EN

Introduction

Introduction

Introduction

AIRAdoc GmbH, Am BioPark 13, 93053 Regensburg, Germany, including its subsidiaries (hereinafter collectively referred to as "the Company," "we," or "us"), takes the protection of your personal data very seriously.

Insofar as we act as the controller within the meaning of the GDPR, we would like to provide you with comprehensive information about our data protection practices in this privacy policy in accordance with Art. 13 GDPR. This includes any processing of personal data on our marketing websites as well as the processing of user data within our AIRAdoc product. These processing operations are listed in detail in sections B and C. For processing activities in which we act solely as a processor, our data processing agreement with the customer pursuant to Art. 28 GDPR applies.

With the implementation of the EU General Data Protection Regulation (Regulation (EU) 2016/679; hereinafter "GDPR"), we, as the data controller, have been assigned additional obligations to ensure the protection of the personal data of the data subjects. In the following, we also refer to you as the data subject as "user," "customer," "you," or "data subject." Furthermore, we are subject to the additional provisions of the Federal Data Protection Act (hereinafter "BDSG"), which specifies and expands the requirements of the GDPR.

In cases where we decide alone or jointly with others on the purposes and means of data processing, we are particularly obliged to inform you transparently about the nature, scope, purpose, duration, and legal basis of the processing (in accordance with Articles 13 and 14 of the GDPR). With this statement (hereinafter referred to as the "Privacy Policy"), we inform you about how we process your personal data.

This privacy policy is divided into three parts. Part A (General Provisions) informs you about the legal basis of data protection. Part B (Marketing Websites) provides specific information about data protection issues that are relevant when using our marketing websites. Part C (AIRAdoc) provides specific information on data protection issues relevant to the use of the AIRAdoc software provided by us. Appendix 1 provides information on the processors from third countries used for certain processing activities. Appendix 2 provides information on our processors within the EEA

AIRAdoc GmbH, Am BioPark 13, 93053 Regensburg, Germany, including its subsidiaries (hereinafter collectively referred to as "the Company," "we," or "us"), takes the protection of your personal data very seriously.

Insofar as we act as the controller within the meaning of the GDPR, we would like to provide you with comprehensive information about our data protection practices in this privacy policy in accordance with Art. 13 GDPR. This includes any processing of personal data on our marketing websites as well as the processing of user data within our AIRAdoc product. These processing operations are listed in detail in sections B and C. For processing activities in which we act solely as a processor, our data processing agreement with the customer pursuant to Art. 28 GDPR applies.

With the implementation of the EU General Data Protection Regulation (Regulation (EU) 2016/679; hereinafter "GDPR"), we, as the data controller, have been assigned additional obligations to ensure the protection of the personal data of the data subjects. In the following, we also refer to you as the data subject as "user," "customer," "you," or "data subject." Furthermore, we are subject to the additional provisions of the Federal Data Protection Act (hereinafter "BDSG"), which specifies and expands the requirements of the GDPR.

In cases where we decide alone or jointly with others on the purposes and means of data processing, we are particularly obliged to inform you transparently about the nature, scope, purpose, duration, and legal basis of the processing (in accordance with Articles 13 and 14 of the GDPR). With this statement (hereinafter referred to as the "Privacy Policy"), we inform you about how we process your personal data.

This privacy policy is divided into three parts. Part A (General Provisions) informs you about the legal basis of data protection. Part B (Marketing Websites) provides specific information about data protection issues that are relevant when using our marketing websites. Part C (AIRAdoc) provides specific information on data protection issues relevant to the use of the AIRAdoc software provided by us. Appendix 1 provides information on the processors from third countries used for certain processing activities. Appendix 2 provides information on our processors within the EEA

AIRAdoc GmbH, Am BioPark 13, 93053 Regensburg, Germany, including its subsidiaries (hereinafter collectively referred to as "the Company," "we," or "us"), takes the protection of your personal data very seriously.

Insofar as we act as the controller within the meaning of the GDPR, we would like to provide you with comprehensive information about our data protection practices in this privacy policy in accordance with Art. 13 GDPR. This includes any processing of personal data on our marketing websites as well as the processing of user data within our AIRAdoc product. These processing operations are listed in detail in sections B and C. For processing activities in which we act solely as a processor, our data processing agreement with the customer pursuant to Art. 28 GDPR applies.

With the implementation of the EU General Data Protection Regulation (Regulation (EU) 2016/679; hereinafter "GDPR"), we, as the data controller, have been assigned additional obligations to ensure the protection of the personal data of the data subjects. In the following, we also refer to you as the data subject as "user," "customer," "you," or "data subject." Furthermore, we are subject to the additional provisions of the Federal Data Protection Act (hereinafter "BDSG"), which specifies and expands the requirements of the GDPR.

In cases where we decide alone or jointly with others on the purposes and means of data processing, we are particularly obliged to inform you transparently about the nature, scope, purpose, duration, and legal basis of the processing (in accordance with Articles 13 and 14 of the GDPR). With this statement (hereinafter referred to as the "Privacy Policy"), we inform you about how we process your personal data.

This privacy policy is divided into three parts. Part A (General Provisions) informs you about the legal basis of data protection. Part B (Marketing Websites) provides specific information about data protection issues that are relevant when using our marketing websites. Part C (AIRAdoc) provides specific information on data protection issues relevant to the use of the AIRAdoc software provided by us. Appendix 1 provides information on the processors from third countries used for certain processing activities. Appendix 2 provides information on our processors within the EEA

A. General provisions

A. General provisions

A. General provisions

1. Definitions

1. Definitions

1. Definitions

In accordance with Art. 4 GDPR, this privacy policy is based on the following definitions:

In accordance with Art. 4 GDPR, this privacy policy is based on the following definitions:

In accordance with Art. 4 GDPR, this privacy policy is based on the following definitions:

"Personal data" (Article 4(1) GDPR)

Means any information relating to an identified or identifiable natural person ("data subject"). A person is considered identifiable if they can be identified directly or indirectly, in particular by association with an identifier such as a name, an identification number, location data, an online identifier, or one or more special characteristics that express the physical, physiological, genetic, psychological, economic, cultural, or social identity of that natural person. Identifiability may also be achieved by linking different pieces of information or by additional knowledge. The form of the information (photos, videos, audio recordings, etc.) is irrelevant.

