Mobidoctor LTD ("Mobi Doctor", "we", "us" or "our") is an information technology (IT) company registered in Malta under company number C90869. Our registered office is Mobidoctor LTD Tower Street 2nd floor Tower Business Center, Swatar, BKR4013, Malta.
We operate the Mobi Doctor website (the "Website"), patient portal, mobile and tablet applications and associated digital services through which online medical assessments, consultations and related Platform services are made available (the "Platform" and the "Services").
Mobidoctor LTD is a data controller for the personal and health information processed through the Platform for the purposes described in this Policy. The section "Roles of Mobi Doctor and Practitioners" explains our responsibilities and how we work with the treating doctors ("Practitioners"). You may contact our Data Protection Officer at [email protected].
This Privacy Policy explains what personal data we collect, the purposes and legal bases for processing, who may receive the data, international transfers, retention, security and your rights. It applies when you browse the Website, create or use an account, complete a medical questionnaire, book or purchase a Service, communicate with us or a Practitioner, receive a Service, or use prescription or medical-document verification facilities made available through the Platform.
This Policy is a privacy notice. It is not a contract and is not a request for general consent to process personal data. Clinical consent to remote care and any consent required for a particular optional activity are dealt with separately.
Consent and purpose
We rely on consent where it is the appropriate legal basis, including for non-essential cookies and optional direct marketing. You can withdraw consent at any time through the cookie settings, an unsubscribe method or by contacting us. Withdrawing consent does not affect the lawfulness of processing carried out on that consent before withdrawal. Separate processing may continue where it is lawfully based on another ground described in this Policy.
Some information is necessary for us and the treating Practitioner to assess whether the Service is suitable, provide care, process payment, communicate with you and maintain required records. Where information is mandatory, we will indicate this. If you do not provide it, we may be unable to provide all or part of the requested Service.
Legal bases for processing personal data
The following table summarises the principal processing activities. The relevant Article 6 GDPR basis is identified for each purpose. Where health information is involved, an applicable Article 9 condition is also required. References to legal obligations apply only where a specific obligation requires the processing. The section "Storing personal data" explains retention criteria, and "International data transfers" explains transfer safeguards.
|
Purpose |
Data and legal basis |
Recipients |
Retention / transfers |
|
Account access, bookings, purchases and service administration |
Identity, contact, account, booking, purchase and service data. Article 6(1)(b) for the purchase and administration of the Service. Article 6(1)(f) for proportionate security and fraud prevention. |
Hosting, authentication, communications, payment and support providers; authorised staff. |
For the active relationship and then for periods required for support, security, complaints, legal claims and applicable law. Transfers: see International data transfers. |
|
Clinical assessment, consultation and medical records |
Symptoms, medical history, allergies, medicines, questionnaire answers, communications, images/documents, clinical notes and outcomes. Article 6(1)(b) and, where applicable, 6(1)(c). Article 9(2)(h) for diagnosis and healthcare under professional secrecy; Article 9(2)(f) for legal claims; Article 9(2)(c) only where vital interests apply and the person is incapable of consent. |
Treating Practitioners; authorised clinical/operational staff; platform processors used to deliver the Service. |
For the period required by applicable healthcare and professional record obligations, patient safety, complaint handling and legal claims. Closing an account does not automatically delete a medical record. |
|
Payments, invoices, refunds and accounting |
Transaction, billing and limited payment metadata. Article 6(1)(b), Article 6(1)(c) and Article 6(1)(f) for payment reconciliation, fraud prevention and disputes. |
Payment service providers, banks, accountants, auditors and tax authorities where applicable. |
For statutory accounting and tax periods and the period needed to resolve payment disputes and claims. International transfers: see the relevant section below. |
|
Identity, age, location or eligibility checks; fraud and security |
Identity, age, current country or location, contact details and technical or security data. Article 6(1)(b) where needed to provide the Service; Article 6(1)(f) for security, fraud prevention and misuse investigations; Article 6(1)(c) only where a specific legal duty applies. |
Verification, anti-abuse, security and payment-risk providers; authorised staff. |
Only for as long as needed for the check, security investigation, audit evidence and any applicable legal requirement. |
|
Customer support and service communications |
Messages, call/chat metadata and information supplied with a request. Article 6(1)(b) for service support; Article 6(1)(f) for complaint administration. Article 9(2)(h) where necessary for a clinical service issue under professional secrecy, or Article 9(2)(f) where necessary for legal claims. |
