Skip to main content

Processing of (personal) data by the entity in charge of the online application process

**Privacy Policy for the Use of Services by MEDICEO GmbH**

MEDICEO GmbH offers doctors, medical students, and non-medical professionals the opportunity to obtain treatment and/or dosage recommendations for patient care via the MEDICEO software. These services are available through the app and the web application. To use the services provided by MEDICEO GmbH, customers must register by providing personal data through our web application or the MEDICEO app.

This privacy policy aims to inform you as customers and users of our website about the nature, scope, and purpose of collecting and processing your personal data by the website operator MEDICEO GmbH in connection with the use of our services.

The website operator takes your data protection very seriously and treats your personal data confidentially and in accordance with legal regulations. Since new technologies and the constant development of this website may result in changes to this privacy policy, we recommend that you review this privacy policy regularly.

Personal data refers to all information used to identify you and that can be traced back to you. This includes your name, address, email addresses, customer and user behavior. For other terminology, particularly the terms "processing" and "consent," we refer to the legal definitions in the General Data Protection Regulation (hereinafter "GDPR") and the Federal Data Protection Act ("BDSG").

**Who is responsible for data processing?**

The data controller within the meaning of the GDPR and other national data protection laws of the EU Member States, as well as other data protection provisions, is:

**MEDICEO GmbH**  
Neue Mainzer Str. 52-58  
60311 Frankfurt am Main  
Germany

Phone: +49 173 181 6603  
Email: info@mediceo.com  
Website: www.mediceo.com  

**What personal data do we process?**

In connection with our services, particularly during the initiation of contracts, at the conclusion of contracts, during registration on our website or app, when using our products, and to meet legal obligations, we process your personal data.

The relevant categories of personal data include:  
- First name, last name  
- Email address  
- Subscription, duration, termination period, contract type  
- Billing data  
- Account data, particularly registration and logins  

**Where do the data come from?**

We process personal data that we receive from our customers, service providers, and business partners in the context of our business relationships.

Additionally, we process personal data from publicly available sources (e.g., debtor registers, land registers, commercial and association registers, press, internet), or that is lawfully transmitted to us by other companies or third parties (e.g., credit agencies) if required for the provision of our services.

**For what purposes do we process your data and on what legal basis?**

We process personal data of our customers only to the extent necessary for providing a functional website, as well as our content and services. The processing of personal data takes place in accordance with the provisions of the GDPR, the BDSG, and all other applicable laws.

**On the basis of your consent (Art. 6 para. 1 lit. b GDPR):**  
If you have given us your consent to process personal data for specific purposes (e.g., for registration in MEDICEO or invoice creation), the lawfulness of this processing is based on your consent.

**For the fulfillment of a contract (Art. 6 para. 1 lit. b GDPR):**  
We process your personal data to fulfill the service contract related to the use of our services.

**To fulfill legal obligations (Art. 6 para. 1 lit. c GDPR) or in the public interest (Art. 6 para. 1 lit. e GDPR):**  
We are subject to legal obligations, such as reporting obligations under the Infection Protection Act or retention obligations. Processing personal data may be required to fulfill these obligations.

**For the protection of legitimate interests (Art. 6 para. 1 lit. f GDPR):**  
Where necessary, we process your data beyond the fulfillment of the contract to safeguard the legitimate interests of us or third parties, such as the exchange of data with credit agencies, the assertion of legal claims, crime prevention, or measures to manage and further develop services and products.

**To whom will my data be shared?**  
Within MEDICEO GmbH, departments, individuals, and employees requiring access to your data to fulfill contractual obligations will have access to it.

Your personal data may also be disclosed to selected external service providers, such as:  
- IT service providers  
- Sponsors  
- Advertising and marketing partners  
- Document and data destruction service providers  
- Printing service providers  
- Telecommunications providers  
- Payment service providers  
- Auditors  
- Accounting service providers  
- Payroll service providers  

Moreover, we may be obligated to transfer your personal data to additional recipients, such as authorities to meet legal reporting obligations:  
- Tax authorities  
- Customs authorities  
- Social security institutions  
- Health authorities in the case of reportable diseases

**Are data transferred to countries outside the European Union or to international organizations?**  
As a rule, no personal data are transmitted to countries outside the European Union (so-called third countries), unless required by law (e.g., tax reporting obligations) or you have given us your consent.

**How long are my data stored?**  
We process and store your personal data as long as necessary to fulfill our contractual and legal obligations. When the data are no longer required for these purposes, they are regularly deleted unless further processing is required for specific reasons.

**What rights do I have concerning the processing of my data?**  
Every data subject has the right to:  
- Access (Art. 15 GDPR)  
- Rectification (Art. 16 GDPR)  
- Erasure (Art. 17 GDPR)  
- Restriction of processing (Art. 18 GDPR)  
- Data portability (Art. 20 GDPR)  
- Object (Art. 21 GDPR)

To exercise these rights, you can contact us at any time using the contact details provided.

