Bestmed 360

Legal

Privacy Policy

Note

Only the German version of this page is legally binding.

This translation is provided for convenience. The legally binding version is the German original.

This privacy policy explains which personal data we process when you visit this website or contact us, for which purposes, and on which legal basis (DSGVO — the EU General Data Protection Regulation, GDPR).

Controller

The controller within the meaning of the GDPR is:

Vladimir Dorn "BESTMED 360" – Zentrum für Arbeitsmedizin, Arbeitssicherheit und Prävention Kurfürstendamm 106, 10711 Berlin, Germany

Phone: +49 30 8913040

info@bestmed360.com

No data protection officer has been appointed, as there is no legal obligation to do so (Art. 37 GDPR, § 38 BDSG — the German Federal Data Protection Act).

In compliance and data protection matters, BESTMED 360 is supported by Kopexa GmbH.

Hosting with Vercel

This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA ("Vercel"). When you visit the website, Vercel automatically processes the data transmitted by your browser: IP address, date and time of access, page requested, browser type and version, operating system and the referring page. These server logs are technically required to deliver the website and to ensure its stability and security (legal basis: Art. 6 (1)(f) GDPR — legitimate interest in secure and reliable operation). Log data is not combined with other data and is deleted after a short period.

A data processing agreement pursuant to Art. 28 GDPR is in place with Vercel. Where data is transferred to the USA, Vercel is certified under the EU-U.S. Data Privacy Framework; EU standard contractual clauses apply in addition. Further information: vercel.com/legal/privacy-policy

Cookies

This website uses exactly one cookie: NEXT_LOCALE stores your language selection. This cookie is technically required for the function you requested (§ 25 (2) no. 2 TDDDG — the German act on data protection in digital services; Art. 6 (1)(f) GDPR) and contains no personal profiling data.

We use no analytics or tracking tools, no advertising cookies and no social media plugins. That is why you will not see a cookie banner on this website — there is nothing that would require your consent.

Quote and contact form

If you use our quote form, we process the data you provide (name, company, email address, optional phone number, topic and message) exclusively to handle your enquiry and prepare a quote (Art. 6 (1)(b) GDPR). Transmission takes place by email (see "Email communication and Microsoft 365"); the data is not stored in a database. The email correspondence is deleted as soon as it is no longer required for processing and no statutory retention obligations apply.

To protect against automated abuse, the forms use invisible technical checks (e.g. a honeypot field and a time-based plausibility check). No additional personal data is collected in the process (Art. 6 (1)(f) GDPR — legitimate interest in preventing spam).

Patient enquiries (private physician)

Via the enquiry form on the private physician page, we process your name, phone number, optional email address, your concern and your message in order to handle your enquiry and arrange appointments (Art. 6 (1)(b) GDPR). Where your details contain health data, we process it on the basis of your explicit consent (Art. 9 (2)(a) GDPR) and for the purpose of healthcare (Art. 9 (2)(h) GDPR in conjunction with § 22 BDSG). Your details are additionally protected by medical confidentiality (§ 203 StGB — the German Criminal Code).

Transmission takes place by email (see "Email communication and Microsoft 365"); the data is not stored in a database. We recommend sharing detailed health information not via the form but in person or by phone.

Email communication and Microsoft 365

Our form emails are sent via our own, self-controlled mail infrastructure with transport encryption (TLS). Our mailboxes (e.g. info@bestmed360.com) are operated on Microsoft 365 / Exchange Online by Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. A data processing agreement pursuant to Art. 28 GDPR is in place with Microsoft; processing generally takes place in data centres within the EU (EU Data Boundary). Where data is transferred to the USA, Microsoft is certified under the EU-U.S. Data Privacy Framework; EU standard contractual clauses apply in addition.

Please note that unencrypted email is generally not suitable for highly sensitive content — for such matters, please use the phone or visit the practice.

Personal WhatsApp channel for patients

As part of the "private physician on call" service, we offer patients a personal WhatsApp channel for scheduling on express request. Its use is voluntary; the contact details are used exclusively for this purpose (Art. 6 (1)(a) GDPR, consent may be withdrawn at any time). We do not send health data via WhatsApp on our own initiative and recommend sharing sensitive information with the physician in person, by phone or at the practice. The privacy policy of WhatsApp (Meta Platforms Ireland Ltd.) applies in addition.

Appointment booking via Doctolib

For online appointment booking we link to Doctolib (Doctolib GmbH, Mehringdamm 51, 10961 Berlin). Booking takes place entirely on Doctolib's platform; Doctolib's privacy policy applies there. Our website does not embed any Doctolib content — you only leave our website when you click the link. From the booking, we receive the data required to conduct the appointment.

Job applications

Applications are sent to us by email. We process your application data exclusively to conduct the application procedure (Art. 6 (1)(b) GDPR, § 26 BDSG). After the procedure is completed, the data is deleted after six months at the latest, unless you have expressly consented to longer retention.

Data security

BESTMED 360 uses technical and organisational security measures to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorised persons. The connection to this website is fully TLS-encrypted (recognisable by "https" in the address bar). Our security measures are continuously improved in line with technological developments.

Retention and deletion

The legislator has set various retention periods and obligations, which we comply with. Once these periods expire, the corresponding data is routinely deleted. Where data is not affected by such periods, it is deleted or anonymised when the purposes for which it was collected cease to apply. Unless stated otherwise in this privacy policy, we store data only for as long as is necessary for the stated purposes.

Your rights

You have the following rights vis-à-vis us regarding your personal data: access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and objection to processing based on legitimate interests (Art. 21 GDPR). You may withdraw any consent you have given at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise your rights, an informal message to the contact details above is sufficient.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information), Alt-Moabit 59–61, 10555 Berlin, www.datenschutz-berlin.de.

Changes to this privacy policy

We will update this privacy policy whenever the data processing on this website or the legal requirements change.

Last updated: 14 July 2026

Book appointmentRequest a quote