GDPR
Privacy Policy in accordance with the GDPR for Docs4D Healthcare, Guardian App, and Website
1. Data Controller
Docs4D GmbH
Am Trimmelter Hof 66
54296 Trèves
Allemagne
Email: legal@docs4d.com
Represented by: Managing Director Dr. Alexandros Paraforos
2. Purpose and Legal Basis of Data Processing
We process personal data solely for legally permitted purposes:
– The use of the Docs4D Healthcare Platform is based on Article 6(1)(b) GDPR, which allows for the processing of data necessary for the performance of a contract. This applies to healthcare professionals (HCPs) and medical institutions using our platform.
– The use of the Guardian App by patients is based on Article 6(1)(a) GDPR, meaning that data collection for symptom monitoring is only performed with the explicit consent of the user.
– The operation of our website, including features such as contact forms and cookies, is based on Article 6(1)(f) GDPR. Here, processing is necessary to pursue our legitimate interests in ensuring effective communication with users and optimizing our services.
– Special categories of personal data, such as health data, are processed exclusively in accordance with Article 9(2)(h) GDPR, and only for the purpose of providing medical care.
3. Recipients of the Data
Data is not transferred to third parties except in the following cases:
– It is necessary for contract performance (e.g., hosting providers, data processors)
– You have given explicit consent
– There is a legal obligation (e.g., supervisory authorities)
All service providers are contractually bound to comply with data protection requirements under Art. 28 GDPR.
4. Data Retention Period
Data is stored only as long as necessary for the respective purpose or as required by legal retention periods:
– Health data: up to 10 years according to § 630f BGB
– Communication data: 6 months after the last contact
– Server logs: 14 days
5. Rights of Data Subjects
As a user, you have the following rights under the GDPR:
– Access to your stored data (Art. 15 GDPR)
– Rectification of inaccurate data (Art. 16 GDPR)
– Erasure (“right to be forgotten”) (Art. 17 GDPR)
– Restriction of processing (Art. 18 GDPR)
– Data portability (Art. 20 GDPR)
– Objection to processing (Art. 21 GDPR)
– Withdrawal of consent (Art. 7(3) GDPR)
To exercise your rights, please contact us at: legal@docs4d.com
6. Data Transfers to Third Countries
Transfers of data outside the EU/EEA only take place if:
– The server is located in a recognized third country with an adequacy decision
– EU Standard Contractual Clauses (SCC) have been concluded with the service provider
7. Data Security
Docs4D implements up-to-date technical and organizational security measures (e.g., TLS encryption, role-based access control, ISO 27001-compliant infrastructure) to protect personal data from manipulation, loss, or unauthorized access.
8. Supervisory Authority and Right to Lodge a Complaint
If you believe the processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with a supervisory authority:
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
https://www.datenschutz-berlin.de/
9. Updates to This Privacy Policy
This privacy policy is effective as of May 2025.
We reserve the right to adapt it to technical developments or legal requirements at any time.
Get in Touch with Us
If you have any questions or need further assistance, we’re here to help! Simply reach out to us through the contact form on our website, and our team will get back to you as soon as possible.