skip to Main Content

Privacy Policy of medic assist GmbH

Welcome to our website.

We, medic assist GmbH, are the operator of this website and take the protection of your personal data very seriously. Therefore, we treat your personal data confidentially and in accordance with applicable data protection laws and this Privacy Policy.

While the use of our website is generally possible without providing personal data, the use of certain services may require the provision of specific personal information. Where we collect personal data (for example, name, address, or email address), this is generally done on a voluntary basis wherever possible. If the provision of such data is mandatory in order to use our services, we will inform you accordingly (see Section 3 for details).

Please note that data transmission over the Internet (for example, communication by email) may be subject to security vulnerabilities. Complete protection of data against access by third parties cannot be guaranteed.

The processing of personal data, such as a data subject’s name, address, email address, or telephone number, is always carried out in accordance with applicable data protection laws and, in particular, the EU General Data Protection Regulation (GDPR).

Through this Privacy Policy, we inform you, as the data subject, about your rights. Furthermore, as the controller responsible for processing, we have implemented extensive technical and organizational measures to ensure the greatest possible protection of personal data processed through this website. Nevertheless, Internet-based data transmissions may generally contain security gaps, so absolute protection cannot be guaranteed. For this reason, every data subject is free to transmit personal data to us by alternative means, for example, by telephone.

Table of Contents

  1. Definitions
  2. Name and Address of the Controller
  3. Data Processing in Connection with Services Offered on Our Website
  4. Data Processing in Connection with Our Website
  5. Legal Bases for Processing
  6. Duration of Storage of Personal Data
  7. Rights of the Data Subject (Access, Rectification, Erasure, Restriction of Processing, Objection, etc.)
  8. Recipients of Personal Data / Transfers to Third Countries
  9. Statutory or Contractual Requirements to Provide Personal Data
  10. Subscription to Our Newsletter
  11. Social Media, Tools and Analytics Services
  12. No Automated Decision-Making
  13. Data Protection Officer
  14. Amendments to Our Privacy Policy

1. Definitions

This Privacy Policy is based on the terminology used in the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). To ensure that this Privacy Policy is easy to read and understand for the public, our customers, and business partners, we would like to explain the terminology used.

Among others, we use the following terms:

a) Personal Data

Personal data means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

b) Data Subject

A data subject is any identified or identifiable natural person whose personal data is processed by the controller.

c) Processing

Processing means any operation or set of operations performed on personal data, whether or not by automated means. This includes collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

d) Restriction of Processing

Restriction of processing means marking stored personal data with the aim of limiting its future processing.

e) Profiling

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, particularly to analyze or predict aspects concerning work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

f) Pseudonymization

Pseudonymization means the processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and subject to technical and organizational measures ensuring that the personal data cannot be attributed to an identified or identifiable person.

g) Controller

The controller is the natural or legal person, public authority, agency, or other body which alone or jointly with others determines the purposes and means of processing personal data.

h) Processor

A processor is a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller.

i) Recipient

A recipient is a natural or legal person, public authority, agency, or another body to whom personal data is disclosed, whether a third party or not. However, public authorities that may receive personal data in the framework of a particular inquiry under Union or Member State law are not regarded as recipients.

j) Third Party

A third party is a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

k) Consent

Consent means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them through a statement or a clear affirmative action.

2. Name and Address of the Controller

The controller within the meaning of data protection laws, in particular the EU General Data Protection Regulation (GDPR), is:

medic assist GmbH
Lise-Meitner-Allee 27
44801 Bochum
Germany

Phone: +49 234 3336710
Email: info@medicassist.de
Website: https://medicassist.eu/

3. Data Processing in Connection with the Services Offered on Our Website

medic assist GmbH provides the following services in the interest of its customers:

  • Innovative services relating to AED (Automated External Defibrillator) services.
  • Unique solutions focusing on the simple and safe use of AEDs and their optimal functionality in emergencies.

