Berlin Chiropractic Studio

Legal

Privacy policy

This is a translation for convenience. The legally binding version is the German one.

1. Controller

The controller within the meaning of the General Data Protection Regulation (DSGVO / GDPR) and other data-protection provisions is:

Kjell Paris – Heilpraktiker (non-medical practitioner) & chiropractor, Kösener Str. 10, 14199 Berlin

Phone: 0151-41353368

Email: kjellparisdc@gmail.com

The practice operates at the locations Berlin (Kösener Str. 10, 14199 Berlin) and Braunschweig (Theaterwall 4, 38100 Braunschweig). You can find the complete details in the legal notice (Impressum).

2. General information on data processing

As a matter of principle, we process the personal data of our users as well as our patients only insofar as this is necessary to provide a functioning website, to deliver our therapeutic services, and to fulfil our legal obligations.

Depending on the purpose, the legal bases for processing are in particular Art. 6 (1) (a) DSGVO (GDPR) (consent), (b) (contract or pre-contractual measures), (c) (legal obligation), and (f) (legitimate interest), as well as – in the case of health data – Art. 9 (2) (h) DSGVO (GDPR) in conjunction with § 22 BDSG (German Federal Data Protection Act).

3. Accessing the website & server log files (hosting)

Each time our website is accessed, the system automatically records data and information from the accessing device. The following, in particular, are collected: IP address, date and time of access, the page/file requested, the amount of data transferred, the browser type and version used, the operating system, and the referrer URL.

This data is stored in the system's log files. This data is not stored together with other personal data of the users. The processing serves the technical provision, the stability, and the security of the website. The legal basis is our legitimate interest pursuant to Art. 6 (1) (f) DSGVO (GDPR).

Our website is hosted by an external service provider (Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA). The provider processes the aforementioned data on our behalf on the basis of a data processing agreement (Art. 28 DSGVO / GDPR). Any transfer to the USA takes place on the basis of appropriate safeguards (EU Standard Contractual Clauses or the EU-U.S. Data Privacy Framework).

4. Cookies & consent management

Our website uses exclusively technically necessary cookies or comparable storage techniques (e.g. your browser's local storage) to save your choice regarding the cookie settings. This local storage merely records your decision („necessary only“ or „accept“) – no personal profiles are created and no data is transferred to third parties.

Optional services (e.g. the map display) are only loaded after your express consent. The legal basis for technically necessary storage is § 25 (2) TDDDG (German Telecommunications and Telemedia Data Protection Act) as well as Art. 6 (1) (f) DSGVO (GDPR); for optional services § 25 (1) TDDDG in conjunction with Art. 6 (1) (a) DSGVO (GDPR). You can withdraw your consent at any time with effect for the future by deleting your browser's local storage.

5. Contacting us (phone & email)

If you contact us by phone or email, the data you provide (e.g. name, contact details, and the content of your enquiry) is processed and stored in order to handle your request.

The legal basis is Art. 6 (1) (b) DSGVO (GDPR), provided that your enquiry is aimed at concluding or performing a contract; otherwise our legitimate interest in responding to your enquiry pursuant to Art. 6 (1) (f) DSGVO (GDPR). If your enquiry contains information about your state of health, the processing is additionally based on Art. 9 (2) (h) DSGVO (GDPR). The data is deleted as soon as it is no longer required to achieve the purpose and no statutory retention obligations conflict with this.

6. Online appointment booking

For online appointment scheduling we use the external service Lemniscus (my.lemniscus.de). When you click on „Book appointment“, you are redirected in a new tab to the provider's platform. The data you enter there (e.g. name, contact details, preferred appointment, and where applicable details about your concern) is processed by the provider in order to carry out the appointment booking.

The legal basis is Art. 6 (1) (b) DSGVO (GDPR) (performance of pre-contractual measures) as well as – insofar as health data is affected – Art. 9 (2) (h) DSGVO (GDPR). The data protection provisions of the respective provider additionally apply to the data processing on the booking platform. Please inform yourself there about the details of the processing.

7. Processing of health and patient data

As part of the treatment, we process special categories of personal data, in particular health data (Art. 9 DSGVO / GDPR). These include, for example, medical history, findings, diagnoses, courses of treatment, and documents you bring with you (such as MRI or X-ray findings).

The processing is carried out for the purpose of health care, diagnostics, treatment, and the administration of the treatment relationship. The legal basis is Art. 9 (2) (h) DSGVO (GDPR) in conjunction with § 22 (1) no. 1 (b) BDSG (German Federal Data Protection Act) as well as Art. 6 (1) (b) DSGVO (GDPR) (treatment contract).

The processing is carried out by us and by our staff, who are bound by professional confidentiality. Professional and criminal-law confidentiality obligations apply (§ 203 StGB, German Criminal Code). Your data is only disclosed to third parties (e.g. laboratories, persons providing follow-up treatment, billing offices, or your private health insurer) insofar as this is necessary for the treatment or billing and a legal basis exists or you have consented.

8. Map material (Google Maps)

To display our location and directions, a map from the Google Maps service may be embedded. This map is only loaded after your express consent. Before you give your consent, no connection to Google's servers is established.

Upon activation, data (including your IP address) is transferred to Google, and where applicable also to the USA. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The legal basis is your consent pursuant to Art. 6 (1) (a) DSGVO (GDPR) and § 25 (1) TDDDG, which you can withdraw at any time with effect for the future. You can find details in Google's privacy policy.

9. Fonts (web fonts)

To ensure a consistent presentation, we use fonts that are embedded locally on our server or with our hosting provider and delivered from there. When the website is accessed, no connection to third-party servers (e.g. Google Fonts) is established and no personal data is transferred to third parties.

10. Storage period & retention periods

We store personal data only for as long as this is necessary for the respective purposes or as long as statutory retention obligations exist. Statutory retention periods apply to patient and treatment records as well as to documents relevant under tax and commercial law, and these can generally be up to ten years. Once the respective periods have expired, the data is deleted.

11. Your rights as a data subject

Within the scope of the legal requirements, you have the following rights:

  • Right of access to the data processed about you (Art. 15 DSGVO / GDPR)
  • Right to rectification of inaccurate data (Art. 16 DSGVO / GDPR)
  • Right to erasure (Art. 17 DSGVO / GDPR)
  • Right to restriction of processing (Art. 18 DSGVO / GDPR)
  • Right to data portability (Art. 20 DSGVO / GDPR)
  • Right to object to the processing (Art. 21 DSGVO / GDPR)
  • Right to withdraw a given consent at any time with effect for the future (Art. 7 (3) DSGVO / GDPR)

12. Right to lodge a complaint with a supervisory authority

Without prejudice to any other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the DSGVO (GDPR). For this purpose, you may in particular contact the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement.

13. Data security

For security reasons and to protect the transmission of confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the padlock symbol in your browser's address bar and by the „https://“ prefix.

14. Currency and amendment of this privacy policy

This privacy policy is currently valid. As our website develops or due to changed statutory or regulatory requirements, it may become necessary to amend this privacy policy. The current version can be accessed on this page at any time.

Last updated: July 2026