Privacy Policy

The legally binding version can be found here.

Preamble

The following privacy policy is intended to inform you about the types of personal data (hereinafter referred to as ‘data’) we process, the purposes for which we do so, and the extent of such processing.

This privacy policy applies to all processing of personal data carried out by us on our websites (hereinafter referred to as the ‘online service’).

The terms used are gender-neutral.

Date: 8 December 2025

Table of Contents

  • Preamble
  • Data Controller
  • Contact details of the Data
  • Protection Officer
  • Overview of processing activities
  • Relevant legal bases
  • Security measures
  • Disclosure of personal data
  • International data transfers
  • General information on data storage and deletion
  • Rights of data subjects
  • Providers and services used in the course of business
  • Provision of the online service and web hosting
  • Use of cookies
  • Contact and enquiry management
  • Web analytics, monitoring and optimisation
  • Plug-ins, embedded functions and content
  • Amendments and updates

Data controller

Hormon- und Stoffwechselzentrum Mainz MVZ GmbH
Wallstraße 3–7
55122 Mainz
Germany
Email address: info@prof-wuester.de
Telephone: +49 6131 588480

Contact details for the Data Protection Officer

datenschutz@hormon-stoffwechselzentrum.de

 

Overview of data processing activities

The following overview summarises the types of data processed and the purposes of such processing, and identifies the data subjects.
Types of data processed

  • Master data
  • Payment data
  • Location data
  • Contact details
  • Content data
  • Contract data
  • Usage data
  • Meta, communication and procedural data
  • Log data

Categories of data subjects

  • Service recipients and clients
  • Prospective customers
  • Communication partners
  • Users
  • Business and contractual partners

Purposes of processing

  • Provision of contractual services and fulfilment of contractual obligations
  • Communication
  • Security measures
  • Audience measurement
  • Tracking
  • Office and organisational procedures
  • Target group identification
  • Organisational and administrative procedures
  • Feedback
  • Marketing
  • Profiles containing user-related information
  • Provision of our online services and user-friendliness
  • IT infrastructure
  • Business processes and business management procedures

Relevant legal bases

Relevant legal bases under the GDPR: Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country of residence or where we are based. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.

  • Consent (Article 6(1), first sentence, point (a) of the GDPR) – The data subject has given their consent to the processing of their personal data for a specific purpose or for several specific purposes.
  • Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR) – The processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.
  • Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR) – The processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the interests, fundamental rights and freedoms of the data subject which require the protection of personal data do not override those interests.

National data protection regulations in Germany: In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Act on the Protection against the Misuse of Personal Data in Data Processing (Federal Data Protection Act – BDSG). The BDSG contains, in particular, specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer of data, as well as automated decision-making in individual cases, including profiling. Furthermore, data protection laws of the individual federal states may apply.

National data protection regulations in Germany: In addition to the references to the applicability of the GDPR and the Swiss Data Protection Act (DSG): These data protection notices serve to provide information in accordance with both the Swiss Data Protection Act (DSG) and the General Data Protection Regulation (GDPR). For this reason, please note that the terms used in the GDPR are employed here due to its broader geographical scope and clarity. In particular, instead of the terms ‘processing’ of ‘personal data’, ‘overriding interest’ and ‘personal data requiring special protection’ used in the Swiss Data Protection Act, the terms ‘processing’ of ‘personal data’, ‘legitimate interest’ and ‘special categories of data’ used in the GDPR are employed. However, the legal meaning of these terms continues to be determined in accordance with the Swiss Data Protection Act (DSG) within the scope of its application.

Security measures

In accordance with statutory requirements, and taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the varying likelihood and severity of threats to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access to, input of, disclosure of, and availability of the data, and ensuring its segregation. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is deleted and that appropriate action is taken in the event of a data breach. Furthermore, we take the protection of personal data into account right from the development and selection of hardware, software and procedures, in accordance with the principle of data protection by design and through privacy-friendly default settings.

