1. responsible body
Responsible for the data processing on this website is:
Dr. med. Parinaz Yavarzadeh
Private cardiology hybrid practice
Elisabethenstrasse 35
70197 Stuttgart
E-Mail: info@kardiocura.de
2. anonymity of the users
The use of our website is generally anonymous. Personal data is only stored if you actively transmit it.
3. data collected
The following types of data are stored when you use our website:
- IP address
- Date and time of access
- Visited pages
- Browser type and version
- Operating system
This data is processed to ensure the functionality and security of the website.
4. online scheduling tool
In our practice, we use Doctolib's practice software to organize our administrative workflows in a modern and efficient way, thus enabling us to
to be able to concentrate more on our patients. Information on data processing and data protection by Doctolib
Doctolib also processes personal (health) data for the medical and administrative care of our patients. The data processing is carried out in compliance with the GDPR as order processing, whereby your data is stored securely.
The most important things at a glance:
Information on on data protection and data security of specific Doctolib functions - for internal use
Consultation assistant: What categories of personal data are processed by the consultation assistant?
- Voice and data in the audio recording
- Transcription of the audio recording
- Patient health data, in particular data from the patient file relating to treatment in your healthcare facility: previous illnesses, medication, information on general physical condition, medical histories, diagnoses, treatment histories and documentation, prescriptions, associated correspondence with other healthcare facilities, billing-related information
- The usage and connection information in connection with your use of the Doctolib service (e.g. log files) Voice recording
What happens to patient data when using the consultation assistant?
- Audio recordings: are NOT kept after the treatment
- Text suggestions & transcriptions: are saved for 48 hours after the treatment
- Validated data: stored after transfer to the patient file in accordance with the regular Doctolib retention period
Patient information & consent
- Do patients have to consent to audio recording by the consultation assistant?
- Yes, patients must be informed via audio recording (verbally - you can also inform them via posters in the practice, for example) - Can patients object to being admitted by the consultation assistant?
- Yes, patients can object to the use at any time
Video consultation:
- What categories of personal data are processed?
- Identity and contact details of the patient or relative: Gender, last name, first name, e-mail address, patient identification number, postal code, date of creation of the user account
- Health data: Patient's medical documents, notes completed by the healthcare professional, screenshots taken by the healthcare professional for the patient's medical follow-up
- Usage and connection information in connection with your use of the Doctolib platform (e.g. log files) What is the legal basis for processing personal data?
- The data controller (usually the medical practice) is responsible for determining the legal basis. Doctolib processes on behalf of the AVV.
How long will the personal data be stored?
- Specific retention periods requested by our users must be communicated to Doctolib. In the absence of such instructions from you, the standard retention period for the appointment history is 5 years. You are free to choose a different retention period between 1 and 20 years.
set.
AI-based telephone assistant:
- Is the patient's telephone conversation recorded?
- Yes, telephone conversations are recorded for interception - Do patients have to consent to the recording?
- No, patients do not have to consent to the recording. However, they are explicitly informed at the beginning of the conversation that the conversation will be recorded as long as they remain on the line. Patients have the option of hanging up at any time if they do not wish to do so. - What is the patient's data used for (purposes of processing)?
- conducting, transcribing and recording telephone conversations between patients of healthcare professionals and other callers and the AI-based telephone assistant
- the display of messages generated from the above transcriptions in the patient message service and the generation of corresponding calendar entries
- Improvements to services, statistics and
- Anonymization of data
- Creation of statistics on behalf of the user/subscriber - Is the data encrypted?
- Yes, all data is encrypted and stored on HDS-certified servers in the EU - Is the AI telephone assistant GDPR-compliant?
- Yes, fully GDPR-compliant
Recall:
- Do my patients have to agree to the sending of recalls in advance?
- Yes, they must. A recall is a “marketing measure” for which the patient's express consent is required - What happens if a patient has not agreed to the recall and I send one anyway?
- The recall will then not be delivered - Can patients refuse or revoke a recall?
- Yes, at any time - How do I obtain the patient's consent for the recall?
- When creating new patients, you will be asked for consent (for appointment notifications and recalls)
- You can subsequently change the patient's consent in the patient card under “Contact details” - Is the recall GDPR compliant?
- Yes, fully GDPR-compliant
Patient news
- Do my patients have to agree to receive notifications about patient messages in advance?
- Yes, prior consent is required for patient messages - Do I have to provide information about the use of patient messages?
- Yes, patients must be informed about the use of patient messages
Online appointment booking in the calendar service
- What categories of personal data are stored when I book an appointment online?
- Only data that is relevant and necessary with regard to appointment management is stored, e.g. identity and contact details of patients, professional status and professional data, health data as well as usage and connection information in connection with the use of the calendar service - Is online appointment booking GDPR-compliant?
- Yes, fully GDPR-compliant
SMS and email notifications
- Can I send SMS and email notifications to patients without their consent?
- No, prior consent is required for SMS/e-mail reminders - Can patients subsequently revoke SMS and email notifications?
- Yes, at any time
Patient file (part of treatment and billing management)
- Are the uploaded documents and data securely encrypted?
- Yes, all documents and data are encrypted on the server side according to an industry standard known as server side encryption and stored securely - at rest and in transit during transmission - Do patients have to consent to document storage?
