{"id":3,"date":"2025-10-27T11:35:11","date_gmt":"2025-10-27T11:35:11","guid":{"rendered":"https:\/\/gskpraxis-cngjpktkui.live-website.com\/?page_id=3"},"modified":"2025-11-19T15:02:19","modified_gmt":"2025-11-19T14:02:19","slug":"privacy-policy","status":"publish","type":"page","link":"http:\/\/gsk-praxis.de\/en\/privacy-policy\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"<div data-elementor-type=\"wp-page\" data-elementor-id=\"3\" class=\"elementor elementor-3\" data-elementor-post-type=\"page\">\n\t\t\t\t<div data-particle_enable=\"false\" data-particle-mobile-disabled=\"false\" class=\"elementor-element elementor-element-78e7eb5d e-flex e-con-boxed e-con e-parent\" data-id=\"78e7eb5d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-0ea5c6a elementor-widget elementor-widget-heading\" data-id=\"0ea5c6a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">Privacy Policy<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-34b236a8 elementor-widget elementor-widget-text-editor\" data-id=\"34b236a8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<section id=\"privacy-art13\" aria-labelledby=\"privacy-heading\">\n<h2 id=\"privacy-heading\"><strong style=\"font-size: 1rem;\">Status:<\/strong><span style=\"font-size: 1rem;\">&nbsp;19.11.2025<\/span><\/h2>\n<nav aria-label=\"Table of contents\">\n<ol>\n<li><a href=\"#verantwortlicher\">Name and address of the responsible party<\/a><\/li>\n<li><a href=\"#kontakt\">Contact options<\/a><\/li>\n<li><a href=\"#grundsaetze\">General information on data processing<\/a><\/li>\n<li><a href=\"#verarbeitungen\">Individual processing activities<\/a><\/li>\n<li><a href=\"#rechte\">Your rights<\/a><\/li>\n<li><a href=\"#aufsicht\">Competent supervisory authority<\/a><\/li>\n<\/ol>\n<\/nav>\n<h3 id=\"verantwortlicher\">1. Name and address of the responsible party<\/h3>\n<p>  <strong>GSK Practice \u2013 Vein Center K\u00f6nigstein im Taunus<br>  Owner: Taher Nazary<\/strong><br>  Frankfurter Str. 9a<br>  61462 K\u00f6nigstein im Taunus<\/p>\n<h3 id=\"kontakt\">2. Contact options<\/h3>\n<p>  Telephone: 06174-961870<br>  E-mail: <a href=\"mailto:mail@gsk-praxis.de\">mail@gsk-praxis.de<\/a><\/p>\n<h3 id=\"grundsaetze\">3. General information on data processing<\/h3>\n<p>  We process personal data in accordance with the GDPR and the TDDDG.<\/p>\n<ul>\n<li><strong>Legal basis:<\/strong> Consent (Art. 6 para. 1 lit. a in conjunction with Art. 7 GDPR), contract\/pre-contractual measures (Art. 6 para. 1 lit. b GDPR), legal obligation (Art. 6 para. 1 lit. c GDPR), legitimate interest (Art. 6 para. 1 lit. f GDPR), vital interests (Art. 6 para. 1 lit. d GDPR). For the storage\/reading of non-essential information on end devices, Section 25 of the German Telemedia Act (TDDG) applies (consent).<\/li>\n<li><strong>Storage duration\/deletion:<\/strong> We adhere to the principles of data minimization (Art. 5 para. 1 lit. c GDPR) and storage limitation (Art. 5 para. 1 lit. e GDPR). Data is deleted as soon as the purpose for which it was collected no longer applies and there are no legal obligations to retain it.<\/li>\n<li><strong>Recipient categories:<\/strong> Hosting\/IT service providers, analytics\/marketing service providers, communications providers, human resources management.<\/li>\n<li><strong>Third-country transfers:<\/strong> Insofar as data is transferred to third countries (especially the USA), we base this on adequacy decisions (EU-US Data Privacy Framework) and\/or EU Standard Contractual Clauses (SCCs) including any supplementary measures.<\/li>\n<li><strong>External links:<\/strong> External links are clearly identifiable as such. Data (e.g., IP address, time, referrer) is only transmitted to the target provider when clicked. This may also occur outside the EEA.<\/li>\n<\/ul>\n<h3 id=\"verarbeitungen\">4. Individual processing activities<\/h3>\n<h4 id=\"hosting\">4.1 Provision of the website (hosting and server log files)<\/h4>\n<p>  <strong>Purposes:<\/strong> Technical operation, IT security, content delivery<br>  <strong>Data:<\/strong> IP address, device\/hostname, operating system, browser type\/version, accessed file\/URL, date\/time, amount of data transferred, status codes<br>  <strong>Legal basis:<\/strong> Article 6 paragraph 1 letter f GDPR (legitimate interest in secure, stable operation); in the case of contract initiation\/fulfillment, additionally Article 6 paragraph 1 letter b GDPR.