"Processing" (Art. 4 No. 2 GDPR)

Refers to any operation or set of operations performed on personal data, with or without the aid of automated processes. This includes the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of data, as well as the change of the original purpose.

"Controller" (Art. 4 No. 7 GDPR)

Refers to the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of the processing of personal data.

"Processor" (Art. 4 No. 8 GDPR)

Refers to a natural or legal person, public authority, agency or other body that processes personal data on behalf of the controller, in particular according to the controller's instructions (e.g. IT service providers). In the context of data protection law, a processor is not considered a third party.

"Third party" (Art. 4 No. 10 GDPR)

Refers to a natural or legal person, public authority, agency, or other body other than the data subject, the controller, the processor, and the persons who, under the direct authority of the controller or processor, are authorized to process personal data. This includes other legal entities belonging to the same group.

"Consent" (Art. 4 No. 11 GDPR)

Of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

"Special categories of personal data" (Art. 9 (1) GDPR)

Are data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation. The processing of such data is subject to different laws, which are explained in more detail in this privacy policy at the relevant points with explicit reference to these categories.

2. Information about the controller

2. Information about the controller

2. Information about the controller

We are the controller responsible for the processing of your personal data within the meaning of Art. 4 No. 7 GDPR:


AIRAdoc GmbH

Am BioPark 13

93053 Regensburg


Managing Director: Prof. Dr. Thomas Bolz

Email: info@airadoc.com


For further information about our company, please refer to the legal notice on our website.

We are the controller responsible for the processing of your personal data within the meaning of Art. 4 No. 7 GDPR:


AIRAdoc GmbH

Am BioPark 13

93053 Regensburg


Managing Director: Prof. Dr. Thomas Bolz

Email: info@airadoc.com


For further information about our company, please refer to the legal notice on our website.

We are the controller responsible for the processing of your personal data within the meaning of Art. 4 No. 7 GDPR:


AIRAdoc GmbH

Am BioPark 13

93053 Regensburg


Managing Director: Prof. Dr. Thomas Bolz

Email: info@airadoc.com


For further information about our company, please refer to the legal notice on our website.

3. Data Protection Officer

3. Data Protection Officer

3. Data Protection Officer

If you have any questions about data protection, our data protection officer is available at any time:


Jonathan Bollig

Am BioPark 13

93053 Regensburg


Email: datenschutz@airadoc.com


For further information about our company, please refer to the legal notice on our website.

If you have any questions about data protection, our data protection officer is available at any time:


Jonathan Bollig

Am BioPark 13

93053 Regensburg


Email: datenschutz@airadoc.com


For further information about our company, please refer to the legal notice on our website.

If you have any questions about data protection, our data protection officer is available at any time:


Jonathan Bollig

Am BioPark 13

93053 Regensburg


Email: datenschutz@airadoc.com


For further information about our company, please refer to the legal notice on our website.

4. Legal basis for data processing

4. Legal basis for data processing

4. Legal basis for data processing

In principle, any processing of personal data is prohibited by law and is only permitted if one of the following justifications applies:

In principle, any processing of personal data is prohibited by law and is only permitted if one of the following justifications applies:

In principle, any processing of personal data is prohibited by law and is only permitted if one of the following justifications applies:

Art. 6 (1) (a) GDPR ("Consent"):
Art. 6 (1) (a) GDPR ("Consent"):
Art. 6 (1) (a) GDPR ("Consent"):

The data subject has voluntarily, knowingly, and unambiguously given their consent to a specific processing operation.

Art. 6 (1) (b) GDPR:
Art. 6 (1) (b) GDPR:
Art. 6 (1) (b) GDPR:

Processing is necessary for the performance of a contract or pre-contractual measures

Art. 6 (1) (c) GDPR:
Art. 6 (1) (c) GDPR:
Art. 6 (1) (c) GDPR:

Processing is necessary for compliance with a legal obligation to which the controller is subject.

Art. 6 (1) (d) GDPR:
Art. 6 (1) (d) GDPR:
Art. 6 (1) (d) GDPR:

Processing is necessary to protect vital interests.

Art. 6 (1) (e) GDPR:
Art. 6 (1) (e) GDPR:
Art. 6 (1) (e) GDPR:

Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

Art. 6 (1) (f) GDPR ("Legitimate interests"):
Art. 6 (1) (f) GDPR ("Legitimate interests"):
Art. 6 (1) (f) GDPR ("Legitimate interests"):

Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.

We specify the applicable legal basis for each of the processing operations we carry out below. Processing may be based on several legal bases.

We specify the applicable legal basis for each of the processing operations we carry out below. Processing may be based on several legal bases.

We specify the applicable legal basis for each of the processing operations we carry out below. Processing may be based on several legal bases.

5. Data deletion and storage period

5. Data deletion and storage period

5. Data deletion and storage period

Unless an explicit storage period is specified, your personal data will be deleted or blocked as soon as the purpose or legal basis for storage no longer applies. Your data is generally stored on our servers in Germany, subject to disclosure in accordance with the provisions in A.7 and A.8. Storage beyond the purposes and legal bases set out in this privacy policy may be necessary in the event of (imminent) legal disputes or if storage is required by law (e.g., Section 257 of the German Commercial Code (HGB), Section 147 of the German Fiscal Code (AO)). In this case, the legal basis for data processing is Art. 6 (1) (f) GDPR or Art. 6 (1) (c) GDPR

Unless an explicit storage period is specified, your personal data will be deleted or blocked as soon as the purpose or legal basis for storage no longer applies. Your data is generally stored on our servers in Germany, subject to disclosure in accordance with the provisions in A.7 and A.8. Storage beyond the purposes and legal bases set out in this privacy policy may be necessary in the event of (imminent) legal disputes or if storage is required by law (e.g., Section 257 of the German Commercial Code (HGB), Section 147 of the German Fiscal Code (AO)). In this case, the legal basis for data processing is Art. 6 (1) (f) GDPR or Art. 6 (1) (c) GDPR