- Yes, patients have full control over their documents - Who can view stored documents?
- Only authorized persons e.g. treating physicians and medical assistants of the practice
Digital patient admission: (medical questionnaires)
- Are the patient responses securely stored in the questionnaire?
- Yes, they are stored in full compliance with the GDPR - Can answers be changed or corrected afterwards?
- Yes, patients can call up and change questionnaires again until their appointment - May questionnaire responses be forwarded to other doctors?
- No, only with the express consent of the patient
Patient online payment (part of treatment and billing management)
- Are credit card details secure when paying online?
- Yes, we use PCI DSS-certified payment service providers with the highest security standards - Will patients' health data be linked to their payment data?
- No, this data is processed strictly separately
Further general information on data processing and data protection at Doctolib
How does Doctolib guarantee the security of my data?
- Encryption: All data exchange is fully encrypted
- Server certification: All servers are HDS-certified (hosting of health data)
- Location: Exclusively servers in the European Union
Which IT service providers (processors) does Doctolib work with for data storage?
- AWS EMEA: Storage of Doctolib service data with server location in the EU
- Cloudinary: Speicherung von Fotografien von Gesundheitsfachkräften mit Serverstandort in den USA
- Atos: Speicherung der Datenverschlüsselungs-Schlüssel mit Serverstandort in Frankreich
Bitte beachten Sie, dass die Liste der oben aufgeführten IT-Dienstleister (Auftragsverarbeiter) nicht abschließend ist. Eine vollständige Liste finden Sie im Auftragsverarbeitungsvertrag (Ziff. 33)
Auf welchen rechtlichen Grundlagen basiert die Verarbeitung meiner Daten?
- Verarbeitung erfolgt gemäß bestehendem AVV (Auftragsverarbeitungsvertrag)
Weitere Hilfreiche Links:
Doctolib AVV: Auftragsverarbeitungsvertrag
Fragen und Antworten zu Datenschutz und Datensicherheit bei Doctolib
Datenschutzhinweise für Patienten
Datenschutzhinweise für Gesundheitsfachkräfte
5. use of PaperFly
We use PaperFly, a cloud-based platform for document and data management.
- Safety measures: Storage in BSI-certified data centers in Germany with 256-bit AES encryption.
- Legal basis: Processing on the basis of Art. 6 para. 1 lit. b GDPR (fulfillment of contract) and Art. 9 para. 2 lit. h GDPR (processing of health data).
-
6. practice management system (PVS)
The data is stored in the Doctorly practice management system:
- Cloud storage: GDPR-compliant in German data centers.
- Legal basis: Art. 6 para. 1 lit. b GDPR and Art. 9 para. 2 lit. h GDPR.
7. data transmission for the purpose of invoicing
We work together with PVS Baden-Württemberg eG in Stuttgart for invoicing and the associated data processing.
- Purpose: Billing of medical services.
- Legal basis: Art. 6 para. 1 lit. b GDPR and Art. 9 para. 2 lit. h GDPR.
-
8. use of Google Maps
Our website uses Google Maps to display maps and to describe locations:
- Processed data: IP address and location data.
- Data protection: Further information can be found in Google's privacy policy: https://policies.google.com/privacy.
9. use of Google Analytics
Our website uses Google Analytics, a web analytics service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses so-called "cookies" - text files that are stored on your device and enable your use of our website to be analyzed.
- Data processing and purpose: The information generated by the cookies about your use of this website (including shortened IP address) is used to better understand user behavior and to improve our website accordingly.
- IP anonymization: We have activated IP anonymization on this website. As a result, your IP address will be truncated by Google within the European Union or other parties to the Agreement on the European Economic Area prior to transmission to the United States. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and truncated there.
- Legal basis of the processing: The data processing is based on your consent in accordance with Art. 6 para. 1 lit. a GDPR.
- Data transfer to third countries: Please note that your data may be transferred to the USA. The USA is considered a country with a lower level of data protection than in the EU. There is a risk that US authorities may gain access to your data without you having any legal recourse against this. However, this transfer will only take place with your express consent.
- Storage duration: The stored data will be deleted after 14 deleted automatically after one month. You can adjust the storage period in the Google Analytics settings.
Revocation and objection options
You have the right to withdraw your consent at any time. You can do this by:
1. prevent the storage of cookies by selecting the appropriate settings in your browser.
2. download and install a browser add-on to deactivate Google Analytics: https://tools.google.com/dlpage/gaoptout?hl=de
10. social media provider
We maintain profiles on various social media platforms in order to communicate with users and provide information about our services.
When using these platforms, the data protection guidelines of the respective providers apply. We have no influence on data processing by the platforms.
11. rights of data subjects
You have the right:
- Information about the processed data (Art. 15 GDPR).
- Correction of incorrect data (Art. 16 GDPR).
- Deletion of the data (Art. 17 GDPR).
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR).
- Objection to the processing (Art. 21 GDPR).
12. data security
We use SSL encryption for secure transmission of your data. Our systems are regularly checked and updated to ensure protection against unauthorized access, loss or misuse.
13. changes to the privacy policy
Diese Datenschutzerklärung hat den Stand Januar 2026 und wird bei Bedarf aktualisiert, beispielsweise aufgrund gesetzlicher Änderungen oder Anpassungen unserer Website.