Support, email, messaging and communications providers; authorised staff and Practitioners where needed. |
For as long as needed to resolve the request and then for proportionate complaint, quality, security and claims periods. |
|
Prescription and medical-document verification |
Document reference, authenticity/status information, relevant prescription details and request logs. Article 6(1)(b) and 9(2)(h) for necessary prescription verification and dispensing. Article 6(1)(f) for proportionate technical security logs. Article 6(1)(a) and 9(2)(a) for an optional disclosure requiring explicit consent. Article 9(2)(f) only where necessary to establish, pursue or defend legal claims. |
Independent pharmacies; other intended recipients where a disclosure is requested and lawful; verification and security providers. |
Only for the period needed to validate the document, prevent reuse or fraud, investigate incidents and comply with healthcare, professional or legal record requirements. |
|
Emergency, safeguarding and vital interests |
Relevant identity, contact, location and health information. Article 6(1)(d) and, where applicable, 6(1)(c); Article 9(2)(c) where the person is incapable of consent, or Article 9(2)(h) within healthcare. |
Emergency services, police, the treating Practitioner and other persons necessary to address the risk. |
Recorded and retained as part of the clinical, safety or incident record for the applicable period. |
|
Legal and regulatory compliance; complaints and claims |
Data relevant to the obligation, complaint, investigation or claim. Article 6(1)(c) and 6(1)(f); Article 9(2)(f) and, where relevant, 9(2)(h). |
Courts, regulators, law enforcement, professional bodies, insurers, auditors and legal advisers. |
For the duration of the obligation, investigation or claim and the applicable limitation/record period. |
|
Direct marketing |
Contact details and marketing preferences. Article 6(1)(a) for optional direct marketing. A minimal suppression record is retained to respect an opt-out, based on the applicable compliance obligation or our legitimate interest in respecting that choice. |
Email/SMS and preference-management providers. |
Until consent is withdrawn or the purpose ends, plus a minimal suppression/audit record where needed to respect the opt-out. |
|
Cookies, analytics and embedded content |
Cookie identifiers, consent choices and technical usage data. Article 6(1)(b), (c) or (f), as applicable, for requested functions, consent records and necessary security. Non-essential technologies rely on Article 6(1)(a) consent and applicable ePrivacy requirements. |
Consent-management, analytics, embedded-content and security providers identified in the cookie banner/table. |
As shown in the current cookie table and consent record, subject to the user changing or withdrawing consent. |
Health data is special-category personal data. Routine clinical processing is carried out where necessary for medical diagnosis, treatment or the management of healthcare Services under Article 9(2)(h) GDPR, subject to the professional-secrecy requirements in Article 9(3). Other Article 9 conditions are used only where they apply, including explicit consent under Article 9(2)(a) for an optional disclosure requiring that consent, Article 9(2)(f) where necessary to establish, pursue or defend a legal claim, and Article 9(2)(c) to protect vital interests where the person is physically or legally incapable of consent. A legitimate interest in preventing misuse is not, by itself, a condition permitting the processing of health data.
Information we collect when you use our Services
Depending on the Service and how you use the Platform, we may collect:
Identity, contact and eligibility information. Your name, date of birth, age confirmation, country or current location, postal address, email address, telephone number and other information reasonably needed to identify you, communicate with you and confirm eligibility for a Service.
Account and authentication information. Where you create or use an account, this may include account identifiers, login credentials in protected form, security settings, session information and account activity.
Health and clinical information. Symptoms, current health, medical history, allergies, medicines, previous treatment, questionnaire answers, clinically relevant sex or pregnancy information, images, video or documents you upload, information communicated during a consultation or secure message, and other information requested for a safe assessment.
Consultation and medical-record information. The treating Practitioner, appointment and assessment details, clinical notes, diagnosis or assessment, advice, treatment recommendations, referrals, prescriptions, other relevant medical documents and related communications. This may include records or documents that you supply from another healthcare provider. Live video or audio streams and related technical data are processed to enable the consultation.
Payment and billing information. The amount, currency, payment status, transaction reference, billing details, refund or dispute information, and the transaction or payment-method information made available to us by the payment provider. Depending on the selected method and checkout configuration, the payment provider may collect full card or wallet credentials directly.
Support and communications. Emails, chat messages, complaints, requests, call or message metadata and any information you provide when contacting us.
