Privacy Policy
Here you can find out which personal data we process when you visit this website and get in touch with us, for what purpose, and what rights you have.
1. Overview
As a medical practice, protecting your data is a matter of course for us and part of our professional duty of confidentiality. We process personal data on this website only to the extent necessary to provide the website, respond to your enquiries, or with your consent.
Personal data is any information that can be used to identify you personally, for example your name, phone number, email address or IP address. Health-related information is a specially protected category of data under Article 9 of the General Data Protection Regulation (GDPR).
This privacy policy covers the website. For the processing of your data as part of treatment at the practice, you will receive separate patient information.
2. Controller
The controller responsible for data processing on this website is:
Kardiologie Chantzaras
Dr. medic Stergios Chantzaras
Josef-Wurzler-Straße 7/3
77855 Achern, Germany
Phone: 07841 6730770
Email: info@kardiologie-chantzaras.de
Data protection officer
Our practice is not legally required to appoint a data protection officer. If you have questions about data protection, please contact us directly using the details above.
3. Hosting and server log files
This website is hosted by IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany. The servers are located in data centres in Germany. We have concluded a data processing agreement with IONOS under Article 28 GDPR; IONOS processes the data solely on our instructions. Further information: www.ionos.de/terms-gtc/datenschutzerklaerung.
Server log files
Every time the website is accessed, the following information transmitted by your browser is automatically recorded:
- IP address of the requesting device
- date and time of access
- page accessed and amount of data transferred
- previously visited page (referrer)
- browser and operating system used
This data is required to deliver the website, ensure its stability and security, and detect attacks. The legal basis is our legitimate interest under Article 6(1)(f) GDPR. Log data is deleted after 30 days at the latest, unless it is needed for longer to investigate a security incident.
Encrypted transmission
This website uses TLS encryption. You can recognise the encrypted connection by the "https://" in your browser's address bar. Data you send to us cannot be read by third parties during transmission.
4. Contact by phone, fax, email and KIM
If you call us, send a fax or write us an email, we process your details (for example name, phone number, email address and your enquiry) in order to answer your request and, if applicable, arrange an appointment.
The legal basis is Article 6(1)(b) GDPR to the extent your enquiry relates to treatment, and otherwise our legitimate interest in processing enquiries under Article 6(1)(f) GDPR. If you share information about your health with us, we process it under Article 9(2)(h) GDPR in conjunction with Section 22(1) No. 1(b) of the Federal Data Protection Act (BDSG) to prepare for treatment.
Please note: an unencrypted email can be viewed by third parties in transit. Please avoid sending us findings, medical letters or other sensitive documents by email; instead, send them by fax or bring them to your appointment.
Transfer of medical documents via KIM or fax
For the privacy-compliant transfer of medical documents and findings, we prefer digital channels via the German healthcare telematics infrastructure (TI). Doctors, hospitals and other healthcare providers can send us documents via KIM (Kommunikation im Medizinwesen), the end-to-end encrypted messaging service of the TI. Alternatively, documents can be sent by fax to 07841 67307743.
We process these documents to carry out your treatment under Article 9(2)(h) GDPR in conjunction with Section 22(1) No. 1(b) BDSG. They become part of your patient record and, in line with the medical documentation obligation, are generally kept for ten years after the end of treatment (Section 630f(3) of the German Civil Code, BGB).
5. Booking an appointment via Doctolib
To book an appointment, the "Termin" and "Nachricht" buttons link directly to the Doctolib platform. To display the Doctolib logo in these buttons, an image file is loaded from Doctolib's servers. In the process, your IP address is transmitted to Doctolib. The legal basis is our legitimate interest in simple and clearly recognisable online appointment booking under Article 6(1)(f) GDPR. Further data is only transmitted once you click one of the buttons.
Once you click "Termin" or "Nachricht", you leave our website and are taken to the website of Doctolib Deutschland GmbH. The data you enter there, in particular your name, contact details and information about your request, is processed by Doctolib under its own responsibility. Doctolib's privacy policy applies: www.doctolib.de/datenschutz.
We receive from Doctolib the information required to prepare and carry out the appointment you have arranged. The legal basis for this processing is Article 6(1)(b) GDPR (initiation of the treatment contract).
6. Cookies and consent
Cookies are small text files that your browser stores on your device. Comparable techniques include, for example, the browser's local storage. We distinguish between:
- Necessary storage: without it, the website does not function as you would expect, for example storing your cookie choice. The legal basis is Section 25(2) No. 2 of the German Telecommunications-Digital-Services-Data-Protection Act (TDDDG) in conjunction with Article 6(1)(f) GDPR.