In the course of providing these services, personal data (first and last name, address, email address, telephone number, bank details, etc.) are processed for the following purposes:

  1. Providing information where requested.
  2. Providing information and materials relating to our products and services.
  3. Managing relationships with our customers and prospective customers.
  4. Processing, advising, and supporting customers and prospective customers regarding materials and services related to AED services. In this context, medic assist GmbH cooperates with its partner company Heartstream US LLC., 22100 Bothell-Everett Highway, Bothell, WA 98021, USA, and other partners.
  5. Exchanging information with the partners referred to above regarding the progress and results of consultations and services provided.
  6. Fulfilling legal obligations, such as risk assessments and similar requirements, as well as creditworthiness and identity checks and the prevention/prosecution of criminal offenses.
  7. Anonymizing customer and prospect data for internal statistical purposes and, where applicable, sharing such anonymized statistics with third parties.
  8. Direct marketing (particularly through the possible future distribution of an email newsletter) and market research.

We generally obtain your personal data directly from you.

4. Data Processing in Connection with Our Website

Our website is hosted by an external service provider (hosting provider). Personal data collected on this website are stored on the host’s servers. This may include, in particular:

  • IP addresses
  • Contact requests
  • Metadata and communication data
  • Contract data
  • Contact details
  • Names
  • Website access data
  • Other data generated through a website

The hosting provider is used for the purpose of fulfilling contractual obligations toward our prospective and existing customers (Art. 6(1)(b) GDPR) and in the interest of providing our online services securely and efficiently through a professional provider (Art. 6(1)(f) GDPR).

To ensure GDPR-compliant processing, we have concluded a Data Processing Agreement pursuant to Art. 28 GDPR with our hosting provider.

Our hosting provider will process your data only to the extent necessary to fulfill its service obligations and in accordance with our instructions.

For this website, we use the following hosting provider:

1&1 AG / IONOS
56410 Montabaur, Germany

a) Server Log Files

When you access our website, information of a general nature is automatically collected. These server log files include:

  • Type of web browser
  • Operating system used
  • Domain name of your Internet service provider
  • Your IP address
  • Other similar information used for protection against threats and attacks on our information technology systems

Logs are deleted after the session or no later than 30 days.

These data are processed in particular for the following purposes:

  1. Ensuring a smooth connection to the website.
  2. Ensuring convenient use of our website.
  3. Evaluating system security and stability.
  4. Optimizing our website.

These data are not used to draw conclusions about your identity. We may evaluate such information anonymously for statistical purposes in order to optimize our website and the technology behind it.

We also reserve the right to review these data retrospectively if there are concrete indications of unlawful use.

b) Cookies

Some pages of this website use so-called cookies. Cookies do not cause any damage to your computer and do not contain viruses. They are used to make our services more user-friendly, effective, and secure.

Cookies are small text files that are stored on your device by your web browser.

Many websites and servers use cookies. Many cookies contain a so-called cookie ID. A cookie ID is a unique identifier consisting of a character string that allows websites and servers to assign the cookie to a specific web browser. This enables visited websites and servers to distinguish the browser of the data subject from other browsers that contain different cookies. A specific browser can be recognized and identified through its unique cookie ID.

Most of the cookies we use are “session cookies.” They are automatically deleted at the end of your visit. Other cookies remain stored on your device until you delete them. These cookies enable us to recognize your browser upon your next visit.

You can configure your browser so that:

  • You are informed about the setting of cookies.
  • Cookies are permitted only in individual cases.
  • Acceptance of cookies can be excluded in certain cases or generally.
  • Cookies are automatically deleted when the browser is closed.

Disabling cookies may limit the functionality of this website.

Where cookies are used by third parties or for analytical purposes, we will inform you separately in this Privacy Policy and, where required, obtain your consent.

c) Registration on Our Website

Data subjects have the opportunity to register on the controller’s website by providing personal data. The specific personal data transmitted to the controller are determined by the respective registration form.

