1. General Information
1.1 What Are Personal Data?
Personal data are details that reveal or can reveal the identity of the user. We adhere to the principle of data minimization. The collection of personal data is avoided as much as possible.
1.2 Handling of Personal Data
Personal data are used solely for the establishment, content design, execution, or handling of the contractual relationship (Art. 6 I S. 1 b GDPR).
Beyond this, personal data are only processed if we have received your consent (Art. 6 I S. 1 a GDPR) or if the data processing is necessary for our legitimate interests and a balancing test determines that there are no overriding interests, fundamental rights, or freedoms on your part that conflict with this (Art. 6 I S. 1 f GDPR).
We may use data processors for processing your personal data. Where necessary, we have concluded data processing agreements with them. However, we generally do not share personal data with third parties.
Personal data will only be transferred to the shipping company responsible for delivery if this is necessary for delivering ordered goods. To process payments, the required payment data will be passed on to the credit institution responsible for the payment and, if applicable, the chosen payment service provider.
The processing of your personal data takes place exclusively within the EU unless otherwise stated below. The processing occurs within the EU and in countries deemed secure or appropriate by the EU. If personal data are processed in the USA, we ensure that the services we use are certified under the "Data Privacy Framework".
1.3 Usage Data
When visiting the website, general technical information is collected. This includes the IP address used, time, duration of the visit, browser type, and, if applicable, the referring page. This usage data is technically recorded in a log file and may be used and stored for statistical evaluation of the website. There is no linkage of this usage data with your other personal data.
1.4 Registration Data
To fully utilize the features of our website, registration is required. Registration data are collected through your respective inputs and used for the explicitly stated purpose based on your consent (Art. 6 I S. 1 a GDPR).
1.5 Duration of Storage
We store your personal data only as long as necessary for the purpose for which they were collected and only as long as required by legal (especially tax law) provisions.
2. Your Rights
2.1 Right to Information
You have the right to request information from us about whether we process personal data concerning you. If this is the case, you have the right to access these personal data and the further information specified in Art. 15 GDPR.
2.2 Right to Rectification
You have the right to have inaccurate personal data concerning you corrected and may request the completion of incomplete personal data in accordance with Art. 16 GDPR.
2.3 Right to Deletion
You have the right to request that we delete your personal data immediately. We are obliged to delete these immediately, especially if one of the following reasons applies:
- Your personal data are no longer necessary for the purposes for which they were collected or otherwise processed.
- You revoke your consent on which the processing of your data was based, and there is no other legal basis for processing.
- Your data have been processed unlawfully.
The right to deletion does not apply if your personal data are required for asserting, exercising, or defending legal claims.
2.4 Right to Restriction of Processing
You have the right to request that we restrict the processing of your personal data if:
- You contest the accuracy of the data, and we need time to verify its accuracy.
- The processing is unlawful, and you oppose deletion and instead request the restriction of use.
- We no longer need the data, but you require them for asserting, exercising, or defending legal claims.
- You have objected to the processing of your data, and it has not yet been determined whether our legitimate reasons override yours.
2.5 Right to Data Portability
You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format and to transmit these data to another controller without hindrance from us, provided that the processing is based on consent or a contract and is carried out by automated means.
2.6 Right to Withdrawal and Objection
If the processing of your personal data is based on consent (Art. 6 S. 1 a GDPR), you have the right to withdraw this consent at any time. This does not affect the lawfulness of the processing carried out based on the consent before its withdrawal.
If the processing of your personal data is based on Art. 6 S. 1 e GDPR or Art. 6 S. 1 f GDPR, you have the right under Art. 21 GDPR to object to the processing of your personal data at any time for reasons arising from your particular situation. In that case, we will no longer process your personal data unless we can demonstrate compelling legitimate reasons for processing that outweigh your interests, rights, and freedoms, or the processing serves to assert, exercise, or defend legal claims.
2.7 General Information and Right to Lodge a Complaint
Exercising your above rights is generally free of charge. You have the right to lodge a complaint directly with the supervisory authority responsible for us, the state data protection officer.