- Optional services: statistics, marketing and external content are only loaded if you agree. The legal basis is your consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR.
On your first visit, we ask you in a notice which categories you agree to. You can decline all optional services without any disadvantage in using the website. You can change or withdraw your choice at any time: open cookie settings. The link is also in the footer of every page.
The consent notice is our own solution and is loaded from our own server; no data is transmitted to third parties in the process.
Overview of stored information
| Name | Category | Purpose | Storage period |
|---|---|---|---|
| kardiologie-privacy-consent-v1 | Necessary | Stores your choice from the cookie notice (local storage) | 6 months |
| kardiologie-language | Necessary | Stores the website language you selected (local storage) | until you clear your browser data |
| _ga, _ga_* | Statistics | Google Analytics: distinguishes visitors for anonymous reach measurement | up to 2 years |
| _fbp | Marketing | Meta Pixel: measurement and optimisation of ads | 3 months |
7. Embedded services
The following services are only loaded once you have consented to the relevant category.
Google Maps (category: external content)
To display our location, we may embed a map from Google Maps. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When the map is loaded, your IP address and information about your browser, among other things, are transmitted to Google and may be transferred to the USA. The map is only loaded after you have consented or clicked "Load map". The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. Google is certified under the EU-US Data Privacy Framework. Further information: policies.google.com/privacy.
Google Analytics (category: statistics)
With your consent, we use Google Analytics 4, possibly via Google Tag Manager, to understand how the website is used and to improve it. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data collected includes, for example, pages visited, time spent, approximate region, device type and browser. IP addresses are not stored by Google Analytics 4. Data may be transferred to the USA; Google is certified under the EU-US Data Privacy Framework. We have limited the retention period of user data to 2 months. The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. We have a data processing agreement in place with Google.
Information about your health is not transmitted to Google Analytics.
Meta Pixel (category: marketing)
With your consent, we use the Meta Pixel provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. This allows us to measure whether visitors reach the website via our ads on Facebook and Instagram, and to improve these ads. This involves transmitting your IP address, browser information and the pages you visit to Meta, which may be transferred to the USA. Meta is certified under the EU-US Data Privacy Framework. We are jointly responsible with Meta for the collection and transmission of this data (Article 26 GDPR); the corresponding agreement can be found at facebook.com/legal/controller_addendum. The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG.
Information about your health is not transmitted to Meta.
Fonts
The fonts used on this website are loaded from our own server. No connection is made to servers operated by Google or other font providers.
8. Recipients and third countries
We only share your data if this is necessary for the purposes stated, if there is a legal obligation to do so, or if you have given your consent. Recipients include, in particular, our hosting provider and, only with your consent, the services listed above. Service providers who process data on our behalf are contractually bound by our instructions and by the requirements of the GDPR.
Data is only transferred to countries outside the European Union where indicated for the individual services, and only on the basis of an adequacy decision by the European Commission or standard contractual clauses.
9. Storage period
We only store personal data for as long as necessary for the respective purpose or as required by statutory retention periods. Specific periods can be found in the individual sections. Once the purpose no longer applies and the periods have expired, the data is deleted.
10. Your rights
You have the following rights regarding your personal data:
- Right of access (Article 15 GDPR)
- Right to rectification (Article 16 GDPR)
- Right to erasure (Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to withdraw consent with effect for the future (Article 7(3) GDPR); the lawfulness of processing carried out before the withdrawal remains unaffected
To exercise your rights, an informal message to the contact details listed in Section 2 is sufficient.
Right to object under Article 21 GDPR
Where we process your data on the basis of our legitimate interest under Article 6(1)(f) GDPR, you may object to this processing at any time for reasons arising from your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to assert, exercise or defend legal claims.
11. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates the GDPR. The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart, Germany
www.baden-wuerttemberg.datenschutz.de
12. Further information
Obligation to provide data
You can use the website without providing personal data. To book an appointment, you use the external platform Doctolib; Doctolib requires the fields marked as mandatory there so that the practice can contact you.
No automated decision-making
No automated decision-making, including profiling, within the meaning of Article 22 GDPR takes place.
Changes to this privacy policy
We will update this privacy policy whenever the website or legal requirements change. The version published here always applies.
Last updated: 6 October 2026