Privacy Policy

Status February 2025, Version 2.4

Our Commitment to Your Privacy

Data protection is not only a statutory obligation for us, but a genuine concern. At Healthy Projects GmbH, we therefore take the protection of your personal data very seriously. We process your personal data in various contexts when you use our website. Pursuant to Articles 13 and 14 of the EU General Data Protection Regulation (GDPR), you have the right to be informed about the processing of your personal data.

1. Controller

This Privacy Policy applies to the processing of your personal data by Healthy Projects GmbH as the controller within the meaning of Article 4 No. 7 GDPR.

Healthy Projects GmbH

Grünstraße 15, 40212 Düsseldorf

Phone: +49 (0)211 600 5731

E-mail: feedback@healthyprojects.de

2. Data Protection Officer

Healthy Projects has appointed a data protection officer. You can reach the data protection officer at the above postal address ("Attn: Data Protection Officer") or by e-mail at feedback@healthyprojects.de

3. Data Processing When Visiting Our Website

3.1 Which data do we process?

When you visit our website, our web server processes, with each request, a range of data that your browser automatically transmits to our server. This includes the IP address of the requesting device, browser type and version, operating system used, referrer URL, hostname of the accessing device, and the date and time of the server request. Apart from the functionally necessary session cookie, no cookies are set.

3.2 Purpose of data processing

The purpose of the processing is to provide and operate our website.

3.3 Legal basis

The legal basis for this processing is Article 6(1) sentence 1 lit. f) GDPR (legitimate interest in operating an online presence).

3.4 Are data disclosed to third parties?

Log and communication data are not disclosed to third parties. We use service providers when delivering our services, in particular for the provision, maintenance and servicing of IT systems. The service providers engaged by Healthy Projects are located within the EU/EEA and are integrated in a manner compliant with data protection law.

3.5 When do we delete the data?

We do not store the full IP address transmitted by your web browser, or we store it only on a case-by-case basis for a period of 7 days. In the event of such case-related storage, we delete or anonymise the IP address after this period has expired.

4. Video Consultation

Our certified video consultation service Arrivara is operated on our website. Certification is granted by a certification body specialising in data protection for video consultations, which regularly audits compliance with legal requirements. The video consultation application is only accessible via a secure login. We provide the video consultation to our customers as a commissioned data processing service (Article 28 GDPR). From a data protection perspective, the respective healthcare professional is responsible vis-à-vis their patients.

5. Web Analytics Service "TrackBoxx"

5.1 Which data are processed?

We use the web analytics service TrackBoxx on our website to evaluate visitor traffic and usage of our online presence. For this purpose, data are stored in anonymised form on a server in Germany. The analytics service does not use any cookies and does not store any personal data of website visitors. Instead, your IP address is used to generate a code that is assigned to an anonymous user ID for the duration of your visit.

5.2 Purpose of data processing

We use your data for statistical recording of visitor traffic and analysis of the use of our online presence.

5.3 Legal basis

The processing of your data is based on our legitimate interests in accordance with Article 6(1) sentence 1 lit. f) GDPR.

pages.privacy.sections.analytics.disclosure.title

pages.privacy.sections.analytics.disclosure.content

pages.privacy.sections.analytics.deletion.title

pages.privacy.sections.analytics.deletion.content

6. Contact Form

6.1 Which data are processed?

When you contact us via the contact form, we store the personal data you provide. This includes your first and last name, e-mail address and the content of your message.

6.2 Purpose of data processing

We use your contact details to respond to your enquiries.

pages.privacy.sections.contactForm.legal.title

pages.privacy.sections.contactForm.legal.content

pages.privacy.sections.contactForm.disclosure.title

pages.privacy.sections.contactForm.disclosure.content

6.5 When do we delete the data?

The data are deleted as soon as they are no longer required to achieve the purpose for which they were collected and we no longer need them for evidentiary purposes. This is the case after 60 days.

7. Customer Support

Healthy Projects offers customer support and provides a support e-mail address. In this context, we collect your name, e-mail address and your enquiry. The legal basis for this data processing is the performance of our (pre-)contractual obligations in connection with the provision of our services in accordance with Article 6(1) sentence 1 lit. b) GDPR. Data are deleted after 60 days.

