FPZ Privacy Policy

Last updated: October 31, 2025

Controller and Data Protection Officer

FPZ GmbH

Gustav-Heinemann-Ufer 88a, 50968 Cologne Phone: +49 221 99 53 00 Fax: +49 221 99 53 08 00 E-mail: info@fpz.de

Data Protection Officer

Dr. Ralf W. Schadowski E-mail: datenschutz@fpz.de

Definitions

The legally binding definitions are those in Articles 4 and 9 GDPR; the following short definitions serve clarity.

  • Personal data: Any information relating to an identified or identifiable natural person (e.g., name, e‑mail, IP address).
  • Processing: Any operation performed on personal data (e.g., collection, storage, use, disclosure, deletion).
  • Controller: The entity that determines the purposes and means of processing (here: FPZ GmbH).
  • Processor: Service providers processing personal data on behalf of the controller (e.g., hosting/IT providers).
  • Recipient: Persons/companies/authorities to whom personal data is disclosed.
  • Third party: Any person/entity outside the controller, the processor and persons acting under their direct authority.
  • Consent: A freely given, informed and unambiguous indication of wishes to permit processing.
  • Pseudonymisation: Processing so that data can no longer be attributed to a person without additional information.
  • Profiling: Any kind of automated processing to evaluate personal aspects (e.g., interests).
  • Special categories (“sensitive data”): e.g., health data (Art. 9 GDPR).
  • End-device information (§ 25 TTDSG): Storing/retrieving information on your device (e.g., cookies, local storage).
  • Third country: A state outside the EEA; transfers there require safeguards (e.g., EU Standard Contractual Clauses).

1 Information on the collection of personal data & legal bases

We process personal data when you visit our website, use forms, contact us, book appointments, make payments or use digital health services (e.g., Mein FPZ).

Categories of personal data (depending on use)

  • Master data (e.g., name, address, e‑mail, phone)
  • Contract/billing data (e.g., booked services, payments, invoices)
  • Communication data (e.g., chat/e‑mail content, timestamps)
  • Usage data (e.g., IP address, device/browser data, referrer, pages viewed)
  • Health data (e.g., for use of Mein FPZ – special categories within Art. 9 GDPR)

Legal bases (Art. 6 GDPR)

  • Art. 6(1)(a) consent – e.g., for analytics/marketing cookies, video/map embeds, newsletter
  • Art. 6(1)(b) contract / pre-contract – e.g., appointment booking, online contracts, payments
  • Art. 6(1)(c) legal obligation – e.g., tax/commercial retention
  • Art. 6(1)(f) legitimate interests – e.g., operation, security and optimisation of the website, customer communication

Special categories (health data)

Processing only with explicit consent (Art. 9(2)(a) GDPR) and/or if necessary to provide health services (Art. 9(2)(h) GDPR).

2 Data deletion & storage duration

We delete or block personal data once the purpose ceases to apply or statutory retention periods expire.

Typical periods (guidance values)

  • Contract, billing and tax-relevant data: 10 years (AO/HGB)
  • General civil claims/correspondence: 3 years (regular limitation)
  • Application documents: 6 months after the process ends
  • Consents & withdrawal logs: until withdrawal (plus proof periods)
  • Server/security logs: usually 90 days
  • Analytics/marketing data: per tool settings, typically 14–26 months or shorter

Specific storage periods may result from special legal requirements (e.g., health/occupational law).

3 Collection of personal data when visiting the website (server logs)

For purely informational use we automatically collect: IP address, date/time, time zone, URL/referrer, HTTP status, transferred data volume, browser/OS, language settings. Purpose: technical provision, stability, IT security (abuse/attack detection). Legal basis: Art. 6(1)(f) GDPR.

4 Cookies, similar technologies & consent management

We use cookies and similar technologies (e.g., local storage) for operation, statistics and marketing. Non-essential technologies are only set with consent.

