1. DATA PROTECTION AT A GLANCE
GENERAL INFORMATION
The following information provides a simple overview of what happens to your personal data when you visit our website. Refers to any information that can be used to identify you personally. Detailed information on the subject of data protection can be found in our privacy policy listed below this text.
DATA COLLECTION ON OUR WEBSITE
Who is responsible for data collection on this website?
The data processing on this website is carried out by the website operator. You can find their contact details in the imprint of this website.
How do we collect your data?
Your data is collected firstly by you providing us with it. This could be data that you enter into a contact form, for example.
Other data is automatically collected by our IT systems when you visit the website. These are primarily technical data (e.g., internet browser, operating system, or time of the page view). The collection of this data occurs automatically as soon as you enter our website.
What do we use your data for?
Part of the data is collected to ensure the proper functioning of the website. Other data can be used to analyze your user behavior.
What rights do you have regarding your data?
You have the right at any time to obtain information free of charge about the origin, recipient, and purpose of your stored personal data. You also have the right to request the correction, blocking, or deletion of this data. For this purpose, as well as for further questions on the subject of data protection, you can contact us at any time at the address given in the imprint. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.
In addition, you have the right to request the restriction of processing of your personal data under certain circumstances. Details on this can be found in the privacy policy under "Right to restriction of processing".
ANALYSIS TOOLS AND THIRD-PARTY TOOLS
When visiting our website, your surfing behavior can be statistically evaluated. This is done primarily with cookies and so-called analysis programs. The analysis of your surfing behavior is generally carried out anonymously; the surfing behavior cannot be traced back to you. You can object to this analysis or prevent it by not using certain tools. Detailed information on this can be found in the following privacy policy.
You can object to this analysis. We will inform you about the possibilities of objection in this privacy policy.
2. GENERAL INFORMATION AND MANDATORY INFORMATION
DATA PROTECTION
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data are collected. Personal data is data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.
Please note that data transmission over the Internet (e.g., when communicating by email) may have security gaps. Complete protection of data against access by third parties is not possible.
The data protection officer of the operator can be reached at Datenschutz@hanseaticum.de.
NOTE ON THE RESPONSIBLE ENTITY
Responsible for the processing of data on this website in terms of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states of the European Union and other data protection regulations are:
- HANSEATICUM- Zentrum für Plastische und Ästhetische Chirurgie, Martinistraße 64, 20251 Hamburg, info@hanseaticum.de
und
- HANSEATICUM-WEST - Facharztkompetenz-Zentrum, Jürgen-Töpfer-Straße 46, 22763 Hamburg, info@hanseaticum-west.de
as joint controllers.
For contact via one of our contact forms or by email, the party responsible for the respective contact service is solely responsible for the data processing, i.e., for the contact form and the online appointment scheduling of HANSEATICUM - Zentrum für Plastische und Ästhetische Chirurgie and the email address info@hanseaticum.de: HANSEATICUM - Zentrum für Plastische und Ästhetische Chirurgie, Martinistraße 64, 20251 Hamburg, info@hanseaticum.de and for the contact form and the online appointment scheduling of HANSEATICUM-WEST - Facharztkompetenz-Zentrum and the email address info@hanseaticum-west.de: HANSEATICUM-WEST - Facharztkompetenz-Zentrum, Jürgen-Töpfer-Straße 46, 22763 Hamburg, info@hanseaticum-west.de. Data is not generally transferred to the other responsible party in the case of such contact.
REVOCATION OF YOUR CONSENT TO DATA PROCESSING
Many data processing operations are only possible with your express consent. You can revoke any consent you have already given at any time. A simple email making this request is sufficient. The legality of the data processing carried out before the revocation remains unaffected by the revocation.
RIGHT TO OBJECT TO DATA COLLECTION IN SPECIAL CASES AND TO DIRECT MARKETING (ART. 21 GDPR)
If data processing is based on Art. 6 para. 1 lit. e or f GDPR, you have the right at any time to object to the processing of your personal data for reasons arising from your particular situation; this also applies to profiling based on these provisions. The respective legal basis on which processing is based can be found in this privacy policy. If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is for the establishment, exercise, or defense of legal claims (objection according to Art. 21 para. 1 GDPR).
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such the purposes; this also applies to profiling to the extent that it is related to such direct marketing. If you object, your personal data will subsequently no longer be used for direct marketing purposes (objection according to Art. 21 para. 2 GDPR).