<br>  <strong>Recipient:<\/strong> Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany<a href=\"https:\/\/www.hetzner.com\/de\/legal\/privacy-policy\" target=\"_blank\" rel=\"noopener\">Data protection<\/a>)<br>  <strong>Order processing:<\/strong> Data processing agreement with Hetzner pursuant to Art. 28 GDPR<br>  <strong>Storage duration:<\/strong> Server logs are typically kept for 7\u201314 days, longer only for evidentiary purposes in the event of security incidents.<\/p>\n<h4 id=\"storage-cookies\">4.2 Local\/Session Storage and Cookies<\/h4>\n<p>  <strong>Purposes:<\/strong> Technically necessary functions, comfort, statistics, marketing<br>  <strong>Legal basis:<\/strong> Necessary: Art. 6 para. 1 lit. f GDPR; all others: Art. 6 para. 1 lit. a GDPR in conjunction with \u00a7 25 TDDDG<br>  <strong>Cancellation:<\/strong> Manageable at any time via the consent banner<\/p>\n<h4 id=\"consent\">4.3 Consent Management (Compliance GDPR\/CCPA Cookie Consent)<\/h4>\n<p>  <strong>Purpose:<\/strong> Obtaining, documenting and managing consents<br>  <strong>Legal basis:<\/strong> Article 6 paragraph 1 letter c GDPR (legal obligation) and Article 6 paragraph 1 letter f GDPR (verifiability)<br>  <strong>Data\/Device:<\/strong> Consent status, policy ID, timestamp (cookie\/local\/session storage)<br>  <strong>Recipient:<\/strong> Complianz BV, NL \u2013 local integration, no transfer to third countries<br>  <strong>Storage duration (examples):<\/strong> <code>cmplz_banner-status<\/code>, <code>cmplz_preferences<\/code>, <code>cmplz_statistics<\/code>, <code>cmplz_marketing<\/code>, <code>cmplz_policy_id<\/code> up to 365 days each; <code>cmplz_cookie_data<\/code> session<\/p>\n<h4 id=\"cdn\">4.4 Content Delivery\/External Content Delivery<\/h4>\n<p>  <strong>Purpose:<\/strong> Performance, availability, secure delivery of static content<br>  <strong>Legal basis:<\/strong> Article 6 paragraph 1 letter f GDPR (legitimate interest in fast, secure provision)<br>  <strong>Recipient:<\/strong> Google User Content \/ possibly CDN provider (see provider&#039;s privacy policy for details)<br>  <strong>Third country:<\/strong> USA; Coverage via EU-US DPF\/SCC<\/p>\n<h4 id=\"elementor\">4.5 Website builder (Elementor)<\/h4>\n<p>  <strong>Purpose:<\/strong> Content creation\/layout\/display<br>  <strong>Legal basis:<\/strong> Article 6 paragraph 1 letter f GDPR (functional, consistent presentation)<br>  <strong>A notice:<\/strong> Elementor is used for technical presentation; independent processing of visitor data beyond mandatory web server protocols is not intended.<\/p>\n<h4 id=\"gtm\">4.6 Tag management (Google Tag Manager)<\/h4>\n<p>  <strong>Purpose:<\/strong> Technical administration\/integration of tags<br>  <strong>Legal basis:<\/strong> Article 6 paragraph 1 letter a GDPR (if tools requiring consent are loaded), otherwise Article 6 paragraph 1 letter f GDPR<br>  <strong>Recipient\/Third country:<\/strong> Google Ireland\/USA (EU-US DPF\/SCC)<\/p>\n<h4 id=\"webfonts\">4.7 Webfonts<\/h4>\n<h5 id=\"webfonts-remote\">4.7.1 Google Fonts (remote integration)<\/h5>\n<p>  <strong>Purpose:<\/strong> Uniform font display<br>  <strong>Data:<\/strong> IP address, browser\/device, font resources retrieved<br>  <strong>Legal basis:<\/strong> Article 6 paragraph 1 letter a GDPR (consent) in conjunction with, where applicable, Section 25 TDDDG<br>  <strong>Recipient\/Third country:<\/strong> Google Ireland\/USA (EU-US DPF\/SCC)<br>  <strong>Alternative:<\/strong> Local integration eliminates the need for transmission (see 4.7.2).