Cookie legal bases

  • Technically necessary cookies (e.g., session, security, consent status): Art. 6(1)(f) GDPR
  • Analytics/marketing (e.g., GA4, Meta Pixel): Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG
  • Through our cookie consent manager you can see a dynamic list of all cookies incl. purpose, provider and duration; you can change or withdraw your consent at any time.

Our cookie consent manager always shows you the current, dynamic list of all cookies used, including their purpose, provider, and storage period; there you can change or revoke your consent at any time.

5 Contact, forms, online contracts & patient services

When you contact us (via email, form, chat), enter into online contracts, register for therapy, or use the Mein FPZ patient platform, we process the data you provide (e.g. name, email, telephone number, address, health insurance company, insurance number, program/appointment). Purpose: Processing your request, contract initiation/fulfillment, customer communication. Legal basis: Art. 6(1)(b) or (f) GDPR; for health data, Art. 9 GDPR (see above).

6 Tools & platforms used

We use selected tools for communication, forms, booking, payments, CRM and patient services as described below.

6.1 Simpli (Live chat & WhatsApp AI)

For fast customer communication we use Simpli (web chat and optional WhatsApp integration). Data: chat content, communication metadata (IP, timestamps, browser), possibly phone number/WhatsApp ID. Purpose: support, handling requests. Legal basis: Art. 6(1)(a) (consent in banner/chat) and/or Art. 6(1)(f) (legitimate interest in efficient support). Note: WhatsApp may carry out its own transfers; please see WhatsApp privacy info in the chat UI. Privacy:https://www.simpli.io/de/privacy

6.2 Jotform (online contracts/forms)

For digital applications/contracts we use Jotform. Data: form contents (e.g., name, address, contact, contract data/uploads). Legal basis: Art. 6(1)(b) GDPR (contract/pre-contract) and/or Art. 6(1)(a) (consent, if required). Privacy:https://www.jotform.com/privacy/

6.3 Calendly (appointment booking)

For online appointment scheduling we use Calendly. Data: name, e‑mail, phone number, appointment details, free text. Legal basis: Art. 6(1)(b) GDPR; transfers to third countries see section 10. Privacy:https://calendly.com/privacy

6.4 Stripe (payment processing)

For paid services we use Stripe. Data: payment/card and transaction data. Purpose: payment processing, fulfilment of contractual and legal obligations. Legal basis: Art. 6(1)(b) (payment), Art. 6(1)(c) (legal obligations). Privacy:https://stripe.com/de/privacy

6.5 Zoho CRM (customer management)

We use Zoho CRM (EU storage). Data: contact data, interactions, notes, documents where applicable. Legal basis: Art. 6(1)(b) (customer relationship) and Art. 6(1)(f) (efficient customer management). Privacy:https://www.zoho.com/privacy.html

6.6 FPZ patient platform “Mein FPZ”

Own protected platform for digital health courses and therapy programmes. Data: registration/login data, course/therapy data; health data where required. Legal basis: Art. 6(1)(b) GDPR; Art. 9(2)(a) (explicit consent) and, where applicable, Art. 9(2)(h). Storage: servers in Germany; access only for authorised staff and processors.

7 Analytics, embeds & marketing

We use analytics and marketing tools as described here.

7.1 Google Analytics 4 (GA4)

We use GA4 for reach measurement and website optimisation. IP anonymisation is applied. Data: e.g., device/browser info, interactions, approximate location (no precise geolocation). Legal basis: Art. 6(1)(a) GDPR (only after consent via consent banner). Privacy:https://policies.google.com/privacy

Opt-out:https://tools.google.com/dlpage/gaoptout

7.2 Google Tag Manager (GTM)

GTM manages tags/scripts. GTM sets no own cookies and does not process personal data beyond firing tags. Legal basis: Art. 6(1)(f) GDPR (efficient management); tags themselves follow their own legal basis (e.g., consent). Privacy:https://marketingplatform.google.com/about/tag-manager/