Preferences and consent records. Marketing choices, cookie choices and evidence of when a preference or consent was given, changed or withdrawn.
Verification information. A prescription or medical-document reference, authenticity and status information, and information submitted or generated when a pharmacy or another intended recipient requests verification of a document.
We obtain personal data primarily from you and from the treating Practitioner. We may also receive limited information from payment and service providers, a person using a verification tool, an authorised person acting for you, or your device and browser. If another person provides information about you, they must have lawful authority to do so.
The Platform or portal may display some of your account and consultation information. You may also request access as explained under Rights of the data subject. The scope of an access response is determined by the GDPR and may be subject to identity checks and lawful limits protecting other people.
Information collected automatically when you use our Services
Log and usage data. IP address, access time, pages or functions used, referring page, session events, error information and security events.
Device and browser data. Device type, operating system, browser type and version, language and other limited technical information needed for compatibility, security and troubleshooting.
Approximate location. We may infer a country or coarse location from an IP address for Service eligibility, localisation, security and fraud prevention. We may also ask you to state your current country or location because the Services are available only in eligible European Union Member States.
Cookies and similar technologies. Cookie identifiers, consent choices and technical or usage data as described in Cookie and tracking technologies below and in the current cookie banner/table.
Verification-tool data. The reference entered, the result returned, request time and technical or security information used to validate the document and prevent misuse. The prescription-verification page uses Google reCAPTCHA to detect automated abuse, as explained under "Cookie and tracking technologies".
How we use your information
We use personal information for the purposes and on the legal bases described above, including:
- to create and secure accounts where used, administer bookings and purchases of Services, and provide the Platform and Services;
- to enable a Practitioner to assess you, communicate with you, provide clinical advice and create or issue an appropriate medical record or document;
- to process the fee for the Mobi Doctor Service, issue invoices, make refunds and manage payment disputes;
- to send booking confirmations, service notices, security messages and other communications necessary for the Service;
- to provide support, handle complaints and coordinate with the relevant Practitioner;
- to protect patients, Practitioners and the Platform, prevent fraud and misuse, investigate incidents and enforce lawful Platform restrictions;
- to verify prescriptions and medical documents for intended recipients while limiting the information shown to what is necessary;
- to comply with legal, regulatory, professional, tax, accounting and record-keeping requirements and to establish, exercise or defend legal claims;
- to maintain, test and improve the reliability, accessibility, safety and performance of the Platform using data that is limited to what is necessary for that purpose; and
- to send optional direct marketing with the required consent, and to enable non-essential analytics, embedded content or similar technologies only after the required prior consent.
Roles of Mobi Doctor and Practitioners
Mobidoctor LTD is a data controller for the personal and health information processed through the Platform for the purposes described in this Policy. We are responsible for managing that processing, including authorised access, the technical environment and security of records, record retention, and the handling of requests to exercise data-protection rights.
Practitioners are licensed doctors who access and use the information necessary to carry out medical assessments and consultations and create the associated clinical records. They exercise independent professional and clinical judgement and are responsible for the clinical information they record, their clinical decisions, professional confidentiality and applicable medical-record and data-protection obligations.
Mobidoctor LTD is your main contact for questions about personal information held on the Platform and for requests to exercise your data-protection rights. We will handle your request and coordinate with the treating Practitioner where necessary. This description does not limit any responsibility imposed by applicable law on Mobidoctor LTD, a Practitioner or another recipient.
How we share your information
We disclose personal data only where necessary for the purposes in this Policy and subject to appropriate confidentiality, data-protection and security requirements. Recipients may include:
Treating Practitioners. We share the personal and health information necessary for your assessment or consultation with the medical practitioner providing that Service. Practitioners must protect the confidentiality of that information and use it for providing the Service and fulfilling their applicable professional and legal obligations.
Service providers. We may share personal data with service providers who process it to provide services to us or on our behalf. These include providers supporting hosting, authentication, video or messaging infrastructure, customer support, email or SMS delivery, payment processing, accounting, security, anti-abuse, analytics, consent management and document verification. Where a provider processes personal data on our behalf, it must act on our documented instructions and under the applicable data-protection agreement, except where processing is required by law. Providers must protect the information and must not use it for unrelated purposes. Some providers are responsible for separate processing to fulfil their own legal or regulatory obligations; their privacy notices explain that processing.
