ShopMed24
close
Language

Privacy policy



Privacy Policy

General Information and Principles of Data Processing

We are pleased that you are visiting our website. The protection of your privacy and the protection of your personal data, so-called personal data, when using our website is very important to us.

Personal data within the meaning of Article 4(1) GDPR includes all information relating to an identified or identifiable natural person. This includes, for example, information such as your first and last name, your address, your telephone number, your email address, as well as your IP address.

Data that cannot be related to your person, for example through anonymization, is not considered personal data. Processing (e.g. collection, storage, retrieval, consultation, use, transmission, deletion or destruction) pursuant to Article 4(2) GDPR always requires a legal basis or your consent. Processed personal data must be deleted as soon as the purpose of processing has been achieved and no statutory retention obligations apply.

Here you will find information on how we handle your personal data when you visit our website. In order to provide the functions and services of our website, it is necessary for us to collect personal data about you.

We also explain the type and scope of the respective data processing, the purpose and the corresponding legal basis, as well as the respective storage period.

This privacy policy applies only to this website. It does not apply to other websites to which we merely refer via hyperlink. We cannot assume responsibility for the confidential handling of your personal data on these third-party websites, as we have no influence on whether these companies comply with data protection regulations. Please inform yourself directly on these websites about how your personal data is handled by these companies.


Data Controller

The controller responsible for the processing of personal data on this website (see legal notice) is:

Med24 GmbH
Managing Director: Kamil Bakhshaliyev
Am Brabrinke 14, 30519 Hanover, Germany
Commercial Register Number: HRB 228844
VAT ID: DE454706297
Register Court: Local Court of Hanover
Phone:+49 511 936 211 84
Email: info@shopmed24.de


Provision and Use of the Website / Server Log Files

a) Type and Scope of Data Processing

When you use this website without transmitting data to us in any other way (e.g. by registering or using the contact form), we collect technically necessary data via server log files that are automatically transmitted to our server, including:

  • IP address

  • Date and time of the request

  • Name and URL of the retrieved file

  • Website from which access is made (referrer URL)

  • Access status / HTTP status code

  • Browser type

  • Language and version of the browser software

  • Operating system

b) Purpose and Legal Basis

This processing is technically necessary to display our website to you. We also use the data to ensure the security and stability of our website.

The legal basis for this processing is Article 6(1)(f) GDPR. The processing of the above data is necessary for the provision of a website and thus serves to safeguard a legitimate interest of our company.

c) Storage Duration

As soon as the personal data mentioned above is no longer required for displaying the website, it will be deleted. The collection of data for the provision of the website and the storage of data in log files is absolutely necessary for the operation of the website. Therefore, there is no possibility for the user to object in this respect. Further storage may occur in individual cases if this is required by law.


Use of Cookies

a) Type, Scope and Purpose of Data Processing

We use cookies. Cookies are small files that are sent to the browser of your end device during your visit to our website and stored there.

Some functions of our website cannot be offered without the use of technically necessary cookies. Other cookies, however, enable us to carry out various analyses. Some cookies can recognize the browser you use when you revisit our website and transmit various information to us. We use cookies to facilitate and improve the use of our website. Among other things, cookies enable us to make our website more user-friendly and effective by tracking your use of our website and determining your preferred settings (e.g. country and language settings). If third parties process information via cookies, they collect the information directly via your browser. Cookies do not cause any damage to your end device. They cannot execute programs or contain viruses. Various types of cookies are used on our website, the type and function of which are explained below.

Temporary Cookies / Session Cookies

Temporary cookies or session cookies are used on our website and are automatically deleted when you close your browser. This type of cookie makes it possible to record your session ID. This allows various requests from your browser to be assigned to a common session and enables your device to be recognized when you visit the website again.

Persistent Cookies

Persistent cookies are used on our website. Persistent cookies are cookies that are stored in your browser for a longer period of time and can transmit information. The respective storage duration varies depending on the cookie. You can delete persistent cookies independently via your browser settings.

Third-Party Cookies

We use analytical cookies to observe anonymized user behavior on our website.

We also use advertising cookies. These cookies can be used to track user behavior for advertising and targeted marketing purposes.

Social media cookies make it possible to connect to your social networks and share content from our website within your networks.

Browser Settings Configuration

Most web browsers are set to accept cookies automatically. However, you can configure your browser so that it only accepts certain cookies or no cookies at all. Please note, however, that you may then not be able to use all functions of our website.

