14.08.2024
Privacy policy
for the Roger web application of Sanos Group AG (for dental practices)
Prepared on behalf of
Sanos Group AG
Industriestraße 44
8304 Walliesellen
Switzerland
Prepared by
QuR.digital GmbH
Große Elbstraße 42
22767 Hamburg
Version: 1.0.0
Table of contents
Definitions
Details of the controller
Questions about data protection
Notes on data security
Data transfers to third countries
Your rights as a data subject
Accessing the platform, access data
Disclosure of data to third parties
Task management via Roger
Implementation reporting via Roger
Use of Roger Chat
Your digital signature, Yousign
Contacting the controller
Contact management, CRM
Data processing by Sanos Technologies GmbH
Technical analysis via Sentry
Use of locally hosted Google Web Fonts
Embedding of third-party content
Updates to this privacy policy
The controller takes the protection of your personal data seriously and therefore complies with the applicable data protection laws. With this privacy policy, the controller fulfils its information obligations under Art. 12 et seq. of the General Data Protection Regulation (hereinafter referred to as the „GDPR“) and informs you about the details of the processing of your data as well as about your statutory rights in this regard.
This privacy policy applies to the use of the controller’s Roger web application (hereinafter referred to as „Roger“ or the „platform“). The privacy policy published there, in conjunction with the controller’s general terms and conditions, applies to the website https://www.goroger.com/ offered by the controller.
The controller reserves the right to amend this privacy policy with effect for the future, in particular in order to respond to changes in legislation or case law as well as to technical developments.
Definitions
- „Controller“ is, pursuant to Art. 4 No. 7 GDPR, the party that decides on the purposes and means of processing personal data. It determines above all what data is processed, how and for what purpose. It is responsible for the processing and must ensure that data protection provisions are complied with.
- „Processor“ is, pursuant to Art. 4 No. 8 GDPR, the party that acts for the controller and processes personal data on its behalf.
- „Personal data“ means, pursuant to Art. 4 No. 1 GDPR, all information that can be attributed to a directly or indirectly identifiable natural person (data subject).
- „Processing“ means, pursuant to Art. 4 No. 2 GDPR, all possible forms of data processing. This includes in particular the collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, alignment, restriction, erasure or destruction of personal data.
- „Data subject“ is, pursuant to Art. 4 No. 1 GDPR, the natural person to whom the data processed by the controller can be attributed directly or indirectly.
- „Recipient“ is, pursuant to Art. 4 No. 9 GDPR, the party to whom personal data is disclosed, irrespective of whether that party is a third party or not.
- „Third party“ is, pursuant to Art. 4 No. 10 GDPR, anyone other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or the processor, are authorised to process the personal data.
- „Special categories of personal data“ are, pursuant to Art. 9 (1) GDPR, in particular also health data of the data subject. Such data requires a higher level of protection.
- „Health data“ means, pursuant to Art. 4 No. 15 GDPR, personal data relating to the physical or mental health of the data subject from which information about the data subject’s state of health emerges.
- „Consent“ means, pursuant to Art. 4 No. 11 GDPR, any freely given, specific, informed and unambiguous indication of the data subject’s wishes in the form of a statement or another clear affirmative action (for example ticking a checkbox provided for that purpose) by which the data subject signifies agreement to the processing of their personal data.
- „Pseudonymisation“ means, pursuant to Art. 4 No. 5 GDPR, that personal data is processed in such a way that it can no longer be attributed to a specific person without additional information. This additional information must be kept separately and measures must be taken to ensure that the data can no longer be attributed to an identified or identifiable person.
- „Anonymisation“ describes, pursuant to DIN EN ISO 25237, the process by which personal data is irreversibly altered, either by the controller alone or in cooperation with another party, in such a way that the data subject can subsequently no longer be identified either directly or indirectly.
Details of the controller
Responsible for the data processing within the scope of the service offering within the meaning of Art. 4 No. 7 GDPR, as the provider of the service offering, is
Sanos Group AG
Industriestraße 44
8304 Wallisellen
Switzerland
represented by its management.
Questions about data protection
Should you have questions about the processing of your data by the controller within the scope of the service offering, or about exercising your data subject rights within the meaning of the GDPR, you can contact the controller or its data protection officer at any time by e-mail at datenschutz@goroger.com.
The controller has appointed the following data protection officer:
Philip Kopf, Dipl.-Jur.
