Skip to main navigation Skip to main content Skip to page footer

Privacy Notice

Last updated: 17 August 2026

This notice explains the processing of personal data when you visit this website in accordance with Articles 12 to 14 of the General Data Protection Regulation (GDPR).

1. Controller

Saphir Medical Engineering Group GmbH
Managing Director: Ulrich-Rüdiger Strege
Eselföterstraße 27
18055 Rostock
Germany
Phone: +49 (0)381 377 879 10
Email: info@saphir-rc.com

For privacy enquiries, please contact datenschutz@saphir-rc.com.

2. Hosting and server logs

When you access the website, the web server processes technically required connection data. This may include your IP address, date and time, requested URL, referrer URL, amount of data transferred, browser type and version, and operating system. Processing is required for secure and stable delivery, error analysis and defence against attacks. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure operation of the website.

Log data is deleted or anonymised when it is no longer required for these purposes. In the event of a specific security incident, relevant data may be retained until the incident has been resolved and for statutory evidence periods. Hosting and IT service providers receive data only where necessary and are contractually bound under Article 28 GDPR where required.

3. Internal search

When you use the website search, we process the search term, the time of the search and the results page viewed. TYPO3 stores this information in an internal search statistic so that we can improve search results and content. The statistic is not directly linked to your name or IP address; the search request may additionally be included in the server logs described in section 2. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is improving the usability of our information service. Please do not enter names, health data or other confidential information in the search field. Statistical data is deleted or anonymised when it is no longer required for analysis.

4. Uploading medical documents via Tresorit

On the “Your treatment” page you may follow an external upload link for Frankfurt or Kiel. By clicking it, you leave this website and connect to Tresorit AG, Pfingstweidstrasse 60b, 8005 Zurich, Switzerland. The selected link allows you to transmit medical documents securely to the selected centre. Contact and technical connection data and, in particular, health data within the meaning of Article 9(1) GDPR may be processed.

The data is processed to review your enquiry, prepare and provide medical measures, and contact you. As a rule, the selected centre is the controller for this medical processing: Saphir Radiochirurgie Zentrum Frankfurt am Main GmbH, Schleusenweg 2–16, 60528 Frankfurt am Main, Germany, info@saphir-frankfurt.de, or Saphir Radiochirurgie Zentrum Norddeutschland GmbH, Feldstraße 21, Haus L, 24105 Kiel, Germany, info@saphir-norddeutschland.de. The legal bases are Article 6(1)(b) GDPR and, for health data, Article 9(2)(h) GDPR in conjunction with Section 22(1) no. 1(b) BDSG. Where processing is not required for these purposes, we obtain separate consent.

Tresorit is used as a technical service provider. Switzerland is covered by an adequacy decision of the European Commission. See the Tresorit Privacy Policy. Providing documents is voluntary; without the required documents, a medical review may not be possible. If documents become part of a treatment record, statutory retention periods generally apply, in particular ten years after completion of treatment under Section 630f(3) BGB. Otherwise, they are deleted when the review is complete unless statutory retention or evidence obligations apply.

5. Contact by email or telephone

If you contact us, we process your contact details, the content of your enquiry and related communication data in order to respond. The legal basis is Article 6(1)(b) GDPR for contractual or pre-contractual matters and otherwise Article 6(1)(f) GDPR. Please send health data only through secure channels expressly provided for that purpose. Enquiries are deleted after completion unless statutory retention or evidence obligations apply.

6. Consent management and necessary storage

We store your privacy choice under the key saphir-consent-v2 for no more than 180 days in your browser’s local storage. If you change the font size, the selected size is additionally stored under saphir-font-size until you change it or clear your browser’s local storage. This information remains on your device and is not transmitted to us. Storage is necessary to provide the settings you requested. The legal basis for access to local storage is Section 25(2) no. 2 TDDDG; where personal data is processed, the basis is Article 6(1)(c) and (f) GDPR. You can change your privacy choice at any time through “Privacy settings” in the footer; withdrawal applies to future processing.

7. Google Ads

Only if you expressly accept the “Marketing” category do we load the Google Ads tag (ID AW-17648266948) from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It measures and attributes advertising campaigns. Data may include IP address, browser and device data, visited URL, timestamps, and advertising or click identifiers. Cookies such as _gcl_* may be read or written.

The legal bases are your consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR. Without consent, the Google tag is not loaded and no cookieless pings are sent. You can withdraw consent through the privacy settings at any time.

Google LLC may process data in the United States or other third countries. The EU-US Data Privacy Framework adequacy decision can apply to certified US companies; Google also states that it uses appropriate safeguards such as standard contractual clauses where required. See the Google Privacy Policy, data transfer frameworks and cookie information. Retention by Google follows its product-specific retention and deletion periods.

8. External videos (YouTube and Vimeo)

If a page offers a video from YouTube (Google Ireland Limited) or Vimeo, it is loaded only if you expressly accept the “External media” category. Only then does your browser connect to the respective provider. Data such as your IP address, browser and device data, the page visited and usage data may be transmitted, and cookies or similar technologies may be used. YouTube videos use privacy-enhanced mode through youtube-nocookie.com; this does not rule out data transmission when the video is played.

The legal bases are your consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR. Processing in the United States or other third countries is possible. You can withdraw consent through the privacy settings at any time. See the Google Privacy Policy and the Vimeo Privacy Policy.

9. Maps and OpenStreetMap

Map views are based on OpenStreetMap. Map tiles are delivered through a proxy on our own domain, so your browser does not connect directly to OpenStreetMap. Technical data relating to our server may be transmitted during server-side retrieval. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is a data-minimising presentation of directions.

10. External links and social networks

The website contains ordinary links to external websites and social networks, particularly Instagram and LinkedIn. Merely visiting our website does not transmit data to these providers. Their privacy terms apply once you follow a link.

11. Recipients and general retention

Within the respective controller, access is limited to people who need it for the purposes stated above. Hosting, IT and communication providers, Tresorit for document uploads, the selected medical centre and, after your consent, Google and Vimeo may also receive data. Service providers are bound under Article 28 GDPR where required. Data is disclosed to public authorities only where legally required. We do not sell personal data.

We retain personal data only for as long as required for the relevant purpose or by statutory retention and evidence obligations. Specific periods or criteria are stated in the relevant sections. Data is then deleted or anonymised unless there is a legal reason for continued storage. This website does not use solely automated decision-making, including profiling, that produces legal or similarly significant effects.

12. Your rights

Subject to the statutory requirements, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), and objection to processing based on Article 6(1)(e) or (f) GDPR (Article 21). You may withdraw consent at any time for future processing (Article 7(3)). You also have the right to lodge a complaint with a supervisory authority (Article 77).

13. Competent supervisory authority

The State Commissioner for Data Protection and Freedom of Information Mecklenburg-Western Pomerania
Schloss Schwerin, Lennéstraße 1, 19053 Schwerin, Germany
Phone: +49 385 59494-0
Email: info@datenschutz-mv.de
www.datenschutz-mv.de

14. Security and updates

This website uses TLS encryption. We apply appropriate technical and organisational safeguards. We update this notice when services, processing activities or legal requirements change.