Unless an explicit storage period is specified, your personal data will be deleted or blocked as soon as the purpose or legal basis for storage no longer applies. Your data is generally stored on our servers in Germany, subject to disclosure in accordance with the provisions in A.7 and A.8. Storage beyond the purposes and legal bases set out in this privacy policy may be necessary in the event of (imminent) legal disputes or if storage is required by law (e.g., Section 257 of the German Commercial Code (HGB), Section 147 of the German Fiscal Code (AO)). In this case, the legal basis for data processing is Art. 6 (1) (f) GDPR or Art. 6 (1) (c) GDPR

6. Data security

6. Data security

6. Data security

We implement appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access (e.g., TLS encryption for our website). In doing so, we take into account the state of the art, the implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, in accordance with Art. 25 (1) GDPR. Our security measures are continuously adapted to technological progress. Further information on this is available on request from our data protection officer (A.3) or can be found in the document on our technical and organizational measures on the marketing websites.

We implement appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access (e.g., TLS encryption for our website). In doing so, we take into account the state of the art, the implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, in accordance with Art. 25 (1) GDPR. Our security measures are continuously adapted to technological progress. Further information on this is available on request from our data protection officer (A.3) or can be found in the document on our technical and organizational measures on the marketing websites.

We implement appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or unauthorized access (e.g., TLS encryption for our website). In doing so, we take into account the state of the art, the implementation costs, and the nature, scope, circumstances, and purposes of the processing, as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, in accordance with Art. 25 (1) GDPR. Our security measures are continuously adapted to technological progress. Further information on this is available on request from our data protection officer (A.3) or can be found in the document on our technical and organizational measures on the marketing websites.

7. Cooperation with processors

7. Cooperation with processors

7. Cooperation with processors

Like any large company, we also use external domestic and foreign service providers (e.g., in the areas of IT, logistics, telecommunications, and marketing). These service providers act exclusively in accordance with our instructions and are contractually obligated to comply with data protection regulations in accordance with Art. 28 GDPR.

Like any large company, we also use external domestic and foreign service providers (e.g., in the areas of IT, logistics, telecommunications, and marketing). These service providers act exclusively in accordance with our instructions and are contractually obligated to comply with data protection regulations in accordance with Art. 28 GDPR.

Like any large company, we also use external domestic and foreign service providers (e.g., in the areas of IT, logistics, telecommunications, and marketing). These service providers act exclusively in accordance with our instructions and are contractually obligated to comply with data protection regulations in accordance with Art. 28 GDPR.

8. Data transfer to third countries

8. Data transfer to third countries

8. Data transfer to third countries

Within the scope of our business relationships, your personal data may be transferred to third-party companies that may also be located outside the European Economic Area (EEA), i.e., in third countries. Such processing is carried out exclusively for the purpose of fulfilling contractual and business obligations and maintaining our business relationship. Details of the respective transfer are explained in the relevant sections of this statement.

Within the scope of our business relationships, your personal data may be transferred to third-party companies that may also be located outside the European Economic Area (EEA), i.e., in third countries. Such processing is carried out exclusively for the purpose of fulfilling contractual and business obligations and maintaining our business relationship. Details of the respective transfer are explained in the relevant sections of this statement.

Within the scope of our business relationships, your personal data may be transferred to third-party companies that may also be located outside the European Economic Area (EEA), i.e., in third countries. Such processing is carried out exclusively for the purpose of fulfilling contractual and business obligations and maintaining our business relationship. Details of the respective transfer are explained in the relevant sections of this statement.

The European Commission certifies that some third countries have a level of data protection comparable to that of the EEA by means of so-called adequacy decisions in accordance with Art. 45 GDPR. A list of these countries and copies of the decisions can be found at http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.html.

Other third countries to which personal data is transferred may not have a comparable level of data protection. In such cases, we ensure that data protection is adequately guaranteed, for example through binding corporate rules, EU standard contractual clauses, certificates, or recognized codes of conduct. For more information, please contact our data protection officer (A.3).

The European Commission certifies that some third countries have a level of data protection comparable to that of the EEA by means of so-called adequacy decisions in accordance with Art. 45 GDPR. A list of these countries and copies of the decisions can be found at http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.html.

Other third countries to which personal data is transferred may not have a comparable level of data protection. In such cases, we ensure that data protection is adequately guaranteed, for example through binding corporate rules, EU standard contractual clauses, certificates, or recognized codes of conduct. For more information, please contact our data protection officer (A.3).

The European Commission certifies that some third countries have a level of data protection comparable to that of the EEA by means of so-called adequacy decisions in accordance with Art. 45 GDPR. A list of these countries and copies of the decisions can be found at http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.html.

Other third countries to which personal data is transferred may not have a comparable level of data protection. In such cases, we ensure that data protection is adequately guaranteed, for example through binding corporate rules, EU standard contractual clauses, certificates, or recognized codes of conduct. For more information, please contact our data protection officer (A.3).

9. Automated decision-making and profiling

9. Automated decision-making and profiling

9. Automated decision-making and profiling

If we carry out automated decision-making, including profiling, we will inform you separately about this and about the underlying logic, scope, and intended effects for the data subject. As a matter of principle, we do not use your personal data for automated decision-making or profiling.

If we carry out automated decision-making, including profiling, we will inform you separately about this and about the underlying logic, scope, and intended effects for the data subject. As a matter of principle, we do not use your personal data for automated decision-making or profiling.

If we carry out automated decision-making, including profiling, we will inform you separately about this and about the underlying logic, scope, and intended effects for the data subject. As a matter of principle, we do not use your personal data for automated decision-making or profiling.

10. No obligation to provide personal data

10. No obligation to provide personal data

10. No obligation to provide personal data

We do not make the conclusion of contracts dependent on you providing us with personal data in advance. There is generally no legal or contractual obligation to provide us with your personal data. However, we may only be able to provide certain offers to a limited extent or not at all if you do not provide the necessary data.

