Privacy Policy
In the following, we inform you about the processing of personal data when you use our website and the services offered on it. We treat your personal data confidentially and in accordance with applicable data protection laws and this Privacy Policy.
§1. Controller and Data Protection Officer
The controller within the meaning of Art. 4(7) GDPR is:
The Body Clinic – leichter leben GmbHSchöneberger Ufer 71
10785 Berlin
Germany
Email: [email protected]
Our Data Protection Officer is Verena Dohms. You can contact her at [email protected].
§2. Purposes of Processing and Legal Bases
1. Informational Use of the Website
If you use our website for informational purposes only, we process certain data that your browser automatically transmits to our web server with each request. This includes, in particular, the IP address currently assigned to your device, the date and time of the request, the time zone, the specific page or file requested, the HTTP status code, and the amount of data transferred, as well as the website from which your request originated, the browser used, the operating system of your device, and your language settings.
We process this data to enable your use of our website, to ensure the long-term security and stability of our systems, to administer our network infrastructure, and to optimize our online offering. The legal basis is our legitimate interest pursuant to Art. 6(1)(f) GDPR.
In addition, this data is evaluated solely for internal statistical purposes and to improve our offering. It is subsequently deleted, at the latest after one year, unless longer storage is required for security reasons or due to legal obligations.
We also use cookies and third-party services when you visit our website. Further information can be found in §5.
2. Contacting Us
If you use a button on our website to book an appointment online, you may be redirected to a booking page provided by an appointment scheduling service. In this case, the information under §2(4) also applies.
If you contact us by email, postal mail, telephone, or via our contact form, we process the following data:
- your contact details, depending on the method of contact, in particular your email address, name, address, or telephone number,
- personal data that you provide to us as part of your inquiry.
This data is processed exclusively for the purpose of corresponding with you and handling your request. The legal basis is our legitimate interest in being able to process your request, Art. 6(1)(f) GDPR. If your inquiry is aimed at entering into or performing a contract, Art. 6(1)(b) GDPR is an additional legal basis.
If your inquiry contains special categories of personal data, such as health data, we process this data based on your explicit consent pursuant to Art. 9(2)(a) GDPR or, where applicable, for the purpose of taking pre-contractual steps or performing contractual measures in connection with our services.
Once the processing of your request is no longer necessary, your personal data will be deleted, unless statutory retention obligations prevent deletion.
Please note that communication by unencrypted email, meaning without end-to-end encryption, always involves the risk that unauthorized third parties may gain access to the transmitted data during transmission and potentially use it for their own purposes. If you wish to avoid this risk, please send us your inquiries, especially when transmitting health data, via our contact form or by postal mail.
3. Newsletter
If you subscribe to our newsletter, we process your email address in order to send you marketing and promotional information. If you have additionally provided consent, we may also process further personal data, such as your name, gender, age, postal code, or topic preferences, in order to address you personally in the newsletter and provide content that is individually relevant to you.
The legal basis for this processing is your explicit consent pursuant to Art. 6(1)(a) GDPR. If, in exceptional cases, special categories of personal data, in particular health data, are processed, this is done only on the basis of your explicit consent pursuant to Art. 9(2)(a) GDPR.
We use a double opt-in procedure for the newsletter. After you subscribe, you will receive a confirmation email with a verification link. Your subscription will only be completed, and you will only receive our newsletter, once you have confirmed your subscription.
For sending newsletters, we use Mailchimp, a service provided by The Rocket Science Group LLC d/b/a Mailchimp, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA, which is part of the Intuit group of companies. Mailchimp processes newsletter data on our behalf pursuant to Art. 28 GDPR. A transfer of personal data to the United States cannot be excluded. Intuit Inc. is certified under the EU-U.S. Data Privacy Framework. In addition, where required, Mailchimp relies on the EU Standard Contractual Clauses for international data transfers.
As a general rule, we do not transmit health data to Mailchimp unless a separate legal basis and appropriate contractual and technical safeguards are in place.
