Privacy Policy

Welcome to our website!

We attach the greatest importance to protecting your data and safeguarding your privacy. Below we therefore inform you about the collection and use of personal data when you use our website.

1. Name and contact details of the controller

This privacy information applies to data processing by:

Controller: Verus Salus GmbH, St. Vinzenz-Allee 1, 36364 Bad Salzschlirf, Germany

2. Collection and storage of personal data and the nature and purpose of their use

a) When visiting the website

When you access our website https://verusbonifatius-en.ppgmbhdev.de/, the browser used on your device automatically sends information to the server of our website – where applicable via our hosting provider. This information is temporarily stored in a so-called log file. The following information is collected without any action on your part and stored until it is automatically deleted: – IP address of the requesting computer, – date and time of access, – name and URL of the file retrieved, – website from which access is made (referrer URL), – browser used and, where applicable, the operating system of your computer and the name of your access provider. We process this data for the following purposes: – ensuring that the connection to the website is established smoothly, – ensuring convenient use of our website, – evaluating system security and stability, and – other administrative purposes. The legal basis for this data processing is Art. 6 (1) sentence 1 (f) GDPR. Our legitimate interest follows from the purposes of data collection listed above. Under no circumstances do we use the data collected to draw conclusions about you personally. In addition, we use cookies and analytics services when you visit our website. You will find more detailed explanations in sections 5 and 6 of this privacy policy.

b) When using our contact form

If you have questions of any kind, you can contact us using a form provided on the website. A valid e-mail address is required so that we know who sent the enquiry and can answer it. Further information can be provided voluntarily. Data processing for the purpose of contacting us is carried out in accordance with Art. 6 (1) sentence 1 (a) GDPR on the basis of your voluntarily given consent. The personal data we collect for the use of the contact form is automatically deleted once your enquiry has been dealt with.

c) Reviews, comments and posts

If users leave reviews, comments or other posts, their entries and data are stored for the period during which the respective entry is visible. The background is possible claims by third parties in the event of unlawful entries. The legal basis is the consent given when submitting the review pursuant to Art. 6 (1) (a) GDPR as well as our legitimate interest pursuant to Art. 6 (1) sentence 1 (f) GDPR.

To validate the e-mail address provided and to ensure that the review really comes from you, submitting a review goes through the following process.

a. The user submits their review including their data.

b. The user is then sent a verification e-mail with a confirmation link (similar to a newsletter subscription).

c. As soon as the user confirms this link, the review is stored as “valid” in our database.

d. The review is then manually approved after checking.

3. Period for which the personal data are stored

The criterion for the duration of storage of personal data is generally the respective statutory retention period or the period for which the data is required for legal reasons. After this period has expired, the corresponding data is routinely deleted, provided that it is no longer required for the performance or initiation of a contract.

4. Disclosure of data

Your personal data will not be transferred to third parties for purposes other than those listed below. We only pass on your personal data to third parties if:

– you have given your express consent to this in accordance with Art. 6 (1) sentence 1 (a) GDPR,

– the disclosure is necessary pursuant to Art. 6 (1) sentence 1 (f) GDPR for the establishment, exercise or defence of legal claims and there is no reason to assume that you have an overriding legitimate interest in your data not being disclosed,

– there is a legal obligation to disclose the data pursuant to Art. 6 (1) sentence 1 (c) GDPR, and

– this is legally permissible and necessary pursuant to Art. 6 (1) sentence 1 (b) GDPR for the performance of contractual relationships with you.

If we process data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this happens in the context of using third-party services or disclosing or transferring data to third parties, this only takes place if it is done to fulfil our (pre-)contractual obligations, on the basis of your consent, on the basis of a legal obligation or on the basis of our legitimate interests. Subject to legal or contractual permissions, we only process data, or have data processed, in a third country if the special requirements of Art. 44 et seq. GDPR are met. This means that processing takes place, for example, on the basis of special guarantees, such as the officially recognised determination of a level of data protection corresponding to that of the EU (e.g. for the USA through the “EU-U.S. Data Privacy Framework”) or compliance with officially recognised special contractual obligations (so-called “standard contractual clauses”).