**Newsletter and job application process**  
The policy also details the processing of data for newsletter subscriptions and job applications submitted through MEDICEO, including the use of Personio software for recruitment management.

Further detailed explanations are available in the full policy text provided.

**Changes to this Privacy Policy**  
We reserve the right to modify this privacy policy to reflect legal or technological changes.

Processing of (personal) data by the operator of the recruitment website

General information

This recruitment website is operated by Personio SE & Co. KG, which offers a human resource and candidate management software solution (https://www.personio.com/legal-notice/). Data transmitted as part of your application will be transferred using TLS encryption and stored in a database. The sole controller of this data within the meaning of article 24 of the GDPR is the enterprise carrying out this online application process. Personio’s role is limited to operating the software and this recruitment website and, in this context, being a processor under article 28 of the GDPR. In this case, the processing by Personio is based on an agreement for the processing of orders between the controller and Personio. In addition, Personio SE & Co. KG processes further data, some of which may be personal data, to provide its services, in particular for operating this recruitment website. We will refer to this in more detail below.

The controller

The controller under data protection law is:
Personio SE & Co. KG
Seidlstraße 3
80335 München
Tel.: +49 (89) 1250 1004
Entry in the commercial register
Commercial register entry number: HRA 115934
Registration Court: Amtsgericht München
Data Protection Officer contact: privacy@personio.com

Access logs (“server logs”)

Each access to this recruitment website automatically causes general protocol data, so-called server logs, to be collected. As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. Without this data, it would, in some cases, be technically impossible to deliver or display the contents of the software. In addition, processing this data is absolutely necessary under security aspects, in particular for access, input, transfer, and storage control. Furthermore, this anonymous information can be used for statistical purposes and for optimizing services and technology. In addition, the log files can be checked and analyzed retrospectively when unlawful use of the software is suspected. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. Generally, data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp of the access to the software is collected. The scope of this log process does not exceed the common log scope of any other site on the web. These access logs are stored for a period of up to 7 days. There is no right to object to this.

Error logs

So-called error logs are generated for the purpose of identifying and fixing bugs. This is absolutely necessary to ensure we can react as quickly as possible to possible problems with displaying and implementing content (legitimate interest). As a rule, this data is a pseudonym and thus does not allow for inferences about the identity of an individual. The legal basis for this is §25 subsection 2 Sentence 2 TDDDG. When an error message occurs, general data such as the domain name of the website, the web browser and web-browser version, the operating system, the IP address, as well as the timestamp upon occurrence of the respective error message and/or specification is collected. These error logs are stored for a period of up to 7 days. There is no right to object to this.

Use of cookies

So-called cookies are used on parts of this recruitment website. They are small text files which are stored on the device with which you access this recruitment website. As a general rule, cookies serve the purpose of ensuring secure access to a website (“absolutely necessary”), implementing certain functionalities such as standard-language settings (“functional”), improving the user experience or the performance of the website (“performance”), or placing targeted advertisements (“marketing”). On this recruitment website, we generally use only cookies that are absolutely necessary, functional or performance-related, in particular for implementing certain default settings such as language, for identifying the job advertising channel, or for analyzing the performance of a job advert via which a user accessed this recruitment website. The use of cookies is absolutely necessary for providing our services and thus for the performance of the contract (article 6 (1) b) of the GDPR). Period of storage: up to 1 month or until the end of the browser session Right to object: You can determine via your browser settings whether you allow or object to the use of cookies. Please note that deactivating cookies may result in limited or completely blocked functionalities of this recruitment website.

Rights of data subjects

If Personio SE & Co. KG as the controller processes personal data, you as the data subject have certain rights under Chapter III of the EU General Data Protection Regulation (GDPR), depending on the legal basis and the purpose of the processing, in particular the right of access (article 15 of the GDPR) and the rights to rectification (article 16 of the GDPR), erasure (article 17 of the GDPR), restriction of processing (article 18 of the GDPR), and data portability (article 20 of the GDPR), as well as the right to object (article 21 of the GDPR). If the personal data is processed with your consent, you have the right to withdraw this consent under article 7 III of the GDPR. To assert your rights as a data subject in relation to the data processed for the purpose of operating this recruitment website, please refer to Personio SE & Co. KG’s Data Protection Officer (see item B).

Concluding provisions

Personio reserves the right to adjust this data privacy statement at any point in time to ensure that it is in line with the current legal requirements at all times, or in order to accommodate changes in the services offered, for example when new services are introduced. In this case, the new data privacy statement applies to any later visit of this recruitment website or any later job application.