Privacy Policy

This privacy policy explains which types of personal data we process, for what purposes and to what extent. Personal data is also referred to below simply as data. This privacy policy applies to all processing of personal data carried out by us, both in connection with the services we provide and, in particular, on our websites. The terms used are gender-neutral.

Last updated: 08.10.2026

Controller

Sanecum Gruppe GmbH Managing directors: Ulf Völkel, Dr. Susanne H. Hoischen Hohe Bleichen 19 20354 Hamburg Germany Phone: +49 (0)40 – 356 740 04 - 0 Email: kontakt@sanecum.de

Privacy contact

You can contact our privacy contact at: datenschutz@sanecum.de

Data protection officer

You can contact our data protection officer at: dsb@sanecum.de

Overview of processing activities

The following overview summarizes the categories of data we process, the purposes of processing and the groups of people affected.

  • Categories of data processed: master data, content data, contact data, health data (special categories of personal data under Art. 9 GDPR), metadata and communication data, and usage data.
  • Groups of people affected: communication partners, patients and users, especially website visitors and applicants for holiday dialysis.
  • Purposes of processing: providing the website, handling holiday dialysis requests, handling contact requests and communication, and measuring reach.

Key legal bases

We process personal data in particular where this is necessary for contract performance or pre-contractual requests under Art. 6 (1) sentence 1 lit. b GDPR, and where processing is based on legitimate interests under Art. 6 (1) sentence 1 lit. f GDPR.

In addition to the GDPR, national data protection rules apply, in particular the German Federal Data Protection Act (BDSG). The BDSG contains specific provisions, including rules on access, erasure, objection, processing special categories of personal data, processing for other purposes and processing data in an employment context.

Where we process special categories of personal data, in particular health data in the context of holiday dialysis requests, we rely on your explicit consent under Art. 9 (2) lit. a GDPR. Your details are only transmitted once you have given your explicit consent by ticking the relevant checkbox in the form. You can withdraw your consent at any time with effect for the future.

Security measures

We take technical and organizational measures to ensure an appropriate level of protection for personal data, for example by controlling physical and electronic access, using encryption and applying secure procedures.

Contacting us

When you contact us, for example by contact form, email or telephone, we process the information you provide if this is necessary to answer your request and deal with any related matter.

We respond within contractual or pre-contractual relationships to meet our contractual obligations or answer requests, and otherwise on the basis of our legitimate interest in responding to enquiries. The data provided is used only to respond to your enquiry. Unless you have consented to further use, your data will be deleted after your request has been answered.

  • Categories of data processed: in particular master data, contact data and content data.
  • People affected: communication partners.
  • Purposes of processing: contact handling and communication.
  • Legal bases: contract performance, pre-contractual requests and legitimate interests.

Handling holiday dialysis requests

When you request holiday dialysis through our form, we process your personal data, including health data, to handle your request, in particular to contact you, check available capacity and schedule appointments and shifts. The only health datum collected through the form is the dialysis method, where you choose to provide it. Further medical records, such as your dialysis plan, medication plan or infection status, are not collected through this form; where they are needed you arrange them directly with the dialysis facility.

The controller for this processing is Sanecum Gruppe GmbH (see the Controller section). Your details are only transmitted after you have expressly consented to the processing by ticking the checkbox in the form. To handle your request, we forward it to the Sanecum dialysis facility you select, which handles your request and gets back to you.

We store the data collected as part of the request only for as long as necessary to handle your request, and at most 90 days after your request has been handled. We retain it beyond that only where statutory retention obligations require it.

  • Categories of data processed: master data, contact data, content data and health data (special categories of personal data under Art. 9 GDPR, here the dialysis method you select).
  • People affected: applicants for holiday dialysis.
  • Purposes of processing: handling the holiday dialysis request, contacting you, checking available capacity, and scheduling appointments and shifts.
  • Recipients: the Sanecum dialysis facility you select.
  • Legal bases: your explicit consent under Art. 6 (1) sentence 1 lit. a and Art. 9 (2) lit. a GDPR.