You may withdraw your consent at any time with effect for the future, either via the unsubscribe link in the newsletter or by notifying the controller.
4. Appointment Scheduling, Health Questionnaire, Online Forms, and Initial Consultation
If you are interested in our services and schedule an appointment with us, we store the personal data collected in this context, in particular your name and contact details as well as the details of your request, in order to provide our service to you and fulfill our contractual or pre-contractual obligations. The legal basis for processing your personal data is Art. 6(1)(b) GDPR.
In this context, we also process special categories of personal data, in particular information about your health, which we collect from you via a questionnaire, online forms, and/or during the initial consultation. The purpose of this processing is to offer or arrange further services, in particular medical consultation, medical assessment, coaching, or nutrition counseling. The processing of special categories of personal data is based on your explicit consent pursuant to Art. 9(2)(a) GDPR.
Appointment scheduling for free initial consultations and nutrition coaching may be carried out via the online appointment scheduling service Calendly, provided by Calendly LLC, 115 E Main St., Ste A1B PMB 123, Buford, GA 30518, USA. Calendly processes the data required for appointment booking, in particular name, email address, telephone number where applicable, and preferred appointment time, on our behalf pursuant to Art. 28 GDPR. When using Calendly, data may be transferred to the United States. Calendly is certified under the EU-U.S. Data Privacy Framework and, where required, also relies on the EU Standard Contractual Clauses. Further information about Calendly’s data processing can be found at: https://calendly.com/legal/privacy-notice.
Appointment scheduling for medical consultations is carried out via Doctolib. Please note that you may need a Doctolib account to schedule an appointment. If you create or already have a Doctolib account and book an appointment through the platform, Doctolib is independently responsible for processing your personal data in connection with your Doctolib account within the meaning of Art. 4(7) GDPR. Please refer to Doctolib’s privacy policy in this regard.
For certain online forms, in particular for eligibility checks, program extensions, or the structured submission of information, we use Typeform. The provider is Typeform SL, Via Augusta 29-31, 08006 Barcelona, Spain. Typeform processes the data submitted via the respective form on our behalf pursuant to Art. 28 GDPR.
Depending on the form, the processed data may include, in particular, your name, contact details, information about your request, and health-related information. The processing is carried out to handle your inquiry, assess eligibility for our services, and take pre-contractual or contractual steps on the basis of Art. 6(1)(b) GDPR. Where special categories of personal data, in particular health data, are involved, processing is based on your explicit consent pursuant to Art. 9(2)(a) GDPR. Further information about Typeform’s data processing can be found at: https://www.typeform.com/privacy/.
5. Patient Service, Reminders, and Postal Delivery
We aim to support you as well as possible throughout your program. For this purpose, we use:
- your email address to send you appointment and program reminders, notices about missing documents, such as medical findings or health questionnaires, and treatment-related service information, such as aftercare tips. The processing is based on Art. 6(1)(b) GDPR. Where this concerns communication with existing customers, § 7(3) of the German Act Against Unfair Competition (UWG) may also apply. You may object to this at any time; an unsubscribe link is included in every email.
- your postal address to send you informational materials, goodie bags, and, depending on the medication, any needles required for use by postal mail. The legal basis is Art. 6(1)(b) GDPR.
Any further use of your data for marketing newsletters will only take place with your explicit consent; please see the “Newsletter” section.
6. Payment Processing and Billing
If you use a paid service, we use the payment service provider Adyen to process your payments. The provider is Adyen N.V., Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, Netherlands.
Via the integrated payment form, the payment service provider collects the personal data required for the payment process, in particular billing data and bank or payment data. In this case, the payment service provider is independently responsible for the data processing. Further information about the processing of your personal data by the payment service provider can be found in Adyen’s privacy policy: https://www.adyen.com/de_DE/privacy-policy.
7. Prescription Transmission
If you instruct us to transmit medical prescriptions to a pharmacy of your choice, we process your prescription data and the transmission data required for this purpose on the basis of your consent pursuant to Art. 6(1)(a) GDPR and Art. 9(2)(a) GDPR.