<\/p>\n<h5 id=\"webfonts-local\">4.7.2 Local Webfonts<\/h5>\n<p>  <strong>Purpose\/Legal basis:<\/strong> Uniform presentation, Art. 6 para. 1 lit. f GDPR; no transfer to third countries<\/p>\n<h4 id=\"ads\">4.8 Advertising\/Conversion Tracking (Google Ads)<\/h4>\n<p>  <strong>Purpose:<\/strong> Advertising placement and success measurement<br>  <strong>Legal basis:<\/strong> Article 6 paragraph 1 letter a GDPR in conjunction with Section 25 TDDDG (consent)<br>  <strong>Data:<\/strong> Online identifiers, IP address (truncated), device\/browser data, interactions, timestamps<br>  <strong>Recipient\/Third country:<\/strong> Google Ireland\/USA (EU-US DPF\/SCC)<br>  <strong>Cancellation:<\/strong> at any time in the consent banner<\/p>\n<h4 id=\"kontaktformular\">4.9 Contact form<\/h4>\n<p>  <strong>Purpose:<\/strong> Handling of requests<br>  <strong>Data:<\/strong> Contact and content data from the form<br>  <strong>Legal basis:<\/strong> Article 6 paragraph 1 letter a GDPR (consent) and\/or Article 6 paragraph 1 letter b GDPR (pre-contractual\/contractual); additionally Article 6 paragraph 1 letter f GDPR (general communication)<br>  <strong>Storage duration:<\/strong> until the processing of the request is completed, and subsequently in accordance with retention obligations.<\/p>\n<h4 id=\"kontakt\">4.10 Contact by telephone \/ email<\/h4>\n<p>  <strong>Purpose:<\/strong> Communication, initiation\/processing of orders<br>  <strong>Legal basis:<\/strong> Article 6(1)(b) GDPR; otherwise, Article 6(1)(f) GDPR<br>  <strong>Storage duration:<\/strong> in accordance with statutory retention periods or requirements<\/p>\n<h4 id=\"bewerbungen\">4.11 Applications<\/h4>\n<p>  <strong>Purpose:<\/strong> Conducting the application process, possibly establishing an employment relationship<br>  <strong>Legal basis:<\/strong> Article 6 paragraph 1 letter b GDPR; in the case of consent, Article 6 paragraph 1 letter a GDPR (revocation possible at any time); for the defense of claims, Article 6 paragraph 1 letter f GDPR<br>  <strong>Storage duration:<\/strong> In case of rejection, the data is stored for 6 months; if consent is given for inclusion in the applicant pool, for a maximum of 2 years (until revoked); if hired, the data is stored for the purpose of the employment relationship.<\/p>\n<h3 id=\"rechte\">5. Your rights<\/h3>\n<ul>\n<li>Right of access (Art. 15 GDPR)<\/li>\n<li>Rectification (Art. 16 GDPR)<\/li>\n<li>Erasure (Art. 17 GDPR)<\/li>\n<li>Restriction of processing (Art. 18 GDPR)<\/li>\n<li>Data portability (Art. 20 GDPR)<\/li>\n<li>Right to object (Art. 21 GDPR) to processing pursuant to Art. 6 para. 1 lit. e or f GDPR; in the case of direct marketing, at any time<\/li>\n<li>Complaint to a supervisory authority<\/li>\n<\/ul>\n<p>  <strong>Revocation of consent:<\/strong> Previously granted consent can be revoked at any time with effect for the future. The lawfulness of the processing carried out until the revocation remains unaffected.<\/p>\n<h3 id=\"aufsicht\">6. Competent supervisory authority<\/h3>\n<p>  <strong>The Hessian Commissioner for Data Protection and Freedom of Information<\/strong><br>  Gustav-Stresemann-Ring 1<br>  65189 Wiesbaden<br>  Website: <a href=\"https:\/\/datenschutz.hessen.de\" target=\"_blank\" rel=\"noopener\">https:\/\/datenschutz.hessen.de<\/a><br>\n<\/p><\/section>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Datenschutzerkl\u00e4rung Stand:&nbsp;19.11.2025 Name und Anschrift des Verantwortlichen Kontaktm\u00f6glichkeiten Allgemeines zur Datenverarbeitung Einzelne Verarbeitungst\u00e4tigkeiten Ihre Rechte Zust\u00e4ndige Aufsichtsbeh\u00f6rde 1. Name und Anschrift des Verantwortlichen GSK Praxis \u2013 Venenzentrum K\u00f6nigstein im Taunus Inhaber: Taher Nazary Frankfurter Str. 9a 61462 K\u00f6nigstein im Taunus 2. Kontaktm\u00f6glichkeiten Telefon: 06174-961870 E-Mail: mail@gsk-praxis.de 3. Allgemeines zur Datenverarbeitung Wir verarbeiten personenbezogene Daten im [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-3","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"http:\/\/gsk-praxis.de\/en\/wp-json\/wp\/v2\/pages\/3","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/gsk-praxis.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"http:\/\/gsk-praxis.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"http:\/\/gsk-praxis.de\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/gsk-praxis.de\/en\/wp-json\/wp\/v2\/comments?post=3"}],"version-history":[{"count":17,"href":"http:\/\/gsk-praxis.de\/en\/wp-json\/wp\/v2\/pages\/3\/revisions"}],"predecessor-version":[{"id":1082,"href":"http:\/\/gsk-praxis.de\/en\/wp-json\/wp\/v2\/pages\/3\/revisions\/1082"}],"wp:attachment":[{"href":"http:\/\/gsk-praxis.de\/en\/wp-json\/wp\/v2\/media?parent=3"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}