Privacy policy

Data protection

Last updated 15 January 2025

As the operator of this site, DTC Healthtech Solution Limited („DTC“ or „we“) takes the protection of your personal data very seriously. Protecting your privacy when personal data is processed is an important concern for us. Below we would like to inform you about which data we collect and process when, for example, you visit our website (hereinafter also “website“) or use the services we otherwise offer (hereinafter „services“). These notes apply both to browser-based use and to our mobile apps, which you can download from the Apple or Google app store.

Controller

The controller within the meaning of the EU General Data Protection Regulation (GDPR) is

DTC Healthtech Solution Limited

Postal address:

Baumwall 5

20459 Hamburg

Germany

Corporate Office:

1st Floor, Behan House,

10 Mount Street Lower,

D02 HT71 Dublin

Ireland

Data protection officer

Our data protection officer is

heyData GmbH,

Gormannstr. 14,

10119 Berlin,

datenschutz@heydata.eu,

https://www.heydata.eu/

Contents

The following privacy policy contains these sections:

1. Logging of data when our website is used

2. Collection and use of personal data

3. Purpose of and legal basis for the processing

- Medical history form

- Order

- Data security

- Contact form

- Cookies

4. Your rights

5. Profiling

6. Storage period, erasure of personal data

7. Transfer of data to third parties

8 Transfer of data to third countries

9 Processors

10 Changes to this privacy policy

11 Contact

As a general principle:

Personal data is any information relating to an identified or identifiable natural person. This includes, for example, details such as name, postal and e-mail address or telephone number, and possibly also usage data such as your IP address.

1. Logging of data when our website is used

When you access our website, information about this is stored and processed in a log file. This takes place anonymously. No conclusions can be drawn about you as a person.

Depending on the access protocol used, the log record contains details with the following content:

- the date and time of the page request

- the IP address of the requesting device

- the access methods/functions requested by the requesting device

- the function requested or the name of the file retrieved

- operating system and browser type or browser settings

- the volume of data transferred and the message stating whether the access/retrieval was successful

We have no way of linking an IP address with any personal data that may exist. The technical information, usage details and browsing activity stored are used exclusively for the purposes of identifying and tracing impermissible access attempts to the web server, for statistical evaluations such as visitor numbers and page popularity, and to improve what we offer online. This data is used exclusively by us. It is not passed on to third parties.

2. Collection and use of personal data

In order for us to make certain services possible, the collection of personal data is unavoidable. We then ask for and store your master data (name, address), your contact data (e-mail, telephone number, delivery address, billing address), details of your identity (date of birth, gender), medical information about your state of health, and whether and to which marketing communications you have consented.

If you make a payment to us, we will process your payment data. DTC does not, however, act as a payment provider, so we do not store your card details but pass them directly to the provider. We do have access to the transaction data: card type, bank details, the last 4 digits of your card, billing address and transaction IDs. These details are not stored directly by us, but we can access them in order to help you or if there is a payment dispute. In the event of a dispute we would store the details of the transaction until the dispute has been resolved.

We use the data collected to answer your enquiries, for service and customer care, and to comply with statutory requirements. In order to provide our services to you, it may be necessary to pass your personal data to companies we engage to deliver the service or to perform the contract. These are, for example, marketing agencies, technicians, IT and hosting service providers, payment service providers and operators of merchandise management systems.

Where you provide us with personal data for the purpose of getting in touch, that data remains stored with us only for as long as is necessary for the purpose of the respective communication and contact. As soon as we no longer need the personal data for those purposes and no longer retention obligations apply, it is erased without delay.

We store information about your state of health and your medical history that you provide to us when you complete our medical history form online. This includes information you have provided to us when communicating with your doctor or our customer service, and the treatments our doctors have prescribed to you. This data is necessary so that your doctor can make a diagnosis and offer you treatment or advice.