Payment and finance recipients. We share relevant billing and transaction information with payment service providers, banks, accountants, auditors and competent tax authorities where necessary to process payments for Services purchased from Mobidoctor LTD, administer refunds and disputes, and meet accounting and tax obligations.
Pharmacies and medical-document recipients. If a prescription is issued, it is made available through the Platform and may be presented to an independent pharmacy. For prescription verification and dispensing, we disclose the necessary prescription-reference, authenticity or status information, prescriber details and, where needed, the prescription itself. For another medical document, any verification or disclosure is limited to the information necessary for the intended recipient and supported by the relevant lawful basis. Where an optional disclosure of health information outside healthcare requires explicit consent, we obtain that consent before disclosure. Pharmacies and other recipients are responsible for their own dispensing, claims or regulatory processing. The verification facilities are not intended for public access to patient records.
Emergency and safeguarding recipients. Emergency services, police or another appropriate person where this is reasonably necessary and lawful to protect life, health or safety.
Authorities and professional advisers. Courts, regulators, law-enforcement bodies, professional authorities, insurers, auditors and legal advisers where disclosure is required by law or is necessary and proportionate for an investigation, complaint, legal claim or protection of rights and safety. Any disclosure of health information also requires an applicable Article 9 condition; it is not authorised merely because a recipient requests it or a fraud-prevention interest exists.
Business transfer recipients. A genuine prospective or completed buyer, investor, funder or successor in connection with a merger, financing, reorganisation or sale, subject to confidentiality, necessity, applicable law and any required notice.
Recipients you direct or authorise. A person or organisation where you ask us to disclose information and the disclosure is lawful, including another healthcare provider or an authorised representative.
Ensuring information is accurate and up to date
Please provide complete, accurate and current identity, contact and health information and update account details when they change. You may correct editable profile information through the available account functions or ask us to correct inaccurate data.
A clinical record may need to preserve the original entry for patient-safety, professional or audit reasons. Where an original clinical entry should not be overwritten, an appropriate correction, clarification or supplementary statement can be added instead.
How we protect your information
We implement technical and organisational measures designed to provide security appropriate to the sensitivity of the data and the risks of the processing. These measures include controls designed to restrict access, protect data during transmission and storage, maintain the confidentiality, integrity, availability and resilience of systems, manage suppliers and incidents, and test the effectiveness of safeguards as appropriate.
Access to health information is limited to persons who need it for legitimate clinical, operational, legal, security or compliance purposes and who are subject to confidentiality requirements. No internet service or storage system can be guaranteed to be completely secure. Please protect your credentials, use a secure device and connection, and contact us promptly if you suspect unauthorised access. Do not send card details or unnecessary health information by ordinary email.
International data transfers
Some service providers or recipients may process personal data outside the European Economic Area. Where GDPR requires a transfer mechanism, we use an adequacy decision, the European Commission Standard Contractual Clauses or another lawful safeguard and assess supplementary measures where required. Limited transfers may also occur under a specific Article 49 GDPR derogation where the legal conditions are met.
You may contact the Data Protection Officer for information about the destination and safeguard used for a particular transfer and to obtain a copy of the relevant safeguards. Information may be redacted where necessary to protect confidential information or other people's rights, without preventing us from explaining the protection applied to your data.
Personal data breach notifications
We assess and document personal data breaches and take steps to contain and address them. We notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a breach, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. If notification is delayed, we explain the reasons. Where a breach is likely to result in a high risk to you, we also communicate the breach to you without undue delay, unless an exception under Article 34 GDPR applies.
Your choices about your information
Marketing is optional and is not required to purchase or receive a medical Service. You can withdraw marketing consent or object to direct marketing at any time by using the unsubscribe method, adjusting available preferences or contacting us. We may retain a minimal suppression record so that your opt-out is respected. Service, clinical, billing, security and legal notices may still be sent where necessary.
You can change or withdraw non-essential cookie consent at any time using Cookie settings on the Website. Storage or access that meets the strictly necessary exception may still be used for the requested function, as explained under "Cookie and tracking technologies".
Rights of the data subject
Subject to the conditions and limits in the GDPR, you may have the following rights:
Access and confirmation. To know whether we process your personal data and obtain a copy together with the information required by Article 15 GDPR.
Rectification. To correct inaccurate data and complete incomplete data, including by a supplementary statement where appropriate.
Erasure. To ask for deletion where an Article 17 ground applies. This right is not absolute: an applicable exception may permit or require necessary retention, for example for a legal obligation or to establish, pursue or defend legal claims.