8. Introductory Webinar

8.1 Which data are processed?

8.2 Purpose of data processing

8.3 Legal basis

8.4 Are data disclosed to third parties?

8.5 When do we delete the data?

9. Registration of Healthcare Professionals

9.1 Which data are processed?

Within the scope of registration, we process the following data: username, password, first and last name, e-mail address, business address, professional title, bank account details, and proof of your professional licence. These data are required for the conclusion of the contract. In your user profile, you may voluntarily provide additional data and upload profile pictures.

9.2 Purpose of data processing

The purpose of data processing is to ensure your registration, create a user profile, and conclude and perform the user agreement between you and Healthy Projects.

9.3 Legal basis

The legal basis for the processing of mandatory information is the performance of our (pre-)contractual obligations in connection with the provision of our services in accordance with Article 6(1) sentence 1 lit. b) GDPR. We process the optional data provided during registration on the basis of your consent in accordance with Article 6(1) sentence 1 lit. a) GDPR.

10. Use of the Platform and Conduct of the Video Consultation

10.1 Which data are processed?

Platform use: When using the Arrivara platform, we process your chat messages provided on the platform, your appointments, and intervention contacts and appointments. In addition, you are notified by e-mail when new appointments for the video consultation or interventions are scheduled.

Video consultation: Within the scope of the video consultation, we process, via our platform, audio and video streams and other content exchanged via the whiteboard. These exchanged data are subject to confidentiality and are transmitted using end-to-end encryption.

10.5 When do we delete your data?

Your data are deleted when they are no longer required for the purposes for which they were collected. For platform usage data, this is the case when the user agreement has ended, you delete your profile with us and there are no statutory retention obligations. Audio and video streams and whiteboard content are not stored.

11. Payment Data

11.1 Which data are processed?

We offer payment by credit card, SEPA direct debit and PayPal. For payment processing, we collect the payment data you provide, including data arising directly in connection with payment processing and credit checks.

11.4 Are data disclosed to third parties?

Your data are forwarded to the payment service provider you select. For handling payment transactions, we use the payment service provider Stripe Payments Europe, Limited (SPEL), 1 Grand Canal Street Lower, Grand Canal Dock, Dublin D02 H210, Ireland, which is integrated as a processor in compliance with data protection requirements.

12. Newsletter Distribution

For the distribution of our newsletter to healthcare professionals, we use names and e-mail addresses. We also require your separate confirmation by e-mail (double opt-in) to send the newsletter. The processing of data in this context is based on your consent in accordance with Article 6(1) sentence 1 lit. a) GDPR. You may withdraw this consent at any time by using the unsubscribe link in the newsletter.

13. Profiling

There is no automated decision-making, including profiling, within the meaning of Article 22 GDPR.

14. What Rights Do You Have as a Data Subject?

  • Right of access (Article 15 GDPR): You have the right to obtain confirmation as to whether or not personal data concerning you are being processed; where that is the case, you have the right of access to this personal data.
  • Right to rectification (Article 16 GDPR): You have the right to obtain without undue delay the rectification of inaccurate personal data concerning you.
  • Right to erasure (Article 17 GDPR): You have the right to obtain the erasure of personal data concerning you without undue delay where one of the grounds listed in Article 17 GDPR applies.
  • Right to restriction of processing (Article 18 GDPR): You have the right to obtain restriction of processing where one of the conditions listed in Article 18 GDPR applies.
  • Right to data portability (Article 20 GDPR): You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format.
  • Right to object (Article 21 GDPR): Where data are processed on the basis of legitimate interests, you have the right to object at any time to the processing of personal data concerning you.

15. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for Healthy Projects is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen

Kavalleriestraße 2–4
40213 Düsseldorf

E-mail: poststelle@ldi.nrw.de

Contact Us About Privacy

If you have any questions about this privacy policy or wish to exercise your rights, please contact us:

Contact Privacy Team

This privacy policy may be updated from time to time. We will notify you of any significant changes via email or through the platform.