You can withdraw the consent you have given us at any time and object to the creation of usage profiles with effect for the future. In addition, where we use your personal data within the limits permitted by law for postal marketing measures, for example, you may also object to that use. In both cases an e-mail to the following address is sufficient: support@solean.com.

3. Purpose of and legal basis for the processing

In accordance with Article 13 GDPR we inform you of the legal basis for our processing of data. The legal basis for the processing depends in each case on the purpose for which the data is processed.

If you have given us your consent to the processing of your personal data, we base the processing on the consent you have given, in accordance with Article 6(1)(a) GDPR.

Processing your personal data may, however, also be necessary for the following reasons: to perform a contract concluded with you or to carry out pre-contractual measures requested by you, to make our services available to you, and to fulfil our legal obligations (Article 6(1) sentence 1(a) to (c) GDPR). We also use your personal data pursuant to Article 6(1) sentence 1(f) GDPR in order to pursue our legitimate interests, provided your rights and freedoms do not override them. Legitimate interests are the establishment, exercise or defence of legal claims.

3.1 Medical history form

So that we can suggest a suitable treatment to you, we ask you to give us data about your medical history to date. This is stored only pseudonymously via a browser key and cannot be identified by us. Only after you complete the order process, once you have given us your contact details and consented to our terms and conditions and this privacy policy, do we assign the health data from the medical history form to you personally and pass it to the treating doctor. Data is collected on the basis of your consent (Article 6(1) sentence 1(a), Article 9(2)(a) GDPR). You may withdraw consent you have already given at any time. An informal notice by e-mail is sufficient for withdrawal. The lawfulness of the processing carried out up to the withdrawal is unaffected by it.

3.2 Order

In order to use our service, we ask you for the following data when you order: e-mail address, telephone number, surname and first name, date of birth, gender, billing address, delivery address, and we link these with the health data from the medical history form stored under the browser key. If you decide to register, we also ask for a password of your choosing. Data transmitted with the order, including your contact details, is stored so that we can process your order and be available for follow-up questions. The data entered in the order form is processed in order to perform the contract concluded with you (Article 6(1) sentence 1(b) GDPR). The data is passed to the cooperating mail-order pharmacy and to the doctor treating you.

Data transmitted with the order otherwise remains with us until you ask us to erase it, withdraw your consent to its storage, or the storage is no longer necessary. Mandatory statutory provisions, in particular retention periods, are unaffected.

3.3 Data security

For security reasons and to protect the transmission of confidential content that you send to us as the site operator, our website uses SSL or TLS encryption. Data you transmit through this website therefore cannot be read by third parties. You can recognise an encrypted connection by the „https://“ in your browser's address bar and by the padlock symbol in the browser bar.

As part of hosting, all data that has to be processed in connection with the operation of this website is stored. This is necessary in order to make the operation of the website possible. We process the data on the basis of our legitimate interests pursuant to Article 6(1)(f) GDPR. To provide our service we use the services of web hosting providers, to whom we transmit the data named above.

3.4 Contact form

Data transmitted via the contact form, including your contact details, is stored so that we can process your enquiry and be available for follow-up questions. This data is not passed on without your consent.

The data entered in the contact form is processed on the basis of our legitimate interest in answering enquiries addressed to us (Article 6(1) sentence 1(f) GDPR). Data transmitted via the contact form remains with us until you ask us to erase it or the storage is no longer necessary. Mandatory statutory provisions, in particular retention periods, are unaffected.

3.5 Cookies

Our website uses cookies. These are small text files that your web browser stores on your device. Cookies help us to make what we offer more user-friendly, more effective and more secure.

Some cookies are “session cookies.” Such cookies are deleted by themselves at the end of your session. Other cookies, by contrast, remain on your device until you delete them yourself. Such cookies help us recognise you when you return to our website.

You can prevent cookies from being stored by adjusting your browser software accordingly. Disabling cookies may, however, result in limited functionality of our website.

