Data protection

1. General Information

With this Privacy Policy, we aim to inform you about the type, scope, and purpose of the personal data we collect, use, and process. Furthermore, this Privacy Policy explains the rights of individuals whose data is affected.

When you use this website, various personal data is collected. Personal data is information that can identify you personally (e.g., name, email address, telephone number, IP address). Some of your data is collected when you provide it to us. Other data is collected automatically by our IT systems when you visit the website. This data is mainly technical (e.g., internet browser, operating system, or the time of the page view). The collection of this technical data occurs automatically once you access our website.

The processing of personal data is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the applicable national data protection laws for the private practice Osteopathie.Kö.

We have implemented numerous technical and organizational measures to ensure the most complete protection possible of personal data processed via this website. Nevertheless, internet-based data transmissions may generally have security gaps, so absolute protection cannot be guaranteed.

This Privacy Policy is based on the terminology used by the European legislator when issuing the General Data Protection Regulation (GDPR). For easier understanding, we would like to explain some important terms in advance.

“Personal data”
Personal data refers to any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

“Data subject”
A data subject is any identified or identifiable natural person whose personal data is processed by the controller responsible for processing.

“Processing”
Processing is any operation or set of operations performed on personal data, with or without automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

“Restriction of processing”
Restriction of processing means marking stored personal data with the aim of limiting its future processing.

“Profiling”
Profiling is any form of automated processing of personal data consisting of the use of such data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

“Pseudonymization”
Pseudonymization is the processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and subject to technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable natural person.

“Controller, responsible entity, or data controller”
The controller is a natural or legal person, authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

“Processor”
A processor is a natural or legal person, authority, agency, or other body which processes personal data on behalf of the controller.

“Recipient”
A recipient is a natural or legal person, authority, agency, or another body to whom personal data is disclosed, whether a third party or not. Authorities which may receive personal data in the framework of a particular inquiry under Union or Member State law shall not, however, be regarded as recipients.

“Third party”
A third party is any natural or legal person, authority, agency, or other body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

“Consent”
Consent is any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of their personal data.

2. Information about the Controller

The controller responsible for data processing on this website is:

Ms. Anett Hörster
Private Practice Osteopathie.Kö.
Königsallee 55a
40212 Düsseldorf

Tel.: +49 (0)211 / 8 62 95 45
Fax: +49 (0)211 / 8 69 37 20
Email: info@osteopathie-koe.de

3. Data Processing on Our Website

a. Data processed
Each time our website is accessed by a data subject or an automated system, a series of general data and information is collected. These general data and information are stored in the server log files. This may include:

  1. browser types and versions used,
  2. the operating system used by the accessing system,
  3. the website from which an accessing system reaches our website (referrer),
  4. the subpages accessed via an accessing system,
  5. the date and time of access to the website,
  6. an Internet Protocol address (IP address),
  7. the internet service provider of the accessing system, and
  8. other similar data and information used for security in case of attacks on our IT systems.

This data is not processed in combination with other personal data.

b. Purposes of processing data
The data stored in log files are used to ensure the functionality of the website, optimize the website, and safeguard the security of our systems.

c. Legal basis
The legal basis for processing is Art. 6(1)(f) GDPR. The purposes stated above also represent our legitimate interests.

d. Disclosure to third parties
The personal data processed on this website is not shared with third parties.

e. Data deletion and retention period
Personal data is deleted after 7 days for security reasons (e.g., in case of hacker attacks). Further information can be found under the following link.

f. No legal or contractual requirement
The processing of data is not legally or contractually required, but it is necessary to provide you with this website in line with the purposes stated above.

4. Use of Cookies

Cookies are text files that are stored on a computer system via an internet browser.

Here you can view the cookie policy and adjust settings.

5. Rights of Data Subjects

a. Withdrawal of consent to data processing
Many data processing operations are only possible with your express consent. You may withdraw consent at any time. A simple informal message to us is sufficient. The lawfulness of data processing carried out before the withdrawal remains unaffected.

b. Right to lodge a complaint with the competent supervisory authority
In the event of GDPR violations, the data subject has the right to lodge a complaint with the relevant supervisory authority. The competent authority in matters of data protection is generally the State Data Protection Officer of the federal state in which our practice is located.

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2-4
40213 Düsseldorf

Tel.: +49 (0)211 / 384 24-0
Fax: +49 (0)211 / 384 24-10
Email: poststelle@ldi.nrw.de
Web: www.ldi.nrw.de

c. Right to access, blocking, deletion, rectification, and restriction of processing
You have the right, within the applicable legal provisions, to request information at any time, free of charge, about your stored personal data, its origin, recipients, and the purpose of processing. You also have the right to request correction, blocking, deletion, or restriction of processing of this data. You may contact us at any time for this purpose. Contact details can be found above in section 2.

d. Right to data portability
You have the right to receive data that we process automatically on the basis of your consent or in fulfillment of a contract, in a commonly used, machine-readable format, or to have it transmitted to another controller. If you request direct transfer of the data to another controller, this will be done only if technically feasible.

6. Automated Decision-Making / Profiling

We do not use automated decision-making or profiling.

7. SSL and TLS Encryption

For security reasons and to protect the transmission of confidential content, such as inquiries you send to us, this site uses SSL or TLS encryption.

You can recognize an encrypted connection by the change in the browser’s address line from “http://” to “https://” and by the lock icon in your browser line. When SSL or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.

8. Use of Email

Please note that special precautions must be taken when transmitting personal data via email. Emails must be encrypted both during transmission (transport level) and, if necessary, at the content level.

When deciding whether content encryption (e.g., end-to-end encryption using S/MIME or OpenPGP) is necessary, the sensitivity of the data and the adequacy of the measure must be considered. If highly sensitive personal data is to be transmitted, especially the special categories of personal data mentioned in Art. 9(1) GDPR (e.g., health data), end-to-end encryption is required under the guidelines of the State Data Protection Commissioner of North Rhine-Westphalia.

For this reason, we kindly ask you not to send medical data such as findings, reports, or X-rays via email. Please call us or send such data by mail or fax instead. Our contact details are listed above in section 2. In return, we will also not send such data to you via email. While our emails are encrypted at the transport level (via SSL/TLS), we currently cannot offer content-level encryption.

9. Objection to Unsolicited Emails

We hereby object to the use of the contact data published within the scope of the legal notice obligation to send unsolicited advertising and information materials. The site operators expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example through spam emails.

10. Appointed Tax Consultancy Firm

We have appointed the following company to handle all of our tax and legal matters:

LTS Steuerberatungsgesellschaft mbH
Bunsenstraße 3
32052 Herford

Tel.: +49 (0)5221 / 69 30 600
Fax: +49 (0)5221 / 69 30 690
Email: info@lts-rechtsanwaelte.com
Web: www.lts-rechtsanwaelte.com

11. Data Protection Officer

We have appointed a Data Protection Officer:

Dr. Stefan Hörster
Private Practice Osteopathie.Kö.
Königsallee 55a
40212 Düsseldorf

Tel.: +49 (0)211 / 8 62 95 45
Fax: +49 (0)211 / 8 69 37 20
Email: datenschutz@osteopathie-koe.de

Logo des Verbands der Osteopathen Deutschlands e.V. (VOD)
Logo der CRAFTA® (Craniofacial Therapy Academy)
Logo der VNS Analyse
Logo Physioenergetik
Bund Deutscher Heilpraktiker e.V. (BDH)
Logo BAO
linkedin logo

 © 2025 2025 Osteopathy Practice Kö. All rights reserved.