Praxis Kerim Logo

Privacy Policy

Privacy at a Glance

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

The use of our website is usually possible without providing personal information. Insofar as personal data (such as name, address or e-mail addresses) is collected on our pages, this is always done, as far as possible, on a voluntary basis.

Controller

Dr. med. Bahtiyar Kerim, MHBA

Jacques-Offenbach-Straße 12

63069 Offenbach am Main

Phone: +49 69 870015360

Email: info@praxiskerim.de

Data Collection on Our Website

Who is responsible for data collection on this website? The data processing on this website is carried out by the website operator. You can find their contact details in the imprint of this website.

How do we collect your data? On the one hand, your data is collected when you communicate it to us. This can be, for example, data that you enter in a contact form.

Other data is collected automatically by our IT systems when you visit the website. These are mainly technical data (e.g. internet browser, operating system or time of page access).

Purpose of Data Collection

Some of the data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior.

What rights do you have regarding your data? You have the right to obtain information about the origin, recipient and purpose of your stored personal data at any time free of charge.

Data Storage

The data processing on this website is carried out by the website operator. You can find their contact details in the imprint of this website.

Your data will be deleted as soon as it is no longer required for the fulfillment of the purpose of collection.

Your Rights

You have the right to information about the personal data we process.

You have the right to correction of incorrect or completion of incomplete data.

You have the right to deletion of your personal data, provided that no legal retention periods oppose this.

You have the right to restrict the processing of your personal data (Art. 18 GDPR).

You have the right to data portability — to receive the data concerning you in a structured, commonly used and machine-readable format (Art. 20 GDPR).

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your data where it is based on a legitimate interest (Art. 21 GDPR).

Where processing is based on your consent, you may withdraw it at any time with effect for the future; the lawfulness of processing carried out before the withdrawal remains unaffected (Art. 7(3) GDPR).

Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your data infringes the GDPR (Art. 77 GDPR).

Competent supervisory authority: The Hesse Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit), Postfach 3163, 65021 Wiesbaden — poststelle@datenschutz.hessen.de.

Cookies

Our websites partially use so-called cookies. Cookies do not cause any damage to your computer and do not contain viruses.

Cookies serve to make our offer more user-friendly, effective and secure.

Digital Practice Services

Below we inform you in detail about the digital services of Praxis Dr. Kerim, how your data is processed, and your rights under GDPR.

1. AI-Powered Phone Assistant "Anna"

We operate an AI-powered voice assistant named "Anna" that handles patient phone calls and assists with appointment booking, prescription renewals, sick-note requests, referral requests, and basic information. At the start of every call you are explicitly informed that you are talking to an AI and can say "human" at any time to be connected directly to a staff member.

Data processed: voice recording (transient, NOT stored), textual transcript of the conversation (max. 30 days), intent category, and patient master data (first/last name, date of birth, insurance number) for identification when needed.

Pseudonymization: Personal data (name, date of birth, insurance number, phone number, address) are replaced with non-reversible tokens before any transmission to AI speech-processing (Azure OpenAI, West Europe). The mapping table token↔plaintext remains exclusively on our servers and is fully destroyed at call end.

Legal basis: Art. 6(1)(b) GDPR (initiation and performance of the treatment contract) and Art. 9(2)(h) GDPR (processing of health data for the purpose of medical treatment). At the start of every call you are explicitly informed that this is an AI and can be connected to a staff member at any time.

Storage duration: voice recording 0 seconds (live-processed); transcript and conversation data max. 30 days; resulting appointments/orders in the practice software per medical record retention obligation (10 years, § 630f BGB).

No solely automated decision with legal or similarly significant effect within the meaning of Art. 22 GDPR takes place. Appointments, prescriptions, sick notes and referrals are always reviewed and approved by practice staff or the treating physician.

2. Online Appointment Booking

Through our website you can independently book appointments with one of our doctors without calling the practice. Transmission is encrypted (TLS 1.2+).

Data processed: first and last name, date of birth, phone number, desired appointment slot, optional reason. The data is stored in our internal practice database and assigned to the corresponding doctor's calendar.

Legal basis: Art. 6 (1) (b) GDPR (contract initiation). Storage duration: per medical record retention obligation (10 years, § 630f BGB) or until explicit deletion request.