Securing online connections using TLS/SSL encryption technology (HTTPS): To protect users’ data transmitted via our online services from unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of ‘HTTPS’ in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.

Transfer of personal data

In the course of our processing of personal data, it may happen that such data is transferred to or disclosed to other bodies, companies, legally independent organisational units or individuals. Recipients of this data may include, for example, service providers commissioned to carry out IT tasks or providers of services and content integrated into a website. In such cases, we comply with the statutory requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.

Data transfer within the group of companies: Data transfer within the group of companies: We may transfer personal data to other companies within our group of companies or grant them access to such data. This data transfer is carried out on the basis of our legitimate business and operational interests. By this we mean, for example, the improvement of business processes, ensuring efficient and effective internal communication, the optimal use of our human and technological resources, and the ability to make informed business decisions.

In certain cases, the disclosure of data may also be necessary in order to fulfil our contractual obligations, or it may be based on the consent of the data subjects or on a statutory authorisation.

Data transfer within the organisation: We may transfer personal data to other departments or units within our organisation, or grant them access to such data. Where the transfer of data is for administrative purposes, it is based on our legitimate business and operational interests, or takes place where it is necessary to fulfil our contractual obligations, or where the data subjects have given their consent or there is a legal authorisation.

International data transfers

Data processing in third countries: Where we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or where this occurs in connection with the use of third-party services or the disclosure or transfer of data to other bodies or bodies or organisations (which can be identified by the postal address of the respective provider or where the privacy policy expressly refers to data transfers to third countries), this is always carried out in accordance with the statutory requirements.

For data transfers to the USA, we rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the European Commission dated 10 July 2023. In addition, we have entered into standard contractual clauses with the relevant providers, which comply with the European Commission’s requirements and set out contractual obligations to protect your data.

This dual safeguard ensures comprehensive protection of your data: the DPF forms the primary layer of protection, whilst the standard contractual clauses serve as an additional safeguard. Should any changes arise within the framework of the DPF, the standard contractual clauses act as a reliable fallback option. In this way, we ensure that your data remains adequately protected at all times, even in the event of any political or legal changes.

For each service provider, we will inform you whether they are certified under the DPF and whether standard contractual clauses are in place. Further information on the DPF and a list of certified companies can be found on the US Department of Commerce’s website at https://www.dataprivacyframework.gov/ (in English).

Appropriate security measures apply to data transfers to other third countries, in particular standard contractual clauses, explicit consent or transfers required by law. Information on transfers to third countries and applicable adequacy decisions can be found on the European Commission’s website: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

General information on data storage and deletion

We delete the personal data we process in accordance with legal provisions as soon as the underlying consents are withdrawn or there are no longer any legal grounds for processing. This applies to cases where the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule apply where legal obligations or specific interests require the data to be retained or archived for a longer period.

In particular, data which must be retained for commercial or tax law reasons, or where storage is necessary for the purposes of legal proceedings or to protect the rights of other natural or legal persons, must be archived accordingly.

Our privacy policy contains additional information on the retention and erasure of data, which applies specifically to certain processing operations.

Where there are several specifications regarding the retention period or deletion deadlines for a particular item of data, the longest period shall always apply. We process data that is no longer retained for its originally intended purpose, but rather due to legal requirements or other reasons, exclusively for the purposes that justify its retention.

Retention and deletion of data: The following general time limits apply to the retention and archiving of data under German law:

  • 10 years – retention period for books and records, annual accounts, inventories, management reports, opening balance sheets, as well as the working instructions and other organisational documents necessary for their understanding (Section 147(1)(1) in conjunction with (3) of the German Fiscal Code (AO), Section 14b(1) of the Value Added Tax Act (UStG), Section 257(1)(1) in conjunction with (4) of the Commercial Code (HGB)).
  • 8 years – accounting documents, such as invoices and expense receipts (Section 147(1)(4) and (4a) in conjunction with (3), first sentence, of the German Fiscal Code (AO) and Section 257(1)(4) in conjunction with (4) of the German Commercial Code (HGB)).
  • 6 years – Other business documents: commercial or business correspondence received, copies of commercial or business correspondence sent, other documents in so far as they are relevant for tax purposes, e.g. hourly pay slips, payroll statements, costing documents, price labels, as well as payroll records, provided they are not already accounting vouchers, and cash register receipts (Section 147(1)(2), (3) and (5) in conjunction with (3) of the German Fiscal Code (AO), Section 257(1)(2) and (3) in conjunction with (4) of the German Commercial Code (HGB)).
  • 3 years – Data required to take into account potential warranty and compensation claims or similar contractual claims and rights, and to process related enquiries, based on previous business experience and standard industry practices, is retained for the duration of the standard statutory limitation period of three years (Sections 195 and 199 of the German Civil Code (BGB)).

Start of a time limit at the end of the year: If a time limit does not expressly commence on a specific date and lasts for at least one year, it automatically begins at the end of the calendar year in which the event triggering the time limit occurred. In the case of ongoing contractual relationships under which data is stored, the event triggering the time limit is the date on which the notice of termination or other termination of the legal relationship takes effect.

Rights of data subjects

Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:

  • Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. Where personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
  • Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
  • Right of access: You have the right to request confirmation as to whether data concerning you is being processed, and to obtain access to that data, as well as further information and a copy of the data, in accordance with the statutory requirements.
  • Right to rectification: In accordance with the statutory provisions, you have the right to request that data relating to you be completed or that any inaccurate data relating to you be rectified.
  • Right to erasure and restriction of processing: In accordance with the statutory provisions, you have the right to request that data relating to you be erased without delay or, alternatively, in accordance with the statutory provisions, to request a restriction on the processing of the data.
  • Right to data portability: You have the right, in accordance with the statutory provisions, to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another data controller.
  • Complaint to a supervisory authority: In accordance with the statutory requirements and without prejudice to any other administrative or judicial remedy, you also have the right to lodge a complaint with a data protection supervisory authority, in particular a supervisory authority in the Member State in which you are habitually resident, the supervisory authority for your place of work or the location of the alleged infringement, should you consider that the processing of your personal data infringes the GDPR.

Providers and services used in the course of our business activities

In the course of our business activities, we use additional third-party services, platforms, interfaces or plug-ins (hereinafter referred to as ‘services’), in compliance with legal requirements. Their use is based on our interests in the proper, lawful and cost-effective management of our business operations and our internal organisation.

  • Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact details (e.g. postal and email addresses or telephone numbers); Content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation); Contract data (e.g. subject matter of the contract, term, customer category).
  • Data subjects: Service recipients and clients; prospective customers; business and contractual partners.
  • Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; administrative and organisational procedures; business processes and management procedures.
  • Retention and erasure: Erasure in accordance with the details set out in the section ‘General information on data storage and erasure’.
  • Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Further information on processing procedures, methods and services:

  • Doctolib (link): On our website, we provide a link to the online appointment booking service via Doctolib. When you visit our website, no personal data is transferred to Doctolib, as no content from the service is embedded. It is only when you click on the relevant link that you leave our website and are redirected directly to the Doctolib website. From this point onwards, data processing is carried out solely under the responsibility of Doctolib; service provider: Doctolib GmbH, Mehringdamm 51, 10961 Berlin. Legal basis: The link is provided on the basis of our legitimate interest pursuant to Article 6(1)(f) of the GDPR, namely to offer our patients a convenient way to book appointments.; Website: https://www.doctolib.de. Privacy policy: https://media.doctolib.com/image/upload/v1753974148/legal/B2C-PrivacyPolicy-JULY_25-DE.pdf. Data processing agreement: Provided by the service provider.

Provision of the online service and web hosting

We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.

  • Types of data processed: usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, individuals involved). Log data (e.g. log files relating to logins, data retrieval or access times).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)). Security measures.
  • Retention and erasure: Erasure in accordance with the details set out in the section ‘General information on data storage and erasure’.
  • Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).