3. Data Security
3.1 Data Security
All data on our website are secured against loss, destruction, access, modification, and distribution through technical and organizational measures.
3.2 Sessions and Cookies
To operate the website, we use cookies or server-side sessions in which data can be stored. We ensure that no personal data from sessions or cookies are stored without your explicit consent, and that cookies are only used when technically necessary for the website (e.g., spam protection in contact forms, shopping cart function). This is based on a balancing test to ensure that no overriding interests on your part are negatively affected (Art. 6 I S. 1 f GDPR) or that explicit consent has been given.
Upon your explicit consent, we use cookies to personalize content and ads, provide social media features, and analyze website traffic. With your consent, we may share information about your use of our website with our social media, advertising, and analytics partners. These partners may combine this information with other data they already have about you.
Details (e.g., domain, name, duration) of cookies used only with your consent can be found in the respective cookie banner.
4. Newsletter
If you sign up for our newsletter, we will use the data required for this purpose or separately provided by you to send you our email newsletter regularly, based on your consent according to Art. 6 I S. 1 a GDPR.
You can unsubscribe from the newsletter at any time by contacting us using the contact details provided in the imprint or via the designated link in the newsletter. After unsubscribing, we will delete your email address unless you have explicitly consented to further use of your data or if we are legally allowed to use the data beyond this, which we inform you about in this statement.
5. Presence on Social Media Platforms
We use the following social media platforms for corporate representation and communication (we explicitly refer to the linked privacy policies and opt-out options below).
- Facebook (Meta Platforms Ireland Ltd., Merrion Road, D04 X2K5, Dublin 4, Ireland)
Privacy Policy: https://www.facebook.com/about/privacy/
Opt-Out: http://www.youronlinechoices.com - X (Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland)
Privacy Policy: https://twitter.com/de/privacy
Opt-Out: https://twitter.com/personalization - WhatsApp (Meta Platforms Ireland Ltd., Merrion Road, D04 X2K5, Dublin 4, Ireland)
Privacy Policy: https://www.whatsapp.com/legal/#privacy-policy - TikTok (TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland)
Privacy Policy: https://www.tiktok.com/legal/privacy-policy?lang=de - Instagram (Meta Platforms Ireland Ltd., Merrion Road, D04 X2K5, Dublin 4, Ireland)
Privacy Policy and Opt-Out: http://instagram.com/about/legal/privacy/
These social media platforms may process personal data outside the EU. We refer to the respective privacy policies of the social media platforms above. The respective platforms may create usage profiles based on your user behavior and the resulting interests and actions, storing cookies on your device that record your behavior. If you have an account and are logged in to the respective social media platform, your user behavior may even be stored across devices. Your user profile can be used, for example, to place ads that are likely aligned with your interests. We process personal data exclusively to communicate with you via your chosen social media platform and to optimize our online presence, ensuring that no interests on your part override our legitimate interests (Art. 6 I S. 1 f GDPR). If you have already given the respective platform operator valid consent for data processing, the processing of your personal data also takes place based on this consent (Art. 6 I S. 1 a GDPR).
6. Services from Third-Party Providers
6.1 Social Media Links and Social Sharing
We have our own social media pages with third-party providers accessible via links from this website. By using these links, you will be redirected to the respective websites of these third parties (e.g., Facebook, Twitter, Instagram), where you can also share our content. No data transfer occurs when you visit our website. To avoid unnecessary data sharing, we recommend logging out of the respective third-party provider before using the link, so that usage profiles are not created simply by using the link.
