Privacy Policy Medigital GmbH
Last updated: 19 May 2026
Medigital GmbH (Medigital for short) takes the protection of your personal data very seriously. The following information is intended to provide you with an overview of how Medigital processes your personal data.
An overview of the individual chapters for better orientation can be found here:
Preamble – Here you will find a brief overview of the relevant data protection topics.
Contact – How can you contact us quickly and easily?
Data processing and storage – Which of your data is stored and processed, how, for what purpose, where, by whom and for how long?
Legal basis – On what legal basis do we process your data?
Data transfer – Under what conditions do we transfer your data to third parties?
Data security – What do we do to protect your data as much as possible?
Your rights – Here you will find an overview of all your rights as a data subject.
1. Preamble
The data protection term “personal data” refers to all information relating to an identified or identifiable individual.
As a company, we process personal data that we receive in the course of our business relationships from, amongst others, our prospective clients (including visitors to our websites), applicants, employees, patients, customers, suppliers or service providers. We also process personal data that we have lawfully received from other companies within the MEDICE Health Family or from other third parties (e.g. Schufa, public authorities, cooperation partners, contractors) (e.g. for the execution of orders, the fulfilment of contracts, due to a legal obligation or on the basis of consent given by you). Furthermore, we process personal data that we have lawfully obtained from publicly accessible sources (e.g. public registers, media, the internet) and are permitted to process.
If the processing of personal data is necessary and there is no legal basis for such processing, we generally obtain your consent.
As the controller, we have implemented numerous technical and organisational measures to ensure the most complete protection of the personal data processed.
2. Contact
You can contact us directly via the service hotline on +49 2371 937-0 or the service email address info-medigital[at]medice.de. Our service hours are Monday to Friday (excluding public holidays) from 7.15 am to 5.30 pm.
Your enquiry will be processed within two working days and no later than two weeks after receipt by the relevant staff at our parent company, MEDICE Arzneimittel Pütter GmbH & Co. KG.
The controller within the meaning of Article 4(7) of the EU General Data Protection Regulation (hereinafter “GDPR”) and other data protection regulations is:
Medigital GmbH
Medice Allee 1
58638 Iserlohn
Telephone: +49 (0)2371 937 0
Email: info-medigital[at]medice.de
Authorised representatives:
Dr Felix Lambrecht
Internal Data Protection Officer:
If you have any questions about our data protection measures, the processing of your data or the protection of your rights as a data subject, you can contact our data protection team as follows:
Medigital GmbH
Data Protection
Medice Allee 1
58638 Iserlohn
Telephone: +49 (0)2371 937 0
Email: privacy-medigital[at]medice.de
If you have any confidential concerns regarding data protection, you can contact our data protection officer directly at dsb[at]medice.de.
3. Data processing and storage
The following personal data may be collected from you when you contact Medigital GmbH and processed when you use our digital health solutions and products:
3.1 Contacting us/contact form
When you contact us (e.g. by telephone, fax, contact form or email), your personal data (such as your first name and surname, email address or telephone/fax number) will be collected and processed.
The data collected when using a contact form is specified in the relevant contact form. All data fields marked as mandatory are required to process your enquiry. Failure to provide this information means we cannot process your enquiry. The provision of additional data is voluntary.
The data collected is stored and processed exclusively for the purpose stated in the contact form, i.e. to establish contact, process your enquiry and for the associated technical administration. When data is collected via the contact form, your data is transmitted in encrypted form.
Customer support for Medigital is provided by MEDICE Arzneimittel Pütter GmbH & Co. KG, as the parent company of Medigital GmbH. To this end, there is a corresponding contractual agreement on joint data processing in accordance with Article 26 of the GDPR between MEDICE Arzneimittel Pütter GmbH & Co. KG and Medigital GmbH.
The legal basis for the processing of the data is our legitimate interest in responding to your enquiry in accordance with Article 6(1)(f) of the GDPR. If your contact is aimed at concluding a contract, the additional legal basis for the processing is Article 6(1)(b) of the GDPR.