Restriction. To ask us to restrict processing in the circumstances set out in Article 18 GDPR.
Data portability. To receive eligible data you provided in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible, when Article 20 applies.
Objection. To object on grounds relating to your situation to processing based on legitimate interests. We will stop unless compelling legitimate grounds or legal claims justify continuing. You may object to direct marketing at any time and we will stop using the data for that purpose.
Withdraw consent. To withdraw consent where processing relies on it, without affecting the lawfulness of earlier processing based on that consent. Separate processing based on another applicable ground is addressed under "Consent and purpose".
Automated decisions. Not to be subject, in the circumstances covered by Article 22 GDPR, to a decision based solely on automated processing that produces legal or similarly significant effects. Mobi Doctor does not use solely automated processing to make medical, diagnostic, treatment or prescribing decisions; those decisions are made by Practitioners. Security and fraud-prevention tools may generate alerts, request additional checks or temporarily restrict activity. Where a solely automated decision would have a legal or similarly significant effect, we will provide the information and safeguards required by law, including human review where applicable.
Complaint. To complain to the Malta Information and Data Protection Commissioner (IDPC) or, where applicable, the supervisory authority in the EEA country of your habitual residence, place of work or the alleged infringement. The IDPC complaint form and current contact details are available at idpc.org.mt.
To exercise a right, contact [email protected]. Where necessary, we may request additional information to verify your identity and protect your data. We respond without undue delay and within one month of receiving your request, subject to any extension permitted by the GDPR. The period may be extended by up to two further months where necessary because of complexity or the number of requests; we will explain the extension and its reasons within the first month. Requests are normally free, although the GDPR permits a reasonable fee or refusal for a manifestly unfounded or excessive request. Where we refuse to act, we explain the reason and the available complaint and judicial remedies.
Storing personal data
We retain personal data only for as long as necessary for the relevant purpose, taking account of healthcare and professional record requirements, patient safety, tax and accounting law, complaint and limitation periods, security and fraud risks, regulatory requirements, consent evidence and the need to establish, exercise or defend legal claims. We delete or irreversibly anonymise data when it is no longer needed, subject to controlled backup cycles and lawful restrictions on deletion.
|
Category |
Retention criterion |
|
Clinical records and medical documents |
Retained for the applicable medical-record requirement, measured from the event required by that obligation, and where necessary for continuing care, an unresolved complaint or legal claims. Only information needed for the relevant purpose is retained after other purposes have ended. Normally 10 years |
|
Account, booking, purchase and service-administration data |
While the account or Service relationship is active. After closure, retain only what is needed to complete bookings, refunds or requests, preserve records subject to a legal duty, or address complaints, security incidents or legal claims. |
|
Payments, invoices and accounting records |
The statutory accounting and tax period, plus any period needed to resolve payment disputes or claims. |
|
Support and communications |
Until the request is resolved, with further retention limited to information needed for follow-up, unresolved complaints, security incidents or legal claims. Information forming part of a clinical record follows the clinical-record criterion. |
|
Security and verification logs |
While needed to validate a document, identify or investigate misuse, protect the Service or retain necessary incident evidence. Relevant entries may be kept while an incident or claim remains open; other entries are deleted or irreversibly anonymised when no longer needed. |
|
Marketing preferences |
Until consent is withdrawn or the purpose ends, with a minimal suppression record retained where needed to ensure marketing does not resume. |
|
Cookie and consent records |
As shown in the cookie table or for as long as necessary to remember and demonstrate the consent choice. |
|
Backups |
For the controlled backup cycle needed for recovery and resilience. Expired copies are overwritten or securely deleted. Restoration is controlled and applicable deletions or restrictions are reapplied so that restoring a backup does not restart ordinary use of data that should no longer be used. |
Children's privacy
The patient Services are intended only for people aged 18 or over. We do not knowingly provide patient Services to a person under 18. If we learn that a child has submitted personal data outside an authorised process, we will take appropriate steps, including restricting access and deleting information that is not required for patient safety, healthcare or professional record obligations, legal compliance or legal claims. A parent, guardian or affected person may contact [email protected].