Personal data entered by the data subject are collected and stored exclusively for internal use by the controller and for its own purposes. Where justified, the controller may arrange for transfer to one or more processors that also use the personal data solely for internal purposes attributable to the controller.

By registering on the website, the IP address assigned by the Internet Service Provider (ISP), as well as the date and time of registration, are also stored.

The storage of these data serves the purpose of preventing misuse of our services and, if necessary, enabling criminal offenses to be investigated. Therefore, the storage of these data is necessary to safeguard the controller.

These data are generally not disclosed to third parties unless disclosure is legally required or serves law enforcement purposes.

Registration, with the voluntary provision of personal data, enables the controller to offer content or services that by their nature can only be provided to registered users.

Registered users may modify the personal data provided during registration at any time or request their complete deletion from the controller’s database.

Upon request, the controller will provide information regarding the personal data stored about a data subject and will correct or delete personal data at the request of the data subject unless statutory retention requirements prevent this.

d) Contact via the Website

Our website contains information that enables rapid electronic contact and direct communication with our company, including a general email address.

If a data subject contacts the controller by email or through a contact form, the personal data transmitted by the data subject are automatically stored.

Such personal data, voluntarily provided by the data subject, are stored for the purpose of processing the inquiry or contacting the data subject.

These personal data are not passed on to third parties.

e) TLS Encryption

For security reasons and to protect the transmission of confidential content, such as inquiries that you send to us as the website operator, this site uses SSL/TLS encryption.

You can recognize an encrypted connection by the browser’s address line changing from “http://” to “https://” and by the padlock symbol in your browser.

When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties.

5. Legal Bases for Processing

Art. 6(1)(a) GDPR serves as the legal basis for processing operations for which we obtain consent for a specific processing purpose.

In particular, we rely on this legal basis when processing data for direct marketing purposes.

Where the processing of personal data is necessary for the performance of a contract to which the data subject is a party, such as processing operations required for the delivery of goods or the provision of services, processing is based on Art. 6(1)(b) GDPR.

We rely on this legal basis particularly with respect to our core business activity, namely the comprehensive support of prospective customers regarding medic assist services. The same applies to processing activities necessary prior to entering into a contract, such as inquiries about our services.

Where we are subject to a legal obligation requiring the processing of personal data, for example to fulfill tax obligations, processing is based on Art. 6(1)(c) GDPR.

For applicant management, the legal basis is Art. 13(1)(c) GDPR in conjunction with Section 26 BDSG and Art. 88 GDPR.

The legal basis for cooperation with partner companies arises from Art. 28 GDPR.

Additionally, processing operations may be based on Art. 6(1)(f) GDPR.

This legal basis applies where processing is necessary for the purposes of the legitimate interests pursued by us or a third party, provided that the interests, fundamental rights, and freedoms of the data subject do not override those interests.

Such processing operations are permitted in particular because they are specifically recognized by the European legislator, which considers that a legitimate interest may exist where the data subject is a customer of the controller (Recital 47, sentence 2 GDPR).

medic assist GmbH has a legitimate interest in:

  • Ensuring IT security.
  • Protecting its property.
  • Establishing, exercising, or defending legal claims.
  • Conducting business activities for the benefit of its employees and shareholders/investors.
  • Anonymizing prospect data for the purpose of generating statistics to analyze and optimize its activities and to share such statistics with third parties.

6. Duration of Storage of Personal Data

The criterion for the duration of the storage of personal data is determined by the respective legal basis, the purpose of processing, and the applicable statutory retention periods (for example, retention obligations under commercial and tax law). After the relevant retention period expires, the corresponding data are routinely deleted unless they are still required for the performance of a contract or for pre-contractual purposes.

Furthermore, medic assist GmbH processes and stores personal data of the data subject only for the period necessary to achieve the purpose of storage or insofar as this is required by European directives and regulations or by other legislators in laws or regulations to which the controller is subject.

If the purpose of storage no longer applies, or if a storage period prescribed by European directives and regulations or another competent legislator expires, the personal data will be routinely blocked or deleted in accordance with statutory provisions.