Further information on processing operations, procedures and services:

  • Provision of the online service on rented storage space: To provide our online service, we use storage space, computing capacity and software which we rent or otherwise obtain from a relevant server provider (also known as a ‘web host’); Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
  • Collection of access data and log files: Access to our online service is logged in the form of so-called ‘server log files’. Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, confirmation of successful access, browser type and version, the user’s operating system, the referrer URL (the page visited previously) and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, e.g. to prevent server overload (particularly in the event of malicious attacks, known as DDoS attacks), and, on the other hand, to ensure server capacity utilisation and stability; legal basis: legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
  • Deletion of data: Log file information is stored for a maximum of 30 days and is then deleted or anonymised. Data which must be retained for evidential purposes is exempt from deletion until the relevant incident has been fully resolved.
  • Contabo: We host our website with Contabo GmbH, Aschauer Straße 32a, 81549 Munich, Germany (Contabo). When you visit our website, your personal data (e.g. IP addresses in log files) is processed on Contabo’s servers. The use of Contabo is based on Article 6(1)(f) of the GDPR. We have a legitimate interest in ensuring that our website is presented, provided and secured as reliably as possible. We have entered into a data processing agreement (DPA) with Contabo in accordance with Article 28 of the GDPR. This is a contract required under data protection law, which ensures that Contabo processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR. Further information on Contabo’s data protection policy can be found at: https://contabo.com.
  • Yoast SEO: Optimisation of websites for search engines; Service provider: Yoast B.V., Don Emanuelstraat 3, 6602 GX Wijchen, Netherlands; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR); Website: https://yoast.com/; Privacy policy: https://www.newfold.com/privacy-center?currencyCode=EUR&langPref=de. Further information: Operated within our own hosting environment.
  • Use of the ‘WPML – WordPress Multilingual Plugin’: We use the ‘WPML’ plugin on our website to display content in multiple languages. WPML is used solely to provide different language versions of the website. No personal data is processed. However, WPML does set cookies to provide the multilingual functions. Without these cookies, the website cannot be displayed correctly in the desired language. Service provider: OnTheGoSystems Limited, Mercedes Barreda 22/F 3 Lockhart Road, Hong Kong, Wanchai, China; website: https://wpml.org/. Privacy policy: https://wpml.org/documentation/privacy-policy-and-gdpr-compliance/. Data processing agreement: As no personal data is processed, there is no data processing relationship.
  • WP Rocket: Caching and loading optimisation – functions designed to store certain website content so that it can be loaded more quickly upon repeated access. This reduces loading times and improves the user experience; Service provider: SAS WP MEDIA, Address: 4 rue de la République, 69001 LYON, France; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://wp-rocket.me/de/; Privacy policy: https://wp-rocket.me/privacy-policy/. Further information: Operated within our own hosting environment.

Use of cookies

The term ‘cookies’ refers to functions that store and retrieve information on users’ devices. Cookies may also be used for various purposes, such as to ensure the functionality, security and user-friendliness of online services, as well as to analyse visitor traffic. We use cookies in accordance with legal requirements. To this end, we obtain users’ consent in advance where necessary. Where consent is not required, we rely on our legitimate interests. This applies where the storage and retrieval of information is essential to provide explicitly requested content and functions. This includes, for example, the storage of settings and ensuring the functionality and security of our online service. Consent may be withdrawn at any time. We provide clear information on the scope of this and which cookies are used.

Notes on the legal basis under data protection law: Whether we process personal data using cookies depends on consent. Where consent has been given, this serves as the legal basis. Without consent, we rely on our legitimate interests, which are explained above in this section and in the context of the respective services and procedures.

