Privacy PolicyHow we process your data under the GDPR
Information on the processing of personal data on the DokTing website and within the booked support services. Version dated: 7 September 2026
Only the German version is legally binding. This English text is a non-binding courtesy translation.
This privacy policy provides information on the processing of personal data on the DokTing website, in the customer portal and within the framework of the support services requested and booked. Only the German version shall be authoritative; translations serve solely for your comprehension.
Binding German version: AGB · Widerrufsbelehrung · Datenschutz · Leistungsbeschreibungen · Impressum
1. Controller
The controller (Verantwortlicher) responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
DokTing – Hazem Ibrahim
Operator of the website “DokTing”
Represented by: Hazem Ibrahim
Berliner Straße 24b
23738 Lensahn
Germany
Email: info@dokting.de
Telephone: +49 152 29555290
Data protection officer (Datenschutzbeauftragter). We have not appointed a data protection officer. The statutory thresholds giving rise to an obligation to designate one under Article 37 GDPR and Section 38 BDSG are not met: we do not employ the requisite number of persons in the automated processing of personal data, our core activity consists neither in the extensive regular and systematic monitoring of data subjects nor in the extensive processing of special categories of data, and we do not carry out any processing operations which are subject to a data protection impact assessment under Section 38(1) sentence 2 BDSG. In all data protection matters – including the exercise of your rights under Articles 15 to 22 GDPR – please contact info@dokting.de or the above address.
2. General Information on Data Processing
We process personal data only in so far as this is necessary for the provision of the website, for the handling of enquiries, for the preparation and performance of contracts, for compliance with legal obligations or on the basis of consent.
The services offered relate to organisational support, administrative assistance, document preparation, application support and general orientation in connection with study, professional, recognition and application processes in Germany.
We process only those data which are necessary for the respective purpose and we erase them as soon as the purpose ceases to apply and no statutory retention obligation prevents erasure.
3. Categories of Personal Data Processed
Depending on your use of the website and on the service booked, the following data in particular may be processed: name, email address, telephone and WhatsApp number, billing address and billing country, details of education, studies, professional experience, language skills and the desired course of study or career path, curriculum vitae, school and university certificates, professional licences, language certificates, application documents, uploaded documents, payment and invoicing data, communication content, evidence of consent, appointment data, portal and account data, browser and device data, the time of access as well as server log files.
A special rule applies to your IP address: full IP addresses arise on a purely temporary basis in the server log files of our hosting provider. In our own data holdings we do not store any full IP addresses, but exclusively a key-bound pseudonymous value, a network prefix and – where available – the autonomous system number and the country code. Details are set out in section 23.
Health-related documents (for example a medical certificate or the proof of medical fitness required by a recognition authority) are not uploaded or stored electronically with us. Where the competent authority requires such a document, we accept it exclusively in paper form and only after your separate explicit consent pursuant to Article 9(2)(a) GDPR (section 11).
4. Purposes of Processing
Processing is carried out in particular for the technical provision of the website, for the handling of contact, consultation and booking enquiries, for the taking of pre-contractual steps, for the performance of the contract, for the preparation and review of documents, for communication with customers, for payment processing, for invoicing, for the documentation of consents, for the arrangement of appointments and appointment reminders, for the processing of uploaded documents, for the operation of the customer and employer portal, for the protection of copyright-protected content and the attribution of unauthorised copies, for ensuring system security and preventing misuse, for the backup and recoverability of the data, for reach measurement subject to consent, for business analysis as well as for compliance with statutory retention and documentation obligations.
5. Legal Bases for Processing
Depending on the purpose, processing is carried out on the basis of
- Article 6(1)(b) GDPR, where it is necessary in order to take steps at your request prior to entering into a contract or for the performance of a contract,
- Article 6(1)(c) GDPR, where legal obligations exist, in particular commercial and tax retention obligations under Section 147 AO (German Fiscal Code) and Section 257 HGB (German Commercial Code) as well as the obligation to ensure data security under Article 32 GDPR,
- Article 6(1)(f) GDPR, where legitimate interests exist in the secure, economical and functional provision of the website, in the protection of our content, in the prevention of misuse and in orderly business operations,
- Article 6(1)(a) GDPR, where consent is obtained, and – for the storage of information on your terminal equipment and access to information already stored therein – Section 25(1) TDDDG; technically necessary storage operations do not require consent pursuant to Section 25(2) no. 2 TDDDG.
We process special categories of personal data within the meaning of Article 9 GDPR only in paper form within a recognition procedure and only on the basis of your separate explicit consent pursuant to Article 9(2)(a) GDPR (section 11); no electronic capture takes place.
For the processing of images in the context of published success stories, Section 22 KUG (German Art Copyright Act) additionally applies. For employee data, Article 88 GDPR in conjunction with Section 26 BDSG applies.
You may withdraw a consent you have given at any time with effect for the future; the lawfulness of the processing carried out up to the withdrawal remains unaffected.
6. Contact Form, Enquiry Form and Communication
If you contact us via a form, by email or by other means of communication, we process the data transmitted by you in order to handle your enquiry and to deal with follow-up questions. These data are not disclosed to third parties unless this is necessary.
The legal basis is Article 6(1)(b) GDPR in so far as the enquiry is directed towards the conclusion or performance of a contract, and otherwise Article 6(1)(f) GDPR (legitimate interest in responding to enquiries). We erase enquiry and contact data which do not lead to the conclusion of a contract as soon as they are no longer required for the handling of the enquiry, as a rule after six months at the latest; the statutory retention periods apply to business and commercial letters.
7. Enquiry for the Free Initial Consultation and Communication via WhatsApp
If you complete the form requesting a free initial consultation, we process the data you enter: first name and surname, email address, WhatsApp number, age group, country of residence, your objective and the route towards it (language of study, status of recognition or nursing experience, depending on your selection), level of German, readiness indicators (starting date, familiarity with the packages, awareness of costs) as well as your optional question.
The purpose is the preliminary assessment of suitability, the organisation of the pre-contractual phase and the reduction of consultations which serve no purpose. The legal basis is your consent pursuant to Article 6(1)(a) GDPR, which you give by ticking the consent box, as well as Article 6(1)(b) GDPR (pre-contractual measures). The time of consent (consent_ts) is stored with each enquiry for evidentiary purposes; for the purposes of such evidence we do not store any full IP address, but exclusively the pseudonymous value described in section 23.
After submission, the system opens a WhatsApp chat with a summary message containing your enquiry code and the most important answers, in order to facilitate our support. We point out that communication via WhatsApp entails the transmission of your contact and message data to Meta Platforms Ireland Ltd. and that data may also be processed by Meta outside the EU; if you prefer a different channel, you may write to us directly at info@dokting.de.
Consultation enquiries which do not result in a customer relationship are stored for a maximum of twelve months and are erased thereafter, unless statutory obligations prevent erasure. You may withdraw your consent at any time with effect for the future or request the erasure of your data via info@dokting.de.
