Data protection
Data protection
Data protection
General Information on Data Processing
This privacy policy describes the collection and use of personal data in connection with the use of our website https://kumihealth.de ("Website") in accordance with the requirements of the General Data Protection Regulation ("GDPR"). Processing activities not covered by this privacy policy may be supplemented by additional privacy policies, which should be observed separately.
Controller
The controller within the meaning of the GDPR is
Kumi Health GmbH ("Kumi"/”we”/“us“)
Lippmannstraße 8a
22769 Hamburg
Germany
Data Protection Officer
We have appointed an external data protection officer through Simpliant. Simpliant advises us as an external data protection officer and in the implementation and maintenance of our data protection management system. More information about Simpliant can be found at http://www.simpliant.eu.
You can reach our appointed data protection officer by e-mail at datenschutz@kumihealth.de.
Rights of Data Subjects and Supervisory Authority
You can exercise the following rights:
Right to access information about your data stored by us and its processing (Art. 15 GDPR),
Right to rectification of incorrect personal data (Art. 16 GDPR),
Right to erasure of your data stored by us (Art. 17 GDPR),
Right to restriction of data processing if we are not yet allowed to delete your data due to legal obligations (Art. 18 GDPR),
Right to data portability if you have consented to the data processing or have concluded a contract with us (Art. 20 GDPR),
Right to object to the processing of your data by us (Art. 21 GDPR)
To exercise your rights, you can contact us by e-mail at datenschutz@kumihealth.de .
For identification purposes, we ask for the following information:
First and last name
E-mail address
In individual cases, further information may be required for unique identification. The processing of your request and the identification of your person is carried out on the basis of Art. 6 para. 1 lit. c GDPR.
You can submit a complaint to a supervisory authority at any time pursuant to Art. 77 GDPR in conjunction with Section 19 of the German Federal Data Protection Act ("BDSG"), e.g., to the competent supervisory authority of the federal state in which you reside or to the authority responsible for us.
Processing of Data, Purpose and Legal Bases
We process your personal data in accordance with the provisions of the GDPR and the BDSG.
The legal basis for all our processing activities is based on Art. 6 para. 1 GDPR. Further information can be found in the description of the individual processing operations.
Storage Period
We take all reasonable steps to ensure that your personal data is only processed for the period necessary for the respective purpose of processing. If the storage period is not specified further below, your personal data will be deleted or blocked as soon as the purpose or legal basis for storage no longer applies. Personal data will not be deleted if storage is required by law (e.g. Section 257 of the German Commercial Code (HGB), Section 147 of the German Fiscal Code (AO)). Furthermore, we may retain your personal data until the expiry of the statutory limitation periods (usually 3 years; in individual cases, however, also up to 10 years or longer), provided this is necessary for the assertion, exercise or defense of legal claims.
Data Security
In order to protect the security of your data during transmission, we use technical and organizational security measures, in particular the encryption of our website, to prevent unauthorized access by third parties. Encryption via HTTPS is preset. Our security measures are continuously improved and adapted in line with technological developments.
Transfer to Service Providers
We use service providers to provide our offers. These service providers act only on our instructions and are contractually obligated to comply with the provisions of Art. 28 GDPR. Unless otherwise specified below, your data will not be transferred to a third country outside the European Union ("EU"). Your personal data will only be transferred to third countries if the requirements of Art. 44 - 49 GDPR are met, in particular standard contractual clauses, binding corporate rules or adequacy decisions of the EU Commission are in place.
No Obligation to Provide Data/No Profiling
There is no legal or contractual obligation to provide us with data. However, some services can only be provided if the required data is provided by you. Your personal data will not be used for automated individual decision-making, including profiling.
Website
Our website offers various areas with different functionalities for visitors, which are described in more detail below.
Server Logs
Type and Purpose of Data Processing:
When you access our website, information of a general nature is automatically collected. This information, referred to as server log files, includes:
IP address
Name of the access provider
Browser type, version of the browser software and browser language
Operating system
Date and time of access
Content of the access
Amount of data transferred
Access status (successful transfer/error)
Website(s) from which access was redirected
Websites visited
Processing is carried out for the following purposes:
Ensuring a trouble-free connection to the website
Ensuring smooth use of our website
Evaluation of system security and stability
Legal Basis:
The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR based on our legitimate interest in hosting the website and improving and monitoring the security, stability, and functionality of the website.
Recipient:
The recipient of the data is a technical service provider responsible for the operation and maintenance of our website. As a processor, the service provider is obliged to process the data only in accordance with our instructions.
Retention Period:
Server log files regarding server accesses are deleted after 14 days, and server log files regarding error messages are deleted after 7 days.
Consent Management
Type and Purpose of Processing:
Our website uses cookies for various processing activities for which your consent is required. To obtain and save such consent, we use a so-called "cookie banner". In this context, a cookie – a small text file – is set on your terminal device to register your choice/consent. For this purpose, we process your IP address, among other things.
