Privacy policy

What happens to your data
and what rights you have.

Who is responsible for your data

Helen Sange
Specialist in gynaecology and obstetrics

Goethestraße 70
10625 Berlin
030-93022004

When you visit this website

Server logs

When you open this website, your browser sends technical information to the server it’s hosted on: your IP address, the date and time, the address requested, the page you came from, and your browser and operating system. The server needs this to deliver the page to you and keeps it in log files for a short time. We don’t analyse it or combine it with other data.

The website is hosted by united-domains AG, Gautinger Straße 10, 82319 Starnberg, Germany, which keeps the logs on our behalf. The legal basis is our legitimate interest in a secure, working website (Art. 6(1)(f) GDPR).

Encryption

The website is transmitted in encrypted form (TLS, recognisable by “https://” in the address bar). This means others cannot read what passes between your browser and the server.

Cookies and your consent

We ask whether you agree to the map on the contact page in the “Privacy settings” window. It is provided by the Complianz plugin, which runs on our own server; no data is sent to its developer. Your browser stores your choice in cookies whose names begin with “cmplz_”: cmplz_functional, cmplz_marketing, cmplz_statistics and cmplz_preferences record what you have allowed, cmplz_banner-status whether the window is open, cmplz_policy_id which version of this policy you agreed to, and cmplz_consented_services individual services. The cookies contain no information about you as a person and are deleted after 365 days.

These cookies are technically necessary so that we can respect your decision and prove it (§ 25(2) no. 2 TDDDG, the German Telecommunications Digital Services Data Protection Act; Art. 6(1)(c) in conjunction with Art. 7(1) GDPR). Anything else stored on or read from your device, and any connection to another provider, only happens with your consent (§ 25(1) TDDDG, Art. 6(1)(a) GDPR). You can change or withdraw your choice at any time using the round cookie button at the bottom left of every page.

No analytics, no advertising

We don’t count visits, use analytics tools, show advertising or build profiles. The website serves its fonts itself, without connecting to Google or any other provider.

The map on the contact page (Google Maps)

On the contact page we show the way to the practice on a Google Maps map. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The map only loads once you agree – with the “Show map” button or under “External content” in the privacy settings. Until then, your browser does not connect to Google.

When the map loads, your browser fetches it directly from Google. Google receives your IP address, the address of the page the map is on, and information about your browser and device, and may set or read cookies on your device. Google may also transfer the data to Google LLC in the USA. For the USA there is an adequacy decision of the European Commission (EU-U.S. Data Privacy Framework), under which Google LLC is certified.

The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can withdraw it at any time using the cookie button at the bottom left; the map then disappears again. Below the map there is also a link that opens the address directly in Google Maps – only when you follow it do you go to Google’s website. What Google does with the data is set out in Google’s privacy policy.

Links to Doctolib and Instagram

Doctolib

You can book appointments online via Doctolib. The online booking buttons are links: only when you follow one do you reach Doctolib’s website, and only there do you share data with Doctolib. What Doctolib does with it is set out in Doctolib’s privacy notice.

Instagram

Some pages link to Instagram. No Instagram content is embedded here; only when you follow a link does your browser connect to Instagram. There, Instagram’s privacy policy applies.

When you email or call us

If you email or call us, we store what you tell us and your contact details in order to deal with your request and reply to you. If your enquiry relates to treatment, it goes into your patient record, and what is said below about treatment applies. We delete other enquiries once they’ve been dealt with and there’s no obligation to keep them. The legal basis is Art. 6(1)(b) GDPR where an appointment or treatment is concerned, otherwise our legitimate interest in replying to you (Art. 6(1)(f) GDPR).

Your data during treatment

When you’re being treated by us, we process your personal data, above all your health data: medical histories, diagnoses, proposed treatments and findings that we or other doctors collect. Other doctors or psychotherapists treating you may also send us data, for example in doctors’ letters. We need this data to treat you with due care and to fulfil our obligations under the treatment contract. Without the necessary information, careful treatment isn’t possible.

The legal basis is Art. 9(2)(h) GDPR in conjunction with § 22(1) no. 1(b) of the German Federal Data Protection Act (BDSG).

Who receives your data

We only pass your personal data on to others if the law permits it or you have given your consent.

Recipients may include, in particular: other doctors, physiotherapists and psychotherapists, Associations of Statutory Health Insurance Physicians, health insurers, the Medical Service, medical associations and private medical billing offices. Usually this is about billing for our services or clarifying medical questions and questions relating to your insurance. In individual cases, other authorised bodies may receive data.

How long we keep your data

We keep your personal data for as long as is necessary for your treatment. The law requires us to keep patient records for at least ten years after treatment ends (§ 630f(3) German Civil Code, BGB). Other regulations may require longer periods.

Your rights

For anything in this section, just send us a message – email is easiest. Access to your data is free of charge.

Access, rectification and erasure

You can find out at any time what data we hold about you, where it comes from, whom we pass it on to and why we process it. If data is incorrect, we correct it. Under certain conditions you can ask us to delete data; data we’re required to keep is deleted only once the retention period has expired.

Restriction of processing

You can ask us to only store your data and not process it in any other way. This applies while we check whether you are right to dispute the accuracy of your data. It also applies if the processing was unlawful and you want restriction instead of erasure. And it applies if we no longer need the data but you need it for legal claims, or, after an objection, as long as it hasn’t been established whose interests prevail.

If your data is restricted, we only process it with your consent, for legal claims, to protect the rights of another person or for reasons of important public interest.

Data portability

On request, we provide data that we process automatically with your consent or to perform a contract to you or to another body in a common, machine-readable format. We transfer it directly to another body where this is technically feasible.

Objection

Where we process data because we have a legitimate interest in doing so (Art. 6(1)(f) GDPR), such as the server logs, you can object on grounds relating to your particular situation. We then stop processing it unless there are compelling grounds for continuing.

Withdrawing consent

We process most data because the law provides for it. Where we ask for your consent, you can withdraw it at any time with effect for the future. Processing carried out up to that point remains lawful.

No automated decisions

We don’t make decisions about you based solely on automated processing, and we don’t create a profile of you (Art. 22 GDPR).

Complaints to a supervisory authority

If you believe we’re not processing your data lawfully, you can complain to a data protection supervisory authority, for example in the country where you live or work. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information)
Alt-Moabit 59–61, 10555 Berlin
www.datenschutz-berlin.de

This policy was last updated on 5 October 2026. This is a translation; in case of doubt, the German version applies.