QuR.digital GmbH
Große Elbstraße 42
22767 Hamburg
Tel.: +49 (40) 3252 4552
E-mail: datenschutz@goroger.com
Please note that, in the event that data subject rights are asserted (for example a request for information), the controller must first verify your identity by means of a suitable procedure.
Notes on data security
In order to ensure the best possible protection of your personal data, Secure Socket Layer (SSL) or Transport Layer Security (TLS) encryption is used for data transmission. This encryption ensures that the data you transmit within the platform cannot be read, redirected or altered by unauthorised third parties during transmission.
Where your data is stored by the controller, such storage takes place exclusively in appropriately security-certified data centres within the European Union (EU), within the scope of application of the GDPR. The controller expressly reserves the right to engage external service providers (known as processors) for the storage and processing of your data; such providers act exclusively on behalf of and in accordance with the instructions of the controller. The processors engaged by the controller are contractually obliged to implement technical and organisational measures (TOMs) which, according to the current state of the art, are suitable for ensuring that your data is processed in compliance with data protection and data security requirements.
Under no circumstances will the controller or any processor engaged by the controller disclose or sell your data to third parties without a legal basis.
Data transfers to third countries
The controller may engage as processors service providers that have their registered office in a third country or are part of an international organisation with its registered office in a third country. In the context of the GDPR, a third country is a country that is not a member of the European Union (EU) or the European Economic Area (EEA) and is therefore not subject to the regulatory scope of the GDPR. What these third countries have in common is that they may have their own data protection law, the substance of which may nevertheless fall below the level of protection of the GDPR. Against this background, Art. 44 GDPR provides that the transfer of data to third countries is permissible only under certain statutory conditions.
As a rule, the permissibility of data transfers to third countries is based, pursuant to Art. 45 GDPR, on an adequacy decision between the EU Commission and the third country concerned. The existence of an adequacy decision expresses that the data protection law applicable in the third country concerned offers a level of protection for your personal data comparable to that of the GDPR. Where no such adequacy decision exists, the data transfer is instead based, pursuant to Art. 46 (2) point (c) GDPR, on the conclusion of a contract between the controller and the relevant service provider on the basis of the
standard contractual clauses adopted by the EU Commission. These contractual clauses provide a sufficient guarantee on the part of the respective service provider, including with regard to the enforceability of the data subject rights provided for by the GDPR.
The controller expressly informs you within this privacy policy where a service provider has such a third-country connection. In that case, by giving your consent you agree that your personal data may be transferred to such a company.
Your rights as a data subject
As a „data subject“ affected by the processing within the meaning of Art. 4 No. 1 GDPR, you have certain indispensable rights (data subject rights). The controller is obliged to ensure these data subject rights and must also contractually oblige any processors it engages to support it as effectively as possible in implementing these rights. Accordingly, you have the following data subject rights:
- Right of access (Article 15 GDPR): You have the right to obtain information from the controller as to whether it processes personal data concerning you and, if so, what data this is and for what purpose the processing takes place.
- Right to rectification (Article 16 GDPR): You have the right to have inaccurate or incomplete personal data stored about you by the controller corrected.
- Right to erasure (Article 17 GDPR): Under certain circumstances you have the right to request the controller to erase your personal data. This right exists, for example, where the data is no longer necessary for the purposes for which it was collected or where you have withdrawn your consent.
- Right to restriction of processing (Article 18 GDPR): Under certain circumstances you have the right to restrict the further processing of your personal data. This right exists, for example, where you contest the accuracy of the data or where the processing is unlawful.
- Right to data portability (Article 20 GDPR):You have the right to receive from the controller a copy of your personal data in a structured, commonly used and machine-readable format. You may also have this data transmitted to another controller, where technically feasible.
- Right to object (Article 21 GDPR): You have the right to object, on grounds relating to your particular situation, to the processing of your personal data. The controller will then no longer process your data unless there are compelling legitimate grounds for the processing.
- Right to withdraw consent (Article 7 (3) GDPR):Where the controller processes your personal data on the basis of your consent, you may withdraw that consent at any time. The lawfulness of processing carried out up to the point of withdrawal remains unaffected.
- Right to lodge a complaint with a supervisory authority (Article 77 GDPR): You have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes data protection provisions.
You may assert your data subject rights at any time in writing or electronically by notifying the controller using the contact details stated in the section „Details of the controller“ of this privacy policy. In this context the controller reserves the right to verify your identity by means of a suitable procedure.