Storage period: With regard to the storage period, a distinction is made between the following types of cookies:

  • Temporary cookies (also known as session cookies): Temporary cookies are deleted at the latest once a user has left an online service and closed their device (e.g. browser or mobile application).
  • Permanent cookies: Permanent cookies remain stored even after the device has been closed. This allows, for example, the login status to be saved and preferred content to be displayed immediately when the user visits a website again. Similarly, user data collected via cookies may be used for audience measurement. Unless we provide users with explicit information regarding the type and storage period of cookies (e.g. when seeking consent), they should assume that these are permanent and that the storage period may be up to two years.

General information on withdrawal of consent and objection (opt-out): Users may withdraw the consent they have given at any time and may also object to the processing in accordance with legal requirements, including via their browser’s privacy settings.

  • Types of data processed: Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, individuals involved).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Consent (Article 6(1), first sentence, point (a) of the GDPR).

Further information on processing procedures, methods and services:

  • Processing of cookie data on the basis of consent: We use a consent management solution through which users’ consent is obtained for the use of cookies or for the procedures and providers specified within the consent management solution. This procedure serves to obtain, log, manage and revoke consents, in particular with regard to the use of cookies and similar technologies employed to store, read and process information on users’ end devices. As part of this procedure, users’ consent is obtained for the use of cookies and the associated processing of information, including the specific processing activities and providers mentioned in the consent management procedure. Users also have the option to manage and withdraw their consent. Consent declarations are stored to avoid having to request consent again and to be able to provide evidence of consent in accordance with legal requirements. Storage takes place on the server and/or in a cookie (a so-called ‘opt-in’ cookie) or by means of similar technologies, in order to be able to associate the consent with a specific user or their device. In the absence of specific information regarding the providers of consent management services, the following general guidelines apply: Consent is stored for up to two years. A pseudonymous user identifier is created, which is stored together with the time of consent, details of the scope of consent (e.g. relevant categories of cookies and/or service providers) and information about the browser, the system and the device used; legal basis: consent (Article 6(1), first sentence, point (a) of the GDPR).
  • BorlabsCookie: Storage and management of consents (consent to cookies and data processing), logging of user decisions, display of notices regarding data protection and cookies, enabling users to withdraw or amend their consents; Service provider: Processed on servers and/or computers under the provider’s own responsibility for data protection; Website: https://de.borlabs.io/borlabs-cookie/. Further information: An individual user ID, language, types of consent and the time at which consent was given are stored on the server and in a cookie on the user’s device.

Contact and Enquiry Management

When you contact us (e.g. by post, via the contact form, by email, by telephone or via social media), as well as in the context of existing user and business relationships, the details provided by the enquirers are processed to the extent necessary to respond to the enquiries and to carry out any requested actions.

  • Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. textual or visual messages and posts, as well as related information such as details of authorship or the time of creation); Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, persons involved).
  • Data subjects: Communication partners.
  • Purposes of processing: Communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form). Provision of our online service and user-friendliness.
  • Storage and erasure: Erasure in accordance with the details set out in the section ‘General information on data storage and erasure’.
  • Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).

Further information on processing operations, procedures and services:

  • Contact form: When you contact us via our contact form, by email or through other communication channels, we process the personal data provided to us in order to respond to and handle the relevant enquiry. This generally includes details such as your name, contact details and, where applicable, any further information provided to us that is necessary for the appropriate handling of your enquiry. We use this data exclusively for the stated purpose of establishing contact and communication; legal bases: performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
  • Contact Form 7: Management of contact enquiries and communication; service provider: Rock Lobster, LLC; legal bases: legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); website: https://contactform7.com/. Further information: operated within our own hosting environment.

Web analytics, monitoring and optimisation

Web analytics (also referred to as ‘reach measurement’) is used to analyse visitor traffic to our online platform and may include pseudonymous data on visitors’ behaviour, interests or demographic information, such as age or gender. With the help of reach analysis, we can, for example, identify at what times our online service or its functions and content are used most frequently, or encourage repeat visits. It also enables us to identify which areas require optimisation.

In addition to web analytics, we may also use testing procedures to, for example, test and optimise different versions of our online service or its components.