6.2 Use of Matomo
We use the web analytics service Matomo, provided by InnoCraft Ltd, 7 Waterloo Quay PO625, 6140 Wellington, New Zealand, on this website. No "cookies" are used, but rather a config_id, which is a randomly generated, time-limited hash of a limited set of website visitor settings and attributes. The config_id or config hash is a string generated for a visitor based on their operating system, browser, browser plugins, IP address, and browser language. The IP address is immediately anonymized so that you as a user remain unidentifiable to us. No device fingerprinting takes place, and the config_id is only valid for less than 24 hours and only for a specific website domain. Furthermore, the generated information about your use of this website is not shared with third parties. The processing is carried out for the general optimization of our website. No user interests are affected that would outweigh this technical necessity, making the use of this service our legitimate interest (Art. 6 I S. 1 f GDPR). You have the option to prevent your actions on this website from being analyzed and linked. This will protect your privacy, but it will also prevent the website operator from learning from your actions and optimizing usability for you and other users.
6.3 Use of Here WeGo
This website uses the map service from Here WeGo, operated by HERE Global B.V, Kennedyplein 222 -226, 5611 ZT Eindhoven, Netherlands. When using Here WeGo, your IP address is processed by the provider to provide the functions. No user interests are affected that would outweigh the technical necessity of integrating interactive map material (Art. 6 I S. 1 f GDPR). The privacy policy of Here WeGo can be found at: https://legal.here.com/de-de/privacy/here-wego-here-application-or-here-maps-privacy-supplement-updated.
6.4 Use of YouTube
This website and the integrated offers contain embedded YouTube videos, allowing a connection to YouTube and access to stored videos. YouTube is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). No user interests are affected that would outweigh the technical necessity of embedding videos (Art. 6 I S. 1 f GDPR). The purpose and scope of data collection and data usage by Google, as well as your rights and settings options for protecting your privacy as a YouTube user, can be found in YouTube’s privacy policy at: http://www.youtube.com/t/privacy/.
6.5 Amazon Affiliate Program
Medizin-in-Europa.de Studienplatzvermittlung GmbH participates in the Amazon Europe Core S.a.r.l. affiliate program (5 Rue Plaetis, L-2338 Luxembourg, Luxembourg, VAT registration number: LU 26375245), an advertising program designed to provide a means for websites to earn advertising fees by placing advertisements and links to Amazon.de. Amazon may use cookies to identify the source of orders or visits. This does not affect the use of our website and does not create any purchase obligation. The affiliate and advertising links or banners are intended only to facilitate purchases. The respective Amazon privacy policies apply:
https://www.amazon.de/gp/help/customer/display.html?nodeId=GX7NJQ4ZB8MHFRNJ.
6.6 Use of Google reCAPTCHA
This website uses the reCAPTCHA service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). This function serves to distinguish whether input is made by a human or abusively through automated, machine processing. The query includes sending the IP address and possibly other data required by Google for the reCAPTCHA service to Google. For this purpose, your input is transmitted to Google and used further there. However, within member states of the European Union or other contracting states of the European Economic Area Agreement, Google truncates the IP address beforehand. Only in exceptional cases is the full IP address sent to a Google server in the USA and truncated there. The IP address transmitted by your browser as part of reCAPTCHA is not merged with other Google data. The processing serves to prevent misuse of this website and is ultimately carried out in an anonymized manner, meaning that no overriding interests on your part counteract this processing (Art. 6 I S. 1 f GDPR). Google's privacy policies apply, which you can find at: https://policies.google.com/privacy?hl=de.
6.7 Use of WhatsApp Business
We may use WhatsApp Business for communication with you. The service provider is WhatsApp LLC, 1601 Willow Road, Menlo Park, California 94025, USA. The responsible entity for the European region is WhatsApp Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
The data you enter for communication purposes (first name, last name, and mobile number) will be stored by us and on the servers of WhatsApp LLC or WhatsApp Ireland Limited.
WhatsApp LLC or WhatsApp Ireland Limited stores and processes personal data and shares them with other companies within and outside the Meta corporate group (Meta Platforms Inc., 1601 S. California Ave, Palo Alto, California 94304, USA). Further information on this can be found in WhatsApp's privacy policy: https://www.whatsapp.com/legal/#privacy-policy. We have neither precise knowledge nor influence over the data processing by WhatsApp LLC, WhatsApp Ireland Limited, or Meta Platforms Inc.
