Privacy aidminutes.anamnesis– Last updated: July 21, 2026 –

I. General Information

This notice applies to the use of “aidminutes.anamnesis” (“App”). The manufacturer of the App and thus the controller within the meaning of Art. 4 No. 7 of the EU General Data Protection Regulation (GDPR) is:

aidminutes.org gUG (haftungsbeschränkt), ℅ Philipp Geisler, Dillstr. 20, 20146 Hamburg, Germany, Tel.: +49 (0) 160 6992976, e-mail: support@aidminutes.org

Please direct all inquiries regarding the processing of (personal) data to this contact.

II. Data Protection Officer

The person responsible for data protection can be reached at privacy@aidminutes.org.
Contact details of the state data protection authority:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
(The Hamburg Commissioner for Data Protection and Freedom of Information)
Ludwig-Erhard-Str. 22
20459 Hamburg
Tel: +49 (0) 40 428 54 - 4040
Fax: +49 (0) 40 428 54 - 4000
E-mail: mailbox@datenschutz.hamburg.de

III. Your Rights

As a data subject, you may assert the following rights against the controller. Please use the contact details provided under Section “I. General Information” for this purpose.

1. Right of Confirmation and Access, Art. 15 GDPR

You may request confirmation as to whether personal data concerning you is being processed. If confirmed, you may request information about the origin of the data, the purpose of the processing, the duration of storage, the recipients, and your rights.

2. Right to Rectification and/or Completion, Art. 16 GDPR

If the personal data concerning you is inaccurate or incomplete, you may request its rectification and/or completion. The controller must then carry out the rectification/completion without undue delay and will inform you accordingly.

3. Right to Erasure (“Right to Be Forgotten”), Art. 17 GDPR

You may request the immediate erasure of personal data concerning you if

  • the data is no longer needed
  • consent has been withdrawn
  • you have objected to the data processing
  • the data was collected unlawfully
  • the controller is legally obliged to erase the data
  • the data was collected and processed pursuant to Art. 8 (1) GDPR

The right to erasure does not apply if the following rights and obligations take precedence:

  • freedom of expression and information
  • compliance with a legal obligation and the establishment of legal claims
  • tasks carried out in the public interest, in particular public health pursuant to Art. 9 (2) lit. h and i and Art. 9 (3) GDPR
  • archiving purposes in the public interest
  • scientific or historical research purposes
  • statistical purposes
  • the exercise of official authority vested in the controller

4. Right to Restriction of Processing, Art. 18 GDPR

A temporary or permanent restriction of data processing may be considered

  • if you have contested the accuracy of the data and this is still being verified
  • instead of erasure, if data was collected unlawfully
  • if you need the data to establish, exercise, or defend legal claims
  • if the legitimacy of an objection you have lodged pursuant to Art. 21 GDPR is still being verified

The controller will inform you of the restriction and its lifting. After the restriction, your data may continue to be stored but may only be processed in the following cases:

  • consent has been given
  • legal claims are to be established, exercised, or defended
  • for the protection of another person
  • there is an important public interest of the EU and/or a Member State

5. Right to Notification, Art. 19 GDPR

If you have asserted your rights pursuant to Art. 16 to 18 GDPR (rectification, erasure, restriction of processing), the controller is obliged to communicate this to all recipients to whom the data has been disclosed, unless this proves impossible or involves disproportionate effort. You have the right to be informed about these recipients.

6. Right to Data Portability, Art. 20 GDPR

The controller must provide you with the personal data concerning you in a structured, commonly used, and machine-readable format. The unhindered transmission of this data to another controller must be ensured, provided that

  • the processing is based on consent (Art. 6 (1) lit. a or Art. 9 (2) lit. a GDPR) and/or
  • the processing is carried out for the performance of a contract or pre-contractual measures (Art. 6 (1) lit. b GDPR) and
  • the processing is carried out by automated means

The freedoms and rights of other persons must not be adversely affected. The right to data portability does not apply to data processing

  • necessary for the performance of a task carried out in the public interest
  • in the exercise of official authority vested in the controller

You may request that the data be transmitted directly to another controller, insofar as this is technically feasible.