5. Cookies

Our web pages use so-called cookies in several places. Cookies are small text files that are placed on your computer and stored by your browser. They serve to make our offering more user-friendly, more effective and more secure. Cookies do not cause any damage to your device and do not contain malware. On the one hand, cookies are used to make using our offering more pleasant for you. For example, we use so-called session cookies to recognise that you have already visited individual pages of our website. These are automatically deleted after you leave our site. In addition, to optimise user-friendliness, we also use temporary cookies that are stored on your device for a specified period of time. If you visit our site again to use our services, it is automatically recognised that you have already been with us and which entries and settings you have made, so that you do not have to enter them again. On the other hand, we use cookies to statistically record the use of our website and to evaluate it for the purpose of optimising our offering for you. These cookies enable us to automatically recognise that you have already been with us when you visit our site again. These cookies are automatically deleted after a defined period of time. We use technically necessary cookies on the basis of Section 25 (2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act) and Art. 6 (1) sentence 1 (f) GDPR. All other cookies (preferences, statistics, marketing) are only used with your consent (Section 25 (1) TDDDG, Art. 6 (1) sentence 1 (a) GDPR), which you give via our cookie banner and can withdraw there at any time. Most browsers accept cookies automatically. However, you can configure your browser so that no cookies are stored on your computer or so that a notice always appears before a new cookie is created. However, completely deactivating cookies may mean that you cannot use all the functions of our website.

6. Analytics & marketing tools

We only use the analytics and marketing tools listed below if you have given us your consent via our cookie banner. The legal basis for storing information on, and accessing information in, your device is Section 25 (1) TDDDG; for the subsequent processing of your data it is Art. 6 (1) sentence 1 (a) GDPR. Without your consent these services are not loaded. You can withdraw or change your consent at any time with effect for the future by reopening the cookie settings via the icon at the bottom of the screen. The lawfulness of processing carried out before the withdrawal remains unaffected.

Where data is transferred to the USA in this context, we base this on the EU Commission’s adequacy decision for the EU-U.S. Data Privacy Framework, provided the respective provider is certified under it, and otherwise on standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.

Consent management with Cookiebot

To obtain and manage your consent we use “Cookiebot” by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark. Cookiebot stores your choice in a cookie (“CookieConsent”, duration 12 months) and in doing so processes your anonymised IP address, the date and time of consent, browser information, the URL of the page and a random key as proof. This processing is necessary to fulfil our obligations to provide proof (Art. 6 (1) sentence 1 (c) GDPR in conjunction with Art. 7 (1) GDPR). A data processing agreement has been concluded with the provider.

Google Tag Manager

We use Google Tag Manager by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Tag Manager is an auxiliary service through which we control the services described below; it does not itself create user profiles or set its own cookies, but for technical reasons processes your IP address when it is loaded. Tag Manager is only loaded on our website after you have consented to statistics or marketing cookies.

Further information on data protection can be found on the following Google web pages:

• Privacy policy: https://policies.google.com/privacy?hl=en

• Google Tag Manager FAQ: https://www.google.com/intl/en/tagmanager/faq.html

• Google Tag Manager terms of use: https://www.google.com/intl/en/tagmanager/use-policy.html

Google Analytics 4 (with server-side tagging)

With your consent to the “Statistics” category we use Google Analytics 4, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. In particular, the following are processed: pseudonymous online identifiers (client ID from the cookies “_ga” and “_ga_*”, duration up to 2 years), truncated IP address, pages viewed, time spent on the site, approximate location, device and browser information, and events such as the submission of a form. Google Analytics 4 does not store IP addresses.

On verusbonifatius-de.ppgmbhdev.de this data is not sent directly from your browser to Google, but first to a tagging server operated by us (sgtm.verusbonifatius-de.ppgmbhdev.de), which forwards it to Google. The server is operated on our behalf by [Stape Europe OÜ, Estonia / Stape, Inc., USA – please enter according to the data processing agreement] as a processor. On verusbonifatius-en.ppgmbhdev.de the data is transmitted directly from your browser.

A transfer to Google LLC in the USA is possible; Google LLC is certified under the EU-U.S. Data Privacy Framework. The retention period for usage data at Google is [2 / 14] months. Further information: https://policies.google.com/privacy

Google Ads conversion tracking, enhanced conversions and remarketing

With your consent to the “Marketing” category we use Google Ads by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. If you reach our website via a Google ad, the click identifier of the ad is stored in cookies (“_gcl_aw”, “_gcl_au”, “FPGCLAW” and “gclid_cookie”, duration up to 90 days). If you subsequently submit a contact, callback or information-pack form, or click on our WhatsApp link, this is reported to Google as a “conversion”. This tells us which ads lead to enquiries; we only receive statistical evaluations from Google and no information with which we could identify you personally.