Once your enquiry has been fully processed, all data collected in the course of your contact with us will be deleted. This is the case where it is clear from the circumstances that the matter in question has been conclusively resolved and there are no statutory retention obligations preventing deletion.
3.2 Application
When you use our application portal, we and our parent company, MEDICE Arzneimittel Pütter GmbH & Co. KG, which is responsible for the application process, collect and process personal data such as your name, address, telephone number and email address. This data is required to contact you. Furthermore, you have the option of providing us and our parent company with electronically stored documents such as your CV, references, photographs or your cover letter.
We are looking for the best candidates, regardless of age, gender, disability, origin, religion, beliefs or sexual identity. We therefore do not require any information from you that cannot be used in accordance with the General Equal Treatment Act. Please do not forward any confidential internal information or trade secrets of your former or current employer to us.
Your personal application data will be collected, processed and stored exclusively for the purpose of processing your application and the associated pre-contractual measures to initiate an employment relationship within the meaning of Article 6(1)(b) of the GDPR. Access to the data submitted to us as part of your application is restricted exclusively to designated employees of Medigital GmbH and MEDICE Arzneimittel Pütter GmbH & Co. KG who are involved in the application process. These employees have been trained in accordance with the requirements of the GDPR and are bound by data confidentiality.
There are no plans to disclose your data to third parties outside MEDICE Health Family Holding GmbH or to countries outside Germany.
If your application is successful, the data you have provided may be used for administrative purposes in connection with your employment.
If we are unable to offer you a position, we will retain the data you have provided for up to six months after the application process has been concluded, for the purpose of answering any questions relating to your application and the decision not to offer you a position. This does not apply if legal provisions prevent deletion, if further storage is necessary for the purposes of providing evidence, or if you have expressly consented to longer storage.
If we are unable to offer you a position currently available but, based on your profile, believe that your application may be of interest for future vacancies, we will, with your separate consent, store your application data for a total of twelve months. You may withdraw this consent at any time, with effect for the future, without this resulting in any disadvantage to you.
3.3 Employment relationship
Within the framework of an employment relationship with Medigital GmbH, we process personal data (such as personal and contact details, payroll data or qualification data) of employees, interns, working students, apprentices, trainers/speakers, etc. for the purpose of fulfilling the contract, as well as in the context of pre-contractual measures pursuant to Article 6(1)(b) GDPR and Article 88 GDPR, as well as on the basis of legal requirements pursuant to Article 6(1)(c) of the GDPR.
In this context, it is necessary for you to provide the personal data required for the establishment and performance of an employment relationship and the fulfilment of the associated contractual obligations, or which we are legally obliged to collect. Without this data, it is not possible to establish the employment relationship.
You will receive all information regarding the scope and purpose of the personal data collected, used and processed in the context of employment at Medigital GmbH, your rights as a data subject and all other data protection-related matters from us during the recruitment process.
3.4 Digital health solutions and products
As a manufacturer of digital health applications (DiGAs) and digital health solutions/products, we process the personal data of our customers (= users).
You can find all information regarding data processing and your rights in connection with our digital health applications (DiGAs) and digital health solutions/products in the relevant privacy policy:
Mental Health section:
Generalised anxiety disorder, depression, binge eating, bulimia:
Privacy Policy Selfapy App (only available in German)
ADHD section:
Privacy Policy hiFoon App (only available in German)
Privacy Policy Jay App (only available in German)
Privacy Policy AUTHARK App (only available in German)
Sleep Disorders section:
Privacy Policy hiPanya App (only available in German)
Women's Health section:
Privacy Policy femfeel App (only available in German)
Privacy Policy Remifemin Companion App (only available in German)
Gut Health section:
Privacy Policy Medibiom (only available in German)
Nephrology section:
Privacy Policy MediOrganizer App (only available in German)
Privacy Policy beCintia App (only available in German)
3.5 Studies, surveys and vigilnce reports
When conducting clinical trials or user surveys relating to our products, we collect personal data such as your name, address, telephone number and email address, as well as health-related data. We collect this data only with your explicit, informed and voluntary consent in accordance with Article 6(1)(a) in conjunction with Article 9(2)(a) of the GDPR. The respective purposes of processing, the departments and locations involved in the processing, the retention and deletion periods, as well as a description of the technical and organisational measures taken to safeguard your data are documented in the relevant study information for the respective clinical trial/user survey.