Cookies that are necessary to carry out electronic communication processes or to provide particular functions you have asked for are set on the basis of Article 6(1)(f) GDPR. As the operator of this website we have a legitimate interest in storing cookies in order to provide our services in a technically error-free and smooth manner. Where other cookies are set (for example for analysis functions), these are dealt with separately in this privacy policy.

4. Your rights

You have various rights in relation to data concerning you. On request you have the right to obtain information about the personal data we hold about you free of charge, a right to rectification, erasure or restriction of the processing of that data, and a right to object to the processing. Whether and to what extent these rights apply in an individual case, and what conditions attach to them, follows from the GDPR and the German Federal Data Protection Act. Under the GDPR you also have, in principle, a right to data portability. Should the processing be based on your consent, you can withdraw that consent at any time with effect for the future.

If you have questions, comments or requests regarding our collection, processing, use or erasure of your personal data, please contact support@solean.com

As a data subject you have a right to lodge a complaint with the competent supervisory authority in the event of a breach of data protection law. The supervisory authority competent for data protection questions is the data protection officer of the member state in which our company has its registered office. In the case of joint controllership with a doctor, you may also contact the supervisory authority competent for that doctor. The relevant supervisory authority is located in the member state in which the doctor is registered and has his practice. For Ireland this is the Data Protection Commissioner. You can find details at https://dataprotection.ie/

You may, however, also assert this right with a supervisory authority in the member state of your residence, your place of work or the place of the alleged infringement. You can find the contact details of the supervisory authorities in Germany at https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

5. Profiling

You have the right not to be subject to a decision based solely on automated processing, as happens with profiling for example, where that decision produces legal effects concerning you or similarly significantly affects you. This does not apply where the decision

(1) is necessary for entering into, or the performance of, a contract between you and us,

(2) is authorised by Union or member state law to which we are subject and which lays down suitable measures to safeguard your rights and freedoms and your legitimate interests, or

(3) is based on your explicit consent.

6. Storage period, erasure of personal data

The data we process is erased or its processing restricted in accordance with Articles 17 and 18 GDPR. Unless expressly stated within this privacy policy, the data stored with us is erased as soon as it is no longer necessary for its intended purpose and no statutory retention obligations prevent erasure. Where data is not erased because it is necessary for other legally permitted purposes, its processing is restricted. That is, the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax law reasons.

7. Transfer of data to third parties

Your personal data is not transferred to third parties for purposes other than those listed below. We pass your personal data to third parties only if and to the extent that:

- you have given your explicit consent to this under Article 6(1) sentence 1(a) GDPR,

- the disclosure is necessary under Article 6(1) sentence 1(f) GDPR for the establishment, exercise or defence of legal claims and there is no reason to assume that you have an overriding legitimate interest in your data not being disclosed,

- there is a legal obligation to disclose under Article 6(1) sentence 1(c) GDPR, and

- this is necessary under Article 6(1) sentence 1(b) GDPR for the handling of contractual relationships with you, such as in the case of disclosure to external service providers who support us in our business operations.

Our employees and partners are obliged by us to maintain confidentiality and to comply with data protection provisions.

8. Transfers of data to third countries

When we share your personal data in accordance with this privacy policy, this may include transferring your personal data to countries outside the European Economic Area (EEA). When we transfer your personal data to countries outside the European Economic Area, we always ensure that an adequate level of protection is guaranteed there by making sure, where this is required by law, that at least one of the following appropriate safeguards is in place:

(1) transfer of personal data to countries which in the opinion of the European Commission offer an adequate level of protection for personal data (an „adequacy decision“);

(2) use of specific contracts approved by the European Commission which give personal data the same protection it enjoys in the EEA (the „EU standard contractual clauses“). The service provider thereby gives specific guarantees for the protection of the data;

(3) transfer of personal data to an entity that has adopted binding internal data protection rules corresponding to the EU level of protection for personal data (so-called „binding corporate rules“).

For transfers of data to the USA, DTC has concluded agreements with the respective service providers on the basis of EU standard contractual clauses. On request you can obtain a copy of the clauses concluded for this purpose from us.