Enhanced conversions: in order to be able to attribute enquiries to an ad even when cookies are no longer available, when a form is submitted we additionally transmit your e-mail address and/or telephone number to Google exclusively in hashed form (SHA-256, not readable in plain text), together with the type of health insurance you selected. Google matches the hash values against user accounts signed in to Google and deletes them after matching. We do not transmit the content of your message.

On verusbonifatius-de.ppgmbhdev.de the conversion is reported both via our tagging server (see Google Analytics) and directly from your browser; a shared transaction number ensures that the enquiry is only counted once. In addition, Google may add visitors to our website to audience lists in order to show them ads later (remarketing). A transfer to Google LLC in the USA is possible (EU-U.S. Data Privacy Framework). Further information: https://policies.google.com/technologies/ads

Note on Google consent mode: we pass your choice in the cookie banner to the Google services as a signal so that they only operate within the permitted scope. Google services are not loaded on our website before you have made a choice.

Ahrefs Web Analytics

With your consent to the “Statistics” category we use Ahrefs Web Analytics by Ahrefs Pte. Ltd., 16 Raffles Quay, #33-03 Hong Leong Building, Singapore 048581. The service works without cookies and records pages viewed, referring page, device type, browser and the country derived from the IP address; the IP address is not stored. The transfer to Singapore is based on standard contractual clauses. Further information: https://ahrefs.com/legal/privacy-policy

Contact via WhatsApp

In the mobile view we offer a link to WhatsApp (wa.me). By clicking it you leave our website; WhatsApp Ireland Limited, Merrion Road, Dublin 4, Ireland, is responsible for the further processing (https://www.whatsapp.com/legal/privacy-policy-eea). Please do not send us any health data via WhatsApp. If you have consented to marketing cookies, the click on the link is reported to Google as a conversion (see Google Ads).

7. Other tools

WordPress

For the purpose of designing our pages in line with requirements, continuously optimising them and operating them economically, we use WordPress tools from the provider Automattic Inc., 60 29th Street #343, San Francisco, CA 94110-4929, USA.

To optimise and improve our information service on our website, we collect and store data such as the date and time of the page view, the page from which you accessed our page, and the like. This is done anonymously without personally identifying the user of the page. Where applicable, user profiles are created using a pseudonym. Here too, no connection is made between the natural persons behind the pseudonym and the usage data collected.

Automattic’s applicable privacy policy is available at https://automattic.com/privacy/.

8. Integration of third-party services and content

We integrate content or services offered by third-party providers (e.g. videos and maps). Content that involves data being transferred to the third-party provider is only loaded after you have consented to the “Marketing” category via our cookie banner (Section 25 (1) TDDDG, Art. 6 (1) sentence 1 (a) GDPR); until then you will see a notice in its place.

This always requires that the third-party providers of this content perceive the IP address of users, since without the IP address they could not send the content to their browser. The IP address is therefore required to display this content. Furthermore, information on visitor traffic on the pages of this website can be evaluated (for cookies see section 5).

YouTube

We integrate videos from the “YouTube” platform of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: https://www.google.com/policies/privacy

Google Maps

We integrate maps from the “Google Maps” service of the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: https://www.google.com/policies/privacy.

Google Fonts

We integrate fonts (“Google Fonts”) from the provider Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Privacy policy: https://www.google.com/policies/privacy.

9. Hosting

We host our website with our processor:

Hetzner Online GmbH

Industriestr. 25

91710 Gunzenhausen

Germany

Connection data is processed for the purpose of providing and delivering the website. For the mere purpose of delivering and providing the website, the data is not stored beyond the page request.

The legal basis for the data processing is legitimate interest (absolute technical necessity for the provision and delivery of the “website” service expressly requested by you through your request) pursuant to Art. 6 (1) (f) GDPR.

For the operation of the website, the connection data and other personal data are additionally processed in the context of various other functions and services. Details are provided in this privacy policy for the individual functions and services.