Provision of the online offering and web hosting

To provide our online offering securely and efficiently, we use the services of one or more web hosting providers. This may include infrastructure and platform services, computing capacity, storage space, database services, security services and technical maintenance.

The data processed while providing the online offering may include information that users provide when using the site or communicating with us. This regularly includes the IP address, which is required to deliver content to browsers, as well as input made within our online offering.

Email sending and hosting

The web hosting services we use also include sending, receiving and storing emails. For these purposes, recipient and sender addresses, further information about email transmission and the content of the relevant emails are processed. This data may also be processed to detect spam.

Emails are generally not sent with end-to-end encryption over the internet; we therefore cannot accept responsibility for the transmission path between the sender and receipt on our server.

Collection of access data and log files

We, or our web hosting provider, collect protocol data about access to the server, known as server log files. The data processed includes in particular content data and metadata or communication data. The people affected are users of the online offering. The legal basis is legitimate interests under Art. 6 (1) sentence 1 lit. f GDPR.

Visitor statistics

To better understand what visitors are interested in on our websites and whether they can find their way around, we use the open-source analytics tool Matomo. Because Matomo is hosted on our own server, this data does not leave our area of responsibility. We run Matomo without cookies: no cookies are set to recognise individual users. IP addresses are anonymized in our configuration and cannot be traced back to the actual connection.

We record page views, clicks on appointment request buttons, and the opening and successful submission of the request form. The details you enter in the form are not transmitted to Matomo; on submission only the selected dialysis center is recorded as a label for the event.

If you do not want your visits to be recorded, you can activate the do-not-track option in your browser. Our Matomo installation evaluates this setting and will then not collect any data from you.

Map display (Mapbox)

On the region pages we embed an interactive map provided by Mapbox showing our dialysis centers and selected places in the region. The map is only loaded once you scroll down to the map section. Until the map becomes visible, and on every page without a map, no connection to Mapbox is made.

When the map loads, your browser retrieves map tiles, fonts and style data directly from Mapbox servers. Your IP address is transmitted to Mapbox in the process; it is technically necessary in order to deliver the map content to your browser. Information about your browser and device, as well as the map section being viewed, is also transmitted.

Mapbox additionally collects usage statistics about the map. For this purpose the map stores three entries in your browser's local storage, including a randomly generated identifier. The map does not set cookies. The identifier remains on your device until you clear your browser's local storage.

Types of data processed: usage data as well as meta, communication and procedural data. Data subjects: users of the online offering. Purposes: provision of the online offering and user-friendliness. Legal basis: legitimate interests pursuant to Art. 6(1)(1)(f) GDPR in presenting the location of our centers in a comprehensible way.

Mapbox is a provider based in the United States; a transfer of data to the USA can therefore not be ruled out. Details of the processing carried out by the provider can be found in its privacy policy at https://www.mapbox.com/legal/privacy.

Deletion of data

The data we process is deleted in accordance with legal requirements as soon as consent is withdrawn or other permissions no longer apply, especially when the purpose of processing no longer exists or the data is no longer required for that purpose.

If data cannot be deleted because it is required for other legally permitted purposes, its processing is restricted to those purposes. This applies, for example, to data that must be retained for commercial or tax reasons, or where storage is required to establish, exercise or defend legal claims. Server log files are deleted after 14 days.

Changes and updates to this privacy policy

Please review this privacy policy regularly. We update it whenever changes to our processing activities make this necessary. We will inform you if a change requires action on your part, such as consent, or an individual notification.

Rights of data subjects

As a data subject under the GDPR, you have various rights, especially under Articles 15 to 18 and 21 GDPR.

  • Right to object
  • Right to withdraw consent
  • Right of access
  • Right to rectification
  • Right to erasure and restriction of processing
  • Right to data portability
  • Right to lodge a complaint with a supervisory authority

Definitions

Personal data means any information relating to an identified or identifiable natural person. Remarketing or retargeting refers to processes in which, for advertising purposes, it is recorded which products or content a user has shown interest in. Tracking means following user behavior across several online offerings.

Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Processing means any operation or set of operations performed on personal data, such as collection, evaluation, storage, transmission or deletion.