Your health data is never transferred to third countries but always remains within the European Economic Area.

9. Processors

The recipients of personal data are exclusively the processors named below:

Google (overview)

We use a number of services from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland („Google“). These are explained in more detail below.

We use Google Ads to serve, optimise and analyse advertising material.

For this, Google uses cookies that are stored on the device and that make it possible to analyse user behaviour in relation to advertising material, and to serve advertising material based on browsing behaviour.

This may also involve a transfer to Google's parent company, Google LLC in the USA. In providing the services, Google acts as our processor. Additional information about data protection at Google can be found in the Google privacy notice: https://policies.google.com/privacy?hl=de

You can object to the collection or evaluation of your data by these tools either by adjusting your browser settings or by installing the plug-in provided by Google (https://www.google.com/settings/ads/plugin).

Google Analytics (usage statistics)

We use the „Google Analytics“ and „Universal Analytics“ services from Google in order to record pseudonymously how users use our platform, to produce anonymised evaluations and to shape our platform accordingly.

By means of Google Analytics we record when a user accesses which pages of our website, their approximate location, and data about the device used (for example device type, operating system or screen resolution). This data is processed pseudonymously, that is, used in such a way that it is not linked to details that directly identify the user (for example name, e-mail address).

As part of Google Analytics we also use Google Optimize, with the help of which the behaviour of users on different variants of our website can be analysed and compared. This makes it possible to improve the usability and efficiency of our website.

For this, Google Analytics uses cookies that are stored on the device and that make it possible to analyse the use of the website. The information generated by the cookie about your use of our website is generally transferred to a Google server in the USA and stored there. The cookie has a lifetime of 14 months.

IP anonymisation has been activated on our website, so that your IP address is truncated beforehand by Google within member states of the European Union or in other states party to the Agreement on the European Economic Area. Only in exceptional cases is the full IP address transferred to a Google server in the USA and truncated there. The IP address transmitted by the browser within the framework of Google Analytics is not merged with other Google data.

On our behalf, Google will use this information to evaluate the use of the website, to compile reports on website activity and, where applicable, to provide us as the website operator with further services connected with website use and internet use.

We also use Universal Analytics. This allows us to obtain information about the use of our platform across different devices, that is, across devices (for example combining use on a smartphone and a laptop). Using cookie technology we deploy a pseudonymised user ID which contains no personal data and transmits none to Google.

The data arising within the framework of Google Analytics and Universal Analytics is erased after 14 months.

The data is processed on the basis of our legitimate interests pursuant to Article 6(1) sentence 1(f) GDPR. Our interest lies in being able to evaluate how our website is used, in order to adapt and optimise our website on the basis of the results.

You can object to the collection and use of data within the framework of Google Analytics and Universal Analytics by downloading and installing this browser plug-in: https://tools.google.com/dlpage/gaoptout?hl=de or by withdrawing your consent by setting the analysis cookies switch to „off“. Withdrawing consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the withdrawal.

Firebase Dynamic Links (optimised links)

We use Google's „Firebase Dynamic Link“ service in order to provide users with optimised links. In doing so, pseudonymised data about the user's device may be recorded for a short time.

For some of the links we provide we use „Firebase Dynamic Links“. The links generated in this way allow us always to direct the user straight to the right address, regardless of whether they are using an Android or iOS device or our website.

For this, data about the device (for example the operating system) is recorded temporarily on a pseudonymous basis. No health data is processed. The legal basis for the processing in connection with Firebase Dynamic Links is our legitimate interests pursuant to Article 6(1) sentence 1(f) GDPR in providing user-friendly links.

Google Ads

We use the Google Ads offering in order to draw attention to what we offer with the help of advertising material (so-called Google Ads). In relation to the data of the advertising campaigns we can determine how successful the individual advertising measures are.