In the context of vigilance reports relating to our products, we collect personal data such as contact details (names of the persons reporting the adverse event and those affected by it), the time of occurrence of the adverse event, as well as information on underlying and concomitant conditions.
We are required under Regulation (EU) 2017/745 on medical devices (MDR) to collect, report and archive these vigilance reports. This serves to protect our users and to ensure high standards of quality and safety for our products.
Your data will only be passed on to third parties (e.g. competent authorities) in pseudonymised form (without any reference to your identity) within the framework of the statutory reporting obligations for vigilance reports.
3.6 Business relationships
Medigital GmbH maintains various business relationships with, for example, doctors, suppliers, data processors, cooperation partners, training participants, other service providers (staffing agencies, consultants, other freelancers, etc.), wholesalers, health insurance funds and other customers.
In this context, contact details, billing data and information from the respective contractual agreements are processed for the purpose of fulfilling the contract or as part of pre-contractual measures in accordance with Article 6(1)(b) of the GDPR.
Within the framework of this business relationship with Medigital GmbH, it is necessary for you to provide the personal data required for the establishment and conduct of a business relationship and the fulfilment of the associated contractual obligations, which we are legally obliged to collect. Without this data, we will generally be unable to accept a business relationship or other order or will be obliged to terminate it.
3.7 Events
Medigital GmbH organises various events such as seminars, expert group meetings or symposia. During these events, photographs and/or video recordings of the participants are taken by employees of Medigital GmbH and/or by external service providers on behalf of Medigital GmbH. We collect and process your personal data on the basis of our legitimate interest in documenting the respective event, reporting on it, and for public relations purposes (e.g. through publication on the company’s internal intranet, on our websites, on social media or in press releases) in accordance with Article 6(1)(f) of the GDPR. You will be informed about these photographs and/or video recordings in advance and during the events, and you may object to the processing of your personal data at any time by sending an informal request to privacy-medigital[at]medice.de.
In connection with the events, Medigital GmbH processes your personal data for the purpose of processing your registration, as well as for the organisation and follow-up of the event. The data collected is specified in the relevant registration form for the event.
Online events/meetings
For the planning, coordination and delivery of our online events/meetings, we use the tools “Zoom” (provided by Zoom Video Communications Inc.) and “Microsoft Teams” (provided by Microsoft Deutschland GmbH), which are made available by our parent company, MEDICE Arzneimittel Pütter GmbH & Co. KG. When you participate in one of our online events or meetings, your personal data will be processed.
You can find all information on data protection for online events via Zoom here: Privacy Policy Online Events via Zoom (only available in German)
You can find all information regarding data protection for online meetings here: Privacy Policy "Use of Microsoft Teams for online meetings" (only available in German)
3.8 Profiling
We process your data in a partially automated manner with the aim of evaluating certain aspects of your person (profiling).
We use profiling in the following cases, for example:
We use evaluation tools to provide you with targeted information and advice about products. These enable us to communicate and advertise in line with your needs, including market and opinion research.
We may use scoring as part of the assessment of your creditworthiness. This takes into account experience from previous business relationships, publicly available data and information from credit agencies.
3.9 Marketing and newsletter distribution
As part of our marketing activities, we send out digital newsletters containing information on products, events, promotions, offers, loyalty programmes or advertising from the MEDICE Health Family product ranges.