8. Booking of Consultation Appointments
You may reserve a consultation appointment via your portal account or via the public booking page. An appointment lasts 30 minutes for guests and 45 minutes for account holders and becomes immediately binding upon your selection — with the exception of Sunday appointments, which are reviewed as an exception and are not confirmed automatically.
What is processed and for what purpose: name, email address, WhatsApp number, your principal concern, the time of the appointment together with your time zone as well as the language of correspondence. The purposes are the organisation of, the preparation for and the reminder of the appointment. The legal basis is Article 6(1)(b) GDPR (steps taken at your request prior to entering into a contract) alongside your consent declared in the form pursuant to Article 6(1)(a) GDPR. The time zone serves exclusively for the correct display of times.
Your principal concern is requested with a minimum length so that we are able to prepare; it is read exclusively by us.
Reminders: We send two email reminders (24 hours and 2 hours in advance). The calendar file attached to the confirmation creates a reminder on your own device — we have no access to your calendar.
Cancellation and rescheduling: With the confirmation you receive a secret management link with which you may reschedule or cancel the appointment yourself up to four hours in advance. The code is located after the # in the link and therefore reaches neither our servers nor their logs; only a hash is stored by us. Merely opening the link cancels nothing — a confirmation page is displayed.
Prioritisation in the allocation of appointments: If you have completed the form for the initial consultation, your details may be used for the prioritisation of available appointments (for example, earlier appointments where the details are complete). No automated rejection takes place: every case which is not scheduled automatically is subject to personal review, and you may at any time propose a preferred appointment or write to us directly.
Retention period: Appointment data which are not followed by an order are erased twelve months after the appointment. We do not store the content of WhatsApp conversations — only the telephone number for the purpose of arranging your appointment.
9. Orders Subject to Payment, Contract Documentation and Withdrawal
In the case of a booking subject to payment, we process in particular the service selected, package data, invoicing data, method of payment, contact data, uploaded documents, messages and the confirmations given in respect of data protection, the General Terms and Conditions, the withdrawal instruction and the order subject to payment as well as – only if you chose it – the optional request for early commencement of performance. The legal bases are Article 6(1)(b) GDPR (initiation and performance of the contract) and Article 6(1)(c) GDPR (statutory documentation and retention obligations).
Contract and consent documentation. For every order, a German-language PDF is generated automatically which documents your full name, your address, email address, the package selected and the price as well as all declarations made by you (confirmation of the payment obligation pursuant to Section 312j(3) BGB (German Civil Code), acknowledgement of the General Terms and Conditions, the privacy policy and the withdrawal instruction, if chosen by you: the optional request for early commencement of performance together with knowledge of the lapse of the right of withdrawal – with wording, display language and time; otherwise “no early commencement requested” is expressly noted –, recognition of the binding nature of the German language version) — in each case with a time stamp and with the checksums of the underlying legal texts.
The contract documentation deliberately contains no IP address and no browser identifier; the time of submission and the checksums suffice as evidence. In our internal evidentiary record, the pseudonymous value of the IP address described in section 23 is additionally maintained.
This document is a commercial and contractual record and is subject to the statutory retention periods for commercial letters (six years from the end of the calendar year, Section 257(1) no. 2, (4) HGB (German Commercial Code); Section 147(1) no. 2, (3) AO (German Fiscal Code)); a request for erasure does not extend to it. You receive your copy with the contract confirmation by email; it is additionally available to you at any time in your portal account and will be sent to you by email upon request to info@dokting.de.
Withdrawal declarations and withdrawal function (Section 356a BGB). Consumers may declare withdrawal via the button “Withdraw from contract” (footer of every page and withdrawal instruction) without a customer account and without a release code, and also by email or post. In doing so we process the data you enter: name, order number or description of the contract, email address, optionally the designation of a part of the contract and the display language selected; in addition, the wording of the withdrawal declaration made, the time of receipt (server time with time zone), a receipt ID, the dispatch status of the acknowledgement of receipt and the pseudonymous value of the IP address described in section 23 for the prevention of abuse. We send the acknowledgement of receipt containing these details and the full wording without undue delay to the email address provided; if dispatch fails, the declaration remains stored and dispatch is retried. No data from our database is disclosed via the withdrawal function or the confirmation page; only what you entered yourself is displayed. Legal bases: Article 6(1)(c) GDPR in conjunction with Section 356a BGB (obligation to acknowledge receipt without undue delay) for receipt, storage and acknowledgement; Article 6(1)(b) GDPR for the assignment to your contract and the reversal (review, refund, credit note); Article 6(1)(f) GDPR for documentation for the establishment, exercise or defence of legal claims. The withdrawal function uses no analytics, marketing or tracking services and passes no personal data in the address bar (URL).
Reversal and refund. For the settlement of a withdrawal we additionally process the review status (scope of the withdrawal, refundable and retained amount with reasons), the refund entry (amount, date, reference) and the credit note. Refunds are made exclusively manually by us; there is no automatic refund or account deletion.
10. Payment Processing
As a method of payment we offer advance payment by bank transfer. In this context we process the data required for invoicing, the allocation of payments and accounting, in particular name, billing address, billing country, order number, amount, payment reference and receipt of payment. The legal bases are Article 6(1)(b) GDPR (performance of the contract) and Article 6(1)(c) GDPR (commercial and tax obligations).
The recipients are the credit institutions involved as well as – in so far as engaged – our accounting and tax advisers. Further methods of payment are offered only where they are expressly indicated during the ordering process; we shall provide information at this point on the service providers then used.
We retain invoices and accounting vouchers in accordance with Section 147(3) AO (German Fiscal Code), Section 257(4) HGB (German Commercial Code) and Section 14b(1) UStG (German Value Added Tax Act).
11. Uploading of Documents
Documents may be uploaded in the context of an enquiry or a booking, for example degree certificates and employment references, transcripts of records, a CV, language certificates as well as identity and procedural documents. Such documents are processed exclusively for the purpose of providing the requested service, for the organisational review of the case and for the preparation of the agreed support. The legal basis is Article 6(1)(b) GDPR.
Two upload paths. For customer documents relating to an order you receive, upon receipt of payment, a secured, time-limited upload link to ownCloud.online (ownCloud GmbH, Germany) as our processor (Auftragsverarbeiter); these documents are processed there and are not stored on the web server of the website. During the upload, ownCloud.online processes the connection data including your IP address; the server location is in Germany. Professionals who maintain a profile in the professionals portal, by contrast, upload their evidence directly in the portal; these files are stored on our server outside the publicly accessible area, re-encoded without metadata in the case of images, delivered only after login and shown to employers exclusively within the scope of the release under section 12.