7. Rights of the Data Subject Regarding Access, Rectification, Erasure, Restriction of Processing, Objection, and Other Rights

a) Right to Confirmation

Every data subject has the right granted by the European legislator to obtain confirmation from the controller as to whether personal data concerning them are being processed.

If a data subject wishes to exercise this right of confirmation, they may contact our Data Protection Officer or any other employee of the controller at any time.

b) Right of Access

Every data subject affected by the processing of personal data has the right granted by the European legislator to obtain, free of charge and at any time, information about the personal data stored concerning them, as well as a copy of such information.

In addition, the data subject has the right to obtain information about:

  • The purposes of the processing.
  • The categories of personal data being processed.
  • The recipients or categories of recipients to whom the personal data have been or will be disclosed, particularly recipients in third countries or international organizations.
  • Where possible, the planned period for which the personal data will be stored, or, if not possible, the criteria used to determine that period.
  • The existence of the right to rectification or erasure of personal data, restriction of processing, or objection to processing.
  • The existence of a right to lodge a complaint with a supervisory authority.
  • Where personal data are not collected from the data subject, any available information about their source.
  • The existence of automated decision-making, including profiling pursuant to Article 22(1) and (4) GDPR, and meaningful information about the logic involved as well as the significance and envisaged consequences of such processing for the data subject.

Furthermore, the data subject has the right to obtain information as to whether personal data have been transferred to a third country or an international organization. If this is the case, the data subject also has the right to be informed about the appropriate safeguards relating to the transfer.

To exercise this right of access, the data subject may contact our Data Protection Officer or any other employee of the controller at any time.

c) Right to Rectification

Every data subject has the right granted by the European legislator to obtain without undue delay the rectification of inaccurate personal data concerning them.

Taking into account the purposes of the processing, the data subject also has the right to have incomplete personal data completed, including by means of providing a supplementary statement.

To exercise this right, the data subject may contact our Data Protection Officer or any other employee of the controller at any time.

d) Right to Erasure (“Right to be Forgotten”)

Every data subject has the right granted by the European legislator to obtain from the controller the erasure of personal data concerning them without undue delay where one of the following grounds applies and where processing is not required:

  1. The personal data are no longer necessary for the purposes for which they were collected or otherwise processed.
  2. The data subject withdraws consent on which the processing was based under Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, and there is no other legal basis for processing.
  3. The data subject objects to processing pursuant to Article 21(1) GDPR and there are no overriding legitimate grounds for processing, or the data subject objects pursuant to Article 21(2) GDPR.
  4. The personal data have been unlawfully processed.
  5. Erasure is required to comply with a legal obligation under Union or Member State law.
  6. The personal data were collected in relation to information society services pursuant to Article 8(1) GDPR.

If one of the above grounds applies and a data subject wishes to request the deletion of personal data stored by us, they may contact our Data Protection Officer or another employee of the controller at any time. The request will be complied with without undue delay.

Where personal data have been made public and we are obliged pursuant to Article 17(1) GDPR to erase them, we shall take reasonable measures, including technical measures, considering available technology and implementation costs, to inform other controllers processing the published data that the data subject has requested the erasure of all links to, copies of, or replications of those personal data, insofar as processing is not required.

e) Right to Restriction of Processing

Every data subject has the right to obtain restriction of processing where one of the following conditions applies:

  1. The accuracy of the personal data is contested by the data subject for a period enabling the controller to verify the accuracy of the data.
  2. The processing is unlawful and the data subject opposes erasure and requests restriction instead.
  3. The controller no longer needs the personal data for processing purposes, but the data subject requires them for the establishment, exercise, or defense of legal claims.
  4. The data subject has objected to processing under Article 21(1) GDPR and verification is pending as to whether the controller’s legitimate grounds override those of the data subject.

If one of these conditions is met, the data subject may contact our Data Protection Officer or another employee of the controller to request restriction of processing.

f) Right to Data Portability

Every data subject has the right to receive personal data concerning them, which they have provided to a controller, in a structured, commonly used, and machine-readable format.