These product ranges cover the following topics:
Women’s health (Remifemin, Remifemin Moisturising Cream, Remifemin mono, Remifemin plus, Remisens, Femicur N, femfeel app, Remifemin Companion app, Cystinol, Aualibra, Healthy Woman, Cystinol, Aqualibra; Apps/digital health solutions: femfeel – medigital GmbH; Remifemin Companion – MEDICE Arzneimittel Pütter GmbH & Co. KG)
Gut health (MEDIBIOM dietary supplements, Tannacomp, Perenterol forte/junior, Tannalbin, Mediolax; Apps/digital health solutions: MEDIBIOM)
Nephrology (Vafseo, Abseamed, Anti-Kalium Na, Calcitriol Nefro, Calciumacetat-Nefro, CC-Nefro, FerMed, Nefrocarnit, Nephrotrans, Phosphonorm, Sevemed; Apps/digital health solutions: beCintia, MediOrganizer – Medigital GmbH)
Mental Health
ADHD (Medikinet, Agakalin, Attentin, Kinecteen, Medikinet retard, Mellozan, ADHD Network/Portal; Apps/digital health solutions: hiToco, hiFoon – Medigital GmbH; brainjo – brainjo GmbH; Attexis – GAIA AG)
Sleep disorders (Apps/digital health solutions: hiPanya – Medigital GmbH)
Anxiety (Sedacur forte)
Depression (Apps/digital health solutions: Online therapy “Depression” – Selfapy GmbH)
Nutrition (apps/digital health solutions: online therapy for ‘bulimia’ and ‘binge eating’ – Selfapy GmbH)
Panic/anxiety disorders (apps/digital health solutions: online therapy for ‘panic disorder’, ‘generalised anxiety disorder’ – Selfapy GmbH)
Chronic pain (apps/digital health solutions: online therapy for ‘chronic pain’ – Selfapy GmbH)
Our marketing activities are primarily aimed at customer loyalty and retention, information sharing, market and opinion research, improving our offerings, and automating communication.
Your contact details (name, email address) are used to send the newsletter. Tools and software solutions from various mailing service providers are used for this purpose.
These are:
Brevo
We use the mailing service provider Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany.
You can view Brevo’s privacy policy at: https://www.brevo.com/de/datenschutz-uebersicht/.
Mailgun
We use the Mailgun email service from MessengerPeople GmbH, St.-Martin-Straße 63, 81669 Munich, as a self-hosted on-premise software solution.
For more information on Mailgun's privacy policy, please visit: https://www.mailgun.com/legal/privacy-policy/
Salesforce
We use the CRM solutions provided by salesforce.com Germany GmbH („salesforce“), Erica-Mann-Str. 31-37, 80636 München, Germany. We use these CRM solutions (customer relationship management solutions) for the management of customer and consent data, sales management, and the automated sending of newsletters. The parent company Salesforce.com Inc. is a US company certified under the EU-US Data Privacy Framework, which means that the adequacy decision of the EU Commission pursuant to Art. 45 GDPR applies and thus confirms an adequate level of data protection.
Further information on Salesforce can be found at: https://www.salesforce.com/company/legal/privacy/
HubSpot
We use the CRM solutions provided by HubSpot Germany GmbH, Am Postbahnhof 17, 10243 Berlin, Germany. We use these CRM (Customer Relationship Management) solutions for the management of customer and consent data, sales management, and the automated dispatch of newsletters. The parent company HubSpot Inc. is a US company certified under the EU-US Data Privacy Framework, meaning that the EU Commission’s adequacy decision pursuant to Article 45 of the GDPR applies, thereby confirming an adequate level of data protection.
Further information on HubSpot can be found at: HubSpot Privacy Policy
Medigital GmbH only uses service providers with whom a corresponding data processing agreement in accordance with Article 28 of the GDPR is in place; in the case of service providers from the USA, only companies that are certified under the EU-US Data Privacy Framework and are therefore subject to the EU Commission’s adequacy decision pursuant to Article 45 of the GDPR.
In the context of personalised newsletters, Medigital GmbH uses contact lists from HCP database service providers such as IQVIA, as well as data collected via web scraping from publicly accessible website content of medical practices.