Mergers and acquisitions
If Mobidoctor LTD is involved in a genuine merger, acquisition, financing, reorganisation, insolvency or sale of all or part of its business, relevant personal data may be disclosed or transferred where necessary and lawful. Confidentiality and data-protection safeguards will apply, and we will provide notice of a material change where required. Any materially different processing by a successor requires an applicable lawful basis, compliance with purpose-limitation requirements, and any additional notice or consent required by law. A new privacy notice alone does not authorise a new use of the data.
Links to third-party websites
The Platform may link to websites or services that we do not control, including independent pharmacies and other information resources. Their privacy notices and cookie practices apply to their processing. A link does not by itself mean that Mobi Doctor endorses or controls the third party.
Notifications and changes to this Policy
We may update this Policy to reflect changes in law, the Platform, the Services or our processing. The current version will show its effective date. Where a change is material or notice is legally required, we will provide an appropriate notice through the Platform, email or another suitable channel before or when the change takes effect. A new purpose that is incompatible with the original purpose will not be introduced merely by changing this Policy; we will identify an appropriate legal basis and provide any additional notice or consent required by law.
Cookie and tracking technologies
We use cookies and similar technologies to support the Website and the functions you request. Consent is not required only where storage or access is strictly necessary to transmit a communication or provide an online service you explicitly requested. This can include remembering your privacy choices, authentication and essential security functions where they meet that test. Analytics, personalisation, non-essential embedded media, advertising and cross-site tracking technologies are activated only after the required prior opt-in consent.
You can accept or refuse non-essential categories and later change or withdraw your choice using Cookie settings in the Website footer or banner. Refusing non-essential cookies does not prevent access to the core Service, although a feature that depends on an optional third-party service may remain unavailable until consent is given.
We use CookieFirst, provided by Digital Data Solutions BV in the Netherlands, to manage and document cookie choices. CookieFirst processes the consent status or withdrawal, IP-related information, browser and device information, the date and time, the page on which the choice was saved, approximate location and a pseudonymous identifier. Processing needed to demonstrate legally required consent relies on Article 6(1)(c); processing necessary to operate and secure the consent tool relies on Article 6(1)(f). The provider processes this information under a data-processing agreement. Technical shortening or pseudonymisation of an identifier does not, by itself, make information anonymous.
The cookie table displayed on the Website identifies the current cookies and similar technologies, providers, purposes, categories and retention periods. Because the technologies used on the Website may change, the live table and banner provide the current information about those technologies and your choices.
The prescription-verification page uses Google reCAPTCHA to detect automated abuse. It may process network, device and interaction information and may involve an international transfer. Any storage or access that does not meet the strictly necessary exception requires prior consent. Further information about the current implementation, provider, purpose, retention and consent category is provided in the Website's cookie/technology declaration and Google's applicable privacy information. The safeguards described under "International data transfers" apply where required.
Contacting us
Privacy and data-subject requests: [email protected]
General support: [email protected]
Mobidoctor LTD C90869, Tower Business Centre, 2nd Floor, Tower Street, Swatar, BKR 4013, Malta.
Consent to the use of cookies.
For our website to function properly we use cookies. To obtain your valid consent for the use and storage of cookies in the browser you use to access our website and to properly document this we use a consent management platform: CookieFirst. This technology is provided by Digital Data Solutions BV, Plantage Middenlaan 42a, 1018 DH, Amsterdam, The Netherlands. Website: https://cookiefirst.com referred to as CookieFirst.
When you access our website, a connection is established with CookieFirst’s server to give us the possibility to obtain valid consent from you to the use of certain cookies. CookieFirst then stores a cookie in your browser in order to be able to activate only those cookies to which you have consented and to properly document this. The data processed is stored until the predefined storage period expires or you request to delete the data. Certain mandatory legal storage periods may apply notwithstanding the aforementioned.
CookieFirst is used to obtain the legally required consent for the use of cookies. The legal basis for this is article 6(1)(c) of the General Data Protection Regulation (GDPR).
Data processing agreement
We have concluded a data processing agreement with CookieFirst. This is a contract required by data protection law, which ensures that data of our website visitors is only processed in accordance with our instructions and in compliance with the GDPR.
Server log files
Our website and CookieFirst automatically collect and store information in so-called server log files, which your browser automatically transmits to us. The following data is collected:
- Your consent status or the withdrawal of consent
- Your anonymised IP address
- Information about your Browser
- Information about your Device
- The date and time you have visited our website
- The webpage url where you saved or updated your consent preferences
- The approximate location of the user that saved their consent preference
- A universally unique identifier (UUID) of the website visitor that clicked the cookie banner