Skip to main content
deinrezept Logo

Privacy Policy

The protection of your personal data is important to us. In this privacy policy, we inform you about the processing of your data when using deinrezept.de.

1. Data Controller

MEDICARE HEALTH GROUP LTD

First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom

[email protected]

Represented by the Director: Houssem Sefi

Company Number: 17089430 (England and Wales)

Data Protection Officer: Currently not appointed; legal requirements under Art. 37 GDPR are being reviewed.

2. What data do we process?
  • Account and contact data (e.g. email, phone number if applicable) for verification (OTP), communication and status updates.
  • Order/contract data (treatment, shopping cart, billing data, delivery address).
  • Health data (questionnaire responses) exclusively for medical review/processing and only to the extent necessary.
  • Technical data (log files, security events) for stability, abuse prevention and error analysis.
3. Purposes & Legal Bases
  • Contract fulfillment (Art. 6(1)(b) GDPR) — Processing of orders, prescription requests, communication.
  • Security/abuse prevention (Art. 6(1)(f) GDPR) — Protection against fraud, rate limiting, logging.
  • Fulfillment of legal obligations (Art. 6(1)(c) GDPR) — Tax retention, pharmaceutical documentation.
  • Health data (Art. 9(2)(h) GDPR) — Processing for healthcare purposes based on the treatment contract. Questionnaire responses are processed exclusively for the medical suitability assessment and stored in pseudonymized form.
  • Consent (Art. 9(2)(a), Art. 6(1)(a) GDPR) — Where explicit consent is obtained (e.g. for optional cookies or additional services).
  • Reach measurement (Art. 6(1)(f) GDPR) — Anonymous, aggregated counting of concurrent visitors to assess site load. NO cookies are set and no device or user profiles are created; a non-reversible short-lived identifier is derived from IP address and browser signature using a secret random value that rotates daily and expires after 60 seconds. Recognition beyond the day or attribution to a person is impossible. The IP address is not stored for this purpose.
Note:Health data is subject to medical confidentiality and is transmitted in encrypted form (TLS 1.3) and stored in EU infrastructure.
4. Recipients / Data Processors
  • Hetzner Online GmbH (Hosting, Industriestr. 25, 91710 Gunzenhausen, Germany) — Server operations and data storage within the EU. DPA concluded.
  • Microsoft Ireland Operations Ltd. (Microsoft 365, sending of login codes and notifications, One Microsoft Place, Dublin 18, Ireland) — processor, servers located in the EU.
  • Stripe Inc. (Payment processing, 354 Oyster Point Blvd, South San Francisco, CA, USA) — Credit card, PayPal, Klarna and Amazon Pay payments. Third-country transfer to USA based on EU Standard Contractual Clauses (SCCs). Details see Section 7.
  • Cloudflare Inc. / Turnstile (Bot protection) — Processing of technical data to distinguish humans from bots. No tracking, GDPR-compliant.
  • Cooperating physicians / partner pharmacy — Medical review and prescription issuance or dispensing of medications. Processing based on the treatment contract.
  • Daily.co (provider: Daily.co, Inc.) — Technical service provider for conducting video consultations. Only the audio and video data arising during the consultation are processed for the purpose of real-time transmission. Media routing takes place within the EU region (Frankfurt). The consultation is NOT recorded. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Daily.co.
  • Google Ireland Ltd. (Google Analytics 4, audience measurement, Gordon House, Barrow Street, Dublin 4, Ireland) — only after your consent to the "Analytics" category. Pseudonymous usage data is transmitted; the page address is stripped of treatment-related details before sending. Transfer to the United States cannot be ruled out (EU-US Data Privacy Framework adequacy decision).
  • Meta Platforms Ireland Ltd. (Meta Pixel, advertising measurement, Merrion Road, Dublin 4, Ireland) — only after your consent to the "Marketing" category. Without that consent the pixel is not loaded and no data leaves your browser.
  • Google Ireland Ltd. (Google Wallet, Gordon House, Barrow Street, Dublin 4, Ireland) — Only if you save your patient card to Google Wallet: the card data (patient number, name, treating practice) is transmitted to Google in a signed token. The Apple Wallet pass, by contrast, is generated and signed entirely on our servers and delivered straight to your device — no data is transmitted to Apple.
5. Storage Period

We store personal data only as long as necessary for the respective purpose or as required by statutory retention periods:

  • Account data: Until account deletion + 30-day grace period.
  • Orders and billing data: 10 years (Section 257 HGB, Section 147 AO).
  • Health data (questionnaires): 10 years after end of treatment (Section 10(3) MBO-A).
  • Server log files: 90 days.
  • Cookies: Between 1 hour (session) and 365 days (consent preference), depending on the cookie.
6. Your Rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), among others. You may revoke any given consent at any time. You also have the right to lodge a complaint with a supervisory authority.
7. Third-Country Transfers
Stripe Inc. as payment service provider processes data in the USA. The transfer is based on EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. Stripe is also certified under the EU-US Data Privacy Framework. All other data processors process data exclusively within the EU/EEA.
8. Automated Decision-Making
The evaluation of your health questionnaire serves to structure the information for medical review. No fully automated decision-making within the meaning of Art. 22 GDPR takes place — every prescription decision is made individually by a licensed physician. You have the right to human review at any time.
9. SSL/TLS & Security Measures
This website uses SSL/TLS encryption (indicated by the lock icon in your browser). All data is transmitted in encrypted form. In addition, we employ extensive technical and organizational measures: Content Security Policy (CSP), rate limiting, CSRF protection, encrypted data storage, and regular security audits.
10. Cookies

Technically necessary cookies are always set. Cookies and comparable storage technologies for analytics and marketing are set only after your consent; you can withdraw it at any time via "Cookie settings" in the footer. Overview:

CookiePurposeDurationType
dr_sessionSession management (login)24 hoursEssential
dr_csrfCSRF protectionSessionEssential
dr_cookie_consentStorage of your cookie preferences365 daysEssential
dr_localeLanguage setting365 daysEssential
dr_themeColor scheme preference365 daysEssential
dr_countryCountry selection365 daysEssential
_ga, _ga_*Google Analytics 4 — distinguishing visitors, audience measurementup to 24 monthsAnalytics (consent only)
_fbpMeta Pixel — attribution of ad contacts90 daysMarketing (consent only)
11. Usage analysis of the ordering process
To improve our ordering process, we record which steps of the ordering process are opened, completed or abandoned. This measurement works without cookies and without storing your IP address, under a random session identifier that cannot be traced back to you. Only if you have consented to marketing in our cookie banner and are logged in do we additionally link this measurement data to your customer account and your order in order to understand and improve your use of our service (Art. 6(1)(a), Art. 9(2)(a) GDPR). You can withdraw this consent at any time via the cookie settings; we delete already collected linked data upon request.
12. Supply reminders and newsletter
If you explicitly turn it on in your account or when completing an order, we calculate from your order (pack size, use per product information, the interval between your previous orders or your own input) how long your supply is expected to last and remind you by email before it runs out (at most two emails per order). The emails only name your treatment area, never a product. The legal basis is your consent (Art. 6(1)(a), Art. 9(2)(a) GDPR); you can withdraw it at any time in the patient portal under “My supply” or via the link in every reminder. You receive the general newsletter (magazine topics, service news) only after signing up and confirming your email address (double opt-in); you can unsubscribe via the link in every issue. We log the time and source of your consent and, per email, only the type and delivery result, not the content.