10. Rights of data subjects

You have the right:

• pursuant to Art. 15 GDPR, to request information about your personal data processed by us. In particular, you can request information about the purposes of processing, the category of personal data, the categories of recipients to whom your data has been or will be disclosed, the planned storage period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the origin of your data if it was not collected by us, and the existence of automated decision-making including profiling and, where applicable, meaningful information about its details;

• pursuant to Art. 16 GDPR, to request without undue delay the rectification of inaccurate personal data or the completion of your personal data stored by us;

• pursuant to Art. 17 GDPR, to request the erasure of your personal data stored by us, unless the processing is necessary for exercising the right to freedom of expression and information, for compliance with a legal obligation, for reasons of public interest or for the establishment, exercise or defence of legal claims;

• pursuant to Art. 18 GDPR, to request the restriction of the processing of your personal data if you contest the accuracy of the data, if the processing is unlawful but you oppose its erasure and we no longer need the data, but you require it for the establishment, exercise or defence of legal claims, or if you have objected to the processing pursuant to Art. 21 GDPR;

• pursuant to Art. 20 GDPR, to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format, or to request its transmission to another controller;

• pursuant to Art. 7 (3) GDPR, to withdraw your consent, once given, at any time. As a result, we may no longer continue the data processing that was based on this consent in the future; and

• pursuant to Art. 77 GDPR, to lodge a complaint with a supervisory authority. As a rule, you can contact the supervisory authority of your usual place of residence or workplace for this purpose.

11. Right to object

If your personal data is processed on the basis of legitimate interests pursuant to Art. 6 (1) sentence 1 (f) GDPR, you have the right pursuant to Art. 21 GDPR to object to the processing of your personal data, provided there are grounds arising from your particular situation or the objection is directed against direct marketing. In the latter case you have a general right to object, which we will implement without you having to specify a particular situation. If you would like to exercise your right of withdrawal or objection, an e-mail to info@verusbonifatius-en.ppgmbhdev.de is sufficient.

12. Data security

During your visit to the website we use the widespread SSL (Secure Socket Layer) method in conjunction with the highest level of encryption supported by your browser. As a rule, this is 256-bit encryption. If your browser does not support 256-bit encryption, we use 128-bit v3 technology instead. You can tell whether an individual page of our website is transmitted in encrypted form by the closed key or lock symbol in the status bar of your browser. We also use suitable technical and organisational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorised access by third parties. Our security measures are continuously improved in line with technological developments.

13. Validity of and changes to this privacy policy

This privacy policy is currently valid and was last updated in September 2026. Due to the further development of our website and the offerings on it, or due to changed legal or official requirements, it may become necessary to change this privacy policy. You can access and print the current privacy policy at any time on the website at verusbonifatius-en.ppgmbhdev.de/privacy-policy/.

Data protection information pursuant to Art. 13 GDPR

This data protection information informs you about the processing of your personal data at Verus Bonifatius Klinik GmbH. Pursuant to Art. 4 no. 1 GDPR, your data includes all information that relates or can be related to you, in particular by means of assignment to an identifier such as a name or to an organisation or customer number with which you can be identified.

Personal information and personal data

During your contractual relationship, Appel & Schindler GbR [check company name – presumably Verus Bonifatius Klinik GmbH] collects and processes information (both in paper and in digital form).

This data may include:

  • Master data (name, academic titles, address, customer number)
  • Nationality, date and place of birth
  • Contract data (names, address, bank details, contact person where applicable)
  • Organisational data (supervisor, location, management level)
  • Business contact and communication data
  • Authorisations (access rights and access bookings, access rights to IT systems and data processing procedures, log data on the use of communication and data processing systems, recordings from the video surveillance system)
  • Applicant data (application, CV, references, proof of school and vocational training, diplomas)
  • Historical data
  • Access data for customers’ IT systems
  • Health data within the meaning of Art. 9 General Data Protection Regulation

Purposes of collection and processing

Verus Bonifatius Klinik GmbH collects, processes and uses your personal data exclusively for the purposes of the contractual or treatment relationship and for business purposes that are permissible within the scope of our business activities and related to your role and function in our clinic. These include:

  • Processing of applications
  • Compliance with legal requirements, e.g. under labour, tax and social security law
  • Internal administrative and organisational purposes
  • Ensuring the security and protection of processing procedures and data against unauthorised access, falsification and unauthorised use
  • Protection of the company’s facilities, equipment and assets against theft and other damage
  • Professional treatment of patients
  • Bookkeeping via tax advisers
  • Spa cards (name, date of birth and length of stay)
  • Billing with health insurance funds and civil-service medical allowance offices (Beihilfestellen)

Your data will only be processed for purposes other than those mentioned if this processing is compatible with the purposes of the contractual relationship. We will inform you about such further processing of your data beforehand and, where necessary, obtain your consent.