No health documents in the upload. Health-related documents – in particular a medical certificate, proof of medical fitness or proof of vaccination – cannot be uploaded via either path; no such document type is technically provided for, and any such upload is rejected. Where the competent recognition authority requires such a document, you send it to us exclusively in paper form by post after having given a separate explicit consent for this purpose pursuant to Article 9(2)(a) GDPR. We hold the document temporarily and forward it to the recognition authority you have named, where it remains. We make no copy and, in the normal course, do not return it to you. Only administrative details are stored: the designation of the document, the date of receipt, the competent authority, the dispatch date, the shipment number and the record of your consent. The content – in particular findings or diagnoses – is neither captured nor scanned nor evaluated. Without this consent we do not accept any health document; in that case you submit it to the authority yourself. The consent may be withdrawn at any time with effect for the future; a document not yet dispatched at that time is returned to you without delay.
Customers are responsible for uploading only such documents as are necessary for the requested service. Particularly sensitive information which is not needed should be redacted before the upload in so far as it is not necessary for the service.
Documents uploaded via ownCloud.online are erased manually from the order folder within 30 days of completion of the booked service, in so far as no statutory retention obligation or another ongoing order prevents erasure; the erasure is documented internally with the date and the person carrying it out. The expiry of the time-limited upload link merely ends the possibility of uploading and does not erase any documents relating to an ongoing service. For employment placement records, we distinguish between the documents you provide and our other business records relating to the placement. We return original documents entrusted to us immediately after completion of the placement activity. We delete electronic copies as soon as they are no longer needed for their specific purpose; continued retention requires a statutory obligation or another legal basis documented for the particular case. Under section 298(2) SGB III, we retain the other placement business records for three years after completion of the placement activity. We then delete the personal data they contain unless another applicable retention obligation remains. The upload date does not start this three-year period. Invoices and other records subject to separate retention obligations follow the periods in section 30. The mere possibility of a future dispute does not justify a blanket extension.
12. Customer and Employer Portal (Personal Account)
We provide a password-protected portal in which you can follow the progress of your case. An account may be opened exclusively by means of a personal activation code which we send to you by email.
Data processed in the portal: account data (email, display name, password — stored as a scrypt hash which cannot be reversed), the case data already transmitted by you, the processing steps published by us as well as your answers to queries. The legal basis is Article 6(1)(b) GDPR.
Technical session data: For each login we store a hashed session token, the expiry date, a shortened browser identifier as well as – instead of the IP address – the pseudonymous value, the network prefix and, where available, the AS number and the country code of the access (see section 23), in order to protect your account against unauthorised access. The same applies to security-relevant operations within your account, such as logging in, changing a password or retrieving the contract documentation. Legal basis: Article 6(1)(f) GDPR in conjunction with Article 32 GDPR (legitimate interest in system security). Expired sessions are erased automatically 30 days after the expiry of the session; ongoing sessions are not shortened thereby. Entries in the access log are erased as soon as they are no longer required for security purposes, at the latest after 12 months (operational period).
Video access log and watermark: Exclusive video content is protected. Before playback we obtain your express agreement to the terms of use and store the time as well as the pseudonymous value and the network prefix of the access, not the full IP address. During playback a watermark bearing your personal reference identifier is displayed; in addition, we log who accessed which content and when. Purpose: protection of copyright, prevention of unauthorised reproduction and traceability in the event of onward disclosure. Legal basis: Article 6(1)(f) GDPR (legitimate interest in the protection of the content) and Article 6(1)(b) GDPR (performance of the contract). No use for advertising purposes takes place. Details are governed by section 14.
Employer portal: Employers receive a time-limited window for inspection (15 days) of applicant profiles. Every viewing of a profile is logged — for the protection of the applicants. Applicant profiles, including photographs and videos, are displayed exclusively on the basis of a documented consent which is separated according to scope (anonymised presentation, photographs, video, naming); the legal basis is Article 6(1)(a) GDPR. Withdrawal is possible at any time and leads to immediate removal from display.
Activation code and its retention: Every customer receives a personal activation code bound to their email address. It is stored exclusively as a hash value (SHA-256) together with a short prefix and cannot be used again once redeemed. Codes which have not been redeemed are erased 30 days after the expiry of their validity; redeemed codes are retained as evidence of an account activation carried out on the customer's own responsibility for 36 months from redemption (operational period, Article 6(1)(f) GDPR) and are erased thereafter. The watermark on protected content does not use this activation code but the release code of your order (section 20).
Retention periods: expired sessions 30 days after expiry, unredeemed activation codes 30 days after expiry, redeemed codes 36 months from redemption, access logs 12 months, answers to follow-up questions 12 months from the answer, portal accounts 36 months from the last login (inactivity of the account; an ongoing order precludes erasure). These are operational periods without a statutory requirement. Invoices, contracts and consent documentation are subject to the statutory retention periods set out in section 30; the last login neither extends those periods nor is it extended by them.
You may at any time change your password, terminate all sessions on all devices, deactivate email notifications and request the erasure of your account at info@dokting.de.
13. Messages in the customer portal and by email
DokTing does not use Web Push notifications. The website does not request permission for browser or device notifications, create Push subscriptions, or store Push endpoints or Push keys. We inform customers by email of material processing stages and new updates appearing in their accounts, while the details are provided in the protected customer portal. For data-minimisation reasons, the notification email does not contain substantive details of the update. The legal basis is Article 6(1)(b) GDPR where the communication serves performance of the contract or pre-contractual steps; Article 6(1)(c) GDPR applies to communications required by law. Further details on email and portal processing are contained in the relevant sections of this privacy notice.
14. Protection of Audiovisual Content and Attribution of Unauthorised Copies
What is processed and for what purpose: When a protected video is played, a technical playback session arises. The following are processed: session identifier, video, start and end time, proportion viewed, network prefix of the IP address (IPv4 /24, IPv6 /48 — not the full address), shortened hash value of the browser identifier (user agent), no device fingerprint, counters of the segments and keys delivered as well as technical playback indicators (dropped frames, regularity of the keep-alive signals, changes to the screen dimensions). Purpose: prevention of unauthorised downloading, detection of automated extraction patterns and attribution of every copy appearing outside the platform to its source.
Watermark: During playback your personal reference code is displayed in motion over the image; express notice of this is given before the first playback. The position of the watermark is derived deterministically from a session-specific seed, which makes it possible to verify subsequently whether a single frame which has been passed on can be attributed to a particular session.
Legal basis and balancing of interests: Article 6(1)(f) GDPR. Our legitimate interest is the protection of copyright-protected content and the prevention of its further dissemination. We have carried out the balancing against your rights as follows: we do not collect the full IP address, but only its network prefix and the key-bound pseudonymous value; we do not link playback data with any marketing profile; we do not use them in order to evaluate you as a customer; we do not disclose them to any third parties. The less intrusive means — mere password protection — has proved unsuitable, because in the event of a leak it permits no attribution.
No automated individual decision-making: The risk indicators are probability values, not evidence; a weak network connection may produce the same indicators as a screen recording. For this reason no permanent measure is taken automatically: at most, the system reduces the quality or terminates the current session; any decision going beyond this (such as the withdrawal of an authorisation) is taken by a human being following a review. Article 22 GDPR therefore does not apply.