You can also delete cookies already stored in your browser via your browser settings. Furthermore, it is possible to configure your browser so that it notifies you before cookies are stored. As different browsers may differ in their functionality, please use the help menu of your browser for the corresponding configuration options.

Disabling the use of cookies may require the storage of a permanent cookie on your computer. If you subsequently delete this cookie, you will need to disable it again.

b) Legal Basis

Due to the described purposes of use, the legal basis for processing personal data using cookies is Article 6(1)(f) GDPR. If you have given us your consent to use cookies on the basis of a notice provided by us on the website (“cookie banner”), the additional legal basis is Article 6(1)(a) GDPR.

c) Storage Duration

As soon as the data transmitted to us via cookies is no longer required for the purposes described above, this information will be deleted. Further storage may occur in individual cases if this is required by law.


Data Collection for Pre-Contractual Measures and Contract Performance

a) Type and Scope of Data Processing

In the pre-contractual phase and upon conclusion of a contract, we collect personal data about you. This includes, for example, first and last name, address, email address, telephone number, or bank details.

b) Purpose and Legal Basis of Data Processing

We collect and process this data exclusively for the purpose of contract execution or to fulfill pre-contractual obligations.

The legal basis for this is Article 6(1)(b) GDPR. If you have additionally given your consent, Article 6(1)(a) GDPR also applies as a legal basis.

c) Storage Duration

The data will be deleted as soon as it is no longer required for the purpose of processing.

In addition, statutory retention obligations may exist, for example under commercial or tax law pursuant to the German Commercial Code (HGB) or the German Fiscal Code (AO). If such retention obligations exist, we block or delete your data upon expiry of these retention periods.


Order Form

An order form is available on our website which can be used for electronic pre-orders.

a) Type and Scope of Data Processing

Our data collection is limited to the following data:

  • First and last name

  • Telephone number

  • Email address

  • Bank details

  • Product name

b) Purpose and Legal Basis

The purpose of data processing is to be able to process your order properly.

The legal basis for this is Article 6(1)(b) GDPR. The processing of the data serves to fulfill a contract or is necessary for the implementation of a pre-contractual measure carried out at the request of the data subject.

c) Storage Duration

The data will be deleted as soon as it is no longer required to achieve the purpose of processing.

Statutory retention obligations may also apply, for example under commercial or tax law pursuant to the German Commercial Code (HGB) or the German Fiscal Code (AO). If such obligations exist, we block or delete your data upon expiry of these retention periods.


Registration Option

a) Type and Scope of Data Processing

You can register on our website. If you register, we collect and store the data you enter in the input form (e.g. last name, first name, email address). Data is not passed on to third parties.

b) Purpose and Legal Basis of Data Processing

Your registration is required for the use of certain content and services on our website or for the fulfillment of a contract or the implementation of pre-contractual measures. After registration, you are free to change the personal data provided during registration at any time or to have it completely deleted from the data inventory of the controller.

The legal basis for processing is Article 6(1)(a) GDPR if consent has been given. If your registration serves to prepare the conclusion of a contract, Article 6(1)(b) GDPR is an additional legal basis.

c) Storage Duration

The data collected during registration will be stored by us as long as you are registered on our website and will then be deleted. Statutory retention periods remain unaffected.


Data Transfer

We only pass on your personal data to third parties if:

a) you have given your express consent pursuant to Article 6(1)(a) GDPR;
b) this is legally permissible and necessary pursuant to Article 6(1)(b) GDPR for the fulfillment of a contractual relationship with you or the implementation of pre-contractual measures;
c) there is a legal obligation to transfer data pursuant to Article 6(1)(c) GDPR.
We are legally obliged to transmit data to public authorities, e.g. tax authorities, social security institutions, health insurance companies, supervisory authorities, and law enforcement authorities;

d) the transfer is necessary pursuant to Article 6(1)(f) GDPR to safeguard legitimate corporate interests or to assert, exercise, or defend legal claims, and there is no reason to assume that you have an overriding legitimate interest in the non-disclosure of your data;
e) we use external service providers as processors pursuant to Article 28 GDPR who have been obliged to handle your data with care.