They also have the right to transmit those data to another controller without hindrance, where:

  • The processing is based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, or on a contract pursuant to Article 6(1)(b) GDPR; and
  • The processing is carried out by automated means.

Furthermore, under Article 20(1) GDPR, the data subject has the right to have personal data transmitted directly from one controller to another where technically feasible and where doing so does not adversely affect the rights and freedoms of others.

To exercise this right, the data subject may contact the Data Protection Officer or another employee.

g) Right to Object

Every data subject has the right, on grounds relating to their particular situation, to object at any time to the processing of personal data concerning them that is based on Article 6(1)(e) or (f) GDPR.

If you have given consent, you may also withdraw that consent at any time with future effect.

If an objection is lodged, we will no longer process the personal data unless we demonstrate compelling legitimate grounds that override the interests, rights, and freedoms of the data subject, or the processing serves the establishment, exercise, or defense of legal claims.

Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to such processing. This also applies to profiling insofar as it relates to direct marketing.

If the data subject objects, we will cease processing the personal data for direct marketing purposes.

The data subject also has the right to object, on grounds relating to their particular situation, to processing carried out for scientific or historical research purposes or statistical purposes pursuant to Article 89(1) GDPR, unless such processing is necessary for the performance of a task carried out in the public interest.

The right to object may be exercised by contacting our Data Protection Officer or any other employee.

h) Automated Individual Decision-Making, Including Profiling

Every data subject has the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them.

This does not apply if the decision:

  • Is necessary for entering into or performing a contract between the data subject and the controller;
  • Is authorized by Union or Member State law containing appropriate safeguards; or
  • Is based on the explicit consent of the data subject.

Where such decisions are necessary for a contract or based on explicit consent, we will implement appropriate measures to safeguard the rights, freedoms, and legitimate interests of the data subject, including at least the right to obtain human intervention, express their point of view, and contest the decision.

To exercise rights relating to automated decision-making, the data subject may contact our Data Protection Officer or another employee at any time.

i) Right to Lodge a Complaint

Every data subject also has the right to lodge a complaint with a supervisory authority regarding our processing of their personal data if they believe that a violation of data protection law has occurred.

A list of supervisory authorities (for the non-public sector), including contact information, can be found at:

https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

8. Recipients of Personal Data / Transfers to Third Countries

Pursuant to Article 4(9) GDPR, recipients of personal data are limited to medic assist GmbH, partner companies directly involved in providing services, and, in individual cases, other authorized recipients such as public authorities or suppliers.

In connection with its services, medic assist GmbH may transfer personal data to the following categories of recipients:

  1. Heartstream US LLC.
    22100 Bothell-Everett Highway
    Bothell, WA 98021, USA
  2. Authorized public authorities.
  3. The partners listed in Section 11 in connection with social media and analytics services.

Except for the company listed above and the providers described in Section 11 (“Social Media, Tools and Analytics Services”), personal data are generally not transferred to third countries.

Where such a transfer is necessary, it is carried out on the basis of the EU-U.S. Data Privacy Framework or the EU Standard Contractual Clauses (SCCs).

9. Statutory or Contractual Requirements for Providing Personal Data; Necessity for Contract Conclusion; Obligation of the Data Subject to Provide Personal Data; Possible Consequences of Failure to Provide Data

We inform you that, in some cases, the provision of personal data is required by law (for example, tax regulations) or may result from contractual provisions (for example, information relating to a contractual partner).

In certain circumstances, it may be necessary for a data subject to provide personal data in order to conclude a contract, after which such data must be processed by us. For example, a data subject is obliged to provide personal data if our company enters into a contract with them.

Failure to provide the required personal data may result in the contract not being concluded with the data subject.

Before providing personal data, the data subject may contact our Data Protection Officer. The Data Protection Officer will inform the data subject on a case-by-case basis whether the provision of personal data is required by law or contract, whether it is necessary for entering into a contract, whether there is an obligation to provide the data, and what consequences may result from a failure to provide the personal data.