3. Online Orders (Prescription, Sick Note, Referral)

Existing patients can request follow-up prescriptions, sick notes (max. 3 days), and referrals via our online form. Every request is reviewed by the treating physician before the document is issued.

Data processed: patient identification, requested medication/concern, pickup or delivery preference. Legal basis: Art. 9 (2) (h) GDPR (medical treatment). Storage duration: 10 years per record retention obligation.

4. Self Check-In at the Practice Kiosk

Our practice has a self check-in terminal ("Kiosk") where you can register independently using your electronic health card (eGK). The card is only read, NOT stored.

Data processed: master data read from eGK (insurance number, name, date of birth, address, health insurance), generated waiting ticket. Optional: photo capture for first-contact identification (only with explicit on-screen consent).

The kiosk PC is locked exclusively to practice functions (kiosk mode); other applications are inaccessible. Data processing occurs entirely on practice-owned hardware — no cloud transfer. Legal basis: Art. 6 (1) (b) and Art. 9 (2) (h) GDPR.

5. Waiting Room Display

In our waiting room there is a screen displaying called patient ticket numbers and the corresponding treatment room, along with an audio announcement.

Data processed: exclusively anonymized ticket numbers and room labels. NO names, NO dates of birth, NO diagnoses are displayed or announced in the waiting room. The voice output runs locally on the display device (Piper Text-to-Speech); NO cloud service is involved.

Storage duration: live display only, no persistence. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in efficient patient flow management in the waiting room).

6. Practice Dashboard (Internal Application)

Our doctors and medical assistants use an internal web dashboard to manage patient data, appointments, orders, invoices, and practice inventory. Access is password-protected with two-factor authentication; every action is logged in a tamper-resistant audit log.

Data processing occurs exclusively on practice-owned servers in Germany. Data processed: complete medical records per treatment documentation. Legal basis: Art. 9 (2) (h) GDPR. Storage duration: 10 years per retention obligation.

7. Data Processors (Art. 28 GDPR)

We have signed Data Processing Agreements (DPAs) per Art. 28 GDPR with the following external services:

  • Microsoft Ireland Operations Ltd. — Azure OpenAI (speech processing for the AI phone assistant, region West Europe / EU)
  • Microsoft Ireland Operations Ltd. — Azure Speech Services (speech synthesis, region West Europe / EU)
  • Deepgram Ltd. — Speech-to-text processing for AI telephony (region EU/Frankfurt)
  • Telnyx LLC — SIP telephony connection (region EU/Frankfurt)
  • Netlify Inc. — Hosting of website praxiskerim.de (region EU)
  • Amazon Web Services EMEA SARL — Software update distribution for practice devices (S3, region eu-north-1)
  • Meta Platforms Ireland Ltd. — Meta Pixel for conversion measurement of Facebook/Instagram advertising (only after consent; third-country transfer to the USA under the EU-US Data Privacy Framework)
  • Google Ireland Ltd. — Google Ads conversion tracking (only after consent; third-country transfer to the USA under the EU-US Data Privacy Framework)

Upon request, we will provide the respective DPA documents for inspection. Third-country transfers occur only to regions with an adequacy decision or under standard contractual clauses.

8. Technical Security & Pseudonymization

All data transmission is encrypted (TLS 1.2+, WSS, SRTP for audio). Practice-owned servers are protected by firewall, access restrictions, and 2-factor authentication. Patient data in databases is encrypted at rest (AES-256).

Personal data is systematically pseudonymized before transmission to cloud AI services: names, dates of birth, insurance and phone numbers are replaced with tokens. The mapping table remains exclusively on our servers and is automatically deleted after each operation (call end, session end).

We implement appropriate technical and organizational measures (TOM) per Art. 32 GDPR, including regular penetration tests, staff training, and a documented Data Protection Impact Assessment (DPIA) for AI-supported services.

9. Advertising & Reach Measurement (Meta Pixel, Google Ads, Marketing Emails)

To measure and improve our online advertising, we use marketing technologies. These are only used on the basis of your explicit consent and can be withdrawn at any time with effect for the future.

Meta Pixel & Google Ads: On our website we use the Meta Pixel (Meta Platforms Ireland Ltd.) and Google Ads conversion tracking (Google Ireland Ltd.) to measure whether a click on one of our ads led to an appointment booking. We only see aggregated conversion figures; the practice does not identify individual persons.