Further information on IQVIA’s data protection policies can be found at: IQVIA Privacy Policy (the “Policy”): - IQVIA
The legal basis for the processing of your data in connection with the sending of newsletters is either a concluded contractual agreement with you (e.g. when entering a competition) in accordance with Article 6(1)(b) or your voluntary consent in accordance with Article 6(1)(a) of the GDPR.
This consent may be obtained directly by Medigital GmbH or by an external HCP database service provider such as IQVIA.
Further information on IQVIA’s data protection policies can be found at: IQVIA Privacy Policy (the “Policy”): - IQVIA
You may withdraw your consent at any time, without giving reasons, and unsubscribe from the newsletter. A link for this purpose is included in every newsletter.
3.10 Our activities on social media
We have our own pages on social media so that we can communicate with you there and inform you about our services.
We are not the original provider of these pages but merely use them within the scope of the options offered to us by the respective providers.
As a precaution, we would therefore like to point out that your data may also be processed outside the European Union or the European Economic Area. Use may therefore involve data protection risks for you, as it may be more difficult to safeguard your rights, e.g. to information, deletion, objection, etc., and processing on social networks is often carried out directly for advertising purposes or to analyse user behaviour by the providers, without us being able to influence this. If usage profiles are created by the provider, cookies are often used or your usage behaviour is assigned to your own member profile on social networks.
The processing of personal data described above is carried out in accordance with Art. 6 (1) (f) GDPR on the basis of our legitimate interest and the legitimate interest of the respective provider in communicating with you in a modern way and informing you about our services. If you have to give your consent to data processing as a user to the respective providers, the legal basis is Art. 6 (1) (a) GDPR.
As we do not have access to the providers' data stocks, we would like to point out that it is best to assert your rights (e.g. to information, correction, deletion, etc.) directly with the respective provider. Further information on the processing of your data in social networks is listed below for each social network provider we use:
Facebook
When you visit our Facebook page, where we present our company or individual products from our range, certain information about you is processed. The controller responsible for data processing in Germany is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
All information on how Facebook handles your personal data can be found here: www.facebook.com/privacy/explanation .
Instagram
When you visit our Instagram page, where we present our company or individual products from our range, certain information about you is processed. The data controller in Germany is Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
All information about how Instagram handles your personal data can be found here: https://instagram.com/legal/privacy/
LinkedIn
When you visit our LinkedIn pages, where we present our company or individual products from our range, certain information about you is processed. The controller responsible for data processing in Germany is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.
All information on how LinkedIn handles your personal data can be found here: https://www.linkedin.com/legal/privacy-policy?trk=homepage-basic_footer-privacy-policy
Vigilance reports via social networks
Occasionally, users, their relatives or healthcare professionals may comment on our products in comments or messages. These comments/messages also count as vigilance reports from section 3.5, in which we process your personal data.
3.11. Cooperation between the parent company and subsidiaries
In order to pursue the legitimate interests of MEDICE Health Family Holding GmbH pursuant to Article 6(1)(f) of the GDPR in optimising the advertising and sales presence of our parent company and subsidiaries, it may be necessary for us to share certain personal data within MEDICE Health Family Holding GmbH. This applies in particular to contact details, information about your interests and your customer profile, as well as your use of our products and services.
The joint processing of this data takes place within the framework of joint responsibility in accordance with Article 26 GDPR. The companies involved within MEDICE Health Family Holding GmbH have set out in an agreement how the respective tasks and responsibilities relating to the processing of personal data are distributed and who fulfils which obligations in accordance with the GDPR.
The primary responsibility for data processing lies in the areas of human resources management, IT infrastructure provision, marketing and sales, legal advice (including data protection advice and management), financial accounting, controlling, corporate communications, pharmacovigilance reporting, quality management and quality assurance services, as well as study planning, coordination and implementation, lies with MEDICE Arzneimittel Pütter GmbH & Co. KG, as the parent company of MEDICE Health Family Holding GmbH, based in Germany.
The subsidiaries and sub-subsidiaries are responsible in particular for data processing in the areas of marketing and sales, pharmacovigilance reporting, study planning, coordination and implementation, as well as human resources management in their respective countries of operation and in relation to their respective product and service portfolios.