RIGHT TO LODGE COMPLAINTS WITH REGULATORY AUTHORITIES
In the case of breaches of the GDPR, those affected have a right to lodge a complaint with a regulatory authority, in particular in the member state of their habitual residence, place of work, or place of the alleged infringement. This right to lodge a complaint is without prejudice to any other administrative or judicial remedies.
RIGHT TO DATA PORTABILITY
You have the right to have data we have processed based on your consent or in fulfillment of a contract automatically delivered to yourself or to a third party in a structured, commonly used, and machine-readable format. If you request the direct transfer of the data to another controller, this will only be done to the extent technically feasible.
SSL OR TLS ENCRYPTION
This site uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or inquiries you send to us as the site operator. You can recognize an encrypted connection in your browser's address line when it changes from "http://" to "https://" and the lock icon is displayed in your browser's address bar.
If SSL or TLS encryption is activated, the data you transfer to us cannot be read by third parties.
INFORMATION, BLOCKING, DELETION, AND CORRECTION
You have the right to:
- be provided with information about your stored personal data, its origin, its recipients, and the purpose of its processing at any time according to Art. 15 GDPR;
- demand the correction of incorrect or incomplete personal data stored by us according to Art. 16 GDPR;
- demand the deletion of your personal data stored by us, unless the processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for reasons of public interest, or for the establishment, exercise, or defense of legal claims according to Art. 17 GDPR;
- demand the restriction of the processing of your personal data according to Art. 18 GDPR if the accuracy of the data is contested by you, the processing is unlawful, but you reject its deletion and we no longer need the data, but you require it for the establishment, exercise, or defense of legal claims, or you have objected to processing according to Art. 21 GDPR.
RIGHT TO RESTRICT PROCESSING
You have the right to demand the restriction of the processing of your personal data. For this purpose, you can contact us at any time at the address given in the imprint. The right to restrict processing applies in the following cases:
- If you contest the accuracy of your personal data stored by us, we usually need time to verify this. For the duration of the review, you have the right to demand the restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you can demand the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you need it to exercise, defend, or claim legal claims, you have the right to demand the restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection pursuant to Art. 21 para. 1 GDPR, balancing must be conducted between your interests and ours. As long as it has not been determined whose interests prevail, you have the right to demand the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, these data - apart from their storage - may only be processed with your consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or juridical person or for reasons of important public interest of the European Union or a Member State.
3. DATA COLLECTION ON OUR WEBSITE
Cookies
Some parts of our website use so-called cookies. Cookies do not cause any damage to your computer and do not contain viruses. Cookies are used to make our offer more user-friendly, effective, and secure. Cookies are small text files that are stored on your computer and saved by your browser.
Most of the cookies we use are so-called "session cookies." They are automatically deleted after your visit. Other cookies remain stored on your device until you delete them. These cookies allow us to recognize your browser on your next visit.
You can configure your browser to inform you about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.
Cookies that are necessary to carry out the electronic communication process or to provide certain functions you desire (e.g., shopping cart function) are stored on the basis of Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in storing cookies for the technically error-free and optimized provision of its services. Insofar as other cookies (e.g., cookies for analyzing your surfing behavior) are stored, they are treated separately in this privacy policy.
SERVER LOG FILES
The provider of the website automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:
- Browser type and browser version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
This data is not combined with other data sources.
The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website - for this purpose, the server log files must be recorded.
CONTACT FORM
If you send us inquiries via the contact form, your details from the inquiry form, including the contact details you provided there, will be stored by us for the purpose of processing the inquiry and in case of follow-up questions. We do not share this information without your consent.
The processing of the data entered into the contact form is therefore based exclusively on your consent (Art. 6 para. 1 lit. a GDPR). You can revoke this consent at any time. A simple email to us is sufficient. The legality of the data processing operations carried out until the revocation remains unaffected by the revocation.
The data you enter in the contact form will remain with us until you ask us to delete it, revoke your consent to storage, or the purpose for data storage no longer applies (e.g., after your request has been processed). Mandatory statutory provisions - in particular retention periods - remain unaffected.
PROCESSING OF DATA (CUSTOMER AND CONTRACT DATA)
We collect, process, and use personal data only insofar as it is necessary for the establishment, content organization, or change of the legal relationship (inventory data). This is done on the basis of Art. 6 para. 1 lit. b GDPR, which allows the processing of data to fulfill a contract or pre-contractual measures. We collect, process, and use personal data regarding the use of our websites (usage data) only to the extent necessary to enable the user to use the service or for billing purposes.