7. Right to Object, Art. 21 GDPR

You may object at any time if the data processing

  • is based on Art. 6 (1) lit. f GDPR or
  • serves direct marketing purposes or
  • is carried out for scientific or historical research purposes or statistical purposes pursuant to Art. 89 (1) GDPR

The same applies to any related profiling. The objection must be justified. It is sufficient to state as a reason that you no longer wish your data to be processed. Following the objection, the data will no longer be processed.
The controller may continue to process the data despite your objection if

  • there are compelling legitimate grounds for the processing that override your interests, rights, and freedoms or
  • the processing serves to establish, exercise, or defend legal claims or
  • in the case of processing pursuant to Art. 89 (1) GDPR: the processing is necessary for the performance of a task carried out in the public interest.

In the context of the use of information society services, you may also exercise your objection by automated means using technical specifications.

8. Right to Withdraw Consent, Art. 7 (3) GDPR

You may withdraw your consent under data protection law in its entirety at any time with effect for the future. The lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal remains unaffected.

9. Automated Individual Decision-Making, Including Profiling, Art. 22 GDPR

You have the right not to be subject to a decision based on automated processing if this decision produces legal effects concerning you or similarly significantly affects you. The same applies to profiling.

This right is not subject to any restrictions if the decision is based on special categories of personal data pursuant to Art. 9 (1) GDPR, e.g. data concerning political opinions, religious or philosophical beliefs, genetic or biometric data, as well as health data or data concerning a person’s sex life or sexual orientation.

However, if you have consented to the automated processing and neither Union law nor the law of a Member State prohibits such consent (Art. 9 (2) lit. a GDPR), or if the processing is necessary for reasons of substantial public interest (Art. 9 (2) lit. g GDPR), your right may be excluded as described below, even if special categories of personal data are processed.

This right does not apply if the decision based on automated processing

  • is necessary for entering into, or the performance of, a contract between you and the controller or
  • is authorised by Union and/or Member State law and
  • that law lays down suitable measures to safeguard your rights, freedoms, and legitimate interests or
  • is based on your explicit consent

In the first-mentioned and the last-mentioned case of an exclusion of the right described here, the controller will implement suitable measures to safeguard your other rights, freedoms, and legitimate interests. This includes in particular the right to obtain human intervention on the part of the controller, to express your own point of view, and to contest the decision.

10. Right to Lodge a Complaint with a Supervisory Authority, Art. 77 GDPR

You have the right to lodge a complaint with a supervisory authority if you consider that the processing of personal data concerning you infringes data protection regulations. The supervisory authority with which the complaint has been lodged will inform you of the status and outcome of the complaint, including the possible legal remedies (in particular Art. 78 GDPR). For more detailed information on the respective competencies, please contact:

Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit
(The Federal Commissioner for Data Protection and Freedom of Information)
Graurheindorfer Str. 153
53117 Bonn
Tel: +49 (0) 228 997799 - 0
E-mail: poststelle@bfdi.bund.de
De-Mail: poststelle@bfdi.de-mail.de
Web: bfdi.bund.de

IV. Processing Operations

We process (personal) data in the following cases:

1. Sentry

To reconstruct potential errors or crashes in the App, we use the service Sentry. The following data is collected and processed:

  • operating system
  • device ID
  • content version
  • release version
  • app version
  • time of publication of the App
  • license information

Provider: Functional Software Inc.
Address: 132 Hawthorne St, San Francisco, CA 94107, USA
Web: sentry.io
Privacy: sentry.io/privacy

Legal basis for processing: Art. 6 (1) lit. b GDPR, Art. 6 (1) lit. f GDPR

2. Aptabase

We use the service Aptabase for the anonymised statistical analysis of App usage in order to further improve the App both in terms of content and technology based on the insights gained.

All data used for analysis is fully anonymised. No personal data is collected in the process. Consent to the data collection is therefore not required.

Aptabase does not pass on usage-related data to other sub-processors or third parties and does not use it for its own purposes. The data is stored on servers within the EU.

Provider: Sumbit Labs Limited
Address: 51 Bracken Road, Sandyford Dublin D18 CV48, Ireland
Web: aptabase.com
Privacy: aptabase.com/legal/privacy

Legal basis for processing: Art. 6 (1) lit. a GDPR

3. RevenueCat

For the management and analysis of in-app subscriptions and purchases, aidminutes uses the service RevenueCat provided by Revenue Cat, Inc. (hereinafter “RevenueCat”), located at

633 Taraval St. Suite 101
San Francisco, CA 94116
USA

The transfer of data takes place in accordance with the provisions of Art. 46 GDPR. The data is stored and processed by RevenueCat and prepared in a web-based interface. RevenueCat stores the data in the USA or Europe and subjects itself to the EU GDPR (EU 2016/679) by way of a DPA: revenuecat.com/dpa.