The shared data may be used to:
Optimise our marketing and sales strategies.
To conduct market research and analyses in order to further improve our products and services.
The companies involved within MEDICE Health Family Holding GmbH ensure that appropriate technical and organisational measures are taken to protect your personal data. The transfer and processing of your data is always carried out in accordance with the applicable data protection regulations.
Further information on data protection, your rights as a data subject and data processing by MEDICE Arzneimittel Pütter GmbH & Co. KG as the parent company of MEDICE Health Family Holding GmbH can be found here: https://medice-health-family.com/de-de/footer/dse/dse-medice-arzneimittel-puetter-gmbh-co-kg
If you have any questions regarding the joint processing of your data within MEDICE Health Family Holding GmbH or wish to exercise your data protection rights, you can contact our data protection team at any time at privacy-medigital[at]medice.de.
3.12 Purpose of processing
Personal data is processed for the following purposes:
to fulfil contractual obligations or as part of pre-contractual measures
to protect the rights and interests of Medigital GmbH and third parties (e.g. employees)
to comply with legal obligations
in rare cases to defend against legal claims or to combat fraud
to carry out product testing, user surveys and clinical trials
for market research and marketing purposes
for documentation, reporting and public relations
to process and verify vigilance reports
for communication and establishing contact
3.13 Retention and deletion periods
Unless otherwise stated in this privacy policy, we will only store your personal data for as long as is necessary to fulfil the stated processing purposes, to meet our contractual or legal obligations, or to pursue and defend against legal claims.
The statutory retention obligations arise in particular from provisions under commercial, tax and medical device law.
4. Legal basis
The legal bases for the processing of your personal data may be your informed, voluntary consent pursuant to Article 6(1)(a) of the GDPR, where applicable in conjunction with Article 7 of the GDPR, the performance of a contract to which you are a party, or the performance of pre-contractual measures pursuant to Article 6(1)(b) of the GDPR, the fulfilment of a legal obligation pursuant to Article 6(1)(c) of the GDPR, or the protection of our legitimate interests or those of a third party pursuant to Article 6(1)(f) of the GDPR.
5. Data transfer
We only pass on your personal data to third parties if:
you have given us your express consent to do so in accordance with Art. 6 (1) (a) GDPR,
the transfer is permissible under Art. 6 para. 1 lit. f) GDPR to safeguard our legitimate interests and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data,
there is a legal obligation to disclose the data in accordance with Art. 6 (1) (c) GDPR, and
this is legally permissible and necessary for the performance of contractual relationships with you in accordance with Art. 6(1)(b) GDPR.
Within the scope of the processing operations described in this privacy policy, personal data may be transferred to the United States. Companies in the United States only have an adequate level of data protection if they are certified under the EU-US Data Privacy Framework and thus the adequacy decision of the European Commission pursuant to Art. 45 GDPR applies.
We have explicitly mentioned this in the privacy policy for the service providers concerned. In order to protect your data in all other cases, we have concluded agreements on order processing based on the standard contractual clauses of the European Commission. If the standard contractual clauses are not sufficient to establish an adequate level of security, your consent pursuant to Art. 49(1)(a) GDPR may serve as the legal basis for the transfer to third countries. This does not apply to data transfers to third countries for which the European Commission has issued an adequacy decision pursuant to Art. 45 GDPR.
Under these conditions, recipients of personal data may include, for example:
Companies affiliated with Medigital GmbH, insofar as this is necessary for the purpose of data processing.
Public authorities and institutions (e.g. European Central Bank, tax authorities, Federal Central Tax Office, public prosecutors) in the event of a legal or official obligation.
Processors to whom we transfer personal data in order to conduct our business relationship with you, e.g. for services related to archiving, document processing, call centre services, controlling, compliance, data destruction, purchasing, debt collection, customer management, lettershops, marketing, media technology, reporting, support/maintenance of IT applications, risk controlling, telephony, goods dispatch, website management, payment transactions.