Unless otherwise stated below, profiles – i.e. data aggregated to represent a usage session – may be created for these purposes, and information may be stored in a browser or on a device and subsequently retrieved. The data collected includes, in particular, websites visited and the elements used there, as well as technical information such as the browser used, the computer system used and details of usage times. Where users have consented to the collection of their location data by us or by the providers of the services we use, the processing of location data is also possible.

In addition, users’ IP addresses are stored. However, we use an IP masking procedure (i.e. pseudonymisation by shortening the IP address) to protect users. In general, no personally identifiable user data (such as email addresses or names) are stored as part of web analytics, A/B testing and optimisation; instead, pseudonyms are used. This means that neither we nor the providers of the software used know the actual identity of the users, but only the information stored in their profiles for the purposes of the respective procedures.

Information on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data are processed on the basis of our legitimate interests (i.e. our interest in providing efficient, economical and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies contained in this Privacy Policy.

  • Types of data processed: Usage data (e.g. page views and length of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Audience measurement (e.g. access statistics, identification of returning visitors); profiles containing user-related information (creation of user profiles).
  • Retention and deletion: Deletion in accordance with the information provided in the section “General Information on Data Retention and Deletion”. Cookies may be stored for up to 2 years (unless otherwise specified, cookies and similar storage methods may be stored on users’ devices for a period of two years).
  • Security measures: IP masking (pseudonymisation of the IP address).
  • Legal bases: Consent (Art. 6(1)(a) GDPR); Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Google Tag Manager: We use Google Tag Manager, software provided by Google that enables us to centrally manage so-called website tags via a user interface. Tags are small code elements on our website that are used to record and analyse visitor activity. This technology helps us improve our website and the content offered on it. Google Tag Manager itself does not create user profiles, store cookies containing user profiles or carry out independent analyses. Its function is limited to simplifying and making more efficient the integration and management of tools and services that we use on our website. Nevertheless, when Google Tag Manager is used, users’ IP addresses are transmitted to Google, which is technically necessary in order to implement the services we use. Cookies may also be set in this process. However, such data processing only takes place if services are integrated via Tag Manager. For more detailed information about these services and their data processing activities, please refer to the relevant sections of this Privacy Policy; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6(1)(a) GDPR); Website: marketingplatform.google.com; Privacy Policy: policies.google.com/privacy; Data Processing Agreement: business.safety.google/adsprocessorterms. Basis for third-country transfers: Data Privacy Framework (DPF), Standard Contractual Clauses (business.safety.google/adsprocessorterms).

Plug-ins, Embedded Functions and Content

We integrate functional and content elements into our online services that are obtained from the servers of their respective providers (hereinafter referred to as “third-party providers”). These may include, for example, graphics, videos or maps (hereinafter collectively referred to as “content”).

The integration of such content always requires the third-party providers to process users’ IP addresses, as without the IP address they would not be able to transmit the content to the users’ browsers. The IP address is therefore necessary in order to display this content or these functions. We endeavour to use only content whose respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible graphics, also referred to as “web beacons”) for statistical or marketing purposes. Pixel tags can be used to evaluate information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the users’ devices and may contain, among other things, technical information about the browser and operating system, referring websites, the time of the visit and other information about the use of our online services. This information may also be combined with information from other sources.

Information on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is consent. Otherwise, user data are processed on the basis of our legitimate interests (i.e. our interest in providing efficient, economical and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies contained in this Privacy Policy.

  • Types of data processed: Usage data (e.g. page views and length of visit, click paths, intensity and frequency of use, device types and operating systems used, interactions with content and functions); meta, communication and procedural data (e.g. IP addresses, time information, identification numbers, persons involved); location data (information on the geographical position of a device or person).
  • Data subjects: Users (e.g. website visitors, users of online services).
  • Purposes of processing: Provision of our online services and user-friendliness; audience measurement (e.g. access statistics, identification of returning visitors); tracking (e.g. interest-/behaviour-based profiling, use of cookies); audience segmentation; marketing.
  • Retention and deletion: Deletion in accordance with the information provided in the section “General Information on Data Retention and Deletion”. Cookies may be stored for up to 2 years (unless otherwise specified, cookies and similar storage methods may be stored on users’ devices for a period of two years).
  • Legal bases: Consent (Art. 6(1)(a) GDPR); Legitimate interests (Art. 6(1)(f) GDPR).