Your data protection rights

Your data protection rights are set out in Chapter III (Art. 12 et seq.) of the European General Data Protection Regulation (GDPR). Under these provisions you have a right to information about the personal data stored about you, about the purposes of processing, about any transfers to other bodies and about the duration of storage.

To exercise your right to information you can also receive extracts or copies. If data is incorrect or no longer required for the purposes for which it was collected, you can request rectification, erasure or restriction of processing. Where provided for in the processing procedures, you can also view your data yourself and correct it if necessary.

If reasons against the processing of your personal data arise from your particular personal situation, you can object to processing insofar as the processing is based on a legitimate interest. In such a case we will only process your data if there are special compelling interests for doing so.

If you have any questions about your rights and how to exercise them, please contact your HR department or the company data protection officer.

Legal basis for the processing of your personal data

The legal basis for the processing of your personal data for the purposes of the contractual relationship is Art. 6 (1) (a), (b) and (f) GDPR. Data is collected and processed for this purpose only to the extent required by law or necessary under the contract. Insofar as any further data is not directly required for the performance of the contractual relationship, the processing is based on a legitimate interest of the company pursuant to Art. 6 (1) (f) GDPR.

A legitimate interest may arise, for example, from internal organisational and administrative purposes, or from the protection of the company’s facilities, equipment and assets as well as its data processing systems and data. Processing of your data is permissible here unless the protection of your interests, fundamental rights and freedoms prevails.

In individual cases we may also obtain your consent to the processing or transfer of your data. In these cases your consent is voluntary and, unless otherwise agreed, can be withdrawn by you at any time for the future. You will not suffer any disadvantages from not giving consent or from any later withdrawal of consent.

Transfer of your personal information

Your personal data will only be transferred or disclosed to external bodies to the extent that this is required by a legal provision or is necessary for the performance of the contract concluded with you (e.g. to tax and social security authorities, banks, auditors), or where Verus Bonifatius Klinik GmbH or an external body has a legitimate interest in the above sense and the transfer is permissible under data protection law.

Your personal data and information may also be disclosed by Verus Bonifatius Klinik GmbH for legitimate purposes to authorised representatives and contractors who provide a service for us, including insurers and consultants, insofar as there is permission for this under data protection law in the individual case. Should your consent or separate notification be required for this, we will obtain your consent beforehand or inform you in good time. Your personal data may also be transferred to service companies for the performance of data processing tasks, e.g. for automated data processing such as accounting. In doing so we will comply with data protection regulations.

Your data will only be transferred or disclosed to the extent necessary for this purpose and in compliance with the relevant data protection regulations. Data is not transferred to third countries or disclosed to bodies in third countries.

Body responsible for the processing of your personal data

Unless otherwise contractually agreed, the body competent and responsible for the collection, processing and use of your personal data is Verus Bonifatius Klinik GmbH in the Federal Republic of Germany.
Personnel data is stored and processed in data processing systems. The technical installation is designed in such a way that only a narrowly defined group of specially authorised persons has access, and any other access to or knowledge of the data is excluded according to the state of the art.

Complaints about the processing of your personal data

If you have any concerns or a question about the processing of your personal data and information, you can contact the HR department or the administration. However, you can also contact the externally appointed data protection officer or the data protection supervisory authority using the contact details below.

Data protection contact:
Dr. Urs Lustenberger, Verus Bonifatius Klinik GmbH, St.-Vinzenz-Allee 1, 36364 Bad Salzschlirf, Germany, Tel. +49 6648 911080

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
(Hessian Commissioner for Data Protection and Freedom of Information)
Postfach 3163
65021 Wiesbaden, Germany
Telephone: +49 611 1408 – 0

Duration of storage
Your personal data will only be stored for as long as knowledge of the data is necessary for the purposes of the contractual relationship or the purposes for which it was collected, or for as long as statutory or contractual retention requirements exist.

Different statutory retention periods result from tax, labour and social security regulations and extend to up to ten years for documents and records relevant under tax law. After termination of the contractual relationship, we will retain your personal data for a further period of 10 years.