We use such service providers in the following areas:

  • IT

  • Logistics

  • Telecommunications

When transferring data to external entities in third countries, i.e. outside the EU or the EEA, we ensure that these entities treat your personal data with the same level of care as within the EU or the EEA. We only transfer personal data to third countries for which the EU Commission has confirmed an adequate level of protection or if we ensure careful handling of personal data through contractual agreements or other suitable safeguards.


Job Applications

a) Type and Scope of Data Processing

You may apply via our website or by email. If you apply, we collect and store the data you enter in the input form or send to us by email.

b) Purpose and Legal Basis

We process your data exclusively for the purpose of processing your application.
Data is not passed on to third parties.

The legal basis for processing is Article 88(1) GDPR in conjunction with Section 26 BDSG, and additionally Article 6(1)(b) GDPR. If you give us your consent to include you in our applicant pool, the legal basis is Article 6(1)(a) GDPR.

c) Storage Duration

If we are unable to offer you a position, we will store your data for a maximum of six months after completion of the application process, taking into account Section 61b(1) ArbGG in conjunction with Section 15 AGG. The limitation period begins upon receipt of the rejection letter.

If you have given us your consent to include you in our applicant pool, we will store your data for a maximum of two years.

d) Data Transfer

Your data will only be received by the departments involved in the decision-making process (responsible HR or specialist departments, management, works council).

In addition, we are obliged to transmit your data to public authorities and institutions (e.g. public prosecutor’s office, police, supervisory authorities, tax office, social security institutions, etc.).

Further data recipients may be those entities to whom you have given your consent for data transmission.


Comment Function

a) Type and Scope of Data Processing

You can comment on posts on our website. When you comment on a post, we collect and store the data you enter in the input form. In addition to the comments you leave, information on the time the comment was entered and, if applicable, the username (pseudonym) you chose will be stored and published. Furthermore, the IP address assigned by the Internet Service Provider (ISP) of the data subject will be stored. Data is not passed on to third parties.

b) Purpose and Legal Basis

The data you provide (e.g. IP address) is processed for security reasons and in the event that the data subject violates third-party rights or posts unlawful content by submitting a comment.

There is no disclosure of this collected personal data to third parties unless such disclosure is required by law or serves the legal defense of the controller.

The legal basis for processing personal data transmitted when using the comment function is Article 6(1)(a) GDPR if and insofar as you have given your consent. You may revoke this consent at any time. The lawfulness of processing carried out prior to revocation remains unaffected.

Another legal basis is Article 6(1)(f) GDPR.

We have a legitimate interest in processing in the event that third-party rights are violated or unlawful content is posted. This serves security purposes in case someone posts illegal content in comments or posts (insults, prohibited political propaganda, etc.).

c) Storage Duration

Comments and the associated data (e.g. IP address) are stored and remain on our website until the commented content has been completely deleted or the comments must be deleted for legal reasons.


Contact Form

a) Type and Scope of Data Processing

We offer you the opportunity to contact us via a form provided on our website. During the submission of your inquiry via the contact form, reference is made to this privacy policy to obtain your consent.

If you use the contact form, the following personal data will be processed:

  • Salutation

  • First name

  • Last name

  • Title

  • Company

  • Industry

  • Position

  • Street

  • Street number

  • Postal code

  • City

  • Country

  • Email address

  • Telephone number

  • Subject

  • Message content

b) Purpose and Legal Basis

Providing your email address serves the purpose of responding to your inquiry by email. No personal data is passed on to third parties when using the contact form.

The legal basis for processing is consent pursuant to Article 6(1)(a) GDPR, based on the consent declaration voluntarily given by you below and revocable at any time for the future.

c) Storage Duration

The data entered in the contact form will remain with us until you request deletion, revoke your consent to storage, or the purpose for data storage no longer applies (e.g. after your inquiry has been fully processed).

Mandatory statutory provisions – in particular retention periods under the German Commercial Code (HGB) or the German Fiscal Code (AO) – remain unaffected.


Contact by Email

A contact option by email is available on our website.

a) Type and Scope of Data Processing

You may contact us by email. Our data collection is limited to the email address of the email account you use to contact us and the personal data you voluntarily provide in the course of contacting us.

b) Purpose and Legal Basis

The purpose of data processing is to be able to respond appropriately to your inquiry. The legal basis for this is Article 6(1)(f) GDPR. There is a legitimate interest in processing the above-mentioned personal data in order to properly handle your request.

c) Storage Duration

The duration of storage of the above data depends on the background of your inquiry. Your personal data will generally be deleted once the purpose of communication has ceased and storage is no longer required, for example after your request has been processed.