Right to object: You may object to the processing pursuant to Article 21 GDPR on grounds relating to your particular situation. We examine your individual case and inform you of the outcome. Lodging an objection does not in itself lead to a permanent blocking of access. Insofar as we may not continue the processing, we examine a reasonable alternative form of provision. If this is not possible, we clarify with you the effects on the service concerned and its remuneration; your statutory rights remain unaffected.
Public level (success story videos): These are accessible without logging in and without a personal code. A technical session without any link to a customer account arises: a random session identifier, the network prefix of the IP address (not the full address), a shortened hash value of the browser identifier (user agent), no device fingerprint, as well as counters of the segments and keys delivered and technical playback indicators — solely for the purpose of preventing automated extraction. No tracking, no profiling, no linkage with an account or code; the session is erased in full after 30 days.
Tiered retention: Technical playback data (network prefix, shortened hash value of the browser identifier (user agent), no device fingerprint, playback indicators, risk values, event log) are erased or cleared field by field 90 days after the start of the session; they serve only protection during and shortly after playback. The proportion viewed is kept for 12 months as long as an entitlement exists, in order to unlock the follow-up questions. Thereafter only a reduced attribution record remains (session identifier, release code, video, start, watermark seed and configuration checksum) for at most five years from the start of the session (Article 6(1)(f) GDPR); this period is an operational maximum based on our balancing of interests, not a period prescribed by law, and its necessity is reviewed annually. A later login or playback does not extend the storage of an earlier session. This record serves solely to determine the source session of an unauthorised copy; it is not used for any other purpose, neither in marketing nor for the evaluation of a person. A watermark match is a technical indication of the session, not proof of the identity of a person; no automated sanctions take place. Temporary blocks of network prefixes are kept in a separate, time-limited register and erased 30 days after the end of the block. Aggregated monthly statistics (mere counts without any identifier) do not constitute personal data and are retained indefinitely.
15. Protection of the Portal Articles and Attribution of Copies
The articles of the information guide in the customer portal are delivered as a personalised copy for each reader. Before the first reading we display an express notice bearing your name and your release code (Freigabecode); no article is opened without your confirmation. We store the time of the confirmation and only the network prefix of your IP address as evidence of the prior information.
Data processed and purpose: When an article is opened, a reading session arises comprising: session reference, release code, name according to the customer file, article and language, start and expiry, number of views, network prefix of the IP address (for example 192.168.1.0 — not the full address), a shortened hash value of the browser identifier (user agent), no device fingerprint, as well as reports from the integrity monitor. Individual features are embedded in the copy displayed: a visible watermark bearing the name, code and time of display, a background bearing the domain, signed trace codes (QR), invisible text markings and microtypographic variants which do not alter a single word of the content.
Legal basis: Article 6(1)(f) GDPR. The legitimate interest lies in the protection of content produced at considerable expense against unauthorised further dissemination and in the possibility of proving the origin of a copy appearing outside the portal. Balancing of interests: Mere password protection is not a less intrusive means of equal effectiveness, because it does not render copies distinguishable once they have left the portal. The data are not used for marketing or for the assessment of personality; we collect the minimum (network prefix instead of the full IP address, a shortened hash value of the browser identifier instead of the identifier itself).
Right to object: You may object to the processing pursuant to Article 21 GDPR on grounds relating to your particular situation. We examine your individual case and inform you of the outcome. Lodging an objection does not in itself lead to a permanent blocking of access. Insofar as we may not continue the processing, we examine a reasonable alternative form of provision. If this is not possible, we clarify with you the effects on the service concerned and its remuneration; your statutory rights remain unaffected.
No automated decision-making: No automated decision in an individual case producing legal effects within the meaning of Article 22 GDPR takes place. Where a leaked copy is suspected, the system produces a technical attribution together with an express statement of its limits; the assessment and any measure are undertaken by a human being.
Retention period: The technical fields (network prefix, shortened hash value of the browser identifier (user agent), no device fingerprint, event data) are cleared field by field or erased 90 days after the start of the session. The attribution core (session reference, code, article, date) is kept for at most five years from the start of the session (operational maximum, annual necessity review; no statutory period) and is then erased. The investigation log stores the result and the SHA-256 checksum of the evidence submitted, not the evidence itself.
What we do not do: Images of a leak are not uploaded to our servers — decoding takes place locally in the browser of the administration. Reading data serve no purpose of performance or behavioural assessment.
16. Answers to Follow-Up Questions
After individual videos we ask short follow-up questions (for example: What is still unclear to you?). Answering is entirely voluntary and affects neither the service provided to you nor access to further videos.
The following are stored: the text of the answer, the associated video, your proportion viewed at the time of the answer and the time of submission. Legal basis: Article 6(1)(b) GDPR in so far as the answer serves the provision of the service, and Article 6(1)(f) GDPR in so far as we evaluate it in order to improve our content. Retention 12 months from the answer (operational period); during an ongoing order the answers remain available until its completion. The same applies to your answers to check-in questions in the customer portal and to questions you ask while reading an article; they are stored only once and erased together. Answers do not constitute evidence that a service package has been performed. Answers are neither published nor disclosed to third parties; you may request erasure at any time.
17. Success Stories and Testimonials
When a success story is published on our website, we process — on the basis of the express written consent of the data subject (Article 6(1)(a) GDPR in conjunction with Section 22 KUG (German Art Copyright Act)) — the name in the form chosen (full name or first name with the initial letter of the surname), occupation, country of origin, city and year, the text of the experience, a photograph and, where applicable, a short video.
The consent document is retained as evidence. Consent may be withdrawn at any time with effect for the future via info@dokting.de; in the event of withdrawal, the contribution is removed from the website and the photograph and video files are erased from our servers. Only the evidence of the consent and of the withdrawal is retained.
The three language versions of a success story are produced by us ourselves; no machine translation by third parties takes place.
18. Reviews Published on the Website
A review can be published exclusively via a personal invitation link — there is no open form available to everyone. The link is valid for thirty days and can be used once only. The review is published immediately without prior examination; we point this out expressly in the reviews section.
What is processed and for what purpose: the name you enter (Latin characters; we recommend the first name and an initial), the star rating, the occupation, your current country of residence (selected from a closed list of countries — without city or address), the text of the review, the service to which it relates (in the case of service experiences), an optional photograph as well as the time of publication. The purpose is the presentation of genuine feedback together with its context: experiences from within Germany read differently from those from abroad. Email address and telephone number are neither collected nor stored. In the event of withdrawal, the country of residence is erased together with your other data.
Photograph: The photograph is entirely optional. If you upload one, it is recalculated on our server and cropped to a circular shape. In the course of this, all metadata are removed — in particular location data (GPS) and device identifiers. They are neither stored nor published. The photograph is held on our server in Germany and is not transmitted to any third party.
Legal basis: Article 6(1)(a) GDPR — your explicit consent, which is obtained in the form before submission. We store a technical hash as evidence of the time of consent, no copy of your data and no full IP address.