We store this data and delete it afterward unless we are legally required to retain it for a longer period. The transmission of your prescription data to the pharmacy you have selected is also based on your consent pursuant to Art. 6(1)(a) GDPR and Art. 9(2)(a) GDPR.
In this context, we also use the qualified electronic signature solution provided by YOUSIGN SAS, Rue de Suède Avenue Pierre Berthelot, 14000 Caen, France, in order to carry out the transmission process in a privacy-compliant and secure manner. Data processing by Yousign takes place exclusively as part of your instruction and for the purpose of securely and traceably transmitting the medical prescription to the pharmacy. Further information about data processing by Yousign can be found in Yousign’s privacy policy: https://yousign.com/de-de/datenschutz.
§3. Recipients of Personal Data
We only disclose your personal data to third parties if you have given your consent, Art. 6(1)(a) GDPR and Art. 9(2)(a) GDPR, if this is necessary to provide our services, Art. 6(1)(b) GDPR, or if we are otherwise legally obligated or authorized to disclose your data.
If, following your appointment with us, medical and/or nutrition-related support is indicated and you wish to schedule an appointment with one of our partner physicians or coaches, we will transmit your personal data, including your health data from the questionnaire and our appointment, to the partner physicians and/or coaches. The transfer of data takes place to fulfill our contractual obligations toward you pursuant to Art. 6(1)(b) GDPR and on the basis of your consent where special categories of personal data, in particular health data, are involved, Art. 6(1)(a) GDPR and Art. 9(2)(a) GDPR.
The respective physician or coach will then process your personal data under their own responsibility. In this regard, we refer you to the privacy policy of the respective physician or coach, which they will be happy to provide to you. Without your consent, we cannot offer you the corresponding service.
If you have received a digital prescription, we transmit the prescription data to the pharmacy of your choice so that the prescription can be filled. The transmission is encrypted. The legal basis for transmitting your data is also your consent pursuant to Art. 6(1)(a) GDPR and Art. 9(2)(a) GDPR.
Where we use service providers to operate our website or provide our services, and those service providers process personal data on our behalf as processors pursuant to Art. 28 GDPR, they may be recipients of your personal data. We use processors, in particular, in the areas of hosting, data storage, software use, appointment management, form processing, newsletter distribution, electronic signatures, and shipping.
These service providers may include, in particular:
- Doctolib GmbH, Mehringdamm 51, 10961 Berlin, Germany, for appointment management and medical appointment booking,
- Calendly LLC, 115 E Main St., Ste A1B PMB 123, Buford, GA 30518, USA, for online appointment booking,
- Typeform SL, Via Augusta 29-31, 08006 Barcelona, Spain, for online forms,
- YOUSIGN SAS, Rue de Suède Avenue Pierre Berthelot, 14000 Caen, France, for qualified electronic signatures in connection with prescription transmission,
- The Rocket Science Group LLC d/b/a Mailchimp, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA, for sending newsletters,
- Adyen N.V., Simon Carmiggeltstraat 6-50, 1011 DJ Amsterdam, Netherlands, for payment processing,
- commissioned shipping service providers, such as Deutsche Post AG or DHL Paket GmbH, for sending informational materials, goodie bags, needles, and other correspondence.
Where personal data is transferred to third countries, in particular to the United States, this takes place on the basis of appropriate safeguards, in particular an adequacy decision by the European Commission, certification under the EU-U.S. Data Privacy Framework, and/or the EU Standard Contractual Clauses.
We will be happy to provide you with a complete list of our current processors upon request. The service providers have been and will be carefully selected and commissioned in writing. They are strictly bound by our instructions and are regularly monitored. Your personal data will not be disclosed to third parties or processed outside the existing processor relationship by the service providers unless there is a separate legal basis for doing so.