10. Subscription to Our Newsletter

Users of our website may, where applicable, be given the opportunity to subscribe to our newsletter.

The personal data transmitted to the controller when subscribing to the newsletter are determined by the input form used for this purpose.

We regularly inform customers and business partners about company offers by means of a newsletter. The newsletter can generally only be received if:

  1. The data subject has a valid email address; and
  2. The data subject has registered to receive the newsletter.

For legal reasons, a confirmation email using the double opt-in procedure is sent to the email address entered for the first time. This confirmation email serves to verify whether the owner of the email address, as the data subject, has authorized receipt of the newsletter.

When subscribing to the newsletter, we also store:

  • The IP address assigned by the Internet Service Provider (ISP) to the computer system used by the data subject at the time of registration.
  • The date and time of registration.

The collection of these data is necessary in order to be able to trace any possible misuse of a data subject’s email address at a later date and therefore serves as legal protection for the controller.

Personal data collected in connection with a newsletter subscription are used solely for sending the newsletter.

In addition, newsletter subscribers may be informed by email if this is necessary for the operation of the newsletter service or related registration, for example in the event of changes to the newsletter offering or changes to technical circumstances.

Personal data collected through the newsletter service will not be disclosed to third parties.

The subscription to our newsletter may be terminated by the data subject at any time.

Consent to the storage of personal data granted for newsletter distribution may be withdrawn at any time. For this purpose, a corresponding unsubscribe link is included in every newsletter.

It is also possible to unsubscribe from the newsletter directly on the website of the controller at any time or to notify the controller of such withdrawal by other means.

11. Social Media, Tools and Analytics Services

Google Web Fonts

This website uses Google Web Fonts, provided by:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

for the uniform display of fonts.

When a page is accessed, your browser loads the required fonts directly from Google’s servers. In this process, your IP address and technical information about your browser are transmitted to Google.

It cannot be ruled out that data may also be transferred to servers operated by Google LLC in the United States.

Processing is carried out exclusively on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Section 25(1) TDDDG, provided that you have granted such consent through our consent management system.

You may withdraw your consent at any time with future effect.

Further information on data protection at Google can be found at:

Google Privacy Information
https://fonts.google.com

Zendesk

To process inquiries, we use the Zendesk ticketing system, a service provided by:

Zendesk, Inc.
181 Fremont Street
San Francisco, CA 94105
USA

In this context, the personal data you provide (for example, your name, email address, and the content of your inquiry) are processed for the purpose of handling and documenting your request.

Processing is carried out on the basis of:

  • 6(1)(b) GDPR (pre-contractual measures or performance of a contract), or
  • 6(1)(f) GDPR (legitimate interest in the efficient processing of inquiries).

Zendesk processes the data on our behalf based on a Data Processing Agreement pursuant to Art. 28 GDPR.

Zendesk states that, when providing its services, it generally acts as a data processor.

Zendesk may transfer data to the United States to provide its services. Such transfers are carried out on the basis of the EU Standard Contractual Clauses (SCCs) together with additional protective measures.

Further information on data protection at Zendesk can be found in Zendesk’s Privacy Notice.

12. No Automated Decision-Making

As a responsible company, we do not use automated individual decision-making.

13. Data Protection Officer

You can contact our Data Protection Officer by email at:

Datenschutzbeauftragter@medicassist.de

14. Changes to Our Privacy Policy

We reserve the right to amend this Privacy Policy to ensure that it always complies with current legal requirements or to reflect changes to our services in this Privacy Policy, for example when introducing new services.

The new Privacy Policy will then apply to your subsequent visits to our website.

Source

German Association for Data Protection (Deutsche Gesellschaft für Datenschutz)
https://dg-datenschutz.de

eRecht24
https://www.e-recht24.de

and other sources.

Privacy Policy Version: July 7, 2026.

Back To Top