Your right of withdrawal and how to exercise it: After publication, a secret withdrawal link is displayed to you on one occasion only. Keep it safe: with it you may withdraw your review yourself at any time without contacting us. Opening the link deletes nothing; a confirmation page is displayed. Following your confirmation, the text, name and photograph are definitively erased from our database (Article 17 GDPR). Only the numerical identifier and the reason remain in the deletion log — not the text of the review — so that the log does not itself undermine the erasure. If you have lost the link, write to us; we shall erase the review manually after a reasonable check.
Translation: The review is written in the language of the person composing it and is displayed in that language. The two other language versions are produced by us ourselves and stored by us; the text is not transmitted to any third party for this purpose. The translated version is distinguishable from the original, and the original remains accessible with a single click. If you withdraw the release of your review, we erase all stored language versions.
What we delete and what we do not: We undertake not to delete any review on account of criticism. What is deleted is advertising, offensive content and information concerning third parties without their consent. Every ground for deletion is logged internally.
19. Processing of Enquiries in the Nursing Sector
When the preliminary assessment form for nursing staff is submitted, we process the details you have entered: contact data, nationality, country of residence and country of entry, details of qualifications, duration of training, year of graduation and professional experience, level of language proficiency, status of recognition, current residence in Germany as well as your comments. The purpose is the administrative preliminary assessment and the answering of your enquiry; the legal bases are Article 6(1)(a) GDPR (consent) and Article 6(1)(b) GDPR (pre-contractual measures).
This form does not request any documents nor any copies of passports or identity documents. Following the preliminary assessment, a secure, time-limited upload link is provided separately.
Disclosure of the profile to a potential employer: Your data are not disclosed automatically to any institution or to an indeterminate group of institutions. Disclosure takes place only once the specific employer has been determined, that employer has been named to you, the data to be disclosed have been explained to you and you have given separate and express consent. You may withdraw this consent at any time with effect for the future.
When the employer form is submitted, we process the details concerning the institution, the contact person and the requirements stated, in order to answer the enquiry and to organise the cooperation; the legal bases are Article 6(1)(b) and (f) GDPR (legitimate interest in answering business enquiries).
The forms are transmitted to DokTing via the secured interface of the website; documents are not stored on the web server. The details are stored for as long as this is necessary for the handling of the enquiry and for the relationship arising from it, or for as long as statutory retention periods exist, and are erased thereafter. You are entitled at any time to the rights of access, rectification, erasure, restriction, objection and withdrawal set out in this policy.
20. Release Code
If a release code (Freigabecode) is issued after the free initial consultation, we process your email address, the package discussed, the language of correspondence as well as the times of issue, expiry and use. The purpose is the organisation of the pre-contractual phase and the examination of whether the service is suited to your situation prior to booking; the legal basis is Article 6(1)(b) GDPR (pre-contractual measures).
The code can be used once only and is bound to your email address and to the package named. Codes which have not been redeemed are erased 30 days after the expiry of their validity. Upon redemption, the code becomes part of the order and invoice number and serves as the reference identifier in the watermark of protected content (sections 14 and 15); the record of the redeemed code is stored for five years from redemption (operational maximum, reviewed annually) and then erased, while the order and invoice numbers follow the periods set out in section 30. No payment obligation arises from the code; as long as it has not been used, you may request its erasure.
21. Data relating to employees and staff
This privacy policy is addressed to visitors to our website, to prospective customers, to customers and to business partners.
Insofar as we engage employees, trainees, applicants or freelance staff, we process their personal data for the purposes of the employment or contractual relationship – in particular for the establishment, performance and termination of the relationship, for settlement and remuneration purposes and for the fulfilment of obligations under tax and social security law. The legal bases are Article 6(1)(b) and (c) GDPR as well as Article 88 GDPR in conjunction with Section 26 BDSG.
Access to the internal administration area is logged for security purposes; for this purpose the time of login, the account, the device identifier and – instead of the IP address – the pseudonym value, the network prefix (Netzwerk-Präfix) and, where available, the AS number and country code of the access are stored (see section 23). Legal basis: Article 6(1)(f) GDPR in conjunction with Article 32 GDPR.
The data subjects concerned receive separate data protection information pursuant to Article 13 GDPR directly from us; these processing operations are not the subject of this policy. Please address any questions in this regard to info@dokting.de.
22. Server log files and hosting
When the website is visited, technical data are automatically processed by the hosting provider, for example the IP address, the date and time of access, the file retrieved, the referrer URL, the browser type, the operating system and status codes. This processing serves the secure and stable provision of the website as well as the prevention of attacks. The legal basis is Article 6(1)(f) GDPR.
Website hosting: Hostinger (Hostinger International Ltd.). For the secure, time-limited upload of customer documents, ownCloud.online (operated by ownCloud GmbH, Germany) is used; the documents are processed there and are not stored on the web server of the website. Data processing agreements (Auftragsverarbeitung) pursuant to Article 28 GDPR are in place with these providers.
The server log files (Server-Logfiles) are deleted or anonymised by the hosting provider after a short time, as a rule within a few days, insofar as they are not required for the investigation of a security incident. Complete IP addresses from the log files are not transferred into our own data holdings.
23. Processing of IP addresses
An IP address is personal data. We therefore handle it in accordance with the following principle, which applies uniformly to all our systems.
Principle: no storage of complete IP addresses. In our own data holdings – security, evidence and protection records – we store no complete IP addresses. Only the following are stored:
- a key-bound pseudonym value of the address, formed as HMAC-SHA256 with a secret key that is not stored together with it. It makes it possible to relate repeated accesses from the same address to one another, but does not permit any inference as to the address itself without the secret key;
- the network prefix (Netzwerk-Präfix) of the address – in the case of IPv4 the first 24 bits (/24), in the case of IPv6 the first 48 bits (/48);
- where available, the number of the autonomous system (AS number) and the country code of the network operator.
Complete IP addresses arise exclusively on a temporary basis in the server log files (Server-Logfiles) of our hosting provider and are deleted or anonymised there after a short time (section 22).
Purposes. We process the information referred to above for three purposes: for the prevention of misuse (detection of unauthorised access to accounts, limitation of repeated failed login attempts, prevention of automated retrievals), for the evidencing of consents and declarations (evidence that a declaration was submitted from a particular access) and for the attribution of unauthorised copies of protected content (tracing of videos and portal articles that appear outside the platform).
Legal bases. Article 6(1)(f) GDPR in conjunction with Article 32 GDPR – our legitimate interest in the security of our systems, in the prevention of misuse and in the protection of our copyright-protected content. For the evidencing of consents and contractual declarations, additionally Article 6(1)(b) GDPR (necessity for the initiation and performance of the contract) and Article 6(1)(c) GDPR in conjunction with Article 7(1) GDPR (statutory obligation to demonstrate consents given).