Data processing is based on your consent (Art. 6 I S.1 a GDPR). You can revoke this consent at any time. The lawfulness of data processing carried out before the revocation remains unaffected.
6.8 Use of Google Ads
6.8.1 Google Ads Conversion
We use Google Ads Conversion (operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to promote our services on external websites using advertisements (so-called Google Ads). These ads are delivered via Google's "Ad Servers." Ad server cookies are used to measure specific success parameters, such as ad impressions or user clicks. If you reach our website via a Google advertisement, a cookie will be stored on your device by Google Ads. These cookies usually expire after 30 days and are not intended to personally identify you. The cookie generally stores analytical values such as the unique cookie ID, number of ad impressions per placement (frequency), last impression (relevant for post-view conversions), and opt-out information. If you visit our website through such an advertisement and the cookie stored on your computer has not yet expired, Google and we can recognize that you clicked on the ad and were redirected to our site. Each Google Ads customer receives a different cookie, meaning cookies cannot be tracked across different advertisers’ websites. We do not collect or process any personal data within these advertising measures. We only receive statistical evaluations from Google. These evaluations help us determine which advertising measures are particularly effective. We do not receive further data from these advertisements, particularly data that would allow us to identify users. Due to the use of these marketing tools, your browser automatically establishes a direct connection to Google's server. We have no influence over the extent or further use of data collected by Google using this tool and can only inform you that Google may associate your visit to our website with your Google account if you are logged in. Additionally, Google may collect and store your IP address regardless of whether you have a user account. The legal basis for using Google Ads is your consent (Art. 6 I S. 1 a GDPR). You can view Google's privacy policy here: http://www.google.com/intl/de/policies/privacy.
6.8.2 Google Ads Remarketing
This website uses the remarketing function of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This function allows us to display interest-based advertisements to website visitors within the Google advertising network. A "cookie" is stored in the visitor’s browser, allowing the visitor to be pseudonymously recognized when they visit websites that belong to Google’s advertising network. On these websites, advertisements related to content the visitor previously viewed on other sites using Google’s remarketing feature may be displayed. According to Google, no personal data is collected in this process. However, if you do not want Google’s remarketing function to be used, you can deactivate it in the settings at http://www.google.com/settings/ads. Alternatively, you can disable interest-based advertising cookies by following the instructions at http://www.networkadvertising.org/managing/opt_out.asp.
You can view Google’s privacy policy here: http://www.google.com/intl/de/policies/privacy.
6.9 Use of Google Tag Manager
This website also uses Google Tag Manager (operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). This tool implements and manages website tags through an interface. No cookies are used. However, your IP address may be transmitted to Google Tag Manager. The Google Tag Manager triggers other tags, which may in turn collect data. However, Google Tag Manager does not access this data. If deactivation has been implemented at the domain or cookie level, it remains in effect for all tracking tags managed via Google Tag Manager. The use of Google Tag Manager occurs solely with your explicit consent when personal data is processed (Art. 6 I S. 1 a GDPR). You can view Google's privacy policy here: http://www.google.com/intl/de/policies/privacy.
6.10 Use of imgix
We use the imgix tool (operated by imgix, Inc., 423 Tehama St, San Francisco, CA 94103, USA) to integrate our graphics. Your IP address is transmitted to imgix in the USA to enable the technical display of images. The use of imgix is in our legitimate interest to provide a simple and fast delivery of our images (Art. 6 I S. 1 f GDPR). No overriding user interests are affected that would outweigh this technical necessity. You can view imgix’s privacy policy here: https://www.imgix.com/privacy.
7. Contact
For inquiries regarding data protection, you may contact us using the following contact details.
Controller as defined by the GDPR:
medizin-in-europa.de Studienplatzvermittlung GmbH
Flemmingstraße 2g
09116 Chemnitz
Email: recht@medizin-in-europa.de
Phone: +49 (0) 371 33 78 98 41
Fax: +49 (0) 371 33 78 98 42