Legal information
Privacy policy
Draft. This text describes the actual technical state of this website. To be confirmed and legally reviewed before publication. The German version is legally authoritative.
1. Controller
The controller under the General Data Protection Regulation (GDPR) is:
Hausarztpraxis am Quirlsberg
Ferrenbergstraße 24
51465 Bergisch Gladbach
Phone: 02202 2711800
Email: info@hausarztpraxis-quirlsberg.de
We have not appointed a data protection officer, as the conditions of Art. 37 GDPR and § 38 BDSG are not met.
The contact person for data protection questions is Linn Krämer, reachable via the contact details above.
2. What this website does not do
This website loads no third-party content when you open it. There are no external fonts, no embedded map, no analytics or tracking tools, no advertising networks, no social media plugins and no embedded booking widgets.
This website sets no cookies and stores nothing in your browser's local storage. That is why there is no cookie banner here: there is nothing to consent to.
No health data is collected through this website. There is no contact form and no symptom form.
3. Server log files
This website is hosted by Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA. Netlify provides the technical infrastructure on which this website runs.
Each time the website is accessed, the hosting service may process technical connection data — in particular the IP address, the date and time of access, browser and device information, and the resources requested — and record it in server and access logs. The processing serves above all to keep the website secure, stable and technically sound, and to detect and prevent misuse and security incidents.
Legal basis for the processing is Art. 6 (1) (f) GDPR. Our legitimate interest lies in providing and protecting our website securely and reliably.
Netlify processes personal data in accordance with the data protection provisions applicable to Netlify and, insofar as it processes personal data on our behalf, as our processor. The retention period follows the respective purpose of processing and Netlify's technical and contractual specifications. Further information on Netlify's data processing can be found in Netlify's privacy statement.
Transfer to a third country: the processing may involve servers in the United States. Netlify, Inc. is certified under the EU-US Data Privacy Framework, so an adequacy decision of the European Commission under Art. 45 GDPR applies to transfers to the United States.
4. Contact by phone or email
If you call or write to us, we process what you tell us in order to deal with your request. The legal basis is Art. 6(1)(b) GDPR where a treatment relationship exists or is being initiated, otherwise Art. 6(1)(f) GDPR.
Please do not send health data by email. Unencrypted email is not a secure channel. For anything concerning symptoms, diagnoses or medication, please call us.
Your treatment records in the practice are covered by medical confidentiality and by a separate, more detailed patient information notice which you receive at the practice. This policy covers the website only.
5. Appointment booking via Doctolib
This website contains a link to our profile with Doctolib GmbH. It is not an embedded widget: as long as you do not click the link, no data is transmitted to Doctolib and Doctolib learns nothing about your visit.
Only when you click do you leave this website. From that point Doctolib's own privacy policy applies, over which we have no influence.
The link carries campaign parameters (utm parameters) which let Doctolib report back to the practice how many bookings came through the website. These parameters contain no personal data.
6. Map link
For directions we link to Google Maps. That is a link, not an embed: the map loads only when you deliberately open it, and only then does your browser transmit data to Google.
7. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21 GDPR).
Please use the contact details above.
You may also complain to a supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf.
8. Status
This policy applies to the technical state of this website at the time of publication and will be updated if the technology used changes.