This advertising material is delivered by Google through so-called „ad servers“. According to Google's own statements, it uses ad server cookies for this, by means of which certain parameters for measuring success, such as the display of the ads or clicks by users, can be measured. If you reach our website via a Google ad, Google Ads stores a cookie in your browser. This cookie loses its validity after 30 days and, according to Google, is not intended to identify you personally. The cookie allows Google to recognise your browser again. If you visit certain pages of ours and the cookie stored on your device has not yet expired, Google and we can recognise that you clicked on the ad and were directed to us. A different cookie is assigned to each Google Ads customer. Cookies can therefore not be tracked across the websites of Google Ads customers.

We ourselves neither collect nor process any personal data in the advertising measures named. We are provided by Google only with statistical evaluations. On the basis of these evaluations we can see which of our advertising measures are particularly effective and thus make them more relevant to you. We cannot identify you or other users on the basis of this information, because we receive no further data from the use of the advertising material and have it available only in aggregated form.

Through the use of the marketing tool, your browser automatically establishes a direct connection with Google's server. We have no influence over the extent and the further use of the data collected by Google as a result. Through the integration of Google Ads conversions, Google receives, according to its own statements, the information that you have accessed the corresponding part of our website or clicked on an advertisement of ours. If you are logged in to Google at that moment, Google can assign the visit to your account. Even if you are not registered with Google or are not logged in, there is a possibility that the provider will learn and store your IP address.

You can prevent participation in this tracking process in various ways:

- by adjusting your browser software accordingly; in particular, suppressing third-party cookies means you will not receive advertisements from third-party providers;

- by disabling the cookies for conversion tracking, by changing the settings in your browser so that cookies from the domain www.googleadservices.com are blocked, whereby this setting is deleted if you delete your cookies or reset your browser;

- by disabling the interest-based advertising of providers that are part of the „About Ads“ self-regulation campaign, via the link http://www.aboutads.info/choices, whereby this setting is deleted if you delete your cookies or reset your browser;

- by permanently disabling it in your Firefox, Internet Explorer or Google Chrome browser via the link https://support.google.com/ads/answer/7395996. Please note that in this case you may not be able to use all the functions of our website in full.

The legal basis for the processing is Article 6(1) sentence 1(f) GDPR. We have a legitimate interest in measuring the success of our advertising campaigns and thereby assessing them.

Google Tag Manager

Google Tag Manager is used to manage the JavaScript plug-ins of the technology service providers deployed, their cookies and the distribution of information. It does not, however, collect any personal data but serves merely as a central instrument for integrating JavaScript code. Based on your selection in the cookie management tool, Google Tag Manager controls or prevents the firing of other tags which may collect data, which the tag manager does not itself access.

Google Cloud Services

In order to store your data and keep it accessible to us, we use Google Cloud Services. All data you provide to us is encrypted by us and stored on Google servers within the EU. This includes your contact details (name, e-mail, billing address, delivery address, telephone number), as well as your health data from the medical history form and your user profile. On the Google Cloud Services servers the data is encrypted by means of a CMEC (customer managed encryption key). This ensures that nobody other than DTC can render the data readable. By means of a specific data processing agreement, Google has undertaken towards us to ensure that your data never leaves the EU. The legal basis for the processing is Article 6(1) sentence 1(f) GDPR. We have a legitimate interest in maintaining a modern and cost-effective hosting environment.

Meta remarketing (advertising on Facebook and Instagram)

On our website we use the remarketing function „Custom Audiences“ of Meta Inc. (1601 S. California Ave, Palo Alto, CA 94304, USA; “Meta”). This allows visits to our website to be recorded by Meta, assigned to the user account and used to display interest-based advertising to the user on Facebook and Instagram.

We have integrated a piece of program code from Meta into our website (a „remarketing tag“). Through this, a direct connection is established between the device and Meta's computers when our web pages are visited. This transmits to the Meta server which of our pages the user has visited and, where applicable, which actions they carried out with us (for example registration as a new user). Meta can assign this information to the user account on Facebook or Instagram or to a pseudonym and thereby determine potential interests. This can also take place across several devices and visited websites. When the user visits the Facebook or Instagram pages, personalised, interest-based advertisements are displayed there. Further information about how Meta handles data and about options for protecting your privacy can be found at https://www.facebook.com/about/privacy/.