The collected customer data will be deleted after completion of the order or termination of the business relationship. Legal retention periods remain unaffected.
4. ANALYSIS TOOLS AND ADVERTISING
Google Analytics
This website uses features of the web analytics service Google Analytics. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics uses so-called "cookies". These are text files that are stored on your computer and that allow an analysis of your use of the website. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.
The storage of Google Analytics cookies and the use of this analysis tool are based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior to optimize both its website and its advertising.
IP ANONYMIZATION
We have activated the IP anonymization feature on this website. As a result, your IP address will be shortened by Google within member states of the European Union or other parties to the Agreement on the European Economic Area prior to transmission to the United States. Only in exceptional cases is the full IP address sent to a Google server in the US and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity, and to provide other services related to website activity and internet usage to the website operator. The IP address transmitted by your browser as part of Google Analytics will not be merged with any other data held by Google.
BROWSER PLUGIN
You can prevent the storage of cookies by selecting the appropriate settings on your browser; however, we would like to point out that if you do this, you may not be able to use all the features of this website to their full extent. You can also prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=de.
OBJECTION TO DATA COLLECTION
You can prevent the collection of your data by Google Analytics by clicking on the following link. An opt-out cookie will be set to prevent your data from being collected on future visits to this site: Disable Google Analytics.
For more information on how to handle user data on Google Analytics, please refer to Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=de.
DATA PROCESSING AGREEMENT
We have concluded a data processing agreement with Google and fully implement the strict requirements of the German data protection authorities when using Google Analytics.
GOOGLE ANALYTICS REMARKETING
Our websites use the features of Google Analytics Remarketing combined with the cross-device capabilities of Google AdWords and Google DoubleClick. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
This feature allows the advertising target groups created with Google Analytics Remarketing to be linked with the cross-device capabilities of Google AdWords and Google DoubleClick. This way, interest-based, personalized advertising messages that have been adapted to you based on your previous usage and browsing behavior on one device (e.g., mobile phone) can also be displayed on another of your devices (e.g., tablet or PC).
If you have given the corresponding consent, Google will link your web and app browsing history to your Google Account for this purpose. This way, any device that signs into your Google Account can use the same personalized promotional messaging.
To support this feature, Google Analytics collects google-authenticated IDs of users that are temporarily linked to our Google Analytics data to define and create target audiences for cross-device ad promotion.
You can permanently opt-out of cross-device remarketing/targeting by turning off personalized advertising in your Google Account; follow this link: https://www.google.com/settings/ads/onweb/.
The aggregation of the data collected in your Google Account data is based solely on your consent, which you may give or withdraw from Google (Art. 6 para. 1 lit. a GDPR). For data collection operations not merged into your Google Account (for example, because you do not have a Google Account or have objected to the merge), the collection of data is based on Art. 6 para. 1 lit. f GDPR. The legitimate interest arises because the website operator has an interest in the anonymized analysis of website visitors for advertising purposes.
Further information and the data protection regulations can be found in Google's privacy policy at: https://www.google.com/policies/technologies/ads/.
GOOGLE ADWORDS AND GOOGLE CONVERSION TRACKING
This website uses Google AdWords. AdWords is an online advertising program of Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States (“Google”).
Within Google AdWords, we use so-called conversion tracking. When you click on an ad served by Google, a conversion tracking cookie is set. Cookies are small text files that the internet browser places on the user's computer. These cookies expire after 30 days and are not used for personal identification of the user. If the user visits certain pages of this website and the cookie has not yet expired, Google and we can tell that the user clicked on the ad and was redirected to this page.
Each Google AdWords advertiser receives a different cookie. Cookies cannot be tracked using the website of an AdWords advertiser. The information obtained using the conversion cookie is used to create conversion statistics for AdWords advertisers who have opted for conversion tracking. Customers are told the total number of users who clicked on their ad and were redirected to a page with a conversion tracking tag. However, advertisers do not obtain any information that can be used to personally identify users. If you do not wish to participate in tracking, you can opt-out of this by easily disabling the Google Conversion Tracking cookie via your internet browser under user settings. You will then not be included in the conversion tracking statistics.
The storage of “conversion cookies” and the use of this tracking tool are based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in analyzing user behavior to optimize both its website and its advertising.