We do not make the conclusion of contracts dependent on you providing us with personal data in advance. There is generally no legal or contractual obligation to provide us with your personal data. However, we may only be able to provide certain offers to a limited extent or not at all if you do not provide the necessary data.

We do not make the conclusion of contracts dependent on you providing us with personal data in advance. There is generally no legal or contractual obligation to provide us with your personal data. However, we may only be able to provide certain offers to a limited extent or not at all if you do not provide the necessary data.

11. Legal transfer obligations

11. Legal transfer obligations

11. Legal transfer obligations

Under certain circumstances, we may be subject to legal or regulatory obligations to provide lawfully processed personal data to third parties, in particular public authorities (in accordance with Art. 6 (1) (c) GDPR).

Under certain circumstances, we may be subject to legal or regulatory obligations to provide lawfully processed personal data to third parties, in particular public authorities (in accordance with Art. 6 (1) (c) GDPR).

Under certain circumstances, we may be subject to legal or regulatory obligations to provide lawfully processed personal data to third parties, in particular public authorities (in accordance with Art. 6 (1) (c) GDPR).

12. Your rights

12. Your rights

12. Your rights

As a data subject, you have the following rights regarding your processed personal data, which you can exercise at any time using the contact details provided in A.2:

As a data subject, you have the following rights regarding your processed personal data, which you can exercise at any time using the contact details provided in A.2:

As a data subject, you have the following rights regarding your processed personal data, which you can exercise at any time using the contact details provided in A.2:

Right of access (Article 15 GDPR):
Right of access (Article 15 GDPR):
Right of access (Article 15 GDPR):

You can request information about your processed data, the purposes of processing, data categories, recipients, storage period, your rights, etc.

Right to rectification (Art. 16 GDPR):
Right to rectification (Art. 16 GDPR):
Right to rectification (Art. 16 GDPR):

You can request the immediate rectification of inaccurate data or the completion of your data.

Right to erasure (Art. 17 GDPR):
Right to erasure (Art. 17 GDPR):
Right to erasure (Art. 17 GDPR):

Under certain conditions, you can request the erasure of your data.

Right to restriction of processing (Art. 18 GDPR):
Right to restriction of processing (Art. 18 GDPR):
Right to restriction of processing (Art. 18 GDPR):

Under certain circumstances, you may request that the processing of your data be restricted.

Right to data portability (Art. 20 GDPR):
Right to data portability (Art. 20 GDPR):
Right to data portability (Art. 20 GDPR):

You may request to receive your data in a structured, commonly used, and machine-readable format or to have it transferred to another controller.

Right to object (Art. 21 GDPR):
Right to object (Art. 21 GDPR):
Right to object (Art. 21 GDPR):

You may object to the processing of your data if it is based on Art. 6 (1) (e) or (f) GDPR.

Right to withdraw consent (Art. 7(3) GDPR):
Right to withdraw consent (Art. 7(3) GDPR):
Right to withdraw consent (Art. 7(3) GDPR):

You may withdraw your consent at any time, thereby prohibiting future processing based on this consent. This does not affect the lawfulness of processing based on consent before its withdrawal.

Right to lodge a complaint (Art. 77 GDPR):

Right to lodge a complaint (Art. 77 GDPR):

Right to lodge a complaint (Art. 77 GDPR):

You can lodge a complaint with a data protection supervisory authority, e.g., the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, email: poststelle@datenschutz-bayern.de.

You can lodge a complaint with a data protection supervisory authority, e.g., the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach,

email: poststelle@datenschutz-bayern.de.

You can lodge a complaint with a data protection supervisory authority, e.g., the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach,

email: poststelle@datenschutz-bayern.de.

13. Cookies

13. Cookies

13. Cookies

Cookies are small text files that are stored on your data carrier by the browser you are using with a specific character string. This storage provides the issuing body with certain information. Cookies are not technically capable of executing programs or transferring malware to your device, which is why they do not pose any danger. They are used to improve the user-friendliness and efficiency of our online offering. Cookies may contain information that enables the device used to be identified. Other cookies only store non-personal configuration settings. It is not possible to directly identify the user through cookies.

Cookies are small text files that are stored on your data carrier by the browser you are using with a specific character string. This storage provides the issuing body with certain information. Cookies are not technically capable of executing programs or transferring malware to your device, which is why they do not pose any danger. They are used to improve the user-friendliness and efficiency of our online offering. Cookies may contain information that enables the device used to be identified. Other cookies only store non-personal configuration settings. It is not possible to directly identify the user through cookies.

Cookies are small text files that are stored on your data carrier by the browser you are using with a specific character string. This storage provides the issuing body with certain information. Cookies are not technically capable of executing programs or transferring malware to your device, which is why they do not pose any danger. They are used to improve the user-friendliness and efficiency of our online offering. Cookies may contain information that enables the device used to be identified. Other cookies only store non-personal configuration settings. It is not possible to directly identify the user through cookies.

Cookies are classified according to their storage duration (temporary session cookies vs. permanent cookies) and their functionality:

Cookies are classified according to their storage duration (temporary session cookies vs. permanent cookies) and their functionality:

Cookies are classified according to their storage duration (temporary session cookies vs. permanent cookies) and their functionality:

Technical cookies:
Technical cookies:
Technical cookies:

These are essential for navigation and basic functionality of our website and ensure its security. They do not collect marketing information or log your browsing history.

Performance cookies:
Performance cookies:
Performance cookies:

These collect pseudonymous data about your use of our website, visited subpages, and any malfunctions. They are used exclusively to optimize our offering and analyze user interests.

Advertising and targeting cookies:
Advertising and targeting cookies:
Advertising and targeting cookies:

These enable the provision of customized advertising on our website or by third-party providers, as well as the measurement of the success of such offers. The maximum storage period is 13 months.

Interaction cookies:
Interaction cookies:
Interaction cookies:

These improve the communication between our website and external services (e.g., social networks). Here too, the maximum storage period is 13 months. Any use of cookies that is not technically necessary constitutes a processing operation relevant to data protection law, which is only permissible with your express and active consent in accordance with Art. 6 (1) (a) GDPR. This applies in particular to advertising, targeting, and interaction cookies. The personal data processed by cookies will also only be passed on to third parties with your express consent

in accordance with Art. 6 (1) (a) GDPR. You can revoke this consent at any time via our cookie management system.

in accordance with Art. 6 (1) (a) GDPR. You can revoke this consent at any time via our cookie management system.

in accordance with Art. 6 (1) (a) GDPR. You can revoke this consent at any time via our cookie management system.