§4. Storage Period
We store your personal data only for as long as is necessary to perform and process the services you have requested, unless more specific provisions are set out above or we are entitled or obligated to store the data for a longer period on the basis of your consent or legal obligations. This may include, in particular, retention obligations under commercial, tax, professional, or medical law.
§5. Cookies and Similar Technologies
We use cookies and similar technologies on our website. These are small files or other pieces of information that may be stored on or read from your device when you visit our site. Cookies do not harm your device and do not contain viruses, Trojans, or other malware.
Depending on the storage period, a distinction is made between transient cookies, which are deleted when you close your browser or log out, and persistent cookies, which are deleted only after a predefined period of time.
The use of technically necessary cookies and similar technologies serves to technically enable the display of the website, provide security functions, store selected privacy settings, and enable required support or booking functions. The legal basis for accessing your device is § 25(2) TDDDG. The legal basis for the subsequent processing of personal data is our legitimate interest pursuant to Art. 6(1)(f) GDPR.
In addition, we use cookies and similar technologies to statistically record the use of our website, optimize our offering, measure the success of our advertising measures, and display interest-based advertising to you. We use these technologies only after you have given your consent via our cookie consent tool. The legal basis for accessing your device is § 25(1) TDDDG. The legal basis for the subsequent processing of personal data is Art. 6(1)(a) GDPR.
You may withdraw your consent at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal. You can change your cookie settings at any time via the cookie consent tool. You can also configure your browser so that no cookies are stored or so that a notice always appears before a new cookie is created. Completely disabling cookies may, however, mean that you cannot use all functions of our website.
Google Analytics 4
For the purpose of tailoring and continuously optimizing our pages, we use Google Analytics 4, a web analytics service provided by Google, if you have given your consent. The provider for users in the European Economic Area and Switzerland is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Ireland Limited may involve services of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Google Analytics 4 uses cookies and similar technologies that enable an analysis of your use of our website. In particular, the following information may be processed:
- pages visited and interactions on the website,
- date and time of access,
- approximate location data,
- technical information about browser, operating system, and device,
- referrer URL,
- interactions with forms, buttons, or booking elements, where configured accordingly.
According to Google, individual IP addresses of users from the EU are not logged or stored in Google Analytics. IP address data for EU traffic is used only to derive coarse location data and is then discarded.
The processing takes place only if you have given us your explicit consent via the cookie banner. The legal basis for accessing your device is § 25(1) TDDDG. The legal basis for the subsequent processing of personal data is Art. 6(1)(a) GDPR.
A transfer of personal data to the United States cannot be excluded. Google LLC is certified under the EU-U.S. Data Privacy Framework. In addition, where required, Google relies on the EU Standard Contractual Clauses for international data transfers.
You may withdraw your consent at any time with effect for the future via our cookie consent tool. In addition, you can prevent Google Analytics from collecting data by downloading and installing the browser add-on provided by Google: https://tools.google.com/dlpage/gaoptout?hl=en. Further information about data protection in connection with Google Analytics can be found at: https://support.google.com/analytics/answer/6004245?hl=en.
Google Ads
We have integrated Google Ads conversion tracking and, where applicable, remarketing functions on our website in order to draw attention to our services on external websites and to determine how successful individual advertising measures are. The provider for users in the European Economic Area and Switzerland is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Ads may use conversion cookies or similar technologies. This makes it possible to record whether users perform certain actions on our website after clicking an ad, such as contacting us, booking an appointment, or completing another conversion. Google may process technical information, cookie IDs, ad interactions, referrer information, and usage data.
As a general rule, we do not receive any information from Google that allows us to directly identify users. Instead, we receive statistical evaluations to measure the success of our advertising measures. If you are logged into a Google service, Google may associate your visit with your Google account.
The processing takes place only if you have given us your explicit consent via the cookie banner. The legal basis for accessing your device is § 25(1) TDDDG. The legal basis for the subsequent processing of personal data is Art. 6(1)(a) GDPR.
