Privacy Policy
Last updated: 19 June 2026
Protecting your personal data is very important to us. This policy explains what data we process when you visit this website, use our contact and booking forms, or subscribe to our newsletter, on what legal basis, and what rights you have. We process health-related data only where you choose to provide it and only on the basis of your explicit consent or the provision of healthcare.
1. Controller
The controller responsible for data processing on this website is:
Mai Jimenez (MaiHealth)
[Postal address — see Legal Notice]
Email: Mai.jimenez@gmx.de
2. What data we process, for what purpose, and on what legal basis
Contact form: first and last name, email address, phone number (optional) and your message. Purpose: to receive and respond to your enquiry. Legal basis: your consent (Art. 6(1)(a) GDPR); where your message contains health data, additionally your explicit consent (Art. 9(2)(a) GDPR).
Appointment booking: name, email address, phone number, the reason for your visit and the chosen appointment details. Purpose: to arrange and carry out your consultation. Legal basis: performance of (pre-)contractual measures (Art. 6(1)(b) GDPR) and, for health data, your explicit consent (Art. 9(2)(a) GDPR) and/or the provision of healthcare (Art. 9(2)(h) GDPR).
Patient account: when you sign in with Google, we receive your name and email address to create and manage your patient account in the portal. Legal basis: Art. 6(1)(b) GDPR.
Newsletter: your email address. We use a double opt-in procedure — you only receive the newsletter after confirming via the link we email you. Purpose: sending our newsletter. Legal basis: your consent (Art. 6(1)(a) GDPR). We store the time of subscription and confirmation to document your consent.
Server log data: when you access the site, technical data such as your IP address, browser type and time of access are processed to deliver the site securely and reliably. Legal basis: our legitimate interest in a secure and functional website (Art. 6(1)(f) GDPR).
3. Recipients and processors
We use carefully selected service providers who process data on our behalf under data processing agreements (Art. 28 GDPR):
- Google Ireland Ltd. / Google LLC — Firebase Authentication, Cloud Firestore (database) and hosting infrastructure. Data is stored in the region [confirm Firestore region — recommended: europe-west, e.g. Frankfurt].
- Resend (Plusten, Inc., USA) — delivery of transactional and newsletter emails.
- Zoom Video Communications, Inc. (USA) — video consultations, where conducted online.
- [Hosting provider — confirm, e.g. Vercel Inc., USA, with EU region] — operation and delivery of the website.
4. Transfers to third countries
Some of the providers above are based in the USA or may process data there. Such transfers take place on the basis of the EU Standard Contractual Clauses (Art. 46 GDPR) and/or the EU–US Data Privacy Framework where the provider is certified. You can request a copy of the relevant safeguards from us at any time.
Where possible, we configure our services to store and process personal data within the European Union.
5. How long we keep your data
Contact enquiries: deleted no later than 6 months after your request has been dealt with, unless a treatment relationship or legal retention obligation arises.
Appointment and treatment-related records: retained for the statutory documentation period applicable to medical/health records (generally up to 10 years; cf. § 630f BGB and professional rules).
Newsletter: until you unsubscribe; the proof-of-consent record is then kept as required to demonstrate lawful processing.
Server logs: deleted or anonymised after a short period.
6. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Access to the data we hold about you (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing based on legitimate interests (Art. 21)
- Withdrawal of consent at any time with effect for the future (Art. 7(3)) — this does not affect the lawfulness of processing carried out before the withdrawal
7. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority competent for us is [the data protection authority of the relevant federal state — to be completed, e.g. Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)].
8. Cookies and local storage
We use only strictly necessary cookies and local storage: a cookie that remembers your chosen language, and the session storage that Firebase Authentication uses to keep you signed in to the patient portal. These are required for the website to function and therefore do not require consent (§ 25(2) TDDDG).
We do not use any analytics, advertising or tracking tools. There is therefore no tracking cookie banner.
9. Fonts
Fonts are hosted on our own server. No connection to Google servers is established to load fonts, so your IP address is not transmitted to Google for this purpose.
10. Automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
11. Changes to this policy
We may update this policy to reflect changes to our services or legal requirements. The current version always applies, as indicated by the date above.
12. Contact regarding data protection
To exercise your rights or for any questions about data protection, contact us at: Mai.jimenez@gmx.de.