Legal Basis:
The processing is carried out based on our legitimate interests in documenting compliance with the provisions of the GDPR under Art. 6 para. 1 lit. f. GDPR.
Further information can be found under the section "Cookies".
Newsletter Subscription and Newsletter Analysis
Type and Purpose of Processing:
If you would like to receive the newsletter offered on the website, we require an e-mail address from you as well as information that allows us to verify that you are the owner of the specified e-mail address and agree to receive the newsletter.
As part of the newsletter, we can also see whether a newsletter message has been opened and which links, if any, were clicked. In this way, we can determine, among other things, which links were clicked particularly often. We can also detect whether certain previously defined actions were carried out after opening/clicking (conversion rate). For example, we can see whether you visited a website after clicking on the newsletter. Furthermore, we can categorize the newsletter recipients based on various categories. In this way, the newsletters can be better adapted to the respective target groups.
Legal Basis:
The processing of the data entered into the newsletter subscription form is based solely on your consent (Art. 6 para. 1 lit. a GDPR).
Data processing for analysis purposes is also based on your consent (Art. 6 para. 1 lit. a GDPR).
You can withdraw your consent at any time, for example via the "Unsubscribe" link in the newsletter. The lawfulness of the data processing operations already carried out remains unaffected by the withdrawal.
If you do not want an analysis of your click behavior in the context of the newsletter, you can reject this. For this purpose, we provide a corresponding link in every newsletter message.
Recipient:
This website uses Evalanche to send newsletters. The provider is SC-NETWORKS GmbH, Enzianstr. 2, 82319 Starnberg, Germany. Evalanche is a service with which, among other things, the dispatch of newsletters can be organized and analyzed.
Retention Period:
The data you have stored with us for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted after you unsubscribe from the newsletter. Data stored by us for other purposes (e.g. e-mail addresses for the member area) remain unaffected by this.
Contacting Us
Type and Purpose of Processing:
In order to provide you with the best possible support when using our offers, we offer you the opportunity to contact us by e-mail.
Legal Basis:
The data is processed for the performance of pre-contractual measures (Art. 6 para. 1 lit. b. GDPR). It is also carried out to safeguard our legitimate interests under Art. 6 para. 1 lit. f. GDPR in efficient communication with interested parties or customers.
Recipient:
The recipients of the data are processors. As processors, the service providers are obliged to process the data only in accordance with our instructions.
Appointment Scheduling / Booking a Demo
Type and Purpose of Data Processing:
We offer the possibility to schedule appointments with our consulting team, in particular to book a demo for our product. In order to schedule an appointment, we must process your name, your e-mail address, and other data provided by you. The appointment will subsequently be conducted as a video call. In doing so, we use an AI-supported tool to transcribe our conversation.
Legal Basis:
The processing of data is carried out solely on the basis of our legitimate interest in offering efficient communication channels to our customers or interested parties (Art. 6 para. 1 lit. f. GDPR), or on the basis of initiating a business relationship or communication within the framework of an existing business relationship (legal basis Art. 6 para. 1 lit. b. GDPR).
Recipient:
Recipients of the data are various software providers for appointment scheduling, video telephony, and AI-supported transcription. We have concluded data processing agreements with the service providers. As processors, the service providers are obliged to process the data only in accordance with our instructions.
Transfer to Third Countries:
The data we process in connection with appointment scheduling may be transferred to the USA. For transfer to the USA, there is an adequacy decision of the EU Commission under the EU-U.S. Data Privacy Framework. The data processing agreement with the service provider also contains standard contractual clauses approved by the EU Commission.
Web Fonts
Type and Purpose of Data Processing:
For a uniform and optimized display of fonts on our website, we use web fonts provided as part of our website hosting. When accessing our website, the font files are loaded via a Content Delivery Network (CDN) of the hosting provider. In the process, technical information – in particular your IP address, the accessed URL, and the date and time of access – is processed to deliver the fonts.
Legal Basis:
The integration of web fonts takes place within the framework of the uniform purpose of providing our website in a secure, high-performance, and graphically appealing manner. The legal basis is our legitimate interest in a user-friendly and technically optimized website pursuant to Art. 6 para. 1 lit. f GDPR.
Recipient:
The recipient of the data is a technical service provider who processes the data on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Transfer to Third Countries:
Any data transfers to third countries take place on the basis of appropriate safeguards (e.g. standard contractual clauses).
Applications
Type and Purpose of Data Processing:
Through our website, we offer you the opportunity to apply for jobs at Kumi. For this purpose, we use a separate portal of a service provider and provide our applicants with a separate privacy policy. This is available at the following link.
Website Analysis
Type and Purpose of Data Processing:
This website uses cookie-based technology that helps us better understand how the website is used. We do this by compiling reports on website activity that do not identify specific individuals. Analytics cookies process your IP address and data on user behavior on our website (e.g., which pages were visited and which buttons were clicked) for this purpose.
