Legal
Privacy Policy
Protecting your personal data is important to us. Below we inform you about how your data is processed in accordance with the General Data Protection Regulation (GDPR).
This is a convenience translation. The German version of this privacy policy (Datenschutz) is the legally binding one.
1. Privacy at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy set out below this text.
Data collection on this website
Who is responsible for the data collection on this website?
The data processing on this website is carried out by the website operator. You can find their contact details in the section “Information on the controller” in this privacy policy.
How do we collect your data?
Your data is collected, on the one hand, by you providing it to us. This may, for example, be data you enter into a form. Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system or the time the page was accessed). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some of the data is collected to ensure the error-free provision of the website. Other data can be used to analyse your user behaviour.
What rights do you have regarding your data?
You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time with effect for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority. You can contact us at any time regarding this and other questions on the subject of data protection.
2. Hosting
We host the content of our website with the following provider:
Strato
The provider is Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany (hereinafter “Strato”). When you visit our website, Strato records various log files including your IP addresses. For further information, please see Strato’s privacy policy: https://www.strato.de/datenschutz/.
Strato is used on the basis of Art. 6 (1) (f) GDPR. We have a legitimate interest in the most reliable presentation of our website possible. Insofar as corresponding consent has been requested, processing is carried out exclusively on the basis of Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG, to the extent that the consent covers the storage of cookies or access to information on the user’s device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.
3. General information and mandatory information
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.
When you use this website, various personal data is collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done.
We would like to point out that data transmission over the internet (e.g. when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.
Information on the controller
The controller responsible for data processing on this website is:
day2 GmbH i.G.
Alte Schützenwiese 1
25764 Wesselburen, Germany
Email: info@day-2.de
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).
Data protection officer
We have appointed a data protection officer for our company:
Joret Schumacher
day2 GmbH i.G.
Alte Schützenwiese 1
25764 Wesselburen, Germany
Email: info@day-2.de
Storage period
Unless a more specific storage period has been stated within this privacy policy, your personal data will remain with us until the purpose for the data processing no longer applies. If you assert a justified request for deletion or revoke consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, deletion will take place once these reasons no longer apply.
General information on the legal bases for data processing on this website
Insofar as you have consented to data processing, we process your personal data on the basis of Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR, where special categories of data pursuant to Art. 9 (1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, data processing is also carried out on the basis of Art. 49 (1) (a) GDPR. Insofar as you have consented to the storage of cookies or to access to information on your device (e.g. via device fingerprinting), data processing is additionally carried out on the basis of Section 25 (1) TDDDG. Consent can be revoked at any time. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6 (1) (b) GDPR. Furthermore, we process your data insofar as it is required to fulfil a legal obligation, on the basis of Art. 6 (1) (c) GDPR. Data processing may also be carried out on the basis of our legitimate interest pursuant to Art. 6 (1) (f) GDPR. Information on the relevant legal bases in each individual case is provided in the following paragraphs of this privacy policy.
Recipients of personal data
In the course of our business activities, we work with various external parties. In some cases, this also requires the transfer of personal data to these external parties. We only pass on personal data to external parties if this is required within the scope of the performance of a contract, if we are legally obliged to do so (e.g. transfer of data to tax authorities), if we have a legitimate interest pursuant to Art. 6 (1) (f) GDPR in the transfer, or if another legal basis permits the data transfer. When using processors, we only pass on personal data of our customers on the basis of a valid data processing agreement. In the case of joint processing, a joint processing agreement is concluded.
Revocation of your consent to data processing
Many data processing operations are only possible with your explicit consent. You can revoke consent you have already given at any time. The lawfulness of the data processing carried out up until the revocation remains unaffected by the revocation.
Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)
IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6 (1) (E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH ANY PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES TO ASSERT, EXERCISE OR DEFEND LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21 (1) GDPR).
IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION PURSUANT TO ART. 21 (2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of breaches of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work or the place of the alleged breach. The right to lodge a complaint applies without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.
Information, correction and deletion
Within the framework of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to correction or deletion of this data. You can contact us at any time regarding this and other questions on the subject of personal data.
Right to restriction of processing
You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restriction of processing exists in the following cases:
- If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the review, you have the right to request the restriction of the processing of your personal data.
- If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of deletion.
- If we no longer need your personal data, but you need it to exercise, defend or assert legal claims, you have the right to request the restriction of the processing of your personal data instead of deletion.
- If you have lodged an objection pursuant to Art. 21 (1) GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.
If you have restricted the processing of your personal data, this data may — apart from being stored — only be processed with your consent or for the assertion, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of an important public interest of the European Union or a member state.
4. Data collection on this website
Cookies
Our web pages use so-called “cookies”. Cookies are small data packages and do not cause any damage to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted after your visit ends. Permanent cookies remain stored on your device until you delete them yourself or until they are automatically deleted by your web browser.
Cookies that are necessary to carry out the electronic communication process, to provide certain functions you have requested or to optimise the website (necessary cookies) are stored on the basis of Art. 6 (1) (f) GDPR, unless another legal basis is specified. Insofar as consent to the storage of cookies and comparable recognition technologies has been requested, processing is carried out exclusively on the basis of this consent (Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG); consent can be revoked at any time.
On this website, we currently use exclusively technically necessary cookies or comparable techniques (e.g. local storage) — for example to store your consent to loading the external booking calendar. Third-party content requiring consent (in particular the Cal.com booking calendar) is only loaded after you have actively given your consent. In addition, you can restrict, deactivate or delete already set cookies at any time via your browser settings.