Accessing the platform, access data
As soon as you access Roger, the device you use automatically transmits access data (known as log files) to the platform’s hosting provider. These log files contain, among other things, data relating to identifiable persons.
Data processed:
- IP address
- Date and time of the request
- Time zone difference from Greenwich Mean Time (GMT)
- Content of the request (specific page)
- Access status/HTTP status code
- Amount of data transferred in each case
- Website from which the request originates
- Browser
- Operating system and its interface
- Language and version of the browser software
Purposes of processing:
The log files are strictly necessary in order to ensure the technical functionality of the platform. The transmission of your IP address in particular is necessary to enable the platform to be displayed on the device you are using. The data stored within the log files is neither combined by the controller with other data sources nor used to identify individual users. In particular, no evaluation of the collected data for marketing purposes takes place.
Lawfulness of processing:
The controller bases the lawfulness of this processing on Art. 6 (1) point (f) GDPR. The „legitimate interest“ required for this arises from the wish to offer you a secure and trouble-free experience when using the platform.
Recipients of the data:
The recipient of your personal data within the meaning of Art. 4 No. 9 GDPR is the platform’s hosting provider, Google (Google Ireland Ltd., Google Building, Gordon House, 4 Barrow St., Grand Canal Dock, Dublin 4, D04 V4X7, Ireland). In this context Google acts as a processor within the meaning of Art. 4 No. 8 GDPR on behalf of the controller and has been obliged by the controller, on the basis of a data processing agreement, to establish and maintain appropriate technical and organisational measures (TOMs) serving to protect your personal data.
Please note in this context that the parent company of Google Ireland Ltd. has its registered office in the USA. Although a transfer of data to the USA is not envisaged in principle, it cannot be conclusively ruled out. The statements on data transfers to third countries apply accordingly.
Storage period:
The log files are automatically deleted after 14 days at the latest, or altered in such a way that they can no longer be attributed to you.
Disclosure of data to third parties
The controller will only disclose your data to third parties within the meaning of Art. 4 No. 10 GDPR where
- you have given your express consent to the disclosure pursuant to Art. 6 (1) point (a) GDPR;
- the disclosure is necessary pursuant to Art. 6 (1) point (b) GDPR for the initiation or performance of a contract between you and the controller;
- the controller is legally obliged to disclose the data pursuant to Art. 6 (1) point (c) GDPR;
- the disclosure is necessary pursuant to Art. 6 (1) point (f) GDPR on the basis of the controller’s „legitimate interest“ in establishing, exercising or defending legal claims, and there is no reason to assume that you have an overriding interest worthy of protection in your data not being disclosed.
Authentication via Firebase
The controller uses an authentication system in order to enable secure authentication and to improve the sign-in experience for end users. For this purpose it uses the Firebase Authentication service from Google (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). No processing of personal data takes place.
Data processed:
- Anonymised IP addresses
Purposes of processing:
The stated data is processed for the purpose of secure authentication and of improving the user experience.
Lawfulness of processing:
The controller bases the lawfulness of this processing on Art. 6 (1) point (f) GDPR („legitimate interest“). The „legitimate interest“ arises from the controller’s wish to provide you with secure and user-friendly authentication.
Recipients of the data:
The recipient of your personal data within the meaning of Art. 4 No. 9 GDPR is the provider of the Firebase Authentication system, Google (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA).
In this context Google acts as a processor within the meaning of Art. 4 No. 8 GDPR on behalf of the controller and has been obliged, on the basis of a data processing agreement, to establish and maintain appropriate technical and organisational measures (TOMs) serving to protect your data.
Please note that Google LLC has its registered office in the USA. Although a transfer of data to the USA is not envisaged in principle, it cannot be conclusively ruled out. The anonymised IP addresses do not, however, contain any personal information and therefore cannot be traced back to identifiable persons. The statements on data transfers to third countries apply accordingly.
Storage period:
The processing of your anonymised IP address is carried out at most until you withdraw the consent you have given. Please note that data which has been anonymised may be stored for an unlimited period.
Task management via Roger
Roger offers you the option of using task management for your practice. Within this task management, data about practice staff may be processed in order to organise and track tasks within your practice efficiently.
Data processed:
- E-mail address
- First and last name
- Profession or role in the practice
- Practitioner number
- Practitioner initials
- Avatar
Purposes of processing:
The stated data is processed for the purpose of managing and tracking tasks within your practice. This processing supports the efficient completion of tasks and enables tasks to be clearly assigned to the respective staff members.