Legal Basis:
The processing is carried out with your consent in accordance with Art. 6 para. 1 lit. a GDPR.
Further information can be found under the section "Cookies".
Personalized Advertising
Type and Purpose of Data Processing:
We use cookie-based technologies that help us deliver more effective and personalized advertising. This allows us to target visitors of our online offering as a target group for displaying ads (so-called "targeted advertising"). Furthermore, we can track the effectiveness of our online advertising by seeing whether users were redirected to our website after clicking on such an advertisement (so-called "conversion tracking"). We may also use service providers to identify users who have visited our website as potential customers and recipients of advertising (so-called "retargeting").
Legal Basis:
The processing is carried out with your consent in accordance with Art. 6 para. 1 lit. a GDPR.
Further information can be found under the section "Cookies".
Cookies
Our website uses so-called cookies. Cookies do not cause any damage to your device and do not contain viruses. Cookies serve to make our offer more user-friendly, effective and secure. Cookies are small text files that are stored on your device and in your browser.
Most of the cookies we use are so-called session cookies. These cookies are automatically deleted at the end of your session. Session cookies are used to assign consecutive page views to individual users accessing our website at the same time. Other cookies are stored on your device until you delete them. These cookies enable us to recognize your browser on your next visit.
Insofar as personal data is processed and the cookies are not technically necessary to display our website, processing is based on Art. 6 para. 1 lit. a. GDPR.
Information on cookies used and options for managing your consent can be found in our Cookie Policy.
Data Processing on Our Social Media Pages
We operate pages on the following social media channels:
Facebook by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (Meta), see under: https://www.facebook.com/policy.php
Instagram by Meta, see under: http://instagram.com/about/legal/privacy/
X by X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA and for EU/EFTA/UK Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, see under: https://x.com/de/privacy
LinkedIn by LinkedIn Corporation, Legal Department - Privacy, 1000 W. Maude Ave, Sunnyvale, CA 94085, USA or LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, see under: https://www.linkedin.com/legal/privacy-policy
Xing by New Work SE, Dammtorstraße 30., 20354 Hamburg, Germany, see also: https://privacy.xing.com/de/datenschutzerklaerung
YouTube by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4., Ireland, see under: https://policies.google.com/privacy
When you visit our social media pages, data is processed both by us and by the respective social media provider as controller.
The respective social media provider assumes the obligations under data protection law towards you as a user, such as providing information about data processing, and is the contact partner for your rights. This arises from the fact that such a provider has direct access to the relevant information on the social media page and the processing of your data.
When using Facebook, Instagram, X, LinkedIn, or YouTube, data may also be processed outside the EU.
Data Processing and Legal Basis:
On our social media pages, we can communicate with you and provide you with interesting information. Through your comments, shared images, messages, and reactions, we may receive further data from you, which we process to communicate with you. If you use social media on multiple devices, a cross-device evaluation of the data may occur. Furthermore, the providers of social media pages may also use cookies and tracking technologies to analyze and improve their services.
Data processing is carried out with your consent or for the purpose of responding to your inquiry (Art. 6 para. 1 lit. a, b GDPR) or based on the legitimate interest in improving services and public relations (Art. 6 para. 1 lit. f GDPR).
Changes to the Privacy Policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements and our current offers.
General Information on Data Processing
This privacy policy describes the collection and use of personal data in connection with the use of our website https://kumihealth.de (“Website”) in accordance with the provisions of the General Data Protection Regulation (“GDPR”). Processing activities not covered by this privacy policy may be supplemented by additional privacy policies, which should be observed separately.
Controller
The controller within the meaning of the GDPR is
Kumi Health GmbH ("Kumi"/”we”/“us“)
Lippmannstraße 8a
22769 Hamburg
Germany
Data Protection Officer
We have appointed an external Data Protection Officer through Simpliant. Simpliant advises us as an external Data Protection Officer and in the implementation and maintenance of our data protection management system. You can find more information about Simpliant at http://www.simpliant.eu.
You can reach our appointed Data Protection Officer by email at datenschutz@kumihealth.de.
Data Subject Rights and Supervisory Authority
You can exercise the following rights:
Right to information about your data stored by us and its processing (Art. 15 GDPR),
Right to rectification of incorrect personal data (Art. 16 GDPR),
Right to erasure of your data stored by us (Art. 17 GDPR),
Right to restriction of data processing if we are not yet allowed to delete your data due to legal obligations (Art. 18 GDPR),
Right to data portability if you have consented to the data processing or have entered into a contract with us (Art. 20 GDPR),
Right to object to the processing of your data by us (Art. 21 GDPR)
To exercise your rights, you can contact us by email at datenschutz@kumihealth.de.
For identification purposes, we ask for the following information:
First and last name
Email address
In individual cases, further information may be required for unambiguous identification. The processing of your application and the identification of your person is carried out on the basis of Art. 6 Para. 1 lit. c GDPR.