You can also deactivate the remarketing function “Custom Audiences” in the advertising settings area at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen. To do so you must be logged in to Facebook.

If you do not have a Facebook account, you can deactivate usage-based advertising from Meta on the website of the European Interactive Digital Advertising Alliance: http://www.youronlinechoices.com/de/praferenzmanagement/.

The data is processed on the legal basis of our legitimate interests pursuant to Article 6(1) sentence 1(f) GDPR in displaying interest-based advertising on Facebook and Instagram and measuring the effectiveness of our advertisements there.

Notifications on mobile devices (push notifications)

We may send push notifications to the user's device running the iOS or Android operating system. Push notifications are messages that are displayed on the device even when our app is not currently being used.

We use push notifications to remind you to take your pill and to log possible side effects and symptoms regularly. The messages contain no health data.

In order to deliver the push notifications we have to hand the content of the notifications to a technical service of the operating system provider. In the case of devices with the Android operating system this is Google, and for iOS it is Apple Inc., One Apple Park Way, Cupertino, California, USA, 95014. The device is addressed technically via a pseudonymous identifier which the operating system provider makes available to us and which applies only to our app and the specific device. We transmit no directly identifying details such as name or e-mail address, and no health data, to the operating system provider.

Delivery of our push notifications can be deactivated in the operating system settings of the mobile device. On iOS the user receives push notifications only after giving prior consent. The legal basis for the processing is the user's consent (Article 6(1) sentence 1(a) GDPR). You may withdraw consent you have already given at any time by changing the settings on your device. The lawfulness of the processing carried out up to the withdrawal is unaffected by it.

Stripe

Payment is processed via the payment service provider Stripe Payments Europe Ltd, Block 4, Harcourt Centre, Harcourt Road, Dublin 2, Ireland, to which we transmit the information you provided during the order process together with the information about your order (name, address, account number, sort code, credit card number where applicable, invoice amount, currency and transaction number). Your data is transmitted to Stripe on the basis of Article 6(1) sentence 1(b) GDPR (processing for the performance of a contract). Your data is disclosed exclusively for the purpose of processing payment with the payment service provider Stripe Payments Europe Ltd. and only to the extent necessary for that purpose.

In the event that personal data is transferred to the USA, EU standard contractual clauses contained in the contract with Stripe guarantee the security of the data. Further information about data protection at Stripe can be found at the URL https://stripe.com/de-gb/privacy

PayPal

On our website we offer payment via PayPal, among other methods. The provider of this payment service is PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg (hereinafter “PayPal”). If you select payment via PayPal, the payment data you enter is transmitted to PayPal. Your data is transmitted to PayPal on the basis of Article 6(1)(a) GDPR (consent) and Article 6(1) sentence 1(b) GDPR (processing for the performance of a contract). You have the option of withdrawing your consent to the processing of data at any time. A withdrawal does not affect the validity of processing operations that took place in the past. For further data protection information please refer to PayPal's privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full

Kompas Health

In order to be able to broker the contract for telemedicine treatment with Kompas Health Ltd, Ground Floor, 71 Lower Baggot Street, Dublin 2, Dublin, Ireland, D02 P593 (hereinafter „Kompas Health“), we share your personal data, including your health data, with Kompas Health. Only if Kompas Health (and its cooperation partner/doctor) has your personal (health) data are they able to treat you individually and, in particular, to decide whether a particular medicinal therapy is suitable for you or not. Following an appropriate medical assessment, the treating doctor ultimately issues an electronic prescription on the basis of which you receive your medicine.

The above processing is necessary in order to perform the contract with Kompas Health that you requested through DTC's brokerage. The legal basis for this processing is the performance of a contract pursuant to Article 6(1)(b) and Article 9(2)(h) GDPR.