Rare exceptions are cookies whose use is otherwise justified by Art. 6 (1) (b)-(f).

Rare exceptions are cookies whose use is otherwise justified by Art. 6 (1) (b)-(f).

Rare exceptions are cookies whose use is otherwise justified by Art. 6 (1) (b)-(f).

14. Updating of the privacy policy

14. Updating of the privacy policy

14. Updating of the privacy policy

As data protection law continues to evolve and technological and organizational changes take place, we regularly review our privacy policy to determine whether any adjustments are necessary. Any changes will be announced on our website at www.airadoc.de. This privacy policy is current as of September 2025.

As data protection law continues to evolve and technological and organizational changes take place, we regularly review our privacy policy to determine whether any adjustments are necessary. Any changes will be announced on our website at www.airadoc.de. This privacy policy is current as of September 2025.

As data protection law continues to evolve and technological and organizational changes take place, we regularly review our privacy policy to determine whether any adjustments are necessary. Any changes will be announced on our website at www.airadoc.de. This privacy policy is current as of September 2025.

B. Marketing websites

B. Marketing websites

B. Marketing websites

1. Function description

1. Function description

1. Function description

Information about our company and the services we offer can be found in particular at www.airadoc.com and the associated subpages (hereinafter collectively referred to as "marketing websites"). When you visit our marketing websites, your personal data may be processed.

Information about our company and the services we offer can be found in particular at www.airadoc.com and the associated subpages (hereinafter collectively referred to as "marketing websites"). When you visit our marketing websites, your personal data may be processed.

Information about our company and the services we offer can be found in particular at www.airadoc.com and the associated subpages (hereinafter collectively referred to as "marketing websites"). When you visit our marketing websites, your personal data may be processed.

2. Processed personal data

2. Processed personal data

2. Processed personal data

Insofar as the processing mentioned below is based on Art. 6 (1) (f) GDPR, the purposes mentioned also represent our legitimate interests.

Insofar as the processing mentioned below is based on Art. 6 (1) (f) GDPR, the purposes mentioned also represent our legitimate interests.

Insofar as the processing mentioned below is based on Art. 6 (1) (f) GDPR, the purposes mentioned also represent our legitimate interests.

a. Informational use

a. Informational use

a. Informational use

The following processing of personal data occurs when our marketing websites are used for purely informational purposes.

The following processing of personal data occurs when our marketing websites are used for purely informational purposes.

The following processing of personal data occurs when our marketing websites are used for purely informational purposes.

Log data

Log data

Log data

Context and scope:
Context and scope:
Context and scope:

Each time you access our marketing websites, a temporary and pseudonymized log data record (known as server log files) is stored, containing the following information:

Each time you access our marketing websites, a temporary and pseudonymized log data record (known as server log files) is stored, containing the following information:

Each time you access our marketing websites, a temporary and pseudonymized log data record (known as server log files) is stored, containing the following information:

Referrer URL (the page from which the request originated)

Referrer URL (the page from which the request originated)

Referrer URL (the page from which the request originated)

Name and URL of the requested page

Name and URL of the requested page

Name and URL of the requested page

Date and time of access

Date and time of access

Date and time of access

Description of the type, language, and version of the browser used

Description of the type, language, and version of the browser used

Description of the type, language, and version of the browser used

Shortened IP address of the requesting computer (pseudonymized)

Shortened IP address of the requesting computer (pseudonymized)

Shortened IP address of the requesting computer (pseudonymized)

Amount of data transferred

Amount of data transferred

Amount of data transferred

Operating system

Operating system

Operating system

Access status/HTTP status code

Access status/HTTP status code

Access status/HTTP status code

GMT time zone difference

GMT time zone difference

GMT time zone difference

Purpose and legal basis:
Purpose and legal basis:
Purpose and legal basis:

The processing of log data serves statistical purposes and the improvement of our website, in particular its stability and security (legal basis: Art. 6 (1) (f) GDPR).

Duration of processing:
Duration of processing:
Duration of processing:

A.5 applies.

Categories of recipients:
Categories of recipients:
Categories of recipients:

Service providers for the operation of our website and the processing of stored data (e.g., data centers, IT security). Furthermore, A.11 applies

Transfer to third countries:
Transfer to third countries:
Transfer to third countries:

Data may be transferred to Hotjar's subcontractors for analysis purposes and to Framer for hosting. More detailed information and the legal classification of the transfer can be found in Appendix 2.

Cookies

Cookies

Cookies

Context and scope:
Context and scope:
Context and scope:
Name

_hjSessionUser_

_ga

ga_<property_id >

fs-consent-*

Domain

airadoc.com

airadoc.com

airadoc.com

airadoc.com

Storage period

12 months

13 months

13 months

1 months

Category

Service

Performance

Performance

Technically necessary

Description

Assignment of the user to an ID (Hotjar)

Assignment of the user to an ID (Google Analytics)

Assignment of the user to a property ID (Google Analytics)

Storage of cookie preferences

Purpose and legal basiss:
Purpose and legal basiss:
Purpose and legal basiss:

See the "Description" column in the overview above. A.13 also applies.

Duration of processing:
Duration of processing:
Duration of processing:

A.5 and A.12 apply.

Categories of recipients:
Categories of recipients:
Categories of recipients:

For performance cookies, our processors for analytics. For the cookie "_hjSessionUser_", these are Hotjar and its processors. For the cookies "_ga" and "_ga_<property_id>", these are Google and its processors. More detailed information and the legal classification of the transfer can be found in Appendix 1.