You can lodge a complaint with a supervisory authority at any time in accordance with Art. 77 GDPR in conjunction with § 19 of the German Federal Data Protection Act („BDSG“), e.g. with the competent supervisory authority of the federal state in which you reside or with the authority competent for us.
Processing of Data, Purpose and Legal Bases
We process your personal data in accordance with the provisions of the GDPR and the BDSG.
The legal basis for all of our processing activities is Art. 6 Para. 1 GDPR. You will find further information within the description of the individual processing operations.
Retention Period
We take all reasonable steps to ensure that your personal data is only processed for the period necessary for the respective purpose of the processing. If the retention period is not specified further below, your personal data will be deleted or blocked as soon as the purpose or legal basis for retention ceases to apply. Personal data will not be deleted if retention is required by law (e.g. § 257 HGB, 147 AO). Furthermore, we may retain your personal data until the expiry of the statutory limitation periods (usually 3 years; in individual cases, however, also up to 10 years or longer) if this is necessary for the establishment, exercise, or defense of legal claims.
Data Security
In order to protect the security of your data during transmission, we use technical and organizational security measures, in particular the encryption of our website, to prevent unauthorized access by third parties. Encryption via HTTPS is pre-configured. Our security measures are continuously improved and adapted in line with technological developments.
Transfer to Service Providers
We use service providers to provide our offers. These service providers act only on our instructions and are contractually obligated to comply with the provisions of Art. 28 GDPR. Unless otherwise specified below, your data will not be transferred to a third country outside the European Union (“EU”). Your personal data will only be transferred to third countries if the requirements of Art. 44 - 49 GDPR are met, in particular standard contractual clauses, binding corporate rules, or adequacy decisions of the EU Commission are in place.
No Obligation to Provide Data/No Profiling
There is no legal or contractual obligation to provide us with data. However, some services can only be provided if the required data is provided by you. Your personal data will not be used for automated individual decision-making, including profiling.
Website
Our website offers various areas with different functionalities for visitors, which are described in more detail below.
Server Logs
Type and Purpose of Data Processing:
When you access our website, information of a general nature is automatically recorded. This information, referred to as server log files, includes:
IP address
Name of the access provider
Browser type, version of the browser software, and browser language
Operating system
Date and time of access
Content of the access
Amount of data transferred
Access status (successful transfer/error)
Website(s) from which the access was redirected
Websites visited
Processing is carried out for the following purposes:
Ensuring a trouble-free connection to the website
Ensuring smooth use of our website
Evaluating system security and stability
Legal Basis:
The processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in hosting the website and in improving and monitoring the security, stability, and functionality of the website.
Recipient:
The recipient of the data is a technical service provider responsible for the operation and maintenance of our website. As a processor, the service provider is obligated to process the data only in accordance with our instructions.
Retention Period:
Server log files regarding server access are deleted after 14 days, and server log files regarding error messages are deleted after 7 days.
Consent Management
Type and Purpose of Processing:
Our website uses cookies for various processing activities for which your consent is required. To obtain such consent and to be able to store it, we use a so-called "cookie banner". As part of this, a cookie – a small text file – is set on your terminal device to register your selection/consent. For this purpose, we process, among other things, your IP address.
Legal Basis:
Processing is carried out based on our legitimate interests in documenting compliance with the provisions of Art. 6 Para. 1 lit. f. GDPR.
For further information, please refer to the section "Cookies".
Newsletter Subscription and Newsletter Analysis
Type and Purpose of Processing:
If you wish to receive the newsletter offered on the website, we require an email address from you as well as information that allows us to verify that you are the owner of the email address provided and agree to receive the newsletter.
Within the scope of the newsletter, we can also see whether a newsletter message was opened and which links, if any, were clicked. In this way, we can determine, among other things, which links were clicked particularly often. We can also detect if certain predefined actions were performed after opening/clicking (conversion rate). For example, we can see if you visited a website after clicking on the newsletter. Furthermore, we can categorize newsletter recipients based on various categories. This allows the newsletters to be better adapted to the respective target groups.
Legal Basis:
The processing of the data entered into the newsletter subscription form takes place exclusively on the basis of your consent (Art. 6 Para. 1 lit. a GDPR).
Data processing for analysis purposes is also based on your consent (Art. 6 Para. 1 lit. a GDPR).
You can withdraw your consent at any time, for example via the "unsubscribe" link in the newsletter. The lawfulness of the data processing operations that have already taken place remains unaffected by the withdrawal.
If you do not want an analysis of your click behavior within the newsletter, you can object to this. For this purpose, we provide a corresponding link in every newsletter message.
Recipient:
This website uses Evalanche to send newsletters. The provider is SC-NETWORKS GmbH, Enzianstr. 2, 82319 Starnberg, Germany. Evalanche is a service that can be used, among other things, to organize and analyze the sending of newsletters.
Retention Period:
The data you deposit with us for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted after you cancel the subscription. Data stored by us for other purposes (e.g. email addresses for the member area) remain unaffected by this.