More information about Google AdWords and Google Conversion Tracking can be found in Google's privacy policy: https://www.google.de/policies/privacy/.
You can set your browser to inform you about the setting of cookies and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.
GOOGLE TAG MANAGER
Our website uses the Google Tag Manager, a service of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (“Google”). The Tag Manager is used to manage tracking tools and other services, called website tags. A tag is an element that is placed in the source code of our website to, for example, record specified usage data. The Google Tag Manager does not use cookies. The Google Tag Manager ensures that the usage data needed by our partners (see the data processing operations described above) is forwarded to them. In some cases, the data is processed on a Google server in the USA. In the event that personal data is transferred to the USA, Google has subjected itself to the EU-US Privacy Shield. The legal basis is Art. 6 para. 1 lit. f GDPR, based on our legitimate interest in integrating. You can find more information on this in Google's Tag Manager information.
5. Plugins and Tools
Jameda
Our website incorporates seals or widgets from jameda GmbH, St. Cajetan-Straße 41, 81669 München. A widget is a small window that displays variable information. Our seal functions similarly, meaning it does not always look the same; the display changes regularly. The corresponding content is displayed on our website, but at that moment, it is retrieved from the jameda servers. This is the only way to always show the current content, especially the current rating. For this to happen, a data connection from this website to jameda must be established, and jameda receives certain technical data (date and time of the visit; the page from which the query comes; used Internet Protocol address (IP address), browser type and version, device type, operating system, and similar technical information), which are necessary for the content to be delivered. These data are only used for the provision of the content and are not stored or used in any other way.
We pursue the purpose and legitimate interest of displaying current and correct content on our homepage by integrating this. The legal basis is Art. 6 Para. 1 f) GDPR. We do not store the mentioned data due to this integration. For appointment scheduling, you will be redirected to www.jameda.de. jameda processes the data you provide there on its own responsibility. Further information on data processing by jameda can be found in the privacy policy of the site www.jameda.de/jameda/datenschutz.php.
Estheticon
Our website incorporates seals or widgets from Estheticon, s.r.o., Dr. Milady Horákové 513/23a, Liberec IV-Perštýn, 46, Czech Republic. Widgets are small fields on doctors' websites displaying a variety of information about the doctor, such as the average rating on the Estheticon portal. Since this information changes over time and the current state needs to be updated, the widget is technically solved by an independent page (iframe technology), where the current information is directly loaded from the Estheticon website. This page does not work with cookies or similar technologies. Estheticon only processes the IP address of the visitor to the doctor's website, which is stored in the server log, to detect possible spam activities and to prevent these activities from accessing these IP addresses. For this reason, access for these IP addresses is blocked for a period of 1 year based on legitimate interest.
We pursue the purpose and legitimate interest of displaying current and correct content on our homepage by integrating this. The legal basis is Art. 6 Para. 1 f) GDPR. We do not store the mentioned data due to this integration. Estheticon processes the data you provide there on its own responsibility. Further information on data processing by Estheticon can be found in the privacy policy of the site https://www.estheticon.de/privacy-policy-visitor.
Google Web Fonts
This site uses so-called web fonts provided by Google for the uniform display of fonts. When you call up a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly.
For this purpose, the browser you are using must connect to Google's servers. As a result, Google becomes aware that our website has been accessed via your IP address. The use of Google Web Fonts is in the interest of a uniform and attractive presentation of our online offers. This constitutes a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR.
If your browser does not support web fonts, a standard font from your computer will be used.
Further information about Google Web Fonts can be found at https://developers.google.com/fonts/faq and in Google's privacy policy: https://www.google.com/policies/privacy/.
Google Maps
This site uses the Google Maps map service via an API. The provider is Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
To use the features of Google Maps, it is necessary to save your IP address. This information is generally transmitted to and stored on a server by Google in the USA. The provider of this site has no influence on this data transfer.
The use of Google Maps is in the interest of making our online offerings appealing and to facilitate the location of places specified by us on the website. This constitutes a legitimate interest within the meaning of Art. 6 Para. 1 lit. f GDPR.
More information on the handling of user data can be found in Google's privacy policy: https://www.google.de/intl/de/policies/privacy/.
You can prevent the collection by Google Analytics by clicking on the following link. An opt-out cookie will be set to prevent future collection of your data when visiting this website: Disable Google Analytics