Transfer to third countries:
Transfer to third countries:
Transfer to third countries:

The transfer of personal data to third countries takes place for the cookies "_hjSessionUser_", "_ga" and "_ga_<property_id>" to Google (Analytics) and, if applicable, to Hotjar's sub-processors. More detailed information and the legal classification of the transfer can be found in Appendices 1 and 2. Data may be transferred to Hotjar's subcontractors for analysis purposes and to Framer for hosting. More detailed information and the legal classification of the transfer can be found in Appendix 2.

b. Contact

b. Contact

b. Contact

As soon as you use our contact form to send us a contact request, the following processing of personal data will take place.

As soon as you use our contact form to send us a contact request, the following processing of personal data will take place.

As soon as you use our contact form to send us a contact request, the following processing of personal data will take place.

Contact form data
Contact form data
Contact form data
Context and scope:
Context and scope:
Context and scope:

When you use our contact forms, we process the data you provide, such as your last name, first name, email address, and the time of transmission. In addition, any optional personal data provided in your message will also be processed

Purpose and legal basis:
Purpose and legal basis:
Purpose and legal basis:

The processing of log data serves statistical purposes and the improvement of our website, in particular its stability and security (legal basis: Art. 6 (1) (f) GDPR).

Duration of processing:
Duration of processing:
Duration of processing:

A.5 applies.

Categories of recipients:
Categories of recipients:
Categories of recipients:

Service providers for the operation of our website and the processing of stored data (e.g., data centers, IT security). Furthermore, A.11 applies

Transfer to third countries:
Transfer to third countries:
Transfer to third countries:

The data may be transferred to Framer's subcontractors for hosting. More detailed information and the legal classification of the transfer can be found in Appendix 2. In addition, data is transferred to Google (email traffic) and its processors. More detailed information and the legal classification of the transfer can be found in Appendix 1.

3. Final remarks

3. Final remarks

3. Final remarks

a. Dealing with social media

a. Dealing with social media

a. Dealing with social media

We do not implement any direct social media plugins on our websites. If symbols from social media platforms (such as Facebook, Instagram, or similar services) appear on our website, these serve exclusively as passive references to the respective provider sites.

We do not implement any direct social media plugins on our websites. If symbols from social media platforms (such as Facebook, Instagram, or similar services) appear on our website, these serve exclusively as passive references to the respective provider sites.

We do not implement any direct social media plugins on our websites. If symbols from social media platforms (such as Facebook, Instagram, or similar services) appear on our website, these serve exclusively as passive references to the respective provider sites.

C. AIRAdoc

C. AIRAdoc

C. AIRAdoc

1. Function descriptionon

1. Function descriptionon

1. Function descriptionon

Our AIRAdoc software includes functions for AI-supported improvement of everyday working life as a doctor. Please refer to the applicable General Terms and Conditions for the specific range of functions, which is also determined by your desired configuration.

Our AIRAdoc software includes functions for AI-supported improvement of everyday working life as a doctor. Please refer to the applicable General Terms and Conditions for the specific range of functions, which is also determined by your desired configuration.

Our AIRAdoc software includes functions for AI-supported improvement of everyday working life as a doctor. Please refer to the applicable General Terms and Conditions for the specific range of functions, which is also determined by your desired configuration.

2. Processed personal data

2. Processed personal data

2. Processed personal data

Insofar as the processing mentioned below is based on Art. 6 (1) (f) GDPR, the purposes mentioned also represent our legitimate interests. No special categories of personal data are processed. In anonymized form, usage data may be aggregated for marketing purposes.

Insofar as the processing mentioned below is based on Art. 6 (1) (f) GDPR, the purposes mentioned also represent our legitimate interests. No special categories of personal data are processed. In anonymized form, usage data may be aggregated for marketing purposes.

Insofar as the processing mentioned below is based on Art. 6 (1) (f) GDPR, the purposes mentioned also represent our legitimate interests. No special categories of personal data are processed. In anonymized form, usage data may be aggregated for marketing purposes.

a. Basic Use

a. Basic Use

a. Basic Use

Any use of AIRAdoc results in the following processing of personal data.

Any use of AIRAdoc results in the following processing of personal data.

Any use of AIRAdoc results in the following processing of personal data.

Log data

Log data

Log data

Context and scope:
Context and scope:
Context and scope:

Each time AIRAdoc is accessed, a temporary and anonymized log data record (so-called server log files) is stored, which contains the following information:

Referrer URL (the page from which the request originated)

Referrer URL (the page from which the request originated)

Referrer URL (the page from which the request originated)

Name and URL of the requested page

Name and URL of the requested page

Name and URL of the requested page

Date and time of access

Date and time of access

Date and time of access

Description of the type, language, and version of the browser used

Description of the type, language, and version of the browser used

Description of the type, language, and version of the browser used

Shortened IP address of the requesting computer (pseudonymized)

Shortened IP address of the requesting computer (pseudonymized)

Shortened IP address of the requesting computer (pseudonymized)

Amount of data transferred

Amount of data transferred

Amount of data transferred

Operating system

Operating system

Operating system

Access status/HTTP status code

Access status/HTTP status code

Access status/HTTP status code

GMT time zone difference

GMT time zone difference

GMT time zone difference

Purpose and legal basis:
Purpose and legal basis:
Purpose and legal basis:

The processing of log data serves statistical purposes and the improvement of our website, in particular its stability and security (legal basis: Art. 6 (1) (f) GDPR).

Duration of processing
Duration of processing
Duration of processing

A.5 applies.

Categories of recipients:
Categories of recipients:
Categories of recipients:

Service providers for the operation of our website and the processing of stored data (e.g., data centers, IT security). Furthermore, A.11 applies

Transfer to third countries:
Transfer to third countries:
Transfer to third countries:

The data may be transferred to Framer's subcontractors for hosting. More detailed information and the legal classification of the transfer can be found in Appendix 2. In addition, data is transferred to Google (email traffic) and its processors. More detailed information and the legal classification of the transfer can be found in Appendix 1.

Cookies

Cookies

Cookies

Context and scope:
Context and scope:
Context and scope:
Name

i18next

Domain

airadoc.com

Storage period

Session

Category

Technically necessary

Description

Storage of language preferences

Purpose and legal basis:
Purpose and legal basis:
Purpose and legal basis:

See the "Description" column in the overview above. A.13 also applies.