Balancing of interests. The restriction to the pseudonym value, network prefix, AS number and country code is the least intrusive means that still fulfils the stated purpose: it enables an access to be recognised again without disclosing the address itself. No profiling, no determination of location beyond the level of the country, no linking with marketing data and no evaluation of persons takes place.
In detail, the following applies:
1. Server log files at the hosting provider. When the website is accessed, our hosting provider automatically processes technical access data including your complete IP address in order to deliver the website and to prevent attacks. Legal basis: Article 6(1)(f) GDPR. Deletion or anonymisation takes place after a short time, as a rule within a few days, insofar as the data are not required for the investigation of a security incident.
2. Evidence of declarations in connection with orders and with the free initial consultation. For the purpose of evidencing the declarations submitted, we store no IP address in plain text, but exclusively the key-bound pseudonym value (HMAC-SHA256) as well as the network prefix. It serves solely as evidence that the declaration was submitted from a particular access. Retention takes place in parallel with the associated contract and consent records (section 30).
3. Contract documentation. The contract documentation that we create for every order and make available to you in the customer portal deliberately contains no IP address and no browser identifier. The time of submission and the checksums of the underlying legal texts are sufficient as evidence.
4. Customer portal. In order to detect unauthorised access, we store, in relation to a login to the customer portal and to security-relevant operations in your account (such as login, password change, retrieval of the contract documentation), the pseudonym value, the network prefix as well as – where available – the AS number and country code of the access, and furthermore a truncated browser identifier. The complete address is not stored. Legal basis: Article 6(1)(f) GDPR in conjunction with Article 32 GDPR. Session records are deleted 30 days after the end of the session; entries in the access log are deleted as soon as they are no longer required for security purposes, at the latest after 12 months.
5. Protection against login attempts (prevention of misuse). In order to limit repeated failed login attempts, we do not store the IP address itself, but merely a truncated pseudonym value derived from it as a counting key. These records are deleted after 30 days. Legal basis: Article 6(1)(f) GDPR in conjunction with Article 32 GDPR.
6. Protection of audiovisual content and of the portal articles. In the playback and reading sessions referred to in sections 14 and 15, exclusively the network prefix and the pseudonym value are processed, never the complete address. The technical fields are deleted or cleared 90 days after the start of the session.
7. Upload of documents. When you upload your documents via the secured link, the provider ownCloud.online, acting as our processor (Auftragsverarbeiter), processes the connection data including the IP address. The server location is Germany.
8. Google Analytics 4 (only with consent). Google does not store complete IP addresses; the IP data are processed for the approximate determination of location and are not stored.
24. Cookies, local storage and other storage operations
We use cookies and comparable storage technologies only to the extent described below. Technically necessary storage operations are exempt from consent pursuant to Section 25(2) no. 2 TDDDG; all others require your consent pursuant to Section 25(1) TDDDG and Article 6(1)(a) GDPR.
All storage operations in the “necessary” category in the overview below take place without your consent, because they are strictly necessary for the service requested by you. Consent is required only for the entries identified as such: the two analytics cookies _ga and _ga_<measurement-ID>.
Complete overview
| Name | Type | Purpose | Storage period | Legal basis |
|---|
dokting_consent_v2 | LocalStorage (first party, DokTing) | Stores your selection in the cookie banner (necessary / analytics / marketing) so that it is taken into account on further visits, and serves as evidence of your decision | Until deleted by you or until you change your selection | Section 25(2) no. 2 TDDDG – necessary, no consent required; for evidencing purposes additionally Article 6(1)(c) GDPR in conjunction with Article 7(1) GDPR |
dk_banner_off | LocalStorage (first party, DokTing) | Remembers which notice banner you last closed, so that it is not displayed again | Until deleted by you | Section 25(2) no. 2 TDDDG – necessary, no consent required; Article 6(1)(f) GDPR |
dokting_last_order | SessionStorage (first party, DokTing) | Displays to you, after the order, the order confirmation with the order number and the bank details | End of the browser session | Section 25(2) no. 2 TDDDG – necessary, no consent required; Article 6(1)(b) GDPR |
dkfs_src | SessionStorage (first party, DokTing) | Retains the source information of the form for the free initial consultation for the duration of the application | End of the browser session | Section 25(2) no. 2 TDDDG – necessary, no consent required; Article 6(1)(b) GDPR |
dkfs_ref | SessionStorage (first party, DokTing) | Retains the referrer information for the same form for the duration of the application | End of the browser session | Section 25(2) no. 2 TDDDG – necessary, no consent required; Article 6(1)(b) GDPR |
dk_portal_lang | SessionStorage (first party, DokTing) | Remembers the language selected in the customer portal | End of the browser session | Section 25(2) no. 2 TDDDG – necessary, no consent required; Article 6(1)(b) GDPR |
dk_portal_from | SessionStorage (first party, DokTing) | Remembers the target page to which you are returned after logging in to the customer portal | End of the browser session | Section 25(2) no. 2 TDDDG – necessary, no consent required; Article 6(1)(b) GDPR |
dk_portal | Cookie (first party, DokTing) | Login to the customer portal (session identifier; HttpOnly, SameSite=Lax, additionally “Secure” in secured operation) | 30 days | Section 25(2) no. 2 TDDDG – necessary, no consent required; Article 6(1)(b) and (f) GDPR |
dk_portal_auth | Cookie (first party, DokTing) | Non-sensitive indication that a portal session exists; controls the display of “My account” in the page header, without data having to be retrieved for this purpose | 30 days | Section 25(2) no. 2 TDDDG – necessary, no consent required; Article 6(1)(b) GDPR |
dk_staff | Cookie (first party, DokTing) | Login to the internal administration area; only for staff, not for visitors to the website (HttpOnly, SameSite=Strict) | Session-based, invalid at the latest after 12 hours without activity | Section 25(2) no. 2 TDDDG – necessary, no consent required; Article 6(1)(f) GDPR in conjunction with Article 32 GDPR, Section 26 BDSG |
dokting-shell-<Version> | Cache Storage (service worker, first party, DokTing) | Cache of the installable web app (progressive web app) for faster loading and offline display | Until a new program version is published; it is then replaced automatically | Section 25(2) no. 2 TDDDG – necessary, no consent required; Article 6(1)(f) GDPR |
_ga | Cookie (Google Ireland Limited) | Distinction between users in Google Analytics 4 | 2 years | Consent required: Section 25(1) TDDDG and Article 6(1)(a) GDPR |
_ga_<measurement-ID> | Cookie (Google Ireland Limited) | Continuation of the session status in Google Analytics 4 | 2 years | Consent required: Section 25(1) TDDDG and Article 6(1)(a) GDPR |
Analytics cookies
The cookies _ga and _ga_<measurement-ID> are set only after you have consented to the “Analytics” category in the cookie banner. Until then, all measurement signals are set to “denied” in accordance with Google Consent Mode v2. You may change your consent at any time with effect for the future via the cookie settings at the bottom of the page. Details on reach measurement can be found in section 25.