Contacting Us
Type and Purpose of Processing:
To provide you with the best possible support in connection with the use of our services, we offer you the option to contact us by email.
Legal Basis:
The data is processed for the implementation of pre-contractual measures (Art. 6 Para. 1 lit. b. GDPR). Furthermore, it is carried out to safeguard our legitimate interests Art. 6 Para. 1 lit. f. GDPR in efficient communication with interested parties or customers.
Recipient:
The recipients of the data are processors. As processors, the service providers are obligated to process the data only in accordance with our instructions.
Scheduling / Booking a Demo
Type and Purpose of Data Processing:
We offer the possibility to schedule appointments with our consulting team, in particular, to book a demo for our product. In order to schedule an appointment, we must process your name, your email address, and other data provided by you. The appointment is subsequently conducted as a video call. In doing so, we use an AI-supported tool to transcribe our conversation.
Legal Basis:
The processing of data is carried out exclusively on the basis of our legitimate interest in offering our customers and interested parties efficient communication channels (Art. 6 Para. 1 lit. f. GDPR), or on the basis of initiating a business relationship or communication within the scope of an existing business relationship (legal basis Art. 6 Para. 1 lit. b. GDPR).
Recipient:
Recipients of the data are various software providers for appointment scheduling, video calls, as well as AI-supported transcription. We have concluded data processing agreements with the service providers. As processors, the service providers are obligated to process the data only in accordance with our instructions.
Transfer to Third Countries:
The data we process as part of appointment scheduling may be transferred to the USA. For transfers to the USA, there is an adequacy decision by the EU Commission under the EU-U.S. Data Privacy Framework. The data processing agreement with the service provider also contains standard contractual clauses approved by the EU Commission.
Web Fonts
Type and Purpose of Data Processing:
For the uniform and optimized display of fonts on our website, we use web fonts provided as part of our website hosting. When our website is accessed, the font files are loaded via a Content Delivery Network (CDN) of the hosting provider. In the process, technical information – in particular your IP address, the URL accessed, and the date and time of access – is processed to deliver the fonts.
Legal Basis:
The integration of web fonts takes place within the scope of the uniform purpose of providing our website in a secure, high-performance, and graphically appealing manner. The legal basis is our legitimate interest in a user-friendly and technically optimized website in accordance with Art. 6 Para. 1 lit. f GDPR.
Recipient:
The recipient of the data is a technical service provider who processes the data on the basis of a data processing agreement in accordance with Art. 28 GDPR.
Transfer to Third Countries:
Any data transfers to third countries take place on the basis of adequate safeguards (e.g. standard contractual clauses).
Applications
Type and Purpose of Data Processing:
Through our website, we offer you the opportunity to apply for positions at Kumi. For this purpose, we use a separate portal of a service provider and provide our applicants with a separate privacy policy. This is available at the following link.
Website Analysis
Type and Purpose of Data Processing:
This website uses cookie-based technology that helps us better understand how the website is used. We do this by compiling reports on website activity that do not identify specific individuals. Analytical cookies process your IP address and user behavior data on our website for this purpose (e.g., which pages were visited and which buttons were clicked).
Legal Basis:
Processing is carried out with your consent in accordance with Art. 6 Para. 1 lit. a GDPR.
For further information, please refer to the section "Cookies".
Personalized Advertising
Type and Purpose of Data Processing:
We use cookie-based technologies to help us deliver more effective and personalized advertising. This allows us to define visitors of our online offering as a target group for the display of advertisements (so-called "targeted advertising"). Furthermore, we can track the effectiveness of our online advertisements by seeing whether users were redirected to our website after clicking on such an advertisement (so-called "conversion tracking"). We may also use service providers to identify users who have visited our website as potential customers and recipients of advertising (so-called "retargeting").
Legal Basis:
Processing is carried out with your consent in accordance with Art. 6 Para. 1 lit. a GDPR.
For further information, please refer to the section "Cookies".
Cookies
Our website uses so-called cookies. Cookies do not harm your device and do not contain viruses. Cookies serve to make our offer more user-friendly, effective, and secure. Cookies are small text files that are stored on your terminal device and in your browser.
Most of the cookies we use are so-called session cookies. These cookies are automatically deleted after the end of your session. Session cookies are used to assign consecutive page views to individual users accessing our website at the same time. Other cookies remain stored on your device until you delete them. These cookies allow us to recognize your browser on your next visit.
Insofar as personal data is processed and the cookies are not technically necessary to display our website, the processing is based on Art. 6 Para. 1 lit. a. GDPR.
Information on cookies used and options for managing your consent can be found in our Cookie Policy.