Duration of processing:
Duration of processing:
Duration of processing:

A.5 and A.12 apply.

Categories of recipients:
Categories of recipients:
Categories of recipients:

Processors for hosting.

Transfer to third countries:
Transfer to third countries:
Transfer to third countries:

Personal data is transferred to third countries for the cookies "i18next" to the processor Microsoft for hosting. More detailed information and the legal classification of the transfer can be found in Appendix 1.

b. Account and settings management

b. Account and settings management

b. Account and settings management

User profile and user settings

User profile and user settings

User profile and user settings

Context and scope:
Context and scope:
Context and scope:

We request some basic information to create and manage your user account. This includes:

First and last name

First and last name

First and last name

Email

Email

Email

Field of study

Field of study

Field of study

Language

Language

Language

Farewell form for doctor's letters

Farewell form for doctor's letters

Farewell form for doctor's letters

Purpose and legal basis:
Purpose and legal basis:
Purpose and legal basis:

This data is processed for the purpose of registering users and fulfilling product functionalities (legal basis: Art. 6 (1) (b) GDPR).

Duration of processing:
Duration of processing:
Duration of processing:

A.5 applies.

Categories of recipients:
Categories of recipients:
Categories of recipients:

Processors for the hosting of AIRAdoc. Furthermore, A.11 applies.

Transfer to third countries:
Transfer to third countries:
Transfer to third countries:

Data is only transferred to third countries when it is transferred to the processor Microsoft and its processors for the purpose of hosting the product. More detailed information and the legal classification of the transfer can be found in Appendix 1.

Payment Process

Payment Process

Payment Process

Context and scope:
Context and scope:
Context and scope:

We require payment information from you for payment processing.

Purpose and legal basis:
Purpose and legal basis:
Purpose and legal basis:

This data is processed exclusively for payment processing (legal basis: Art. 6 (1) (b) GDPR).

Duration of processing:
Duration of processing:
Duration of processing:

A.5 applies.

Categories of recipients:
Categories of recipients:
Categories of recipients:

Processors for payment processing by AIRAdoc. Furthermore, A.11 applies.

Transfer to third countries:
Transfer to third countries:
Transfer to third countries:

Transfers to third countries are made exclusively in the course of transfers to the processor Stripe and its processors for payment processing. More detailed information and the legal classification of the transfer can be found in Appendix 1.

Organizations

Organizations

Organizations

Context and scope:
Context and scope:
Context and scope:

In order to map organizational structures within AIRAdoc, we process the affiliation of various users to an organization and the identification of users as administrators for this organization.

Purpose and legal basis:
Purpose and legal basis:
Purpose and legal basis:

This data is processed in order to fulfill the product functionalities (legal basis: Art. 6 (1) (b) GDPR).

Duration of processing:
Duration of processing:
Duration of processing:

A.5 applies.

Categories of recipients:
Categories of recipients:
Categories of recipients:

Processors for the hosting of AIRAdoc. Furthermore, A.11 applies.

Transfer to third countries:
Transfer to third countries:
Transfer to third countries:

Transfer to third countries takes place exclusively in the course of transfer to the processor Microsoft and its processors for hosting.

More detailed information and the legal classification of the transfer can be found in Appendix 1.

More detailed information and the legal classification of the transfer can be found in Appendix 1.

More detailed information and the legal classification of the transfer can be found in Appendix 1.

c. Use of the software functions

c. Use of the software functions

c. Use of the software functions

Feedback function

Feedback function

Feedback function

Context and scope:
Context and scope:
Context and scope:

You have the option of voluntarily evaluating the quality of the documentation provided. This includes a simple selection (positive or negative) and the option to enter text.

Purpose and legal basis:
Purpose and legal basis:
Purpose and legal basis:

This data is processed to improve our product (legal basis: Art. 6 (1) (a) GDPR).

Duration of processing:
Duration of processing:
Duration of processing:

A.5 applies.

Categories of recipients:
Categories of recipients:
Categories of recipients:

Processors for the hosting of AIRAdoc. Furthermore, A.11 applies.

Transfer to third countries:
Transfer to third countries:
Transfer to third countries:

Transfers to third countries are made exclusively in the course of transfers to the processor Microsoft and its processors for hosting purposes. More detailed information and the legal classification of the transfer can be found in Appendix 1.

More detailed information and the legal classification of the transfer can be found in Appendix 1.

More detailed information and the legal classification of the transfer can be found in Appendix 1.

More detailed information and the legal classification of the transfer can be found in Appendix 1.

Creation and use of audio recordings, documents, and templates

Creation and use of audio recordings, documents, and templates

Creation and use of audio recordings, documents, and templates

Context and scope:
Context and scope:
Context and scope:

Within the scope of the intended use of AIRAdoc, the user regularly shares personal data that is absolutely necessary for the fulfillment of the product functionalities. This includes, among other things:

Audio recordings

Audio recordings

Audio recordings

Documents

Documents

Documents

Creating, retrieving, and sharing templates

Creating, retrieving, and sharing templates

Creating, retrieving, and sharing templates

Information about the use of and access to documents and templates

Information about the use of and access to documents and templates

Information about the use of and access to documents and templates

This may apply at both the user and organizational levels.

This may apply at both the user and organizational levels.

This may apply at both the user and organizational levels.

Purpose and legal basis:
Purpose and legal basis:
Purpose and legal basis:

This data is processed for the purpose of fulfilling product functionalities (legal basis: Art. 6 (1) (b) GDPR).

Duration of processing:
Duration of processing:
Duration of processing:

A.5 applies.

Categories of recipients:
Categories of recipients:
Categories of recipients:

Processors for the hosting of AIRAdoc. Furthermore, A.11 applies.

Transfer to third countries:
Transfer to third countries:
Transfer to third countries:

Transfer to third countries takes place exclusively in the course of transfer to the processor Microsoft and its processors for hosting. More detailed information and the legal classification of the transfer can be found in Appendix 1.