Legal basis: Art. 6(1)(a) GDPR (consent). These marketing cookies and scripts are only loaded after you have selected "Accept all" in the cookie banner or activated the marketing checkbox. Without your consent, no marketing tracking takes place.

Recipients / third-country transfer: With Meta and Google, data may be transferred to the USA; these providers are certified under the EU-US Data Privacy Framework, supplemented by standard contractual clauses. Withdrawal: you can withdraw your consent at any time via the "Cookie settings" link in the footer. Consent is valid for 6 months, after which we ask again.

Marketing emails (optional): During online appointment booking and at the practice kiosk, you can voluntarily consent to receiving information about health offers and promotions from the practice by email. This consent is not a prerequisite for booking an appointment or for treatment.

Data processed: email address and name. Legal basis: Art. 6(1)(a) GDPR (consent); the consent is recorded with a timestamp. Without consent, we do not send you any advertising emails.

Withdrawal: you can object to the promotional use of your email address at any time without any formality (e.g. via the unsubscribe notice in every email or by message to info@praxiskerim.de) — without any disadvantages. After withdrawal, we no longer use your data for advertising purposes.

10. Employee data (staff app and practice dashboard)

Our doctors and medical assistants work with the practice dashboard on the computer and the staff app “Praxis Team” on their phone. In doing so we also process personal data of our employees. This section is addressed to them.

Account and master data: first and last name, work e-mail address, role (doctor or medical assistant), assigned permissions, an optional profile picture and the time of the last sign-in. Legal basis: § 26 (1) sentence 1 BDSG in conjunction with Art. 88 GDPR — the processing is necessary for carrying out the employment relationship.

Working-time recording: arrival and departure are recorded by scanning a QR code at the practice kiosk and confirmed with a key stored on the phone. Recorded are the time, the type of entry and the account making it. For employees without their own account, times can be booked automatically according to a stored weekly schedule; such entries are marked as automatic. Legal basis: Art. 6 (1) (c) GDPR in conjunction with § 16 (2) ArbZG and the duty to record working time (Federal Labour Court, decision of 13 September 2022 – 1 ABR 22/21).

Absences: holiday and absence notices with the period and, where stated, the reason.

Sign-in and security logs: successful sign-ins, failed sign-in attempts and the setup and use of two-factor authentication. These logs serve solely to protect patient data. Legal basis: Art. 6 (1) (f) and Art. 32 GDPR. Failed sign-in attempts are deleted automatically after 90 days.

Assignment to treatment: the patient record documents who called, treated or made an entry for a patient — for example for vaccinations, preventive examinations and messages from the patient portal. This assignment is part of the medical duty of documentation. Legal basis: Art. 9 (2) (h) GDPR in conjunction with § 630f BGB.

Team messages: the internal chat stores sender, recipient, time and content. Messages are deleted automatically after seven days.

Notifications and devices: for push notifications we store a device identifier and the platform (iOS or Android). Devices that have had no contact for a year are removed automatically. The notifications themselves never contain content: neither a patient name nor a text appears on the lock screen.

Use on private phones: the staff app may only be used on a private device on the basis of a separate written agreement. The app does not access contacts, calendar, location or the photo library. Camera and microphone are used only when you yourself start a recording, a photo or a video consultation at that moment. Only the sign-in session and cached files you opened yourself remain on the device.

No performance or conduct monitoring: the recorded times and logs are not evaluated to assess performance or conduct. Evaluation takes place solely to account for working time, to fulfil legal obligations and, in justified individual cases, to investigate a security incident.

Applications: data submitted through our application form (name, contact details, cover letter, attachments) is processed solely for the selection decision. Legal basis: § 26 (1) sentence 1 BDSG. After the procedure has ended the documents are deleted at the latest after six months, unless you have consented to longer storage.

Retention: account data is deleted or blocked as soon as the employment relationship ends and no retention obligations stand in the way. Working-time records are kept for at least two years (§ 16 (2) ArbZG); longer commercial and tax law periods remain unaffected. Entries in the patient record are subject to the ten-year retention obligation under § 630f (3) BGB.

Your rights as an employee: the same rights apply as for all data subjects — see the section “Your rights”. Please address enquiries to the controller named above.

Contact

If you have any questions about data protection, you can contact us at any time.

You can find the contact details in the imprint of this website.

Praxis Dr. Kerim - General Practitioner in Offenbach | Book Online