Privacy Policy


  1. Responsible Authority and Data Protection Officer

    The responsible entity according to Art. 4 Par. 7 of the European General Data Protection Regulation (GDPR) is Evela Health GmbH, Chausseestraße 58d, 10115 Berlin, Germany. You can contact our Data Protection Officer at datenschutz@evela.health or our postal address with the addition "the Data Protection Officer".


  2. Purpose and Legal Basis for Processing Personal Data
    1. When Accessing/Visiting Our Website. When you access the website evela.health, the following data is automatically transmitted to the webserver of Evela Health:

      1. IP address of the device used during the access

      2. Web address (URL) of the page from which the file was requested (referrer)

      3. Date and time of the request

      4. Amount of data transferred

      5. Description of the type of browser used

        The processing of these browser data, which have a (pseudonymized) reference to individuals via the IP address, is technically necessary to provide you with Evela Health's services. The legal basis for the processing mentioned is Art. 6 Par. 1 Sentence 1 lit. f GDPR (processing is necessary for the protection of the legitimate interests of the controller). To protect the security of the infrastructure of Evela Health and to provide law enforcement authorities with the necessary information in the case of a cyber attack, such as a DDOS attack, the above-mentioned data is generally stored in log files for a period of two days. In case of an attack, log data is retained for evidence purposes until the incident is resolved. The legal basis for this processing is Art. 6 Par. 1 Sentence 1 lit. f GDPR (processing is necessary for the protection of the legitimate interests of the controller).

    2. Registration for the Email Newsletter

      If you have consented, you can subscribe to our email newsletter, which regularly informs you about Evela Health and developments in the health sector. We process your email address, which you provided when registering for the newsletter, to send you an email confirming your registration and to deliver the newsletter. The legal basis for the processing described above for sending our email newsletter is Art. 6 Par. 1 Sentence 1 lit. a GDPR (processing based on the consent of the data subject). You can revoke your consent at any time and unsubscribe from the newsletter. After revoking your consent, you will no longer receive newsletters from us. To revoke your consent, you can click on the unsubscribe link included in every newsletter or contact us via the methods mentioned in section 1 above and/or listed in our imprint.

    3. Registration for Contact

      You can register on our website for business contact. This registration is equivalent to exchanging business cards. If you register, we process your first and last name, possibly company name, email address, and the referrer website for business contact. The legal basis for the processing mentioned is Art. 6 Par. 1 Sentence 1 lit. f GDPR (processing is necessary for the protection of the legitimate interests of the controller). We have a legitimate interest in establishing business contacts with other companies.

    4. Support/Contact

      If you contact us, e.g., via email, mail, or phone, we process the data you provide (e.g., your email address and the content of your request) necessary to answer your question. If your inquiry includes optional personal data, such as your name, we process this data to support you more specifically. The legal basis for collecting data in the context of contact and support inquiries is Art. 6 Par. 1 Sentence 1 lit. b GDPR (processing is necessary for the performance of a contract with the data subject) if a contractual relationship is sought or already exists. The legal basis is Art. 6 Par. 1 Sentence 1 lit. f GDPR (processing is necessary for the protection of the legitimate interests of the controller) if no contractual relationship exists or is intended, e.g., if the contact is general in nature. In the latter case, our legitimate interest is to respond to your inquiry in an appropriate manner. The data incurred in this context are anonymized after storage is no longer necessary (usually four weeks after completely resolving your concern) or processing is restricted if legal retention obligations exist. The legal basis for the mentioned processing is Art. 6 Par. 1 Sentence 1 lit. f GDPR (processing is necessary for the protection of the legitimate interests of the controller). Evela Health has a legitimate interest in performing metrics as part of quality management to continuously improve the services offered. For this purpose, we systematically evaluate the number and reasons for contacts, the processing time of inquiries, and other metrics.

  3. Recipients or Categories of Recipients

    To provide the necessary server infrastructure for the operation of our website and to enable faster loading speeds, we use the service IONOS Deploy Now from the service provider IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. We have concluded a data processing agreement according to Art. 28 Par. 3 GDPR with IONOS. For enabling email communication for general inquiries and notifications via email addresses, Evela Health uses Google Workspace, provided by our processor Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google processes your contact information, such as your email address and the content of your email. Google stores your personal data on servers operated in the European Economic Area (EEA). However, we cannot exclude the possibility that Google accesses your personal data and thus transfers it to the United States. We have concluded a data processing agreement according to Art. 28 Par. 3 GDPR and EU standard contractual clauses with Google.

  4. Social Media Pages of Evela Health

    We inform you below about the handling of your personal data when visiting Evela Health's social media pages on Facebook, LinkedIn, and Instagram. The processing of your personal data occurs both by Evela Health and by the respective social media platform.

    1. Processing by Evela Health

      As the operator of a social media page, we process the content you share on our pages, such as posts, comments, direct messages. Additionally, we process the data from the information stored in your publicly visible profile, such as your profile picture and name, when you leave a comment on one of our pages. We advise you never to share sensitive personal data, such as health data, with us via social media pages, as this also involves transferring the data to the respective social media platforms and the data may be transferred to insecure third countries outside the European Union. The purposes of processing your profile and content data on our social media pages are the external presentation of Evela Health and providing a contact opportunity with customers, partners, and interested individuals who want to learn more about Evela Health. The legal basis for the described processing activity is Art. 6 Par. 1 Sentence 1 lit. f GDPR (processing is necessary for the protection of the legitimate interests of the controller). Our legitimate interest lies in improving the user experience of our social media pages. Evela Health uses the usage statistics provided by the operators of the social networks to improve the user experience when visiting our social media pages. This includes data such as the number and duration of your visits to the social media page, your interactions with us regarding our posts, and information about you, such as age, gender, and interests. We do not have access to the usage data used to create these statistics. The legal basis for the described processing activity is Art. 6 Par. 1 Sentence 1 lit. f GDPR (processing is necessary for the protection of the legitimate interests of the controller). Our legitimate interest lies in improving the user experience of our social media pages.

