Skip to content

Privacy policy

This website processes personal data solely to the extent described here.

Controller

The controller for the processing of personal data on this website is:

Coordinated Care GmbH
Wodanstraße 75
51107 Köln
Represented by: Prof. Dr. med. Christian Schmidt MPH
info@coordinated-care.de

No cookies, no tracking

The website sets no cookies and embeds no analytics or advertising services.

Fonts are served by us

The Inter typeface is served from this server. Opening the page establishes no connection to Google Fonts or any other third party.

Server log files

When you open this website, our hosting provider processes the connection data required to serve it: IP address, time of access, the address requested and the identifier of the browser used. A page cannot be delivered without them. The legal basis is our legitimate interest in secure and reliable operation (Art. 6(1)(f) GDPR). We do not combine these logs with other data and do not evaluate them to recognise individual people. At the hosting provider they are deleted automatically according to its retention setting.

Handover request

We process the details given in the request form solely in order to handle your request. The form deliberately collects no patient or health data, only categories of care and a way to reach you.

Protecting the form against misuse

To keep automated submissions out, we limit how many requests a single sender may make. To do so the sender's IP address is held in the server's memory for at most one hour and then discarded. It is not attached to the request itself. The form also contains a field that is invisible to people, and the time taken to fill the form in is measured. Submissions recognised as automated are discarded. The legal basis is our legitimate interest in keeping the form working and free of abuse (Art. 6(1)(f) GDPR).

Legal basis and retention

The legal basis is Art. 6(1)(b) GDPR where the request concerns the initiation of a care handover, and otherwise our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). The request reaches us by email. Only a transient copy is written on the server, and it expires together with the runtime environment. We delete the data six months after the request has been dealt with, unless statutory retention periods require otherwise.

Consent and withdrawal

Before the request form is sent, it asks for your express consent to the processing of the details you entered (Art. 6(1)(a) GDPR). You may withdraw that consent at any time with effect for the future, informally to the postal or email address given above. The lawfulness of processing carried out before the withdrawal is not affected.

Providing the data, and automated decisions

Supplying the fields marked as mandatory is required neither by law nor by contract. It is, however, necessary for us to handle your request and reply to you. Without it we cannot get back to you. There is no automated decision-making that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR).

Operation of the site and recipients

The website is operated on our behalf by AI-Revolution WLS UG (haftungsbeschränkt) as our processor under Art. 28 GDPR. Vercel Inc. provides the technical hosting and Brevo (Sendinblue SAS, France) sends the emails generated by the form. Both act as sub-processors and the servers are located within the European Union. The request then arrives in the mailbox of Coordinated Care GmbH, which is operated by ALL-INKL.COM – Neue Medien Münnich.

Transfers to the United States

Vercel Inc. is a company based in the United States. Even though the servers are located in the European Union, access from the US, for maintenance purposes for example, cannot be ruled out. A transfer to a third country therefore takes place. It is covered by the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), which form part of Vercel's data processing agreement. Its wording can be consulted at vercel.com/legal/dpa. Vercel Inc. is also certified under the EU-U.S. Data Privacy Framework, for which the European Commission adopted an adequacy decision on 10 July 2023.

Your rights

Under the General Data Protection Regulation you have the following rights in respect of your personal data:

  • Access to the data held about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)

Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority at any time. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4
40213 Düsseldorf
www.ldi.nrw.de

You may equally approach the supervisory authority where you live or work.

Request a handover