Data Processing on our Social Media Pages
We operate pages on the following social media channels:
Facebook by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (Meta), see under: https://www.facebook.com/policy.php
Instagram by Meta, see under: http://instagram.com/about/legal/privacy/
X by X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA and for EU/EFTA/UK Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, see under: https://x.com/de/privacy
LinkedIn by LinkedIn Corporation, Legal Department - Privacy, 1000 W. Maude Ave, Sunnyvale, CA 94085, USA or LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, see under: https://www.linkedin.com/legal/privacy-policy
Xing by New Work SE, Dammtorstraße 30., 20354 Hamburg, Germany see also: https://privacy.xing.com/de/datenschutzerklaerung
YouTube by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4., Ireland, see under: https://policies.google.com/privacy
When you visit our social media pages, data is processed both by us and by the respective social media provider as controller.
The respective social media provider assumes the obligations under data protection law towards you as a user, such as providing information about data processing, and is the contact partner for your rights. This results from the fact that such a provider has direct access to the relevant information on the social media page and the processing of your data.
When using Facebook, Instagram, X, LinkedIn, or YouTube, data may also be processed outside the EU.
Data Processing and Legal Basis:
On our social media pages, we can communicate with you and provide you with interesting information. Through your comments, shared images, messages, and reactions, we may receive further data from you, which we process to communicate with you. If you use social media on multiple end devices, cross-device evaluation of the data may take place. Furthermore, the providers of social media pages may also use cookies and tracking technologies to analyze and improve their services.
Data processing takes place with your consent or for the purpose of responding to your request (Art. 6 Para. 1 lit. a, b GDPR) or based on the legitimate interest in improving services and public relations (Art. 6 Para. 1 lit. f GDPR).
Changes to the Privacy Policy
We reserve the right to adapt this privacy policy so that it always complies with the current legal requirements as well as our current offerings.
General Information on Data Processing
This privacy policy describes the collection and use of personal data in connection with the use of our website https://kumihealth.de (“Website”) in accordance with the provisions of the General Data Protection Regulation (“GDPR”). Processing activities not covered by this privacy policy may be supplemented by additional privacy policies, which should be observed separately.
Controller
The controller within the meaning of the GDPR is
Kumi Health GmbH ("Kumi"/”we”/“us“)
Lippmannstraße 8a
22769 Hamburg
Germany
Data Protection Officer
We have appointed an external Data Protection Officer through Simpliant. Simpliant advises us as an external Data Protection Officer and in the implementation and maintenance of our data protection management system. You can find more information about Simpliant at http://www.simpliant.eu.
You can reach our appointed Data Protection Officer by email at datenschutz@kumihealth.de.
Data Subject Rights and Supervisory Authority
You can exercise the following rights:
Right to information about your data stored by us and its processing (Art. 15 GDPR),
Right to rectification of incorrect personal data (Art. 16 GDPR),
Right to erasure of your data stored by us (Art. 17 GDPR),
Right to restriction of data processing if we are not yet allowed to delete your data due to legal obligations (Art. 18 GDPR),
Right to data portability if you have consented to the data processing or have entered into a contract with us (Art. 20 GDPR),
Right to object to the processing of your data by us (Art. 21 GDPR)
To exercise your rights, you can contact us by email at datenschutz@kumihealth.de.
For identification purposes, we ask for the following information:
First and last name
Email address
In individual cases, further information may be required for unambiguous identification. The processing of your application and the identification of your person is carried out on the basis of Art. 6 Para. 1 lit. c GDPR.
You can lodge a complaint with a supervisory authority at any time in accordance with Art. 77 GDPR in conjunction with § 19 of the German Federal Data Protection Act („BDSG“), e.g. with the competent supervisory authority of the federal state in which you reside or with the authority competent for us.
Processing of Data, Purpose and Legal Bases
We process your personal data in accordance with the provisions of the GDPR and the BDSG.
The legal basis for all of our processing activities is Art. 6 Para. 1 GDPR. You will find further information within the description of the individual processing operations.
Retention Period
We take all reasonable steps to ensure that your personal data is only processed for the period necessary for the respective purpose of the processing. If the retention period is not specified further below, your personal data will be deleted or blocked as soon as the purpose or legal basis for retention ceases to apply. Personal data will not be deleted if retention is required by law (e.g. § 257 HGB, 147 AO). Furthermore, we may retain your personal data until the expiry of the statutory limitation periods (usually 3 years; in individual cases, however, also up to 10 years or longer) if this is necessary for the establishment, exercise, or defense of legal claims.
Data Security
In order to protect the security of your data during transmission, we use technical and organizational security measures, in particular the encryption of our website, to prevent unauthorized access by third parties. Encryption via HTTPS is pre-configured. Our security measures are continuously improved and adapted in line with technological developments.
Transfer to Service Providers
We use service providers to provide our offers. These service providers act only on our instructions and are contractually obligated to comply with the provisions of Art. 28 GDPR. Unless otherwise specified below, your data will not be transferred to a third country outside the European Union (“EU”). Your personal data will only be transferred to third countries if the requirements of Art. 44 - 49 GDPR are met, in particular standard contractual clauses, binding corporate rules, or adequacy decisions of the EU Commission are in place.