Further information on processing operations, procedures and services:

  • Google Fonts (hosted on our own server): Provision of font files for the user-friendly presentation of our online services; Service provider: Google Fonts are hosted on our server; no data are transmitted to Google; Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).
  • Google Maps: We integrate maps provided by the Google Maps service. The data processed may include, in particular, users’ IP addresses and location data; Service provider: Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland; Legal basis: Consent (Art. 6(1)(a) GDPR); Website: mapsplatform.google.com; Privacy Policy: policies.google.com/privacy. Basis for third-country transfers: Data Privacy Framework (DPF).
  • YouTube Videos: Videos stored on YouTube are embedded within our online services. These YouTube videos are integrated via a special domain using the “youtube-nocookie” component in so-called “Privacy-Enhanced Mode”. In Privacy-Enhanced Mode, until the video is started, only information including your IP address and information about your browser and device may be stored on your device in cookies or by means of comparable technologies that YouTube requires to display, control and optimise the video. Once you play the videos, additional information may be processed by YouTube for the purpose of analysing usage behaviour, storing information in the user profile and personalising content and advertisements. Cookies may be stored for up to two years; Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6(1)(a) GDPR); Website: youtube.com; Privacy Policy: policies.google.com/privacy; Basis for third-country transfers: Data Privacy Framework (DPF). Further information: support.google.com/youtube/answer/171780.

Amendments and Updates

We ask you to regularly review the contents of our Privacy Policy. We will amend the Privacy Policy whenever changes to the data processing activities we carry out make this necessary. We will inform you whenever such changes require action on your part (e.g. consent) or any other form of individual notification.

Where we provide addresses and contact details of companies and organisations in this Privacy Policy, please note that addresses may change over time. We therefore ask you to verify the relevant details before contacting them.

Detailed Data Protection Information

Below, we provide information and documents containing legally required notices on the processing of personal data as well as other mandatory information:

Processing of personal data in connection with your use of our online services

Detailed information on the processing of your personal data in connection with the use of our online services and our website can be found on the left (desktop view) or above (mobile view).

Processing of personal data in connection with patient treatment

Detailed information on the processing of your data in connection with your treatment as a patient can be found here (available in German only).

Detailed information on the processing of your personal data in connection with the use of medical online tools (e.g. appointment scheduling, video consultations, online medical history forms) can be found in the supplementary data protection information for patients regarding the use of medical tools, here (available in German only).

Processing of personal data in connection with reporting to the State Cancer Registry

Detailed information on reporting to the State Cancer Registry can be found here (available in German only).

Processing of personal data in connection with the electronic patient record (ePA)

Detailed information on the electronic patient record (ePA) can be found here (available in German only).

Processing of personal data in connection with job applications

Detailed information on the processing of your data in connection with your application can be found here (available in German only).

Processing of personal data in connection with contractual and business relationships

Detailed information on the processing of your data in connection with our business relationship can be found here (available in German only).

Change Cookie settings
Contact
Hormon- und Stoffwechselzentrum MVZ GmbH · Prof. Dr. med. Dr. h. c. Christian Wüster · Wallstraße 3–7 · 55122 Mainz · Telephone: 06131 58848-0 · Private Patient: 06131 58848-18 · Emergency Phone: 06131 58848-11 · Fax: 06131 58848-48 · E-Mail: info@prof-wuester.de · E-Mail für Kolleginnen und Kollegen: mainzmvz@praxis.tm.kim.telematik
© 2026 Hormon- und Stoffwechselzentrum MVZ GmbH   
Doctolib Make an appointment online Click here