Persons bound to professional secrecy (including solicitors, tax advisors, auditors) for support in fulfilling legal or official obligations, as well as for pursuing and defending legal claims and in criminal prosecution.
Other data recipients may be those entities to which you have given your consent for data transfer.
Medigital guarantees that your data will only be passed on to entities that can demonstrate an appropriate data protection concept in accordance with the applicable regulations and laws and with which, if necessary, appropriate contractual agreements have been concluded in accordance with Art. 26 and Art. 28 GDPR.
6. Data security
The security of your personal information is very important to us.
Every instance of data collection, storage, use and transfer involves confidentiality risks (e.g. the possibility of identifying the person concerned). These risks cannot be completely ruled out and increase the more data can be linked together. Medigital GmbH assures you that it will do everything possible in line with the state of the art to protect the transmission of your data.
To this end, we take the following technical and organisational measures, amongst others:
BSI certification for digital health applications (DiGA)
Two-factor authentication via Health ID (DiGA): To protect your data from unauthorised access and thus ensure its confidentiality and integrity, we use two-factor authentication, whereby you log in to the app using your Health ID. This ensures that only you have access to your user account.
Two-factor authentication without a Health ID (DiGA): To protect your data from unauthorised access and thus ensure its confidentiality and integrity, we also offer two-factor authentication without a Health ID. Here, you log in to the app using a login procedure that requires a username, password and TOTP (time-based one-time password). This ensures that only you have access to your user account.
Two-factor authentication via email: To protect your data from unauthorised access and thus ensure its confidentiality and integrity, we offer you the option of two-factor authentication via email when logging into the app. In this case, you must confirm your email address by entering a six-digit code. This ensures that only you have access to your user account.
Strict separation of the storage and processing of health and contact data, with access rights restricted to authorised employees of Medigital GmbH.
Anonymisation of data collected for the purposes of quality assurance, further development and continuous improvement of the application. This means that it is not possible to identify you personally.
SSL/TLS encryption: Personal data is transmitted only via state-of-the-art encrypted connections. We comply with the applicable guidelines of the Federal Office for Information Security and use this technology to protect the transmission of your data.
Different passwords for all software tools
Virus protection for all IT hardware in use
Firewall for our internal company network
Regular training on data security and protection for all employees
Regular updates of all software components
Regular data backups to ensure availability
Regular risk analyses of the relevant IT systems and products
7. Your rights
When processing your personal data, our aim is to ensure your data protection rights at all times. You can find our service hours and all contact details under section 2 ‘Contact’ of the detailed privacy policy.
You may exercise the following rights in relation to your personal data:
You can request information about the processing of your data.
You can request the correction of your personal data if it is incorrect or incomplete.
You can request the restriction of the processing of your personal data. (1) For the duration of the verification of the accuracy of the data. (2) If the processing is unlawful and you refuse to have it deleted. (3) If the data is no longer required by the controller for the purposes of processing, but you need it to assert, exercise or defend legal claims. (4) In the event of an objection to data processing, as long as the corresponding balancing of interests has not been clarified.
You can request that the data collected about you be transferred to you or to a body designated by you.
If there are grounds for complaint, you can lodge a complaint with the competent data protection authority.
You may request the deletion of the data collected about you.
You can object to the processing of your personal data at any time without giving reasons. If the processing is based on Article 6(1)(e) or (f) of the GDPR.
You can withdraw any consent given for data processing at any time, informally and without giving reasons.
You will not suffer any disadvantages as a result of an objection/withdrawal. The objection shall take effect for the future; previous data transfers shall remain lawful. From then on, your data will only be processed by MEDICE Arzneimittel Pütter GmbH & Co. KG to a limited extent if this is required by the relevant legal provisions under Art. 6 (1) (c) and our legitimate interest under Art. 6 (1) (f) GDPR.
If you have any further questions about the handling of your personal data or would like to exercise your other rights, please contact our data protection team at privacy-medigital[at]medice.de.
For confidential matters relating to data protection, you can contact our data protection officer directly at dsb[at]medice.de.
