p4mx health

Privacy Policy

This is a translation for convenience. In case of doubt or dispute, the German version of this page prevails.
Controller

The controller for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:

p4mx health GmbH
Bei den Wildpferden 1, 64832 Babenhausen, Germany
Managing Director: Dr Patrik Scholler
Email: info@p4mx-health.com

Please direct questions about data protection to datenschutz@p4mx-health.com. We have not appointed a data protection officer, as the statutory conditions for doing so are not met; this assessment is documented.

Principle

We treat personal data confidentially, sparingly and strictly bound to purpose, in accordance with the GDPR and the German Federal Data Protection Act. We collect only the data required for the respective purpose. Health data constitutes a special category of personal data and enjoys particular protection; through this website itself we process no health data.

Hosting and server log files

This website is operated on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Germany. A data processing agreement pursuant to Article 28 GDPR is in place with the provider.

On every visit, the server processes technical access data transmitted by your browser: IP address, date and time of access, the resource requested, the transfer status, the volume of data transferred, and the requesting browser and operating system. This processing is technically necessary in order to deliver the website. We keep no permanent access log of regular page views. Only faults, error cases and server operating events are recorded; the resulting entries may contain the technical data named above and are deleted automatically after 14 days. This serves the stability and security of operations. The legal basis is Article 6(1)(f) GDPR (legitimate interest in a secure and functioning service).

Contact form

When you write to us via the contact form, we process the data you provide — name, company, email address, telephone number where given, and your message — solely in order to handle and answer your enquiry. The legal basis is Article 6(1)(b) GDPR where your enquiry serves the initiation or performance of a contract, otherwise Article 6(1)(f) GDPR on the basis of our legitimate interest in answering enquiries. We do not obtain consent for this — you need not give any in order for us to answer your enquiry.

Your enquiry is not stored in a database. The details you submit are delivered solely by email to our mailbox and handled there. We operate this mailbox via Microsoft 365 (Exchange Online); to that extent Microsoft acts as our processor under Article 28 GDPR. A transfer to third countries cannot be ruled out in this context; details are set out in the section on transfers to third countries.

We delete the email as soon as your enquiry has been conclusively dealt with, at the latest six months after conclusion, provided no contract arises. Where your enquiry leads to a contract, the retention periods under commercial and tax law of six and ten years respectively apply.

Completing the required fields is necessary in order to process your enquiry; without them we cannot reply to you. All further details are voluntary.

Please do not send us any health data or other special category data via the form. We do not request such details and do not process them further.

Cookies and audience measurement

This website uses no cookies requiring consent and no analytics, tracking or marketing tools. There is no audience measurement and no profiling. Details are summarised in our Cookie Policy.

Fonts and external content

We embed no external fonts (for example from third-party font services) and no external scripts or media via content delivery networks. Opening these pages therefore transmits no data to third parties.

Appointment booking

To arrange appointments we use Microsoft Bookings, a service of Microsoft Corporation. The booking calendar is not embedded in our website: only when you click the booking button are you forwarded to a Microsoft page. Until that click, no data is transmitted to Microsoft.

On the Microsoft page, Microsoft processes the data you enter there, along with technical access data, under its own responsibility. Microsoft’s privacy policy applies. Transfer to third countries cannot be ruled out in this context.

Links to social networks

In the footer we may link to profiles on social networks (for example LinkedIn), and under individual articles in the Impulses section we offer buttons for sharing on LinkedIn and X (formerly Twitter). In every case these are plain links, not embedded content. Data is transmitted to the respective provider only when you actively click the link and open that page. The privacy policy of the respective provider then applies.

Recipients of your data

We pass on your data only where this is necessary to fulfil the purpose or where we are legally obliged to do so. Service providers processing data on our behalf are contractually bound under Article 28 GDPR and may use the data only on our instructions.

Categories of recipients:

  • IT service providers for server operation, domain and data backup — Hetzner Online GmbH, Germany, as processor,
  • providers of email and office communication — Microsoft Ireland Operations Ltd. as processor,
  • where a contract comes about, additionally the tax advisers as a recipient acting on their own responsibility, tax authorities within the scope of statutory obligations, and the bank for payment transactions.
Transfers to third countries

We transfer data to Microsoft Ireland Operations Ltd. insofar as Microsoft provides support and administration access from third countries — primarily from the United States; further support locations cannot be ruled out. The basis for this is the European Commission’s standard contractual clauses within the Microsoft Products and Services Data Protection Addendum. We have additionally assessed the transfer. You may obtain a copy of the safeguards from us on request.

Beyond this, no transfer takes place to countries outside the European Union and the European Economic Area.

Data security

Transmission is encrypted via TLS (recognisable by the “https” and the padlock symbol in your browser’s address bar) in order to protect the data you transmit against unauthorised access.

Your rights

Under the GDPR you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20) and a right to object (Article 21). We base no processing on consent; if you have given us consent in the past, you may withdraw it at any time with effect for the future (Article 7(3)).

Right to object: You have the right to object at any time, on grounds relating to your particular situation, to processing of data concerning you carried out on the basis of Article 6(1)(f) GDPR.

To exercise your rights, a message to info@p4mx-health.com is sufficient.

You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information, Postfach 3163, 65021 Wiesbaden, Germany.

Automated decision-making

Automated decision-making, including profiling, within the meaning of Article 22 GDPR does not take place.

Changes to this privacy policy

We adapt this privacy policy as soon as changes to the website or to the legal situation require it. The version published on this page applies in each case.

Last updated: 17 August 2026.