Appendix 1 – Overview of processors outside the EEA

Appendix 1 – Overview of processors outside the EEA

Appendix 1 – Overview of processors outside the EEA

Below you will find a list of all processors outside the EEA, their location, and the legal basis for the transfer of personal data to this processor. If the legal basis for a processor is an adequacy decision, you will find it at

http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.html.

The list also includes all processors whose services are used by the processors. Corresponding cross-references can be found in the entries for the individual processors.

Below you will find a list of all processors outside the EEA, their location, and the legal basis for the transfer of personal data to this processor. If the legal basis for a processor is an adequacy decision, you will find it at

http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.html.

The list also includes all processors whose services are used by the processors. Corresponding cross-references can be found in the entries for the individual processors.

Below you will find a list of all processors outside the EEA, their location, and the legal basis for the transfer of personal data to this processor. If the legal basis for a processor is an adequacy decision, you will find it at

http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.html.

The list also includes all processors whose services are used by the processors. Corresponding cross-references can be found in the entries for the individual processors.

Company name:
Company name:
Company name:

Google LLC

Google LLC

Google LLC

Company headquarters:
Company headquarters:
Company headquarters:

Mountain View, California, USA

Mountain View, California, USA

Mountain View, California, USA

Processing activities used:
Processing activities used:
Processing activities used:

Email delivery

Email delivery

Email delivery

Legal basis:
Legal basis:
Legal basis:

Certification in accordance with Art. 45 (1) GDPR within the framework of the Data Privacy Framework. For more information on certification, see Data Privacy Framework.

Company name:
Company name:
Company name:

Microsoft Corporation

Microsoft Corporation

Microsoft Corporation

Company headquarters:
Company headquarters:
Company headquarters:

Redmond, Washington, USA

Redmond, Washington, USA

Redmond, Washington, USA

Processing activities used:
Processing activities used:
Processing activities used:

Hosting of the AIRAdoc product

Hosting of the AIRAdoc product

Hosting of the AIRAdoc product

Legal basis:
Legal basis:
Legal basis:

Certification pursuant to Art. 45(1) GDPR within the framework of the Data Privacy Framework. For more information on certification, see Data Privacy Framework.

Company name:
Company name:
Company name:

Stripe, Inc.

Stripe, Inc.

Stripe, Inc.

Company headquarters:
Company headquarters:
Company headquarters:

South San Francisco, California, USA, and Dublin, Ireland

South San Francisco, California, USA, and Dublin, Ireland

South San Francisco, California, USA, and Dublin, Ireland

Processing activities used:
Processing activities used:
Processing activities used:

Payment processing

Payment processing

Payment processing

Legal basis:
Legal basis:
Legal basis:

Certification pursuant to Art. 45 (1) GDPR within the framework of the Data Privacy Framework. For more information on certification, see Data Privacy Framework.

Appendix 2 – Overview of processors within the EEA

Appendix 2 – Overview of processors within the EEA

Appendix 2 – Overview of processors within the EEA

Below is a list of all processors within the EEA. It is possible that these processors may use sub-processors in third countries. In this case, this is contractually secured in accordance with Art. 28 GDPR.

Below is a list of all processors within the EEA. It is possible that these processors may use sub-processors in third countries. In this case, this is contractually secured in accordance with Art. 28 GDPR.

Below is a list of all processors within the EEA. It is possible that these processors may use sub-processors in third countries. In this case, this is contractually secured in accordance with Art. 28 GDPR.

Company name:
Company name:
Company name:

Hotjar Ltd.

Hotjar Ltd.

Hotjar Ltd.

Company headquarters:
Company headquarters:
Company headquarters:

Malta

Malta

Malta

Processing activities used:
Processing activities used:
Processing activities used:

Analysis of user behavior on our marketing websites

Analysis of user behavior on our marketing websites

Analysis of user behavior on our marketing websites

Company name:
Company name:
Company name:

Framer B.V.

Framer B.V.

Framer B.V.

Company headquarters:
Company headquarters:
Company headquarters:

Amsterdam, Netherlands

Amsterdam, Netherlands

Amsterdam, Netherlands

Processing activities used:
Processing activities used:
Processing activities used:

Creation and hosting of our marketing websites

Creation and hosting of our marketing websites

Creation and hosting of our marketing websites

Experience the Future of Patient Care Today

Save time, reduce stress, and elevate your practice with our AI-powered Platform.

Experience the Future of Patient Care Today

Save time, reduce stress, and elevate your practice with our AI-powered Platform.

Experience the Future of Patient Care Today

Save time, reduce stress, and elevate your practice with our AI-powered Platform.

Frequently Asked Questions

Frequently Ask Questions

Frequently Asked Questions

1. How does AIRAdoc protect personal data?

1. How does AIRAdoc protect personal data?

1. How does AIRAdoc protect personal data?

2. What data does AIRAdoc collect?

2. What data does AIRAdoc collect?

2. What data does AIRAdoc collect?

3. Is AIRAdoc's AI used for training with patient data?

3. Is AIRAdoc's AI used for training with patient data?

3. Is AIRAdoc's AI used for training with patient data?

4. Where is the data stored and processed?

4. Where is the data stored and processed?

4. Where is the data stored and processed?

5. What rights do users have regarding their data?

5. What rights do users have regarding their data?

5. What rights do users have regarding their data?

6. How does AIRAdoc protect personal data when using AI-based systems?

6. How does AIRAdoc protect personal data when using AI-based systems?

6. How does AIRAdoc protect personal data when using AI-based systems?

Have Questions? We're Here to Help!

Get in touch with our team for support, demos, or partnership inquiries.

AIRAdoc connects exceptional healthcare professionals with their patients.

Email

info@airadoc.com

© 2025 AIRAdoc. All rights reserved.

Have Questions? We're Here to Help!

Get in touch with our team for support, demos, or partnership inquiries.

AIRAdoc connects exceptional healthcare professionals with their patients.

Email

info@airadoc.com

© 2025 AIRAdoc. All rights reserved.

Have Questions? We're Here to Help!

Get in touch with our team for support, demos, or partnership inquiries.

AIRAdoc connects exceptional healthcare professionals with their patients.

Email

info@airadoc.com

© 2025 AIRAdoc. All rights reserved.