Enquiry by email or form
If you contact us by form or email, your details, including the contact data you provide there, will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. The contact form is sent exclusively via our own mail server operated at our host (Strato); no external form or dispatch service provider is used and no transfer to third countries takes place. We do not pass on this data without your consent. The processing of this data is carried out on the basis of Art. 6 (1) (b) GDPR, insofar as your enquiry is related to the performance of a contract or is required to carry out pre-contractual measures. In all other cases, the processing is based on our legitimate interest in the effective handling of the enquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR), which you give by submitting the form via the mandatory checkbox; consent can be revoked at any time.
5. Social media
Functions of the Instagram service are integrated into this website. These functions are offered by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When the social media element is active, a direct connection is established between your device and the Instagram server. Instagram thereby receives information about your visit to this website. If you are logged into your Instagram account, you can link the content of this website to your Instagram profile by clicking the Instagram button. This allows Instagram to associate your visit to this website with your user account. We would like to point out that, as the provider of the pages, we have no knowledge of the content of the transmitted data or its use by Instagram.
The use of this service is based on your consent pursuant to Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG. Consent can be revoked at any time.
Insofar as personal data is collected on our website with the help of the tool described here and forwarded to Facebook or Instagram, we and Meta Platforms Ireland Limited are jointly responsible for this data processing (Art. 26 GDPR). The joint responsibility is limited exclusively to the collection of the data and its transfer to Facebook or Instagram. The processing carried out by Facebook or Instagram after the transfer is not part of the joint responsibility. The obligations incumbent on us jointly have been set out in a joint processing agreement: facebook.com/legal/controller_addendum.
The transfer of data to the USA is based on the standard contractual clauses of the EU Commission. Details: facebook.com/legal/EU_data_transfer_addendum and privacycenter.instagram.com/policy. The company is certified under the “EU-US Data Privacy Framework” (DPF): dataprivacyframework.gov/participant/4452.
For more information, please see Instagram’s privacy policy: privacycenter.instagram.com/policy.
6. Newsletter
Newsletter data
If you wish to receive the newsletter offered on the website, we require an email address from you as well as your first name. We also store the time of registration and a pseudonymised (hashed) IP address in order to be able to prove consent. We use this data exclusively for sending the requested newsletter and do not pass it on to third parties. Storage takes place in our own database hosted at Strato (no external newsletter service provider).
Registration takes place using the so-called double opt-in procedure: after registration, you will receive an email in which you must confirm your subscription to the newsletter. You will only be added to the distribution list after your confirmation. The processing of the data entered into the newsletter registration form is carried out exclusively on the basis of your consent (Art. 6 (1) (a) GDPR).
You can revoke your consent to the storage of the data, the email address and its use for sending the newsletter at any time, for example via the unsubscribe link in every newsletter email. The lawfulness of the data processing operations already carried out remains unaffected by the revocation. After you unsubscribe, the data will be deleted from the distribution list.
Success measurement (open and click rates)
Our newsletters contain technologies for statistical success measurement. For this purpose, a small, invisible image element (a so-called tracking pixel) is embedded in the email, which is retrieved from our server when the message is opened; this allows us to detect whether and when a newsletter email was opened. We also record whether the links contained in the email were clicked by routing these links via our server. The time of the retrieval, the relevant newsletter campaign and the clicked link are collected — in each case in relation to your recipient address.
This analysis serves exclusively to improve our newsletters and to align them with the interests of our recipients. The processing is carried out on the basis of your consent (Art. 6 (1) (a) GDPR), which you give when registering for the newsletter. You can object to this success measurement at any time by unsubscribing from the newsletter (unsubscribe link in every email). An isolated cancellation of only the success measurement is not possible; in this case, the newsletter subscription must be cancelled as a whole.
7. Online appointment booking (Cal.com)
For booking treatment appointments, we use the Cal.com service. The provider is Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA (hereinafter “Cal.com”). The booking function is provided via the EU instance of Cal.com (app.cal.eu); the data arising in the course of the appointment booking is processed on servers within the European Union.
The booking calendar is only loaded on our website after you have actively given your consent (so-called two-click solution). Before your consent, no connection to the Cal.com servers is established. As soon as you load the calendar, a connection to Cal.com is established, whereby, among other things, your IP address and technical information about your device are transmitted to Cal.com. When you book an appointment, Cal.com processes the data you provide (e.g. name, email address, desired appointment) on our behalf in order to carry out the appointment arrangement.
The use of Cal.com is based on your consent pursuant to Art. 6 (1) (a) GDPR and Section 25 (1) TDDDG, insofar as the consent covers access to information on your device or its storage. The processing of the data required to carry out the appointment booking is also carried out on the basis of Art. 6 (1) (b) GDPR (contract or pre-contractual measures). Your consent can be revoked at any time with effect for the future.
Insofar as personal data is processed on our behalf by Cal.com, we have concluded a data processing agreement with Cal.com. For more information on data protection at Cal.com, please see: https://cal.com/privacy.
8. Fonts and scripts (locally hosted)
Web fonts
This website uses the fonts “Archivo” and “JetBrains Mono” for a consistent typeface. These fonts are integrated locally on our server and are loaded exclusively from there. No connection to third-party servers (e.g. Google Fonts) is established and no IP address is transmitted to third parties.
Program libraries
For technical functions (e.g. animations) we use the JavaScript library “GSAP”. This is also stored locally on our server and delivered from there; integration via external content delivery networks (CDN) and any associated data transfer to third parties does not take place.
← Back to home