DSGVO-Information

Privacy policy.

Which data we process and why — transparently, in plain language.

Responsible party

Dr. Marion Hansberg-Otte
Rosgartenstraße 27
78462 Konstanz
Telefon: +49 7531 17666 · Telefax: +49 7531 2618
KIM: DrHansberg-Otte@tomedo.kim.telematik
praxis@frauenaerztinnen-konstanz.de

Your rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), notification (Art. 19), data portability (Art. 20), objection (Art. 21), withdrawal of consent (Art. 7(3)) and the right to lodge a complaint (Art. 77) — any time by email.

Practice data

Patientenakten sind nicht accessible via this website — only in the secured practice software.

Consent

External services (map, appointment booking, newsletter) only load after your consent via the cookie banner. No analytics without consent.

1. Hosting & server log files

This website is hosted by ALL-INKL.COM — Neue Medien Münnich (Hauptstraße 68, 02742 Friedrichroda). When you visit, Server-Logfiles are automatically recorded (IP address, time of access, browser type, referrer) and stored briefly to ensure operation. A data processing agreement is in place with the provider. Legal basis: Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an sicherem Betrieb).

2. Contact form (Web3Forms)

Information submitted via the contact form (name, email, where applicable phone, message) is processed to answer your enquiry. Submission is via Web3Forms as processor. Legal basis: Art. 6 Abs. 1 lit. b DSGVO (contract initiation) or lit. a (consent).

3. Online appointment booking (arzt-direkt · Zollsoft)

Appointments are booked via arzt-direkt der Zollsoft GmbH (Engelplatz 8, 07743 Jena). The booking widget or booking link only loads after your consent. From the moment it is opened, the privacy policy of Zollsoft/arzt-direkt applies. Legal basis: Art. 6 Abs. 1 lit. a DSGVO (consent) or lit. b.

4. Online reception (Docmedico)

For the online reception we embed a service from Docmedico . The associated script only loads after your consent via the cookie banner. Connection data may be transmitted to the provider in the process. Legal basis: Art. 6 Abs. 1 lit. a DSGVO (consent).

5. Online forms (Zollsoft)

For fillable online forms (e.g. history, concern) we use services from Zollsoft GmbH (Engelplatz 8, 07743 Jena). The information transmitted serves solely to prepare your concern. Legal basis: Art. 6 Abs. 1 lit. a DSGVO or lit. b.

6. Newsletter

For sending our newsletter and the sign-up form we use Brevo (Brevo GmbH, formerly Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin). On sign-up we process the data you provide (first name, surname, email) as well as the time of sign-up and confirmation (proof of consent). Sign-up uses double opt-in: after registering you receive an email with a confirmation link; only after you click are you added to the list. The sign-up is automated via n8n (n8n GmbH, Berlin; hosting in the EU). Data processing agreements (Art. 28 GDPR) exist with both providers; appropriate safeguards apply to any third-country transfers. You can withdraw your consent at any time via the unsubscribe link in every email. Legal basis: Art. 6 Abs. 1 lit. a DSGVO (consent).

7. Map embed (OpenStreetMap)

On the contact page we show a OpenStreetMap-Karte (OpenStreetMap Foundation, UK). It only loads after your consent; your IP address is transmitted to OpenStreetMap in the process. Legal basis: Art. 6 Abs. 1 lit. a DSGVO (consent).

8. Fonts (Adobe Fonts)

The DM Sans font is served locally from our own server — no data is transmitted to third parties. We additionally use Avenir Next via Adobe Fonts (Adobe Systems Software Ireland Ltd.); your IP address may be transmitted to Adobe when loading. Legal basis: Art. 6 Abs. 1 lit. f DSGVO.

8a. Job applications

If you apply via our career forms, we process your details and CV exclusively to conduct the application procedure (Section 26 BDSG, Art. 6(1)(b) GDPR). Transmission runs through our own automation infrastructure (n8n, EU hosting); the confirmation email is sent via Brevo (Sendinblue GmbH, Germany). Your documents are never used for marketing and are deleted no later than six months after the procedure ends, unless you consent to longer retention.

9. YouTube video (Google)

On individual pages we embed videos via YouTube in privacy-enhanced mode (youtube-nocookie.com) from Google Ireland Ltd. The video loads only after your consent; before that only a thumbnail is shown. Loading transmits connection data (incl. your IP address) to Google; this may involve a transfer to the USA (Google has joined the EU-US Data Privacy Framework). Legal basis: Art. 6(1)(a) GDPR (consent).

9a. Phone assistant "Clara" (VITAS)

Calls outside opening hours, and some calls during opening hours, are answered by our digital phone assistant "Clara". The conversation is processed automatically and converted to text in order to handle your request; you are informed of this at the start of the call. The data processed are the details you provide (e.g. name, date of birth, callback number, request).