7.3 Google Web Fonts

Google Web Fonts are integrated to ensure uniform display. When accessed, your IP address may be transmitted to Google. Legal basis: Art. 6 (1) lit. f GDPR (appropriate presentation). Note: Where possible, we use local integration for further data economy. Info:https://developers.google.com/fonts/faq

7.4 YouTube & Vimeo (videos)

Videos load only after your activation (2-click/consent). Legal basis: Art. 6(1)(a) GDPR (consent). When playing, data (e.g., IP, device info, referrer) is sent to the provider. Privacy: Google/YouTube:https://policies.google.com/privacy

Vimeo:https://vimeo.com/privacy

7.5 Meta (Facebook) Pixel & Conversion API

We use the Meta Pixel and, where applicable, the Conversion API to measure the effectiveness of our advertisements and to form target groups (custom audiences). Data: e.g., page views, events (lead/complete registration), IP, device/browser data, hashed email address if applicable. Legal basis: Art. 6(1)(f) GDPR i.v.m. § 25(1) TTDSG (only with consent). Note: The provider is Meta Platforms; data may be transferred to the USA. Opt-out:https://www.facebook.com/settings/?tab=ads

Data protection:https://www.facebook.com/privacy/policy

7.6 Google Ads / Remarketing (formerly DoubleClick/Display & Video 360) – if activated

Cookies/pixels may be set to measure the reach/optimize digital campaigns. Legal basis: Art. 6 (1) (a) GDPR i.V.M. § 25 (1) TTDSG (only with consent). Opt-out:https://adssettings.google.com/

7.7 New Relic (performance monitoring) – if enabled

Collects aggregated performance data (e.g., load times, error codes) for troubleshooting and stability. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable website); where cookies/similar tech are used, only after consent. Privacy:https://newrelic.com/termsandconditions/privacy

8 Newsletter (double opt-in)

When subscribing we store your e‑mail address, optionally your name, and IP/timestamps for proof. Legal basis: Art. 6(1)(a) GDPR (consent). Withdrawal: possible at any time via the unsubscribe link in every e‑mail.

9 Recipients, processing on behalf & third-country transfers

We use processors (e.g., hosting, IT support, tools) under Art. 28 GDPR, contractually bound to instructions. Transfers to third countries (e.g., USA with Google, Meta, Calendly, Stripe, possibly Jotform/Zoho) occur only with an adequacy decision (e.g., EU-US Data Privacy Framework) or appropriate safeguards under Art. 46 GDPR (esp. EU SCCs); we apply additional protections (e.g., encryption, data minimisation).

10 Rights of data subjects

In accordance with the GDPR, you have the right at any time to:

  • Information (Art. 15) about the personal data processed,
  • Rectification (Art. 16) of inaccurate data,
  • Erasure (Art. 17),
  • Restriction of processing (Art. 18),
  • Data portability (Art. 20),
  • Objection (Art. 21) to processing based on Art. 6(1)(f),
  • Withdrawal of consent (Art. 7(3)) with effect for the future.

Right to lodge a complaint: You can lodge a complaint with a data protection supervisory authority, e.g.: State Commissioner for Data Protection and Freedom of Information NRW, Kavalleriestraße 2-4, 40213 Düsseldorf, The State Commissioner is looking for reinforcement.http://www.ldi.nrw.de/

11 Automated decision-making / profiling

There is no automated decision-making within the meaning of Art. 22 GDPR and no profiling with legal effect – except, where applicable, marketing segmentation within the scope of the tools described in Section 8, exclusively with your consent.

12 IT Security, Encryption & Hosting

We use TLS encryption (HTTPS), role-based access, logging, and regular security updates. The website is operated by a European hosting service provider; log/security data is only processed for the purposes stated (see section 4).

13 Obligation to provide data

The processing of technically necessary data is required to provide the website. For contractual services (e.g., appointment booking, payments, patient platform), the mandatory information requested in each case is required; without this information, the service cannot be provided. Consent is voluntary and can be revoked at any time (see section 10).

14 Changes to this privacy policy

We adapt this privacy policy when legal, technical or organisational circumstances change.