Health Finder

In order to be able to broker the contract for telemedicine treatment with Health Finder Pro Ireland Ltd, 6-9 Trinity House, Dublin 2, Ireland (hereinafter „Health Finder“), we share your personal data, including your health data, with Health Finder. Only if Health Finder (and its cooperation partner/doctor) has your personal (health) data are they able to treat you individually and, in particular, to decide whether a particular medicinal therapy is suitable for you or not. Following an appropriate medical assessment, the treating doctor ultimately issues an electronic prescription on the basis of which you receive your medicine.

The above processing is necessary in order to perform the contract with Health Finder that you requested through DTC's brokerage. The legal basis for this processing is the performance of a contract pursuant to Article 6(1)(b) and Article 9(2)(h) GDPR.

APONS

So that you can receive the product you ordered after your electronic prescription has been issued and qualified-signed by the doctor, we cooperate with the mail-order pharmacy Apotheek Bad Nieuweschans B.V., Verlenge Hoofdstraat 1 D, 9693 AB Bad Nieuweschans, the Netherlands (hereinafter „APONS“), unless you opt to have the prescription sent to you and to collect locally. Your personal data is forwarded to APONS together with the electronic prescription issued by the doctor and the associated medicine voucher created by DTC, in order to process your order.

To handle the dispatch of medicines by APONS, DTC transmits the following data there: your full name, the delivery address you provided, and the doctor's prescription (including details of the medicine, namely the name of the medicine, pack size, product ID, instructions for use, a list of ingredients where applicable, and the name and address of the treating doctor). This transfer of data to the partner pharmacy is necessary so that the prescribed medicine can be sent to the address you want.

The transmission and processing of your data by DTC to APONS takes place on the basis of Article 6(1)(b) GDPR (processing for the performance of a contract). The pharmacy is responsible for the processing of the personal data and for proper handling; here too the basis is Article 6(1)(b) GDPR (processing for the performance of a contract).

Klaviyo (e-mail marketing and website tracking)

We use the services of Klaviyo Inc., 125 Summer Street, Boston, MA 02110, USA („Klaviyo“) for sending newsletters and other marketing e-mails and for analysing user behaviour on our website (website tracking).

E-mail marketing:

If you sign up for our newsletter or otherwise give your consent to receiving marketing e-mails, the data you provide (for example your e-mail address) is transferred to Klaviyo and stored there. Klaviyo uses this data to send newsletters and other marketing e-mails on our behalf.

Website tracking:

Klaviyo uses cookies and similar technologies to collect information about your usage behaviour on our website. This information is used to personalise your user experience and to show you more relevant content and offers. For example, we can recommend products that might interest you based on your previous browsing behaviour.

Data processing in the USA:

Klaviyo also processes your data in the USA. Klaviyo is an active participant in the EU-US Data Privacy Framework, which governs the correct and secure transfer of personal data of EU citizens to the USA. Through the EU-US Data Privacy Framework and the standard contractual clauses, Klaviyo undertakes to observe the European level of data protection when processing your data, even where the data is stored, processed and managed in the USA.
Further information and withdrawal:

Further information about data protection at Klaviyo can be found in Klaviyo's privacy policy: https://www.klaviyo.com/legal/privacy-policy

The legal basis for the processing of your data in connection with Klaviyo is your consent pursuant to Article 6(1)(a) GDPR. You can withdraw your consent at any time by unsubscribing from the newsletter, adjusting the cookie settings in your browser, or sending us an e-mail at support@melloe.de.

Klar Attribution

On our website we use the services of Klar (Klar Insights GmbH, Marktstr. 18, 80802 Munich, Germany). On this website and its subpages, Klar collects, processes and stores data for reach measurement and statistical analysis on our behalf. This collection takes place on the following legal basis:

Where the user has given consent under Article 6(1) sentence 1(a) GDPR and section 25(1) sentence 1 TTDSG, the data to be processed is collected on a user-related basis.