Lawfulness of processing:
The controller bases the lawfulness of this processing on Art. 6 (1) point (b) GDPR, since the processing is necessary for the performance of the contract between you and the controller which covers the use of task management.
Recipients of the data:
The recipient of your personal data within the meaning of Art. 4 No. 9 GDPR is the technical service provider engaged by the controller, Sanos (Sanos Technologies GmbH, Rykestraße 3, 10405 Berlin, Germany), which provides and administers the technical infrastructure for task management.
In this context Sanos Technologies GmbH acts as a processor within the meaning of Art. 4 No. 8 GDPR on behalf of the controller and has been obliged, on the basis of a data processing agreement, to establish and maintain appropriate technical and organisational measures (TOMs) serving to protect your data.
Storage period:
The processed data is stored by the controller only for as long as this is necessary for the performance of the contract. The data is then erased or anonymised, unless statutory retention obligations preclude erasure.
Implementation reporting via Roger
Roger provides implementation reporting which enables you to monitor the progress and completion of the tasks defined in task management as well as the implementation rates of treatment plans.
Data processed:
- E-mail address
- First and last name
- Profession or role in the practice
- Practitioner number
- Practitioner initials
- Avatar
Purposes of processing:
The stated data is processed for the purpose of reviewing the implementation rates of treatment plans and open tasks per patient and practitioner. The performance report serves to monitor the efficiency and effectiveness of treatment plans and task management and to ensure that the intended objectives are achieved.
Lawfulness of processing:
The controller bases the lawfulness of this processing on Art. 6 (1) point (b) GDPR, since the processing is necessary for the performance of the contract between you and the controller which covers the use of implementation reporting.
Storage period:
The processed data is stored by the controller only for as long as this is necessary for the performance of the contract. The data is then erased or anonymised, unless statutory retention obligations preclude erasure.
Use of Roger Chat
Roger Chat enables you to contact your patients directly via various communication channels such as e-mail, SMS and Business WhatsApp. Handling enquiries or messages via these channels requires the personal data you transmit to be processed.
Data processed:
- Communication content (e-mails, SMS messages, WhatsApp messages)
- Data about practice staff
- Name
- E-mail address
- Profession or role in the practice
- Practitioner number
- Practitioner initials
- Avatar
Purposes of processing:
The data you transmit within Roger Chat is processed exclusively for the purpose of handling and responding to enquiries or messages from your patients. The controller uses these communication channels in order to enable you to make contact quickly and easily and to ensure efficient patient service.
Lawfulness of processing:
The controller bases the lawfulness of this processing on Art. 6 (1) point (b) GDPR, since the processing is necessary for the performance of the contract between you and the controller which covers the use of Roger Chat.
Recipients of the data:
The recipients of your personal data within the meaning of Art. 4 No. 9 GDPR are the provider of the API platform for telephony services, Twilio (Twilio Inc., 375 Beale Street, Suite 300, San Francisco, CA 94105, USA), the provider of the WhatsApp Business API used, 360Dialog (360Dialog GmbH, Torstraße 61, 10119 Berlin, Germany), the provider of the e-mail program used, Google (Google Ireland Ltd., Google Building, Gordon House, 4 Barrow St., Grand Canal Dock, Dublin 4, D04 V4X7, Ireland), as well as the technical service provider engaged by the controller, Sanos (Sanos Technologies GmbH, Rykestraße 3, 10405 Berlin, Germany).
All of the aforementioned service providers act in this context as processors within the meaning of Art. 4 No. 8 GDPR on behalf of the controller and have been obliged, on the basis of a data processing agreement, to establish and maintain appropriate technical and organisational measures (TOMs) serving to protect your data.
Please note in this context that Twilio Inc. and the parent company of Google Ireland Ltd. have their registered offices in the USA. Although a transfer of data to the USA is not envisaged in principle, it cannot be conclusively ruled out. The statements on data transfers to third countries apply accordingly.
Storage period:
The processed data is stored by the controller only for as long as this is necessary to achieve the purposes pursued with this processing. Once the communication has been concluded, the data is erased, unless statutory retention obligations preclude erasure.
Your digital signature, Yousign
Roger offers you the option of sending your patients cost estimates and other treatment-relevant documents, in particular supplementary agreements, in digital form. Patients can view these documents and confirm and sign agreements digitally. Once the signature process has been completed by the patient, the signed documents are transferred back into your practice management software (PMS).
