Note: This English page is a translation provided for convenience. The German version (Datenschutzerklärung) is the legally binding one.

Praxis Godau — www.praxis-godau.de

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Polina Godau, M.A. Psych.
Practice for psychodynamic psychotherapy and psychoanalysis
Jüterboger Str. 6, 10965 Berlin
Phone: +49 30 984 286 20
Email: praxis.godau@protonmail.com
Website: www.praxis-godau.de

2. Special categories of personal data (health data)

In the course of my work as a psychological psychotherapist, I process particularly sensitive personal data within the meaning of Art. 9 (1) GDPR in connection with the treatment of my patients, in particular health data. This processing takes place exclusively for the purpose of psychotherapeutic treatment and the associated billing.

The legal basis for this is Art. 9 (2) (h) GDPR in conjunction with Section 22 (1) no. 1 (b) of the German Federal Data Protection Act (BDSG) (processing for the purposes of preventive healthcare and medical diagnosis), as well as Art. 6 (1) (b) GDPR insofar as the processing is necessary for the performance of the treatment contract.

As a psychological psychotherapist, I am subject to the statutory duty of confidentiality under Section 203 of the German Criminal Code (StGB). All information that becomes known to me in the course of treatment is treated as strictly confidential and is only passed on to third parties (e.g. health insurers for billing purposes) with your express consent or on the basis of a legal obligation.

3. Retention of treatment records

Your patient file is retained for a period of 10 years after the end of treatment. This period follows from the documentation obligations under professional law and from Section 630f of the German Civil Code (BGB). After this period expires, the records are deleted or destroyed in accordance with data protection law.

4. Retention of business records

Independently of the treatment records referred to in section 3, I retain business records such as invoices and accounting documents in accordance with the statutory retention periods under Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO), generally for a period of 6 to 10 years. After these periods expire, the records are deleted or destroyed.

5. Website hosting

This website is hosted by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner. Data processing takes place exclusively in Germany; no data is transferred to third countries.

This website collects no visitor data: no access logs are written. Technical errors (e.g. faulty requests or server problems) are recorded in an error log used solely for fault diagnosis. These entries generally contain the IP address of the requesting device and the error type; they are deleted automatically after 14 days at the latest and are not analysed. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the secure and stable operation of the website).

6. Cookies, storage and external content

This website uses no cookies and no client-side storage. No analytics, advertising or tracking services and no third-party content are embedded; fonts, too, are loaded locally from this website. Visiting the website therefore establishes no connections to third-party providers. For this reason, no cookie banner is required.

This website contains links to external websites and services (e.g. eterminservice.de, OpenStreetMap). Only when you open such a link do the privacy terms of the respective provider apply.

This website embeds no map services. On the contact page I merely link to OpenStreetMap; only when you open this link do the privacy terms of that provider (OpenStreetMap Foundation) apply.

8. Appointment booking via the 116117 Terminservice

For online appointment booking I link to the external 116117 Terminservice (www.116117-termine.de, formerly eterminservice.de) of the National Association of Statutory Health Insurance Physicians (Kassenärztliche Bundesvereinigung, KBV), technically operated by kv.digital GmbH, Berlin. If you use this service, its own privacy terms apply; the data you enter there (e.g. name, contact details, requested appointment) is processed by me for the purpose of organising appointments. The legal basis is Art. 6 (1) (b) GDPR (pre-contractual measures or performance of a contract).

9. Communication by email

If you contact me by email, I process the transmitted data (email address, name, message content) exclusively to handle your enquiry; it is not passed on to third parties. The legal basis is Art. 6 (1) (b) or (f) GDPR. The correspondence is deleted as soon as it is no longer required for its purpose; statutory retention periods (see sections 3 and 4) remain unaffected.

For email communication I use the provider Proton Mail (Proton AG, Switzerland). Please note that an unencrypted email generally offers no complete protection against access by third parties. For particularly sensitive information, I recommend conveying it in person rather than by email.

10. Online sessions (video)

If you receive treatment via video session, it takes place via the video consultation service of Epikur Software GmbH & Co. KG, Franklinstraße 26 a, 10587 Berlin. Epikur is practice software designed for the processing of health data that meets the requirements for secure, encrypted transmission in the context of video treatment. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider. Further information on data processing by Epikur can be found in its own privacy policy, which I will provide on request.

11. Your rights as a data subject

Under the GDPR you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing (Art. 21). You may withdraw any consent you have given at any time with effect for the future. Please use the contact details given above for this purpose.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular with the authority responsible for Berlin: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstr. 219, 10969 Berlin, www.datenschutz-berlin.de.

12. Automated decision-making

No automated decision-making, including profiling, takes place.