protection information in the application process
- We process applicant data only for the purpose and within the scope of the application process in accordance with the legal requirements. Applicant data is processed to fulfil our (pre-)contractual obligations as part of the application process within the scope of Art. 6 (1) b GDPR/Art. 6 (1) f GDPR if the data processing becomes necessary for us, e.g. in the context of legal proceedings (in Germany, Section 26 BDSG also applies).
- The application process requires applicants to provide us with applicant data. Necessary applicant data includes personal details, postal and contact addresses and the documents relating to the application, such as cover letter, CV and references. Applicants can also voluntarily provide us with additional information.
- By submitting their application to MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH, applicants consent to the processing of their data for the purposes of the application process in accordance with the type and scope set out in this privacy policy.
- Insofar as special categories of personal data within the scope of Art. 9 (1) GDPR are voluntarily communicated as part of the application process, their processing is also carried out in accordance with Art. 9 (2) b GDPR (e.g. health data, such as severely disabled status or ethnic origin). Insofar as special categories of personal data within the scope of Art. 9 (1) GDPR are requested from applicants as part of the application process, their processing is also carried out in accordance with Art. 9 (2) a GDPR (e.g. health data if required for the exercise of the profession).
- Applicants can send us their applications by post or by e-mail. Please note, however, that e-mails are generally not sent in encrypted form and applicants must ensure that they are encrypted themselves. We can therefore accept no responsibility for the transmission path of the application between the sender and receipt on our server. If the applicant has any concerns regarding the security of the application documents sent by e-mail, we recommend sending the application documents by post.
- In the event of a successful application, the data provided by the applicant may be processed by us for the purposes of the employment relationship. Otherwise, if the application for a job offer is not successful, the applicant’s data will be deleted. Applicants’ data will also be deleted if an application is withdrawn, which applicants are entitled to do at any time.
- The deletion takes place, subject to a justified cancellation by the applicants, after the application procedure has been completed for six months so that we can answer any follow-up questions about the application and fulfil our obligations to provide evidence under the Gleichbehandlungsgesetz (German Equal Treatment Act). If you have been accepted for a position as part of the application process, the data from the application will be transferred to a personnel file and deleted 10 years after termination of the employment relationship.
Invoices for any reimbursement of travel expenses will be archived in accordance with tax regulations.
Rights of data subjects
You have the right,
- to request information about your personal data processed by us in accordance with 15 GDPR. In particular, you can request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, such as the existence of automated decision-making and, if applicable, meaningful information about its details;
- in accordance with Art. 16 GDPR, to immediately request the correction of incorrect or the completion of your personal data stored by us
- in accordance with Art. 17 GDPR, to demand the erasure of personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation in the public interest or for the establishment, exercise or defence of legal claims
- in accordance with Art. 18 GDPR, to demand the restriction of the processing of your personal data if the accuracy of the data is disputed by you, the processing is unlawful, but you refuse to delete it and we no longer need the data, but you need it for the assertion, exercise or defence of legal claims or you have lodged an objection to the processing in accordance with Art. 21 GDPR;
- in accordance with Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format or to request that it be transmitted to another controller
- in accordance with Art. 7 para. 3 GDPR, to revoke your consent given to us at any time. The consequence of this is that we may no longer continue the data processing that was based on this consent in the future; and
- to lodge a complaint with a supervisory authority in accordance with Art. 77 GDPR. As a rule, you can contact the supervisory authority of your usual place of residence or workplace or the registered office of our company.
The competent supervisory authority for data protection at MVZ für Diagnostik, Prävention, Onkologie und Gastroenterologie Tübingen GmbH:
Baden-Württemberg Supervisory Authority
The State Commissioner for Data Protection Baden-Württemberg
P.O. Box 10 29 32, 70025 Stuttgart
Lautenschlagerstraße 20, 70173 Stuttgart
Tel. +49 711 615541-0
Fax: +49 711 615541-15
Mail: poststelle@lfd.bwl.de
http://www.baden-wuerttemberg.datenschutz.de
To assert the aforementioned rights and ask questions about data protection, you can contact the data controller in accordance with Section 1 above or send an e-mail to info(at)mvz-tuebingen.de
Right to object
If your personal data is processed on the basis of legitimate interests in accordance with Art. 6 (1) (1) f GDPR, you have the right to object to the processing of your personal data in accordance with Art. 21 GDPR, provided that there are reasons for this arising from your particular situation or the objection is directed against direct advertising. In the latter case, you have a general right to object, which will be implemented by us without specifying a particular situation. If you would like to exercise your right of cancellation or objection, simply send an e-mail to info(at)mvz-tuebingen.de
Data security
- We use the widespread SSL (Secure Sockets Layer) method in conjunction with the highest level of encryption supported by your browser when you visit our website. As a rule, this is 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can recognise whether an individual page of our website is transmitted in encrypted form by the closed display of the key or lock symbol in the lower status bar of your browser.
- We also use suitable technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorised access by third parties. Our security measures are continuously improved in line with technological developments.
- In addition, we oblige each of our employees to maintain data protection and confidentiality in accordance with the General Data Protection Regulation (GDPR).
Changes to this privacy policy
Due to current circumstances, such as a change in the relevant data protection regulations, we will update this privacy policy if necessary.
Status: 07/05/2026