The provider is VITAS GmbH (Germany), with whom a data processing agreement under Art. 28 GDPR is in place. Processing takes place on servers in the EU. VITAS is certified to ISO 27001 and in March 2026 obtained the C5 attestation under the audit catalogue of the German Federal Office for Information Security (BSI) — the strictest German standard for cloud security in healthcare, confirmed by an independent auditor (details at VITAS). The legal basis is Art. 6(1)(b) GDPR (appointment arrangement and request handling) or Art. 9(2)(h) GDPR insofar as you provide health-related information. If you prefer not to speak with Clara, you can be transferred to the team at any time or use the online reception.

9b. Feedback form (Realitycheck)

On our Realitycheck page you can give us feedback — anonymously if you wish. Only the ratings and texts you enter are transmitted, plus optionally your first name and email address. Transmission runs via our automation platform n8n (n8n GmbH, Berlin; EU hosting); if you provide an email address, you receive a confirmation via our email provider Brevo (Sendinblue GmbH, Berlin). Data processing agreements are in place with both providers.

The legal basis is your consent (Art. 6(1)(a) GDPR), given by submitting the form and revocable at any time with future effect. Please do not enter health data in the feedback form — the protected online reception is available for that. Anonymous feedback can neither be attributed nor deleted afterwards, as no personal reference exists.

9c. Google Analytics 4 (only with consent)

If you consent in the cookie banner, we use Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to understand anonymously how our website is used. Without your consent Google Analytics is not loaded — we use Google Consent Mode v2 with a default of "denied".

Pseudonymised usage data are processed (truncated IP address, pages visited, device type, approximate region). Transfer to Google LLC in the USA is possible; Google is certified under the EU-US Data Privacy Framework. The legal basis is your consent (Art. 6(1)(a) GDPR, Sec. 25(1) TTDSG). You can revoke it at any time via the "Cookie settings" link in the footer; Analytics data are retained for 14 months.

9d. Practice management system tomedo (Zollsoft)

To manage your treatment data we use the practice management system tomedo by zollsoft GmbH (Jena, Germany). It processes your master, appointment, billing and treatment data — including health data within the meaning of Art. 9 GDPR. The legal basis is Art. 6(1)(b) and (c) in conjunction with Art. 9(2)(h) GDPR (treatment contract, statutory documentation duties under Sec. 630f BGB and professional law) together with our data processing agreement under Art. 28 GDPR with zollsoft. Retention follows the statutory periods (generally 10 years, longer in certain cases). For online booking and online forms from the same provider see sections 3 and 5.

9e. AI-assisted documentation in the consulting room (tomedo.Intelligence)

To spend more time on the conversation than on the keyboard, we use the AI functions of our practice management system — tomedo.Intelligence by zollsoft GmbH (see section 9d). These include medical speech recognition and the consultation assistant: on request, the conversation in the consulting room is captured via a microphone, converted into text and prepared as a structured draft entry for your file. The doctor reviews and is responsible for every entry — the AI decides nothing, makes no diagnosis and replaces no medical judgement.

How the recording is handled: speech processing is encrypted; according to the provider, the transmitted voice data are not stored. The language model used is hosted within the EU, and a zero-data-retention agreement ensures the data are neither stored nor further used after processing — in particular not for training AI models. Only the text the doctor adopts into the treatment documentation is stored permanently. The basis is our Art. 28 GDPR data processing agreement with zollsoft.

Your decision: we use this solely with your prior consent (Art. 6(1)(a) in conjunction with Art. 9(2)(a) GDPR), which we obtain and document before any recording. You may object at any time or withdraw consent with future effect — without any disadvantage for your treatment. If you say no, we document by hand as before. That is not a special request but your right.

You will find the consent and information forms — including the treatment contract and the data protection consent — at any time under Forms (in German). You can fill them in from home in advance or on the tablet on site.

9f. EU hosting & data security

We host all data in Europe and ensure compliant data residency. We avoid US cloud services without adequate EU data guarantees — which is why we use OpenStreetMap instead of Google Maps, embed videos only in enhanced privacy mode and do without external font services. Practice management and phone assistance run on servers in Germany; the AI speech processing (section 9e) runs on EU servers with zero data retention. Where a service may exceptionally involve a transfer to the USA (see section 9c), this occurs solely after your consent and on the basis of recognised safeguards.

This website is transmitted encrypted (TLS). For medical concerns please always use the protected online reception rather than unencrypted email.

10. Storage & deletion

We store personal data only as long as necessary for the respective purpose or as required by statutory retention periods (e.g. commercial and tax law). Data from enquiries is deleted after final processing; consent-based data until you withdraw consent. Patient data is subject to medical retention obligations and is kept solely in the secured practice software, not via this website.

11. Cookies & consent

Technically necessary storage (e.g. your cookie choice) takes place locally in your browser. External services (appointment booking, online reception, newsletter, map, where applicable statistics) are only after your consent loaded via the cookie banner. You can change or withdraw your choice at any time via the icon at the bottom left. Legal basis: Art. 6 Abs. 1 lit. a DSGVO or § 25 TDDDG.

12. Right to complain

You have the right to lodge a complaint with the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg. Address: baden-wuerttemberg.datenschutz.de.

Stand: 07/2026 · Bei Fragen: praxis@frauenaerztinnen-konstanz.de · Imprint

Anrufen Chatten