Marketing
We do not currently use marketing services that require consent – such as the Meta Pixel. In this respect, no cookies are set and no information is stored on or read from your terminal device. Should we use such services in the future, this will take place exclusively after prior consent given via the cookie banner (category “Marketing”).
Deletion
You may delete cookies and local storage at any time via the settings of your browser and restrict their being set. If technically necessary storage operations are deleted, it may be that you have to log in again or that the cookie banner is displayed again.
25. Reach measurement with Google Analytics 4 (only with your consent)
On this website we use the web analytics service Google Analytics 4 (GA4) in order to understand the use of the website and to improve our offering. The service is loaded and activated only after you have expressly consented via the cookie banner (category “Analytics”). Until then, all measurement signals are set to “denied” in accordance with Google Consent Mode v2.
Legal basis: your consent pursuant to Article 6(1)(a) GDPR as well as Section 25(1) TDDDG. You may withdraw your consent at any time with effect for the future by changing your selection via the “Cookie settings” link at the bottom of the page.
Recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. In this context, data may be transferred to Google LLC in the USA; this transfer is based on the adequacy decision on the EU-US Data Privacy Framework, to which Google has adhered, as well as, where necessary, on standard contractual clauses (Standardvertragsklauseln).
Data processed: pseudonymous usage data (pages accessed, time spent, events, device and browser information, approximate location). GA4 does not log complete IP addresses; IP data are processed for the approximate determination of location and are not stored.
Storage period: the retention of user-related and event-related data in GA4 is set to the maximum selectable period of 14 months; thereafter the data are automatically deleted or aggregated.
Further information: policies.google.com/privacy
26. Data backup
Purpose. We regularly create backup copies of our database in order to ensure the availability and restorability of the data following a technical failure (Article 32(1)(b) and (c) GDPR).
Scope. The backup covers the data holdings of the application, in particular order, invoice, customer, portal and evidence data.
Encryption. Backup copies that leave our system are transmitted and stored exclusively in encrypted form. Encryption is carried out using AES-256-GCM. The key is not stored in the backup file, in the backup directory or in log files. Unencrypted backups are not uploaded.
Storage locations. A local backup copy is stored in a directory that lies outside the area served by the web server and is therefore not retrievable via the website. The external, encrypted backup copy is transferred via WebDAV into a separate backup folder at ownCloud.online (ownCloud GmbH, Germany). A data processing agreement (Auftragsverarbeitung) pursuant to Article 28 GDPR is in place with the provider. The server location is in Germany; no third-country transfer (Drittlandübermittlung) takes place in this respect.
Legal basis. Article 6(1)(c) GDPR in conjunction with Article 32 GDPR (obligation to ensure data security) as well as Article 6(1)(f) GDPR (legitimate interest in fail-safe operation).
Storage period. Backup copies are retained according to a fixed rotation procedure (number) and are additionally deleted after a maximum age; the oldest copies in each case are removed automatically, whereby the last remaining copy is only deleted once a newer one exists. Periodic backups and emergency copies created before a restore are deleted separately in accordance with the same rule. Backup copies are operational copies for recovery and not an archive for the fulfilment of statutory retention obligations.
Relationship to deletion requests. We carry out deletions in the live system. For technical reasons, the data concerned remain contained in backup copies already created until the expiry of the rotation period; they are not further processed there and are deleted upon expiry of the retention period of the copy in question. A restore from a backup is carried out exclusively in order to remedy a loss of data; deletions already carried out are executed again following a restore on the basis of a separately kept deletion record, without affecting data lawfully created thereafter.
27. Recipients of data
Recipients of personal data may, insofar as necessary, be IT and hosting service providers, payment service providers and credit institutions, email and communication service providers, accounting, invoicing and tax advisory service providers as well as, at the express request or with the consent of the customer, also universities, employers, recognition authorities, public authorities or other competent bodies.
Disclosure to universities, employers, recognition authorities or public authorities takes place exclusively after prior information about the specific recipient and the scope of the data, and on the basis of your separate consent (Article 6(1)(a) GDPR) or for the performance of the contract (Article 6(1)(b) GDPR).
In addition, we disclose personal data insofar as we are legally obliged to do so (Article 6(1)(c) GDPR) or insofar as this is necessary for the establishment, exercise or defence of legal claims (Article 6(1)(f) GDPR). No sale of personal data takes place.
28. Processors
Data processing agreements pursuant to Article 28 GDPR are in place with the following service providers:
| Processor (Auftragsverarbeiter) | Task | Place of processing |
|---|
| Hostinger International Ltd. | Hosting of the website, server log files (Server-Logfiles); mailbox of the domain dokting.de through which order, contract and withdrawal confirmations are sent | EU/EEA |
| ownCloud GmbH (ownCloud.online), Germany | Secure, time-limited upload of customer documents; storage of the encrypted external data backup | Germany |
| Google Ireland Limited, Dublin, Ireland | Reach measurement with Google Analytics 4 (only with consent) | EU, transfer to the USA possible (see section 29) |
The processors are contractually obliged to process personal data exclusively in accordance with our instructions and in compliance with appropriate technical and organisational measures.
Where you choose to communicate via WhatsApp, Meta Platforms Ireland Ltd. acts as an independent recipient; possible transfers to third countries are described in section 29.
29. Third-country transfer (Drittlandübermittlung)
The principal processors (Hostinger for website hosting, ownCloud.online for the document upload and the data backup) process personal data within the European Union or the European Economic Area.
A transfer to countries outside the EU/the EEA may come into consideration in the following cases:
- Google (Google Analytics 4): the recipient is Google Ireland Limited; a transfer to Google LLC in the USA is possible. The basis is the adequacy decision on the EU-US Data Privacy Framework as well as, where necessary, the standard contractual clauses (Standardvertragsklauseln) of the EU Commission.
- WhatsApp (Meta Platforms Ireland Ltd.): if you choose to make contact via WhatsApp, your contact and message data are transmitted to Meta; data may also be processed there outside the EU. You may instead choose the email route via info@dokting.de at any time.
Insofar as further services with their seat or infrastructure outside the EU/the EEA are used in an individual case, we base the transfer on appropriate safeguards within the meaning of Articles 44 et seq. GDPR, in particular the standard contractual clauses of the EU Commission or an adequacy decision.
30. Storage period
Personal data are stored only for as long as this is necessary for the respective purposes or statutory retention obligations exist. In detail, the following periods apply in particular:
- Invoices and accounting vouchers: 8 years pursuant to Section 147(3) AO (in the version applicable since 2025), Section 257(4) HGB and Section 14b(1) UStG.
- Annual financial statements and comparable accounting documents: 10 years pursuant to Section 147(3) AO / Section 257(4) HGB.
- Business and commercial letters (including emails): 6 years pursuant to Section 147(1) nos. 2 and 3 in conjunction with subsection (3) AO / Section 257(4) HGB.
