Privacy Policy
The protection of your personal data is important to us. In this privacy policy, we inform you about the processing of your data when using deinrezept.de.
MEDICARE HEALTH GROUP LTD
First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom
Represented by the Director: Houssem Sefi
Company Number: 17089430 (England and Wales)
Data Protection Officer: Currently not appointed; legal requirements under Art. 37 GDPR are being reviewed.
- •Account and contact data (e.g. email, phone number if applicable) for verification (OTP), communication and status updates.
- •Order/contract data (treatment, shopping cart, billing data, delivery address).
- •Health data (questionnaire responses) exclusively for medical review/processing and only to the extent necessary.
- •Technical data (log files, security events) for stability, abuse prevention and error analysis.
- •Contract fulfillment (Art. 6(1)(b) GDPR) — Processing of orders, prescription requests, communication.
- •Security/abuse prevention (Art. 6(1)(f) GDPR) — Protection against fraud, rate limiting, logging.
- •Fulfillment of legal obligations (Art. 6(1)(c) GDPR) — Tax retention, pharmaceutical documentation.
- •Health data (Art. 9(2)(h) GDPR) — Processing for healthcare purposes based on the treatment contract. Questionnaire responses are processed exclusively for the medical suitability assessment and stored in pseudonymized form.
- •Consent (Art. 9(2)(a), Art. 6(1)(a) GDPR) — Where explicit consent is obtained (e.g. for optional cookies or additional services).
- •Reach measurement (Art. 6(1)(f) GDPR) — Anonymous, aggregated counting of concurrent visitors to assess site load. NO cookies are set and no device or user profiles are created; a non-reversible short-lived identifier is derived from IP address and browser signature using a secret random value that rotates daily and expires after 60 seconds. Recognition beyond the day or attribution to a person is impossible. The IP address is not stored for this purpose.
- •Hetzner Online GmbH (Hosting, Industriestr. 25, 91710 Gunzenhausen, Germany) — Server operations and data storage within the EU. DPA concluded.
- •Microsoft Ireland Operations Ltd. (Microsoft 365, sending of login codes and notifications, One Microsoft Place, Dublin 18, Ireland) — processor, servers located in the EU.
- •Stripe Inc. (Payment processing, 354 Oyster Point Blvd, South San Francisco, CA, USA) — Credit card, PayPal, Klarna and Amazon Pay payments. Third-country transfer to USA based on EU Standard Contractual Clauses (SCCs). Details see Section 7.
- •Cloudflare Inc. / Turnstile (Bot protection) — Processing of technical data to distinguish humans from bots. No tracking, GDPR-compliant.
- •Cooperating physicians / partner pharmacy — Medical review and prescription issuance or dispensing of medications. Processing based on the treatment contract.
- •Daily.co (provider: Daily.co, Inc.) — Technical service provider for conducting video consultations. Only the audio and video data arising during the consultation are processed for the purpose of real-time transmission. Media routing takes place within the EU region (Frankfurt). The consultation is NOT recorded. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Daily.co.
- •Google Ireland Ltd. (Google Analytics 4, audience measurement, Gordon House, Barrow Street, Dublin 4, Ireland) — only after your consent to the "Analytics" category. Pseudonymous usage data is transmitted; the page address is stripped of treatment-related details before sending. Transfer to the United States cannot be ruled out (EU-US Data Privacy Framework adequacy decision).
- •Meta Platforms Ireland Ltd. (Meta Pixel, advertising measurement, Merrion Road, Dublin 4, Ireland) — only after your consent to the "Marketing" category. Without that consent the pixel is not loaded and no data leaves your browser.
- •Google Ireland Ltd. (Google Wallet, Gordon House, Barrow Street, Dublin 4, Ireland) — Only if you save your patient card to Google Wallet: the card data (patient number, name, treating practice) is transmitted to Google in a signed token. The Apple Wallet pass, by contrast, is generated and signed entirely on our servers and delivered straight to your device — no data is transmitted to Apple.
We store personal data only as long as necessary for the respective purpose or as required by statutory retention periods:
- •Account data: Until account deletion + 30-day grace period.
- •Orders and billing data: 10 years (Section 257 HGB, Section 147 AO).
- •Health data (questionnaires): 10 years after end of treatment (Section 10(3) MBO-A).
- •Server log files: 90 days.
- •Cookies: Between 1 hour (session) and 365 days (consent preference), depending on the cookie.
Technically necessary cookies are always set. Cookies and comparable storage technologies for analytics and marketing are set only after your consent; you can withdraw it at any time via "Cookie settings" in the footer. Overview:
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| dr_session | Session management (login) | 24 hours | Essential |
| dr_csrf | CSRF protection | Session | Essential |
| dr_cookie_consent | Storage of your cookie preferences | 365 days | Essential |
| dr_locale | Language setting | 365 days | Essential |
| dr_theme | Color scheme preference | 365 days | Essential |
| dr_country | Country selection | 365 days | Essential |
| _ga, _ga_* | Google Analytics 4 — distinguishing visitors, audience measurement | up to 24 months | Analytics (consent only) |
| _fbp | Meta Pixel — attribution of ad contacts | 90 days | Marketing (consent only) |