Data processed:
- Signed document (for example cost estimate, supplementary agreement)
- IP address (within the signature process)
- Date and time of the signature
- Data about practice staff
- Name
- Profession or role in the practice
- Practitioner number
- Practitioner initials
- Avatar
Lawfulness of processing:
The controller bases the lawfulness of this processing on Art. 6 (1) point (b) GDPR, since the processing is necessary for the performance of the contract between you and the controller which covers the use of Yousign.
Recipients of the data:
The recipients of your personal data within the meaning of Art. 4 No. 9 GDPR are the provider of the signature service Yousign (Yousign, WeWork Atrium Tower, Eichhornstraße 3, 10785 Berlin, Germany), as well as the technical service provider engaged by the controller, Sanos (Sanos Technologies GmbH, Rykestraße 3, 10405 Berlin, Germany).
All of the aforementioned service providers act in this context as processors within the meaning of Art. 4 No. 8 GDPR on behalf of the controller and have been obliged, on the basis of a data processing agreement, to establish and maintain appropriate technical and organisational measures (TOMs) serving to protect your data.
Storage period:
The processed data is stored by the controller only for as long as this is necessary to achieve the purposes pursued with this processing. Once the communication has been concluded, the data is erased, unless statutory retention obligations preclude erasure.
Contacting the controller
You have the option of contacting the controller from within the platform (for example by e-mail). Handling your enquiry requires the controller to process the personal data you transmit as part of the enquiry.
Data processed:
- First name, last name
- E-mail address
- Telephone number
- Content of your enquiry
Purposes of processing:
The data you transmit when making contact is processed by the controller exclusively for the purpose of handling and responding to your enquiry. Please note that complaints may be used by the controller in anonymised form as part of quality assurance in order to assess the quality and safety of the service.
Lawfulness of processing:
The controller bases the lawfulness of this processing on Art. 6 (1) point (f) GDPR („legitimate interest“) or on Art. 6 (1) point (b) GDPR, where you make contact in the context of the initiation or performance of a contract. The „legitimate interest“ arises from the controller’s wish to answer your enquiry comprehensively and in a targeted manner and to resolve any problems with the services offered as quickly as possible.
Recipients of the data:
The recipients of your personal data within the meaning of Art. 4 No. 9 GDPR are the hosting provider of the platform and of the e-mail program used, Google (Google Ireland Ltd., Google Building, Gordon House, 4 Barrow St., Grand Canal Dock, Dublin 4, D04 V4X7, Ireland), as well as the technical service provider engaged by the controller, Sanos (Sanos Technologies GmbH, Rykestraße 3, 10405 Berlin, Germany).
All of the aforementioned service providers act in this context as processors within the meaning of Art. 4 No. 8 GDPR on behalf of the controller and have been obliged, on the basis of a data processing agreement, to establish and maintain appropriate technical and organisational measures (TOMs) serving to protect your data.
Please note in this context that the parent company of Google Ireland Ltd. has its registered office in the USA. Although a transfer of data to the USA is not envisaged in principle, it cannot be conclusively ruled out. The statements on data transfers to third countries apply accordingly.
Storage period:
The processed data is stored by the controller only for as long as this is necessary to handle and respond to your enquiry. The data is then erased by the controller, unless statutory retention obligations preclude erasure.
Data processing by Sanos Technologies GmbH
The controller engages Sanos Technologies GmbH to provide support with data processing and in particular with the administration of treatment plans and the handling of billing. Sanos Technologies acts here as a technical service provider on behalf of Sanos Group AG and supports the collection, storage and processing of the necessary data.
Data processed:
- Master personal data of practice staff
- Contact data
- Billing data
- Communication data
- Technical usage data
Purposes of processing:
The support with data processing provided by Sanos Technologies GmbH pursues several objectives. It serves to ensure the comprehensive documentation and coordination of treatment plans as well as the agreement of planned procedures with patients. It also enables the efficient handling of billing processes between you and your patients. In addition, the processing supports the functionality and optimisation of the Roger platform, including technical troubleshooting and adaptation to user requirements.
Lawfulness of processing:
The controller bases the lawfulness of this processing on Art. 6 (1) point (a) GDPR where your consent has been given, and on Art. 6 (1) point (b) GDPR where the processing is necessary for the performance of the contract between you and us. You give your consent during the registration process by ticking the checkbox provided for that purpose.