Newsletter

a) Type and Scope of Data Processing

Our website offers the option to subscribe to a free regular email newsletter. In order to send you the newsletter regularly, we require your email address.

We use the so-called double opt-in procedure for sending the newsletter.

This means that we will only send you an email newsletter once you have expressly confirmed that you consent to receiving the newsletter. We will then send you a confirmation email asking you to confirm by clicking a corresponding link that you wish to receive newsletters from us in the future.

This ensures that only you, as the owner of the specified email address, can subscribe to the newsletter. Your confirmation must be given promptly after receiving the confirmation email, otherwise your newsletter subscription will be automatically deleted from our database.

When you subscribe to the newsletter, we collect and store the data you enter in the input form (e.g. last name, first name, email address).

When registering for the newsletter, we also store your IP address provided by the Internet Service Provider (ISP), as well as the date and time of registration, in order to trace possible misuse of your email address at a later time. For the confirmation email sent for verification purposes (double opt-in email), we also store the date and time of clicking the confirmation link and the IP address provided by the ISP.

b) Purpose and Legal Basis

The data collected during newsletter registration is used exclusively for promotional communication via the newsletter.

The processing of your email address for newsletter distribution is based on your consent pursuant to Article 6(1)(a) GDPR and Section 7(2)(3) UWG, which you have voluntarily given and may revoke at any time for the future.

In addition, processing is based on Article 6(1)(f) GDPR due to our legitimate interest in documenting proof of the required consent.

c) Storage Duration

Your email address will be stored for as long as you are subscribed to the newsletter. After unsubscribing from the newsletter, your email address will be deleted unless you have expressly consented to further use of your data.


Tracking and Analysis Tools

An exact overview of the web analytics and social media tools we use can be found here.


Data Security and Protective Measures

We undertake to protect your privacy and to treat your personal data confidentially. To this end, we implement extensive technical and organizational security measures that are regularly reviewed and adapted to technological progress.

These include, among other things, the use of recognized encryption methods (SSL or TLS). Data disclosed unencrypted, for example via unencrypted email, may possibly be read by third parties. We have no influence over this. It is the responsibility of the respective user to protect the data they provide against misuse by encryption or other means.


Changes to This Privacy Policy

We reserve the right to update this statement at any time if necessary.


Your Rights

Below you will find your rights with regard to your personal data. Details arise from Articles 7, 15–22 and 77 GDPR. You may contact the responsible controller (Section 2) in this regard.

Right to Withdraw Consent under Article 7(3) GDPR

You may withdraw your consent to the processing of your personal data at any time with effect for the future. The lawfulness of processing carried out prior to the withdrawal remains unaffected.

Right of Access under Article 15 GDPR

You have the right to request confirmation as to whether personal data concerning you is being processed. If so, you have the right to access this personal data and further information, such as the purposes of processing, the categories of personal data processed, the recipients, and the planned storage duration or the criteria used to determine that duration.

Right to Rectification under Article 16 GDPR

You have the right to request the immediate rectification of inaccurate data. Taking into account the purposes of processing, you also have the right to request the completion of incomplete data.

Right to Erasure (“Right to Be Forgotten”) under Article 17 GDPR

You have the right to erasure insofar as processing is not necessary. This is the case, for example, if your data is no longer required for the original purposes, you have withdrawn your consent, or the data has been unlawfully processed.

Right to Restriction of Processing under Article 18 GDPR

You have the right to request restriction of processing, for example if you believe that the personal data is inaccurate.

Right to Data Portability under Article 20 GDPR

You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format.

Right to Object under Article 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you.

In the case of direct marketing, you have the right to object at any time to the processing of personal data concerning you for such marketing purposes; this also applies to profiling insofar as it is related to such direct marketing.

Automated Individual Decision-Making Including Profiling under Article 22 GDPR

You have the right not to be subject to a decision based solely on automated processing, including profiling, except in the cases referred to in Article 22 GDPR.

Right to Lodge a Complaint under Article 77 GDPR

You also have the right to lodge a complaint with a data protection supervisory authority at any time, for example if you believe that the processing of personal data does not comply with data protection regulations.


 

B2B Login

Forgot your password?

No business account yet?
Create a B2B account for exclusive pricing