No Obligation to Provide Data/No Profiling
There is no legal or contractual obligation to provide us with data. However, some services can only be provided if the required data is provided by you. Your personal data will not be used for automated individual decision-making, including profiling.
Website
Our website offers various areas with different functionalities for visitors, which are described in more detail below.
Server Logs
Type and Purpose of Data Processing:
When you access our website, information of a general nature is automatically recorded. This information, referred to as server log files, includes:
IP address
Name of the access provider
Browser type, version of the browser software, and browser language
Operating system
Date and time of access
Content of the access
Amount of data transferred
Access status (successful transfer/error)
Website(s) from which the access was redirected
Websites visited
Processing is carried out for the following purposes:
Ensuring a trouble-free connection to the website
Ensuring smooth use of our website
Evaluating system security and stability
Legal Basis:
The processing is carried out in accordance with Art. 6 Para. 1 lit. f GDPR based on our legitimate interest in hosting the website and in improving and monitoring the security, stability, and functionality of the website.
Recipient:
The recipient of the data is a technical service provider responsible for the operation and maintenance of our website. As a processor, the service provider is obligated to process the data only in accordance with our instructions.
Retention Period:
Server log files regarding server access are deleted after 14 days, and server log files regarding error messages are deleted after 7 days.
Consent Management
Type and Purpose of Processing:
Our website uses cookies for various processing activities for which your consent is required. To obtain such consent and to be able to store it, we use a so-called "cookie banner". As part of this, a cookie – a small text file – is set on your terminal device to register your selection/consent. For this purpose, we process, among other things, your IP address.
Legal Basis:
Processing is carried out based on our legitimate interests in documenting compliance with the provisions of Art. 6 Para. 1 lit. f. GDPR.
For further information, please refer to the section "Cookies".
Newsletter Subscription and Newsletter Analysis
Type and Purpose of Processing:
If you wish to receive the newsletter offered on the website, we require an email address from you as well as information that allows us to verify that you are the owner of the email address provided and agree to receive the newsletter.
Within the scope of the newsletter, we can also see whether a newsletter message was opened and which links, if any, were clicked. In this way, we can determine, among other things, which links were clicked particularly often. We can also detect if certain predefined actions were performed after opening/clicking (conversion rate). For example, we can see if you visited a website after clicking on the newsletter. Furthermore, we can categorize newsletter recipients based on various categories. This allows the newsletters to be better adapted to the respective target groups.
Legal Basis:
The processing of the data entered into the newsletter subscription form takes place exclusively on the basis of your consent (Art. 6 Para. 1 lit. a GDPR).
Data processing for analysis purposes is also based on your consent (Art. 6 Para. 1 lit. a GDPR).
You can withdraw your consent at any time, for example via the "unsubscribe" link in the newsletter. The lawfulness of the data processing operations that have already taken place remains unaffected by the withdrawal.
If you do not want an analysis of your click behavior within the newsletter, you can object to this. For this purpose, we provide a corresponding link in every newsletter message.
Recipient:
This website uses Evalanche to send newsletters. The provider is SC-NETWORKS GmbH, Enzianstr. 2, 82319 Starnberg, Germany. Evalanche is a service that can be used, among other things, to organize and analyze the sending of newsletters.
Retention Period:
The data you deposit with us for the purpose of receiving the newsletter will be stored by us until you unsubscribe from the newsletter and will be deleted after you cancel the subscription. Data stored by us for other purposes (e.g. email addresses for the member area) remain unaffected by this.
Contacting Us
Type and Purpose of Processing:
To provide you with the best possible support in connection with the use of our services, we offer you the option to contact us by email.
Legal Basis:
The data is processed for the implementation of pre-contractual measures (Art. 6 Para. 1 lit. b. GDPR). Furthermore, it is carried out to safeguard our legitimate interests Art. 6 Para. 1 lit. f. GDPR in efficient communication with interested parties or customers.
Recipient:
The recipients of the data are processors. As processors, the service providers are obligated to process the data only in accordance with our instructions.
Scheduling / Booking a Demo
Type and Purpose of Data Processing:
We offer the possibility to schedule appointments with our consulting team, in particular, to book a demo for our product. In order to schedule an appointment, we must process your name, your email address, and other data provided by you. The appointment is subsequently conducted as a video call. In doing so, we use an AI-supported tool to transcribe our conversation.
Legal Basis:
The processing of data is carried out exclusively on the basis of our legitimate interest in offering our customers and interested parties efficient communication channels (Art. 6 Para. 1 lit. f. GDPR), or on the basis of initiating a business relationship or communication within the scope of an existing business relationship (legal basis Art. 6 Para. 1 lit. b. GDPR).
Recipient:
Recipients of the data are various software providers for appointment scheduling, video calls, as well as AI-supported transcription. We have concluded data processing agreements with the service providers. As processors, the service providers are obligated to process the data only in accordance with our instructions.
Transfer to Third Countries:
The data we process as part of appointment scheduling may be transferred to the USA. For transfers to the USA, there is an adequacy decision by the EU Commission under the EU-U.S. Data Privacy Framework. The data processing agreement with the service provider also contains standard contractual clauses approved by the EU Commission.