- Withdrawal declarations and acknowledgements of receipt relating to a contract: 6 years from the end of the calendar year as contract-related correspondence (Section 257(1) no. 2, (4) HGB; Section 147(1) no. 2, (3) AO).
- Withdrawal-related accounting and refund records (credit notes, refund entries, payment journal): 8 years (Section 147(3) AO, Section 257(4) HGB, Section 14b(1) UStG).
- Declarations via the withdrawal function without reference to a contract: deletion after clarification, at the latest after 6 months.
- Contract documentation relating to an order (contract record, pro forma invoice, completion notice): 6 years from the end of the calendar year as commercial letters (Section 257(1) nos. 2/3, (4) HGB; Section 147(1) nos. 2/3, (3) AO); a request for deletion does not extend to this.
- Contract data and consent records: for the duration of the contractual relationship and thereafter until the expiry of the statutory limitation periods, as a rule 3 years from the end of the year in which the contract ended pursuant to Sections 195 and 199 BGB, insofar as no longer retention obligations exist. The order data underlying an invoice (name, email address, package, amount) remain stored with the invoice for 8 years; operational contact data (telephone number, street) and your message accompanying the order are removed after the expiry of the limitation period or upon your request for erasure. The remaining data are pseudonymised or restricted in processing, not anonymised.
- Documents uploaded via ownCloud.online: manual deletion within 30 days of completion of the service booked, documented with date and person carrying it out, insofar as no statutory retention obligation or another ongoing order precludes this; the expiry of the upload link does not delete any documents.
- Enquiry and contact data without conclusion of a contract: deletion as soon as they are no longer required for the handling of the matter, as a rule at the latest after 6 months.
- Requests for the free initial consultation without a customer relationship: at most 12 months.
- Appointment data without a subsequent engagement: 12 months after the appointment.
- Server log files: deletion or anonymisation by the hosting provider after a short time, as a rule within a few days, insofar as they are not required for the investigation of security incidents.
- Placement business records: three years after completion of the placement activity; applicants’ documents and copies as described in section 11.
- Portal sessions: 30 days after the end of the session; access and video retrieval logs 12 months; answers to check-in and article questions 12 months from the answer; portal accounts 36 months from the last login (operational periods; an ongoing order precludes deletion).
- Counting keys for limiting failed login attempts: 30 days.
- Technical playback and reading data relating to protected content: 90 days from the start of the session; the proportion viewed 12 months while an entitlement exists; the reduced attribution record for at most 5 years from the start of the session (operational maximum, annual review). Temporary network-prefix blocks: 30 days after the end of the block. Sessions of public videos without any account link: 30 days.
- Responses to follow-up questions: 12 months from the answer; during an ongoing order until its completion.
- Activation codes (portal): unredeemed 30 days after expiry, redeemed 36 months from redemption. Release codes: unredeemed 30 days after expiry, redeemed 5 years from redemption (operational maximum).
- Reviews and success stories: until withdrawal of consent; thereafter only the record of consent and withdrawal remains.
- Data in Google Analytics 4: 14 months.
- Backup copies: according to a fixed rotation procedure and a maximum age; the oldest copies in each case are deleted automatically.
Upon expiry of the respective period, the data are deleted or destroyed in a data-protection-compliant manner, unless further retention is required by law or is necessary for the establishment, exercise or defence of legal claims. Documents of relevance for tax purposes may in individual cases have to be retained for longer, as long as the period for tax assessment (Sections 169 and 170 AO) has not yet expired.
We implement these retention periods through a structured internal process. For records subject to a statutory retention period, we calculate and document its end using the starting point specified by the applicable law. The end of the calendar year is used only where the applicable provision requires it. For the intermediary’s other business records under section 298(2) SGB III, the three-year retention period is calculated from completion of the placement activity. Technical changes to a record do not extend the period. Records whose retention period has expired are deleted after review; documents subject to statutory retention obligations are not deleted before that period ends. Retention beyond that period takes place only in a documented individual case, such as ongoing litigation, with a reason, responsible person and review date.
31. Rights of data subjects
Within the scope of the statutory requirements, data subjects have the following rights:
- Access to the data processed concerning them (Article 15 GDPR),
- Rectification of inaccurate or incomplete data (Article 16 GDPR),
- Erasure (Article 17 GDPR); excluded are data that we require in order to comply with statutory retention obligations or for the establishment, exercise or defence of legal claims (Article 17(3)(b) and (e) GDPR),
- Restriction of processing (Article 18 GDPR),
- Data portability (Article 20 GDPR),
- Objection to processing operations based on Article 6(1)(f) GDPR, on grounds relating to your particular situation (Article 21(1) GDPR),
- Withdrawal of a consent given with effect for the future (Article 7(3) GDPR); the lawfulness of the processing carried out up to the withdrawal remains unaffected.
In order to exercise these rights, an informal message to info@dokting.de or to the address stated in section 1 is sufficient. In order to protect your data, we may, in the case of justified doubts, request additional information to confirm your identity (Article 12(6) GDPR). The handling of your request is free of charge for you.
32. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right under Article 77 GDPR to lodge a complaint with a supervisory authority, in particular in the Member State of your place of residence, your place of work or the place of the alleged infringement.
The supervisory authority competent for us is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98
24103 Kiel
https://www.datenschutzzentrum.de
33. Obligation to provide data
The provision of certain data is necessary in order to answer enquiries, to prepare contracts or to provide services; in part we are legally obliged to collect data, for example in connection with invoicing. Without these data, the handling or performance of the desired service may be wholly or partly impossible. Information based exclusively on consent – such as a photograph and video for a success story – is always voluntary; refusal to provide it entails no disadvantage for the service owed under the contract.
34. Automated decision-making
Automated decision-making in individual cases, including profiling within the meaning of Article 22 GDPR, does not take place.
The protection mechanisms for audiovisual content and portal articles (sections 14 and 15) generate exclusively probability values; at most they lead to a reduction in quality or to the termination of the current session. Any decision going beyond this is taken by a human being following review. The prioritisation of available consultation appointments (section 8) likewise does not result in any automated rejection; every case that is not automatically scheduled is submitted for personal review.
35. Data security
We take appropriate technical and organisational measures pursuant to Article 32 GDPR in order to protect personal data against loss, misuse, unauthorised access, alteration or disclosure. These include in particular encrypted transmission via TLS, the storage of passwords exclusively as a non-reversible scrypt hash, the pseudonymisation of IP addresses (section 23), HttpOnly and SameSite protection for session cookies, the limitation of failed login attempts, the separation of the upload area from the web server, the encryption of external backup copies with AES-256-GCM as well as the logging of security-relevant accesses. The measures are adapted in line with technical developments.
36. Currency and amendment of this privacy policy
This privacy policy may be adapted if technical, legal or organisational conditions change. The version currently applicable is available on this website.
DokTing – Hazem Ibrahim, Berliner Straße 24b, 23738 Lensahn, Germany · info@dokting.de · Telephone +49 152 29555290