Recipients of the data:
The recipient of your personal data within the meaning of Art. 4 No. 9 GDPR is the technical service provider engaged by the controller, Sanos (Sanos Technologies GmbH, Münzstrasse 21, 10178 Berlin, Germany). In this context Sanos Technologies GmbH acts as a processor within the meaning of Art. 4 No. 8 GDPR on behalf of the controller and has been obliged, on the basis of a data processing agreement, to establish and maintain appropriate technical and organisational measures (TOMs) serving to protect your data.
Storage period:
The processed data is stored by the controller only for as long as this is necessary to achieve the purpose pursued with this processing activity. The data is then erased by the controller, unless statutory retention obligations preclude erasure.
Technical analysis via Sentry
In order to maintain the reliable functionality of Roger, the operator must continuously monitor performance. This monitoring is essential in order to identify errors quickly and to remedy them without delay. Personal data is processed as part of this monitoring.
Data processed:
- IP address
- Information about the device used
- Error codes
Purposes of processing:
The aforementioned data is required in order to detect and remedy errors immediately. This ensures the technical stability of the platform and the reliable availability of Roger.
Legal basis:
The controller bases the lawfulness of this processing on Art. 6 (1) point (f) GDPR (legitimate interest). This interest lies in the fact that the operator wishes to ensure a reliable and secure experience when using Roger. There are no overriding interests opposing this processing, since the method used corresponds to the latest technical standards and takes strict security precautions into account.
Recipients:
The recipient of your personal data within the meaning of Art. 4 No. 9 GDPR is the Sentry service (Functional Software Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA). In this context the provider of Sentry acts as a processor on behalf of the controller and has been obliged by the controller, on the basis of a data processing agreement, to establish and maintain appropriate technical and organisational measures (TOMs) serving to protect your data.
Please note in this context that Functional Software Inc. has its registered office in the USA. A transfer of data to the USA is not envisaged in principle, but it cannot be conclusively ruled out. The statements on data transfers to third countries apply accordingly.
Storage period:
The data processed in connection with the use of Sentry remains stored at most until the purpose of the processing ceases to apply or until an effective objection to this processing is raised.
Use of locally hosted Google Web Fonts
In order to improve the presentation of the platform, the controller uses locally hosted web fonts from Google (Google Web Fonts). In order to display these fonts, the browser you are using must send your data to the hosting provider on whose servers Roger is hosted. This includes, among other things, personal data.
Data processed:
- IP address
- Browser type/version
- Operating system of the device
- Website from which the request originates (known as the referrer URL)
- Content of the request (specific page of the platform)
- Date and time of the request
- Time zone
- Access status/HTTP status code
- Amount of data transferred
Purposes of processing:
Processing the aforementioned data enables the controller, in conjunction with the use of the locally hosted Google Web Fonts, to display the content of the platform consistently in different browsers and on different devices.
Legal basis for processing:
The controller bases the lawfulness of this processing on Art. 6 (1) point (f) GDPR. The controller bases the „legitimate interest“ required for this on its wish to offer you a secure and trouble-free experience when using Roger.
Recipients of the data:
The recipient of your personal data within the meaning of Art. 4 No. 9 GDPR is the platform’s hosting provider, on whose servers it is operated, Google (Google Ireland Ltd., Google Building, Gordon House, 4 Barrow St., Grand Canal Dock, Dublin 4, D04 V4X7, Ireland).
In this context Google acts as a processor within the meaning of Art. 4 No. 8 GDPR on behalf of the controller and has been obliged, on the basis of a data processing agreement, to establish and maintain appropriate technical and organisational measures (TOMs) serving to protect your data.
Please note in this context that the parent company of Google Ireland Ltd. has its registered office in the USA. Although a transfer of data to the USA is not envisaged in principle, it cannot be conclusively ruled out. The statements on data transfers to third countries apply accordingly.
Storage period:
The stored data is erased immediately after you have finished accessing Roger.
Embedding of third-party content
Third-party content such as videos or graphics may also be embedded within the platform. Embedding this content requires the providers of that content (third-party providers) to receive your IP address, since the content could otherwise not be displayed within the platform.
The controller endeavours to use only third-party content whose providers use your IP address exclusively for the purpose of delivering the content. However, the controller has no influence over whether third-party providers process your IP address for further purposes, such as statistical analysis. Where the controller becomes aware of such practices, you will be informed within this privacy policy.
Updates to this privacy policy
The controller reserves the right to update this privacy policy with effect for the future in order to respond appropriately to changes in legislation, changes in case law or changes in economic circumstances. Your rights as a data subject within the meaning of the GDPR will never be restricted by an amendment to this privacy policy.