A transfer of personal data to the United States cannot be excluded. Google LLC is certified under the EU-U.S. Data Privacy Framework. In addition, where required, Google relies on the EU Standard Contractual Clauses for international data transfers.
You may withdraw your consent at any time with effect for the future via our cookie consent tool. Further information about Google’s data processing can be found at: https://policies.google.com/privacy?hl=en.
Meta Pixel
If you have given your consent, we have integrated the Meta Pixel provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, on our website. The Meta Pixel allows us to measure the success of our advertising campaigns on Meta platforms such as Facebook and Instagram and to create target groups for advertising campaigns.
The Meta Pixel may transmit, in particular, the following data to Meta:
- pages or URLs accessed,
- interactions on our website, such as clicks on buttons or form events,
- technical information such as browser, device, screen resolution, and IP address,
- cookie IDs or similar identifiers,
- advertising click IDs if you reached our website via an advertisement.
We configure the Meta Pixel so that no directly identifying information such as name, address, email address, or telephone number, and no health data or information about medications, is actively transmitted to Meta. Nevertheless, Meta may associate the transmitted data with your account, especially if you are logged into Facebook or Instagram, and may process it for its own purposes. We do not have full control over Meta’s further data processing.
The processing takes place only if you have given us your explicit consent via the cookie banner. The legal basis for accessing your device is § 25(1) TDDDG. The legal basis for the subsequent processing of personal data is Art. 6(1)(a) GDPR.
A transfer of personal data to the United States cannot be excluded. Meta Platforms, Inc. is certified under the EU-U.S. Data Privacy Framework. In addition, where required, Meta relies on the EU Standard Contractual Clauses for international data transfers.
You may withdraw your consent at any time with effect for the future via our cookie consent tool. Further information about Meta’s data processing can be found at: https://www.facebook.com/privacy/policy/.
Meta Lookalike Audiences
If you have given your consent, we also use the “Lookalike Audiences” function provided by Meta Platforms Ireland Limited. In this context, event data may be processed that we collect via the Meta Pixel implemented on our website, for example certain interactions or conversion events.
This event data is used to create statistical target groups in order to display advertising campaigns to people who are similar to existing target groups. We make sure that we do not actively transmit directly identifying information such as names or email addresses, or health data or medication-related information, to Meta.
The legal basis for accessing your device is § 25(1) TDDDG. The legal basis for the subsequent processing of personal data is your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future via our cookie consent tool.
§6. Data Subject Rights
You have the following rights in relation to us:
- pursuant to Art. 15 GDPR, the right to obtain free information about the personal data processed and to receive a copy of this data;
- pursuant to Art. 15 GDPR, the right to information about the source and recipients of the data, the purpose of the processing, and the storage period;
- pursuant to Art. 16 GDPR, the right to obtain the rectification of inaccurate data or the completion of incomplete data without undue delay;
- pursuant to Art. 17 GDPR, the right to obtain the deletion of your personal data stored by us;
- pursuant to Art. 18 GDPR, the right to obtain restriction of the processing of your personal data;
- pursuant to Art. 20 GDPR, the right to receive the data provided to us in a structured, commonly used, and machine-readable format, or to have it transmitted to a third party;
- pursuant to Art. 19 GDPR, the right to be informed about all recipients to whom personal data has been disclosed;
- pursuant to Art. 21 GDPR, the right to object to the processing of personal data;
- pursuant to Art. 7(3) GDPR, the right to withdraw your consent to the processing of personal data at any time with effect for the future, without affecting the lawfulness of processing carried out before withdrawal.
You may exercise your rights at any time by contacting the controller named in §1. In addition, pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, the registered office of the controller, or the place of the alleged infringement, if you believe that the processing of personal data concerning you violates data protection requirements.
The supervisory authority responsible for the controller’s registered office is:
Berlin Commissioner for Data Protection and Freedom of InformationAlt-Moabit 59-61
10555 Berlin
Germany
Telephone: +49 30 13889-0
Email: [email protected]
Website: www.datenschutz-berlin.de
Last updated: April 2026