    2. Processing by Social Media Platforms

      The extent of the processing of personal data depends on the respective operator of the social network, may therefore differ, and is not necessarily comprehensible to us. You can view the details of the collection and storage as well as the type, extent, and purpose of the use of your data by the operator in the privacy policies of the respective operator:


      Facebook: https://de-de.facebook.com/about/privacy

      
Instagram: https://help.instagram.com/519522125107875

      
LinkedIn: https://www.linkedin.com/legal/privacy-policy 

    3. The operators bear the primary responsibility for data processing on social media pages of Evela Health

      We therefore recommend that you assert your data subject rights directly with the respective operators. Alternatively, we are happy to help you, considering our possibilities, to influence the data subject rights process of the social media platforms in exercising your rights.

  5. Your Rights

    You have the following rights regarding the personal data concerning you:

    Right of access (Art. 15 GDPR),


    Right to rectification (Art. 16 GDPR), 


    Right to erasure (Art. 17 GDPR; "right to be forgotten"),


    Right to restriction of processing (Art. 18 GDPR), 


    Right to object to processing (Art. 21 GDPR),


    Right to data portability (Art. 20 GDPR). 

    You also have the right to lodge a complaint with a data protection supervisory authority in the Member State of your habitual residence, place of work, or place of the alleged infringement if you believe that the processing of personal data relating to you is unlawful. The competent supervisory authority for...

    You also have the right to lodge a complaint with a data protection supervisory authority in the member state of your residence, your place of work, or the place of the alleged infringement if you believe that the processing of your personal data by us is unlawful. The supervisory authority responsible for us is: Berlin Commissioner for Data Protection and Freedom of Information Alt-Moabit 59-61 10555 Berlin, Germany

    If you have given us consent to process your data, you may withdraw this consent at any time with effect for the future. The legality of the processing of your data until the revocation remains unaffected. You can assert your rights or contact us at any time via the contact methods mentioned in section 1 above and/or listed in our imprint.

  6. Additional Note on Your Right to Object

    We would like to point out that if the processing of your personal data is based on legitimate interest according to Art. 6 Para. 1 Sentence 1 lit. f GDPR and/or your personal data is processed for direct marketing purposes, you have the right to object to the processing of your personal data at any time.

    Cookies

    Our websites use so-called cookies. Cookies are small data packets that do not cause any damage to your device. They are either temporarily stored for the duration of a session (session cookies) or permanently (permanent cookies) on your device. Session cookies are automatically deleted after your visit. Permanent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser.



    Cookies can be set by us (first-party cookies) or by third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain third-party services within websites (e.g., cookies for processing payment services).

 Cookies serve various functions. Numerous cookies are technically necessary, as certain website functions would not work without them (e.g., the shopping cart function or the display of videos). Other cookies may be used to analyze user behavior or for advertising purposes.



    Cookies that are necessary for the execution of the electronic communications process, to provide certain functions you desire (e.g., for the shopping cart function), or to optimize the website (e.g., cookies to measure web audience) are stored based on Art. 6 Para. 1 lit. f GDPR unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. If consent has been requested for the storage of cookies and similar recognition technologies, processing is exclusively based on this consent (Art. 6 Para. 1 lit. a GDPR and § 25 Para. 1 TTDSG); the consent can be revoked at any time.

    You can set your browser to inform you about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.

Google Analytics This website uses the service "Google Analytics", which is provided by Google Inc. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA) for analyzing how users use the site. Google Inc. has certified itself under the new EU-US Data Privacy Framework and thus commits to adhering to the principles of the EU-US data protection framework.

    Google Analytics uses "cookies" - text files that are stored on your device. The information collected by the cookies is usually sent to a Google server in the USA and stored there. Google Analytics collects the following personal data: online identifiers, including cookie identifiers, internet protocol addresses, and device identifiers, client identifiers such as browser information, behavioral data, location information, and device information.



    On this website, IP anonymization is activated. The IP address of the users is shortened within the member states of the EU and the European Economic Area. This shortening eliminates the personal reference to your IP address. As part of the agreement on data processing which the website operators have concluded with Google Inc., Google uses the collected information to evaluate the use of the website and website activity and provides services related to internet usage.



    You have the option to prevent the storage of the cookie on your device by making appropriate settings in your browser. It is not guaranteed that you can access all functions of this website without restrictions if your browser does not allow cookies.

Moreover, you can prevent the information collected by cookies (including your IP address) from being sent to Google Inc. and used by Google Inc. by downloading and installing a browser plugin available under the following link: https://tools.google.com/dlpage/gaoptout?hl=en

    Here you can find more information about data usage by Google Inc.: https://support.google.com/analytics/answer/6004245?hl=en



    Google Tag Manager We use a service called Google Tag Manager by Google. "Google" is a group of companies that includes Google Ireland Ltd. (service provider), Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, among other affiliated companies of Google LLC. Google LLC, based in the USA, has certified itself under the new EU-US Data Privacy Framework and thus commits to adhering to the principles of the EU-US data protection framework.



    We have concluded a data processing agreement with Google. The Google Tag Manager is an auxiliary service and only processes personal data for technically necessary purposes. The Google Tag Manager ensures the loading of other components, which may themselves collect data. The Google Tag Manager does not access these data.

    For further information about Google Tag Manager, you can review the privacy policies of Google.