Different cookies are used for the different types of collection named above, in order to ensure the respective type of collection.

Information about data protection and the use of data by Klar can be found on the following website: https://www.getklar.com/data-protection

Hotjar (analysis of usage behaviour)

We use Hotjar, analysis software from Hotjar Ltd. („Hotjar“) (http://www.hotjar.com, 3 Lyons Range, 20 Bisazza Street, Sliema SLM 1640, Malta, Europe), to evaluate your usage behaviour pseudonymously.

By means of Hotjar we record the usage behaviour of our visitors (usage data), for example when which page was accessed, how users behave on individual pages (for example mouse and scroll movements, form use) and how they move through the website (for example pages accessed, click paths), as well as details about the device (for example device type, screen size, browser used, preferred language) and the location (country only). The device's IP address is stored only in anonymised form.

Hotjar works with cookies and other technologies in order to collect this information. Cookies have a lifetime of 365 days; details of the cookies can be found at https://help.hotjar.com/hc/en-us/articles/115011789248-Hotjar-Cookies.

On the basis of device-specific information (for example screen size, installed fonts) we create a device-specific identifier (a technical fingerprint) in order to recognise a device across several visits.

We use the usage data to analyse the usage behaviour of our website (reports) and thus ultimately to shape our website to meet demand. For example, we can see which content and areas attract particular attention and whether there are problems or stumbling blocks when filling in forms.

Hotjar stores the usage data named in a pseudonymised user profile. The information is used neither by Hotjar nor by us to identify individual users, nor is it merged with further data about individual users. Further information can be found in Hotjar's privacy policy at https://www.hotjar.com/legal/policies/privacy. The usage data is erased after 365 days.

You can object to Hotjar's tracking cookie being set and to the collection of usage data by clicking the following link (to Hotjar's page): https://www.hotjar.com/legal/compliance/opt-out

The data is processed on the legal basis of our legitimate interests pursuant to Article 6(1) sentence 1(f) GDPR (balancing of interests). Our interest lies in understanding the use of our website better and shaping the website to meet demand.

Shopify

We use Shopify to operate an online shop. The provider is Shopify International Limited, Victoria Buildings, 2nd floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland. The provider processes meta/communication data (for example device information, IP addresses) in the EU.

The legal basis for the processing is Article 6(1) sentence 1(a) GDPR. The processing takes place on the basis of consent. Data subjects can withdraw their consent at any time, for example by contacting us using the contact details given in our privacy policy. The withdrawal does not affect the lawfulness of the processing up to the withdrawal.

The data is erased once the purpose of its collection has ceased to apply and no retention obligation prevents this. Further information is available in the provider's privacy policy at https://www.shopify.de/legal/datenschutz.

Post & DHL shipping app

We use the Deutsche Post & DHL shipping app on our website for the purpose of ordering and tracking parcels. The provider is DHL Paket GmbH, Sträßchensweg 10, 53113 Bonn. The provider processes contact data (name, e-mail address and telephone number), location data (address and geolocation) and device information (IP address, browser and operating system) in the EU.

The legal basis for the processing is Article 6(1) sentence 1(b) GDPR. The processing is necessary in order to perform the shipping contract with the respective shipping service provider.

Further information is available in the provider's privacy policy at https://www.dhl.de/de/toolbar/footer/datenschutz.html.

10. Changes to this privacy policy

We reserve the right to change this privacy policy at any time with effect for the future. A current version is always available on our website. Please visit our website regularly and inform yourself about the data protection provisions in force.

Please also note that data protection provisions and data protection practices may change continuously at third parties too, for example Stripe. It is therefore advisable and necessary to keep yourself informed about changes to statutory provisions and to companies' practices.

11. Contact

If you have questions, comments or requests regarding this privacy policy, please contact: support@solean.com

If you wish to withdraw your consent to the processing of your data, to have your data transferred, or to obtain information about the personal data we hold about you, please write to us at: support@solean.com