By concluding an in-app subscription or an in-app purchase, you consent to the data collection by aidminutes and the transfer to RevenueCat.

To have your own data deleted from RevenueCat’s database, you can send an e-mail to support@aidminutes.org (with the note “Deletion of my data at RevenueCat”). If this is not done, the data will be deleted no later than after the statutory retention periods have expired.

Reference is made to RevenueCat’s Terms of Service and Privacy Policy:

Terms of Service: revenuecat.com/terms.
Privacy Policy: revenuecat.com/privacy.

The data stored by RevenueCat and prepared for analysis can be viewed at the following link: revenuecat.com/dpa.

4. Appwrite

The App uses the backend service Appwrite to process activation codes for individual license offers. No personal data is transferred to Appwrite in this process.

Provider: Appwrite
Address: Hamerkaz 98473737, Tel Aviv, Israel
Web: appwrite.io
GDPR: appwrite.io/docs/advanced/security/gdpr
Privacy: appwrite.io/privacy

5. DigitalOcean (Hosting)

Parts of the app, or its backend, run on the infrastructure of the provider DigitalOcean (hosting). DigitalOcean provides the servers on which the app is executed and on which the data required for its provision is stored and processed. As a processor within the meaning of Art. 28 GDPR, DigitalOcean processes all data that is transmitted to the servers, or stored on them, for the purpose of providing the app; this includes in particular IP addresses in server log files as well as the content and connection data arising in the course of use. A data processing agreement is in place with DigitalOcean.

To provide the platform, DigitalOcean in turn engages sub-processors. For the App Platform, an integrated content delivery network (CDN) with upstream security functions provided by the sub-processor Cloudflare, Inc. (USA) is used by default. In this context, data traffic is routed through Cloudflare’s network, in the course of which technically necessary cookies may be set. This includes in particular the “__cf_bm” cookie, which serves bot detection, contains an encrypted assessment value (bot score) and expires after 30 minutes of inactivity. This cookie serves exclusively security and provisioning purposes and is technically necessary within the meaning of Section 25(2) TDDDG.

The server location is Frankfurt am Main. Since both DigitalOcean, LLC and Cloudflare, Inc. are US companies, access from the USA cannot be ruled out. Both DigitalOcean, LLC and Cloudflare, Inc. are certified under the EU-US Data Privacy Framework (DPF); in addition, Standard Contractual Clauses pursuant to Art. 46 GDPR are in place.

Provider: DigitalOcean, LLC
Address: 101 Avenue of the Americas, 10th Floor, New York, NY 10013, USA
Web: digitalocean.com
Privacy: digitalocean.com/legal/privacy-policy
Data processing (DPA): digitalocean.com/legal/data-processing-agreement
Sub-processors: digitalocean.com/trust/subprocessors
GDPR: digitalocean.com/trust/gdpr-at-do

Legal basis for processing: Art. 6(1)(f) GDPR

6. University Medical Center Göttingen

For the implementation of a medical health services research project, a data processing agreement exists between aidminutes and the Institute of General Practice, University Medical Center Göttingen (Universitätsmedizin Göttingen).

aidminutes.org gUG ensures and warrants that only with your explicit consent (opt-in) will non-personal, anonymous data from the use of the App be forwarded to the Institute of General Practice, University Medical Center Göttingen, exclusively for this research purpose.

Consent is given within the App by selecting the option “Yes, anonymous data from my practice may be used for the research project” (opt-in). This consent can be withdrawn at any time via the menu item “Account” or given at a later time. Please note that a withdrawal of consent cannot be applied retroactively to already existing data due to its anonymous nature.

An ethics opinion by the Ethics Committee of the University Medical Center Göttingen is available for the research project (application number 4/8/24).

The controller is:

Universitätsmedizin Göttingen
- Data Protection Officer -
37099 Göttingen
Phone: +49 (0)551 3962762
E-mail: datenschutz@med.uni-goettingen.de

The data protection supervisory authority responsible for the UMG is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
(The State Commissioner for Data Protection of Lower Saxony)
Prinzenstraße 5
30159 Hannover
Phone: +49 (0)511 120 45 00
Fax: +49 (0)511 120 45 99
E-mail: aidminutes.org/poststelle@lfd.niedersachsen.de