Web Fonts
Type and Purpose of Data Processing:
For the uniform and optimized display of fonts on our website, we use web fonts provided as part of our website hosting. When our website is accessed, the font files are loaded via a Content Delivery Network (CDN) of the hosting provider. In the process, technical information – in particular your IP address, the URL accessed, and the date and time of access – is processed to deliver the fonts.
Legal Basis:
The integration of web fonts takes place within the scope of the uniform purpose of providing our website in a secure, high-performance, and graphically appealing manner. The legal basis is our legitimate interest in a user-friendly and technically optimized website in accordance with Art. 6 Para. 1 lit. f GDPR.
Recipient:
The recipient of the data is a technical service provider who processes the data on the basis of a data processing agreement in accordance with Art. 28 GDPR.
Transfer to Third Countries:
Any data transfers to third countries take place on the basis of adequate safeguards (e.g. standard contractual clauses).
Applications
Type and Purpose of Data Processing:
Through our website, we offer you the opportunity to apply for positions at Kumi. For this purpose, we use a separate portal of a service provider and provide our applicants with a separate privacy policy. This is available at the following link.
Website Analysis
Type and Purpose of Data Processing:
This website uses cookie-based technology that helps us better understand how the website is used. We do this by compiling reports on website activity that do not identify specific individuals. Analytical cookies process your IP address and user behavior data on our website for this purpose (e.g., which pages were visited and which buttons were clicked).
Legal Basis:
Processing is carried out with your consent in accordance with Art. 6 Para. 1 lit. a GDPR.
For further information, please refer to the section "Cookies".
Personalized Advertising
Type and Purpose of Data Processing:
We use cookie-based technologies to help us deliver more effective and personalized advertising. This allows us to define visitors of our online offering as a target group for the display of advertisements (so-called "targeted advertising"). Furthermore, we can track the effectiveness of our online advertisements by seeing whether users were redirected to our website after clicking on such an advertisement (so-called "conversion tracking"). We may also use service providers to identify users who have visited our website as potential customers and recipients of advertising (so-called "retargeting").
Legal Basis:
Processing is carried out with your consent in accordance with Art. 6 Para. 1 lit. a GDPR.
For further information, please refer to the section "Cookies".
Cookies
Our website uses so-called cookies. Cookies do not harm your device and do not contain viruses. Cookies serve to make our offer more user-friendly, effective, and secure. Cookies are small text files that are stored on your terminal device and in your browser.
Most of the cookies we use are so-called session cookies. These cookies are automatically deleted after the end of your session. Session cookies are used to assign consecutive page views to individual users accessing our website at the same time. Other cookies remain stored on your device until you delete them. These cookies allow us to recognize your browser on your next visit.
Insofar as personal data is processed and the cookies are not technically necessary to display our website, the processing is based on Art. 6 Para. 1 lit. a. GDPR.
Information on cookies used and options for managing your consent can be found in our Cookie Policy.
Data Processing on our Social Media Pages
We operate pages on the following social media channels:
Facebook by Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (Meta), see under: https://www.facebook.com/policy.php
Instagram by Meta, see under: http://instagram.com/about/legal/privacy/
X by X Corp., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA and for EU/EFTA/UK Twitter International Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, D02 AX07, Ireland, see under: https://x.com/de/privacy
LinkedIn by LinkedIn Corporation, Legal Department - Privacy, 1000 W. Maude Ave, Sunnyvale, CA 94085, USA or LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland, see under: https://www.linkedin.com/legal/privacy-policy
Xing by New Work SE, Dammtorstraße 30., 20354 Hamburg, Germany see also: https://privacy.xing.com/de/datenschutzerklaerung
YouTube by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4., Ireland, see under: https://policies.google.com/privacy
When you visit our social media pages, data is processed both by us and by the respective social media provider as controller.
The respective social media provider assumes the obligations under data protection law towards you as a user, such as providing information about data processing, and is the contact partner for your rights. This results from the fact that such a provider has direct access to the relevant information on the social media page and the processing of your data.
When using Facebook, Instagram, X, LinkedIn, or YouTube, data may also be processed outside the EU.
Data Processing and Legal Basis:
On our social media pages, we can communicate with you and provide you with interesting information. Through your comments, shared images, messages, and reactions, we may receive further data from you, which we process to communicate with you. If you use social media on multiple end devices, cross-device evaluation of the data may take place. Furthermore, the providers of social media pages may also use cookies and tracking technologies to analyze and improve their services.
Data processing takes place with your consent or for the purpose of responding to your request (Art. 6 Para. 1 lit. a, b GDPR) or based on the legitimate interest in improving services and public relations (Art. 6 Para. 1 lit. f GDPR).
Changes to the Privacy Policy
We reserve the right to adapt this privacy policy so that it always complies with the current legal requirements as well as our current offerings.